RandDelay: Mitigating Fine-Grained Timing-Based Controlled-Channel Attacks on Intel TDX via Randomized SEAMCALL Latency
RandDelay introduces a cryptographically randomized latency into the SEAMCALL handler of Intel TDX to disrupt fine-grained timing-based controlled-channel attacks like T-Time, increasing the measurement budget needed for successful attacks and making them impractical under the proposed security model.
Intel Trust Domain Extensions (TDX) is a Confidential Virtual Machine (CVM) technology that provides hardware-enforced isolation through Trusted Execution Environments (TEEs). While TDX effectively mitigates interrupt-based stepping attacks, it remains vulnerable to fine-grained timing-based controlled-channel attacks such as T-Time, which exploit precise dwell-time measurements between consecutive page faults to infer secret-dependent control flows even within a single memory page. Existing page-level confinement defenses are insufficient against such timing attacks. In this paper, we propose RandDelay, a lightweight defense mechanism that raises the measurement budget required for a successful T-Time attack by injecting a cryptographically random latency into the SEAMCALL handler of the TDX module. We argue that SEAMCALL is the most practical and effective injection point among mandatory boundary handlers: it lies strictly between the attacker’s timestamp Ts and the victim’s secret-dependent code execution, ensuring that every dwell-time measurement is corrupted by an independent random variable. We further integrate an anomaly-based page-fault rate limiter (RandDelay+) to prevent statistical averaging attacks. Security analysis shows that RandDelay raises the minimum number of measurements required for a successful attack beyond the budget enforced by RandDelay+, rendering the attack impractical under the analytical model and assumed parameter settings. We discuss implementation considerations within the TDX module firmware, expected performance overhead, and generalization to other TEE platforms. This paper contributes a design rationale, a quantitative tuning rule, and an analytical security–overhead model that together provide a deployable baseline for empirical follow-up. The proposed defense has not been experimentally validated on a deployed TDX system; a prototype, simulation, or trace-driven study is identified as essential future work.
- Conference Article
4
- 10.1109/trustcom.2014.121
- Sep 1, 2014
Mobile security becomes a hot topic recently, especially in mobile payment and privacy data fields. Traditional solution can't keep a good balance between convenience and security. Against this background, a dual OS security solution named Trusted Execution Environment (TEE) is proposed and implemented by many institutions and companies. However, it raised TEE fragmentation and control problem. Addressing this issue, a mobile security infrastructure named Trusted Execution Environment Integration (TEEI) is presented to integrate multiple different TEEs. By using Trusted Virtual Machine (TVM) tech-nology, TEEI allows multiple TEEs running on one secure world on one mobile device at the same time and isolates them safely. Furthermore, a Virtual Network protocol is proposed to enable communication and cooperation among TEEs which includes TEE on TVM and TEE on SE. At last, a SOA-like Internal Trusted Service (ITS) framework is given to facilitate the development and maintenance of TEEs.
- Research Article
- 10.1016/j.cose.2022.103003
- Nov 3, 2022
- Computers & Security
FaultMorse: An automated controlled-channel attack via longest recurring sequence
- Book Chapter
108
- 10.1007/978-3-642-32946-3_23
- Jan 1, 2012
We show in this paper that the isolation characteristic of system virtualization can be bypassed by the use of a cache timing attack. Using Bernstein’s correlation in this attack, an adversary is able to extract sensitive keying material from an isolated trusted execution domain. We demonstrate this cache timing attack on an embedded ARM-based platform running an L4 microkernel as virtualization layer. An attacker who gained access to the untrusted domain can extract the key of an AES-based authentication protocol used for a financial transaction. We provide measurements for different public domain AES implementations. Our results indicate that cache timing attacks are highly relevant in virtualization-based security architectures, such as trusted execution environments.
