AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGX
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866917019416264704 |
|---|---|
| author | Dutly, Nicolas Groschupp, Friederike Puddu, Ivan Kostiainen, Kari Capkun, Srdjan |
| author_facet | Dutly, Nicolas Groschupp, Friederike Puddu, Ivan Kostiainen, Kari Capkun, Srdjan |
| contents | To mitigate interrupt-based stepping attacks (notably using SGX-Step), Intel introduced AEX-Notify, an ISA extension to Intel SGX that aims to prevent deterministic single-stepping. In this work, we introduce AEX-NStep, the first interrupt counting attack on AEX-Notify-enabled Enclaves. We show that deterministic single-stepping is not required for interrupt counting attacks to be practical and that, therefore, AEX-Notify does not entirely prevent such attacks. We specifically show that one of AEX-Notify's security guarantees, obfuscated forward progress, does not hold, and we introduce two new probabilistic interrupt counting attacks. We use these attacks to construct a practical ECDSA key leakage attack on an AEX-Notify-enabled SGX enclave. Our results extend the original security analysis of AEX-Notify and inform the design of future mitigations. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2510_14675 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGX Dutly, Nicolas Groschupp, Friederike Puddu, Ivan Kostiainen, Kari Capkun, Srdjan Cryptography and Security To mitigate interrupt-based stepping attacks (notably using SGX-Step), Intel introduced AEX-Notify, an ISA extension to Intel SGX that aims to prevent deterministic single-stepping. In this work, we introduce AEX-NStep, the first interrupt counting attack on AEX-Notify-enabled Enclaves. We show that deterministic single-stepping is not required for interrupt counting attacks to be practical and that, therefore, AEX-Notify does not entirely prevent such attacks. We specifically show that one of AEX-Notify's security guarantees, obfuscated forward progress, does not hold, and we introduce two new probabilistic interrupt counting attacks. We use these attacks to construct a practical ECDSA key leakage attack on an AEX-Notify-enabled SGX enclave. Our results extend the original security analysis of AEX-Notify and inform the design of future mitigations. |
| title | AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGX |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2510.14675 |