Computer Architectures

Physical Attacks on Confidential Computing and Trusted Execution

Durham University

Not stated

Location
Durham, United Kingdom, United Kingdom
Funding
Self-Funded PhD Students Only
Application deadline
Year-round applications

About the project

About the Project The project: The research group of Prof David Oswald at Durham University, UK, is looking for PhD student(s) to work on physical attacks on confidential computing and trusted execution environments (TEEs), including those extending to GPUs. Technologies such as Intel SGX and TDX, AMD SEV-SNP, and Arm CCA are designed to protect sensitive workloads even from a compromised operating system, hypervisor, or cloud provider. The project will investigate how physical effects can undermine these guarantees, for example through fault injection, side-channel analysis, or hardware interposers on memory and other buses. The student will also have the opportunity to explore countermeasures and ways to make future TEE designs more robust. The group has a long track record of collaborative publications at top-tier security venues such as IEEE S&P, USENIX Security, and ACM CCS in this area. Examples include: DDRop (ACM CCS 2026, https://ddropattack.eu/ ): a low-cost DDR5 interposer that silently drops memory writes, breaking the integrity of Intel TDX/SGX, and AMD SEV-SNP. BadRAM (IEEE S&P 2025, https://badram.eu/ ): manipulating the SPD chip of DRAM modules to create memory aliases that bypass AMD SEV-SNP protections. PLATYPUS (IEEE S&P 2021, https://platypusattack.com/ ): power side-channel attacks via software-accessible energy interfaces, recovering secrets from Intel SGX enclaves. Plundervolt (IEEE S&P 2020, https://plundervolt.com/ ): software-based undervolting to inject faults into Intel SGX enclaves. Depending on the topic, some of our industry partners may also contribute time to the project, giving the student the opportunity to work with them directly. Durham provides a yearly allowance for a personal laptop and travel funding to attend conferences or summer schools. The group has access to a fully equipped security lab. Students will also have the chance to work as demonstrators, which is paid separately. Eligibility: Applicants from most countries are welcome. Candidates should have a good background in systems-level programming (e.g. C, C++, Assembly, and/or Rust) and/or embedded systems and hardware. Experience with electronics, PCB design, FPGAs, or lab equipment such as oscilloscopes is great but not required. We expect a first-class undergraduate or postgraduate degree in a relevant subject (e.g. computer science or electrical engineering). Funding: We welcome strong self-funded applicants and candidates who wish to apply through one of Durham's competitive funding routes ( https://www.durham.ac.uk/departments/academic/science/research-excellence/science-doctoral-training/pgr-funding-routes/ ), for example the SCOPE programme with application deadline in December 2026. For UK home students, additional funding routes may be available. We also welcome part-time industrial students. How to apply: Please send your CV and a brief statement of your research interests and relevant experience to Prof David Oswald ( david.f.oswald@durham.ac.uk ). Informal enquiries are welcome, but note the constraints on funding outlined above.

Research areas

ComputerArchitecturesCyberSecurityPhysicalAttacksonConfidentialComputingandTrustedExecution