01 / The mechanism and its boundary
What is being described
Tamper evidence is an external indication that someone has tried to compromise a device's physical security; tamper resistance makes such attempts difficult, costly or both; and tamper response is an automatic action, at minimum erasing plaintext keys, taken when tampering is detected S-1605 S-1600.
The US standard for cryptographic modules, FIPS 140-2, since superseded by FIPS 140-3, layers these properties S-1605:
- Level 2 requires evidence of tampering, such as tamper-evident coatings or seals, or pick-resistant locks on covers and doors S-1605.
- Level 3 adds detection and response circuitry that zeroizes plaintext secret and private keys when covers or doors are opened S-1605.
- Level 4 requires a complete envelope of protection intended to detect and respond to all unauthorized attempts at physical access S-1605.
These properties matter because the prover usually controls the hardware: Shavit notes that unlimited physical access could undermine a chip's attestation, and relies on inspections to find hardware attacks that damage chips in ways that are hard to hide S-0029. The flexHEG proposal houses its guarantee processor in a secure enclosure that provides physical tamper protection (Hardware-enabled guarantees (flexHEG) and guarantee processors) S-0035. One verification plan names tamper-evident enclosures among "promising future directions and existing methods" for physical security of AI computing infrastructure S-0067. Protecting verifier equipment in the prover's facility, such as network taps and recomputation servers, is the subject of tamper evidence for verifier devices. Seals can be defeated with simple methods: a 1996 Los Alamos study demonstrated low-tech defeats for each of the 94 passive and electronic seals it examined, with a mean defeat time of 4.3 minutes for one practised person S-1317.
Connections in the research map
Related research
Sources and provenance
- S-1605 / Tier A
Security Requirements for Cryptographic Modules (FIPS PUB 140-2) ↗
National Institute of Standards and Technology · 2001 · National Institute of Standards and Technology
Supports: definitions of tamper evidence, tamper detection and tamper response; physical security Levels 2–4; superseded by FIPS 140-3
Locator: §2.1 Glossary; §4.5; CSRC status page
Version and catalogue details - S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: tamper resistant: makes alterations difficult, costly or both (definition written for data)
Locator: term: tamper_resistant (NISTIR 8202)
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: unlimited physical access can undermine attestation; inspections detect hard-to-hide hardware attacks
Locator: §3.1
Version and catalogue details - S-0035 / Tier B
Flexible Hardware-Enabled Guarantees for AI Compute ↗
J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv
Supports: flexHEG secure enclosure providing physical tamper protection
Locator: abstract
Version and catalogue details - S-0067 / Tier C
Verification Plan ↗
R. Dean · 2026 · AI 2040
Supports: tamper-evident enclosures named among promising future directions and existing methods for physical security of AI computing infrastructure
Locator: physical security measures
Version and catalogue details - S-1317 / Tier B
Physical Security and Tamper-Indicating Devices ↗
R. G. Johnston, A. R. E. Garcia · 1996 · Los Alamos National Laboratory, LA-UR-96-3827
Supports: 94 seals studied; 1–3 low-tech defeats demonstrated for each, 132 in total; mean defeat time 4.3 minutes by one practised person
Locator: abstract; results
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review