Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86

Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86
复制标题

DOI:
10.1109/mm.2023.3274619
复制
发表时间:
2023-07
期刊:
影响因子:
3.6
通讯作者:
Yingchen Wang;Riccardo Paccagnella;Elizabeth Tang He;H. Shacham;Christopher W. Fletcher;David Kohlbrenner
Yingchen Wang;Riccardo Paccagnella;Elizabeth Tang He;H. Shacham;Christopher W. Fletcher;David Kohlbrenner
中科院分区:
计算机科学3区
文献类型:
--
作者:
Yingchen Wang;Riccardo Paccagnella;Elizabeth Tang He;H. Shacham;Christopher W. Fletcher;David Kohlbrenner

文献摘要

相似文献

功率侧信道攻击利用CPU功耗中的数据依赖性变化来泄露秘密。在本文中,我们展示了在现代CPU上,功率侧信道攻击可以转化为定时攻击,可以在不访问任何功率测量接口的情况下进行安装。这一发现利用了在某些情况下,现代x86 CPU的动态频率缩放如何取决于当前功耗(以及数据)。我们证明了这种"频率边信道"对密码软件的安全性是一个真实的威胁。首先,我们对现代x86 CPU上的数据、功率和频率之间的依赖性进行了逆向工程,发现除其他外,可以通过频率变化来区分小到一个字中设置位位置的差异。其次,我们描述了一种新的选择密文攻击(恒定时间的实现)超奇异的iskey封装,允许通过远程定时完整的密钥提取。
Power side-channel attacks exploit data-dependent variations in a CPU’s power consumption to leak secrets. In this article, we show that on modern CPUs, power side-channel attacks can be turned into timing attacks that can be mounted without access to any power measurement interface. This discovery exploits how, under certain circumstances, the dynamic frequency scaling of modern x86 CPU depends on the current power consumption (and hence, data). We demonstrate that this “frequency side channel” is a real threat to the security of cryptographic software. First, we reverse engineer the dependency between data, power, and frequency on a modern x86 CPU—finding, among other things, that differences as small as a set bit’s position in a word can be distinguished through frequency changes. Second, we describe a novel chosen-ciphertext attack against (constant-time implementations of) supersingular isogeny key encapsulation that allows full key extraction via remote timing.