A joint team from the Georgia Institute of Technology, the University of Michigan, and Ruhr-Universität Bochum in Germany report a new form of side-channel attack that exploits power and speed management methods used by graphics processing units and systems on a chip (SoC). Dynamic Voltage and Frequency Scaling (DVFS) mechanisms on most modern chips release data, and the research team shows how they can steal personal information.
As manufacturers race to develop thinner, more power-efficient devices, they must balance power consumption, heat generation and processing speed. But researchers recently published a paper on the preprint server arXiv pointing out that SoC exhibits instruction- and data-dependent behavior precisely because of efforts to make trade-offs among the three parties.
Using four categories of devices: SoC units, Intel CPUs, AMD and Nvidia GPUs, the team was able to detect behavioral patterns that occur as processors constantly balance power demands and thermal constraints. This was revealed through data leaked from sensors embedded in the processor. This "hot pixel" attack forces one of the variables tracked by DVFS to remain unchanged. By monitoring the other two variables, they are able to determine which instructions are being executed.
Such leaks are common: So-called ARM chips in smartphones, which contain passively cooled processors, leak data containing power and frequency readings; actively cooled processors in desktop devices may leak data through temperature and power readings.
By reading this data, researchers deployed several types of attacks, such as history sniffing and website fingerprinting. The results show that hackers can sniff browsing history by detecting different colors of links that a user has previously visited. Once a sensitive site, such as a bank, is identified, hackers can provide links to fake sites that resemble the real site.
The researchers tested devices such as Apple MacBook Air (M1 and M2), Google Pixel 6 Pro, OnePlus 10 Pro, Nvidia GeForce RTX 3060, AMD Radeon RX 6600 and Intel Iris Xe (i7-1280P). All devices leaked data, with the AMD Radeon RX 6600 performing the worst, with an unauthorized data extraction accuracy rate of 94%. Apple devices received the highest ratings, with data retrieval accuracy ranging from only 60% to 67%.
The researchers have notified all affected manufacturers of the vulnerabilities and recommend that manufacturers implement hardware-based thermal throttling that limits unprivileged access to sensor readings.
Previous article:Quantum lidar acquires 3D images underwater and is expected to be used in fields such as security and defense
Next article:Report says solar panels also have security vulnerabilities that could be exploited by hackers for cyberattacks
Recommended ReadingLatest update time:2024-11-23 07:51
- Popular Resources
- Popular amplifiers
- Siemens PLC Programming Technology and Application Cases (Edited by Liu Zhenquan, Wang Hanzhi, Yang Kun, etc.)
- Siemens PLC from Beginner to Mastery with Color Illustrations (Yang Rui)
- Experience and skills in using Siemens S7-200PLC (Shang Baoxing)
- Siemens S7-1200-PLC Programming and Application Tutorial (3rd Edition) (Edited by Shi Shouyong)
- These exhibits at the Zhuhai Air Show are eye-catching
- Mir T527 series core board, high-performance vehicle video surveillance, departmental standard all-in-one solution
- Akamai Expands Control Over Media Platforms with New Video Workflow Capabilities
- Tsinghua Unigroup launches the world's first open architecture security chip E450R, which has obtained the National Security Level 2 Certification
- Pickering exhibits a variety of modular signal switches and simulation solutions at the Defense Electronics Show
- Parker Hannifin Launches Service Master COMPACT Measuring Device for Field Monitoring and Diagnostics
- Connection and distance: A new trend in security cameras - Wi-Fi HaLow brings longer transmission distance and lower power consumption
- Smartway made a strong appearance at the 2023 CPSE Expo with a number of blockbuster products
- Dual-wheel drive, Intellifusion launches 12TOPS edge vision SoC
- Intel promotes AI with multi-dimensional efforts in technology, application, and ecology
- ChinaJoy Qualcomm Snapdragon Theme Pavilion takes you to experience the new changes in digital entertainment in the 5G era
- Infineon's latest generation IGBT technology platform enables precise control of speed and position
- Two test methods for LED lighting life
- Don't Let Lightning Induced Surges Scare You
- Application of brushless motor controller ML4425/4426
- Easy identification of LED power supply quality
- World's first integrated photovoltaic solar system completed in Israel
- Sliding window mean filter for avr microcontroller AD conversion
- What does call mean in the detailed explanation of ABB robot programming instructions?
- STMicroelectronics discloses its 2027-2028 financial model and path to achieve its 2030 goals
- 2024 China Automotive Charging and Battery Swapping Ecosystem Conference held in Taiyuan
- State-owned enterprises team up to invest in solid-state battery giant
- The evolution of electronic and electrical architecture is accelerating
- The first! National Automotive Chip Quality Inspection Center established
- BYD releases self-developed automotive chip using 4nm process, with a running score of up to 1.15 million
- GEODNET launches GEO-PULSE, a car GPS navigation device
- Should Chinese car companies develop their own high-computing chips?
- Infineon and Siemens combine embedded automotive software platform with microcontrollers to provide the necessary functions for next-generation SDVs
- Continental launches invisible biometric sensor display to monitor passengers' vital signs
- ④. Drive five-wire four-phase stepper motor
- Bluetooth Protocol
- I encountered a problem when testing the CAN communication isolation chip a few days ago. I hope you can give me some advice.
- Reminiscing about the past! A brief discussion on the century-long history of radio development
- Learn embedded linux c programming from practice
- What are the benefits of changing the synchronous rectification power supply to asynchronous rectification with an external diode?
- How to create a secure area for Flasher for secure burning?
- High-precision metering socket solution based on SDI7768
- [RVB2601 Creative Application Development] Feiyan Platform Product Creation
- SD and MMC device driver process in Linux