M-Step: A Single-Stepping Framework for Side-Channel Analysis on TrustZone-M
Cristiano Rodrigues, Marton Bognar, Sandro Pinto, Jo Van Bulck
摘要
Trusted Execution Environments (TEEs) have become a key technology for isolating sensitive enclave applications from untrusted operating systems. Extensive research on high-end platforms like Intel SGX and TDX, AMD SEV, and Arm TrustZone-A has exposed their limitations in terms of software-based side-channel analysis, amplified by specialized single-stepping attack frameworks that exploit privileged timer interrupts to execute enclaves one instruction at a time. Meanwhile, TEEs are increasingly deployed on resource-constrained IoT devices, with Arm TrustZone-M emerging as a leading solution, which, however, remains largely unexplored for high-resolution, software-based side channels. This paper presents M-Step, an open and extensible single-stepping attack framework for TrustZone-M. While Cortex-M microcontrollers feature precise timers and deterministic behavior, achieving precise, instruction-level stepping remains challenging due to (i) the absence of virtual memory and page tables used in high-end frameworks; and (ii) Cortex-M's unique interrupt behavior, where certain multi-cycle instructions are abandoned or paused to reduce latency. To overcome these challenges, we extensively profile interrupt handling CPU behavior and develop a novel approach that uses previously dismissed interrupt-latency leakage to dynamically adjust the timer interrupts. We demonstrate M-Step's improved resolution and practicality by discovering previously unknown vulnerabilities in the latest Arm Mbed TLS library that enable single-trace, deterministic attacks recovering full RSA keys from a TrustZone enclave.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper22
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens 等USENIX Security 2017 · 被引用 316 次
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García 等S&P 2019 · 被引用 240 次
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 被引用 231 次
相关 Paper
- Load-Step: A Precise TrustZone Execution Control Framework for Exploring New Side-channel Attacks Like Flush+EvictZili Kou, Wenjian He, Sharad Sinha, Wei ZhangDAC 2021 · 被引用 23 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
- TDXdown: Single-Stepping and Instruction Counting Attacks against Intel TDXLuca Wilke, Florian Sieck, Thomas EisenbarthCCS 2024 · 被引用 9 次
- AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX EnclavesScott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao 等USENIX Security 2023
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 被引用 15 次
