메뉴
BL
Ars Technica 43일 전

AMD, 일반 CPU 메모리 암호화 기능(TSME) 은밀히 제거해 논란

IMP
7/10
핵심 요약

AMD가 최신 펌웨어(AGESA) 업데이트를 통해 소비자용 라이젠(Ryzen) CPU의 메모리 암호화 기능인 TSME를 사전 공지 없이 제거하여 사용자들의 비판을 받고 있습니다. 보안에 민감한 리눅스 사용자의 추적 끝에 이 사실이 알려졌으며, AMD는 해당 보안 기능이 이제 기업용 PRO 라인업 전용이라는 입장을 내놓았습니다. 이 조치가 고의적인 기능 제한인지, 단순한 펌웨어 버그인지에 대해 IT 커뮤니티의 논쟁이 진행 중입니다.

번역된 본문

10년 전, AMD는 자사의 최고급 CPU에 콜드 부팅 공격이나 연결된 메모리 칩에서 민감한 데이터를 빼내는 물리적 해킹으로부터 시스템을 보호하기 위한 보안 기능을 추가했다. TSME(Transparent Secure Memory Encryption)의 약자인 이 기능은 메모리에 저장된 모든 데이터를 암호화하여 물리적 공격자가 데이터를 볼 수 없게 만든다. 시간이 지나면서 AMD는 Pro 버전보다 저렴한 라이젠 소비자용 칩을 포함한 저가형 프로세서에도 TSME를 추가했다. 지난 수년 동안 이러한 저가형 칩의 사용자들은 이 추가된 보안 기능에 익숙해져 왔다.

그러나 최근 사전 경고나 공지 없이, 이 저가형 라인의 AMD 칩은 갑자기 이 보안 기능을 삭제했다. 더구나 이 변화는 윈도우 머신에서는 전혀 감지할 수 없었고, 리눅스를 사용할 때도 상당한 기술적 노력이 필요했다.

사라진 기능 AMD는 아직까지도 이 CPU들에서 TSME가 작동했던 이유나 심지어 이러한 변화를 확인해 주지 않고 있다. AMD는 이메일로 보낸 질문에 대해 TSME가 "AMD PRO 기술의 일환으로 PRO CPU에만 적용되는 보안 기능"이라고 말하는 것 외에는 답변을 거부했다. 이 성명은 해당 칩 제조사가 이러한 제한을 명시적으로 공개한 것으로 알려진 첫 번째 사례다.

지난 4월, 자신을 '프라이버시에 민감한 리눅스 취미 사용자'라고 소개한 벤 킬패트릭(Ben Kilpatrick)은 Zen 5 아키텍처 기반의 라이젠 7 9700X가 탑재된 머신에 새로운 운영체제를 설치하고 있었다. 모든 보안 보호 기능이 활성화되어 있는지 확인하기 위해 그는 펌웨어 및 하드웨어 보안 구성을 평가하는 감사 기능인 호스트 보안 ID(HSI)를 실행했다. 놀랍게도 HSI는 TSME가 더 이상 지원되지 않는다는 것을 보여주었고, 아래 스크린샷 하단 근처에 '암호화된 RAM: 지원되지 않음(encrypted RAM: not supported)'이라는 줄이 표시되었다. 몇 줄 아래에서 HSI는 이전에는 TSME가 '암호화됨(encrypted)'으로 표시되었다고 나타냈다. 이 사실은 킬패트릭을 당혹스럽게 했다. 왜냐하면 그는 그동안 BIOS 설정에서 항상 TSME를 활성화해 두었기 때문이다.

이 일로 인해 킬패트릭은 무슨 일이 일어났는지 알아내기 위해 수개월에 걸친 조사를 시작했다. 그의 메인보드 제조사인 MSI의 지원 및 엔지니어링 팀에 문의를 보낸 후, 그는 마침내 회사 엔지니어들이 테스트를 실행하도록 설득했다. 그들은 MSI 및 기가바이트 메인보드에서 실행되는 소비자용 버전의 라이젠이 부팅 과정에서 구형 펌웨어 버전(오직 AMD AGESA를 통해서만 제공됨)을 사용할 때만 TSME가 활성화된다는 것을 발견했다. 대신 최신 AGESA, 특히 버전 1.2.7.0의 펌웨어가 실행될 때 TSME는 '지원되지 않음'으로 표시되었다. 반면 Pro 버전의 라이젠 CPU는 두 가지 메인보드 및 AGESA 버전 모두에서 TSME를 지원했다.

