MetaLeak: Uncovering Side Channels in Secure Processor Architectures Exploiting Metadata
Md Hafizul Islam Chowdhuryy, Hao Zheng, Fan Yao
摘要
Microarchitectural side channels raise severe security concerns. Recent studies indicate that microarchitecture security should be examined holistically (rather than separately) in systems. Although the effects of performance optimizations on side channels are widely studied, the impacts of integrating security mechanisms intended for other threats on microarchitecture security are not well explored. In this paper, we perform the first side channel exploration in secure processor architectures that offer data confidentiality and integrity protection through hardware. We investigate microarchitecture security in the design space of secure processors and identify unique properties in the underlying metadata management schemes, which can be leveraged for new information leakage attacks. We present MetaLeak, an end-to-end side channel attack framework that exploits timing variations due to metadata maintenance to exfiltrate program secrets in secure processors. Particularly, we present two variants of the attack: MetaLeak-T that exploits the sharing of integrity tree metadata, and MetaLeak-C that manipulates counter metadata states. Our evaluation first shows highly accurate covert communication using the security metadata that can operate across cores and sockets without explicit data sharing. We further perform extensive side channel case studies on state-of-the-art secure architecture designs as well as the SGX processors. Our results show that MetaLeak can successfully exfiltrate program secrets (up to accuracy) from image-processing application and cryptographic software running in enclave. Our study indicates that the fundamental metadata mechanism is the root cause of the leakage, which necessitates the use of leakage-taming techniques in future secure processors. This work highlights the need to synergistically understand microarchitecture security, as new security mechanisms are integrated.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer MitigationsJeonghyun Woo, Joyce Qu, Gururaj Saileshwar, Prashant Jayaprakash NairISCA 2025 · 被引用 6 次
- Assassyn: A Unified Abstraction for Architectural Simulation and ImplementationJian Weng, Boyang Han, Derui Gao, Ruijie Gao 等ISCA 2025 · 被引用 1 次
- Practice Makes (Im)Perfect: A Look Back at Benchmarking Practices for Microarchitectural Side-Channel AttacksIliana Fayolle, Antoine Geimer, Daniel De Almeida Braga, Clémentine MauriceCCS 2026
相关 Paper
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 被引用 141 次
- ÆPIC Leak: Architecturally Leaking Uninitialized Data from the MicroarchitecturePietro Borrello, Andreas Kogler, Martin Schwarzl, Moritz Lipp 等USENIX Security 2022
- UncoreBleed: AEX-Free, High-Resolution, and Low-Noise Side-Channel Attacks on SGX Enclaved ExecutionDecheng Chen, Zhi Zhang, Zhenkai Zhang, Xin Zhang 等USENIX Security 2026
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos 等S&P 2021 · 被引用 162 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
