SECURITY
Attackers would need physical access to the server to pull off the DDR5 trick
Computer security researchers have identified a design flaw in modern encryption hardware that allows access to protected memory in notionally confidential computing environments. But the attacker would need physical access to the victim system.
Boffins affiliated with KU Leuven, ETH Zurich, Durham University, and Google have found that scalable memory encryption hardware fails to check whether the data in memory is fresh.
As a result, they've been able to devise a small hardware interposer, dubbed DDRop, that when wired to an appropriate circuit board, interferes with DDR5 write operations. Unable to tell that memory isn't fresh, a protected VM becomes vulnerable to a replay attack that uses stale, attacker-selected data.
They describe their work in a paper titled, "DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes." Their attack requires physical access and so it is relevant mainly in scenarios where confidential computing guarantees have been made to tenants by cloud service providers.
"DDRop uses a custom-built 'interposer': a small, custom-designed circuit board, costing under $200, that sits between the processor and a memory module," explained Jo Van Bulck, a professor in the DistriNet lab at KU Leuven, Belgium, in an email to The Register. "It corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory. The protected VM keeps computing on old data that still decrypts perfectly. We are releasing the complete interposer design as open-source hardware."
The attack breaks the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP, used in trusted execution environments (TEEs).
Van Bulck and colleagues Jesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi, David Oswald, Martin Thompson, Kaveh Razavi, and Ingrid Verbauwhede developed a proof-of-concept attack on a current Intel TDX server.
"By injecting maliciously crafted secure page-table entries, we can force any protected VM into debug mode and read out its private memory in plaintext," said Van Bulck. "Furthermore, writing to critical TDX metadata structures enables forged attestation reports, so that a backdoored VM appears trusted to the remote user."
Both attacks, said Van Bulck, succeed deterministically in under two minutes without crashing the machine.
Several of these researchers developed a similar attack on DDR4. But Van Bulck said this is the first active interposer attack on DDR5.
"DDR5’s redesigned command bus prevents the address-aliasing tricks used by Battering RAM, and until now, only considerably weaker passive attacks had been demonstrated on DDR5: TEE.fail monitors the data bus using bulky, second-hand logic analyzers that are easier to detect and require slowing the memory bus to its lowest speed to observe ciphertext patterns, which can be masked in software," he explained.
DDRop differs in that it alters DDR5 bus traffic at full speed. According to Van Bulck, it's the first attack to subvert TDX's trusted management interface without exploiting a software bug. It also reduces the cost of prior interposition attacks that took an estimated $170,000 in lab equipment to perform.
There's no easy fix for Intel's and AMD's current scalable memory-encryption designs, said Van Bulck, and no simple software or hardware patch that can address the root cause.
"Scalable memory encryption deliberately trades cryptographic freshness (e.g., available in early Intel SGX offerings supporting only 128/256 MB of protected memory) for the ability to protect large amounts of memory in cloud systems," he said.
Noting that Intel's Simon Johnson recently discussed memory-interposer attacks at an industry conference, Van Bulck said that planned mitigations like "cache line versioning" still appear to be vulnerable to DDRop.
In a security bulletin released on Monday, Intel acknowledged the DDRop disclosure and said the attack is out of scope for its cloud computing threat model. The company said it is "evaluating additional architectural hardening options and detection mechanisms as part of ongoing platform security improvements…"
AMD also said the attack is out of scope and no mitigation is planned. ®

5 hours ago
9








English (US) ·