Researchers Uncover Hardware Flaw That Can Break 'Confidential Computing' Protections
Researchers from KU Leuven, ETH Zurich, Durham University and Google have discovered a design flaw affecting memory encryption hardware used in 'confidential computing' environments, technology that cloud providers use to promise tenants their data stays private even from the cloud provider itself. The flaw exists because the hardware fails to check whether data stored in memory is current or outdated.
Using a custom-built circuit board called DDRop, costing under $200, the researchers demonstrated they could interfere with memory write operations on DDR5 systems. This tricks a protected virtual machine into using old, attacker-controlled data instead of fresh information, all while the data still appears to decrypt correctly. In their proof-of-concept, the team showed they could force a protected virtual machine into a debug mode and read its private data in plain text, and even forge trust certificates so a compromised system still appears legitimate to remote users. The attack reportedly works reliably in under two minutes without crashing the target machine.
Importantly, this attack requires physical access to the server hardware, so it is most relevant to organisations relying on cloud providers' confidential computing guarantees, or to businesses with on-premises servers containing sensitive data that could be physically accessed by an untrusted party.