IP Library Granted Patent US 12,118,381
Granted Patent B2
US 12,118,381 · App. 18/197,824 · Granted Oct 15, 2024

Extraction of side channel information from multithreaded processors based on processor resource contention

Inventor: Viliam Holub (Prague, CZ)
Assignee: Rapid7, Inc.
G06F9/48G06F9/455G06F9/45558G06F9/4806G06F9/4843G06F9/4881G06F9/50G06F9/5027G06F9/5038G06F21/50G06F21/55G06F21/556G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,118,381
App. No.
18/197,824
Granted
Oct 15, 2024
Kind
B2
Abstract

Systems and methods are disclosed to implement a thread sensor generation system to generate thread sensors for extracting side channel information about other executing threads on a multithreading CPU. In embodiments, the system generates a set of sensors for evaluation. Each sensor may include a sequence of arithmetic or logic operations between variables or constants, which will cause a particular resource usage pattern by the CPU. The sensors are executed on the CPU in parallel with instances of a victim thread to measure an execution slowdown profile of the sensor thread caused by CPU resource conflicts with the victim thread. Based on the execution slowdown profiles, a sensitivity metric is calculated for each sensor, which is used to select the best sensor(s) for the victim thread. Sensors generated using the disclosed techniques can be used to extract secret information via side-channel attacks on currently available multithreaded processors.

Claims (66)

1. A method comprising:

performing, by one or more computer devices that implements a side channel information extraction system:

creating a plurality of sensors for extracting side channel information from a central processing unit (CPU) that executes multiple threads in parallel;

repeatedly executing the sensors in respective sensor threads on the CPU in parallel with a victim thread;

determining, based on the repeated execution of the sensors, a detection profile of the victim thread, wherein the detection profile indicates conditions of the CPU during execution of the victim thread comprising an execution slowdown of the sensor threads caused by CPU resource conflicts between the sensor threads and the victim thread;

executing the sensor threads again on the CPU to determine later conditions of the CPU; and

in response to a determination that the later conditions of the CPU sufficiently match the detection profile of the victim thread, generating an output indicating that the victim thread is detected on the CPU.

2. The method of claim 1 , wherein

the side channel information extraction system is implemented on an attacker machine that is remote from a victim machine associated with the CPU, and

the method comprises the side channel information extraction system uploading the sensors to the victim machine and downloading sensor results from the victim machine.

3. The method of claim 1 , wherein

the side channel information extraction system is implemented on an attacker virtual machine executing on a physical host,

the CPU is a physical CPU of the physical host, and

the victim thread is executed by a victim virtual machine executing on the physical host.

4. The method of claim 1 , further comprising:

the side channel information extraction system detecting different actions performed by the victim thread and time lapses between the different actions using sensor results generated by the sensor threads.

5. The method of claim 4 , wherein

the different actions comprise different steps of an encryption algorithm performed by the victim thread to encrypt a secret key, and

the method comprises the side channel information extraction system extracting at least a portion of the secret key using sensor results generated by the sensor threads.

6. The method of claim 1 , wherein

the victim thread performs a sequence of processing actions at a high resolution, and

the method comprises the side channel information extraction system:

executing the sensor threads using different sampling patterns; and

extracting a low-resolution view of the processing actions using sensor results generated by the sensor threads.

7. The method of claim 6 , wherein

the victim thread processes a high-resolution image, and

the method comprises the side channel information extraction system extracting a low-resolution version of the image using the sensor results.

8. The method of claim 1 , wherein

the method comprises the side channel information extraction system repeatedly generating new sensors to improve a sensitivity metric for detecting the victim thread.

9. The method of claim 8 , wherein

the new sensors are generated from one or more previous generations of sensors based on a genetic algorithm.

10. The method of claim 8 , wherein

the new sensors are generated using random sequences of instructions used by the victim thread.

11. The method of claim 8 , wherein

the new sensors are generated as code, and the code comprises a random sequence of operations and one or more system calls to measure an execution time of the random sequence of operations on the CPU.

12. A system comprising:

a side channel information extraction system implemented using one or more computer devices, configured to:

create a plurality of sensors for extracting side channel information from a central processing unit (CPU) that executes multiple threads in parallel;

repeatedly execute the sensors in respective sensor threads on the CPU in parallel with a victim thread;

determine, based on the repeated execution of the sensors, a detection profile of the victim thread, wherein the detection profile indicates conditions of the CPU during execution of the victim thread comprising an execution slowdown of the sensor threads caused by CPU resource conflicts between the sensor threads and the victim thread;

execute the sensor threads again on the CPU to determine later conditions of the CPU; and

in response to a determination that the later conditions of the CPU sufficiently match the detection profile of the victim thread, generate an output indicating that the victim thread is detected on the CPU.

13. The system of claim 12 , wherein

the side channel information extraction system is implemented on an attacker machine that is remote from a victim machine associated with the CPU, and

the side channel information extraction system is configured to upload the sensors to the victim machine and download sensor results from the victim machine.

14. The system of claim 12 , wherein

the side channel information extraction system is implemented on an attacker virtual machine executing on a physical host,

the CPU is a physical CPU of the physical host, and

the victim thread is executed by a victim virtual machine executing on the physical host.

15. The system of claim 12 , wherein

the side channel information extraction system is configured to use the sensor threads to detect different actions performed by the victim thread and time lapses between the different actions.

16. The system of claim 15 , wherein

the different actions comprise different steps of an encryption algorithm performed by the victim thread to encrypt a secret key, and

the side channel information extraction system is configured to extract at least a portion of the secret key using sensor results generated by the sensor threads.

17. The system of claim 12 , wherein

the victim thread performs a sequence of processing actions at a high resolution, and

the side channel information extraction system is configured to:

execute the sensor threads at one or more low sampling resolutions using different sampling patterns; and

use sensor results generated by the sensor threads to extract a low-resolution view of the processing actions.

18. The system of claim 17 , wherein

the victim thread processes a high-resolution image, and

the side channel information extraction system is configured to extract a low-resolution version of the image using the sensor results.

19. The system of claim 12 , wherein

the side channel information extraction system is configured to repeatedly generate new sensors to improve a sensitivity metric for detecting the victim thread.

20. The system of claim 19 , wherein

the side channel information extraction system is configured to generate the new sensors from one or more previous generations of sensors based on a genetic algorithm.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2024
From: HOLUB, VILIAM
To: RAPID7, INC.
Reel/Frame 068623/0059 →
Continuity (2)
Continuation 17183162 · Feb 23, 2021
Related Publication 20230289210A1 · Sep 14, 2023