This post is also available in:
Confidential computing is supposed to solve one of cloud computing’s biggest security problems: how to process sensitive information on infrastructure operated by someone else without giving that operator access to the data. But new research shows that even encrypted cloud workloads can be undermined if an attacker can interfere with the server’s physical memory.
An international research team has developed DDRop, a small, low-cost hardware device that demonstrates a vulnerability affecting confidential-computing technologies on Intel and AMD platforms.
The attack requires physical access, but only briefly. Researchers designed it so that it can be attached to a server during a one-time visit. Once installed, the device interferes with memory operations rather than attempting to directly decrypt protected information.
That distinction is important.
Confidential-computing systems use hardware-based protections to isolate sensitive workloads, such as protected virtual machines, from other software and even from the cloud provider itself. Data stored in memory is encrypted so that someone controlling the surrounding infrastructure should not simply be able to inspect it.
It attacks a different part of the process: memory writes.
According to TechXplore, instead of reading encrypted information, the device can interfere when the server attempts to save updated data to memory. This can cause a protected virtual machine to continue operating with an older version of that data rather than the new information it expected to store.
Because the memory contents remain encrypted and can still appear legitimate to the system, detecting the manipulation can be difficult. The virtual machine may therefore continue processing information without realizing that its view of memory has been altered.
Researchers tested the technique against confidential-computing systems including Intel TDX, with the Durham University team contributing to the attack hardware and evaluating its effectiveness. The researchers also found implications for AMD-based confidential-computing technology.
In some scenarios, it could interfere with attestation, the mechanism used to demonstrate that a protected virtual machine is running in a trustworthy environment. Undermining that assurance could weaken one of the fundamental guarantees confidential computing is intended to provide.
The findings have clear relevance to government and defense organizations increasingly moving sensitive workloads, including AI processing, into shared cloud infrastructure. They show that encryption alone cannot protect a workload if an attacker can manipulate the hardware responsible for handling encrypted memory.
The attack does require physical access to install the device, which significantly limits the threat compared with remotely exploitable vulnerabilities. Still, cloud data centers and other high-value computing environments must consider supply-chain, maintenance and insider-access risks alongside conventional cyberattacks.
The researchers disclosed their findings through a coordinated process, contributing to security advisories from the companies.
This highlights a broader hardware-security lesson: confidential computing can hide what is stored in memory, but systems must also ensure that the memory itself behaves exactly as the processor expects.

























