SHOT
Copy Text
中文
零知识证明
零知識証明
zkDaily
ZKP Frontier Tracker 🎯
零知识证明 前沿热点追踪 🎯
ZKP フロンティアトラッカー 🎯
Sat
星期六
土曜日
10.04
2025
Intel and AMD trusted enclaves, the backbone of network security, fall to physical attacks
News
新闻
ニュース
https://arstechnica.com/security/2025/09/intel-and-amd-trusted-enclaves-the-backbone-of-network-security-fall-to-physical-attacks/
Dan Goodin
Ars Technica
TEE
Researchers independently published two papers disclosing physical attacks Battering RAM and Wiretap against Intel SGX and AMD SEV-SNP, exploiting deterministic encryption vulnerabilities, allowing attackers to view and manipulate protected data.
研究人员独立发布两篇论文,披露针对Intel SGX和AMD SEV-SNP的物理攻击Battering RAM和Wiretap,利用确定性加密漏洞,允许攻击者查看和操纵受保护数据。
研究者たちは、決定論的暗号化の脆弱性を悪用した物理攻撃であるBattering RAMとWiretapについて、Intel SGXおよびAMD SEV-SNPに対する2つの論文を独立して発表しました。これにより、攻撃者は保護されたデータの内容を閲覧し、操作することが可能になります。
Notes
Notes
要点
TEE depends on deterministic encryption, vulnerable to replay attacks, requiring hardware changes to enhance security
Battering RAM attack costs less than $50, supporting active data read and write
Wiretap attack costs $500-1000, supporting passive data read only
Attacks through physical interceptors, supply chain or physical access can lead to vulnerability exploitation
Chip manufacturers claim TEE design does not defend against physical attacks, but cloud services still widely rely on it
Blockchain services like Phala use TEE to protect smart contracts, facing potential security risks
TEE依赖确定性加密,易受重放攻击,需改硬件以增强安全
Battering RAM攻击成本低于50美元,支持数据读写和篡改
Wiretap攻击成本500-1000美元,仅支持被动数据读取
攻击通过物理拦截器实现,物理访问可导致漏洞利用
芯片商称TEE设计不防御物理攻击,但云服务仍广泛依赖
区块链服务如Phala使用TEE保护智能合约,面临潜在安全风险
TEEは決定論的暗号に依存しており、リプレイ攻撃に対して脆弱であり、セキュリティ強化にはハードウェア変更が必要である。
Battering RAMアタックのコストは50ドル未満であり、アクティブなデータ読み取りと書き込みをサポートする。
Wiretapアタックのコストは500〜1000ドルであり、パッシブなデータ読み取りのみをサポートする。
物理的な傍受、サプライチェーン、または物理的アクセスを経由した攻撃により、脆弱性の悪用につながる可能性がある。
チップメーカーはTEE設計が物理的攻撃を防げないと主張しているが、クラウドサービスは依然として広くこれに依存している。
Phalaのようなブロックチェーンサービスはスマートコントラクトを保護するためにTEEを使用しているが、潜在的なセキュリティリスクに直面している。