题名 | A Systematic Look at Ciphertext Side Channels on AMD SEV-SNP |
作者 | |
DOI | |
发表日期 | 2022
|
ISSN | 1081-6011
|
ISBN | 978-1-6654-1317-6
|
会议录名称 | |
卷号 | 2022-May
|
页码 | 337-351
|
会议日期 | 22-26 May 2022
|
会议地点 | San Francisco, CA, USA
|
摘要 | Hardware-assisted memory encryption offers strong confidentiality guarantees for trusted execution environments like Intel SGX and AMD SEV. However, a recent study by Li et al. presented at USENIX Security 2021 has demonstrated the CipherLeaks attack, which monitors ciphertext changes in the special VMSA page. By leaking register values saved by the VM during context switches, they broke state-of-the-art constant-time cryptographic implementations, including RSA and ECDSA in the OpenSSL. In this paper, we perform a comprehensive study on the ciphertext side channels. Our work suggests that while the CipherLeaks attack targets only the VMSA page, a generic ciphertext side-channel attack may exploit the ciphertext leakage from any memory pages, including those for kernel data structures, stacks and heaps. As such, AMD's existing countermeasures to the CipherLeaks attack, a firmware patch that introduces randomness into the ciphertext of the VMSA page, is clearly insufficient. The root cause of the leakage in AMD SEV's memory encryption - the use of a stateless yet unauthenticated encryption mode and the unrestricted read accesses to the ciphertext of the encrypted memory - remains unfixed. Given the challenges faced by AMD to eradicate the vulnerability from the hardware design, we propose a set of software countermeasures to the ciphertext side channels, including patches to the OS kernel and cryptographic libraries. We are working closely with AMD to merge these changes into affected open-source projects. |
关键词 | |
学校署名 | 其他
|
语种 | 英语
|
相关链接 | [Scopus记录] |
收录类别 | |
EI入藏号 | 20223412587275
|
EI主题词 | Open source software
; Side channel attack
; Time switches
|
EI分类号 | Computer Software, Data Handling and Applications:723
|
Scopus记录号 | 2-s2.0-85135909950
|
来源库 | Scopus
|
全文链接 | https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9833768 |
引用统计 |
被引频次[WOS]:0
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/382636 |
专题 | 南方科技大学 |
作者单位 | 1.The Ohio State University,United States 2.University of Lübeck,Germany 3.Southern University of Science and Technology,China |
推荐引用方式 GB/T 7714 |
Li,Mengyuan,Wilke,Luca,Wichelmann,Jan,et al. A Systematic Look at Ciphertext Side Channels on AMD SEV-SNP[C],2022:337-351.
|
条目包含的文件 | 条目无相关文件。 |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论