Skip to main content
  1. Home
  2. Computing
  3. News

Researchers bypass Intel's Software Guard Extensions to access RSA keys

Add as a preferred source on Google

Intended to help users keep their systems safe and secure, Intel Software Guard Extensions is a set of CPU instructions that can make particular portions of code and data private. However, a new paper suggests that SGX could in fact be used to facilitate a malicious attack.

Samuel Weiser and four collaborators from the Graz University of Technology in Austria have published research that demonstrates how SGX can be used to conceal a piece of malware. Within minutes, this technique was used to gain access to RSA keys hidden in SGX enclaves, according to a report from The Register.

Recommended Videos

The researchers developed a method of monitoring vulnerable cache sets that allowed them to spot the telltale signature of an RSA key calculation. “Key recovery comes in three steps,” reads the paper. “First, traces are preprocessed. Second, a partial key is extracted from each trace. Third, the partial keys are merged to recover the private key.”

Tests were run on an SGX-capable Lenovo ThinkPad T460S, which was running Ubuntu version 16.10. The team found that a single cache trace offered access to 96 percent of a 4,096-bit RSA key, and it only took eleven traces for the complete key to be assembled. The process took less than five minutes.

The authors of the paper said it’s possible to block the type of attack that they’ve demonstrated. However, the responsibility of addressing the vulnerability falls to Intel, as changes made to operating systems could end up causing further damage to the SGX model.

This isn’t the first time that Weiser has gone public with evidence that SGX is vulnerable. In January 2017, he was part of a group of researchers that published a paper that demonstrated how its input-output protections could be abused to gain access to private user data.

Digital Trends was given the following statement by Intel:

There have been many academic articles looking at the security of SGX, including side-channel attacks. In general these papers do not demonstrate anything new or unexpected about the Intel SGX architecture.

Preventing side channel attacks is a matter for the enclave developer. Intel makes this clear In the security objectives for SGX, which are well documented. The types of side-channel attacks identified on the RSA implementation used in the Graz paper were well-known for some time and are addressed by other crypto libraries available to developers (e.g. OpenSSL).

Updated on 03-17-2017 by Brad Jones: Added statement from Intel.
Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
AI tools that help students cheat are multiplying, and the detectors can’t keep up
A New York Times report has found that cheating tools are evolving faster than the software meant to catch AI writing.
GPTZero website on a laptop

A wave of new apps marketed on TikTok and YouTube is making it nearly impossible for teachers to tell whether students are actually writing their own homework or offloading it to AI. The New York Times reports that tools known as humanizers and autotypers have closed the gap that used to give AI-written homework away, and that the same companies selling detection software are sometimes the ones helping students get around it.

The tools work around the checks teachers rely on

Read more
This monstrous ASUS gaming laptop costs as much as three new MacBook Pros
Asus’ flagship gaming laptop is back, bigger, brighter, and wildly expensive.
ASUS ROG Strix Scar 18 Computex 2026

Following up on the ROG Strix Scar 18 (2025)'s impressive act, ASUS has built a successor that looks even more ridiculous if you glance at the spec sheet. The ROG Strix Scar 18 (2026) is not a cute little café laptop. The flagship gaming machine is built around a large 18-inch 4K miniLED display and hardware that embarrasses most desktop PCs.

But all of this comes at a cost, and you might want to sit down for this one.

Read more
ASUS fanboys can now spend $16,578 on its 20th anniversary gaming gear
ASUS ROG Family Bucket Collector’s Edition Featured

ASUS’ Republic of Gamers brand is celebrating its 20th anniversary by bringing a five-figure collection of its coolest gaming hardware. The company just revealed pricing for its ROG 20th Anniversary Family Bucket Collector’s Edition, a monster bundle that costs 112,026 yuan, or roughly $16,578. The collection is apparently selling through an offline flash sale in Shanghai from June 20 to July 19, with buyers being selected through a lottery system.

This is more than your typical PC upgrade. ASUS is selling you the whole ROG lifestyle starter pack, which will attract collectors after their next limited edition bundle.

Read more