- Conference Article
375
- 10.14722/ndss.2017.23193
- Jan 1, 2017
Intel Software Guard Extensions (SGX) is a hardware-based Trusted Execution Environment (TEE) that enables secure execution of a program in an isolated environment, called an enclave. SGX hardware protects the running enclave against malicious software, including the operating system, hypervisor, and even low-level firmware. This strong security property allows trustworthy execution of programs in hostile environments, such as a public cloud, without trusting anyone (e.g., a cloud provider) between the enclave and the SGX hardware. However, recent studies have demonstrated that enclave programs are vulnerable to accurate controlled-channel attacks conducted by a malicious OS. Since enclaves rely on the underlying OS, curious and potentially malicious OSs can observe a sequence of accessed addresses by intentionally triggering page faults. In this paper, we propose T-SGX, a complete mitigation solution to the controlled-channel attack in terms of compatibility, performance, and ease of use. T-SGX relies on a commodity component of the Intel processor (since Haswell), called Transactional Synchronization Extensions (TSX), which implements a restricted form of hardware transactional memory. As TSX is implemented as an extension (i.e., snooping the cache protocol), any unusual event, such as an exception or interrupt, that should be handled in its core component, results in an abort of the ongoing transaction. One interesting property is that the TSX abort suppresses the notification of errors to the underlying OS. This means that the OS cannot know whether a page fault has occurred during the transaction. T-SGX, by utilizing this property of TSX, can carefully isolate the effect of attempts to tap running enclaves, thereby completely eradicating the known controlled channel attack. We have implemented T-SGX as a compiler-level scheme to automatically transform a normal enclave program into a secured enclave program without requiring manual source code modification or annotation. We not only evaluate the security properties of T-SGX, but also demonstrate that it could be applied to all the previously demonstrated attack targets, such as libjpeg, Hunspell, and FreeType. To evaluate the performance of T-SGX, we ported 10 benchmark programs of nbench to the SGX environment. Our evaluation results look promising. T-SGX is an order of magnitude faster than the state-of-the-art mitigation schemes. On our benchmarks, T-SGX incurs on average 50% performance overhead and less than 30% storage overhead.
- Preprint Article
4
- 10.1109/sp46214.2022.00118
- Dec 9, 2021
- arXiv (Cornell University)
Differential privacy is a de facto privacy framework that has seen adoption in practice via a number of mature software platforms. Implementation of differentially private (DP) mechanisms has to be done carefully to ensure end-to-end security guarantees. In this paper we study two implementation flaws in the noise generation commonly used in DP systems. First we examine the Gaussian mechanism's susceptibility to a floating-point representation attack. The premise of this first vulnerability is similar to the one carried out by Mironov in 2011 against the Laplace mechanism. Our experiments show attack's success against DP algorithms, including deep learning models trained using differentially-private stochastic gradient descent. In the second part of the paper we study discrete counterparts of the Laplace and Gaussian mechanisms that were previously proposed to alleviate the shortcomings of floating-point representation of real numbers. We show that such implementations unfortunately suffer from another side channel: a novel timing attack. An observer that can measure the time to draw (discrete) Laplace or Gaussian noise can predict the noise magnitude, which can then be used to recover sensitive attributes. This attack invalidates differential privacy guarantees of systems implementing such mechanisms. We demonstrate that several commonly used, state-of-the-art implementations of differential privacy are susceptible to these attacks. We report success rates up to 92.56% for floating point attacks on DP-SGD, and up to 99.65% for end-to-end timing attacks on private sum protected with discrete Laplace. Finally, we evaluate and suggest partial mitigations.
- Conference Article
4
- 10.1109/sgsma.2019.8784502
- May 1, 2019
Precise timing within the power grid is of growing importance, facilitating sensing and monitoring to provide realtime situational awareness. This wide-area synchronization is performed through use of GNSS receivers, and is therefore susceptible to attacks as well as natural anomalies. Resiliency in the event of timing errors and attacks is crucial to ensuring reliability of the power grid, and supporting future advancements in automation and control. This work presents a framework aimed at practical deployment to existing and future sites within the power system, as well as other critical infrastructures where precise timing is relevant. We discuss the defense-in-depth scheme utilized to maximize the coverage surface, and individual metrics employed to detect GNSS attacks and errors, equipment malfunctions, and timing attacks via other surfaces such as malware and physical intrusion. A prototype system is developed and discussed, including implementation considerations. We analyze the effectiveness of the metrics against various threat sources, and provide preliminary results demonstrating detection capability against the TEXBAT spoofing dataset. These analysis and results bear testament to the robustness and capability of the system.
- Conference Article
1
- 10.1145/3649329.3658241
- Jun 23, 2024
As a prevalent privacy-preserving technology, Trusted Execution Environment has become widely adopted in numerous commercial processors. Nonetheless, they remain susceptible to various controlled-channel attacks. Untrusted operating systems can deduce enclave secrets by manipulating page tables or observing allocation- or swap-based page faults. In this paper, we propose SecPaging, a novel secure enclave paging mechanism based on hardware-enforced and microcode-supported protection to prevent these attacks. First, enclave PTEs are protected through hardware isolation, preventing privileged attackers from malicious tampering or observations. Second, an Eager-Allocation mechanism is employed to prevent allocation-based controlled-channel attacks. Besides, a Record-Reload mechanism is proposed to prevent swap-based controlled-channel attacks. We simulate SecPaging on real SGX. Experiments demonstrate that controlled channel attacks can be defended with minimal performance overhead.
