Lune

USENIX Security2026顶会

Jailbreaking the AMD Secure Processor: Enabling Live Analysis of SEV-SNP's Undocumented Security Boundaries

Muyan Shen, Hongzhan Ma, Ketong Shang, Ruofei Qu, Yu Qin, Dengguo Feng

出版方
2026年份
1顶会引用

摘要

AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) protects virtual machines using its hardware root of trust, the AMD Secure Processor (ASP). However, its security relies on complex, opaque firmware features, such as a dynamic hot-patching mechanism, that create attack surfaces shielded from independent scrutiny. To overcome this "black-box" challenge, we present ASPBreaker, the first practical, fully deterministic jailbreak of the ASP, achieved by exploiting a novel combination of memory aliasing and time-of-check-to-time-of-use (TOCTOU) vulnerability.

Using this jailbreak as a tool for live analysis, we demonstrate how achieving arbitrary code execution on a vulnerable firmware version can be used to subvert the security of a subsequent, fully-patched one. Our analysis revealed critical flaws, enabling two practical attacks against the latest firmware: one that allows an adversary to decrypt the memory of a virtual machine and another that bypasses existing mitigations to forge attestation reports. Our findings, which were responsibly disclosed, demonstrate a fundamental break in the forward-security model of SEV-SNP and highlight the critical need for independent auditing of opaque firmware boundaries.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

它引用的顶会 Paper16

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