Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs 

Intel and AMD have published advisories after academics disclosed details of the new TEE.fail attack method.

Chipmaker Patch Tuesday

A team of academic researchers has disclosed the details of a new attack method that can be used to break CPU-based security technologies from Intel and AMD by targeting DDR5 memory.

The attack method, named TEE.fail, was discovered by researchers from Purdue University and Georgia Institute of Technology. 

The attack requires physical access to the targeted system and involves placing a device named an interposer between the computer’s CPU and memory in an effort to analyze DRAM bus traffic.

An attacker can then use the captured data to extract cryptographic keys from Intel TDX and AMD SEV-SNP trusted execution environment (TEE) implementations. In addition, a hacker can extract attestation keys that can be leveraged to compromise Nvidia’s GPU Confidential Computing, which allows attackers to run AI workloads without any TEE protections, the researchers explained. 

These confidential computing technologies, used for data centers and cloud computing, are designed to protect code and data from attackers who have compromised the host system, and even from malicious insiders. 

The TEE.fail attack involves soldering the interposer to the DIMM. The interposer built by the researchers, for which they have made available schematics, costs under $1,000 if off-the-shelf electronic components are used. 

Advertisement. Scroll to continue reading.

TEE.fail is similar to the recently disclosed WireTap and Battering RAM attacks, which also involved using an interposer to capture valuable data from memory. 

However, there are some significant differences. WireTap and Battering RAM only worked against DDR4 memory, while TEE.fail targets DDR5.

“The difference is critical, as TEE.fail can be used to attack the latest TEE offerings by Intel and AMD, namely Intel TDX and AMD SEV-SNP with Ciphertext Hiding, which offer confidential virtual machines (CVMs),” the researchers explained. “As CVMs are used for the trust anchor in Nvidia’s GPU confidential computing, we show how our attack also breaks GPU attestation.”

Both Intel and AMD have published advisories in response to the TEE.fail research. However, as in the case of WireTap and Battering RAM, the chip giants said attacks requiring physical access to the targeted system are not in scope of their products’ threat model.

Related: New CounterSEVeillance and TDXDown Attacks Target AMD and Intel TEEs

Related: RMPocalypse: New Attack Breaks AMD Confidential Computing

Related: VMScape: Academics Break Cloud Isolation With New Spectre Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.