TPM-FAIL: TPM meets Timing and Lattice Attacks

TPM-FAIL: TPM meets Timing and Lattice Attacks
复制标题

DOI:
--
复制
发表时间:
2019-11
期刊:
ArXiv
影响因子:
--
通讯作者:
D. Moghimi;B. Sunar;T. Eisenbarth;N. Heninger
D. Moghimi;B. Sunar;T. Eisenbarth;N. Heninger
中科院分区:
其他
文献类型:
--
作者:
D. Moghimi;B. Sunar;T. Eisenbarth;N. Heninger

文献摘要

相似文献

可信平台模块 (TPM) 充当基于硬件的信任根,保护加密密钥免受特权系统和物理对手的攻击。在这项工作中,我们对部署在商用计算机上的 TPM 2.0 设备进行黑盒时序分析。我们的分析表明,其中一些设备在基于椭圆曲线的签名生成过程中具有与秘密相关的执行时间。特别是,我们发现基于英特尔固件的 TPM 以及硬件 TPM 上存在时序泄漏。我们展示了此信息如何允许攻击者应用点阵技术来恢复 ECDSA 和 ECSchnorr 签名的 256 位私钥。在英特尔 fTPM 上,我们的密钥恢复在大约 1,300 次观察后在不到两分钟的时间内成功。同样,经过不到 40,000 次观察,我们从意法半导体制造的硬件 TPM 中提取了私有 ECDSA 密钥,该硬件 TPM 通过了通用标准 (CC) EAL 4+ 认证。我们通过演示针对 StrongSwan IPsec VPN 的远程攻击(使用 TPM 生成用于身份验证的数字签名)来进一步强调这些漏洞的影响。在此攻击中,远程客户端通过网络连接仅计时 45,000 次身份验证握手,从而恢复服务器的私有身份验证密钥。我们发现的漏洞强调了正确实现已知恒定时间技术的难度,并显示了进化测试和加密实现的透明评估的重要性。随着我们对这些攻击的了解越来越多,即使是声称能够抵御攻击的经过认证的设备也需要社区和行业的额外审查。
Trusted Platform Module (TPM) serves as a hardware-based root of trust that protects cryptographic keys from privileged system and physical adversaries. In this work, we perform a black-box timing analysis of TPM 2.0 devices deployed on commodity computers. Our analysis reveals that some of these devices feature secret-dependent execution times during signature generation based on elliptic curves. In particular, we discovered timing leakage on an Intel firmware-based TPM as well as a hardware TPM. We show how this information allows an attacker to apply lattice techniques to recover 256-bit private keys for ECDSA and ECSchnorr signatures. On Intel fTPM, our key recovery succeeds after about 1,300 observations and in less than two minutes. Similarly, we extract the private ECDSA key from a hardware TPM manufactured by STMicroelectronics, which is certified at Common Criteria (CC) EAL 4+, after fewer than 40,000 observations. We further highlight the impact of these vulnerabilities by demonstrating a remote attack against a StrongSwan IPsec VPN that uses a TPM to generate the digital signatures for authentication. In this attack, the remote client recovers the server's private authentication key by timing only 45,000 authentication handshakes via a network connection. The vulnerabilities we have uncovered emphasize the difficulty of correctly implementing known constant-time techniques, and show the importance of evolutionary testing and transparent evaluation of cryptographic implementations. Even certified devices that claim resistance against attacks require additional scrutiny by the community and industry, as we learn more about these attacks.