M-0018 / Accounting & provenance

Chip location verification

Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.

R1 ProposedSource reviewed 2026-09-25

01 / The mechanism and its boundary

What the technique establishes

Location verification aims to show that an AI chip is where its owner says, or at least not in a restricted region. Trusted "landmark" servers at known places exchange cryptographic challenges with the chip, which signs its replies with a key unique to it. Signals cannot travel faster than light, so a fast reply caps the chip's distance from each landmark. A slow reply does not show that a chip is far away, because internet routes add delay. The designers estimate under $1 million for firmware and software, plus $2.5–12.5 million a year for 100–500 landmarks. Ulyssean describes an H100 prototype on its demonstration website. NVIDIA is reportedly developing a version that uses its own servers. The main weaknesses are extraction of a chip's key, manipulated network delay and compromised landmarks. The check says nothing about chips in transit or how they are used.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
Existing hardware features
Prover cooperation
Required
Confidentiality
Preserving
Category
Accounting & provenance
Technical detail and cited results

Brass and Aarne give the distance bound as D = T × 200, where D is the maximum distance in km and T the one-way delay in ms, taking about 200,000 km/s as the speed of light in optical fibre S-1400. In their case study, a 4.665 ms one-way delay bounds the chip to within 933 km of the landmark S-1400. They note that a limit based on the vacuum speed of light, about 300,000 km/s, covers worst cases such as out-of-band radio or satellite links and cannot be beaten physically S-1400. The cost is more false negatives: honest chips near a landmark may not reply fast enough, which the authors' moderate experimentation suggested could happen "perhaps even in more than 50% of cases" S-1400. Calibrating landmark delay factors might reduce this rate but needs further work S-1400. Recent geolocation algorithms reach a median error under 10 km given excellent landmark distribution and coverage; delay-based methods in general give about 10 km to 1,000 km, depending on the algorithm S-1400.

The Sovereignty Certificates draft (Lucid sovereignty (location) certificates) casts the protocol as a RATS (RFC 9334) attestation flow with Entity Attestation Token (RFC 9711) claims S-1404. The verifier issues a nonce and a signed directory of anchors. The attester probes anchors from inside a TEE, and each anchor returns a signed receipt with a high-precision timestamp and a nonce. The verifier then runs a deterministic multilateration to compute a feasible region S-1404. Per-cycle ephemeral keys are bound into the hardware root of trust's attestation quote to prevent replay S-1404.

Tee and Happel propose identifying a GPU by a hardware fingerprint instead of an extractable on-chip key. Their proof of concept races atomic operations across streaming multiprocessors S-1403. Over 480 runs on 24 NVIDIA H200 GPUs rented from a cloud provider, re-identification accuracy was 98.8% from a single run and 100% from paired runs, with each run taking about 2.9 s S-1403. The authors state that the fingerprint still has to be validated on more GPUs, shown to be stable over time and conditions, and shown to resist an adversary who runs the function faster or simulates the GPU S-1403.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R1 Proposed

Assessed use: bounding how far a chip is from trusted landmark servers when checked

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

The design is public and detailed, but the one reported prototype has a single published result, which cannot be checked.

  • R1 met: Brass and Aarne give a full design with adversary classes, attacks and cost estimates S-1400. Aarne, Fist and Withers describe landmark-based verification S-0056, and Avellar and Grunewald set out how a regulator could run it S-1402.
  • R2 not met: the IAPS brief reports a rudimentary H100 prototype and one result, a Singapore landmark bounding a chip in Singapore to within 300 miles S-1401. Ulyssean describes an H100 and AMD SEV-SNP setup with 38 cloud landmarks and a timing method, but publishes no code or systematic end-to-end location results or error rates S-3570. The single result cannot be reproduced from the available information. NVIDIA's delay-based scheme, reported by Avellar and Grunewald S-1402, has no published design or results. Tee and Happel publish reproducible results for GPU fingerprinting, which is a component, not end-to-end location verification S-1403. The most mature implementation for this use, the draft Sovereignty Certificates specification (Lucid sovereignty (location) certificates), is itself R1 S-1404.

Confidence is medium: the demo describes its setup and timing method, but the code is not public and its single location result lacks the data needed for independent reproduction S-3570 S-1401.

Evidence needed for the next level

  • A public implementation, or reproducible end-to-end results, on data-centre accelerators with a real landmark network.

  • Published measurements of false-positive and false-negative rates under realistic internet routing.

  • An evaluation against a stated adversary covering delay manipulation, faster network paths, landmark compromise and key extraction.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / theoretical argument

Extracting a chip's key lets another device answer for it

Ping-based protocols rely on cryptographic keys stored on the chip. Tee and Happel argue that an adversary with physical access could extract these keys and so compromise location verification S-1403. They propose GPU fingerprints as a mitigation, so far tested on 24 GPUs S-1403. Brass and Aarne assume the keys are stored securely, for example in a TPM S-1400.

S-1403S-1400

significant / open / demonstrated attack

Added delay can shift an estimated position

Brass and Aarne cite internet-geolocation research in which artificially increased round-trip times moved the estimated location by up to 1,000 km, with a 74% chance of avoiding detection S-1400. Avellar and Grunewald list inflated ping times from circuitous routing as an evasion route S-1402. Added delay only loosens a distance bound, and Brass and Aarne propose a hard time limit as the counter: a chip that replies too slowly cannot be ruled out of a restricted location S-1400.

