Attack of the Knights:Non Uniform Cache Side Channel Attack

Attack of the Knights:Non Uniform Cache Side Channel Attack
复制标题

DOI:
10.1145/3627106.3627199
复制
发表时间:
2021-12
期刊:
Proceedings of the 39th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Farabi Mahmud;Sungkeun Kim;H. Chawla;Eun Jung Kim;Chia-che Tsai;A. Muzahid
Farabi Mahmud;Sungkeun Kim;H. Chawla;Eun Jung Kim;Chia-che Tsai;A. Muzahid
中科院分区:
其他
文献类型:
--
作者:
Farabi Mahmud;Sungkeun Kim;H. Chawla;Eun Jung Kim;Chia-che Tsai;A. Muzahid

文献摘要

相似文献

对于大型多核芯片中的分布式最后一级缓存(LLC),由于物理距离的差异,对一个LLC bank的访问时间可能会与另一个有很大的不同。在本文中,我们成功地演示了一种新的基于距离的侧信道攻击,通过定时AES解密操作和提取部分AES密钥在英特尔骑士登陆CPU上。我们介绍了几种技术来克服攻击的挑战,包括使用多个攻击线程来确保LLC命中,检测易受攻击的内存位置,以及获得受害者操作的细粒度定时。当作为隐蔽通道运行时,这种攻击可以达到205 KBPS的带宽,错误率仅为0.02%。我们还观察到,侧信道攻击可以提取4字节的AES密钥,准确度为100%,只有4000轮加密试验。
For a distributed last-level cache (LLC) in a large multicore chip, the access time to one LLC bank can significantly differ from that to another due to the difference in physical distance. In this paper, we successfully demonstrate a new distance-based side-channel attack by timing the AES decryption operation and extracting part of an AES secret key on an Intel Knights Landing CPU. We introduce several techniques to overcome the challenges of the attack, including the use of multiple attack threads to ensure LLC hits, to detect vulnerable memory locations, and to obtain fine-grained timing of the victim operations. While operating as a covert channel, this attack can reach a bandwidth of 205 KBPS with an error rate of only 0.02%. We also observed that the side-channel attack can extract 4 bytes of an AES key with 100% accuracy with only 4000 trial rounds of encryption.