01 / The mechanism and its boundary
What the technique establishes
Location verification aims to show that an AI chip is where its owner says, or at least not in a restricted region. Trusted "landmark" servers at known places exchange cryptographic challenges with the chip, which signs its replies with a key unique to it. Signals cannot travel faster than light, so a fast reply caps the chip's distance from each landmark. A slow reply does not show that a chip is far away, because internet routes add delay. The designers estimate under $1 million for firmware and software, plus $2.5–12.5 million a year for 100–500 landmarks. Ulyssean describes an H100 prototype on its demonstration website. NVIDIA is reportedly developing a version that uses its own servers. The main weaknesses are extraction of a chip's key, manipulated network delay and compromised landmarks. The check says nothing about chips in transit or how they are used.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- Existing hardware features
- Prover cooperation
- Required
- Confidentiality
- Preserving
- Category
- Accounting & provenance
Technical detail and cited results
Brass and Aarne give the distance bound as D = T × 200, where D is the maximum distance in km and T the one-way delay in ms, taking about 200,000 km/s as the speed of light in optical fibre S-1400. In their case study, a 4.665 ms one-way delay bounds the chip to within 933 km of the landmark S-1400. They note that a limit based on the vacuum speed of light, about 300,000 km/s, covers worst cases such as out-of-band radio or satellite links and cannot be beaten physically S-1400. The cost is more false negatives: honest chips near a landmark may not reply fast enough, which the authors' moderate experimentation suggested could happen "perhaps even in more than 50% of cases" S-1400. Calibrating landmark delay factors might reduce this rate but needs further work S-1400. Recent geolocation algorithms reach a median error under 10 km given excellent landmark distribution and coverage; delay-based methods in general give about 10 km to 1,000 km, depending on the algorithm S-1400.
The Sovereignty Certificates draft (Lucid sovereignty (location) certificates) casts the protocol as a RATS (RFC 9334) attestation flow with Entity Attestation Token (RFC 9711) claims S-1404. The verifier issues a nonce and a signed directory of anchors. The attester probes anchors from inside a TEE, and each anchor returns a signed receipt with a high-precision timestamp and a nonce. The verifier then runs a deterministic multilateration to compute a feasible region S-1404. Per-cycle ephemeral keys are bound into the hardware root of trust's attestation quote to prevent replay S-1404.
Tee and Happel propose identifying a GPU by a hardware fingerprint instead of an extractable on-chip key. Their proof of concept races atomic operations across streaming multiprocessors S-1403. Over 480 runs on 24 NVIDIA H200 GPUs rented from a cloud provider, re-identification accuracy was 98.8% from a single run and 100% from paired runs, with each run taking about 2.9 s S-1403. The authors state that the fingerprint still has to be validated on more GPUs, shown to be stable over time and conditions, and shown to resist an adversary who runs the function faster or simulates the GPU S-1403.
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
Chips are where they are declared to be
Bounds how far a responding chip can be from trusted landmark servers at the time of the check.
There is no undeclared relevant compute
Can flag enrolled chips that stop responding or answer from outside declared regions; says nothing about chips outside the scheme.
Readiness for a stated use
Assessed use: bounding how far a chip is from trusted landmark servers when checked
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
The design is public and detailed, but the one reported prototype has a single published result, which cannot be checked.
- R1 met: Brass and Aarne give a full design with adversary classes, attacks and cost estimates S-1400. Aarne, Fist and Withers describe landmark-based verification S-0056, and Avellar and Grunewald set out how a regulator could run it S-1402.
- R2 not met: the IAPS brief reports a rudimentary H100 prototype and one result, a Singapore landmark bounding a chip in Singapore to within 300 miles S-1401. Ulyssean describes an H100 and AMD SEV-SNP setup with 38 cloud landmarks and a timing method, but publishes no code or systematic end-to-end location results or error rates S-3570. The single result cannot be reproduced from the available information. NVIDIA's delay-based scheme, reported by Avellar and Grunewald S-1402, has no published design or results. Tee and Happel publish reproducible results for GPU fingerprinting, which is a component, not end-to-end location verification S-1403. The most mature implementation for this use, the draft Sovereignty Certificates specification (Lucid sovereignty (location) certificates), is itself R1 S-1404.
Confidence is medium: the demo describes its setup and timing method, but the code is not public and its single location result lacks the data needed for independent reproduction S-3570 S-1401.
Evidence needed for the next level
A public implementation, or reproducible end-to-end results, on data-centre accelerators with a real landmark network.
Published measurements of false-positive and false-negative rates under realistic internet routing.
An evaluation against a stated adversary covering delay manipulation, faster network paths, landmark compromise and key extraction.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Extracting a chip's key lets another device answer for it
Ping-based protocols rely on cryptographic keys stored on the chip. Tee and Happel argue that an adversary with physical access could extract these keys and so compromise location verification S-1403. They propose GPU fingerprints as a mitigation, so far tested on 24 GPUs S-1403. Brass and Aarne assume the keys are stored securely, for example in a TPM S-1400.
significant / open / demonstrated attack
Added delay can shift an estimated position
Brass and Aarne cite internet-geolocation research in which artificially increased round-trip times moved the estimated location by up to 1,000 km, with a 74% chance of avoiding detection S-1400. Avellar and Grunewald list inflated ping times from circuitous routing as an evasion route S-1402. Added delay only loosens a distance bound, and Brass and Aarne propose a hard time limit as the counter: a chip that replies too slowly cannot be ruled out of a restricted location S-1400.
