K-0015

Tamper evidence and tamper resistance

Tamper evidence makes interference detectable; tamper resistance makes it difficult or costly; tamper response reacts to it, often by erasing secrets.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

Tamper evidence is an external indication that someone has tried to compromise a device's physical security; tamper resistance makes such attempts difficult, costly or both; and tamper response is an automatic action, at minimum erasing plaintext keys, taken when tampering is detected S-1605 S-1600.

The US standard for cryptographic modules, FIPS 140-2, since superseded by FIPS 140-3, layers these properties S-1605:

  • Level 2 requires evidence of tampering, such as tamper-evident coatings or seals, or pick-resistant locks on covers and doors S-1605.
  • Level 3 adds detection and response circuitry that zeroizes plaintext secret and private keys when covers or doors are opened S-1605.
  • Level 4 requires a complete envelope of protection intended to detect and respond to all unauthorized attempts at physical access S-1605.

These properties matter because the prover usually controls the hardware: Shavit notes that unlimited physical access could undermine a chip's attestation, and relies on inspections to find hardware attacks that damage chips in ways that are hard to hide S-0029. The flexHEG proposal houses its guarantee processor in a secure enclosure that provides physical tamper protection (Hardware-enabled guarantees (flexHEG) and guarantee processors) S-0035. One verification plan names tamper-evident enclosures among "promising future directions and existing methods" for physical security of AI computing infrastructure S-0067. Protecting verifier equipment in the prover's facility, such as network taps and recomputation servers, is the subject of tamper evidence for verifier devices. Seals can be defeated with simple methods: a 1996 Los Alamos study demonstrated low-tech defeats for each of the 94 passive and electronic seals it examined, with a mean defeat time of 4.3 minutes for one practised person S-1317.

Connections in the research map

Related research

Sources and provenance

  1. S-1605 / Tier A

    Security Requirements for Cryptographic Modules (FIPS PUB 140-2) ↗

    National Institute of Standards and Technology · 2001 · National Institute of Standards and Technology

    Supports: definitions of tamper evidence, tamper detection and tamper response; physical security Levels 2–4; superseded by FIPS 140-3

    Locator: §2.1 Glossary; §4.5; CSRC status page

    Version and catalogue details
  2. S-1600 / Tier A

    NIST Computer Security Resource Center (CSRC) Glossary ↗

    National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center

    Supports: tamper resistant: makes alterations difficult, costly or both (definition written for data)

    Locator: term: tamper_resistant (NISTIR 8202)

    Version and catalogue details
  3. S-0029 / Tier B

    What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗

    Y. Shavit · 2023 · arXiv

    Supports: unlimited physical access can undermine attestation; inspections detect hard-to-hide hardware attacks

    Locator: §3.1

    Version and catalogue details
  4. S-0035 / Tier B

    Flexible Hardware-Enabled Guarantees for AI Compute ↗

    J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv

    Supports: flexHEG secure enclosure providing physical tamper protection

    Locator: abstract

    Version and catalogue details
  5. S-0067 / Tier C

    Verification Plan ↗

    R. Dean · 2026 · AI 2040

    Supports: tamper-evident enclosures named among promising future directions and existing methods for physical security of AI computing infrastructure

    Locator: physical security measures

    Version and catalogue details
  6. S-1317 / Tier B

    Physical Security and Tamper-Indicating Devices ↗

    R. G. Johnston, A. R. E. Garcia · 1996 · Los Alamos National Laboratory, LA-UR-96-3827

    Supports: 94 seals studied; 1–3 low-tech defeats demonstrated for each, 132 in total; mean defeat time 4.3 minutes by one practised person

    Locator: abstract; results

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review