Ohm's Law in Data Centers: A Voltage Side Channel for Timing Power Attacks
Mohammad A. Islam, Shaolei Ren
摘要
Maliciously-injected power load, a.k.a. power attack, has recently surfaced as a new egregious attack vector for dangerously compromising the data center availability. This paper focuses on the emerging threat of power attacks in a multi-tenant colocation data center, an important type of data center where multiple tenants house their own servers and share the power distribution system. Concretely, we discover a novel physical side channel -a voltage side channel -which leaks the benign tenants' power usage information at runtime and helps an attacker precisely time its power attacks. The key idea we exploit is that, due to the Ohm's Law, the high-frequency switching operation (40 ∼ 100kHz) of the power factor correction circuit universally built in today's server power supply units creates voltage ripples in the data center power lines. Importantly, without overlapping the grid voltage in the frequency domain, the voltage ripple signals can be easily sensed by the attacker to track the benign tenants' runtime power usage and precisely time its power attacks. We evaluate the timing accuracy of the voltage side channel in a real data center prototype, demonstrating that the attacker can extract benign tenants' power pattern with a great accuracy (correlation coefficient = 0.90+) and utilize 64% of all the attack opportunities without launching attacks randomly or consecutively. Finally, we highlight a few possible defense strategies and extend our study to more complex three-phase power distribution systems used in large multi-tenant data centers. CCS CONCEPTS • Security and privacy → Side-channel analysis and countermeasures;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- PLATYPUS: Software-based Power Side-Channel Attacks on x86Moritz Lipp, Andreas Kogler, David F. Oswald, Michael Schwarz 等S&P 2021 · 被引用 242 次
- C3APSULe: Cross-FPGA Covert-Channel Attacks through Power Supply Unit LeakageIlias Giechaskiel, Kasper Bonne Rasmussen, Jakub SzeferS&P 2020 · 被引用 74 次
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom 等CCS 2019 · 被引用 62 次
- Heat Behind the Meter: A Hidden Threat of Thermal Attacks in Edge Colocation Data CentersZhihui Shao, Mohammad A. Islam, Shaolei RenHPCA 2021 · 被引用 10 次
- AquaSonic: Acoustic Manipulation of Underwater Data Center Operations and Resource ManagementJennifer Sheldon, Weidong Zhu, Adnan Abdullah, Sri Hrushikesh Varma Bhupathiraju 等S&P 2024 · 被引用 5 次
它引用的顶会 Paper2
相关 Paper
- DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioFan Zhang, Zhiyong Wang, Haoting Shen, Bolin Yang 等DAC 2022 · 被引用 8 次
- Exploration of Power Side-Channel Vulnerabilities in Quantum Computer ControllersChuanqi Xu, Ferhat Erata, Jakub SzeferCCS 2023 · 被引用 26 次
- Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham 等USENIX Security 2022
- Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel AttacksJiaxin Jiang, Xutong Zhang, Jiahao Li, Leqi Zhao 等WWW 2026
- LeakyDSP: Exploiting Digital Signal Processing Blocks to Sense Voltage Fluctuations in FPGAsXin Zhang, Jiajun Zou, Yi Yang, Qingni Shen 等DAC 2025