킬패트릭은 매체와의 인터뷰에서 "가장 큰 의문은 이것이 TSME를 PRO 칩으로 제한하려는 AMD의 의도적인 정책 결정인지, 아니면 AGESA 1.2.7.0에서 도입된 의도치 않은 기능 퇴화(regression)인지 여부"라고 말했다. 그는 이어서 말했다. "이러한 구분이 중요한 이유는, 만약 의도적인 정책이라면 AMD는 소비자용 하드웨어에서 작동 중인 기능을 제거하고 기업 고객으로 제한하기로 의식적인 결정을 내린 것입니다. 반면 우연한 기능 퇴화라면 AMD가 수정해야 할 펌웨어 버그입니다. 어느 쪽이든 칩셋의 하드웨어는 이를 지원할 능력이 있으며, 어느 쪽이든 변경은 AGESA에서 발생했고, 어느 쪽이든 AMD는 이에 대한 설명을 거부했습니다. 하지만 두 가지 시나리오는 실제로 무슨 일이 일어났는지에 대해 매우 다른 의미를 내포합니다."

조사의 일환으로, 킬패트릭은 AMD의 공개 엔지니어링 GitHub 저장소에 버그 보고서를 제출했다. 두 명의 AMD 엔지니어가 직접 응답에 나섰다. AMD 펠로우 소프트웨어 엔지니어인 톰 렌다키(Tom Lendacky)는 무엇이 이러한 변화를 일으켰는지 모르겠다고 답변했다. 그는 BIOS에서 이 옵션을 비활성화했다가 다시 활성화해 보라고 제안했다. "만약 그것이 작동하지 않는다면, BIOS 문제일 것으로 추측되므로 MSI에 연락하는 것이 좋을 것입니다." (바로 이 제안 때문에 킬패트릭은 MSI 엔지니어에게 앞서 언급된 테스트를 실행해 달라고 요청하게 되었다.) AMD 시니어 프린시펄 엔지니어인 마리오 리몬첼로(Mario Limonciello)...

