7 ms·
Ok, I see: it isn't TME-MK that does it alone -- that is covered by the paper, even, as insufficient -- but this extra "cryptographic integrity protection mode"
by saurik 1y ago
Ok, I see: it isn't TME-MK that does it alone -- that is covered by the paper, even, as insufficient -- but this extra "cryptographic integrity protection mode", which is separate and yet not given a fancy name.
> Furthermore,
TDX adds cryptographic integrity via a 28-bit MAC in ECC
bits [19, 47].
> While the logical integrity could be bypassed by aliasing
between two different TDs, as demonstrated in Section 5,
the cryptographic integrity remains robust against simple
aliasing attacks. This is because, while an interposer enables
replay of the data bits containing the ciphertext, it cannot be
used to replay the ECC bits, which store the cryptographic
MAC. Replaying both data and ECC bits, while theoretically
possible, would require a full-fledged interposer capable
of intercepting and replaying the data contents. Such an
interposer poses significantly higher engineering challenges.
Even this is only sort of better, in that it isn't actually secure against a truly evil RAM chip: it just happens to be using a feature of the RAM chip that narrowly defeats this particular form of command address override attack... but, though, that's still pretty reasonable, as the only reason this attack could be so cheap to build is because of its limitations.
Thanks!!