Flush+Revisit: A Cross-CCX Side-Channel Attack on AMD Processors
Danping Li, Ziyuan Zhu, Jiao Shen, Yusha Zhang, Gang Shi, Dan Meng · 2023
Cross-core cache side-channel attacks allow attackers to launch more threatening cross-virtual machine (cross-VM) attacks in the virtualized environment. Most of these cross-core cache side-channel attacks take advantage of the feature that the last-level cache (LLC) is shared by all cores. However, these attacks may not perform well in cross-core attacks on processors that the LLC is not shared by all cores. This paper mainly focuses on the AMD Zen series processors, which introduce the design of the CPU complex (or Core Complex, CCX), and different CCXs have their independent LLCs. We find that previous cross-core cache side-channel attacks such as Flush+Reload do not work well in crossing CCXs on these processors, as these attacks mainly utilize the sharing characteristics of the LLC between different cores. In this paper, we present a cross-CCX side-channel attack named Flush+Revisit. As far as we know, we are the first to study cross-CCX side-channel attacks on AMD processors. Compared with traditional cache side-channel attacks, when crossing CCX, a more distinguishable time difference can be observed between accessed and unaccessed addresses with Flush+Revisit. We have carried out evaluation experiments to show that Flush+Revisit is an effective cross-CCX side-channel attack on an AMD Ryzen 7 3700X processor, which is known to have employed the CCX structure. In addition, we have also applied Flush+Revisit in a real-world attack scenario: attacking the T-Table-based AES implementation of OpenSSL in the cross-CCX scenario and leaking the full 128-bit key on the AMD Ryzen 7 3700X processor within 3.75 seconds successfully, with an error rate of 0.00%.