See More

Crypto Keys Could Be Compromised by Intel and AMD ‘Hertzbleed’ Chip Vulnerability

2 mins
Updated by Geraint Price
Join our Trading Community on Telegram

In Brief

  • The attack observes power signature of any cryptographic workload.
  • Modern Intel Core and AMD Ryzen chips are affected.
  • It is not practical outside of a lab environment according to Intel.
  • promo

Researchers have discovered a vulnerability in Intel and AMD central processing units (CPUs) that could be used by malicious actors to access cryptographic keys.

According to researchers at the University of Texas Austin, the University of Illinois at Urbana-Champaign, and the University of Washington, a vulnerability called “Hertzbleed” in CPUs could allow “side-channel attacks” that can steal cryptographic keys.

CPUs from both chip giants Intel and AMD are affected. These include Intel desktop and laptop models from the eighth to the 11th generation Core microarchitecture, and AMD Ryzen chips desktop and laptop models from the Zen 2 and Zen 3 microarchitectures.

The vulnerability was reported by computer hardware outlet Tom’s Hardware. Both Intel and AMD have issued advisories about the issue.  

Hertzbleed attack

Hertzbleed is a new type of side-channel attack called frequency side channels (hence the name Hertz and bleeding out the data). According to the research paper on the attack:

“In the worst case, these attacks can allow an attacker to extract cryptographic keys from remote servers that were previously believed to be secure.”

A Hertzbleed attack observes the power signature of any cryptographic workload and uses this to steal the data. This power signature varies due to the CPU’s dynamic boost clock frequency adjustments during the workload, reported Tom’s Hardware.

Dynamic voltage and frequency scaling (DVFS) is a feature of modern processors used to reduce power consumption, so the vulnerability is not a bug.

Attackers can deduce the changes in power consumption by monitoring the time it takes for a server to respond to specific queries.

“Hertzbleed is a real, and practical, threat to the security of cryptographic software,” the researchers noted.

In 2020, Be[In]Crypto reported the discovery of a flaw in Intel’s SGX (Software Guard Extension) that could also lead to side-channel attacks and compromised crypto keys.

Is there a workaround?

Intel and AMD have no current plans to deploy any firmware patches to mitigate Hertzbleed which can also be exploited remotely, however, there are workarounds.

According to the chip companies, the workaround to mitigate Hertzbleed is to disable frequency boost. For Intel CPUs the feature is called “Turbo Boost”, and for AMD chips it is known as “Turbo Core” or “Precision Boost”. However, this is likely to impact the performance of the processor, they noted.

According to Intel Senior Director of Security Communications and Incident Response Jerry Bryant, this attack is not practical outside of a lab environment, partially because it takes “hours to days” to steal a cryptographic key. He added that “cryptographic implementations that are hardened against power side-channel attacks are not vulnerable to this issue.”

Top crypto platforms in the US | March 2024
Coinbase Coinbase Explore →
AlgosOne AlgosOne Explore →
Chain GPT Chain GPT Explore →
iTrustCapital iTrustCapital Explore →

Trusted

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.

profile.jpg
Martin Young
Martin Young is a seasoned cryptocurrency journalist and editor with over 7 years of experience covering the latest news and trends in the digital asset space. He is passionate about making complex blockchain, fintech, and macroeconomics concepts understandable for mainstream audiences.   Martin has been featured in top finance, technology, and crypto publications including BeInCrypto, CoinTelegraph, NewsBTC, FX Empire, and Asia Times. His articles provide an in-depth analysis of...
READ FULL BIO
Sponsored
Sponsored