IP Library › Granted Patent US 12,254,087
Granted Patent B2
US 12,254,087 · App. 17/746,585 · Granted Mar 18, 2025

Translation lookaside buffer (TLB) poisoning attacks on secure encrypted virtualization

Inventors: Huibo Wang (Milpitas, CA); Kang Li (Santa Clara, CA); Mengyuan Li (Columbus, OH); Yinqian Zhang (Sunnyvale, CA); Yueqiang Cheng (San Jose, CA)
G06F21/566G06F9/45558G06F12/1483G06F21/52G06F21/54G06F21/554G06F21/556G06F21/577G06F21/602G06F21/75G06F2009/45583G06F2009/45587G06F2212/1052G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,254,087
App. No.
17/746,585
Granted
Mar 18, 2025
Kind
B2
Abstract

TLB poisoning attacks take advantage of security issues of translation lookaside buffer (TLB) management on SEV processors in Secure Encrypted Virtualization (SEV) virtual machines (VMs). In various embodiments, a hypervisor may poison TLB entries between two processes of a SEV VM to compromise the integrity and confidentiality of the SEV VM. Variants of TLB poisoning attacks and end-to-end attacks are shown to be successful on both Advanced Micro Devices (AMD) SEV and SEV-Encrypted State (SEV-ES). Countermeasures for thwarting TLB poisoning attacks include hardware-enforced TLB flush processes and re-exec schemes that, among other things, prevent attackers from manipulating TLB entries and causing a privileged victim process to execute malicious code in an attempt to bypass a password authentication.

Claims (12)

1. A hypervisor-controlled attack method for manipulating a privileged victim process's execution to bypass password authentication:

given an attacker process that operates on a first virtual CPU (vCPU) on a guest virtual machine (VM) and has obtained a virtual address of a victim process that operates on a second vCPU, using the attacker process to perform steps comprising:

in response to a victim process calling a target function whose virtual address has been mapped to a malicious code physical address, suspending execution of the target function at the physical address;

causing the virtual address in one or more translation lookaside buffer (TLB) entries to point to the malicious code physical address to generate one or more poisoned TLB entries; and

in response to a hypervisor pausing the victim process, suspending, after a context switch between the first vCPU and the second vCPU and before the victim process resumes processing, a TLB flush at a subsequent VM Exit (VMEXIT) event to access the one or more poisoned TLB entries and execute the malicious code to bypass a password authentication.

2. The method according to claim 1 , wherein the hypervisor uses one or more nested page fault (NPF) events to learn the physical address of the target function.

3. The method according to claim 2 , wherein the hypervisor, in response to learning the physical address of the target function, maps the virtual address of the victim process to the malicious code physical address.

4. The method according to claim 2 , wherein the hypervisor manipulates one or more page table entries to trigger the one or more NPF events.

5. The method according to claim 1 , wherein the hypervisor schedules the first vCPU at a same logical core as a second vCPU.

6. The method according to claim 1 , wherein the hypervisor uses one or more CPU identification (CPUID) instructions to initiate transmission or receipt of covert data in a CPUID-based covert data channel.

7. The method according to claim 6 , wherein the hypervisor causes the attacker process to execute the one or more CPUID instructions to trigger one or more VMEXIT events.

