Software Grand Exposure: SGX Cache Attacks Are Practical

Грандиозное раскрытие программного обеспечения: атаки на кэш SGX практически осуществимы
Ferdinand Brasser, Urs Müller, Alexandra Dmitrienko, Kari Kostiainen, Srđjan Čapkun, Ahmad‐Reza Sadeghi
2017-02-24

RSA-2048 key extractionSGX cache attackscache access pattern monitoringgenomic indexingside-channel attacks
Side-channel information leakage is a known limitation of SGX. Researchers have demonstrated that secret-dependent information can be extracted from enclave execution through page-fault access patterns. Consequently, various recent research efforts are actively seeking countermeasures to SGX side-channel attacks. It is widely assumed that SGX may be vulnerable to other side channels, such as cache access pattern monitoring, as well. However, prior to our work, the practicality and the extent of such information leakage was not studied. In this paper we demonstrate that cache-based attacks are indeed a serious threat to the confidentiality of SGX-protected programs. Our goal was to design an attack that is hard to mitigate using known defenses, and therefore we mount our attack without interrupting enclave execution. This approach has major technical challenges, since the existing cache monitoring techniques experience significant noise if the victim process is not interrupted. We designed and implemented novel attack techniques to reduce this noise by leveraging the capabilities of the privileged adversary. Our attacks are able to recover confidential information from SGX enclaves, which we illustrate in two example cases: extraction of an entire RSA-2048 key during RSA decryption, and detection of specific human genome sequences during genomic indexing. We show that our attacks are more effective than previous cache attacks and harder to mitigate than previous SGX side-channel attacks.
1
Cache-based side-channel attacks are a practical and serious confidentiality threat to SGX-protected programs.
2
Novel noise-reduction techniques leverage privileged-adversary capabilities to enable effective cache monitoring despite the victim enclave continuing execution.
3
The attack monitors cache access patterns without interrupting enclave execution, making it difficult to mitigate with defenses targeting interruption-based attacks.
4
The attacks recover sensitive data in practice, including an entire RSA-2048 private key during decryption and specific human genome sequences during genomic indexing.
5
The demonstrated attacks are more effective than previous cache attacks and harder to mitigate than earlier SGX side-channel attacks.

SGX-protected enclave programs, including RSA decryption and genomic indexing

The practicality, effectiveness, and confidentiality impact of non-interrupting cache-based side-channel attacks on SGX enclaves

Publication Details
Publication Date
2017-02-24
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Ferdinand Brasser
Urs Müller
Alexandra Dmitrienko
Kari Kostiainen
Srđjan Čapkun
Ahmad‐Reza Sadeghi
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%