Standardizing Bad Cryptographic Practice: A Teardown of the IEEE Standard for Protecting Electronic-design Intellectual Property

Standardizing Bad Cryptographic Practice: A Teardown of the IEEE Standard for Protecting Electronic-design Intellectual Property
复制标题

DOI:
10.1145/3133956.3134040
复制
发表时间:
2017-10
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor
Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor
中科院分区:
其他
文献类型:
--
作者:
Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor

文献摘要

相似文献

我们提供了一个分析IEEE标准P1735,它描述了加密电子设计知识产权(IP)的方法,以及这样的IP访问权限的管理。我们在标准中发现了数量惊人的密码错误。在最严重的情况下,这些错误会使攻击向量允许我们恢复整个底层明文IP。这些攻击向量中的一些是众所周知的,例如padding-oracle攻击。其他是新的,并且由于需要支持底层IP的典型用途而成为可能;特别是需要商业片上系统(SoC)工具将多个IP合成为完全指定的芯片设计并提供语法错误。我们以各种方式利用这些错误,利用商业SoC工具作为黑盒预言机。除了能够恢复整个明文IP,我们展示了如何产生符合标准的IP密文已被修改,包括有针对性的硬件木马。例如,在除了一个(任意)明文之外的所有明文上正确实现AES分组密码的IP,该明文导致分组密码返回秘密密钥。我们概述了该标准允许的其他一些攻击,包括IP许可的加密机制。不幸的是,我们表明,对标准(以及支持它的工具)的明显“快速修复”并不能阻止我们所有的攻击。这表明该标准需要进行重大改革,使用P1735加密的IP作者应该考虑自己的风险。
We provide an analysis of IEEE standard P1735, which describes methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP. We find a surprising number of cryptographic mistakes in the standard. In the most egregious cases, these mistakes enable attack vectors that allow us to recover the entire underlying plaintext IP. Some of these attack vectors are well-known, e.g. padding-oracle attacks. Others are new, and are made possible by the need to support the typical uses of the underlying IP; in particular, the need for commercial system-on-chip (SoC) tools to synthesize multiple pieces of IP into a fully specified chip design and to provide syntax errors. We exploit these mistakes in a variety of ways, leveraging a commercial SoC tool as a black-box oracle. In addition to being able to recover entire plaintext IP, we show how to produce standard-compliant ciphertexts of IP that have been modified to include targeted hardware Trojans. For example, IP that correctly implements the AES block cipher on all but one (arbitrary) plaintext that induces the block cipher to return the secret key. We outline a number of other attacks that the standard allows, including on the cryptographic mechanism for IP licensing. Unfortunately, we show that obvious "quick fixes" to the standard (and the tools that support it) do not stop all of our attacks. This suggests that the standard requires a significant overhaul, and that IP-authors using P1735 encryption should consider themselves at risk.