TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution Environments

TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution Environments
复制标题

DOI:
10.1145/3579371.3589070
复制
发表时间:
2023-06
期刊:
Proceedings of the 50th Annual International Symposium on Computer Architecture
影响因子:
--
通讯作者:
Moein Ghaniyoun;Kristin Barber;Yuan Xiao;Yinqian Zhang;R. Teodorescu
Moein Ghaniyoun;Kristin Barber;Yuan Xiao;Yinqian Zhang;R. Teodorescu
中科院分区:
其他
文献类型:
--
作者:
Moein Ghaniyoun;Kristin Barber;Yuan Xiao;Yinqian Zhang;R. Teodorescu

文献摘要

被引文献

相似文献

受信任的执行环境(TEE)是CPU硬件扩展,可为在不受信任的操作系统上运行的应用程序提供安全保证。 T恤的安全受到各种微体系漏洞的威胁,这些脆弱性导致了大量证明的攻击。尽管已经提出了用于验证TEE设计的正确性和安全性的各种解决方案,但它们通常不会扩展到共同验证基础微体系结构的安全性。本文介绍了TEESEC,这是在可信赖的执行环境中发现微体系漏洞的第一个预硅框架。 TEESEC旨在共同和系统地测试针对跨隔离边界的数据和元数据泄漏的TEE和基础微体系结构。我们在Chipyard框架中实现TEESEC,并在两个运行Keystone Tee的开源RISC-V-V级处理器上进行评估。使用TEESEC,我们在这些处理器中发现了10个不同的漏洞,这些漏洞违反了TEE安全原则,并可能导致飞地秘密泄漏。
Trusted execution environments (TEE) are CPU hardware extensions that provide security guarantees for applications running on untrusted operating systems. The security of TEEs is threatened by a variety of microarchitectural vulnerabilities, which have led to a large number of demonstrated attacks. While various solutions for verifying the correctness and security of TEE designs have been proposed, they generally do not extend to jointly verifying the security of the underlying microarchitecture. This paper presents TEESec, the first pre-silicon framework for discovering microarchitectural vulnerabilities in the context of trusted execution environments. TEESec is designed to jointly and systematically test the TEE and underlying microarchitecture against data and metadata leakage across isolation boundaries. We implement TEESec in the Chipyard framework and evaluate it on two open-source RISC-V out-of-order processors running the Keystone TEE. Using TEESec we uncover 10 distinct vulnerabilities in these processors that violate TEE security principles and could lead to leakage of enclave secrets.