BEGIN:VCALENDAR
VERSION:2.0
PRODID:Linklings LLC
BEGIN:VTIMEZONE
TZID:America/Los_Angeles
X-LIC-LOCATION:America/Los_Angeles
BEGIN:DAYLIGHT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
DTSTART:19700308T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
TZNAME:PST
DTSTART:19701101T020000
RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20260402T024533Z
LOCATION:3006\, Level 3
DTSTART;TZID=America/Los_Angeles:20250623T140000
DTEND;TZID=America/Los_Angeles:20250623T141500
UID:dac_DAC 2025_sess153_RESEARCH1860@linklings.com
SUMMARY:"OOPS!": Out-Of-Band Remote Power Side-Channel Attacks on Intel SG
 X and TDX
DESCRIPTION:Nimish Mishra, Kislay Arya, and Sarani Bhattacharya (Indian In
 stitute of Technology, Kharagpur); Paritosh Saxena (Intel Corporation); an
 d Debdeep Mukhopadhyay (Indian Institute of Technology, Kharagpur)\n\nPrio
 r work shows that remote power attacks on Intel processors are possible th
 rough two Model Specific Registers (MSRs): MSR_PKG_Energy_Status and MSR_P
 P0_Energy_Status. In response, Intel introduced a defence: a bit in MSR IA
 32_MISC_PACKAGE_CTLS allows users to enable/disable "filtering'' mechanism
  that adds additional noise to energy measurements, making remote power at
 tacks infeasible.\n\nIn this work, we demonstrate that "filtering'' does n
 ot cover all possible avenues of measuring power. On Intel server-grade pl
 atforms, components like out-of-band management interface (OOB) exist whic
 h also expose telemetric information like in-band energy consumption. For 
 this, we first reverse engineer the protocol structure over which OOB comm
 unicates with in-band components. We then show how OOB allows read-only ac
 cess to the Package Configuration Space (PCS) and note that energy reading
 s through PCS are outside the scope of filtering.\n\nUsing this, we re-ena
 ble remote power side-channels on Intel SGX and TDX operational on Intel S
 apphire Rapids. We first construct a synchronization mechanism to align in
 -band execution with out-of-band measurements by leveraging deliberately d
 isabled MSRs. We then use energy readings through OOB PCS to recover 2048-
 bit RSA keys from MbedTLS operational within in-band Intel SGX and TDX (wi
 th generic single-stepping assumption). Finally, we also leak AESNI keys f
 rom within in-band Intel SGX and TDX (without any single-step assumption).
 \n\nPrior to our work, the literature on side-channels has been focused on
  attacks leveraging in-band interfaces. Our work establishes the importanc
 e of evaluating confidential computing architectures against attack vector
 s that combine abilities of both in-band and out-of-band interfaces to ach
 ieve adversarial objectives (that both in-band and out-of-band interfaces 
 cannot achieve independently).\n\nTopics: Security\n\nTracks: SEC3: Hardwa
 re Security: Attack & Defense\n\nSession Chairs: Tinoosh Mohsenin (Johns H
 opkins University) and Sazadur Rahman (University of Central Florida)\n\n
END:VEVENT
END:VCALENDAR
