Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
1–10 of 66 posts
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#2---
It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#3With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#4With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
No, safe execution of untrusted code is impossible by the very definition, not without undoing 40 years of IC design practices.
It's an almost physical limitation which makes it very hard to compute something without some electromagnetic leakage from/to the die.
Take a look on secure CPUs for credit cards. They have layer, upon layers of anti-tampering, anti-extraction measures, and yet TEM shops in China do firmware/secret extraction from them for $10k-$20k
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#5Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#6With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
> It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside. No, safe execution of untrusted code is impossible by the very definition, not without undoing 40 years of IC design practices. It's an almost physical limitation which makes it very hard to compute something without some electromagnetic leakage from/to the die. Take a look on secure CPUs for credit ca…
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#7With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#8With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
> It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside. No, safe execution of untrusted code is impossible by the very definition, not without undoing 40 years of IC design practices. It's an almost physical limitation which makes it very hard to compute something without some electromagnetic leakage from/to the die. Take a look on secure CPUs for credit ca…
> No, safe execution of untrusted code is impossible by the very definition
I think this is more about data processing while hiding the data from whoever operates the hardware. Homomorphic encryption could be a partial answer to that.
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#9With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
Achievable in any circumstances? No. Within a well-defined threat model, definitely.
Re: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
#10With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rouge administrators, on currently available CPUs. --- It is an interesting attack but is the above goal ever achievable? To protect against adversaries from the inside.
That the CPU should be able to cryptographically prove that a VM has been setup without any interference from an inside attacker who controls the hardware.
At the very least, SEV massively raises the barrier to such attacks. It's now beyond the ability of a rogue administrator or technician, requiring complex custom motherboards. But a well-funded inside attacker can target something with high enough value.