Enclave Side-Channel Attack Detection via State Save Area

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current side-channel attack detection methods for electronic devices rely on additional hardware, which is costly and inefficient, and fail to effectively detect attacks without occupying significant cache resources.

Innovation Solution

A method and apparatus that clear data in a state save area of a target enclave, sequentially execute an instruction sequence, and acquire data to determine if an asynchronous enclave exit with a cause of exception exit occurs, thereby detecting side-channel attacks without additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If additional hardware is used for side-channel attack detection, then detection capability is improved, but device cost and complexity increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidhardware complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based detection mechanisms with software-based detection using enclave instructions and timestamp counters. The detection is achieved through software monitoring of execution time and state save area data without requiring additional physical hardware components, thus maintaining detection capability while reducing device complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The enclave itself provides detection capabilities through its built-in timestamp counter and state save area mechanisms. The enclave's own execution time and state data are used to detect attacks, eliminating the need for external detection hardware and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If additional hardware is used for side-channel attack detection, then detection capability is improved, but device cost increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice cost
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent substitutes expensive hardware detection components with software-based detection utilizing existing enclave infrastructure. This approach maintains effective attack detection while significantly reducing manufacturing costs by eliminating the need for specialized detection hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses software copies and simulations of hardware detection functionality through enclave instructions and timestamp counters. This allows detection capabilities to be replicated in software form, avoiding the need for expensive physical hardware implementations.

Inventive Principle:
Principle #26Copying

3Device complexity

If existing detection methods are used without additional hardware, then device complexity is reduced, but detection capability deteriorates

Engineering Contradiction:
Improvehardware complexityVSAvoiddetection capability
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters used for detection from requiring additional hardware to utilizing existing enclave parameters such as timestamp counters and state save area data. This allows effective detection to be achieved through software analysis of existing system parameters without increasing hardware complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces software-based intermediaries (enclave instructions, timestamp counter readings, state save area analysis) that mediate between the enclave execution and attack detection. These software intermediaries enable detection capability without requiring additional hardware components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10521585B2Method and apparatus for detecting side-channel attack
Publication Date: 2019.12.31 BAIDU USA LLC
  • US10521585B2 patent drawing
  • US10521585B2 patent drawing
  • US10521585B2 patent drawing

AI summary

Embodiments of the present disclosure disclose a method and apparatus for detecting a side channel attack. An embodiment of the method comprises: clearing data in a state save area of a target enclave; sequentially executing an instruction sequence in the target enclave; acquiring data in the state save area; and in response to determining that the acquired data in the state save area indicates that an asynchronous enclave exit with a cause of exception exit happens to the target enclave, determining that the side-channel attack to the target enclave exists. The embodiment implements detecting a side channel attack to the enclave without additional hardware.