ืคื’ื™ืขื•ืช TPM-Fail ื”ืžืืคืฉืจืช ืœืš ืœืฉื—ื–ืจ ืžืคืชื—ื•ืช ื”ืžืื•ื—ืกื ื™ื ื‘ืžื•ื“ื•ืœื™ TPM

ืฆื•ื•ืช ื—ื•ืงืจื™ื ืžื”ืžื›ื•ืŸ ื”ืคื•ืœื™ื˜ื›ื ื™ ืฉืœ ื•ื•ืกื˜ืจ, ืื•ื ื™ื‘ืจืกื™ื˜ืช ืœื™ื‘ืง ื•ืื•ื ื™ื‘ืจืกื™ื˜ืช ืงืœื™ืคื•ืจื ื™ื” ื‘ืกืŸ ื“ื™ื™ื’ื• ื”ืชืคืชื— ืฉื™ื˜ืช ื”ืชืงืคื” ืฆื“ื“ื™ืช ื”ืžืืคืฉืจืช ืœืฉื—ื–ืจ ืืช ื”ืขืจืš ืฉืœ ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื”ืžืื•ื—ืกื ื™ื ื‘-TPM (Trusted Platform Module). ื”ืžืชืงืคื” ืงื™ื‘ืœื” ืฉื ืงื•ื“ TPM-ื›ืฉืœ ื•ืžืฉืคื™ืข ืขืœ fTPM (ื”ื˜ืžืขืช ืชื•ื›ื ื” ืžื‘ื•ืกืก ืขืœ ืงื•ืฉื—ื” ื”ืคื•ืขืœืช ืขืœ ืžืขื‘ื“ ื ืคืจื“ ื‘ืชื•ืš ื”-CPU) ืฉืœ ืื™ื ื˜ืœ (CVE-2019-11090) ื•ื—ื•ืžืจื” TPM ืขืœ ืฉื‘ื‘ื™ STMicroelectronics ST33 (CVE-2019-16863).

ื—ื•ืงืจื™ื ืคื•ืจืกื ืขืจื›ืช ื›ืœื™ื ืœืชืงื™ืคื” ืฉืœ ืื‘ ื˜ื™ืคื•ืก ื•ื”ื“ื’ื™ืžื” ืืช ื”ื™ื›ื•ืœืช ืœืฉื—ื–ืจ ืžืคืชื— ืคืจื˜ื™ ืฉืœ 256 ืกื™ื‘ื™ื•ืช ื”ืžืฉืžืฉ ืœื™ืฆื™ืจืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชืžื™ื ืฉืœ ืขืงื•ืžื” ืืœื™ืคื˜ื™ืช ECDSA ื•-EC-Schnorr. ื‘ื”ืชืื ืœื–ื›ื•ื™ื•ืช ื”ื’ื™ืฉื”, ื–ืžืŸ ื”ื”ืชืงืคื” ื”ื›ื•ืœืœ ืขืœ ืžืขืจื›ื•ืช Intel fTPM ื”ื•ื 4-20 ื“ืงื•ืช ื•ื“ื•ืจืฉ ื ื™ืชื•ื— ืฉืœ 1-15 ืืœืฃ ืคืขื•ืœื•ืช. ืœื•ืงื— ื›-33 ื“ืงื•ืช ืœืชืงื•ืฃ ืžืขืจื›ื•ืช ืขื ืฉื‘ื‘ ST80 ื•ืœื ืชื— ื›-40 ืืœืฃ ืคืขื•ืœื•ืช ืœื™ืฆื™ืจืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช.

ื”ื—ื•ืงืจื™ื ื”ื“ื’ื™ืžื• ื’ื ืืคืฉืจื•ืช ืœื‘ืฆืข ืชืงื™ืคื” ืžืจื—ื•ืง ื‘ืจืฉืชื•ืช ืžื”ื™ืจื•ืช, ืฉืืคืฉืจื” ืœืฉื—ื–ืจ ืžืคืชื— ืคืจื˜ื™ ื‘ืจืฉืช ืžืงื•ืžื™ืช ื‘ืจื•ื—ื‘ ืคืก ืฉืœ 1GB ื‘ืชื ืื™ ืžืขื‘ื“ื” ืชื•ืš ื—ืžืฉ ืฉืขื•ืช, ืœืื—ืจ ืžื“ื™ื“ืช ื–ืžืŸ ื”ืชื’ื•ื‘ื” ื‘ืžืฉืš 45 ืืœืฃ ื”ืคืขืœื•ืช ืื™ืžื•ืช ืขื ืฉืจืช VPN ื”ืžื‘ื•ืกืก ืขืœ ืชื•ื›ื ืช strongSwan, ื”ืžืื—ืกื ืช ืืช ื”ืžืคืชื—ื•ืช ืฉืœื” ื‘-TPM ื”ืคื’ื™ืข.

ืฉื™ื˜ืช ื”ืชืงื™ืคื” ืžื‘ื•ืกืกืช ืขืœ ื ื™ืชื•ื— ื”ื‘ื“ืœื™ื ื‘ื–ืžืŸ ื”ื‘ื™ืฆื•ืข ืฉืœ ืคืขื•ืœื•ืช ื‘ืชื”ืœื™ืš ื™ืฆื™ืจืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช. ื”ืขืจื›ืช ื–ืžืŸ ื”ืฉื”ื™ื™ื” ื‘ื—ื™ืฉื•ื‘ ืžืืคืฉืจืช ืœืš ืœืงื‘ื•ืข ืžื™ื“ืข ืขืœ ื‘ื™ื˜ื™ื ื‘ื•ื“ื“ื™ื ื‘ืžื”ืœืš ื”ื›ืคืœื” ืกืงืœืจื™ืช ื‘ืคืขื•ืœื•ืช ืขืงื•ืžื” ืืœื™ืคื˜ื™ืช. ืขื‘ื•ืจ ECDSA, ืงื‘ื™ืขืช ืืคื™ืœื• ื›ืžื” ื‘ื™ื˜ื™ื ืขื ืžื™ื“ืข ืขืœ ื•ืงื˜ื•ืจ ื”ืืชื—ื•ืœ (nonce) ืžืกืคื™ืงื” ื›ื“ื™ ืœื‘ืฆืข ื”ืชืงืคื” ื›ื“ื™ ืœืฉื—ื–ืจ ื‘ืจืฆืฃ ืืช ื›ืœ ื”ืžืคืชื— ื”ืคืจื˜ื™. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื” ืžื•ืฆืœื—ืช, ื™ืฉ ืฆื•ืจืš ืœื ืชื— ืืช ื–ืžืŸ ื”ื”ืคืงื” ืฉืœ ื›ืžื” ืืœืคื™ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืฉื ื•ืฆืจื• ืขืœ ืคื™ ื ืชื•ื ื™ื ื”ืžื•ื›ืจื™ื ืœืชื•ืงืฃ.

ืคื’ื™ืขื•ืช ื—ื•ืกืœื• ืขืœ ื™ื“ื™ STMicroelectronics ื‘ืžื”ื“ื•ืจื” ื—ื“ืฉื” ืฉืœ ืฉื‘ื‘ื™ื ืฉื‘ื” ื”ื˜ืžืขืช ืืœื’ื•ืจื™ืชื ECDSA ืฉื•ื—ืจืจื” ืžืชืืžื™ื ืขื ื–ืžืŸ ื”ื‘ื™ืฆื•ืข ืฉืœ ื”ืคืขื•ืœื•ืช. ืžืขื ื™ื™ืŸ, ืฉื‘ื‘ื™ STMicroelectronics ื”ืžื•ืฉืคืขื™ื ืžืฉืžืฉื™ื ื’ื ื‘ืฆื™ื•ื“ ื”ืขื•ืžื“ ื‘ืจืžืช ื”ืื‘ื˜ื—ื” CommonCriteria (CC) EAL 4+. ื”ื—ื•ืงืจื™ื ื‘ื“ืงื• ื’ื ืฉื‘ื‘ื™ TPM ืฉืœ Infineon ื•- Nuvoton, ืืš ื”ื ืœื ื“ืœืคื• ืขืœ ืกืžืš ืฉื™ื ื•ื™ื™ื ื‘ื–ืžืŸ ื”ื—ื™ืฉื•ื‘.

ื‘ืžืขื‘ื“ื™ ืื™ื ื˜ืœ, ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื”ื—ืœ ืžืžืฉืคื—ืช Haswell ืฉืคื•ืจืกืžื” ื‘-2013. ื™ืฆื•ื™ืŸ ื›ื™ ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืžื—ืฉื‘ื™ื ื ื™ื™ื“ื™ื, ืžื—ืฉื‘ื™ื ืื™ืฉื™ื™ื ื•ืฉืจืชื™ื ื”ืžื™ื•ืฆืจื™ื ืขืœ ื™ื“ื™ ื™ืฆืจื ื™ื ืฉื•ื ื™ื, ื‘ื™ื ื™ื”ื Dell, Lenovo ื•-HP.

