VoltJockey: Breaching TrustZone by Software-Controlled Voltage Manipulation over Multi-core Frequencies
Pengfei Qiu, Dongsheng Wang, Yongqiang Lyu, Gang Qu
摘要
ARM TrustZone builds a trusted execution environment based on the concept of hardware separation. It has been quite successful in defending against various software attacks and forcing attackers to explore vulnerabilities in interface designs and side channels. The recently reported CLKscrew attack breaks TrustZone through software by overclocking CPU to generate hardware faults. However, overclocking makes the processor run at a very high frequency, which is relatively easy to detect and prevent, for example by hardware frequency locking. In this paper, we propose an innovative software-controlled hardware fault-based attack, VoltJockey, on multi-core processors that adopt dynamic voltage and frequency scaling (DVFS) techniques for energy efficiency. Unlike CLKscrew, we manipulate the voltages rather than the frequencies via DVFS unit to generate hardware faults on the victim cores, which makes VoltJockey stealthier and harder to prevent than CLKscrew. We deliberately control the fault generation to facilitate differential fault analysis to break TrustZone. The entire attack process is based on software without any involvement of hardware. We implement VoltJockey on an ARM-based Krait processor from a commodity Android phone and demonstrate how to reveal the AES key from TrustZone and how to breach the RSA-based TrustZone authentication. These results suggest that VoltJockey has a comparable efficiency to side channels in obtaining TrustZone-guarded credentials, as well as the potential of bypassing the RSA-based verification to load untrusted applications into TrustZone. We also discuss both hardware-based and software-based countermeasures and their limitations.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper18
- VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interfaceZitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean 等USENIX Security 2021 · 被引用 127 次
- SoK: SGX.Fail: How Stuff Gets eXposedStephan van Schaik, Alexander Seto, Thomas Yurek, Adam Batori 等S&P 2024 · 被引用 52 次
- On the Usability of Authenticity Checks for Hardware Security TokensKatharina Pfeffer, Alexandra Mai, Adrian Dabrowski, Matthias Gusenbauer 等USENIX Security 2021 · 被引用 12 次
- UnTrustZone: Systematic Accelerated Aging to Expose On-chip SecretsJubayer Mahmod, Matthew HicksS&P 2024 · 被引用 11 次
- SUIT: Secure Undervolting with Instruction TrapsJonas Juffinger, Stepan Kalinin, Daniel Gruss, Frank MuellerASPLOS 2024 · 被引用 4 次
相关 Paper
- CLKSCREW: Exposing the Perils of Security-Oblivious Energy ManagementAdrian Tang, Simha Sethumadhavan, Salvatore J. StolfoUSENIX Security 2017
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck 等S&P 2020 · 被引用 369 次
- Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault AttacksNimish Mishra, Rahul Arvind Mool, Anirban Chakraborty, Debdeep MukhopadhyayDAC 2024 · 被引用 3 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
- Oops..! I Glitched It Again! How to Multi-Glitch the Glitching-Protections on ARM TrustZone-MXhani Marvin Saß, Richard Mitev, Ahmad-Reza SadeghiUSENIX Security 2023
