{"id":35693,"date":"2019-10-31T22:05:48","date_gmt":"2019-10-31T19:05:48","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya\/"},"modified":"2019-10-31T22:05:48","modified_gmt":"2019-10-31T19:05:48","slug":"uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya","title":{"rendered":"Haavatavus AMD SEV-s, mis v\u00f5imaldab kindlaks teha kr\u00fcpteerimisv\u00f5tmed","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Google Cloud'i meeskonna arendajad <noindex><a rel=\"nofollow\" href=\"https:\/\/seclists.org\/fulldisclosure\/2019\/Jun\/46\">tuvastasid<\/a><\/noindex> haavatavus (CVE-2019-9836) AMD SEV (Secure Encrypted Virtualization) tehnoloogia rakenduses, mis v\u00f5imaldab kompromiteerida selle tehnoloogia kaudu kaitstud andmeid. AMD SEV tagab riistvaratasandil l\u00e4bipaistva virtuaalmasinate m\u00e4lu kr\u00fcpteerimise, kus juurdep\u00e4\u00e4s dekr\u00fcpteeritud andmetele on ainult praegusel k\u00fclalisoperatsioonis\u00fcsteemil, samas kui teised virtuaalmasinad ja h\u00fcperviisor saavad selle m\u00e4lu juurde p\u00e4\u00e4semise korral kr\u00fcpteeritud andmekogumi.<\/p>\n<p>Tuvastatud probleem v\u00f5imaldab t\u00e4ielikult taastada suletud PDH-v\u00f5tme sisu, mida t\u00f6\u00f6deldakse eraldi kaitstud protsessori PSP (AMD Security Processor) tasemel, mis ei ole peamisele ops\u00fcsteemile kergesti ligip\u00e4\u00e4setav.<br \/>\nOlles PDH-v\u00f5ti k\u00e4es, suudab r\u00fcndaja then taastada sessiooniv\u00f5tme ja salajase j\u00e4rjestuse, mis m\u00e4\u00e4rati virtuaalmasina loomisel, ning p\u00e4\u00e4seda ligi kr\u00fcpteeritud andmetele. <\/p>\n<p>Haavatavus tuleneb elliptsete k\u00f5verate (ECC) rakenduse puudustest, mis v\u00f5imaldab <noindex><a rel=\"nofollow\" href=\"https:\/\/web-in-security.blogspot.com\/2015\/09\/practical-invalid-curve-attacks.html\">r\u00fcnnakut<\/a><\/noindex> k\u00f5veraparametrite taastamiseks. Kaitstud virtuaalmasina k\u00e4ivitamise k\u00e4su k\u00e4ivitamise ajal saab r\u00fcndaja saata k\u00f5veraparameetreid, mis ei vasta NIST-i soovitatavatele parameetritele, mis toob kaasa madala j\u00e4rgu punkti v\u00e4\u00e4rtuste kasutamise operatsioonides, kus tehakse tehteid suletud v\u00f5tmega. <\/p>\n<p>ECDH protokolli turvalisus s\u00f5ltub otseselt <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%AD%D0%BB%D0%BB%D0%B8%D0%BF%D1%82%D0%B8%D1%87%D0%B5%D1%81%D0%BA%D0%B0%D1%8F_%D0%BA%D1%80%D0%B8%D0%BF%D1%82%D0%BE%D0%B3%D1%80%D0%B0%D1%84%D0%B8%D1%8F\">punkty j\u00e4rjestusest<\/a><\/noindex> alates <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9F%D0%BE%D1%80%D1%8F%D0%B4%D0%BE%D0%BA_%D0%B3%D1%80%D1%83%D0%BF%D0%BF%D1%8B\">kusjuures selles toimingutes, diskreetne logaritmimine on v\u00e4ga keeruline \u00fclesanne. AMD SEV keskkonna initsialiseerimise \u00fchel sammul kasutatakse suletud v\u00f5tme arvutustes parameetreid, mis on saadud kasutajalt. P\u00f5him\u00f5tteliselt toimub kahe punkti korrutamine, kus \u00fcks punkt vastab suletud v\u00f5tmele. Kui teine punkt kuulub madala j\u00e4rgu algarvude kategooriasse, suudab r\u00fcndaja m\u00e4\u00e4rata esimese punkti parameetrid (mooduli kasutav bit), kasutades k\u00f5ikide v\u00f5imalike v\u00e4\u00e4rtuste proovimist. Suletud v\u00f5tme m\u00e4\u00e4ramiseks saab seej\u00e4rel valitud lihtnumbreid kokku koguda<\/a><\/noindex> Hiina j\u00e4\u00e4kide teoreemiga <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9A%D0%B8%D1%82%D0%B0%D0%B9%D1%81%D0%BA%D0%B0%D1%8F_%D1%82%D0%B5%D0%BE%D1%80%D0%B5%D0%BC%D0%B0_%D0%BE%D0%B1_%D0%BE%D1%81%D1%82%D0%B0%D1%82%D0%BA%D0%B0%D1%85\">Probleem on m\u00f5jutatud AMD EPYC serveritehnoloogiatest, mis kasutavad SEV-firmware kuni versioonini 0.17 build 11. AMD on juba<\/a><\/noindex>.<\/p>\n<p>Probleem on m\u00f5jutatud AMD EPYC serverite platvormidest, mis kasutavad SEV p\u00fcsivara versioonini 0.17 build 11. Ettev\u00f5te AMD on juba  <noindex>avalikustas<\/noindex> firmware update, which introduces a block on the use of points that do not comply with the NIST curve. At the same time, previously generated certificates for PDH keys remain valid, allowing an attacker to carry out a migration attack of virtual machines from environments protected against the vulnerability to environments that are susceptible to the issue. There is also mention of the possibility of rolling back the firmware version to an older vulnerable release, but this possibility has not yet been confirmed.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Allikas: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50969\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Cloud \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-9836) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 AMD SEV (Secure Encrypted Virtualization), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0435 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0434\u0430\u043d\u043d\u043e\u0439 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u0434\u0430\u043d\u043d\u044b\u0435. AMD SEV \u043d\u0430 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u043c \u0443\u0440\u043e\u0432\u043d\u0435 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043f\u0440\u043e\u0437\u0440\u0430\u0447\u043d\u043e\u0435 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d, \u043f\u0440\u0438 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u0434\u0430\u043d\u043d\u044b\u043c \u0438\u043c\u0435\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u0442\u0435\u043a\u0443\u0449\u0430\u044f \u0433\u043e\u0441\u0442\u0435\u0432\u0430\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u0430, \u0430 \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u043c\u0430\u0448\u0438\u043d\u044b \u0438 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440 \u043f\u0440\u0438 \u043f\u043e\u043f\u044b\u0442\u043a\u0435 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35693","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Cloud \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-9836) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 AMD SEV (Secure.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"et_EE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 AMD SEV, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Cloud \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-9836) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 AMD SEV (Secure.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:05:48+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:05:48+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in AMD SEV that allows the decryption of encryption keys | ProHoster","description":"Developers from the Google Cloud team have identified a vulnerability (CVE-2019-9836) in the implementation of AMD SEV (Secure).","canonical_url":"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"et_EE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 AMD SEV, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Cloud \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-9836) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 AMD SEV (Secure.","og:url":"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-amd-sev-pozvolyayushhaya-opredelit-klyuchi-shifrovaniya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:05:48+00:00","article:modified_time":"2019-10-31T19:05:48+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35693","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 00:24:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:57:46","updated":"2026-01-22 00:24:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/35693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/comments?post=35693"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/35693\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/media?parent=35693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/categories?post=35693"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/tags?post=35693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}