CacheQuote: Efficiently Recovering Long-term Secrets of SGX EPID via Cache Attacks

CacheQuote: Efficiently Recovering Long-term Secrets of SGX EPID via Cache Attacks
复制标题

DOI:
10.13154/tches.v2018.i2.171-191
复制
发表时间:
2018-05
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
通讯作者:
Fergus Dall;Gabrielle De Micheli;T. Eisenbarth;Daniel Genkin;N. Heninger;A. Moghimi;Y. Yarom
Fergus Dall;Gabrielle De Micheli;T. Eisenbarth;Daniel Genkin;N. Heninger;A. Moghimi;Y. Yarom
中科院分区:
其他
文献类型:
--
作者:
Fergus Dall;Gabrielle De Micheli;T. Eisenbarth;Daniel Genkin;N. Heninger;A. Moghimi;Y. Yarom

文献摘要

相似文献

英特尔软件防护扩展 (SGX) 允许用户在运行不受信任软件的平台上执行安全计算。为了验证计算是否已正确初始化并在可信硬件上执行,SGX 支持可以为用户的计算提供担保的证明提供商。与这些证明提供商的通信基于扩展隐私 ID (EPID) 协议,该协议不仅验证计算,而且还旨在维护用户的隐私。特别是,EPID 旨在确保证明提供者无法识别执行计算的主机。在这项工作中,我们研究了 Intel 实施 EPID 协议的安全性。我们发现了一个通过缓存侧通道泄漏信息的实现弱点。我们表明,恶意证明提供商可以使用泄露的信息来破坏 EPID 的不可链接性保证。我们使用基于格的方法分析泄露的信息来解决隐藏数问题,我们将其应用于EPID方案中的零知识证明,扩展了对签名方案的先前攻击。
Intel Software Guard Extensions (SGX) allows users to perform secure computation on platforms that run untrusted software. To validate that the computation is correctly initialized and that it executes on trusted hardware, SGX supports attestation providers that can vouch for the user’s computation. Communication with these attestation providers is based on the Extended Privacy ID (EPID) protocol, which not only validates the computation but is also designed to maintain the user’s privacy. In particular, EPID is designed to ensure that the attestation provider is unable to identify the host on which the computation executes. In this work we investigate the security of the Intel implementation of the EPID protocol. We identify an implementation weakness that leaks information via a cache side channel. We show that a malicious attestation provider can use the leaked information to break the unlinkability guarantees of EPID. We analyze the leaked information using a lattice-based approach for solving the hidden number problem, which we adapt to the zero-knowledge proof in the EPID scheme, extending prior attacks on signature schemes.