An international team of researchers, including Professor David Oswald from our Department of Computer Science, has discovered a security vulnerability that could put sensitive data stored in cloud computing systems at risk.
The research, led by Belgian university KU Leuven, identified weaknesses in servers used to provide so-called 'confidential computing' services.
These technologies are designed to keep information secure, even from the companies that operate the cloud infrastructure.
A hardware device that can undermine security
The team developed and tested a hardware attack called DDRop, a small and low-cost device that can be physically attached to a server during a brief, one-time visit.
The Durham research team contributed to designing the hardware device and evaluating its effectiveness on Intel TDX systems.
Once installed, the device can interfere with the way a server processes information, potentially allowing attackers to bypass important security protections.
This has significant implications for confidential computing technologies, which are increasingly used to protect sensitive data and workloads in shared cloud environments, for example for protected AI workloads.
Processing sensitive data
Confidential computing helps organisations process sensitive information in the cloud without needing to fully trust the cloud provider.
It is used in a wide range of applications where privacy and security are critical, such as handling personal data, financial information and business-sensitive workloads.
Rather than trying to read encrypted information, DDRop interferes with the process of saving new data to memory. This makes an attack particularly difficult to detect because the affected information remains encrypted and appears legitimate to the system.
By exploiting this weakness, an attacker could cause a protected virtual machine to continue using older, manipulated data without realising anything is wrong.
Serious implications for cloud security
The researchers found that DDRop can affect confidential computing technologies on both Intel and AMD platforms.
In some cases, it can even undermine the mechanisms used to prove that a virtual machine is secure and trustworthy.
The findings highlight the importance of strengthening hardware security protections as organisations increasingly rely on cloud-based services to process and store sensitive information.
The DDRop research has informed industry response through a co-ordinated disclosure process, contributing to public security advisories issued by Intel and AMD and helping shape discussions on future memory-encryption designs and hardware protections.