SEVurity: No Security Without Integrity : Breaking Integrity-Free Memory Encryption with Minimal Assumptions
Luca Wilke, Jan Wichelmann, Mathias Morbitzer, Thomas Eisenbarth
摘要
One reason for not adopting cloud services is the required trust in the cloud provider: As they control the hypervisor, any data processed in the system is accessible to them. Full memory encryption for Virtual Machines (VM) protects against curious cloud providers as well as otherwise compromised hypervisors. AMD Secure Encrypted Virtualization (SEV) is the most prevalent hardware-based full memory encryption for VMs. Its newest extension, SEV-ES, also protects the entire VM state during context switches, aiming to ensure that the host neither learns anything about the data that is processed inside the VM, nor is able to modify its execution state. Several previous works have analyzed the security of SEV and have shown that, by controlling I/O, it is possible to exfiltrate data or even gain control over the VM’s execution. In this work, we introduce two new methods that allow us to inject arbitrary code into SEV-ES secured virtual machines. Due to the lack of proper integrity protection, it is sufficient to reuse existing ciphertext to build a high-speed encryption oracle. As a result, our attack no longer depends on control over the I/O, which is needed by prior attacks. As I/O manipulation is highly detectable, our attacks are stealthier. In addition, we reverse-engineer the previously unknown, improved Xor-Encrypt-Xor (XEX) based encryption mode, that AMD is using on updated processors, and show, for the first time, how it can be overcome by our new attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper35
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li 等USENIX Security 2021 · 被引用 130 次
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth 等S&P 2022 · 被引用 87 次
- Design and Verification of the Arm Confidential Compute ArchitectureXupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu 等OSDI 2022 · 被引用 60 次
- SoK: SGX.Fail: How Stuff Gets eXposedStephan van Schaik, Alexander Seto, Thomas Yurek, Adam Batori 等S&P 2024 · 被引用 52 次
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi 等USENIX Security 2024 · 被引用 48 次
它引用的顶会 Paper2
- Exploiting Unprotected I/O Operations in AMD's Secure Encrypted VirtualizationMengyuan Li, Yinqian Zhang, Zhiqiang Lin, Yan SolihinUSENIX Security 2019 · 被引用 104 次
- Insecure Until Proven Updated: Analyzing AMD SEV's Remote AttestationRobert Buhren, Christian Werling, Jean-Pierre SeifertCCS 2019 · 被引用 60 次
相关 Paper
- CrossLine: Breaking "Security-by-Crash" based Memory Isolation in AMD SEVMengyuan Li, Yinqian Zhang, Zhiqiang LinCCS 2021 · 被引用 41 次
- Reload+Reload: Exploiting Cache and Memory Contention Side Channel on AMD SEVLi-Chung Chiang, Shih-Wei LiASPLOS 2025 · 被引用 8 次
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
- Nested SEV: Secure and Generic SEV Support for Nested VirtualizationKazuki Takiguchi, Kenichi KouraiOSDI 2026
- Heracles: Chosen Plaintext Attack on AMD SEV-SNPBenedict Schlüter, Christoph Wech, Shweta ShindeCCS 2025 · 被引用 1 次
