Pseudo Constant Time Implementations of TLS Are Only Pseudo Secure
Eyal Ronen, Kenneth G. Paterson, Adi Shamir
Abstract
Today, about 10% of TLS connections are still using CBC-mode cipher suites, despite a long history of attacks and the availability of better options (e.g. AES-GCM). In this work, we present three new types of attack against four popular fully patched implementations of TLS (Amazon's s2n, GnuTLS, mbed TLS and wolfSSL) which elected to use "pseudo constant time" countermeasures against the Lucky 13 attack on CBC-mode. Our attacks combine several variants of the PRIME+PROBE cache timing technique with a new extension of the original Lucky 13 attack. They apply in a cross-VM attack setting and are capable of recovering most of the plaintext whilst requiring only a moderate number of TLS connections. Along the way, we uncovered additional serious (but easy to patch) bugs in all four of the TLS implementations that we studied; in three cases, these bugs lead to Lucky 13 style attacks that can be mounted remotely with no access to a shared cache. Our work shows that adopting pseudo constant time countermeasures is not sufficient to attain real security in TLS implementations in CBC mode.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1b6f7af6-8103-4880-a1c1-e6fcea6cff7aCited by top-tier papers18
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 146 citations
- Formal verification of a constant-time preserving C compilerGilles Barthe, Sandrine Blazy, Benjamin Grégoire, Rémi Hutin et al.POPL 2020 · 77 citations
- Binsec/Rel: Efficient Relational Symbolic Execution for Constant-Time at Binary-LevelLesly-Ann Daniel, Sébastien Bardin, Tamara RezkS&P 2020 · 76 citations
- The 9 Lives of Bleichenbacher's CAT: New Cache ATtacks on TLS ImplementationsEyal Ronen, Robert Gillham, Daniel Genkin, Adi Shamir et al.S&P 2019 · 59 citations
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 57 citations
Builds on6
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
- STACCO: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure EnclavesYuan Xiao, Mengyuan Li, Sanchuan Chen, Yinqian ZhangCCS 2017 · 77 citations
Related papers
- Multi-User Security of CCM Authenticated Encryption ModeXiangyang Zhang, Yaobin Shen, Lei WangCCS 2024 · 2 citations
- The Security of ChaCha20-Poly1305 in the Multi-User SettingJean Paul Degabriele, Jérôme Govinden, Felix Günther, Kenneth G. PatersonCCS 2021 · 23 citations
- With Great Power Come Great Side Channels: Statistical Timing Side-Channel Analyses with Bounded Type-1 ErrorsMartin Dunsche, Marcel Maehren, Nurullah Erinola, Robert Merget et al.USENIX Security 2024 · 5 citations
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young et al.USENIX Security 2019 · 27 citations
- The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce RandomizationViet Tung Hoang, Stefano Tessaro, Aishwarya ThiruvengadamCCS 2018 · 39 citations
