Academics from the Georgia Institute of Technology and Purdue University have demonstrated that the security guarantees offered by Software Guard eXtensions (SGX) can be bypassed in DDR4 systems to passively decrypt sensitive data, using the new WireTap attack.
See also: RAM Battering Attack Bypasses Intel and AMD Security

SGX is designed as a hardware feature in Intel server processors that allows applications to run in a Trusted Execution Environment (TEE). It essentially isolates trusted code and resources inside what are called enclaves, preventing attackers from seeing their memory or CPU state.
In this way, the mechanism ensures that data remains confidential even when the underlying operating system has been compromised or otherwise altered. However, recent findings show the limitations of SGX.
“We show how one can build a device to physically inspect all memory traffic inside a computer cheaply and easily, in environments with only basic power tools and using equipment that is easily purchased online,” the researchers said. “By using our proxy device against the SGX authentication mechanism, we can extract a secret SGX authentication key from a machine in a fully trusted state, thereby breaching SGX security.”
Like the Battering RAM recently uncovered by researchers at KU Leuven and the University of Birmingham, the new method – codenamed WireTap – relies on an intermediary placed between the CPU and the memory module to monitor the data flowing between them. The intermediary can be installed by an attacker either through a supply chain attack or through a physical breach.
See also: Nvidia invests $5 billion in Intel for chip development

At its core, the physical attack exploits Intel's use of deterministic cryptography to perform full key recovery against Intel SGX's Quoting Enclave (QE) , essentially making it possible to extract an ECDSA signing key that can be used to sign arbitrary SGX enclaves.
In other words, an attacker can exploit the deterministic nature of memory encryption to create a kind of oracle to break the security of the fixed-time cryptographic code.
However, while Battering RAM is a low-cost attack that can be carried out with equipment costing less than $50, WireTap costs around $1,000, including the logic analyzer.
In a hypothetical attack scenario targeting SGX-backed blockchain deployments such as Phala Network, Secret Network, Crust Network , and IntegriTEE, the study found that WireTap can be leveraged to undermine confidentiality and integrity guarantees and allow attackers to disclose confidential transactions or illegally obtain transaction rewards.
See also: Intel: Layoffs will affect 15% of staff

In response to the findings, Intel stated that the exploit is outside the scope of its threat model, as it assumes a physical adversary with direct access to the hardware with a memory bus broker. In the absence of a “patch,” it is recommended that servers operate in secure physical environments and use cloud providers that provide independent physical security.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
