ENCIDER: Detecting Timing and Cache Side Channels in SGX Enclaves and Cryptographic APIs

ENCIDER: Detecting Timing and Cache Side Channels in SGX Enclaves and Cryptographic APIs
复制标题

DOI:
10.1109/tdsc.2022.3160346
复制
发表时间:
2023-03
影响因子:
7.3
通讯作者:
Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian
Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian

文献摘要

相似文献

机密计算旨在通过为使用英特尔SGX等硬件功能的应用程序提供可信执行环境(TEE)来保护使用中的代码和数据。然而,定时和缓存侧通道攻击通常不在威胁模型的范围内,尽管一旦被利用,它们就能够破坏硬件强制执行的所有默认安全保证。不幸的是,检测应用程序中潜在侧通道漏洞的工具非常有限,并且通常会忽略英特尔SGX所采用的强大攻击模型和独特编程模型。本文提出了一个精确的侧通道分析工具ENCIDER,通过推断潜在的时序观察点并将SGX编程模型纳入分析,检测SGX应用程序中的时序和缓存侧通道漏洞。ENCIDER基于有界无干扰特性,采用动态符号执行分解边信道需求,通过API建模实现字节级信息流跟踪。我们已经将ENCIDER应用于4个真实世界的SGX应用程序,2个SGX加密库和3个广泛使用的加密库,并发现了29个定时侧通道和73个代码和数据缓存侧通道。我们还比较ENCIDER与三个国家的最先进的侧信道分析工具,使用他们的基准。ENCIDER不仅报告了大多数错误,运行时间改善了20%-50%,内存使用率改善了65%-92%,而且还从这些工具中检测到9个缺失的错误。我们已向相应各方报告了我们的调查结果,例如,英特尔和ARM,他们已经确认了检测到的大部分漏洞。
Confidential computing aims to secure the code and data in use by providing a Trusted Execution Environment (TEE) for applications using hardware features such as Intel SGX. Timing and cache side-channel attacks, however, are often outside the scope of the threat model, although once exploited they are able to break all the default security guarantees enforced by hardware. Unfortunately, tools detecting potential side-channel vulnerabilities within applications are limited and usually ignore the strong attack model and the unique programming model imposed by Intel SGX. This article proposes a precise side-channel analysis tool, ENCIDER, detecting both timing and cache side-channel vulnerabilities within SGX applications via inferring potential timing observation points and incorporating the SGX programming model into analysis. ENCIDER uses dynamic symbolic execution to decompose the side-channel requirement based on the bounded non-interference property and implements byte-level information flow tracking via API modeling. We have applied ENCIDER to 4 real-world SGX applications, 2 SGX crypto libraries, and 3 widely-used crypto libraries, and found 29 timing side channels and 73 code and data cache side channels. We also compare ENCIDER with three state-of-the-art side channel analysis tools using their benchmarks. ENCIDER does not only report most of the bugs with 20%-50% run time improvement and 65%-92% memory usage improvement, but also detects 9 missing bugs from these tools. We have reported our findings to the corresponding parties, e.g., Intel and ARM, who have confirmed most of the vulnerabilities detected.