首页> 外文会议>European Symposium on Research in Computer Security >Towards Efficient Evaluation of a Time-Driven Cache Attack on Modern Processors
【24h】

Towards Efficient Evaluation of a Time-Driven Cache Attack on Modern Processors

机译:有效地评估现代处理器的时间驱动缓存攻击

获取原文

摘要

Software implementations of block ciphers are widely used to perform critical operations such as disk encryption or TLS traffic protection. To speed up cipher execution, many implementations rely on pre-computed lookup tables, which makes them vulnerable to cache-timing attacks on modern processors. For time-driven attacks, the overall execution time of a cipher is sufficient to recover the secret key. Testing cryptographic software on actual hardware is consequently essential for vulnerability and risk assessment. In this work, we investigate the efficient and robust evaluation of cryptographic software on modern processors under a time-driven attack. Using a practical case study, we discuss necessary adaptations to the original attack and identify promising new micro-architectural side-channels for it. To leverage the leakage of multiple side-channels, we propose a simple, heuristic way to combine their corresponding attacks. As an additional benefit, combined attacks simplify a comprehensive evaluation of cryptographic software across multiple different processors. We finally formulate practical evaluation suggestions based on the results of our case study.
机译:块密码的软件实现广泛用于执行诸如磁盘加密或TLS流量保护之类的关键操作。为了加快密码执行,许多实现依赖于预计算机查找表,这使得它们容易受到现代处理器上的缓存定时攻击。对于时间驱动的攻击,密码的总体执行时间足以恢复密钥。在实际硬件上测试加密软件因此对于漏洞和风险评估是必不可少的。在这项工作中,我们在时间驱动攻击下调查了现代处理器上加密软件的高效和稳健评估。使用实用案例研究,我们讨论了对原始攻击的必要调整,并确定了有希望的新微型建筑侧通道。要利用多个侧通道的泄漏,我们提出了一种简单,启发式的方式来结合其相应的攻击。作为额外的好处,综合攻击简化了多个不同处理器的加密软件的全面评估。我们终于根据案例研究的结果制定实际评估建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号