MemJam: A False Dependency Attack Against Constant-Time Crypto Implementations in SGX

MemJam: A False Dependency Attack Against Constant-Time Crypto Implementations in SGX
复制标题

MemJam:针对新交所恒定时间加密实现的虚假依赖攻击

DOI:
--
复制
发表时间:
2018
期刊:
The Cryptographer's Track at RSA Conference
影响因子:
--
通讯作者:
B. Sunar
B. Sunar
中科院分区:
--
文献类型:
--
作者:
A. Moghimi;T. Eisenbarth;B. Sunar

文献摘要

被引文献

相似文献

缓存攻击利用加密实现的内存访问模式。恒定时间实现技术已成为对抗缓存定时攻击不可或缺的工具。这些技术对加密操作的内存访问进行设计,以遵循统一的密钥独立模式。然而,恒定时间行为取决于底层架构,该架构可能非常复杂,并且通常包含未发布的功能。 CacheBleed 攻击针对的是缓存组冲突,从而使微架构侧通道攻击者只能以缓存行粒度观察内存的假设无效。在这项工作中,我们提出了 MemJam,这是一种侧通道攻击,它利用内存写入后读取的错误依赖性,并提供高质量的内部缓存级时序通道。作为概念验证,我们演示了对 AES 恒定时间实现的首次密钥恢复攻击,以及当前英特尔集成性能基元(英特尔 IPP)加密库中具有缓存保护的 SM4 实现。此外,我们通过在使用上述 AES 恒定时间实现执行加密的 enclave 上重现 AES 密钥恢复结果,演示了对 SGX 的首次内部缓存级定时攻击。我们的结果表明,我们不仅可以使用此侧通道有效地攻击依赖于内存的加密操作,还可以绕过建议的保护。与仅限于旧处理器的 CacheBleed 相比,MemJam 是第一个适用于所有主要 Intel 处理器(包括支持 SGX 扩展的最新一代处理器)的内部缓存级攻击。
Cache attacks exploit memory access patterns of cryptographic implementations. Constant-Time implementation techniques have become an indispensable tool in fighting cache timing attacks. These techniques engineer the memory accesses of cryptographic operations to follow a uniform key independent pattern. However, the constant-time behavior is dependent on the underlying architecture, which can be highly complex and often incorporates unpublished features. CacheBleed attack targets cache bank conflicts and thereby invalidates the assumption that microarchitectural side-channel adversaries can only observe memory with cache line granularity. In this work, we propose MemJam, a side-channel attack that exploits false dependency of memory read-after-write and provides a high quality intra cache level timing channel. As a proof of concept, we demonstrate the first key recovery attacks on a constant-time implementation of AES, and a SM4 implementation with cache protection in the current Intel Integrated Performance Primitives (Intel IPP) cryptographic library. Further, we demonstrate the first intra cache level timing attack on SGX by reproducing the AES key recovery results on an enclave that performs encryption using the aforementioned constant-time implementation of AES. Our results show that we can not only use this side channel to efficiently attack memory dependent cryptographic operations but also to bypass proposed protections. Compared to CacheBleed, which is limited to older processor generations, MemJam is the first intra cache level attack applicable to all major Intel processors including the latest generations that support the SGX extension.