Author:
Cabrera Aldaya Alejandro,Brumley Billy Bob
Abstract
Microarchitecture based side-channel attacks are common threats nowadays. Intel SGX technology provides a strong isolation from an adversarial OS, however, does not guarantee protection against side-channel attacks. In this paper, we analyze the security of the mbedTLS binary GCD algorithm, an implementation that offers interesting challenges when compared for example with OpenSSL, due to the usage of very tight loops in the former. Using practical experiments we demonstrate the mbedTLS binary GCD implementation is vulnerable to side-channel analysis using the SGX-Step framework against mbedTLS based SGX enclaves.We analyze the security of some use cases of this algorithm in this library, resulting in the discovery of a new vulnerability in the ECDSA code path that allows a single-trace attack against this implementation. This vulnerability is three-fold interesting:
It resides in the implementation of a countermeasure which makes it more dangerous due to the false state of security the countermeasure currently offers.
It reduces mbedTLS ECDSA security to an integer factorization problem.
An unexpected GCD call inside the ECDSA code path compromises the countermeasure.
We also cover an orthogonal use case, this time inside the mbedTLS RSA code path during the computation of a CRT parameter when loading a private key. The attack also exploits the binary GCD implementation threat, showing how a single vulnerable primitive leads to multiple vulnerabilities. We demonstrate both security threats with end-to-end attacks using 1000 trials each, showing in both cases single-trace attacks can be achieved with success rates very close to 100%.
Publisher
Universitatsbibliothek der Ruhr-Universitat Bochum
Cited by
3 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Microwalk-CI;Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security;2022-11-07
2. SGXDump: A Repeatable Code-Reuse Attack for Extracting SGX Enclave Memory;Applied Sciences;2022-07-29
3. Util::Lookup;Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security;2021-11-12