Utilize este identificador para referenciar este registo: https://hdl.handle.net/1822/87668

TítuloBUSted!!! Microarchitectural side-channel attacks on the MCU bus interconnect
Autor(es)Rodrigues, Cristiano
Oliveira, Daniel
Pinto, Sandro
Palavras-chaveSide-channels
Microarchitecture
Bus
Micro controllers
TEE
TrustZone-M
Data2023
EditoraInstitute of Electrical and Electronics Engineers (IEEE)
RevistaProceedings - IEEE Symposium on Security and Privacy
Resumo(s)Spectre and Meltdown have pushed the research community toward an otherwise-unavailable understanding of the security implications of processors’ microarchitecture. Notwithstanding, research efforts have concentrated on highend processors (e.g., Intel, AMD, Arm Cortex-A), and very little has been done for microcontrollers (MCU) that power billions of small embedded and IoT devices. In this paper, we present BUSted. BUSted is a novel side-channel attack that explores the side effects of the MCU bus interconnect arbitration logic to bypass security guarantees enforced by memory protection primitives. Side-channel attacks on MCUs pose incremental and unforeseen challenges, which are strictly tied to the resource-constrained nature of these systems (e.g., single-core CPU, stateless bus). We devise a unique approach that relies on the concept of hardware gadgets. We present practical attacks on state-of-the-art Armv8-M MCUs with TrustZone-M, running the Trusted Firmware-M (TF-M). In contrast to the Nemesis attack, our attack is practical on Arm Cortex-M MCUs, and our findings suggest that it can scale across the full MCU spectrum.
TipoArtigo em ata de conferência
URIhttps://hdl.handle.net/1822/87668
ISBN979-8-3503-3130-1
DOI10.1109/SP54263.2024.00062
ISSN2375-1207
Versão da editorahttps://www.computer.org/csdl/proceedings-article/sp/2024/313000a062/1RjEazNfZ5u
Arbitragem científicayes
AcessoAcesso aberto
Aparece nas coleções:CAlg - Artigos em livros de atas/Papers in proceedings

Ficheiros deste registo:
Ficheiro Descrição TamanhoFormato 
BUSted-final.pdf1,67 MBAdobe PDFVer/Abrir

Partilhe no FacebookPartilhe no TwitterPartilhe no DeliciousPartilhe no LinkedInPartilhe no DiggAdicionar ao Google BookmarksPartilhe no MySpacePartilhe no Orkut
Exporte no formato BibTex mendeley Exporte no formato Endnote Adicione ao seu ORCID