Armageddon: Cache Attacks On Mobile Devices

Армагеддон: атаки на кэш мобильных устройств
Moritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice, Stefan Mangard
2016-06-19

ARM cache attacksAndroid smartphonesFlush+ReloadPrime+Probecross-core cache attacks
In the last 10 years, cache attacks on Intel x86 CPUs have gained increasing attention among the scientific community and powerful techniques to exploit cache side channels have been developed. However, modern smartphones use one or more multi-core ARM CPUs that have a different cache organization and instruction set than Intel x86 CPUs. So far, no cross-core cache attacks have been demonstrated on non-rooted Android smartphones. In this work, we demonstrate how to solve key challenges to perform the most powerful cross-core cache attacks Prime+Probe, Flush+Reload, Evict+Reload, and Flush+Flush on non-rooted ARM-based devices without any privileges. Based on our techniques, we demonstrate covert channels that outperform state-of-the-art covert channels on Android by several orders of magnitude. Moreover, we present attacks to monitor tap and swipe events as well as keystrokes, and even derive the lengths of words entered on the touchscreen. Eventually, we are the first to attack cryptographic primitives implemented in Java. Our attacks work across CPUs and can even monitor cache activity in the ARM TrustZone from the normal world. The techniques we present can be used to attack hundreds of millions of Android devices.
1
The attacks can monitor touchscreen tap and swipe events, detect keystrokes, and infer the lengths of words entered on the touchscreen.
2
The attacks operate across CPUs and can monitor cache activity in ARM TrustZone from the normal world, potentially affecting hundreds of millions of Android devices.
3
The proposed techniques enable covert channels that outperform previous Android covert channels by several orders of magnitude.
4
The study presents the first attacks on cryptographic primitives implemented in Java using cache side channels.
5
The work demonstrates cross-core Prime+Probe, Flush+Reload, Evict+Reload, and Flush+Flush attacks on non-rooted ARM-based Android devices without privileges.

non-rooted Android smartphones with multi-core ARM CPUs and their cache activity

cross-core cache side-channel attack capabilities, including covert-channel performance and monitoring of touchscreen input, Java cryptographic primitives, and ARM TrustZone activity

Publication Details
Publication Date
2016-06-19
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Moritz Lipp
Daniel Gruss
Raphael Spreitzer
Clémentine Maurice
Stefan Mangard
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%