Preventing Your Faults From Telling Your Secrets: Defenses Against Pigeonhole Attacks

Preventing Your Faults From Telling Your Secrets: Defenses Against Pigeonhole Attacks
复制标题

DOI:
--
复制
发表时间:
2015-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Shweta Shinde;Zheng Leong Chua;Viswesh Narayanan;P. Saxena
Shweta Shinde;Zheng Leong Chua;Viswesh Narayanan;P. Saxena
中科院分区:
其他
文献类型:
--
作者:
Shweta Shinde;Zheng Leong Chua;Viswesh Narayanan;P. Saxena

文献摘要

被引文献

相似文献

新的硬件原语(如Intel SGX)可在存在不可信或受危害的操作系统的情况下保护用户级进程。这样的“包围式执行”系统容易受到几个旁路的攻击,其中之一就是页面错误通道。在本文中,我们证明了页面错误侧通道具有足够的通道容量来从OpenSSL和Libgcrypt中密码例程的商用实现中提取加密密钥的比特-平均泄漏27%,在许多案例研究中高达100%的秘密比特。为了缓解这一问题,我们提出了一种仅限软件的防御措施,通过确定程序的内存访问行为来屏蔽页面错误模式。我们证明了这样的技术可以被构建到编译器中,并在足以处理我们研究的密码例程的C子集上实现。这种防御在一般情况下可以有高达4000倍的显著开销,但在开发人员辅助的编译器优化的帮助下,在我们的案例研究中,开销最多减少到29.22%。最后,我们讨论了硬件辅助防御的范围,并展示了一个解决方案,该解决方案可以在支持硬件更改的情况下将管理费用降低到6.77%。
New hardware primitives such as Intel SGX secure a user-level process in presence of an untrusted or compromised OS. Such "enclaved execution" systems are vulnerable to several side-channels, one of which is the page fault channel. In this paper, we show that the page fault side-channel has sufficient channel capacity to extract bits of encryption keys from commodity implementations of cryptographic routines in OpenSSL and Libgcrypt --- leaking 27% on average and up to 100% of the secret bits in many case-studies. To mitigate this, we propose a software-only defense that masks page fault patterns by determinising the program's memory access behavior. We show that such a technique can be built into a compiler, and implement it for a subset of C which is sufficient to handle the cryptographic routines we study. This defense when implemented generically can have significant overhead of up to 4000X, but with help of developer-assisted compiler optimizations, the overhead reduces to at most 29.22% in our case studies. Finally, we discuss scope for hardware-assisted defenses, and show one solution that can reduce overheads to 6.77% with support from hardware changes.