UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets
Jubayer Mahmod, Matthew Hicks
摘要
As technology scaling brings society closer to the vision of smart dust, system designers must address the threat of physical attacks. To address the threat of physical access to computing devices, defenders move secrets on the chip, keeping them out of reach of non-nation-state-level attackers. Modern systems allow hardware-backed security enclaves called Trusted Execution Environments (TEEs); TEEs add hardware-level protections on top of keeping secrets on chips that extend protection against privileged software and flaws within the untrusted parts of the software. While the best TEEs protect against concurrent and temporally recent attacks (e.g., the cold boot attack), we uncover a new threat to all forms of on-chip crypto: long-term data remanence.We show that the most ubiquitous form of on-chip memory, Static Random-Access Memory (SRAM), changes at the analog-domain-level in a data-dependent way as software uses it. Under normal conditions, these changes occur gradually over a device’s lifetime, but we show how an attacker can systematically accelerate this data imprinting on SRAM’s analog domain to effectively burn-in on-chip secrets. We then reveal the imprinted secrets through measurements of SRAM’s power-on state. We use this capability to demonstrate three attacks: one that reveals an AES key protected by TrustZone, proprietary firmware protected by TrustZone, and secrets stored in cache memory. Overall, we show that it is possible to imprint and exfiltrate secrets from a range of SRAM-based memories across 13 devices, from 8 manufacturers, produced across three decades—with up to 98% accuracy. To address this threat, we provide guidance to chip vendors and programmers on the defensive trade space.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper8
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 被引用 231 次
- VoltJockey: Breaching TrustZone by Software-Controlled Voltage Manipulation over Multi-core FrequenciesPengfei Qiu, Dongsheng Wang, Yongqiang Lyu, Gang QuCCS 2019 · 被引用 124 次
- CaSE: Cache-Assisted Secure Execution on ARM ProcessorsNing Zhang, Kun Sun, Wenjing Lou, Yiwei Thomas HouS&P 2016 · 被引用 104 次
- Cache Storage Channels: Alias-Driven Attacks and Verified CountermeasuresRoberto Guanciale, Hamed Nemati, Christoph Baumann, Mads DamS&P 2016 · 被引用 103 次
相关 Paper
- SRAM has no chill: exploiting power domain separation to steal on-chip secretsJubayer Mahmod, Matthew HicksASPLOS 2022 · 被引用 16 次
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik 等S&P 2026 · 被引用 29 次
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 被引用 20 次
- Invisible bits: hiding secret messages in SRAM's analog domainJubayer Mahmod, Matthew HicksASPLOS 2022 · 被引用 5 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
