Lune

USENIX Security2021顶会

VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interface

Zitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean, David F. Oswald, Flavio D. Garcia

出版方
2021年份
127被引次数
29顶会引用

摘要

Hardware-based fault injection attacks such as voltage and clock glitching have been thoroughly studied on embedded devices. Typical targets for such attacks include smartcards and low-power microcontrollers used in IoT devices. This paper presents the first hardware-based voltage glitching attack against a fully-fledged Intel CPU. The transition to complex CPUs is not trivial due to several factors, including: a complex operating system, large power consumption, multi-threading, and high clock speeds. To this end, we have built VoltPillager, a low-cost tool for injecting messages on the Serial Voltage Identification bus between the CPU and the voltage regulator on the motherboard. This allows us to precisely control the CPU core voltage. We leverage this powerful tool to mount fault-injection attacks that breach confidentiality and integrity of Intel SGX enclaves. We present proof-of-concept key-recovery attacks against cryptographic algorithms running inside SGX. We demonstrate that VoltPillager attacks are more powerful than recent software-only undervolting attacks against SGX (CVE-2019-11157) because they work on fully patched systems with all countermeasures against software undervolting enabled. Additionally, we are able to fault securitycritical operations by delaying memory writes. Mitigation of VoltPillager is not straightforward and may require a rethink of the SGX adversarial model where a cloud provider is untrusted and has physical access to the hardware. Our Contribution In this paper, we analyse the dynamic voltage scaling features of x86 systems at the hardware level. We found that a three-wire bus, Serial Voltage Identification (SVID), is used to send the currently required voltage to an external Voltage Regulator (VR) chip on the motherboard. The VR then adjusts the voltage supplied to the CPU. We reverse-engineered the communication protocol of SVID and developed a small microcontroller-based board that can be connected to the SVID bus. As there is no cryptographic authentication of the SVID packets, we were able to inject our own commands to control the CPU voltage. With this, we reproduced Plundervolt's [37] open-source Proof-of-Concept (PoC) attacks, including against code running inside an SGX enclave. Beyond that, we also found (and document) faults not previously observed. These faults affect elementary operations such as memory accesses. Because the software interface MSR 0x150 is not used, Intel's countermeasures do not prevent this attack. The main contributions of this paper are: • We showcase the (to our knowledge) first hardware-based attack that directly breaches SGX's integrity guarantees. We demonstrate its practicality with end-to-end secret-key recovery attacks against mbed TLS and the unmodified file-encryptor sample enclave from Microsoft Open Enclave. • We show that Intel's countermeasures for CVE-2019-11157 do not prevent fault-injection attacks from adversaries with physical access. This challenges the widely accepted belief that SGX can protect enclave integrity against a malicious cloud provider (cf. e.g., [2, 5, 27, 8] ). • We demonstrate novel fault effects discovered through hardware-based undervolting, in particular by briefly delaying memory writes. • We present VoltPillager, an open-source hardware device to inject SVID packets. VoltPillager is based on a low-cost, widely available microcontroller board, the Teensy 4.0, and can be built for approximately $ 30. We also document the internal power management interfaces on modern motherboards, SVID and System Management Bus (SMBus).

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper29

问问它们各自怎么用它

它引用的顶会 Paper11

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