DVFS Frequently Leaks Secrets: Hertzbleed Attacks
Maatla Sefawe and Ayush Vashi
1
Background
2
DVFS
3
4
Hamming Weight
Hamming Distance
Hertzbleed
5
6
Impact
7
Expanding the Threat Scope
8
Expanding the Threat Scope
9
10
Elliptic Curve Digital Signature Algortihm(ECDSA)
Classic McEliece
Beyond Cryptography and CPU Core Data: Leaking Web Browser Secrets from the iGPU
11
iGPU-CPU Frequency Leakage Channel
12
13
CPU Frequency is iGPU workload-dependent
CPU Frequency is iGPU data-dependent
Pixel Stealing
14
SVG Filter Stack Framework
15
Attacker Setup
16
Filter Stack
17
Amplification
18
Measuring CPU Frequency
19
Experimental Results
20
21
Proof of Concept
22
23
24
Discussion
25
26
What are the possible software mitigations against this attack?
Question 1
Browser Side Mitigations
27
28
What are the possible hardware mitigations against this attack?
Question 2
29
What are the broader security implications of cross component leakage (iGPU-CPU leakage) on modern processors?
Question 3
Thank you!
30