Enclave Side-Channel Attack Detection via State Save Area
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current side-channel attack detection methods for electronic devices rely on additional hardware, which is costly and inefficient, and fail to effectively detect attacks without occupying significant cache resources.
Innovation Solution
A method and apparatus that clear data in a state save area of a target enclave, sequentially execute an instruction sequence, and acquire data to determine if an asynchronous enclave exit with a cause of exception exit occurs, thereby detecting side-channel attacks without additional hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If additional hardware is used for side-channel attack detection, then detection capability is improved, but device cost and complexity increase
Solution Approach 1:
The patent replaces hardware-based detection mechanisms with software-based detection using enclave instructions and timestamp counters. The detection is achieved through software monitoring of execution time and state save area data without requiring additional physical hardware components, thus maintaining detection capability while reducing device complexity.
Solution Approach 2:
The enclave itself provides detection capabilities through its built-in timestamp counter and state save area mechanisms. The enclave's own execution time and state data are used to detect attacks, eliminating the need for external detection hardware and reducing overall system complexity.
2Measurement precision
If additional hardware is used for side-channel attack detection, then detection capability is improved, but device cost increases
Solution Approach 1:
The patent substitutes expensive hardware detection components with software-based detection utilizing existing enclave infrastructure. This approach maintains effective attack detection while significantly reducing manufacturing costs by eliminating the need for specialized detection hardware.
Solution Approach 2:
The patent uses software copies and simulations of hardware detection functionality through enclave instructions and timestamp counters. This allows detection capabilities to be replicated in software form, avoiding the need for expensive physical hardware implementations.
3Device complexity
If existing detection methods are used without additional hardware, then device complexity is reduced, but detection capability deteriorates
Solution Approach 1:
The patent changes the parameters used for detection from requiring additional hardware to utilizing existing enclave parameters such as timestamp counters and state save area data. This allows effective detection to be achieved through software analysis of existing system parameters without increasing hardware complexity.
Solution Approach 2:
The patent introduces software-based intermediaries (enclave instructions, timestamp counter readings, state save area analysis) that mediate between the enclave execution and attack detection. These software intermediaries enable detection capability without requiring additional hardware components.
Data Source
AI summary
Embodiments of the present disclosure disclose a method and apparatus for detecting a side channel attack. An embodiment of the method comprises: clearing data in a state save area of a target enclave; sequentially executing an instruction sequence in the target enclave; acquiring data in the state save area; and in response to determining that the acquired data in the state save area indicates that an asynchronous enclave exit with a cause of exception exit happens to the target enclave, determining that the side-channel attack to the target enclave exists. The embodiment implements detecting a side channel attack to the enclave without additional hardware.


