USENIX Security2018Top-tier venue
A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping
Seunghun Han, Wook Shin, Jun-Hyeok Park, Hyoung-Chun Kim
Abstract
This paper reports two sorts of Trusted Platform Module (TPM) attacks regarding power management. The attacks allow an adversary to reset and forge platform configuration registers which are designed to securely hold measurements of software that are used for bootstrapping a computer. One attack is exploiting a design flaw in the TPM 2.0 specification for the static root of trust for measurement (SRTM). The other attack is exploiting an implementation flaw in tboot, the most popular measured launched environment used with Intel's Trusted Execution Technology. Considering TPM-based platform integrity protection is widely used, the attacks may affect a large number of devices. We demonstrate the attacks with commodity hardware. The SRTM attack is significant because its countermeasure requires hardwarespecific firmware patches that could take a long time to be applied.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3ddfc772-d143-4758-aa6a-4d1a1ce82b0cCited by top-tier papers4
- simTPM: User-centric TPM for Mobile DevicesDhiman Chakraborty, Lucjan Hanzlik, Sven BugielUSENIX Security 2019 · 26 citations
- SafetyPin: Encrypted Backups with Human-Memorable SecretsEmma Dauterman, Henry Corrigan-Gibbs, David MazièresOSDI 2020 · 22 citations
- FIDO2 the Rescue? Platform vs. Roaming Authentication on SmartphonesLeon Würsching, Florentin Putz, Steffen Haesler, Matthias HollickCHI 2023 · 15 citations
- TPM-FAIL: TPM meets Timing and Lattice AttacksDaniel Moghimi, Berk Sunar, Thomas Eisenbarth, Nadia HeningerUSENIX Security 2020
Related papers
- V0LTpwn: Attacking x86 Processor Integrity from SoftwareZijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz et al.USENIX Security 2020
- fTPM: A Software-Only Implementation of a TPM ChipHimanshu Raj, Stefan Saroiu, Alec Wolman, Ronald Aigner et al.USENIX Security 2016 · 105 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- TDXploit: Novel Techniques for Single-Stepping and Cache Attacks on Intel TDXFabian Rauscher, Luca Wilke, Hannes Weissteiner, Thomas Eisenbarth et al.USENIX Security 2025
