Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86
Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham, Christopher W. Fletcher, David Kohlbrenner
摘要
Power side-channel attacks exploit data-dependent variations in a CPU's power consumption to leak secrets. In this paper, we show that on modern Intel (and AMD) x86 CPUs, power side-channel attacks can be turned into timing attacks that can be mounted without access to any power measurement interface. Our discovery is enabled by dynamic voltage and frequency scaling (DVFS). We find that, under certain circumstances, DVFS-induced variations in CPU frequency depend on the current power consumption (and hence, data) at the granularity of milliseconds. Making matters worse, these variations can be observed by a remote attacker, since frequency differences translate to wall time differences!The frequency side channel is theoretically more powerful than the software side channels considered in cryptographic engineering practice today, but it is difficult to exploit because it has a coarse granularity. Yet, we show that this new channel is a real threat to the security of cryptographic software. First, we reverse engineer the dependency between data, power, and frequency on a modern x86 CPU—finding, among other things, that differences as seemingly minute as a set bit's position in a word can be distinguished through frequency changes. Second, we describe a novel chosen-ciphertext attack against (constant-time implementations of) SIKE, a post-quantum key encapsulation mechanism, that amplifies a single key-bit guess into many thousands of high- or low-power operations, allowing full key extraction via remote timing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper33
- GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent PrefetchersBoru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher 等USENIX Security 2024 · 被引用 52 次
- Frequency Throttling Side-Channel AttackChen Liu, Abhishek Chakraborty, Nikhil Chawla, Neer RoggelCCS 2022 · 被引用 33 次
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 被引用 19 次
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt 等USENIX Security 2024 · 被引用 15 次
- A Systematic Evaluation of Automated Tools for Side-Channel Vulnerabilities Detection in Cryptographic LibrariesAntoine Geimer, Mathéo Vergnolle, Frédéric Recoules, Lesly-Ann Daniel 等CCS 2023 · 被引用 12 次
它引用的顶会 Paper9
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss 等CCS 2019 · 被引用 289 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- PLATYPUS: Software-based Power Side-Channel Attacks on x86Moritz Lipp, Andreas Kogler, David F. Oswald, Michael Schwarz 等S&P 2021 · 被引用 242 次
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer 等CCS 2016 · 被引用 196 次
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 被引用 174 次
相关 Paper
- Scheduled Disclosure: Turning Power into Timing Without Frequency ScalingInwhan Chun, Isabella Siu, Riccardo PaccagnellaS&P 2025
- DVFS Frequently Leaks Secrets: Hertzbleed Attacks Beyond SIKE, Cryptography, and CPU-Only DataYingchen Wang, Riccardo Paccagnella, Alan Wandke, Zhao Gang 等S&P 2023
- TimeGaps Channels: Exploiting CPU Halted Time for Fun and ProfitYusi Feng, Xin Zhang, Sioli O'Connell, Liangwei Qiu 等ISCA 2026 · 被引用 1 次
- BrokenSleep: Remote Power Timing Attack Exploiting Processor Idle StatesHyosang Kim, Ki-Dong Kang, Gyeongseo Park, Seungkyu Lee 等HPCA 2025 · 被引用 2 次
- Uncore Encore: Covert Channels Exploiting Uncore Frequency ScalingYanan Guo, Dingyuan Cao, Xin Xin, Youtao Zhang 等MICRO 2023 · 被引用 9 次
