TUDRESDEN

Confidential computing's trust mechanism is broken. The fix may not exist

Marcus Chen
Marcus Chen
NewsHue Author
Researcher Muhammad Usama Sardar evaluating cryptographic protocols for confidential computing systems.

Confidential computing is currently being sold as the foundation for European sovereign cloud projects, promising a secure way to run workloads in trusted execution environments. However, new research from Muhammad Usama Sardar at TU Dresden reveals a critical flaw in the remote attestation protocols meant to verify these systems. The core issue lies in attested TLS, a protocol designed to prove that a server is running genuine hardware and unmodified software.

Sardar’s work, which utilized formal verification tools, uncovered relay attacks where traffic intended for a secure server can be silently redirected to a malicious one. These findings are not mere theoretical exercises. They affect production systems like Meta’s Private Processing for WhatsApp, Edgeless Systems’ Contrast, and the open-source Cocos AI platform. The researchers demonstrated that current intra-handshake attestation methods cannot cryptographically bind evidence to the application data once the connection is established.

What makes this discovery significant is the failure of traditional manual security audits to catch these vulnerabilities. Trail of Bits, for instance, reviewed Meta’s implementation without detecting the flaw. This highlights the difference between manual sampling and formal methods which exhaustively test protocols against all possible threat scenarios. Despite this, major cloud providers continue to market these technologies as providing full, auditable control over sensitive customer data.

Industry bodies like the IETF and the Confidential Computing Consortium have acknowledged these relay attacks, yet the marketing messaging remains unchanged. Even worse, the administrative response to these findings included delays in publishing the research artifacts, suggesting an reluctance to address the underlying architectural reality. For organizations relying on these systems to maintain digital sovereignty, this presents a significant risk. The research indicates that the highest level of cryptographic binding required for true security may be impossible to achieve within the current architecture of intra-handshake attestation. Experts now suggest that developers should abandon these methods entirely in favor of post-handshake attestation to maintain actual data integrity.

Frequently Asked Questions

What is the primary security flaw in confidential computing?+
The research identifies that attested TLS protocols used in confidential computing are vulnerable to relay attacks, meaning data can be intercepted by unauthorized servers.
Are production systems affected by this vulnerability?+
Yes, systems including Meta's WhatsApp Private Processing, Edgeless Systems' Contrast, and the Cocos AI platform were found to be vulnerable.
Can this vulnerability be fixed?+
The researchers suggest that the highest level of security required for true data binding may not be achievable within the current intra-handshake architecture.
Tags
Marcus Chen
Marcus Chen
Marcus Chen is our resident technology and science expert, exploring the cutting edge of AI, gadgets, and research.