Exploiting Unprotected I/O Operations in AMD's Secure Encrypted Virtualization

Exploiting Unprotected I/O Operations in AMD's Secure Encrypted Virtualization
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Mengyuan Li;Yinqian Zhang;Zhiqiang Lin;Yan Solihin
Mengyuan Li;Yinqian Zhang;Zhiqiang Lin;Yan Solihin
中科院分区:
其他
文献类型:
--
作者:
Mengyuan Li;Yinqian Zhang;Zhiqiang Lin;Yan Solihin

文献摘要

被引文献

相似文献

AMD的安全加密虚拟化(SEV)是一项新兴技术,即使在存在恶意虚拟机管理程序的情况下也能保护虚拟机(VM)。然而,对特权软件缺乏信任也为支持SEV的VM引入了各种新的攻击向量,这些攻击向量在文献中大多未被探索。本文从支持SEV的虚拟机中不受保护的I/O操作的角度研究了SEV的不安全性。结果令人警醒:我们不仅发现了破坏这些I/O操作的机密性和完整性的攻击-我们发现很难通过现有方法减轻-而且更重要的是,我们证明了针对SEV的存储器加密方案的两个攻击原语的构造,即存储器解密预言机和存储器加密预言机,这使得对手能够使用VM的存储器加密密钥来解密和加密任意消息。我们评估提出的攻击,并讨论潜在的解决方案的根本问题。
AMD’s Secure Encrypted Virtualization (SEV) is an emerging technology to secure virtual machines (VM) even in the presence of malicious hypervisors. However, the lack of trust in the privileged software also introduces an assortment of new attack vectors to SEV-enabled VMs that were mostly unexplored in the literature. This paper studies the insecurity of SEV from the perspective of the unprotected I/O operations in the SEV-enabled VMs. The results are alerting: not only have we discovered attacks that breach the confidentiality and integrity of these I/O operations—which we find very difficult to mitigate by existing approaches—but more significantly we demonstrate the construction of two attack primitives against SEV’s memory encryption schemes, namely a memory decryption oracle and a memory encryption oracle, which enables an adversary to decrypt and encrypt arbitrary messages using the memory encryption keys of the VMs. We evaluate the proposed attacks and discuss potential solutions to the underlying problems.