The 9 Lives of Bleichenbacher's CAT: New Cache ATtacks on TLS Implementations
Eyal Ronen, Robert Gillham, Daniel Genkin, Adi Shamir, David Wong, Yuval Yarom
摘要
At CRYPTO'98, Bleichenbacher published his seminal paper which described a padding oracle attack against RSA implementations that follow the PKCS #1 v1.5 standard. Over the last twenty years researchers and implementors had spent a huge amount of effort in developing and deploying numerous mitigation techniques which were supposed to plug all the possible sources of Bleichenbacher-like leakages. However, as we show in this paper, most implementations are still vulnerable to several novel types of attack based on leakage from various microarchitectural side channels: Out of nine popular implementations of TLS that we tested, we were able to break the security of seven implementations with practical proof-of-concept attacks. We demonstrate the feasibility of using those Cache-like ATacks (CATs) to perform a downgrade attack against any TLS connection to a vulnerable server, using a BEAST-like Man in the Browser attack. The main difficulty we face is how to perform the thousands of oracle queries required before the browser's imposed timeout (which is 30 seconds for almost all browsers, with the exception of Firefox which can be tricked into extending this period). Due to its use of adaptive chosen ciphertext queries, the attack seems to be inherently sequential, but we describe a new way to parallelize Bleichenbacher-like padding attacks by exploiting any available number of TLS servers that share the same public key certificate. With this improvement, we can demonstrate the feasibility of a downgrade attack which could recover all the 2048 bits of the RSA plaintext (including the premaster secret value, which suffices to establish a secure connection) from five available TLS servers in under 30 seconds. This sequential-to-parallel transformation of such attacks can be of independent interest, speeding up and facilitating other side channel attacks on RSA implementations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper21
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 被引用 146 次
- Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel DefensesAnatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin 等USENIX Security 2021 · 被引用 73 次
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 被引用 48 次
- Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)Robert Merget, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky 等USENIX Security 2021 · 被引用 36 次
- Spook.js: Attacking Chrome Strict Site Isolation via Speculative ExecutionAyush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel 等S&P 2022 · 被引用 32 次
它引用的顶会 Paper11
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSXCraig Disselkoen, David Kohlbrenner, Leo Porter, Dean M. TullsenUSENIX Security 2017 · 被引用 186 次
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 被引用 141 次
- A Systematic Analysis of the Juniper Dual EC IncidentStephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried 等CCS 2016 · 被引用 91 次
相关 Paper
- Return Of Bleichenbacher's Oracle Threat (ROBOT)Hanno Böck, Juraj Somorovsky, Craig YoungUSENIX Security 2018 · 被引用 69 次
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger 等USENIX Security 2016 · 被引用 192 次
- Windows into the Past: Exploiting Legacy Crypto in Modern OS's Kerberos ImplementationMichal Shagam, Eyal RonenUSENIX Security 2024
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 被引用 93 次
- Pseudorandom Black Swans: Cache Attacks on CTR_DRBGShaanan Cohney, Andrew Kwong, Shahar Paz, Daniel Genkin 等S&P 2020 · 被引用 36 次