8. The method according to claim 1 , wherein the attacker process is an unprivileged process and the victim process is a privileged child secure shell daemon process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2022
From: WANG, HUIBO; LI, KANG; LI, MENGYUAN; ZHANG, YINQIAN; CHENG, YUEQIANG
To: BAIDU USA LLC
Reel/Frame 060263/0143 →
Continuity (2)
Provisional Application 63248418 · Sep 24, 2021
Related Publication 20230098117A1 · Mar 30, 2023
References Cited (49)
US 8209510B1 · Tuli · 2012 [cited by applicant]
US 11010495B1 · McArdle · 2021 [cited by examiner]
US 20010011304A1 · Coley · 2001 [cited by applicant]
US 20020046230A1 · Davis · 2002 [cited by applicant]
US 20080244155A1 · Lee · 2008 [cited by applicant]
US 20130047168A1 · Shah · 2013 [cited by applicant]
US 20190228155A1 · Basak · 2019 [cited by examiner]
US 20190361815A1 · Tsirkin · 2019 [cited by applicant]
US 20220114135A1 · Rahman · 2022 [cited by applicant]
US 20220264503A1 · Starsinic · 2022 [cited by applicant]
CN 111400081A · 2020 [cited by applicant]
Mi et al. “(Mostly) Exitless VM Protection from Untrusted Hypervisor through Disaggregated Nested Virtualization” SEC'20: Proceedings of the 29th USENIX Conference on Security Symposium Article No. 96, pp. 1695-1712 Aug… [cited by examiner]
Radev et al. “Exploiting Interfaces of Secure Encrypted Virtual Machines” arXiv:2010.07094 Oct. 14, 2020 (Year: 2020). [cited by examiner]
Morbitzer et al. “SEVerity: Code Injection Attacks against Encrypted Virtual Machines” arXiv:2105.13824 May 28, 2021 (Year: 2021). [cited by examiner]
Non-Final Office Action received in the related matter U.S. Appl. No. 17/746,559, mailed May 30, 2024, (27pgs). [cited by applicant]
AMD, “AMD virtualization (amd-v),” [online], [Retrieved Feb. 21, 2024]. Retrieved from Internet <URL:https://www.amd.com/en/technologies/>virtualization-solutions, 2021. (13pgs). [cited by applicant]
Costan et al.,“Intel SGX explained,” IACR Cryptol. ePrint Arch., vol. 2016, No. 86, pp. 1-118, 2016.(118 pgs). [cited by applicant]
Microsoft, “Azure and AMD announce landmark in confidential computing evolution,” [online], [Retrieved Feb. 21, 2024]. Retrieved from Internet <URL:https://azure.microsoft.com/en-us/blog/azure-and-amd-enable-lift-and-sh… [cited by applicant]
Google, “Introducing Google Cloud Confidential Computing with Confidential VMs,” [online], [Retrieved Feb. 21, 2024]. Retrieved from Internet <URL:https://cloud.google.com/blog/products/identity-security/introducing-goo… [cited by applicant]
Hetzelt et al., “Security Analysis of Encrypted Virtual Machines,” arXiv preprint arXiv:1612.01119, 2017. (14pgs). [cited by applicant]
Werner et al.,“The SEVerESt of Them All: Inference Attacks Against Secure Virtual Enclaves,” in ACM Asia Conference on Computer and Communications Security, 2019. (13 pgs). [cited by applicant]
D. Kaplan, “Protecting VM register state with SEV-ES,” White paper, 2017. (8pgs). [cited by applicant]
Buhren et al.,“Fault Attacks on Encrypted General Purpose Compute Platforms,” arXiv preprint arXiv:1612.03744, 2016. (18pgs). [cited by applicant]
Maurice et al.,“Hello from the other side: SSH over robust cache covert channels in the cloud,” in NDSS, vol. 17, 2017. (15pgs). [cited by applicant]
Lipp et al.,“Take a way: Exploring the security implications of AMD's cache way predictors,” in 15th ACM Asia Conference on Computer & Communications Security (ACM ASIACCS 2020), 2020.(13pgs), 2020. [cited by applicant]
Lee et al.,“From zygote to morula: Fortifying weakened aslr on android,” in 2014 IEEE Symposium on Security & Privacy, IEEE, 2014. (16 pgs). [cited by applicant]
