Tamper evidence and tamper resistance
Tamper evidence is an external indication that someone has tried to compromise a device's physical security; tamper resistance makes such attempts difficult, costly or both; and tamper response is an automatic action, at minimum erasing plaintext keys, taken when tampering is detected 1 2.
The US standard for cryptographic modules, FIPS 140-2, since superseded by FIPS 140-3, layers these properties 1:
- Level 2 requires evidence of tampering, such as tamper-evident coatings or seals, or pick-resistant locks on covers and doors 1.
- Level 3 adds detection and response circuitry that zeroizes plaintext secret and private keys when covers or doors are opened 1.
- Level 4 requires a complete envelope of protection intended to detect and respond to all unauthorized attempts at physical access 1.
These properties matter because the prover usually controls the hardware: Shavit notes that unlimited physical access could undermine a chip's attestation, and relies on inspections to find hardware attacks that damage chips in ways that are hard to hide 3. The flexHEG proposal houses its guarantee processor in a secure enclosure that provides physical tamper protection (Hardware-enabled guarantees (flexHEG) and guarantee processors) 4. One verification plan names tamper-evident enclosures among "promising future directions and existing methods" for physical security of AI computing infrastructure 5. Protecting verifier equipment in the prover's facility, such as network taps and recomputation servers, is the subject of tamper evidence for verifier devices. Seals can be defeated with simple methods: a 1996 Los Alamos study demonstrated low-tech defeats for each of the 94 passive and electronic seals it examined, with a mean defeat time of 4.3 minutes for one practised person 6.
Related
Used in
- R1Chip registries and manufacturing records
- R1Hardware-enabled guarantees (flexHEG) and guarantee processors
- R2Tamper evidence for verifier devices
- R3TEE remote attestation for AI workloads⚠
- R1Low-trust AI compute verification system overview
- R1RAND secure inference data center (SIDC) design
- Chips are where they are declared to be
Sources
- ANational Institute of Standards and Technology (2001). Security Requirements for Cryptographic Modules (FIPS PUB 140-2). National Institute of Standards and Technology. Source recordSupports: definitions of tamper evidence, tamper detection and tamper response; physical security Levels 2–4; superseded by FIPS 140-3 · §2.1 Glossary; §4.5; CSRC status page
- ANational Institute of Standards and Technology (2026). NIST Computer Security Resource Center (CSRC) Glossary. NIST Computer Security Resource Center. Source recordSupports: tamper resistant: makes alterations difficult, costly or both (definition written for data) · term: tamper_resistant (NISTIR 8202)
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: unlimited physical access can undermine attestation; inspections detect hard-to-hide hardware attacks · §3.1
- BJ. Petrie et al. (2025). Flexible Hardware-Enabled Guarantees for AI Compute. arXiv. Source recordSupports: flexHEG secure enclosure providing physical tamper protection · abstract
- CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: tamper-evident enclosures named among promising future directions and existing methods for physical security of AI computing infrastructure · physical security measures
- BR. G. Johnston & A. R. E. Garcia (1996). Physical Security and Tamper-Indicating Devices. Los Alamos National Laboratory, LA-UR-96-3827. Source recordSupports: 94 seals studied; 1–3 low-tech defeats demonstrated for each, 132 in total; mean defeat time 4.3 minutes by one practised person · abstract; results