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire contents stored in memory, making the data useless to physical attackers. Over time, AMD added TSME to lower-end processors, including the consumer version of its Ryzen chips, a CPU that costs less than the Pro version. Over the years, users of these lower-end chips have gotten used to the added security. Recently and without warning or notice, this lower-end line of AMD chips suddenly dropped the protection, and did so in a way that was impossible to detect on Windows machines and required a fair amount of technical work when using Linux. Now you see it, now you don’t AMD has yet to say why TSME worked on these CPUs, or even to confirm the change. AMD declined to answer questions sent by email other than to say TSME “is a security feature only applied to PRO CPUs as part of AMD PRO Technologies.” The statement is the first known time the chipmaker has explicitly made this restriction public. In April, Ben Kilpatrick, who describes himself as a “privacy-conscious Linux hobbyist,” was installing a new OS on his machine running a Ryzen 7 9700X from the Zen 5 architecture. To check that all security protections were enabled, he had his machine run Host Security ID (HSI), an auditing feature that evaluates the firmware and hardware security configurations. To his surprise, HSI showed TSME was no longer possible, as indicated by the “encrypted RAM: not supported” line near the bottom of the screenshot below. A few lines lower, the HSI indicates that previously, TSME had shown as “encrypted.” This made no sense to Kilpatrick because he had enabled TSME in his BIOS settings all along. This sent Kilpatrick into a monthslong investigation to figure out what had happened. After sending an inquiry to both the support and engineering teams at MSI, the manufacturer of his motherboard, he finally convinced company engineers to run tests. They found that consumer versions of Ryzen running on MSI and Gigabyte motherboards had TSME enabled when an older firmware version, available exclusively through the AMD Generic Encapsulated Software Architecture (AGESA), described here , was used during the boot process. When the firmware in a newer AGESA, specifically version 1.2.7.0, ran instead, TSME showed as “not supported.” Pro versions of the Ryzen CPU supported TSME across both motherboards and AGESA versions. “The big outstanding question is whether this is a deliberate policy decision by AMD to restrict TSME to PRO chips, or an unintentional regression that was introduced in AGESA 1.2.7.0,” Kilpatrick told Ars. He continued: The reason that distinction matters is that if it is deliberate policy, AMD made a conscious decision to remove a working feature from consumer hardware and restrict it to enterprise customers. If it is an accidental regression, it is a firmware bug that AMD should fix. Either way the silicon is capable, either way the change happened in AGESA, and either way AMD has declined to explain it. But the two scenarios imply very different things about exactly what happened. As part of his investigation, Killpatrick filed a bug report on AMD’s public engineering GitHub repository. Two AMD engineers engaged directly. Tom Lendacky, an AMD fellow software engineer, replied that he didn’t know what caused the change. He suggested disabling and then re-enabling the option in the BIOS. “If that doesn’t work, my guess would be that it is a BIOS issue and you would want to contact MSI,” (It was this suggestion that led Kilpatrick to prevail upon MSI engineers to run the tests mentioned earlier.) Mario Limonciello, AMD senior principal software engineer and maintainer of the fwupd version of HSI, then chimed in. He, too, suggested disabling and re-enabling the BIOS settings. “If it still doesn’t work; then yes please report it to your board vendor to debug,” he said. I have nothing more to share, AMD engineer says Six weeks later, Kilpatrick resumed the discussion. After getting the results of MSI’s investigations, he reported them to the AMD engineers. “MSI’s product marketing team has informed me that AMD officially communicated to MSI that TSME is exclusively supported on PRO series processors,” he wrote. “They [MSI support personnel] also conducted controlled testing on an Asus X870E motherboard with a Ryzen 9800X3D (consumer) and a Ryzen 9945 (PRO), finding tsme_status = 1 on the PRO processor and tsme_status = 0 on the consumer processor with the same board and BIOS.” A setting of 1 indicated TSME was enabled. A status of 0 meant it was off. Next, Kilpatrick turned the engineers’ attention to results from memory captures from the AMD Boot Loader. Typically abbreviated as ABL, it’s a component within AGESA that initializes the hardware prior to the OS loading. MSI’s engineering team found that a string indicating the status of TSME early in the boot process was never enabled. The memory capture showed that DfIsTsmeEnabled, an internal AGESA flag that controls whether TSME is activated during the firmware initialization process, showed that it was not turned on. The ABL memory dump comparisons returned different values depending on whether the Pro or consumer CPU version was used. The flag showed FALSE for consumer processors and TRUE for PRO or EPYC processors when TSME was enabled in the BIOS. “Their BIOS engineer also provided ABL dump comparisons showing DfIsTsmeEnabled returning FALSE for the 9800X3D regardless of whether TSME is set to AUTO or ENABLED in BIOS,” Kilpatrick reported, “while the 9945 returns TRUE when TSME is ENABLED.” Kilpatrick went on in the thread to remind Lendacky that in 2020 , the engineer had confirmed TSME was supported on a Ryzen 3700X (a consumer CPU). After more back-and-forth discussion, Kilpatrick asked bluntly: “is DfIsTsmeEnabled being set to FALSE on consumer SKUs a silicon-level limitation, or is it a firmware policy decision within AGESA? The distinction matters quite a bit from a user perspective, since one is fixed and the other is potentially changeable.” Limoncello promptly replied: “My apologies; but I don’t have any more information to share on this topic.” With that, the discussion and Kilpatrick’s inquiry were over. The Lendacky comment in 2020 Kilpatrick referred to came in this thread discussing encryption features available in AMD CPUs. Lendacky said that the Ryzen 3700x, a consumer CPU, “should support TSME.” In a 2025 comment in the same thread, the engineer followed up on his comment concerning the 3700x. “I recommend using TSME (Transparent SME), but it is a BIOS option that needs to be exposed by your BIOS provider,” Lendacky said in response to the question about the consumer chip. There’s no indication that AMD ever advertised or marketed TSME as being available in consumer CPUs. AMD has long said that a related memory protection, Secure Memory Encryption (SME), is available only in the Pro and Epyc CPU tiers. SME is OS-managed. It uses a single key and allows the OS to selectively encrypt individual memory pages. TSME is firmware-managed. It encrypts all RAM with no OS involvement. When active, it provides protection against physical attacks, including cold boot exploits, DRAM interface snooping, and memory module removal. It activates silently when enabled in the BIOS, making it the more practically useful of the two protections. AMD engineers’ comments, such as those mentioned above, and the years of TSME working just fine in the lower-cost tier processors, have understandably conditioned Kilpatrick and other users to reasonably regard it as an expected part of the chip package. AMD quietly re