AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGX

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Dutly, Nicolas, Groschupp, Friederike, Puddu, Ivan, Kostiainen, Kari, Capkun, Srdjan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917019416264704
author Dutly, Nicolas
Groschupp, Friederike
Puddu, Ivan
Kostiainen, Kari
Capkun, Srdjan
author_facet Dutly, Nicolas
Groschupp, Friederike
Puddu, Ivan
Kostiainen, Kari
Capkun, Srdjan
contents To mitigate interrupt-based stepping attacks (notably using SGX-Step), Intel introduced AEX-Notify, an ISA extension to Intel SGX that aims to prevent deterministic single-stepping. In this work, we introduce AEX-NStep, the first interrupt counting attack on AEX-Notify-enabled Enclaves. We show that deterministic single-stepping is not required for interrupt counting attacks to be practical and that, therefore, AEX-Notify does not entirely prevent such attacks. We specifically show that one of AEX-Notify's security guarantees, obfuscated forward progress, does not hold, and we introduce two new probabilistic interrupt counting attacks. We use these attacks to construct a practical ECDSA key leakage attack on an AEX-Notify-enabled SGX enclave. Our results extend the original security analysis of AEX-Notify and inform the design of future mitigations.
format Preprint
id arxiv_https___arxiv_org_abs_2510_14675
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGX
Dutly, Nicolas
Groschupp, Friederike
Puddu, Ivan
Kostiainen, Kari
Capkun, Srdjan
Cryptography and Security
To mitigate interrupt-based stepping attacks (notably using SGX-Step), Intel introduced AEX-Notify, an ISA extension to Intel SGX that aims to prevent deterministic single-stepping. In this work, we introduce AEX-NStep, the first interrupt counting attack on AEX-Notify-enabled Enclaves. We show that deterministic single-stepping is not required for interrupt counting attacks to be practical and that, therefore, AEX-Notify does not entirely prevent such attacks. We specifically show that one of AEX-Notify's security guarantees, obfuscated forward progress, does not hold, and we introduce two new probabilistic interrupt counting attacks. We use these attacks to construct a practical ECDSA key leakage attack on an AEX-Notify-enabled SGX enclave. Our results extend the original security analysis of AEX-Notify and inform the design of future mitigations.
title AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGX
topic Cryptography and Security
url https://arxiv.org/abs/2510.14675