Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86
Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86
复制标题
DOI:
10.1109/mm.2023.3274619
复制
发表时间:
2023-07
期刊:
影响因子:
3.6
通讯作者:
Yingchen Wang;Riccardo Paccagnella;Elizabeth Tang He;H. Shacham;Christopher W. Fletcher;David Kohlbrenner
中科院分区:
文献类型:
--
作者:
Yingchen Wang;Riccardo Paccagnella;Elizabeth Tang He;H. Shacham;Christopher W. Fletcher;David Kohlbrenner
Power side-channel attacks exploit data-dependent variations in a CPU’s power consumption to leak secrets. In this article, we show that on modern CPUs, power side-channel attacks can be turned into timing attacks that can be mounted without access to any power measurement interface. This discovery exploits how, under certain circumstances, the dynamic frequency scaling of modern x86 CPU depends on the current power consumption (and hence, data). We demonstrate that this “frequency side channel” is a real threat to the security of cryptographic software. First, we reverse engineer the dependency between data, power, and frequency on a modern x86 CPU—finding, among other things, that differences as small as a set bit’s position in a word can be distinguished through frequency changes. Second, we describe a novel chosen-ciphertext attack against (constant-time implementations of) supersingular isogeny key encapsulation that allows full key extraction via remote timing.