2021/08/10 by Robert Buhren, Hans Niklas Jacob, Buhren, Robert +6 · 1 voice · 1 citation
Computer Science · #Security and Verification in Computing #Cloud Data Security Solutions #Physical Unclonable Functions (PUFs) and Hardware Security
paper · pdf · doi:10.48550/arxiv.2108.04575
AMD Secure Encrypted Virtualization (SEV) offers protection mechanisms for\nvirtual machines in untrusted environments through memory and register\nencryption. To separate security-sensitive operations from software executing\non the main x86 cores, SEV leverages the AMD Secure Processor (AMD-SP). This\npaper introduces a new approach to attack SEV-protected virtual machines (VMs)\nby targeting the AMD-SP. We present a voltage glitching attack that allows an\nattacker to execute custom payloads on the AMD-SPs of all microarchitectures\nthat support SEV currently on the market (Zen 1, Zen 2, and Zen 3). The\npresented methods allow us to deploy a custom SEV firmware on the AMD-SP, which\nenables an adversary to decrypt a VM's memory. Furthermore, using our approach,\nwe can extract endorsement keys of SEV-enabled CPUs, which allows us to fake\nattestation reports or to pose as a valid target for VM migration without\nrequiring physical access to the target host. Moreover, we reverse-engineered\nthe Versioned Chip Endorsement Key (VCEK) mechanism introduced with SEV Secure\nNested Paging (SEV-SNP). The VCEK binds the endorsement keys to the firmware\nversion of TCB components relevant for SEV. Building on the ability to extract\nthe endorsement keys, we show how to derive valid VCEKs for arbitrary firmware\nversions. With our findings, we prove that SEV cannot adequately protect\nconfidential data in cloud environments from insider attackers, such as rogue\nadministrators, on currently available CPUs.\n