significant / open / theoretical argument
Faster-than-assumed network paths
Brass and Aarne list dark fibre and other private high-speed interconnects as ways to lower measured delays artificially. They judge that leasing dark fibre would probably not be a considerable challenge for covertly or openly adversarial actors S-1400. Avellar and Grunewald note that this can make a chip appear to be somewhere else entirely S-1402. A limit set at the vacuum speed of light cannot be beaten, but it makes honest chips fail more often S-1400.
significant / open / theoretical argument
Compromised landmarks can falsify measurements
A party that controls landmark servers can report false timing. Brass and Aarne cite research in which manipulating a third of the landmarks shifted the estimated location by about 700 km S-1400. Avellar and Grunewald note that compromised landmarks let adversaries spoof travel-time measurements directly S-1402. The draft specification asks verifiers to require anchors in diverse places, run by several independent operators S-1404.
What still blocks use or stronger assurance
- S-1401S-3570
No public code or reproducible end-to-end location results are available for the reported H100 prototype.
- S-1400S-1403S-0007
Per-chip keys must be provisioned and protected against extraction; hardware-integrated, tamper-resistant versions still need R&D.
- S-1400
The time limit forces a trade-off: a limit at the speed of light in fibre can be beaten by faster links, while one at the vacuum speed of light makes honest chips fail often.
- S-1400S-1402
A trusted landmark network must be built and secured, and who should operate it, under what oversight, is unsettled.
Connections in the research map
Depends on
- TEE remote attestation for AI workloads
Binding a timed reply to one physical chip relies on a per-chip key held in secure hardware, as in remote attestation.
Complementary techniques
Concepts used
Organizations and developers
Implementations
The Consortium’s case files
Related editorial reviews use the Consortium’s own descriptive scores and review dates. Their scores are separate from the atlas readiness rubric.
LV-01 / LocationGeography by ping timeRead case file ↗Sources and provenance
- S-1400 / Tier B
Location Verification for AI Chips ↗
A. Brass, O. Aarne · 2024 · Institute for AI Policy and Strategy
Supports: design, problem framing, adversary classes, distance bound, fibre versus vacuum speed limits and false negatives, precision, attacks and hard time limits, costs, key storage
Locator: Detailed Summary; Solution requirements and threat models; Delay-based methods sections; Three adversarial strategies; Proposed Solution Requirements
Version and catalogue details - S-1401 / Tier B
Location Verification for AI Chips (issue brief) ↗
A. Brass · 2025 · Institute for AI Policy and Strategy
Supports: reported H100 prototype (builder not named) and its single Singapore result; summary of Brass and Aarne's 2024 report; development and landmark network cost estimates
Locator: issue brief, pp. 1-2
Version and catalogue details - S-3570 / Tier B
Ping-based Location ↗
Ulyssean · 2025 · Ulyssean demonstration site
Supports: Ulyssean's account of the H100 and AMD SEV-SNP demonstration, 38 landmarks, timing method, code status
Locator: Technical details, public JavaScript asset
Version and catalogue details - S-1402 / Tier B
Near-Term Verification Methods for AI Chip Exports ↗
B. Avellar, E. Grunewald · 2026 · Institute for AI Policy and Strategy
Supports: regulator workflow; maturity and effectiveness ratings; costs; transit gap; evasion and landmark compromise; NVIDIA confirmed developing delay-based verification with NVIDIA-run servers (citing Reuters, December 2025)
Locator: §1.6; Executive Summary
Version and catalogue details - S-1413 / Tier B
Opt-In NVIDIA Software Enables Data Center Fleet Management ↗
NVIDIA · 2025 · NVIDIA Blog
Supports: NVIDIA's opt-in, customer-installed fleet-management service with read-only telemetry and an agent to be open-sourced; NVIDIA's statement that its GPUs lack hardware tracking, kill switches and backdoors (provider self-description)
Locator: blog post
Version and catalogue details - S-3180 / Tier B
Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization ↗
C. Shrauder, G. Frederick · 2026 · NVIDIA Technical Blog
Supports: Fleet Intelligence (May 2026): read-only agent released as open source; telemetry and GPU integrity attestation, no location check described (provider self-description)
Locator: blog post
Version and catalogue details - S-0056 / Tier B
Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing ↗
O. Aarne, T. Fist, C. Withers · 2024 · Center for a New American Security
Supports: speed-of-light upper bound; landmark-server illustration; hundreds of landmarks
Locator: 'Location Verification', p. 11
Version and catalogue details - S-0007 / Tier B
Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification ↗
S. Ansari · 2026 · arXiv
Supports: feasibility rating; physical attacks on embedded mechanisms
Locator: §3.1 (M6); §4.3
Version and catalogue details - S-1403 / Tier B
GPU Fingerprinting for Location Verification ↗
W. Tee, J. Happel · 2026 · arXiv
Supports: key-extraction weakness; fingerprinting proof of concept and its stated limitations
Locator: Abstract; threat model; results; limitations
Version and catalogue details - S-1404 / Tier B
Sovereignty Certificates: draft specification, version 0.1.0 ↗
Sovereignty Certificates Working Group · 2025 · GitHub (Lucid-Computing/sovereignty-certificate-specification)
Supports: draft protocol structure, threat model, anchor diversity and tunnelling check
Locator: §0.3, §4.2, §6.3, §8.1, §8.3.3, §8.3.4
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review