๐ Hertzbleed: A New Side-Channel Attack
๐ก Newskategorie: Reverse Engineering
๐ Quelle: schneier.com
Hertzbleed is a new side-channel attack that works against a variety of microprocressors. Deducing cryptographic keys by analyzing power consumption has long been an attack, but itโs not generally viable because measuring power consumption is often hard. This new attack measures power consumption by measuring time, making it easier to exploit.
...The team discovered that dynamic voltage and frequency scaling (DVFS)โa power and thermal management feature added to every modern CPUโallows attackers to deduce the changes in power consumption by monitoring the time it takes for a server to respond to specific carefully made queries. The discovery greatly reduces whatโs required. With an understanding of how the DVFS feature works, power side-channel attacks become much simpler timing attacks that can be done remotely...