维普中文期刊产品整合服务

Malware Guard Extension:abusing Intel SGX to conceal cache attacks

查看全文 作  者:Michael [1]Schwarz;Samuel [1]Weiser;Daniel [1]Gruss;Clementine [2]Maurice;Stefan [1]Mangard 高影响力作者 机构地区:[1]Graz University of Technology,Graz,Austria;[2]CNRS,IRISA,Rennes,France.高影响力机构 出  处:《Cybersecurity》索引2020年第3卷第1期,共20页高影响力期刊 基  金:This project has received funding from the European Research Council(ERC)under the European Union’s Horizon 2020 research and innovation programme(grant agreement No 681402);This work was partially supported by the TU Graz LEAD project“Dependable Internet of Things in Adverse Environments”. 摘  要:In modern computer systems,user processes are isolated from each other by the operating system and the hardware.Additionally,in a cloud scenario it is crucial that the hypervisor isolates tenants from other tenants that are co-located on the same physical machine.However,the hypervisor does not protect tenants against the cloud provider and thus,the supplied operating system and hardware.Intel SGX provides a mechanism that addresses this scenario.It aims at protecting user-level software from attacks from other processes,the operating system,and even physical attackers.In this paper,we demonstrate fine-grained software-based side-channel attacks from a malicious SGX enclave targeting co-located enclaves.Our attack is the first malware running on real SGX hardware,abusing SGX protection features to conceal itself.Furthermore,we demonstrate our attack both in a native environment and across multiple Docker containers.We perform a Prime+Probe cache side-channel attack on a co-located SGX enclave running an up-to-date RSA implementation that uses a constant-time multiplication primitive.The attack works,although in SGX enclaves,there are no timers,no large pages,no physical addresses,and no shared memory.In a semi-synchronous attack,we extract 96%of an RSA private key from a single trace.We extract the full RSA private key in an automated attack from 11 traces within 5 min. 关 键 词:Intel SGX Side channel Side-channel attack Prime+Probe
相关文献

参考文献(87)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费