New 'DDRop' Attack Undermines Intel and AMD Confidential Computing Protections
Security researchers have revealed a new hardware attack named DDRop that defeats the memory protection built into Intel TDX, Intel Scalable SGX, and AMD SEV-SNP. These technologies are used by cloud providers to keep customer data encrypted and private even from the provider itself, but DDRop exposes a gap in how they verify data freshness. Rather than confirming memory holds the most recent value, these systems only check that data is encrypted, meaning old data can still be read back as if it were current.
To carry out the attack, someone would need existing control over a server's software and brief physical access to insert a small circuit board, called an interposer, between the processor and memory. Costing under $200 to build, the interposer runs at full memory speed and quietly forces the memory module to discard write commands without alerting the processor, leaving outdated encrypted data in place undetected.
DDRop is notable as the first active interposer attack to work against modern DDR5 memory and the first to break the integrity, not just the confidentiality, of an up-to-date Intel TDX system. Earlier similar attacks either only listened passively to memory traffic or worked exclusively on older DDR4 memory, which DDR5's redesigned command structure was thought to prevent.