Synchronization Storage Channels (S2C): Timer-less Cache Side-Channel Attacks on the Apple M1 via Hardware Synchronization Instructions
Jiyong Yu, Aishani Dutta, Trent Jaeger, David Kohlbrenner, Christopher W. Fletcher
摘要
Shared caches have been a prime target for mounting crossprocess/core side-channel attacks. Fundamentally, these attacks require a mechanism to accurately observe changes in cache state. Most cache attacks rely on timing measurements to indirectly infer cache state changes, and attack success hinges on the reliability/availability of accurate timing sources. Far fewer techniques have been proposed to directly observe cache state changes without reliance on timers. Further, none of said 'timer-less' techniques are accessible to userspace attackers targeting modern CPUs. This paper proposes a novel technique for mounting timerless cache attacks targeting Apple M1 CPUs named Synchronization Storage Channels (S 2 C). The key observation is that the implementation of synchronization instructions, specifically Load-Linked/Store-Conditional (LL/SC), makes architectural state changes when L1 cache evictions occur. This by itself is a useful starting point for attacks, however faces multiple technical challenges when being used to perpetrate cross-core cache attacks. Specifically, LL/SC only observes L1 evictions (not shared L2 cache evictions). Further, each attacker thread can only simultaneously monitor one address at a time through LL/SC (as opposed to many). We propose a suite of techniques and reverse engineering to overcome these limitations, and demonstrate how a single-threaded userspace attacker can use LL/SC to simultaneously monitor multiple (up to 11) victim L2 sets and succeed at standard cache-attack applications, such as breaking cryptographic implementations and constructing covert channels.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent PrefetchersBoru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher 等USENIX Security 2024 · 被引用 52 次
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 被引用 17 次
- Invalidate+Compare: A Timer-Free GPU Cache Attack PrimitiveZhenkai Zhang, Kunbei Cai, Yanan Guo, Fan Yao 等USENIX Security 2024 · 被引用 15 次
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 被引用 6 次
- Controlled Preemption: Amplifying Side-Channel Attacks from UserspaceYongye Zhu, Boru Chen, Zirui Neil Zhao, Christopher W. FletcherASPLOS 2025 · 被引用 5 次
它引用的顶会 Paper26
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta 等USENIX Security 2016 · 被引用 594 次
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- ZeroTrace : Oblivious Memory Primitives from Intel SGXSajin Sasy, Sergey Gorbunov, Christopher W. FletcherNDSS 2018 · 被引用 244 次
相关 Paper
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 被引用 1 次
- Charting the Cache Side-Channel Frontier: A Systematic Study of Eviction Set Construction on Apple SiliconHan Wang, Yakun Wu, Yusi Feng, Yinqian ZhangUSENIX Security 2026
- SQUIP: Exploiting the Scheduler Queue Contention Side ChannelStefan Gast, Jonas Juffinger, Martin Schwarzl, Gururaj Saileshwar 等S&P 2023
- Uncovering Software-Based Power Side-Channel Attacks on Apple M1/M2 SystemsNikhil Chawla, Chen Liu, Abhishek Chakraborty, Igor Chervatyuk 等DAC 2024 · 被引用 2 次
- SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple SiliconTianhong Xu, Saion Kumar Roy, Ruyi Ding, A. Adam Ding 等CCS 2026
