中文

SGX 应用面临克隆攻击的真实威胁

密码学与安全 2026-01-15 v1

摘要

可信执行环境(TEEs)作为在云中提供机密性的有效手段正日益普及。诸如 Intel SGX 等 TEEs 存在所谓的回滚和克隆攻击(通常被称为分叉攻击)。回滚攻击是由于密封数据缺乏新鲜度保证而成为可能的;克隆攻击则源于无法确定同一平台上是否运行着同一飞地的其他实例。尽管社区对回滚攻击进行了广泛研究,但遗憾的是,克隆攻击受到的调查较少。为了弥补这一空白,我们广泛研究并深入分析了 72 个基于 SGX 的方案对克隆攻击的易感性。我们的结果表明,大约 20% 的被分析方案容易受到克隆攻击——包括那些依赖单调计数器因此能抵御回滚攻击的应用。

关键词

引用

@article{arxiv.2601.09273,
  title  = {The Real Menace of Cloning Attacks on SGX Applications},
  author = {Annika Wilde and Samira Briongos and Claudio Soriente and Ghassan Karame},
  journal= {arXiv preprint arXiv:2601.09273},
  year   = {2026}
}

备注

These results were presented at the Learning from Authoritative Security Experiment Results (LASER) Workshop 2023 and extend the paper "No Forking Way: Detecting Cloning Attacks on Intel SGX Applications", published in the Proceedings of the 39th Annual Computer Security Applications Conference (ACSAC) 2023