Article 4WCH6 Intel’s SGX coughs up crypto keys when scientists tweak CPU voltage

Intel’s SGX coughs up crypto keys when scientists tweak CPU voltage

by
Dan Goodin
from Ars Technica - All content on (#4WCH6)
intel-sgx-800x444.jpg

Enlarge (credit: Intel)

To counter the growing sophistication of computer attacks, Intel and other chipmakers have built digital vaults into CPUs to segregate sensitive computations and secrets from the main engine computers use. Now, scientists have devised an attack that causes the Software Guard Extensions-Intel's implementation of this secure CPU environment-to divulge cryptographic keys and induce potentially dangerous memory errors.

Plundervault, as the attack has been dubbed, starts with the assumption that an attacker is able to run privileged software on a targeted computer. While that's a lofty prerequisite, it's precisely the scenario Intel's SGX feature is designed to protect against. The chipmaker bills SGX as a private region that uses hardware-based memory encryption to isolate sensitive computations and data from malicious processes that run with high privilege levels. Intel goes as far as saying that "Only Intel SGX offers such a granular level of control and protection."

But it turns out that subtle fluctuations in voltage powering the main CPU can corrupt the normal functioning inside the SGX. By subtly increasing or decreasing the current delivered to a CPU-operations known as "overvolting" and "undervolting"-a team of scientists has figured out how to induce SGX faults that leak cryptographic keys, break integrity assurances, and potentially induce memory errors that could be used in other types of attacks. While the exploit requires the execution of privileged code, it doesn't rely on physical access, raising the possibility of remote attacks.

Read 14 remaining paragraphs | Comments

index?i=Lj3cbM38GJs:G3EfCV9MpTI:V_sGLiPB index?i=Lj3cbM38GJs:G3EfCV9MpTI:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments