CipherH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations
Sen Deng, Mengyuan Li, Yining Tang, Shuai Wang, Shoumeng Yan, Yinqian Zhang
摘要
The ciphertext side channel is a new type of side channels that exploits deterministic memory encryption of trusted execution environments (TEE). It enables the adversary with read accesses to the ciphertext of the encrypted memory, either logically or physically, to compromise cryptographic implementations protected by TEEs with high fidelity. Prior studies have concluded that the ciphertext side channel is a severe threat to not only AMD SEV-SNP, where the vulnerability was first discovered, but to all TEEs with deterministic memory encryption. In this paper, we propose CIPHERH, a practical framework for automating the analysis of cryptographic software and detecting program points vulnerable to ciphertext side channels. CIPHERH is designed to perform a practical hybrid analysis in production cryptographic software, with a speedy dynamic taint analysis to track the usage of secrets throughout the entire program and a static symbolic execution procedure on each "tainted" function to reason about ciphertext side-channel vulnerabilities using symbolic constraint. Empirical evaluation has led to the discovery of over 200 vulnerable program points from the state-of-the-art RSA and ECDSA/ECDH implementations from OpenSSL, MbedTLS, and WolfSSL. Representative cases have been reported to and confirmed or patched by the developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM AgentsFabian Schwarz, Christian RossowUSENIX Security 2024 · 被引用 10 次
- HyperTheft: Thieving Model Weights from TEE-Shielded Neural Networks via Ciphertext Side ChannelsYuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen 等CCS 2024 · 被引用 8 次
- Testing Side-channel Security of Cryptographic Implementations against Future MicroarchitecturesGilles Barthe, Marcel Böhme, Sunjay Cauligi, Chitchanok Chuengsatiansup 等CCS 2024 · 被引用 6 次
- TensorShield: Safeguarding On-Device Inference by Shielding Critical DNN Tensors with TEETong Sun, Bowen Jiang, Hailong Lin, Borui Li 等CCS 2025 · 被引用 3 次
- StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack EngineRuiyi Zhang, Tristan Hornetz, Daniel Weber, Fabian Thomas 等USENIX Security 2026 · 被引用 1 次
它引用的顶会 Paper16
- CacheD: Identifying Cache-Based Timing Channels in Production SoftwareShuai Wang, Pei Wang, Xiao Liu, Danfeng Zhang 等USENIX Security 2017 · 被引用 130 次
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li 等USENIX Security 2021 · 被引用 130 次
- Exploiting Unprotected I/O Operations in AMD's Secure Encrypted VirtualizationMengyuan Li, Yinqian Zhang, Zhiqiang Lin, Yan SolihinUSENIX Security 2019 · 被引用 104 次
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth 等S&P 2022 · 被引用 87 次
- CaSym: Cache Aware Symbolic Execution for Side Channel Detection and MitigationRobert Brotzman, Shen Liu, Danfeng Zhang, Gang Tan 等S&P 2019 · 被引用 77 次
相关 Paper
- Cipherfix: Mitigating Ciphertext Side-Channel Attacks in SoftwareJan Wichelmann, Anna Pätschke, Luca Wilke, Thomas EisenbarthUSENIX Security 2023
- CipherSteal: Stealing Input Data from TEE-Shielded Neural Networks with Ciphertext Side ChannelsYuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen 等S&P 2025
- Identifying Cache-Based Side Channels through Secret-Augmented Abstract InterpretationShuai Wang, Yuyan Bao, Xiao Liu, Pei Wang 等USENIX Security 2019 · 被引用 57 次
- An Empirical Study Measuring In-The-Wild Cryptographic Microarchitectural Side-Channel PatchesSen Deng, Zhibo Liu, Shuai Wang, Yinqian ZhangCCS 2025
- SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMsRuiyi Zhang, Albert Cheu, Adrià Gascón, Daniel Moghimi 等NDSS 2026 · 被引用 7 次
