首页> 外文期刊>Computer networks >Enhanced cache attack on AES applicable on ARM-based devices with new operating systems
【24h】

Enhanced cache attack on AES applicable on ARM-based devices with new operating systems

机译:增强了对具有新操作系统的ARM的设备上适用的AES的缓存攻击

获取原文
获取原文并翻译 | 示例
           

摘要

There are several key challenges in performing cache-based attacks on ARM-based devices. Lipp et al. introduced various techniques to tackle these challenges and applied successfully different cache-based attacks on ARM-based mobile devices. In the cache-based attacks proposed by Lipp et al. it is assumed that the attacker has access to the mapping of virtual addresses to physical addresses through/proc/self/pagemap which is an important limiting factor in Linux and newer versions of Android operating systems. To access this mapping, the attacker must know the root of the operating system. In this paper, we introduce an Evict+Reload attack on the T-table-based implementation of AES which applies to ARM-based devices in which root access is required to use the mapping of virtual addresses to physical addresses. The attack consists of two phases. The profiling is a preprocessing phase to profile all the timing characteristics when AES is executed with a known key. In this phase, the attacker can identify specific bits of the physical addresses of the AES T-table elements without having root access. In the exploitation phase, full key bytes are retrieved by a conventional Evict+Reload attack. To verify the theoretical model of our technique, we implemented the described attack on AES.
机译:在执行基于ARM的设备上执行基于缓存的攻击时存在若干关键挑战。 lipp等人。介绍了各种技术来解决这些挑战,并在基于ARM的移动设备上成功应用了基于缓存的基于缓存的攻击。在Lipp等人提出的基于缓存的攻击中。假设攻击者可以访问虚拟地址的映射到通过/ proc / self / pagemap的物理地址,这是Linux和较新版本的Android操作系统的重要限制因素。要访问此映射,攻击者必须知道操作系统的根目录。在本文中,我们对AE的基于T表的实现介绍了一种evict +重新加载攻击,该AES适用于基于ARM的设备,其中需要root访问来使用虚拟地址映射到物理地址。攻击由两个阶段组成。分析是预处理阶段,以便在用已知密钥执行AES时配置所有定时特性。在该阶段,攻击者可以识别AES T表元素的物理地址的特定位,而不具有根访问。在开发阶段,通过传统的evict +重新加载攻击检索全关键字节。为了验证我们技术的理论模型,我们对AES的攻击实施了。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号