M. Johnston, “Dropbear SSH,” [online], [Retrieved Feb. 22, 2024]. Retrieved from Internet <URL:https://github.com/mkj/dropbear> 2021.(1p). [cited by applicant]
H. Shacham, “The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86),” In: 14th ACM Conference on Computer and Communications Security (ACM), 2007. (30pgs), 2007. [cited by applicant]
NVD, [online], [Retrieved Feb. 20, 2024]. Retrieved from Internet <URL:https://nvd.nist.gov/vuln/detail/CVE-2021-26340> (23pgs), 2021. [cited by applicant]
AMD, [online], [Retrieved Feb. 22, 2024]. Retrieved from Internet <URL:https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1023> (10pgs). [cited by applicant]
Li et al.,“Cipherleaks: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel,” in 30th USENIX Security Symposium, 2021. (17pgs). [cited by applicant]
Du et al.,“Secure encrypted virtualization is unsecure,” arXiv preprint arXiv:1712.05090, 2017. (10pgs). [cited by applicant]
Morbitzer et al.,“SEVered: Subverting AMD's virtual machine encryption,” arXiv preprint arXiv:1805.09604, 2018. (6pgs). [cited by applicant]
Morbitzer et al.,“Extracting Secrets from Encrypted Virtual Machines,” arXiv preprint arXiv:1901.01759, 2019. (10pgs). [cited by applicant]
Li et al.,“Exploiting Unprotected I/O Operations in AMD's Secure Encrypted Virtualization,” in 28th USENIX Security Symposium, 2019. (17pgs). [cited by applicant]
Wilke et al.,“SEVurity: No security without integrity: Breaking integrity-free memory encryption with minimal assumptions,” arXiv preprint arXiv:2004.11071, 2020. (14pgs). [cited by applicant]
AMD, “AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More,” White paper, 2020.(20pgs). [cited by applicant]
Li et al.,“CrossLine: Breaking “Security-by-Crash” based Memory Isolation in AMD SEV,” arXiv preprint arXiv:2008.00146, 2020. (14pgs). [cited by applicant]
Kaplan et al.,“AMD memory encryption,” White paper, 2021. (12pgs). [cited by applicant]
AMD, “AMD64 architecture programmer's manual vol. 2: System programming,” AMD64 Technology, 2019. (833pgs). [cited by applicant]
Hund et al.,“Practical Timing Side Channel Attacks Against Kernel Space ASLR,” in 2013 IEEE Symposium on Security & Privacy, IEEE, 2013. (15pgs). [cited by applicant]
Jang et al.,“Breaking kernel address space layout randomization with intel TSX,” in Proc. of the 2016 ACM SIGSAC Conference on Computer & Communications Security, 2016.(13pgs). [cited by applicant]
Barresi et al.,“CAIN: silently breaking ASLR in the cloud,” in 9th USENIX Workshop on Offensive Technologies (WOOT 15), 2015. (9pgs). [cited by applicant]
Koschel et al.,“TagBleed: Breaking KASLR on the Isolated Kernel Address Space using Tagged TLBs,” in 2020 IEEE European Symposium on Security & Privacy (EuroS&P), IEEE, 2020. (13pgs), 2020. [cited by applicant]
Gras et al.,“ASLR on the Line: Practical Cache Attacks on the MMU,” in NDSS, vol. 17, 2017. (15pgs). [cited by applicant]
Weston et al.,“Windows 10 mitigation improvements,” Black Hat USA, 2016. (41 pgs). [cited by applicant]
AMD, “AMD-V nested paging,” [online], [Retrieved Feb. 22, 2024]. Retrieved from Internet <URL:http://developer.amd.com/wordpress/media/2012/10/NPT-WP-1%201-final-TM.pdf> 2008.(13P. [cited by applicant]
“AMDSEV/SEV-ES branch,” [online], [Retrieved Feb. 22, 2024]. Retrieved from Internet <URL:https://github.com/AMDESE/AMDSEV/tree/sev-es> 2020. (1p). [cited by applicant]
Maurice et al.,“C5: Cross-Cores Cache Covert Channel,” in International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Springer, 2015.[Abstract] (12 pgs), 2015. [cited by applicant]