论文标题

一项针对英特尔SGX发表的攻击的调查

A Survey of Published Attacks on Intel SGX

论文作者

Nilsson, Alexander, Bideh, Pegah Nikbakht, Brorsson, Joakim

论文摘要

英特尔软件后卫扩展(SGX)提供了一个可信赖的执行环境(TEE)来运行代码并操作敏感数据。 SGX提供运行时硬件保护,即使其他代码组件是恶意的,也可以保护代码和数据。但是,最近已经确定并引入了许多针对SGX的攻击,可以阻止SGX提供的硬件防御。在本文中,我们介绍了所有针对作者已知的专门针对英特尔SGX的攻击的调查。我们将攻击基于其实施细节分为7种不同的类别。我们还研究了针对已确定攻击的可用防御机制,并为每次提出的攻击分类了可用的缓解类型。

Intel Software Guard Extensions (SGX) provides a trusted execution environment (TEE) to run code and operate sensitive data. SGX provides runtime hardware protection where both code and data are protected even if other code components are malicious. However, recently many attacks targeting SGX have been identified and introduced that can thwart the hardware defence provided by SGX. In this paper we present a survey of all attacks specifically targeting Intel SGX that are known to the authors, to date. We categorized the attacks based on their implementation details into 7 different categories. We also look into the available defence mechanisms against identified attacks and categorize the available types of mitigations for each presented attack.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源