Eavesdropping user credentials via GPU side channels on smartphones

Eavesdropping user credentials via GPU side channels on smartphones
复制标题

DOI:
10.1145/3503222.3507757
复制
发表时间:
2022-02
期刊:
Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Boyuan Yang;Ruirong Chen;Kai Huang;Jun Yang;Wei Gao
Boyuan Yang;Ruirong Chen;Kai Huang;Jun Yang;Wei Gao
中科院分区:
其他
文献类型:
--
作者:
Boyuan Yang;Ruirong Chen;Kai Huang;Jun Yang;Wei Gao

文献摘要

相似文献

智能手机上的图形处理单元(GPU)是硬件攻击的有效目标。在本文中,我们对Android智能手机的移动GPU进行了新的侧渠道攻击,从而通过屏幕键盘从输入中窃取了无私人的攻击者的凭借用户的凭据(例如登录用户名和密码)。我们对Qualcomm Adreno GPU的攻击目标,并在渲染用户键入输入的键盘弹出窗口时研究GPU透支的数量。每次按键引起的这种GPU透支对应于所选GPU性能计数器的唯一变化,从中可以准确地推断出这些键压。实验在多种模型的Android智能手机上的实际使用结果表明,我们的攻击可以正确地推断出用户的凭证输入的80%以上,但在受害者设备上会遇到可忽略的计算开销和网络流量。为了应对这一攻击,本文建议缓解GPU性能计数器上的访问控制,或在GPU性能计数器的值上应用混淆。
Graphics Processing Unit (GPU) on smartphones is an effective target for hardware attacks. In this paper, we present a new side channel attack on mobile GPUs of Android smartphones, allowing an unprivileged attacker to eavesdrop the user's credentials, such as login usernames and passwords, from their inputs through on-screen keyboard. Our attack targets on Qualcomm Adreno GPUs and investigate the amount of GPU overdraw when rendering the popups of user's key presses of inputs. Such GPU overdraw caused by each key press corresponds to unique variations of selected GPU performance counters, from which these key presses can be accurately inferred. Experiment results from practical use on multiple models of Android smartphones show that our attack can correctly infer more than 80% of user's credential inputs, but incur negligible amounts of computing overhead and network traffic on the victim device. To counter this attack, this paper suggests mitigations of access control on GPU performance counters, or applying obfuscations on the values of GPU performance counters.