Load-Step: A Precise TrustZone Execution Control Framework for Exploring New Side-channel Attacks Like Flush+Evict
Zili Kou, Wenjian He, Sharad Sinha, Wei Zhang
Abstract
Trusted execution environments (TEEs) are imported into processors to protect sensitive programs against a potentially malicious operating system (OS), though, they are announced not effective in defending microarchitecture ( arch) side-channel attacks. Furthermore, TEE attackers often utilize their high privilege to strengthen attacks by interrupting the execution of victim programs. Maximum temporal resolution is achieved on the x86 platform, which interrupts and measures by every instruction. However, the capability of arch side-channel attacks and the precision a kernel-privileged attacker can achieve in the TrustZone system are still unexplored. In this paper, we propose Load-Step, a precise framework that periodically interrupts the victim program in the TrustZone system and then conducts arch side-channel attacks. Our self-designed benchmark shows that Load-Step can invoke interrupts with load-instruction precision. Based on Load-Step, we present Flush+Evict, a new side-channel attack detecting the Arm Cache Coherent Interconnect (ArmCCI). It outperforms Prime+Probe with much higher precision and 282 % of the profiling speed. When attacking the RSA decryption in the latest MbedTLS library, Load-Step can recover the full key by only a single trace in 7.5 seconds. Our work thus breaches the exponent blinding, which aims to defend RSA decryption against side-channel attacks in the MbedTLS library.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f0361abc-8ac2-47be-ad63-1024ce9027f2Cited by top-tier papers5
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 15 citations
- M-Step: A Single-Stepping Framework for Side-Channel Analysis on TrustZone-MCristiano Rodrigues, Marton Bognar, Sandro Pinto, Jo Van BulckUSENIX Security 2026
- AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX EnclavesScott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao et al.USENIX Security 2023
- Secure Caches for Compartmentalized SoftwareKerem Arikan, Huaxin Tang, Williams Zhang Cen, Yu David Liu et al.USENIX Security 2025
- DNN Latency Sequencing: Extracting DNN Architectures from Intel SGX Enclaves with Single-Stepping AttacksMinkyung Park, Zelun Kong, DaveTian, Z. Berkay Celik et al.NDSS 2026
Related papers
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 90 citations
- TDXploit: Novel Techniques for Single-Stepping and Cache Attacks on Intel TDXFabian Rauscher, Luca Wilke, Hannes Weissteiner, Thomas Eisenbarth et al.USENIX Security 2025
- TEEcorrelate: An Information-Preserving Defense against Performance-Counter Attacks on TEEsHannes Weissteiner, Fabian Rauscher, Robin Leander Schröder, Jonas Juffinger et al.USENIX Security 2025
- A Systematic Evaluation of Novel and Existing Cache Side ChannelsFabian Rauscher, Carina Fiedler, Andreas Kogler, Daniel GrussNDSS 2025
- Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android DevicesXiaokuan Zhang, Yuan Xiao, Yinqian ZhangCCS 2016 · 77 citations
