USENIX Security2020Top-tier venue
TPM-FAIL: TPM meets Timing and Lattice Attacks
Daniel Moghimi, Berk Sunar, Thomas Eisenbarth, Nadia Heninger
Abstract
Trusted Platform Module (TPM) serves as a hardware-based root of trust that protects cryptographic keys from privileged system and physical adversaries. In this work, we perform a black-box timing analysis of TPM 2.0 devices deployed on commodity computers. Our analysis reveals that some of these devices feature secret-dependent execution times during signature generation based on elliptic curves. In particular, we discovered timing leakage on an Intel firmware-based TPM as well as a hardware TPM. We show how this information allows an attacker to apply lattice techniques to recover 256-bit private keys for ECDSA and ECSchnorr signatures. On Intel fTPM, our key recovery succeeds after about 1,300 observations and in less than two minutes. Similarly, we extract the private ECDSA key from a hardware TPM manufactured by STMicroelectronics, which is certified at Common Criteria (CC) EAL 4+, after fewer than 40,000 observations. We further highlight the impact of these vulnerabilities by demonstrating a remote attack against a StrongSwan IPsec VPN that uses a TPM to generate the digital signatures for authentication. In this attack, the remote client recovers the server's private authentication key by timing only 45,000 authentication handshakes via a network connection. The vulnerabilities we have uncovered emphasize the difficulty of correctly implementing known constant-time techniques, and show the importance of evolutionary testing and transparent evaluation of cryptographic implementations. Even certified devices that claim resistance against attacks require additional scrutiny by the community and industry, as we learn more about these attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a66053da-f51d-4204-90be-ba884b747b39Cited by top-tier papers19
- LadderLeak: Breaking ECDSA with Less than One Bit of Nonce LeakageDiego F. Aranha, Felipe Rodrigues Novaes, Akira Takahashi, Mehdi Tibouchi et al.CCS 2020 · 58 citations
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 52 citations
- A Side Journey To TitanThomas Roche, Victor Lomné, Camille Mutschler, Laurent ImbertUSENIX Security 2021 · 49 citations
- On Bounded Distance Decoding with Predicate: Breaking the "Lattice Barrier" for the Hidden Number ProblemMartin R. Albrecht, Nadia HeningerEUROCRYPT 2021 · 31 citations
- DICE*: A Formally Verified Implementation of DICE Measured BootZhe Tao, Aseem Rastogi, Naman Gupta, Kapil Vaswani et al.USENIX Security 2021 · 25 citations
Builds on6
- The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA ModuliMatús Nemec, Marek Sýs, Petr Svenda, Dusan Klinec et al.CCS 2017 · 147 citations
- fTPM: A Software-Only Implementation of a TPM ChipHimanshu Raj, Stefan Saroiu, Alec Wolman, Ronald Aigner et al.USENIX Security 2016 · 105 citations
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 93 citations
- The 9 Lives of Bleichenbacher's CAT: New Cache ATtacks on TLS ImplementationsEyal Ronen, Robert Gillham, Daniel Genkin, Adi Shamir et al.S&P 2019 · 59 citations
- Attacking OpenSSL Implementation of ECDSA with a Few SignaturesShuqin Fan, Wenbo Wang, Qingfeng ChengCCS 2016 · 44 citations
Related papers
- A Bad Dream: Subverting Trusted Platform Module While You Are SleepingSeunghun Han, Wook Shin, Jun-Hyeok Park, Hyoung-Chun KimUSENIX Security 2018 · 34 citations
- Constant-Time Callees with Variable-Time CallersCesar Pereida García, Billy Bob BrumleyUSENIX Security 2017 · 63 citations
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 90 citations
- One TPM to Bind Them All: Fixing TPM 2.0 for Provably Secure Anonymous AttestationJan Camenisch, Liqun Chen, Manu Drijvers, Anja Lehmann et al.S&P 2017 · 58 citations
- Util: : Lookup: Exploiting Key Decoding in Cryptographic LibrariesFlorian Sieck, Sebastian Berndt, Jan Wichelmann, Thomas EisenbarthCCS 2021 · 7 citations
