A malicious cloud provider can extract the CPU-unique CEK key from AMD's PSP firmware and use it to impersonate SEV platforms, intercept migrations, and read guest memory on Epyc Naples CPUs.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2019 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Insecure Until Proven Updated: Analyzing AMD SEV's Remote Attestation
A malicious cloud provider can extract the CPU-unique CEK key from AMD's PSP firmware and use it to impersonate SEV platforms, intercept migrations, and read guest memory on Epyc Naples CPUs.