PwrLeak: Exploiting Power Reporting Interface for Side-Channel Attacks on AMD SEV

PwrLeak: Exploiting Power Reporting Interface for Side-Channel Attacks on AMD SEV
复制标题

DOI:
10.1007/978-3-031-35504-2_3
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Wubing Wang;Mengyuan Li;Yinqian Zhang;Zhiqiang Lin
Wubing Wang;Mengyuan Li;Yinqian Zhang;Zhiqiang Lin
中科院分区:
其他
文献类型:
--
作者:
Wubing Wang;Mengyuan Li;Yinqian Zhang;Zhiqiang Lin

文献摘要

相似文献

越来越多的可信执行环境(TEE)正在采用各种商业产品来保护云上的数据安全。然而,TES仍然暴露在各种侧通道漏洞中,例如基于执行顺序、基于时间和基于功率的漏洞。虽然最近的硬件正在应用各种技术来缓解基于顺序和基于时间的侧通道漏洞,但基于功率的侧通道攻击仍然是硬件安全的一个问题,特别是对于服务器不受云用户控制的机密计算环境。在本文中,我们提出了一个攻击框架PwrLeak,该框架利用AMD的电源报告接口来构建针对受AMD安全加密虚拟化(SEV)保护的虚拟机的电源侧通道攻击。我们设计并实现了攻击框架,包括三个一般步骤:(1)识别运行在AMD SEV中的指令;(2)应用功率插值器来放大功耗,包括用于分析目的的基于仿真的插值器和更通用的基于中断的插值器;(3)通过各种分析方法推断秘密。使用基于仿真的内插器推断libjpeg处理的整个JPEG图像的案例研究表明,该内插器能够帮助分析SEV VM内部的功耗。我们对英特尔集成性能基元(英特尔IPP)库的端到端攻击表明,使用基于中断的内插器,可以利用PwrLeak推断RSA私钥,准确率超过80%。
An increasing number of Trusted Execution Environment (TEE) is adopting to a variety of commercial products for protecting data security on the cloud. However, TEEs are still exposed to various side-channel vulnerabilities, such as execution order-based, timing-based, and power-based vulnerabilities. While recent hardware is applying various techniques to mitigate order-based and timing-based side-channel vulnerabilities, power-based side-channel attacks remain a concern of hardware security, especially for the confidential computing settings where the server machines are beyond the control of cloud users. In this paper, we presentPwrLeak, an attack framework that exploits AMD’s power reporting interfaces to build power side-channel attacks against AMD Secure Encrypted Virtualization (SEV)-protected VM. We design and implement the attack framework with three general steps: (1) identify the instruction running inside AMD SEV, (2) apply a power interpolator to amplify power consumption, including an emulation-based interpolator for analyzing purposes and a more general interrupt-based interpolator, and (3) infer secrets with various analysis approaches. A case study of using the emulation-based interpolator to infer the whole JPEG images processed by libjpeg demonstrates its ability to help analyze power consumption inside SEV VM. Our end-to-end attacks against Intel’s Integrated Performance Primitives (Intel IPP) library indicates thatPwrLeakcan be exploited to infer RSA private keys with over 80% accuracy using the interrupt-based interpolator.