VoltJockey: Breaching TrustZone by Software-Controlled Voltage Manipulation over Multi-core Frequencies
Pengfei Qiu, Dongsheng Wang, Yongqiang Lyu, Gang Qu
Abstract
ARM TrustZone builds a trusted execution environment based on the concept of hardware separation. It has been quite successful in defending against various software attacks and forcing attackers to explore vulnerabilities in interface designs and side channels. The recently reported CLKscrew attack breaks TrustZone through software by overclocking CPU to generate hardware faults. However, overclocking makes the processor run at a very high frequency, which is relatively easy to detect and prevent, for example by hardware frequency locking. In this paper, we propose an innovative software-controlled hardware fault-based attack, VoltJockey, on multi-core processors that adopt dynamic voltage and frequency scaling (DVFS) techniques for energy efficiency. Unlike CLKscrew, we manipulate the voltages rather than the frequencies via DVFS unit to generate hardware faults on the victim cores, which makes VoltJockey stealthier and harder to prevent than CLKscrew. We deliberately control the fault generation to facilitate differential fault analysis to break TrustZone. The entire attack process is based on software without any involvement of hardware. We implement VoltJockey on an ARM-based Krait processor from a commodity Android phone and demonstrate how to reveal the AES key from TrustZone and how to breach the RSA-based TrustZone authentication. These results suggest that VoltJockey has a comparable efficiency to side channels in obtaining TrustZone-guarded credentials, as well as the potential of bypassing the RSA-based verification to load untrusted applications into TrustZone. We also discuss both hardware-based and software-based countermeasures and their limitations.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 563d81d3-00fc-4c4d-8a7b-17c922576bdbCited by top-tier papers18
- VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interfaceZitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean et al.USENIX Security 2021 · 127 citations
- SoK: SGX.Fail: How Stuff Gets eXposedStephan van Schaik, Alexander Seto, Thomas Yurek, Adam Batori et al.S&P 2024 · 52 citations
- On the Usability of Authenticity Checks for Hardware Security TokensKatharina Pfeffer, Alexandra Mai, Adrian Dabrowski, Matthias Gusenbauer et al.USENIX Security 2021 · 12 citations
- UnTrustZone: Systematic Accelerated Aging to Expose On-chip SecretsJubayer Mahmod, Matthew HicksS&P 2024 · 11 citations
- SUIT: Secure Undervolting with Instruction TrapsJonas Juffinger, Stepan Kalinin, Daniel Gruss, Frank MuellerASPLOS 2024 · 4 citations
Related papers
- CLKSCREW: Exposing the Perils of Security-Oblivious Energy ManagementAdrian Tang, Simha Sethumadhavan, Salvatore J. StolfoUSENIX Security 2017
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault AttacksNimish Mishra, Rahul Arvind Mool, Anirban Chakraborty, Debdeep MukhopadhyayDAC 2024 · 3 citations
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 90 citations
- Oops..! I Glitched It Again! How to Multi-Glitch the Glitching-Protections on ARM TrustZone-MXhani Marvin Saß, Richard Mitev, Ahmad-Reza SadeghiUSENIX Security 2023
