How TrustZone Could Be Bypassed: Side-Channel Attacks on a Modern System-on-Chip

Bukasa, Sebanjila;Lashermes, Ronan;Bouder, Hélène;Lanet, Jean-Louis;Legay, Axel
(2017) 11th IFIP International Conference on Information Security Theory and Practice (WISTP) (28.September.2017)

Files

No attached file found for this publication.

Details

Authors
  • Bukasa, Sebanjila
    Author
  • Lashermes, Ronan
    Author
  • Bouder, Hélène
    Author
  • Lanet, Jean-Louis
    Author
  • Legay, AxelUCLouvain
    Author
Abstract
Side-channel attacks (SCA) exploit the reification of a computation through its physical dimensions (current consumption, EM emission, ...). Focusing on Electromagnetic analyses (EMA), such analyses have mostly been considered on low-end devices: smartcards and microcontrollers. In the wake of recent works, we propose to analyze the effects of a modern microarchitecture on the efficiency of EMA (here Correlation Power Analysis and template attacks). We show that despite the difficulty to synchronize the measurements, the speed of the targeted core and the activity of other cores on the same chip can still be accommodated. Finally, we confirm that enabling the secure mode of TrustZone (a hardware-assisted software countermeasure) has no effect whatsoever on the EMA efficiency. Therefore, critical applications in TrustZone are not more secure than in the normal world with respect to EMA, in accordance with the fact that it is not a countermeasure against physical attacks. For the best of our knowledge this is the first application of EMA against TrustZone.
Affiliations

Citations

Bukasa, S., Lashermes, R., Bouder, H., Lanet, J.-L., & Legay, A. (2017). How TrustZone Could Be Bypassed: Side-Channel Attacks on a Modern System-on-Chip. Information Security Theory and Practice Lecture Notes in Computer Science. Published. 11th IFIP International Conference on Information Security Theory and Practice (WISTP). https://doi.org/10.1007/978-3-319-93524-9_6