Faulty Point Unit: ABI Poisoning Attacks on Trusted Execution Environments

Faulty Point Unit: ABI Poisoning Attacks on Trusted Execution Environments
复制标题

DOI:
10.1145/3491264
复制
发表时间:
2021-10
期刊:
Digital Threats: Research and Practice (DTRAP)
影响因子:
--
通讯作者:
F. Alder;Jo Van Bulck;Jesse Spielman;David F. Oswald;Frank Piessens
F. Alder;Jo Van Bulck;Jesse Spielman;David F. Oswald;Frank Piessens
中科院分区:
其他
文献类型:
--
作者:
F. Alder;Jo Van Bulck;Jesse Spielman;David F. Oswald;Frank Piessens

文献摘要

相似文献

本文分析了一个以前被忽视的攻击面,它允许无特权的攻击者通过应用程序二进制接口(ABI)影响安全区中的浮点计算。在针对英特尔Software Guard Extensions(SGX)的7种行业标准和研究安全区屏蔽运行时的全面研究中,我们发现x87浮点单元(FPU)和英特尔SIMD流处理扩展的控制和状态寄存器在安全区进入时并不总是正确清理。我们还表明,这种攻击超出了x86架构,也可能影响RISC-V飞地。专注于SGX,我们滥用对手对精度和舍入模式的控制作为ABI故障注入原语来破坏飞地浮点运算。我们的分析表明,这与使用旧x87 FPU的应用程序特别相关,现代编译器在某些条件下仍然使用旧x87 FPU。我们分析了ABI质量降级攻击对飞地机器学习和SPEC基准测试的潜在影响。然后,我们探讨的机密性的影响,显示异常掩码的控制可以被滥用为一个受控的通道,以恢复飞地乘法操作数。我们的研究结果影响了7个研究SGX运行时中的5个和一个RISC-V运行时,展示了在计算架构中实施高保证可信执行的挑战。
This article analyzes a previously overlooked attack surface that allows unprivileged adversaries to impact floating-point computations in enclaves through the Application Binary Interface (ABI). In a comprehensive study across 7 industry-standard and research enclave shielding runtimes for Intel Software Guard Extensions (SGX), we show that control and state registers of the x87 Floating-Point Unit (FPU) and Intel Streaming SIMD Extensions are not always properly sanitized on enclave entry. We furthermore show that this attack goes beyond the x86 architecture and can also affect RISC-V enclaves. Focusing on SGX, we abuse the adversary’s control over precision and rounding modes as an ABI fault injection primitive to corrupt enclaved floating-point operations. Our analysis reveals that this is especially relevant for applications that use the older x87 FPU, which is still under certain conditions used by modern compilers. We exemplify the potential impact of ABI quality-degradation attacks for enclaved machine learning and for the SPEC benchmarks. We then explore the impact on confidentiality, showing that control over exception masks can be abused as a controlled channel to recover enclaved multiplication operands. Our findings, affecting 5 of 7 studied SGX runtimes and one RISC-V runtime, demonstrate the challenges of implementing high-assurance trusted execution across computing architectures.