中文版 | English
题名

TLB Poisoning Attacks on AMD Secure Encrypted Virtualization

作者
通讯作者Zhang,Yinqian
DOI
发表日期
2021-12-06
会议名称
ACSAC ’21
会议录名称
页码
609-619
会议日期
December 6–10, 2021
会议地点
USA
摘要

AMD's Secure Encrypted Virtualization (SEV) is an emerging technology of AMD server processors, which provides transparent memory encryption and key management for virtual machines (VM) without trusting the underlying hypervisor. Like Intel Software Guard Extension (SGX), SEV forms a foundation for confidential computing on untrusted machines; unlike SGX, SEV supports full VM encryption and thus makes porting applications straightforward. To date, many mainstream cloud service providers, including Microsoft Azure and Google Cloud, have already adopted (or are planning to adopt) SEV for confidential cloud services. In this paper, we provide the first exploration of the security issues of TLB management on SEV processors and demonstrate a novel class of TLB Poisoning attacks against SEV VMs. We first demystify how SEV extends the TLB implementation atop AMD Virtualization (AMD-V) and show that the TLB management is no longer secure under SEV's threat model, which allows the hypervisor to poison TLB entries between two processes of a SEV VM. We then present TLB Poisoning Attacks, a class of attacks that break the integrity and confidentiality of the SEV VM by poisoning its TLB entries. Two variants of TLB Poisoning Attacks are described in the paper; and two end-to-end attacks are performed successfully on both AMD SEV and SEV-ES.

关键词
学校署名
通讯
语种
英语
相关链接[Scopus记录]
收录类别
EI入藏号
20215211386480
EI主题词
Application programs ; Cloud data security ; Cryptography ; Distributed database systems ; Trusted computing ; Virtual reality ; Windows operating system
EI分类号
Computer Software, Data Handling and Applications:723 ; Data Processing and Image Processing:723.2 ; Database Systems:723.3
Scopus记录号
2-s2.0-85121630245
来源库
Scopus
引用统计
被引频次[WOS]:6
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/259973
专题南方科技大学
工学院_计算机科学与工程系
作者单位
1.The Ohio State University,Columbus,United States
2.Southern University of Science and Technology,Shenzhen,Guangdong,China
3.Baidu Security,Sunnyvale,United States
4.NIO Security Research,San Jose,United States
通讯作者单位南方科技大学
推荐引用方式
GB/T 7714
Li,Mengyuan,Zhang,Yinqian,Wang,Huibo,et al. TLB Poisoning Attacks on AMD Secure Encrypted Virtualization[C],2021:609-619.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
TLB.pdf(855KB)----限制开放--
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Li,Mengyuan]的文章
[Zhang,Yinqian]的文章
[Wang,Huibo]的文章
百度学术
百度学术中相似的文章
[Li,Mengyuan]的文章
[Zhang,Yinqian]的文章
[Wang,Huibo]的文章
必应学术
必应学术中相似的文章
[Li,Mengyuan]的文章
[Zhang,Yinqian]的文章
[Wang,Huibo]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。