HomeinetResearchers extract secret encryption key of Intel CPU code

Researchers extract secret encryption key for Intel CPU code

Researchers have for the first time extracted the secret key that encrypts updates to a variety of Intel processors .

Intel

The key makes it possible to decrypt microcode updates that Intel provides to fix security vulnerabilities and other types of bugs. Having a decrypted copy of an update could allow malicious actors to reverse engineer it and learn exactly how to exploit the security flaw it fixes. The key could also allow a chip to be updated with other microcodes, although this customized version would not be able to survive a reboot.

The key can be extracted for any chip – be it Celeron, Pentium or Atom – based on Intel's Goldmont.

The effort to find it began three years earlier, when Goryachy and Ermolov found a critical vulnerability known as Intel SA-00086, which allowed them to execute arbitrary code inside the chips' independent core, which included a subsystem known as the Intel Management Engine. Intel fixed the bug and released a patch, but because the chips can always be rolled back to an older firmware version and then exploited, there is no way to effectively eliminate the vulnerability.

Researchers extract secret encryption key for Intel CPU code

Five months ago, the trio was able to use the vulnerability to access “Red Unlock,” a service feature built into Intel chips. The company’s engineers use this feature to find microcode bugs before publicly releasing a chip. The researchers called their tool Chip Red Pillbecause it allows researchers to experience the inner workings of a chip that is usually off-limits. The technique works by using a USB cable or a special Intel adapter that pipes data to a vulnerable CPU.

Accessing a Goldmont CPU in Red Unlock mode allowed the researchers to extract a special ROM area known as MSROM. From there, they began the painstaking process of reverse engineering the microcode. After months of analysis, they were able to uncover the update process and the RC4 key it uses. The analysis, however, did not reveal the signing key that Intel uses to cryptographically prove the authenticity of an update. This discovery has raised many questions about security.

Theoretically, it could be possible to use the Red Pill chip in a malicious attack, through which someone could hack a device. However, for such an attack to succeed, the device must be connected. Once rebooted, the chip will return to its normal state. In some cases, the ability to execute arbitrary microcode within the CPU could also be useful for attacks on encryption keys, such as those used in trusted platform units.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS