{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:08:35Z","timestamp":1782968915248,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Federal Ministry of Education and Research of Germany","award":["FKZ 01IS17052"],"award-info":[{"award-number":["FKZ 01IS17052"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3354216","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"1087-1099","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":44,"title":["Insecure Until Proven Updated"],"prefix":"10.1145","author":[{"given":"Robert","family":"Buhren","sequence":"first","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Werling","sequence":"additional","affiliation":[{"name":"Hasso Plattner Institute, Potsdam, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jean-Pierre","family":"Seifert","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"AMD. 2005. Secure Virtual Machine Architecture Reference Manual. Whitepaper.  AMD. 2005. Secure Virtual Machine Architecture Reference Manual. Whitepaper."},{"key":"e_1_3_2_2_2_1","unstructured":"AMD. 2013. AMD Security and Server innovation.https:\/\/members.uefi.org\/learning_center\/UEFI_PlugFest_AMD_Security_and_Server_innovation_AMD_March_2013.pdf Accessed: 2019-04--29.  AMD. 2013. AMD Security and Server innovation.https:\/\/members.uefi.org\/learning_center\/UEFI_PlugFest_AMD_Security_and_Server_innovation_AMD_March_2013.pdf Accessed: 2019-04--29."},{"key":"e_1_3_2_2_3_1","unstructured":"AMD. 2018. AMD Secure Encrypted Virtualization API Version 0.17. https:\/\/developer.amd.com\/wp-content\/resources\/55766.PDF Accessed: 2019-08-05.  AMD. 2018. AMD Secure Encrypted Virtualization API Version 0.17. https:\/\/developer.amd.com\/wp-content\/resources\/55766.PDF Accessed: 2019-08-05."},{"key":"e_1_3_2_2_4_1","unstructured":"AMD. 2019. AMD CEK Certificate Server. https:\/\/kdsintf.amd.com\/cek\/ Accessed:2019-04--16.  AMD. 2019. AMD CEK Certificate Server. https:\/\/kdsintf.amd.com\/cek\/ Accessed:2019-04--16."},{"key":"e_1_3_2_2_5_1","unstructured":"AMD. 2019. SEV firmware for Naples. https:\/\/developer.amd.com\/wp-content\/resources\/amd_sev_fam17h_model0xh_0.17b11.zip Accessed: 2019-04--16.  AMD. 2019. SEV firmware for Naples. https:\/\/developer.amd.com\/wp-content\/resources\/amd_sev_fam17h_model0xh_0.17b11.zip Accessed: 2019-04--16."},{"key":"e_1_3_2_2_6_1","unstructured":"Kaplan AMD and Others. 2016. AMD Memory Encryption. https:\/\/developer.amd.com\/wordpress\/media\/2013\/12\/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf Accessed: 2019-08-05.  Kaplan AMD and Others. 2016. AMD Memory Encryption. https:\/\/developer.amd.com\/wordpress\/media\/2013\/12\/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf Accessed: 2019-08-05."},{"key":"e_1_3_2_2_7_1","volume-title":"Proceedings of the linux symposium. Citeseer, 19--28","author":"Arcangeli Andrea","year":"2009","unstructured":"Andrea Arcangeli , Izik Eidus , and Chris Wright . 2009 . Increasing memory densityby using KSM . In Proceedings of the linux symposium. Citeseer, 19--28 . Andrea Arcangeli, Izik Eidus, and Chris Wright. 2009. Increasing memory densityby using KSM. In Proceedings of the linux symposium. Citeseer, 19--28."},{"key":"e_1_3_2_2_8_1","unstructured":"Russell Brandom and Colin Lecher. 2018. House passes controversial legislationgiving the US more access to overseas data. (2018). https:\/\/www.theverge.com\/2018\/3\/22\/17131004\/cloud-act-congress-omnibus-passed-mlat Accessed:2019-05--14.  Russell Brandom and Colin Lecher. 2018. House passes controversial legislationgiving the US more access to overseas data. (2018). https:\/\/www.theverge.com\/2018\/3\/22\/17131004\/cloud-act-congress-omnibus-passed-mlat Accessed:2019-05--14."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"crossref","unstructured":"Robert Buhren. 2019. Repository containing supplemental data and results.(2019). https:\/\/github.com\/RobertBuhren\/Insecure-Until-Proven-Updated-Analyzing-AMD-SEV-s-Remote-Attestation Accessed: 2019-08-01.  Robert Buhren. 2019. Repository containing supplemental data and results.(2019). https:\/\/github.com\/RobertBuhren\/Insecure-Until-Proven-Updated-Analyzing-AMD-SEV-s-Remote-Attestation Accessed: 2019-08-01.","DOI":"10.1145\/3319535.3354216"},{"key":"e_1_3_2_2_10_1","unstructured":"Code Rush. 2013. Flashing modified AMIAptio UEFI using AFU. https:\/\/www.win-raid.com\/t286f16-Guide-Deprecated-Flashing-modified-AMI-Aptio-UEFI-using-AFU.html Accessed: 2019-04--18.  Code Rush. 2013. Flashing modified AMIAptio UEFI using AFU. https:\/\/www.win-raid.com\/t286f16-Guide-Deprecated-Flashing-modified-AMI-Aptio-UEFI-using-AFU.html Accessed: 2019-04--18."},{"key":"e_1_3_2_2_11_1","volume-title":"andJesse Fang","author":"Du Zhao-Hui","year":"2017","unstructured":"Zhao-Hui Du , Zhiwei Ying , Zhenke Ma , Yufei Mai , Phoebe Wang , Jesse Liu , andJesse Fang . 2017 . Secure Encrypted Virtualization is Unsecure . arXiv:1712.05090 Zhao-Hui Du, Zhiwei Ying, Zhenke Ma, Yufei Mai, Phoebe Wang, Jesse Liu, andJesse Fang. 2017. Secure Encrypted Virtualization is Unsecure. arXiv:1712.05090"},{"key":"e_1_3_2_2_12_1","unstructured":"Unified EFI. 2017. Platform Initialization (PI) Specification. https:\/\/uefi.org\/sites\/default\/files\/resources\/PI_Spec_1_6.pdf Accessed: 2019-05-02.  Unified EFI. 2017. Platform Initialization (PI) Specification. https:\/\/uefi.org\/sites\/default\/files\/resources\/PI_Spec_1_6.pdf Accessed: 2019-05-02."},{"key":"e_1_3_2_2_13_1","unstructured":"Uri Farkas and CTS-Labs Ido Li On. 2019. AMDFlaws -- A Technical Deep Dive. https:\/\/msrnd-cdn-stor.azureedge.net\/bluehat\/bluehatil\/2019\/assets\/doc\/The%20AMDFlaws%20Story%20Technical%20Deep%20Dive.pdf Accessed: 2019-05-06.  Uri Farkas and CTS-Labs Ido Li On. 2019. AMDFlaws -- A Technical Deep Dive. https:\/\/msrnd-cdn-stor.azureedge.net\/bluehat\/bluehatil\/2019\/assets\/doc\/The%20AMDFlaws%20Story%20Technical%20Deep%20Dive.pdf Accessed: 2019-05-06."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1186\/1869-0238-4-5"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3050748.3050763"},{"key":"e_1_3_2_2_16_1","volume-title":"Trusted Ex-ecution Engine and Intel\u00aeActive Management Technology","author":"Intel Security Center","year":"2018","unstructured":"Intel Security Center . 2019. Intel CSME , Server Platform Services , Trusted Ex-ecution Engine and Intel\u00aeActive Management Technology 2018 .4 QSR Advisory. https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00185.html. Accessed : 2019-05-06. Intel Security Center. 2019. Intel CSME, Server Platform Services, Trusted Ex-ecution Engine and Intel\u00aeActive Management Technology 2018.4 QSR Advisory. https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00185.html. Accessed: 2019-05-06."},{"key":"e_1_3_2_2_17_1","unstructured":"Intel Security Center. 2019. Intel Firmware 2018.4 QSR Advisory. https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00191.html. Accessed: 2019-05-06.  Intel Security Center. 2019. Intel Firmware 2018.4 QSR Advisory. https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00191.html. Accessed: 2019-05-06."},{"key":"e_1_3_2_2_18_1","volume-title":"2011 44th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 272--283","author":"Jin S.","unstructured":"S. Jin , J. Ahn , S. Cha , and J. Huh . 2011. Architectural support for secure virtualization under a vulnerable hypervisor . In 2011 44th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 272--283 . S. Jin, J. Ahn, S. Cha, and J. Huh. 2011. Architectural support for secure virtualization under a vulnerable hypervisor. In 2011 44th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 272--283."},{"key":"e_1_3_2_2_19_1","volume-title":"The InsiderThreat in Cloud Computing","author":"Kandias Miltiadis","unstructured":"Miltiadis Kandias , Nikos Virvilis , and Dimitris Gritzalis . 2013. The InsiderThreat in Cloud Computing . InCritical Information Infrastructure Security, Sandro Bologna, Bernhard H\u00e4mmerli, Dimitris Gritzalis, and Stephen Wolthusen (Eds.). Springer Berlin Heidelberg , Berlin, Heidelberg , 93--103. Miltiadis Kandias, Nikos Virvilis, and Dimitris Gritzalis. 2013. The InsiderThreat in Cloud Computing. InCritical Information Infrastructure Security, Sandro Bologna, Bernhard H\u00e4mmerli, Dimitris Gritzalis, and Stephen Wolthusen (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 93--103."},{"key":"e_1_3_2_2_20_1","unstructured":"David Kaplan. 2017. Protecting VM Register State with SEV-ES. https:\/\/www.amd.com\/system\/files\/TechDocs\/Protecting%20VM%20Register%20State%20with%20SEV-ES.pdf Accessed: 2019-05-06.  David Kaplan. 2017. Protecting VM Register State with SEV-ES. https:\/\/www.amd.com\/system\/files\/TechDocs\/Protecting%20VM%20Register%20State%20with%20SEV-ES.pdf Accessed: 2019-05-06."},{"key":"e_1_3_2_2_21_1","unstructured":"CTS Labs. 2018. Severe Security Advisory on AMD Processors. https:\/\/safefirmware.com\/amdflaws_whitepaper.pdf Accessed: 2019-05-06.  CTS Labs. 2018. Severe Security Advisory on AMD Processors. https:\/\/safefirmware.com\/amdflaws_whitepaper.pdf Accessed: 2019-05-06."},{"key":"e_1_3_2_2_22_1","unstructured":"Thomas Lendacky and Gary Hook. 2016. ccp-dev.h.https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/stable\/linux.git\/tree\/drivers\/crypto\/ccp\/ccp-dev.h?h=v5.0.12#n402 Accessed: 2019-05-04.  Thomas Lendacky and Gary Hook. 2016. ccp-dev.h.https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/stable\/linux.git\/tree\/drivers\/crypto\/ccp\/ccp-dev.h?h=v5.0.12#n402 Accessed: 2019-05-04."},{"key":"#cr-split#-e_1_3_2_2_23_1.1","doi-asserted-by":"crossref","unstructured":"Jonathan M. McCune Bryan Parno Adrian Perrig Michael Reiter and Hiroshi Isozaki. 2008. Flicker: an execution infrastructure for TCB minimization. EuroSys'08 - Proceedings of the EuroSys 2008 Conference 42 315--328. https:\/\/doi.org\/10.1145\/1352592.1352625 10.1145\/1352592.1352625","DOI":"10.1145\/1357010.1352625"},{"key":"#cr-split#-e_1_3_2_2_23_1.2","doi-asserted-by":"crossref","unstructured":"Jonathan M. McCune Bryan Parno Adrian Perrig Michael Reiter and Hiroshi Isozaki. 2008. Flicker: an execution infrastructure for TCB minimization. EuroSys'08 - Proceedings of the EuroSys 2008 Conference 42 315--328. https:\/\/doi.org\/10.1145\/1352592.1352625","DOI":"10.1145\/1357010.1352625"},{"key":"e_1_3_2_2_24_1","unstructured":"Mark Papermaste. 2018. Initial AMD Technical Assessment of CTS Labs Research. https:\/\/community.amd.com\/community\/amd-corporate\/blog\/2018\/03\/21\/initial-amd-technical-assessment-of-cts-labs-research. Accessed: 2019-05--10.  Mark Papermaste. 2018. Initial AMD Technical Assessment of CTS Labs Research. https:\/\/community.amd.com\/community\/amd-corporate\/blog\/2018\/03\/21\/initial-amd-technical-assessment-of-cts-labs-research. Accessed: 2019-05--10."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3193111.3193112"},{"key":"e_1_3_2_2_26_1","unstructured":"Coreboot Project. 2014. PspDirectory.h. https:\/\/github.com\/coreboot\/coreboot\/blob\/master\/src\/vendorcode\/amd\/pi\/00660F01\/Proc\/Psp\/PspBaseLib\/PspDirectory.h Accessed: 2019-04-03.  Coreboot Project. 2014. PspDirectory.h. https:\/\/github.com\/coreboot\/coreboot\/blob\/master\/src\/vendorcode\/amd\/pi\/00660F01\/Proc\/Psp\/PspBaseLib\/PspDirectory.h Accessed: 2019-04-03."},{"key":"e_1_3_2_2_27_1","volume-title":"andHerbert Bos","author":"Razavi Kaveh","year":"2016","unstructured":"Kaveh Razavi , Ben Gras , Erik Bosman , Bart Preneel , Cristiano Giuffrida , andHerbert Bos . 2016 . Flip feng shui: Hammering a needle in the software stack. In 25th {USENIX}Security Symposium ( {USENIX}Security 16). 1--18. Kaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel, Cristiano Giuffrida, andHerbert Bos. 2016. Flip feng shui: Hammering a needle in the software stack. In 25th {USENIX}Security Symposium ({USENIX}Security 16). 1--18."},{"key":"e_1_3_2_2_28_1","unstructured":"Supermicro. [n. d.]. Supermicro Update Manager. https:\/\/www.supermicro.com\/solutions\/SMS_SUM.cfm Accessed: 2019-04--26.  Supermicro. [n. d.]. Supermicro Update Manager. https:\/\/www.supermicro.com\/solutions\/SMS_SUM.cfm Accessed: 2019-04--26."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/2248487.2151022"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.163"},{"key":"e_1_3_2_2_31_1","unstructured":"Stefan Weil. 2019. QEMU version 4.0.93 User Documentation. (2019). https:\/\/qemu.weilnetz.de\/doc\/qemu-doc.html#Commands Accessed: 2019-08-01.  Stefan Weil. 2019. QEMU version 4.0.93 User Documentation. (2019). https:\/\/qemu.weilnetz.de\/doc\/qemu-doc.html#Commands Accessed: 2019-08-01."},{"key":"e_1_3_2_2_32_1","unstructured":"Christian Werling and Robert Buhren. 2019. PSPTool: Display extract andmanipulate PSP firmware inside UEFI images. (2019).https:\/\/github.com\/cwerling\/psptool Accessed: 2019-08-01.  Christian Werling and Robert Buhren. 2019. PSPTool: Display extract andmanipulate PSP firmware inside UEFI images. (2019).https:\/\/github.com\/cwerling\/psptool Accessed: 2019-08-01."},{"key":"e_1_3_2_2_33_1","volume-title":"Comprehensive VM Protection Against Untrusted Hypervisor Through Retrofitted AMD MemoryEncryption. In 2018 IEEE International Symposium on High Performance Computer Architecture (HPCA). 441--453","author":"Wu Y.","year":"2018","unstructured":"Y. Wu , Y. Liu , R. Liu , H. Chen , B. Zang , and H. Guan . 2018 . Comprehensive VM Protection Against Untrusted Hypervisor Through Retrofitted AMD MemoryEncryption. In 2018 IEEE International Symposium on High Performance Computer Architecture (HPCA). 441--453 . https:\/\/doi.org\/10.1109\/HPCA. 2018 .00045 10.1109\/HPCA.2018.00045 Y. Wu, Y. Liu, R. Liu, H. Chen, B. Zang, and H. Guan. 2018. Comprehensive VM Protection Against Untrusted Hypervisor Through Retrofitted AMD MemoryEncryption. In 2018 IEEE International Symposium on High Performance Computer Architecture (HPCA). 441--453. https:\/\/doi.org\/10.1109\/HPCA.2018.00045"},{"key":"e_1_3_2_2_34_1","volume-title":"2013 IEEE 19th International Symposium on High Performance Computer Architecture (HPCA).246--257","author":"Xia Y.","year":"2013","unstructured":"Y. Xia , Y. Liu , and H. Chen . 2013. Architecture support for guest-transparentVM protection from untrusted hypervisor and physical attacks . In 2013 IEEE 19th International Symposium on High Performance Computer Architecture (HPCA).246--257 . https:\/\/doi.org\/10.1109\/HPCA. 2013 .6522323 10.1109\/HPCA.2013.6522323 Y. Xia, Y. Liu, and H. Chen. 2013. Architecture support for guest-transparentVM protection from untrusted hypervisor and physical attacks. In 2013 IEEE 19th International Symposium on High Performance Computer Architecture (HPCA).246--257. https:\/\/doi.org\/10.1109\/HPCA.2013.6522323"},{"key":"e_1_3_2_2_35_1","volume-title":"L3 cache side-channel attack. In 23rd {USENIX}Security Symposium({USENIX}Security 14). 719--732.","author":"Yarom Yuval","unstructured":"Yuval Yarom and Katrina Falkner . 2014. FLUSH+ RELOAD : a high resolution, low noise , L3 cache side-channel attack. In 23rd {USENIX}Security Symposium({USENIX}Security 14). 719--732. Yuval Yarom and Katrina Falkner. 2014. FLUSH+ RELOAD: a high resolution, low noise, L3 cache side-channel attack. In 23rd {USENIX}Security Symposium({USENIX}Security 14). 719--732."},{"key":"e_1_3_2_2_36_1","volume-title":"SOSP'11 - Proceedings of the 23rd ACM Symposium on Operating Systems Principles, 203--216","author":"Zhang Fengzhe","year":"2011","unstructured":"Fengzhe Zhang , Jin Chen , Haibo Chen , and Binyu Zang . 2011 . Cloud Visor: Retrofitting protection of virtual machines in multi-tenant cloud with nested virtualization . SOSP'11 - Proceedings of the 23rd ACM Symposium on Operating Systems Principles, 203--216 . https:\/\/doi.org\/10.1145\/2043556.2043576 10.1145\/2043556.2043576 Fengzhe Zhang, Jin Chen, Haibo Chen, and Binyu Zang. 2011. Cloud Visor: Retrofitting protection of virtual machines in multi-tenant cloud with nested virtualization. SOSP'11 - Proceedings of the 23rd ACM Symposium on Operating Systems Principles, 203--216. https:\/\/doi.org\/10.1145\/2043556.2043576"}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354216","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3354216","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:24:03Z","timestamp":1750202643000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354216"}},"subtitle":["Analyzing AMD SEV's Remote Attestation"],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":37,"alternative-id":["10.1145\/3319535.3354216","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3354216","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}