BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNP
Philipp Giersfeld, Benedict Schlüter, Shweta Shinde
Abstract
SEV-SNP is AMD's offering of confidential computing in the cloud. It enables the creation of so-called confidential virtual machines. To achieve its security, SEV-SNP relies on a trusted co-processor called the Platform Security Processor (PSP). In this paper, we present the following novel observations: The hypervisor can change the MMIO address mapping of internal devices (e.g., SMU that manages power). Worse, these changes affect how PSP accesses to system DRAM are routed. With this ability, we showcase that we can mount a confused deputy attack on the PSP. Specifically, we can trick the PSP into writing attacker-controlled values to the MMIO range of internal devices. As there is little documentation on internal devices, it is challenging to identify: which device to write to, at what location, and with what value. To this end, we reverse engineer an undocumented device called FASTREG. Its role is to map the internal control network 4 GB address space as an addressable range (e.g., to the internal device, hypervisor, PSP) to facilitate read/write. Putting these two observations together, we use the PSP to update the internal control network to disable the IOMMU's SEV-SNP protections, to subsequently fake attestation and enable debug on production CVMs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f14a3f4-12ec-4289-8eb7-c534f455ccd9Cited by top-tier papers1
Ask how each one uses itBuilds on25
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li et al.USENIX Security 2021 · 130 citations
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth et al.S&P 2022 · 87 citations
- SEVurity: No Security Without Integrity : Breaking Integrity-Free Memory Encryption with Minimal AssumptionsLuca Wilke, Jan Wichelmann, Mathias Morbitzer, Thomas EisenbarthS&P 2020 · 72 citations
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
- WeSee: Using Malicious #VC Interrupts to Break AMD SEV-SNPBenedict Schlüter, Supraja Sridhara, Andrin Bertschi, Shweta ShindeS&P 2024 · 42 citations
Related papers
- RMPocalypse: How a Catch-22 Breaks AMD SEV-SNPBenedict Schlüter, Shweta ShindeCCS 2025 · 1 citation
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
- StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack EngineRuiyi Zhang, Tristan Hornetz, Daniel Weber, Fabian Thomas et al.USENIX Security 2026 · 1 citation
- FABRICKED: Misconfiguring Infinity Fabric to Break AMD SEV-SNPBenedict Schlüter, Christoph Wech, Shweta ShindeUSENIX Security 2026
- BadRAM: Practical Memory Aliasing Attacks on Trusted Execution EnvironmentsJesse De Meulemeester, Luca Wilke, David F. Oswald, Thomas Eisenbarth et al.S&P 2025