ืื™ื ื˜ืœ ื›ืœืœื” ืชื™ืงื•ืŸ ื ื•ึนื‘ึถืžื‘ึผึถืจ ืขื“ื›ื•ืŸ ืงื•ืฉื—ื”, ืฉื‘ื•, ื‘ื ื•ืกืฃ ืœื‘ืขื™ื” ื”ื ื‘ื“ืงืช, ื—ื•ืกืœื• ืขื•ื“ 24 ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืžืชื•ื›ืŸ ืชืฉืข ืžื™ื•ื—ืกืช ืจืžืช ืกื›ื ื” ื’ื‘ื•ื”ื”, ื•ืื—ืช ืงืจื™ื˜ื™ืช. ืขืœ ื‘ืขื™ื•ืช ืืœื• ืžืกื•ืคืง ืžื™ื“ืข ื›ืœืœื™ ื‘ืœื‘ื“, ืœืžืฉืœ, ืžื•ื–ื›ืจ ืฉื”ืคื’ื™ืขื•ืช ื”ืงืจื™ื˜ื™ืช (CVE-2019-0169) ื ื•ื‘ืขืช ืžื”ื™ื›ื•ืœืช ืœื’ืจื•ื ืœื”ืฆืคื” ืฉืœ ืขืจื™ืžื” ื‘ืฆื“ ืฉืœ Intel CSME (Converged Security and Management Engine) ) ื•ืกื‘ื™ื‘ื•ืช Intel TXE (Trusted Execution Engine), ื”ืžืืคืฉืจื•ืช ืœืชื•ืงืฃ ืœื”ื’ื“ื™ืœ ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื•ืœืงื‘ืœ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืกื•ื“ื™ื™ื.

ืืคืฉืจ ื’ื ืœืฆื™ื™ืŸ ื’ื™ืœื•ื™ ื ืื•ืช ืชื•ืฆืื•ืช ื‘ื™ืงื•ืจืช ืฉืœ SDKs ืฉื•ื ื•ืช ืœืคื™ืชื•ื— ื™ื™ืฉื•ืžื™ื ื”ืžืงื™ื™ืžื™ื ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืงื•ื“ ื”ืžื•ืคืขืœ ื‘ืฆื“ ืฉืœ ืžื•ื‘ืœืขื•ืช ืžื‘ื•ื“ื“ื•ืช. ืขืœ ืžื ืช ืœื–ื”ื•ืช ืคื•ื ืงืฆื™ื•ืช ื‘ืขื™ื™ืชื™ื•ืช ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ืœื‘ื™ืฆื•ืข ื”ืชืงืคื•ืช, ื ื—ืงืจื• ืฉืžื•ื ื” SDK: ืื™ื ื˜ืœ SGX-SDK, SGX-LKL, Microsoft OpenEnclave, ื’ืจืคืŸ,
Rust-EDP ะธ ื’ื•ื’ืœ ืืกื™ืœื• ืขื‘ื•ืจ ืื™ื ื˜ืœ SGX, ืื‘ืŸ ืจืืฉื” ืขื‘ื•ืจ RISC-V ื• ืกื ืงื•ืก ืขื‘ื•ืจ Sancus TEE. ื‘ืžื”ืœืš ื”ื‘ื™ืงื•ืจืช ื–ื” ื”ื™ื” ื’ื™ืœื” 35 ืคืจืฆื•ืช, ืฉืขืœ ื‘ืกื™ืกืŸ ืคื•ืชื—ื• ืžืกืคืจ ืชืจื—ื™ืฉื™ ืชืงื™ืคื” ื”ืžืืคืฉืจื™ื ืœืš ืœื—ืœืฅ ืžืคืชื—ื•ืช AES ืžืžื•ื‘ืœืขืช ืื• ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืชื ืื™ื ืœืคื’ื™ืขื” ื‘ืชื•ื›ืŸ ื”ื–ื™ื›ืจื•ืŸ.

ืคื’ื™ืขื•ืช TPM-Fail ื”ืžืืคืฉืจืช ืœืš ืœืฉื—ื–ืจ ืžืคืชื—ื•ืช ื”ืžืื•ื—ืกื ื™ื ื‘ืžื•ื“ื•ืœื™ TPM

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”