Voltage Fault Injection (VFI), also known as power glitching, has proven to be a severe threat to real-world systems. In VFI attacks, the adversary disturbs the power-supply of the target-device forcing the device to illegitimate behavior. Various countermeasures have been proposed to address different types of fault injection attacks at different abstraction layers, either requiring to modify the underlying hardware or software/firmware at the machine instruction level. Moreover, only recently, individual chip manufacturers have started to respond to this threat by integrating countermeasures in their products. Generally, these countermeasures aim at protecting against single fault injection (SFI) attacks, since Multiple Fault Injection (MFI) is believed to be challenging and sometimes even impractical. In this paper, we present {\mu}-Glitch, the first Voltage Fault Injection (VFI) platform which is capable of injecting multiple, coordinated voltage faults into a target device, requiring only a single trigger signal. We provide a novel flow for Multiple Voltage Fault Injection (MVFI) attacks to significantly reduce the search complexity for fault parameters, as the search space increases exponentially with each additional fault injection. We evaluate and showcase the effectiveness and practicality of our attack platform on four real-world chips, featuring TrustZone-M: The first two have interdependent backchecking mechanisms, while the second two have additionally integrated countermeasures against fault injection. Our evaluation revealed that {\mu}-Glitch can successfully inject four consecutive faults within an average time of one day. Finally, we discuss potential countermeasures to mitigate VFI attacks and additionally propose two novel attack scenarios for MVFI.
翻译:电压故障注入(VFI),亦称电源毛刺攻击,已被证明是对现实系统构成严重威胁。在VFI攻击中,攻击者干扰目标设备的电源供应,迫使设备产生非法行为。针对不同抽象层级上不同类型的故障注入攻击,学术界提出了多种防御措施,这些措施要么需要修改底层硬件,要么需要在机器指令级别修改软件/固件。此外,直到最近,个别芯片制造商才开始通过在其产品中集成防御机制来应对这一威胁。一般而言,这些防御机制旨在保护设备免受单次故障注入(SFI)攻击,因为多次故障注入(MFI)被认为具有挑战性,有时甚至不切实际。在本文中,我们提出了μ-Glitch,这是首个能够仅需单个触发信号即可向目标设备注入多个协调电压故障的电压故障注入(VFI)平台。我们为多次电压故障注入(MVFI)攻击提供了一种新流程,以显著降低故障参数的搜索复杂度——因为每次额外注入故障都会导致搜索空间呈指数级增长。我们在四款集成TrustZone-M的真实芯片上评估并展示了攻击平台的有效性和实用性:前两款芯片具有相互依赖的后向检查机制,而后两款芯片则额外集成了针对故障注入的防御措施。评估结果显示,μ-Glitch能在平均一天时间内成功注入四个连续故障。最后,我们讨论了缓解VFI攻击的潜在防御措施,并额外提出了两种适用于MVFI的新型攻击场景。