USENIX Security2021Top-tier venue
VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface
Zitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean, David F. Oswald, Flavio D. Garcia
Abstract
Hardware-based fault injection attacks such as voltage and clock glitching have been thoroughly studied on embedded devices. Typical targets for such attacks include smartcards and low-power microcontrollers used in IoT devices. This paper presents the first hardware-based voltage glitching attack against a fully-fledged Intel CPU. The transition to complex CPUs is not trivial due to several factors, including: a complex operating system, large power consumption, multi-threading, and high clock speeds. To this end, we have built VoltPillager, a low-cost tool for injecting messages on the Serial Voltage Identification bus between the CPU and the voltage regulator on the motherboard. This allows us to precisely control the CPU core voltage. We leverage this powerful tool to mount fault-injection attacks that breach confidentiality and integrity of Intel SGX enclaves. We present proof-of-concept key-recovery attacks against cryptographic algorithms running inside SGX. We demonstrate that VoltPillager attacks are more powerful than recent software-only undervolting attacks against SGX (CVE-2019-11157) because they work on fully patched systems with all countermeasures against software undervolting enabled. Additionally, we are able to fault securitycritical operations by delaying memory writes. Mitigation of VoltPillager is not straightforward and may require a rethink of the SGX adversarial model where a cloud provider is untrusted and has physical access to the hardware. Our Contribution In this paper, we analyse the dynamic voltage scaling features of x86 systems at the hardware level. We found that a three-wire bus, Serial Voltage Identification (SVID), is used to send the currently required voltage to an external Voltage Regulator (VR) chip on the motherboard. The VR then adjusts the voltage supplied to the CPU. We reverse-engineered the communication protocol of SVID and developed a small microcontroller-based board that can be connected to the SVID bus. As there is no cryptographic authentication of the SVID packets, we were able to inject our own commands to control the CPU voltage. With this, we reproduced Plundervolt's [37] open-source Proof-of-Concept (PoC) attacks, including against code running inside an SGX enclave. Beyond that, we also found (and document) faults not previously observed. These faults affect elementary operations such as memory accesses. Because the software interface MSR 0x150 is not used, Intel's countermeasures do not prevent this attack. The main contributions of this paper are: • We showcase the (to our knowledge) first hardware-based attack that directly breaches SGX's integrity guarantees. We demonstrate its practicality with end-to-end secret-key recovery attacks against mbed TLS and the unmodified file-encryptor sample enclave from Microsoft Open Enclave. • We show that Intel's countermeasures for CVE-2019-11157 do not prevent fault-injection attacks from adversaries with physical access. This challenges the widely accepted belief that SGX can protect enclave integrity against a malicious cloud provider (cf. e.g., [2, 5, 27, 8] ). • We demonstrate novel fault effects discovered through hardware-based undervolting, in particular by briefly delaying memory writes. • We present VoltPillager, an open-source hardware device to inject SVID packets. VoltPillager is based on a low-cost, widely available microcontroller board, the Teensy 4.0, and can be built for approximately $ 30. We also document the internal power management interfaces on modern motherboards, SVID and System Management Bus (SMBus).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 961e707f-c06b-4467-b8e0-82b63d87b5d3Cited by top-tier papers29
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik et al.S&P 2026 · 29 citations
- Snoopy: Surpassing the Scalability Bottleneck of Oblivious StorageEmma Dauterman, Vivian Fang, Ioannis Demertzis, Natacha Crooks et al.SOSP 2021 · 26 citations
- Private Web Search with TiptoeAlexandra Henzinger, Emma Dauterman, Henry Corrigan-Gibbs, Nickolai ZeldovichSOSP 2023 · 25 citations
- Pantheon: Private Retrieval from Public Key-Value StoreIshtiyaque Ahmad, Divyakant Agrawal, Amr El Abbadi, Trinabh GuptaVLDB 2023 · 23 citations
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 20 citations
Builds on11
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel et al.USENIX Security 2016 · 306 citations
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen et al.S&P 2020 · 274 citations
- RAMBleed: Reading Bits in Memory Without Accessing ThemAndrew Kwong, Daniel Genkin, Daniel Gruss, Yuval YaromS&P 2020 · 239 citations
Related papers
- V0LTpwn: Attacking x86 Processor Integrity from SoftwareZijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz et al.USENIX Security 2020
- Minefield: A Software-only Protection for SGX Enclaves against DVFS AttacksAndreas Kogler, Daniel Gruss, Michael SchwarzUSENIX Security 2022
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
- IntraFuzz: Coverage-Guided Intra-Enclave Fuzzing for Intel SGX ApplicationsJinhua Cui, Qiao Peng, Yiwen Yao, Ke Ye et al.DAC 2025 · 1 citation
- Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault AttacksNimish Mishra, Rahul Arvind Mool, Anirban Chakraborty, Debdeep MukhopadhyayDAC 2024 · 3 citations
