Malware Guard Extension: Using SGX to Conceal Cache Attacks

Расширение для защиты от вредоносных программ: использование SGX для сокрытия атак на кэш
Michael Schwarz, Samuel Weiser, Daniel Gruss, Clémentine Maurice, Stefan Mangard
2017-02-28

Docker containersIntel SGXPrime+Probe attackRSA private key extractioncache side-channel attacks
In modern computer systems, user processes are isolated from each other by the operating system and the hardware. Additionally, in a cloud scenario it is crucial that the hypervisor isolates tenants from other tenants that are co-located on the same physical machine. However, the hypervisor does not protect tenants against the cloud provider and thus the supplied operating system and hardware. Intel SGX provides a mechanism that addresses this scenario. It aims at protecting user-level software from attacks from other processes, the operating system, and even physical attackers. In this paper, we demonstrate fine-grained software-based side-channel attacks from a malicious SGX enclave targeting co-located enclaves. Our attack is the first malware running on real SGX hardware, abusing SGX protection features to conceal itself. Furthermore, we demonstrate our attack both in a native environment and across multiple Docker containers. We perform a Prime+Probe cache side-channel attack on a co-located SGX enclave running an up-to-date RSA implementation that uses a constant-time multiplication primitive. The attack works although in SGX enclaves there are no timers, no large pages, no physical addresses, and no shared memory. In a semi-synchronous attack, we extract 96% of an RSA private key from a single trace. We extract the full RSA private key in an automated attack from 11 traces within 5 minutes.
1
A Prime+Probe cache attack succeeds against an up-to-date constant-time RSA implementation despite SGX restrictions eliminating timers, large pages, physical addresses, and shared memory.
2
A malicious SGX enclave can conduct fine-grained software-based side-channel attacks against co-located SGX enclaves on real Intel SGX hardware.
3
An automated attack recovers the full RSA private key from 11 traces within five minutes.
4
The demonstrated malware abuses SGX protection features to conceal its presence and operates both natively and across multiple Docker containers.
5
The semi-synchronous attack extracts 96% of an RSA private key from a single trace.

co-located Intel SGX enclaves, including an RSA enclave running on real SGX hardware

fine-grained Prime+Probe cache side-channel attacks and their concealment by a malicious SGX enclave, including RSA private-key extraction

Publication Details
Publication Date
2017-02-28
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Michael Schwarz
Samuel Weiser
Daniel Gruss
Clémentine Maurice
Stefan Mangard
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%