UncoreBleed: AEX-Free, High-Resolution, and Low-Noise Side-Channel Attacks on SGX Enclaved Execution
Decheng Chen, Zhi Zhang, Zhenkai Zhang, Xin Zhang, Yansong Gao, Yi Zou
摘要
Trusted execution environments such as Intel SGX provide strong confidentiality and integrity guarantees by isolating enclaves from the OS and hypervisor. Prior works claim that SGX disables PMCs to mitigate side-channel attacks. In this paper, we show that modern processors feature uncore PMCs whose behavior under SGX has not been fully evaluated. Leveraging this observation, we investigate the state of PMCs in production-mode SGX enclaves and overturn the long-held belief that performance monitoring is suppressed: uncore PMCs record events correlated with enclaved execution. We further identify a critical event in the mesh-to-memory uncore subsystem that allows address-based monitoring at 64 B granularity. Through reverse engineering, we uncover its filtering mechanism, programmability, availability, and address mapping across SGX-capable Xeon processors. Building on the event, we present UncoreBleed, the first PMC-based, AEX-free, high-resolution, and low-noise sidechannel attack against SGX. UncoreBleed can reconstruct pictures from enclaved Libjpeg and extract RSA private keys from a single decryption, in the presence of TLBlur with AEX-Notify, the most state-of-the-art software defense on off-the-shelf SGX platforms. Our findings demonstrate that active uncore PMCs pose a previously underestimated threat to enclave confidentiality, highlighting the need to reconsider SGX's security assumptions of performance monitoring.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper23
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
相关 Paper
- TLBlur: Compiler-Assisted Automated Hardening against Controlled Channels on Off-the-Shelf Intel SGX PlatformsDaan Vanoverloop, Andrés Sánchez, Flavio Toffalini, Frank Piessens 等USENIX Security 2025
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens 等USENIX Security 2017 · 被引用 316 次
- AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX EnclavesScott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao 等USENIX Security 2023
- Frontal Attack: Leaking Control-Flow in SGX via the CPU FrontendIvan Puddu, Moritz Schneider, Miro Haller, Srdjan CapkunUSENIX Security 2021 · 被引用 63 次
- STACCO: Differentially Analyzing Side-Channel Traces for Detecting SSL/TLS Vulnerabilities in Secure EnclavesYuan Xiao, Mengyuan Li, Sanchuan Chen, Yinqian ZhangCCS 2017 · 被引用 77 次
