Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh Interconnects

Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh Interconnects
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Miles Dai;Riccardo Paccagnella;Miguel Gomez-Garcia;John D. McCalpin;Mengjia Yan
Miles Dai;Riccardo Paccagnella;Miguel Gomez-Garcia;John D. McCalpin;Mengjia Yan
中科院分区:
其他
文献类型:
--
作者:
Miles Dai;Riccardo Paccagnella;Miguel Gomez-Garcia;John D. McCalpin;Mengjia Yan

文献摘要

相似文献

本文研究了现代服务器级英特尔处理器中使用的片上网状互连的微架构侧信道攻击和缓解措施。我们发现,尽管很难利用,但即使核心和缓存内的已知攻击向量被关闭,网状互连也可能被对手滥用。然后,我们提出了新的,非侵入性的缓解机制,以互连侧信道攻击,并提供见解,以指导未来的防御设计。我们的分析首先对网格互连进行彻底的逆向工程,以首次揭示它易受竞争影响的精确条件。我们表明,攻击者可以使用这些条件来建立一个跨核心的隐蔽通道,容量超过1.5 Mbps。然后,我们证明了侧信道攻击的可行性,从脆弱的加密实现通过监测网格互连争用泄漏密钥。最后,我们提出了一个分析模型来量化不同的受害者和攻击者放置在芯片上的脆弱性水平,并使用结果来设计一个软件的缓解机制。
This paper studies microarchitectural side-channel attacks and mitigations on the on-chip mesh interconnect used in modern, server-class Intel processors. We find that, though difficult to exploit, the mesh interconnect can be abused by an adversary even when known attack vectors inside the cores and caches are closed . We then present novel, non-invasive mitigation mechanisms to interconnect side-channel attacks and offer insights to guide the design of future defenses. Our analysis starts by thoroughly reverse engineering the mesh interconnect to reveal, for the first time, the precise conditions under which it is susceptible to contention. We show that an attacker can use these conditions to build a cross-core covert channel with a capacity of over 1.5 Mbps. We then demonstrate the feasibility of side-channel attacks that leak keys from vulnerable cryptographic implementations by monitoring mesh interconnect contention. Finally, we present an analytical model to quantify the vulnerability levels of different victim and attacker placements on the chip and use the results to design a software-only mitigation mechanism.