The TPM-Fail vulnerability allows for the recovery of keys stored in TPM modules.

A group of researchers from Worcester Polytechnic Institute, the University of Lübeck, and the University of California, San Diego. developed a side-channel attack method that allows for the recovery of the values of private keys stored in TPM (Trusted Platform Module). The attack has been codenamed TPM-Fail. and affects fTPM (a software implementation based on firmware running on a separate microprocessor inside the CPU) from Intel (CVE-2019-11090) and hardware TPMs on STMicroelectronics chips. ST33 (CVE-2019-16863).

Researchers have published developed a prototype toolkit for conducting the attack and demonstrated the feasibility of recovering a 256-bit private key used for generating digital signatures using algorithms based on elliptic curves ECDSA and EC-Schnorr. Depending on access rights, the total attack time on Intel fTPM systems ranges from 4 to 20 minutes and requires the analysis of 1,000 to 15,000 operations. For attacks on systems with the ST33 chip, around 80 minutes and the analysis of approximately 40,000 digital signature generation operations are needed.

The researchers also demonstrated the possibility of performing a remote attack in high-speed networks, which allowed for the recovery of the private key in a local network with a bandwidth of 1 GB in laboratory conditions over five hours, after measuring response times for 45,000 authentication sessions with a VPN server based on strongSwan software, which stores its keys in a vulnerable TPM.

The attack method is based on analyzing timing variations in the execution of operations during digital signature generation. Estimating the delay in computations allows for determining information about individual bits during scalar multiplication in elliptic curve operations. For ECDSA, obtaining even a few bits of information regarding the initialization vector (nonce) is sufficient for a sequential attack to recover the entire private key. Successful execution of the attack requires analysis of the generation time for several thousand digital signatures created over known attacker data.

The vulnerability has been closed by STMicroelectronics in the new version of chips, in which the implementation of the ECDSA algorithm was freed from timing correlations during operation. Interestingly, the affected STMicroelectronics chips are also used in equipment that meets the Common Criteria (CC) EAL 4+ security level. Researchers also examined TPM chips from Infineon and Nuvoton, but in those, there is no leakage based on changes in computation time.

In Intel processors, the issue emerges starting with the Haswell family launched in 2013. It has been noted that a wide range of laptops, PCs, and servers produced by various manufacturers, including Dell, Lenovo, and HP, are affected by this problem.

Intel included a fix in the November firmware update, which, in addition to the issue discussed, resolved addresses 24 vulnerabilities, nine of which are classified as high severity and one as critical. For the mentioned issues, only general information is provided; for instance, it is noted that the critical vulnerability (CVE-2019-0169) is due to the possibility of triggering a heap overflow in Intel CSME (Converged Security and Management Engine) and Intel TXE (Trusted Execution Engine) environments, allowing an attacker to elevate their privileges and access confidential data.

It is also worth noting disclosure of audit results for various SDKs for developing applications that interact with code running in isolated enclaves. Aiming to identify problematic functions that could be exploited for attacks, eight SDKs were examined: Intel SGX-SDK, SGX-LKL, Microsoft OpenEnclave, Graphene,
Rust-EDP and Google Asylo for Intel SGX, Keystone for RISC-V, and Sancus for Sancus TEE. During the audit, seven vulnerabilities have been identified 35 vulnerabilities were found, based on which several attack scenarios were developed that allow extracting AES keys from the enclave or enabling the execution of one's own code by creating conditions that compromise memory content.

The TPM-Fail vulnerability allows for the recovery of keys stored in TPM modules.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster