Researchers at Durham University have helped uncover a low-cost hardware attack that could put sensitive information stored in cloud-computing systems at risk.
The international research team includes Professor David Oswald from Durham University’s Department of Computer Science. Led by Belgian university KU Leuven, the team identified weaknesses in servers used for “confidential computing” services, which are designed to protect data even from the companies operating the cloud infrastructure.
How the DDRop attack works
The researchers developed and tested a device called DDRop. The university describes it as a small, low-cost piece of hardware that can be physically attached to a server during a brief, one-time visit.
Durham’s research team contributed to designing the device and assessing how effective it was against Intel TDX systems. Once installed, DDRop can interfere with the way a server processes information, potentially allowing an attacker to bypass key security protections.
Rather than attempting to read encrypted information directly, the attack interferes with the process of saving new data to memory. That could make it difficult to detect because the affected information remains encrypted and appears legitimate to the system.
By exploiting the weakness, an attacker could cause a protected virtual machine to continue using older, manipulated data without recognising that anything had changed. A virtual machine is a software-based computer environment commonly used to run workloads on shared cloud infrastructure.
Why the finding matters
Confidential computing is intended to let organisations process sensitive information in the cloud without having to place complete trust in their cloud provider. It is used for applications involving personal data, financial information and business-sensitive workloads, as well as protected artificial-intelligence workloads.
The researchers found that DDRop could affect confidential-computing technologies on both Intel and AMD platforms. In some cases, the attack could also undermine the mechanisms used to demonstrate that a virtual machine is secure and trustworthy.
The findings raise wider concerns as organisations increasingly use cloud services to process and store sensitive information. They also highlight the importance of strengthening hardware-level security protections, rather than relying only on encryption and software controls.
Industry response and next steps
The research has already contributed to a co-ordinated industry response. The work informed public security advisories issued by Intel and AMD and helped shape discussions about future memory-encryption designs and hardware protections.
Durham University said further information is available through Professor Oswald, the DDRop project and the Department of Computer Science. The department is ranked eighth in the UK in the Complete University Guide 2027, according to the university.