STACCO: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure Enclaves
Yuan Xiao, Mengyuan Li, Sanchuan Chen, Yinqian Zhang
Abstract
Intel Software Guard Extension (SGX) offers software applications a shielded execution environment, dubbed enclave, to protect their confidentiality and integrity from malicious operating systems. As processors with this extended feature become commercially available, many new software applications are developed to enrich to the SGX-enabled ecosystem. One important primitive for these applications is a secure communication channel between the enclave and a remote trusted party. The SSL/TLS protocol, which is the de facto standard for protecting transport-layer network communications, has been broadly regarded a natural choice for such purposes. However, in this paper, we show that the marriage between SGX and SSL may not be smooth sailing. Particularly, we consider a category of side-channel attacks against SSL/TLS implementations in secure enclaves, which we call the control-flow inference attacks. In these attacks, the malicious operating system kernel may perform a powerful man-in-the-kernel attack to collect execution traces of the enclave programs at the page level, the cacheline level, or the branch level, while positioning itself in the middle of the two communicating parties. At the center of our work is a differential analysis framework, dubbed Stacco, to dynamically analyze the SSL/TLS implementations and detect vulnerabilities-discernible execution traces-that can be exploited as decryption oracles. Surprisingly, in spite of the prevailing constant-time programming paradigm adopted by many cryptographic libraries, we found exploitable vulnerabilities in the latest versions of all the SSL/TLS libraries we have examined. To validate the detected vulnerabilities, we developed a man-in-the-kernel adversary to demonstrate Bleichenbacher attacks against the latest OpenSSL library running in the SGX enclave (with the help of Graphene) and completely broke the PreMasterSecret encrypted by a 4096-bit RSA public key with only 57286 queries. We also conducted CBC padding oracle attacks against the latest GnuTLS running in Graphene-SGX and an open-source SGX implementation of mbedTLS (i.e., mbedTLS-SGX) that runs directly inside the enclave, and showed that it only needs 48388 and 25717 queries, respectively, to break one block of AES ciphertext. Empirical evaluation suggests these man-in-the-kernel attacks can be completed within 1 or 2 hours. Our results reveal the insufficient understanding of side-channel security in SGX settings, and our study will provoke discussions on the secure implementation and adoption of SSL/TLS in secure enclaves.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 37326bd6-d838-4657-a27b-90bc19d1cca6Cited by top-tier papers23
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz et al.USENIX Security 2019 · 221 citations
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang et al.OSDI 2021 · 126 citations
- CaSym: Cache Aware Symbolic Execution for Side Channel Detection and MitigationRobert Brotzman, Shen Liu, Danfeng Zhang, Gang Tan et al.S&P 2019 · 77 citations
- DATA - Differential Address Trace Analysis: Finding Address-based Side-Channels in BinariesSamuel Weiser, Andreas Zankl, Raphael Spreitzer, Katja Miller et al.USENIX Security 2018 · 77 citations
Builds on12
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels et al.CCS 2016 · 668 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta et al.USENIX Security 2016 · 594 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
Related papers
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens et al.USENIX Security 2017 · 316 citations
- Frontal Attack: Leaking Control-Flow in SGX via the CPU FrontendIvan Puddu, Moritz Schneider, Miro Haller, Srdjan CapkunUSENIX Security 2021 · 63 citations
- SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic ExecutionDaniel Weber, Lukas Gerlach, Leon Trampert, Youheng Lü et al.USENIX Security 2025
- Klotski: Efficient Obfuscated Execution against Controlled-Channel AttacksPan Zhang, Chengyu Song, Heng Yin, Deqing Zou et al.ASPLOS 2020 · 14 citations
- TLBlur: Compiler-Assisted Automated Hardening against Controlled Channels on Off-the-Shelf Intel SGX PlatformsDaan Vanoverloop, Andrés Sánchez, Flavio Toffalini, Frank Piessens et al.USENIX Security 2025
