Hertzbleed — a new family of side-channel attacks affecting modern CPUs

A group of researchers from the universities of Texas, Illinois, and Washington has revealed information about a new family of side-channel attacks (CVE-2022-23823, CVE-2022-24436) code-named Hertzbleed. The proposed attack method is based on the peculiarities of dynamic frequency scaling in modern processors and affects all current Intel and AMD CPUs. The problem may potentially also arise in processors from other manufacturers that support dynamic frequency adjustment, such as ARM systems, but the research conducted was limited to testing Intel and AMD chips. The source code implementing the attack method has been published on GitHub (the implementation was tested on a computer with an Intel i7-9700 CPU).

To optimize power consumption and prevent overheating, processors dynamically change their frequency based on workload, which leads to changes in performance and affects operation execution times (a frequency change of 1 Hz results in a performance change of 1 clock cycle per second). The study found that under certain conditions on AMD and Intel processors, frequency changes directly correlate with the processed data, which means, for example, that the computation times for the operations '2022 + 23823' and '2022 + 24436' will differ. Based on the analysis of the differences in execution times for operations with different data, it is possible to indirectly recover the information used in calculations. Additionally, in high-speed networks with predictable constant latencies, the attack can be carried out remotely by evaluating the execution time of requests.

If the attack is successful, the identified issues allow for the determination of private keys based on the analysis of computation times in cryptographic libraries that use algorithms where mathematical calculations are always executed in constant time, regardless of the nature of the processed data. Such libraries were considered secure against side-channel attacks, but it turns out that computation time is influenced not only by the algorithm but also by the characteristics of the processor's operation.

As a practical example demonstrating the feasibility of the proposed method, an attack on the implementation of the SIKE (Supersingular Isogeny Key Encapsulation) key encapsulation mechanism is presented. This mechanism reached the finals of the post-quantum cryptography competition held by the U.S. National Institute of Standards and Technology (NIST) and is marketed as being secure against side-channel attacks. In the experiment, using a new variant of the attack based on crafted ciphertext (iterative guessing based on manipulations with the encrypted text and obtaining its decryption), it was possible to fully recover the key used for encryption, conducting measurements from a remote system, despite the implementation of SIKE having constant computation time. Determining a 364-bit key using the CIRCL implementation took 36 hours, while the PQCrypto-SIDH took 89 hours.

Intel and AMD have acknowledged that their processors are vulnerable to the issue but do not plan to patch the vulnerability through microcode updates, as it is impossible to eliminate it without significantly affecting performance. Instead, developers of cryptographic libraries have been advised on software methods to block information leakage during confidential computations. Companies Cloudflare and Microsoft have already added such protection to their SIKE implementations, which resulted in a 5% decrease in the performance of CIRCL and an 11% decrease for PQCrypto-SIDH. As another workaround to block the vulnerability in BIOS or drivers, one can disable the 'Turbo Boost', 'Turbo Core', or 'Precision Boost' modes, but this change will lead to a drastic reduction in performance.

Intel, Cloudflare, and Microsoft were informed of the issue in the third quarter of 2021, while AMD was notified in the first quarter of 2022. However, at Intel's request, the public disclosure of the issue was postponed until June 14, 2022. The existence of the problem has been confirmed in processors for desktop systems and laptops based on 8th to 11th generation Intel Core microarchitecture, as well as for various desktop, mobile, and server processors including AMD Ryzen, Athlon, A-Series, and EPYC (researchers demonstrated the method on Ryzen CPUs with Zen 2 and Zen 3 microarchitecture).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster