A systematic survey of side-channel attack surfaces in Intel TDX

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Intel Trust Domain Extensions (TDX) provides hardware-enforced isolation to protect virtual machines (VMs) from a compromised hypervisor. However, TDX fundamentally delegates key resource management functions such as CPU scheduling, interrupt delivery, and memory virtualization to an untrusted hypervisor, making the execution behavior of a protected VM externally observable. This execution observability creates side-channel attack surfaces even when the hardware ensures the confidentiality of the VM's architectural state. Despite growing interest in the security of Intel TDX, these attacks have not been systematically studied. In this paper, we present a systematic analysis of side-channel attack surfaces in Intel TDX. We model each side-channel attack on TDX as a (P, C, A) tuple consisting of an observation primitive, a leakage channel, and an optional observability amplification mechanism. Using this framework, we categorize existing attacks, identify underlying root causes, and derive security implications and directions for future research.

키워드

Trusted execution environment; Intel TDX; Confidential computing; Side-channel attack; Microarchitectural attack
제목
A systematic survey of side-channel attack surfaces in Intel TDX
저자
Kim, Taehun; Shin, Youngjoo
DOI
10.1016/j.cose.2026.105024
발행일
2026-11
유형
Article
저널명
Computers and Security
권
170