PLATYPUS: software-based power side-channel attacks on x86

Moritz Lipp, Andreas Kogler, David Oswald, Michael Schwarz, Catherine Easdon, Claudio Canella, Daniel Gruss

Research output: Chapter in Book/Report/Conference proceedingConference contribution

524 Downloads (Pure)

Abstract

Power side-channel attacks exploit variations in power consumption to extract secrets from a device, e.g., cryptographic keys. Prior attacks typically required physical access to the target device and specialized equipment such as probes and a high-resolution oscilloscope. In this paper, we present novel software-based power side-channel attacks on Intel server, desktop, and laptop CPUs. We exploit unprivileged access to the Intel Running Average Power Limit (RAPL) interface that exposes values directly correlated with power consumption, forming a low-resolution side channel. We show that with sufficient statistical evaluation, we can observe variations in power consumption, which distinguish different instructions and different Hamming weights of operands and memory loads. This enables us to not only monitor the control flow of applications but also to infer data and extract cryptographic keys. We demonstrate how an unprivileged attacker can leak AES-NI keys from Intel SGX and the Linux kernel, break kernel address-space layout randomization (KASLR), infer secret instruction streams, and establish a timing-independent covert channel. We also present a privileged attack on mbed TLS, utilizing precise execution control to recover RSA keys from an SGX enclave. We discuss countermeasures and show that mitigating these attacks in a privileged context is not trivial.
Original languageEnglish
Title of host publication2021 IEEE Symposium on Security and Privacy (SP)
PublisherIEEE Computer Society Press
Pages355-371
Number of pages17
ISBN (Electronic)9781728189345
ISBN (Print)9781728189352 (PoD)
DOIs
Publication statusPublished - 26 Aug 2021
Event42nd IEEE Symposium on Security and Privacy (IEEE S&P 2021) - virtual event
Duration: 24 May 202127 May 2021

Publication series

NameProceedings of the IEEE Symposium on Security and Privacy
PublisherIEEE
ISSN (Print)1081-6011
ISSN (Electronic)2375-1207

Conference

Conference42nd IEEE Symposium on Security and Privacy (IEEE S&P 2021)
Cityvirtual event
Period24/05/2127/05/21

Keywords

  • Energy consumption
  • Privacy
  • Power demand
  • Portable computers
  • Side-channel attacks
  • Thermal management
  • Servers

Fingerprint

Dive into the research topics of 'PLATYPUS: software-based power side-channel attacks on x86'. Together they form a unique fingerprint.

Cite this