VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface

VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Zitai Chen;G. Vasilakis;Kit Murdock;Edward Dean;David F. Oswald;Flavio D. Garcia
Zitai Chen;G. Vasilakis;Kit Murdock;Edward Dean;David F. Oswald;Flavio D. Garcia
中科院分区:
其他
文献类型:
--
作者:
Zitai Chen;G. Vasilakis;Kit Murdock;Edward Dean;David F. Oswald;Flavio D. Garcia

文献摘要

相似文献

基于硬件的故障注入攻击,如电压和时钟毛刺,已经在嵌入式设备上得到了深入的研究。此类攻击的典型目标包括物联网设备中使用的智能卡和低功耗微控制器。本文介绍了第一个针对成熟的Intel CPU的基于硬件的电压毛刺攻击。由于几个因素,向复杂CPU的过渡并不容易,这些因素包括:复杂的操作系统、高功耗、多线程和高时钟速度。为此,我们构建了VoltPillager,这是一个低成本的工具,用于在CPU和主板上的电压调节器之间的串行电压识别总线上插入消息。这使我们能够精确地控制CPU内核电压。我们利用这一强大的工具发起故障注入攻击,破坏英特尔SGX飞地的机密性和完整性。我们提出了针对运行在SGX中的密码算法的概念验证密钥恢复攻击。我们证明了VoltPillager攻击比最近针对新加坡交易所的纯软件欠电压攻击(CVE-2019-11157)更强大,因为它们工作在启用了所有软件欠电压对策的完全修补的系统上。此外,我们还可以通过延迟内存写入来对安全关键操作进行故障诊断。缓解VoltPillager并不是一帆风顺的,可能需要重新考虑SGX对手模式,在这种模式下,云提供商不受信任,并且可以物理访问硬件。
Hardware-based fault injection attacks such as voltage and clock glitching have been thoroughly studied on embedded devices. Typical targets for such attacks include smartcards and low-power microcontrollers used in IoT devices. This paper presents the first hardware-based voltage glitching attack against a fully-fledged Intel CPU. The transition to complex CPUs is not trivial due to several factors, including: a complex operating system, large power consumption, multi-threading, and high clock speeds. To this end, we have built VoltPillager, a low-cost tool for injecting messages on the Serial Voltage Identification bus between the CPU and the voltage regulator on the motherboard. This allows us to precisely control the CPU core voltage. We leverage this powerful tool to mount fault-injection attacks that breach confidentiality and integrity of Intel SGX enclaves. We present proof-of-concept key-recovery attacks against cryptographic algorithms running inside SGX. We demonstrate that VoltPillager attacks are more powerful than recent software-only undervolting attacks against SGX (CVE-2019-11157) because they work on fully patched systems with all countermeasures against software undervolting enabled. Additionally, we are able to fault securitycritical operations by delaying memory writes. Mitigation of VoltPillager is not straightforward and may require a rethink of the SGX adversarial model where a cloud provider is untrusted and has physical access to the hardware.