Google Finds Flaws in Intel TDX After Nine-Month Audit

Google analyzed 81 potential attack vectors and identified 10 vulnerabilities in Intel Trust Domain Extensions (TDX) after a nine-month audit process.

TDX is a type of “confidential computing” technology built to provide security while processing sensitive data in a hardware-isolated environment. According to Intel, TDX offers several new features, including a full VM (virtual machine) computing model, requiring no code changes.

Confidential Computing Deep Dive: Answers to 3 Questions About Confidential Computing

“Organizations use confidential computing to manage data and provide access to trusted parties in a verifiable, revocable, and time-sensitive manner. Intel. reinforced our commitment to performing thorough analysis to address all potential vulnerabilities.”

In a blog post published today, Cfir Cohen, Staff Software Engineer at Google, and Andrés Lagar-Cavilla, Principal Engineer Platform Security, discussed several issues related to arbitrary code execution (RCE), safe error handling, and state management. He said he checked the TDX firmware for some issues. , and Denial of Service (DoS). Intel is reported to have fixed all the issues Google identified.

“We are happy to report that all the issues we reported have been fixed by Intel,” wrote Cohen and Lagar-Cavilla. “The secondary goal was to better understand the expected Intel TDX threat model, identify limitations in its design and implementation, and inform Google’s deployment decisions.”

To this end, Google and Intel conducted reviews through a shared issue tracker and regular technical meetings.

“This allowed Intel to provide detailed technical information about the capabilities of the Intel TDX components and to help reviewers resolve potential ambiguities in the documentation and source code,” the Google post said. It is written.

The search giant has also confirmed that it supports Intel in making the TDX firmware source code base publicly available and verifiably buildable.

The collaboration with Intel comes a few weeks after Google’s Project Zero reported 18 zero-day defects in Samsung’s Exynos modems.

Editorial image credit: rafapress / Shutterstock.com

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *