中文版 | English
题名

CIPHERH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations

作者
通讯作者Wang, Shuai; Zhang, Yinqian
发表日期
2023
会议名称
32nd USENIX Security Symposium
会议录名称
会议日期
AUG 09-11, 2023
会议地点
null,Anaheim,CA
出版地
SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA
出版者
摘要
["The ciphertext side channel is a new type of side channels that exploits deterministic memory encryption of trusted execution environments (TEE). It enables the adversary with read accesses to the ciphertext of the encrypted memory, either logically or physically, to compromise cryptographic implementations protected by TEEs with high fidelity. Prior studies have concluded that the ciphertext side channel is a severe threat to not onlyAMD SEV-SNP, where the vulnerability was first discovered, but to all TEEs with deterministic memory encryption.","In this paper, we propose CIPHERH, a practical framework for automating the analysis of cryptographic software and detecting program points vulnerable to ciphertext side channels. CIPHERH is designed to perform a practical hybrid analysis in production cryptographic software, with a speedy dynamic taint analysis to track the usage of secrets throughout the entire program and a static symbolic execution procedure on each \"tainted\" function to reason about ciphertext side-channel vulnerabilities using symbolic constraint. Empirical evaluation has led to the discovery of over 200 vulnerable program points from the state-of-the-art RSA and ECDSA/ECDH implementations from OpenSSL, MbedTLS, andWolfSSL. Representative cases have been reported to and confirmed or patched by the developers."]
学校署名
第一 ; 通讯
语种
英语
相关链接[来源记录]
收录类别
WOS研究方向
Computer Science
WOS类目
Computer Science, Information Systems ; Computer Science, Interdisciplinary Applications ; Computer Science, Theory & Methods
WOS记录号
WOS:001066451507004
来源库
Web of Science
引用统计
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/673962
专题南方科技大学
作者单位
1.Southern University of Science and Technology, China
2.The Ohio State University, United States
3.Hong Kong University of Science and Technology, Hong Kong
4.The Ant Group, China
第一作者单位南方科技大学
通讯作者单位南方科技大学
第一作者的第一单位南方科技大学
推荐引用方式
GB/T 7714
Deng, Sen,Li, Mengyuan,Tang, Yining,et al. CIPHERH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations[C]. SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA:USENIX ASSOC,2023.
条目包含的文件
条目无相关文件。
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Deng, Sen]的文章
[Li, Mengyuan]的文章
[Tang, Yining]的文章
百度学术
百度学术中相似的文章
[Deng, Sen]的文章
[Li, Mengyuan]的文章
[Tang, Yining]的文章
必应学术
必应学术中相似的文章
[Deng, Sen]的文章
[Li, Mengyuan]的文章
[Tang, Yining]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。