- Conference Article
24
- 10.1109/csac.2005.11
- Dec 5, 2005
As the number of system vulnerabilities multiplies in recent years, vulnerability assessment has emerged as a powerful system security administration tool that can identify vulnerabilities in existing systems before they are exploited. Although there are many commercial vulnerability assessment tools in the market, none of them can formally guarantee that the assessment process never compromises the computer systems being tested. This paper proposes a featherweight virtual machine (FVM) technology to address the safety issue associated with vulnerability testing. Compared with other virtual machine technologies, FVM is designed to facilitate sharing between virtual machines but still provides strong protection between them. The FVM technology allows a vulnerability assessment tool to test an exact replica of a production-mode network service, including both hardware and system software components, while guaranteeing that the production-mode network service is fully isolated from the testing process. In addition to safety, the vulnerability assessment support system described in this paper can also automate the entire process of vulnerability testing and thus for the first time makes it feasible to run vulnerability testing autonomously and frequently. Experiments on a Windows-based prototype show that Nessus assessment results against an FVM virtual machine are identical to those against a real machine. Furthermore, modifications to the file system and registry state made by vulnerability assessment runs are completely isolated from the host machine. Finally, the performance impact of vulnerability assessment runs on production network services is as low as 3%.
- Research Article
12
- 10.1109/tdsc.2022.3160346
- Mar 1, 2023
- IEEE Transactions on Dependable and Secure Computing
Confidential computing aims to secure the code and data in use by providing a Trusted Execution Environment (TEE) for applications using hardware features such as Intel SGX. Timing and cache side-channel attacks, however, are often outside the scope of the threat model, although once exploited they are able to break all the default security guarantees enforced by hardware. Unfortunately, tools detecting potential side-channel vulnerabilities within applications are limited and usually ignore the strong attack model and the unique programming model imposed by Intel SGX. This article proposes a precise side-channel analysis tool, ENCIDER, detecting both timing and cache side-channel vulnerabilities within SGX applications via inferring potential timing observation points and incorporating the SGX programming model into analysis. ENCIDER uses dynamic symbolic execution to decompose the side-channel requirement based on the bounded non-interference property and implements byte-level information flow tracking via API modeling. We have applied ENCIDER to 4 real-world SGX applications, 2 SGX crypto libraries, and 3 widely-used crypto libraries, and found 29 timing side channels and 73 code and data cache side channels. We also compare ENCIDER with three state-of-the-art side channel analysis tools using their benchmarks. ENCIDER does not only report most of the bugs with 20%-50% run time improvement and 65%-92% memory usage improvement, but also detects 9 missing bugs from these tools. We have reported our findings to the corresponding parties, e.g., Intel and ARM, who have confirmed most of the vulnerabilities detected.
- Research Article
33
- 10.1016/j.eswa.2023.122410
- Nov 7, 2023
- Expert Systems with Applications
SRFL: A Secure & Robust Federated Learning framework for IoT with trusted execution environments
- Research Article
14
- 10.46586/tches.v2024.i1.180-206
- Dec 4, 2023
- IACR Transactions on Cryptographic Hardware and Embedded Systems
The ever increasing popularity and availability of Trusted Execution Environments (TEEs) had a stark influence on microarchitectural attack research in academia, as their strong attacker model both boosts existing attack vectors and introduces several new ones. While many works have focused on Intel SGX, other TEEs like AMD SEV have recently also started to receive more attention. A common technique when attacking SGX enclaves is single-stepping, where the system’s APIC timer is used to interrupt the enclave after every instruction. Single-stepping increases the temporal resolution of subsequent microarchitectural attacks to a maximum. A key driver in the proliferation of this complex attack technique was the SGX-Step framework, which offered a stable reference implementation for single-stepping and a relatively easy setup. In this paper, we demonstrate that SEV VMs can also be reliably single-stepped. To lay the foundation for further microarchitectural attack research against SEV, we introduce the reusable SEV-Step framework. Besides reliable single-stepping, SEV-Step provides easy access to common attack primitives like page fault tracking and cache attacks against SEV. All features can be used interactively from user space. We demonstrate SEV-Step’s capabilities by carrying out an end-toend cache attack against SEV that leaks the volume key of a LUKS2-encrypted disk. Finally, we show for the first time that SEV is vulnerable to Nemesis-style attacks, which allow to extract information about the type and operands of single-stepped instructions from SEV-protected VMs.
