News by Xiaomi Miui Hellas

Hertzbleed: New vulnerability in Intel and AMD CPUs allows hackers to steal encryption keys

Hertzbleed logo

The processors of Intel, AMD and other companies contain a recently discovered security vulnerability

ΜIn this way, malicious users can be exploited to obtain cryptographic keys and other secret data transmitted through the material, researchers said on Tuesday.

Hardware makers have long known that hackers can extract secret cryptographic data from a chip by measuring the power it consumes when processing these values. Fortunately, the tools for exploiting microprocessor power analysis attacks are limited because the threat factor has few viable ways to remotely measure power consumption when processing encrypted data. Now, a team of researchers has found a way to turn power analysis attacks into a different category of side channel exploitation that is much less demanding.

The team found that dynamic voltage and frequency scaling (DVFS) - a power and heat management feature added to every modern CPU - allows intruders to calculate changes in power consumption by carefully monitoring the time it takes for a server to respond to specific queries. Discovery significantly reduces the time required.

By understanding how DVFS works, lateral power channel attacks become much simpler attacks that can be done remotely. The researchers named their attack Hertzbleed because it uses DVFS information to expose - or steal - data that is expected to remain private.

Vulnerability is monitored as CVE-2022-24436 for chips Intel and CVE-2022-23823 for processors AMD. Researchers have already shown how the exploitation technique they developed can be used to extract an encryption key from a server running SIKE, a cryptographic algorithm used to create a secret key between two parties through an otherwise insecure channel. communication.

Mi TeamDo not forget to follow it on Google News to be informed immediately about all our new articles! You can also if you use RSS reader, add our page to your list by simply following this link >>


Follow us on Telegram  so that you are the first to learn our every news!


Follow us on Telegram (English language) so that you are the first to learn our every news!

Read also

Leave a comment

* By using this form you agree to the storage and distribution of your messages on our page.

This site uses Akismet to reduce spam. Learn how your comment is processed.

Leave a Review

Read also
The online platform for submitting applications opens today, Friday 17 June, in order for…
Translate »