SmmPack: Obfuscation for SMM Modules with TPM Sealed Key

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Matsuo, Kazuki, Tanda, Satoshi, Suzaki, Kuniyasu, Kawakoya, Yuhei, Mori, Tatsuya
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910439204454400
author Matsuo, Kazuki
Tanda, Satoshi
Suzaki, Kuniyasu
Kawakoya, Yuhei
Mori, Tatsuya
author_facet Matsuo, Kazuki
Tanda, Satoshi
Suzaki, Kuniyasu
Kawakoya, Yuhei
Mori, Tatsuya
contents System Management Mode (SMM) is the highest-privileged operating mode of x86 and x86-64 processors. Through SMM exploitation, attackers can tamper with the Unified Extensible Firmware Interface (UEFI) firmware, disabling the security mechanisms implemented by the operating system and hypervisor. Vulnerabilities enabling SMM code execution are often reported as Common Vulnerabilities and Exposures (CVEs); however, no security mechanisms currently exist to prevent attackers from analyzing those vulnerabilities. To increase the cost of vulnerability analysis of SMM modules, we introduced SmmPack. The core concept of SmmPack involves encrypting an SMM module with the key securely stored in a Trusted Platform Module (TPM). We assessed the effectiveness of SmmPack in preventing attackers from obtaining and analyzing SMM modules using various acquisition methods. Our results show that SmmPack significantly increases the cost by narrowing down the means of module acquisition. Furthermore, we demonstrated that SmmPack operates without compromising the performance of the original SMM modules. We also clarified the management and adoption methods of SmmPack, as well as the procedure for applying BIOS updates, and demonstrated that the implementation of SmmPack is realistic.
format Preprint
id arxiv_https___arxiv_org_abs_2405_04355
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle SmmPack: Obfuscation for SMM Modules with TPM Sealed Key
Matsuo, Kazuki
Tanda, Satoshi
Suzaki, Kuniyasu
Kawakoya, Yuhei
Mori, Tatsuya
Cryptography and Security
System Management Mode (SMM) is the highest-privileged operating mode of x86 and x86-64 processors. Through SMM exploitation, attackers can tamper with the Unified Extensible Firmware Interface (UEFI) firmware, disabling the security mechanisms implemented by the operating system and hypervisor. Vulnerabilities enabling SMM code execution are often reported as Common Vulnerabilities and Exposures (CVEs); however, no security mechanisms currently exist to prevent attackers from analyzing those vulnerabilities. To increase the cost of vulnerability analysis of SMM modules, we introduced SmmPack. The core concept of SmmPack involves encrypting an SMM module with the key securely stored in a Trusted Platform Module (TPM). We assessed the effectiveness of SmmPack in preventing attackers from obtaining and analyzing SMM modules using various acquisition methods. Our results show that SmmPack significantly increases the cost by narrowing down the means of module acquisition. Furthermore, we demonstrated that SmmPack operates without compromising the performance of the original SMM modules. We also clarified the management and adoption methods of SmmPack, as well as the procedure for applying BIOS updates, and demonstrated that the implementation of SmmPack is realistic.
title SmmPack: Obfuscation for SMM Modules with TPM Sealed Key
topic Cryptography and Security
url https://arxiv.org/abs/2405.04355