- Research Article
10
- 10.1016/j.comnet.2021.108744
- Jan 11, 2022
- Computer Networks
Internet of Things (IoT) is becoming integrated into nearly every aspect of our modern life. Indeed, exploitation of such devices can directly lead to physical consequences in the real world. Previous work has shown that IoT devices can be compromised by exploits in lower software layers such as the Operating System (OS). Embedded Trusted Execution Environments (TEEs) provide a small Trusted Computing Base (TCB) to protect sensitive codes and data in such devices. TEEs assume a strong threat model where even a privileged attacker (e.g. OS) cannot compromise the confidentiality and integrity of the execution. Nevertheless, it has been shown that side channel attacks make it challenging to keep secrets during application execution.Interrupt latency side channel attacks (a.k.a. Nemesis) are a novel type of timing attacks that target embedded TEEs and extract application secrets from them. Nemesis attacks exploit the CPU’s interrupt mechanism to reveal microarchitectural instruction timings from embedded TEEs. Specifically, the attacker measures the latency of a precisely timed interrupt to differentiate between secret-dependent branches. In this paper, we present NemesisGuard, the first mitigation mechanism against such side channel attacks that does not require a modified compiler or hardware and can protect COTS binaries without access to source code. NemesisGuard applies a novel static binary instrumentation technique to balance secret-dependent branches in IoT application binaries. Evaluation of NemesisGuard shows that it mitigates Nemesis side channel attacks effectively and efficiently.
- Conference Article
1
- 10.1109/iswcs.2018.8491196
- Aug 1, 2018
Modern secure communication systems typically follow a pattern at the transmitter of first compression encoding followed by encryption, and then additional encoders to mitigate the effects of channel noise, etc. One of the purposes of the compression algorithm is to remove statistical information about the plaintext, so as to render the ciphertext impervious to statistical attacks. It is well known, however, that in practice there is no such thing as a universal compression algorithm; thus, some statistical information about the plaintext tends to survive the compression process. In this paper, we consider Lempel-Ziv Welch compression and analyze its effectiveness in removing statistical information from English plaintext. Specifically, we present several techniques for exploiting the structure of the compression algorithm to launch a successful statistical attack on compressed and encrypted data. All attacks are ciphertext only, and one of them relies on linear programming. Although our attacks indicate that an eavesdropper may require additional ciphertext to carry out a successful attack if compression is used, the specific adaptive nature of the Lempel-Ziv compression technique leaves its own statistics on the message, which can be exploited by an attacker.
- Conference Article
1
- 10.1145/3338467.3358952
- Nov 11, 2019
Computing platforms sometimes provide hardware support for enclaves or trusted execution environments. On such platforms, security critical code can execute in an enclave or secure world, isolated from all other software on the platform. But the past few years, several successful side-channel attacks have been developed that break, or at least significantly weaken the isolation that these mechanisms offer. Particularly dangerous are software-based side-channels, as they can be launched even without physical access to the computing platform. These attacks often exploit architectural or micro-architectural features of the platform, like caches, paging, speculative execution, or interrupts. Extending a platform with new features, brings a risk of introducing new such side-channel attacks. In this talk, we will discuss an approach to formally prove the security of platform extensions against these side-channel attacks, and instantiate that approach in a simple setting. More specifically, we will consider the concrete case of extending a microprocessor that supports enclaved execution with support for securely interrupting these enclaves. The base platform we start from is the Sancus system. We show how making enclaves interruptible can lead to new side-channel attacks that weaken the isolation properties of enclaves. We then discuss how to formalize security against such attacks, and discuss the design and implementation of an interrupt handling mechanism for Sancus that is provably secure in the sense that it does not introduce new side-channel attacks.
- Conference Article
5
- 10.1109/chinagrid.2009.36
- Aug 1, 2009
The virtual machine (VM) technology has received an increasing interest a spotlight both in the industry and the research communities. Although the potential advantages of virtualization in HPC workloads have been documented, the potential impact to application performance in HPC environments is not clearly understood. This paper presents a study on performance evaluation of virtual HPC systems using High Performance Computing Challenge (HPCC) benchmark suite and xVM as the workload representative and VM technology, respectively. Based on the extended AHP (Analytic Hierarchy Process) method, we propose an efficient performance evaluation model based on extended AHP and analyze the results and quantify the performance overhead of xVM in terms of compute, memory, and network overhead. Our analysis shows that the computational and network performance in HVM is slightly better and the memory performance is significantly better compared to paravirtualization.