One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
Robert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre Seifert
Abstract
AMD Secure Encrypted Virtualization (SEV) offers protection mechanisms for virtual machines in untrusted environments through memory and register encryption. To separate security-sensitive operations from software executing on the main x86 cores, SEV leverages the AMD Secure Processor (AMD-SP). This paper introduces a new approach to attack SEV-protected virtual machines (VMs) by targeting the AMD-SP. We present a voltage glitching attack that allows an attacker to execute custom payloads on the AMD-SPs of all microarchitectures that support SEV currently on the market (Zen 1, Zen 2, and Zen 3). The presented methods allow us to deploy a custom SEV firmware on the AMD-SP, which enables an adversary to decrypt a VM's memory. Furthermore, using our approach, we can extract endorsement keys of SEV-enabled CPUs, which allows us to fake attestation reports or to pose as a valid target for VM migration without requiring physical access to the target host. Moreover, we reverse-engineered the Versioned Chip Endorsement Key (VCEK) mechanism introduced with SEV Secure Nested Paging (SEV-SNP). The VCEK binds the endorsement keys to the firmware version of TCB components relevant for SEV. Building on the ability to extract the endorsement keys, we show how to derive valid VCEKs for arbitrary firmware versions. With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rogue administrators, on currently available CPUs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d6b89156-425a-4963-aa0f-57cd085c372aCited by top-tier papers31
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth et al.S&P 2022 · 87 citations
- SoK: SGX.Fail: How Stuff Gets eXposedStephan van Schaik, Alexander Seto, Thomas Yurek, Adam Batori et al.S&P 2024 · 52 citations
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
- CacheWarp: Software-based Fault Injection using Selective State ResetRuiyi Zhang, Lukas Gerlach, Daniel Weber, Lorenz Hetterich et al.USENIX Security 2024 · 36 citations
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik et al.S&P 2026 · 29 citations
Builds on4
- VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interfaceZitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean et al.USENIX Security 2021 · 127 citations
- Exploiting Unprotected I/O Operations in AMD's Secure Encrypted VirtualizationMengyuan Li, Yinqian Zhang, Zhiqiang Lin, Yan SolihinUSENIX Security 2019 · 104 citations
- SEVurity: No Security Without Integrity : Breaking Integrity-Free Memory Encryption with Minimal AssumptionsLuca Wilke, Jan Wichelmann, Mathias Morbitzer, Thomas EisenbarthS&P 2020 · 72 citations
- Insecure Until Proven Updated: Analyzing AMD SEV's Remote AttestationRobert Buhren, Christian Werling, Jean-Pierre SeifertCCS 2019 · 60 citations
Related papers
- StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack EngineRuiyi Zhang, Tristan Hornetz, Daniel Weber, Fabian Thomas et al.USENIX Security 2026 · 1 citation
- STALEUS: Breaking AMD SEV-SNP via Memory IncoherenceBenedict Schlüter, Shweta ShindeUSENIX Security 2026
- CrossLine: Breaking "Security-by-Crash" based Memory Isolation in AMD SEVMengyuan Li, Yinqian Zhang, Zhiqiang LinCCS 2021 · 41 citations
- Jailbreaking the AMD Secure Processor: Enabling Live Analysis of SEV-SNP's Undocumented Security BoundariesMuyan Shen, Hongzhan Ma, Ketong Shang, Ruofei Qu et al.USENIX Security 2026
- Reload+Reload: Exploiting Cache and Memory Contention Side Channel on AMD SEVLi-Chung Chiang, Shih-Wei LiASPLOS 2025 · 8 citations
