题名 | CIPHERH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations |
作者 | |
通讯作者 | Wang, Shuai; Zhang, Yinqian |
发表日期 | 2023
|
会议名称 | 32nd USENIX Security Symposium
|
会议录名称 | |
会议日期 | AUG 09-11, 2023
|
会议地点 | null,Anaheim,CA
|
出版地 | SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA
|
出版者 | |
摘要 | ["The ciphertext side channel is a new type of side channels that exploits deterministic memory encryption of trusted execution environments (TEE). It enables the adversary with read accesses to the ciphertext of the encrypted memory, either logically or physically, to compromise cryptographic implementations protected by TEEs with high fidelity. Prior studies have concluded that the ciphertext side channel is a severe threat to not onlyAMD SEV-SNP, where the vulnerability was first discovered, but to all TEEs with deterministic memory encryption.","In this paper, we propose CIPHERH, a practical framework for automating the analysis of cryptographic software and detecting program points vulnerable to ciphertext side channels. CIPHERH is designed to perform a practical hybrid analysis in production cryptographic software, with a speedy dynamic taint analysis to track the usage of secrets throughout the entire program and a static symbolic execution procedure on each \"tainted\" function to reason about ciphertext side-channel vulnerabilities using symbolic constraint. Empirical evaluation has led to the discovery of over 200 vulnerable program points from the state-of-the-art RSA and ECDSA/ECDH implementations from OpenSSL, MbedTLS, andWolfSSL. Representative cases have been reported to and confirmed or patched by the developers."] |
学校署名 | 第一
; 通讯
|
语种 | 英语
|
相关链接 | [来源记录] |
收录类别 | |
WOS研究方向 | Computer Science
|
WOS类目 | Computer Science, Information Systems
; Computer Science, Interdisciplinary Applications
; Computer Science, Theory & Methods
|
WOS记录号 | WOS:001066451507004
|
来源库 | Web of Science
|
引用统计 | |
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/673962 |
专题 | 南方科技大学 |
作者单位 | 1.Southern University of Science and Technology, China 2.The Ohio State University, United States 3.Hong Kong University of Science and Technology, Hong Kong 4.The Ant Group, China |
第一作者单位 | 南方科技大学 |
通讯作者单位 | 南方科技大学 |
第一作者的第一单位 | 南方科技大学 |
推荐引用方式 GB/T 7714 |
Deng, Sen,Li, Mengyuan,Tang, Yining,et al. CIPHERH: Automated Detection of Ciphertext Side-channel Vulnerabilities in Cryptographic Implementations[C]. SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA:USENIX ASSOC,2023.
|
条目包含的文件 | 条目无相关文件。 |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论