arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

不够离散:关于离散可信平台模块(dTPMs)在测量启动中的固有安全性问题

Not Discrete Enough: On the Inherent Insecurity of dTPMs for Measured Boot

Christian Werling, Tahmid Zahin, Jean-Pierre Seifert

arXiv 2608.14736首次发表:更新:

AI 中文总结

本文指出离散TPMs(dTPMs)存在固有安全漏洞,攻击者可通过短暂物理访问TPM 2.0及从其控制的系统启动重置重放测量值以解封密钥,认为SoC内部TPMs更安全,需结合用户PIN提升dTPM保护。

AI 中文摘要

测量启动(Measured Boot)是一种通过可信平台模块(TPMs)实现的机制,通常用于静态数据的无密码保护,旨在设备丢失或被盗时保护数据。微软对TPM的实现方式持中立立场:固件TPMs(fTPMs)被认为更经济但安全性较低。尽管离散TPMs(dTPMs)固有易受总线嗅探攻击,但仍被视为黄金标准,因为许多dTPMs在理论上提供更好的防篡改能力。人们常认为,总线加密以及理想情况下CPU与TPM之间的双向认证可缓解针对总线的攻击。本立场论文旨在强调针对dTPMs的另一种固有且难以缓解的攻击,该攻击最初在20多年前针对TPM 1.1被展示:我们证明,即使仅短暂物理访问TPM 2.0并能从攻击者控制的系统启动,攻击者也可重置并重放任意测量值,从而允许攻击者解封例如仅由TPM保护的磁盘加密密钥。虽然也存在针对fTPMs的攻击,但我们认为它们的实际攻击面从根本上更小。总线保护技术可用于保护dTPMs,但仅能防范被动攻击。总之,我们认为从安全角度看,固件TPMs或任何SoC内部的TPMs优于离散(外部)TPMs。最后,为使基于dTPM的设置能为密封密钥提供有意义的保护,配置必须要求用户提供的个人识别码(PIN)或密码与测量启动配置一同使用。

英文摘要

Measured Boot, a mechanism enabled through Trusted Platform Modules (TPMs), is commonly used for passwordless protection of data-at-rest, aiming to protect data when the device is lost or stolen. Microsoft's standpoint is neutral on which way a TPM should be implemented: Firmware-based TPMs (fTPMs) are viewed as more economical but less secure. Despite the inherent susceptibility to bus sniffing attacks, discrete TPMs (dTPMs) are still seen as the gold standard, as many deliver better on-paper tamper resistance. It is often argued that attacks against the bus can be mitigated by bus encryption and, ideally, mutual authentication between the CPU and TPM. This position paper aims to emphasize another inherent, difficult-to-mitigate attack against dTPMs that was originally shown against a TPM 1.1 over 20 years ago: We demonstrate that even brief physical access to a TPM 2.0 and the ability to boot from an attacker-controlled system enable an attacker to reset and replay arbitrary measurements, thereby allowing an attacker to unseal, for example, a disk encryption key solely protected by the TPM. While there have been attacks against fTPMs, too, we argue that their practical attack surface is fundamentally smaller. Bus protection techniques can be used to protect dTPMs, but only guard against passive attacks. After all, we argue that, from a security standpoint, firmware TPMs, or any TPM internal to the SoC, are superior to discrete (external) ones. Lastly, in order for dTPM-based setups to provide meaningful protection of sealed secrets, configurations must require a user-provided PIN or password along with the Measured Boot configuration.

CommentsPublished in: 2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)

DOI:10.1109/ACSACW69556.2025.00063

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