S-1400S-1402

significant / open / theoretical argument

Faster-than-assumed network paths

Brass and Aarne list dark fibre and other private high-speed interconnects as ways to lower measured delays artificially. They judge that leasing dark fibre would probably not be a considerable challenge for covertly or openly adversarial actors S-1400. Avellar and Grunewald note that this can make a chip appear to be somewhere else entirely S-1402. A limit set at the vacuum speed of light cannot be beaten, but it makes honest chips fail more often S-1400.

S-1400S-1402

significant / open / theoretical argument

Compromised landmarks can falsify measurements

A party that controls landmark servers can report false timing. Brass and Aarne cite research in which manipulating a third of the landmarks shifted the estimated location by about 700 km S-1400. Avellar and Grunewald note that compromised landmarks let adversaries spoof travel-time measurements directly S-1402. The draft specification asks verifiers to require anchors in diverse places, run by several independent operators S-1404.

S-1400S-1402S-1404

What still blocks use or stronger assurance

  1. No public code or reproducible end-to-end location results are available for the reported H100 prototype.

    S-1401S-3570
  2. Per-chip keys must be provisioned and protected against extraction; hardware-integrated, tamper-resistant versions still need R&D.

    S-1400S-1403S-0007
  3. The time limit forces a trade-off: a limit at the speed of light in fibre can be beaten by faster links, while one at the vacuum speed of light makes honest chips fail often.

    S-1400
  4. A trusted landmark network must be built and secured, and who should operate it, under what oversight, is unsettled.

    S-1400S-1402

Connections in the research map

Depends on

Complementary techniques

Concepts used

Organizations and developers

Implementations

The Consortium’s case files

Related editorial reviews use the Consortium’s own descriptive scores and review dates. Their scores are separate from the atlas readiness rubric.

LV-01 / LocationGeography by ping timeRead case file ↗

Sources and provenance

  1. S-1400 / Tier B

    Location Verification for AI Chips ↗

    A. Brass, O. Aarne · 2024 · Institute for AI Policy and Strategy

    Supports: design, problem framing, adversary classes, distance bound, fibre versus vacuum speed limits and false negatives, precision, attacks and hard time limits, costs, key storage

    Locator: Detailed Summary; Solution requirements and threat models; Delay-based methods sections; Three adversarial strategies; Proposed Solution Requirements

    Version and catalogue details
  2. S-1401 / Tier B

    Location Verification for AI Chips (issue brief) ↗

    A. Brass · 2025 · Institute for AI Policy and Strategy

    Supports: reported H100 prototype (builder not named) and its single Singapore result; summary of Brass and Aarne's 2024 report; development and landmark network cost estimates

    Locator: issue brief, pp. 1-2

    Version and catalogue details
  3. S-3570 / Tier B

    Ping-based Location ↗

    Ulyssean · 2025 · Ulyssean demonstration site

    Supports: Ulyssean's account of the H100 and AMD SEV-SNP demonstration, 38 landmarks, timing method, code status

    Locator: Technical details, public JavaScript asset

    Version and catalogue details
  4. S-1402 / Tier B

    Near-Term Verification Methods for AI Chip Exports ↗

    B. Avellar, E. Grunewald · 2026 · Institute for AI Policy and Strategy

    Supports: regulator workflow; maturity and effectiveness ratings; costs; transit gap; evasion and landmark compromise; NVIDIA confirmed developing delay-based verification with NVIDIA-run servers (citing Reuters, December 2025)

    Locator: §1.6; Executive Summary

    Version and catalogue details
  5. S-1413 / Tier B

    Opt-In NVIDIA Software Enables Data Center Fleet Management ↗

    NVIDIA · 2025 · NVIDIA Blog

    Supports: NVIDIA's opt-in, customer-installed fleet-management service with read-only telemetry and an agent to be open-sourced; NVIDIA's statement that its GPUs lack hardware tracking, kill switches and backdoors (provider self-description)

    Locator: blog post

    Version and catalogue details
  6. S-3180 / Tier B

    Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization ↗

    C. Shrauder, G. Frederick · 2026 · NVIDIA Technical Blog

    Supports: Fleet Intelligence (May 2026): read-only agent released as open source; telemetry and GPU integrity attestation, no location check described (provider self-description)

    Locator: blog post

    Version and catalogue details
  7. S-0056 / Tier B

    Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing ↗

    O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security

    Supports: speed-of-light upper bound; landmark-server illustration; hundreds of landmarks

    Locator: 'Location Verification', p. 11

    Version and catalogue details
  8. S-0007 / Tier B

    Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification ↗

    S. Ansari · 2026 · arXiv

    Supports: feasibility rating; physical attacks on embedded mechanisms

    Locator: §3.1 (M6); §4.3

    Version and catalogue details
  9. S-1403 / Tier B

    GPU Fingerprinting for Location Verification ↗

    W. Tee, J. Happel · 2026 · arXiv

    Supports: key-extraction weakness; fingerprinting proof of concept and its stated limitations

    Locator: Abstract; threat model; results; limitations

    Version and catalogue details
  10. S-1404 / Tier B

    Sovereignty Certificates: draft specification, version 0.1.0 ↗

    Sovereignty Certificates Working Group · 2025 · GitHub (Lucid-Computing/sovereignty-certificate-specification)

    Supports: draft protocol structure, threat model, anchor diversity and tunnelling check

    Locator: §0.3, §4.2, §6.3, §8.1, §8.3.3, §8.3.4

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review