Hertzbleed can use Intel/AMD processor frequency increase vulnerability to steal encryption keys

Publisher:zuiquanLatest update time:2022-06-15 Source: cnbetaKeywords:Intel  AMD Reading articles on mobile phones Scan QR code
Read articles on your mobile phone anytime, anywhere

After being shocked by the "Spectre" and "Meltdown" side-channel attack vulnerabilities that affected modern Intel, AMD and ARM processors in 2017, security researchers have now exposed a more advanced vulnerability that uses CPU boost frequencies to steal encryption keys - it is Hertzbleed.


1.jpg

(Source: Hertzbleed website)


The attack works by monitoring the power signature of any cryptographic workload for a side-channel vulnerability, and like everything else in a CPU, processor power adjusts as workloads change.


But after observing this power information, the Hertzbleed attacker can convert it into timing data and steal the encryption keys of the user process.

● Currently, both Intel and AMD have announced systems that are vulnerable to the Heartzbleed vulnerability attack, which affects the entire Intel series and AMD Zen 2 / Zen 3 processors.

● The former was assigned the vulnerability IDs Intel-SA-00698 and CVE-2022-24436, while the latter was CVE-2022-23823.

2.webp

Principle diagram (Image from: Intel website)


Worse still, the Hertzbleed vulnerability can be exploited remotely without the need for an attacker to have physical access to the device.


The two chip companies will then provide microcode-based patch mitigations to prevent such vulnerabilities from being further exploited by attackers.


Fortunately, Intel claims that such attacks are not very practical outside of laboratory research, as stealing encryption keys is said to take hours to days.


As for the CPU performance loss that may be caused by the vulnerability patch, it still depends on the specific application scenario.


Keywords:Intel  AMD Reference address:Hertzbleed can use Intel/AMD processor frequency increase vulnerability to steal encryption keys

Previous article:Self-developed chips may revitalize Apple's Mac computers and Microsoft's Windows cash cow may be threatened
Next article:The 6th Intel Grandmasters Challenge has been upgraded to a professional level, and the winners will be sent to the League of Legends Youth Training Camp

Latest Home Electronics Articles
Change More Related Popular Components

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号