VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface
Zitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean, David F. Oswald, Flavio D. Garcia
摘要
Hardware-based fault injection attacks such as voltage and clock glitching have been thoroughly studied on embedded devices. Typical targets for such attacks include smartcards and low-power microcontrollers used in IoT devices. This paper presents the first hardware-based voltage glitching attack against a fully-fledged Intel CPU. The transition to complex CPUs is not trivial due to several factors, including: a complex operating system, large power consumption, multi-threading, and high clock speeds. To this end, we have built VoltPillager, a low-cost tool for injecting messages on the Serial Voltage Identification bus between the CPU and the voltage regulator on the motherboard. This allows us to precisely control the CPU core voltage. We leverage this powerful tool to mount fault-injection attacks that breach confidentiality and integrity of Intel SGX enclaves. We present proof-of-concept key-recovery attacks against cryptographic algorithms running inside SGX. We demonstrate that VoltPillager attacks are more powerful than recent software-only undervolting attacks against SGX (CVE-2019-11157) because they work on fully patched systems with all countermeasures against software undervolting enabled. Additionally, we are able to fault securitycritical operations by delaying memory writes. Mitigation of VoltPillager is not straightforward and may require a rethink of the SGX adversarial model where a cloud provider is untrusted and has physical access to the hardware. Our Contribution In this paper, we analyse the dynamic voltage scaling features of x86 systems at the hardware level. We found that a three-wire bus, Serial Voltage Identification (SVID), is used to send the currently required voltage to an external Voltage Regulator (VR) chip on the motherboard. The VR then adjusts the voltage supplied to the CPU. We reverse-engineered the communication protocol of SVID and developed a small microcontroller-based board that can be connected to the SVID bus. As there is no cryptographic authentication of the SVID packets, we were able to inject our own commands to control the CPU voltage. With this, we reproduced Plundervolt's [37] open-source Proof-of-Concept (PoC) attacks, including against code running inside an SGX enclave. Beyond that, we also found (and document) faults not previously observed. These faults affect elementary operations such as memory accesses. Because the software interface MSR 0x150 is not used, Intel's countermeasures do not prevent this attack. The main contributions of this paper are: • We showcase the (to our knowledge) first hardware-based attack that directly breaches SGX's integrity guarantees. We demonstrate its practicality with end-to-end secret-key recovery attacks against mbed TLS and the unmodified file-encryptor sample enclave from Microsoft Open Enclave. • We show that Intel's countermeasures for CVE-2019-11157 do not prevent fault-injection attacks from adversaries with physical access. This challenges the widely accepted belief that SGX can protect enclave integrity against a malicious cloud provider (cf. e.g., [2, 5, 27, 8] ). • We demonstrate novel fault effects discovered through hardware-based undervolting, in particular by briefly delaying memory writes. • We present VoltPillager, an open-source hardware device to inject SVID packets. VoltPillager is based on a low-cost, widely available microcontroller board, the Teensy 4.0, and can be built for approximately $ 30. We also document the internal power management interfaces on modern motherboards, SVID and System Management Bus (SMBus).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper29
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik 等S&P 2026 · 被引用 29 次
- Snoopy: Surpassing the Scalability Bottleneck of Oblivious StorageEmma Dauterman, Vivian Fang, Ioannis Demertzis, Natacha Crooks 等SOSP 2021 · 被引用 26 次
- Private Web Search with TiptoeAlexandra Henzinger, Emma Dauterman, Henry Corrigan-Gibbs, Nickolai ZeldovichSOSP 2023 · 被引用 25 次
- Pantheon: Private Retrieval from Public Key-Value StoreIshtiyaque Ahmad, Divyakant Agrawal, Amr El Abbadi, Trinabh GuptaVLDB 2023 · 被引用 23 次
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 被引用 20 次
它引用的顶会 Paper11
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck 等S&P 2020 · 被引用 369 次
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel 等USENIX Security 2016 · 被引用 306 次
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin 等S&P 2018 · 被引用 288 次
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen 等S&P 2020 · 被引用 274 次
- RAMBleed: Reading Bits in Memory Without Accessing ThemAndrew Kwong, Daniel Genkin, Daniel Gruss, Yuval YaromS&P 2020 · 被引用 239 次
相关 Paper
- V0LTpwn: Attacking x86 Processor Integrity from SoftwareZijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz 等USENIX Security 2020
- Minefield: A Software-only Protection for SGX Enclaves against DVFS AttacksAndreas Kogler, Daniel Gruss, Michael SchwarzUSENIX Security 2022
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
- IntraFuzz: Coverage-Guided Intra-Enclave Fuzzing for Intel SGX ApplicationsJinhua Cui, Qiao Peng, Yiwen Yao, Ke Ye 等DAC 2025 · 被引用 1 次
- Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault AttacksNimish Mishra, Rahul Arvind Mool, Anirban Chakraborty, Debdeep MukhopadhyayDAC 2024 · 被引用 3 次
