Woomin Lee

dblp:194/3313 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2025
0009-0002-1081-1133ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 T-Time: A Fine-Grained Timing-Based Controlled-Channel Attack Against Intel TDX
Woomin Lee, Seunghee Shin, Junbeom Hur, Young-joo Shin
ESORICS (3)1
2024 POSTER: On the Feasibility of Inferring SGX Execution through PMU
abstract
Intel SGX is a power technology designed to establish a trusted execution environment on processors. Despite its promising features, there are various potential attack surfaces like the Performance Monitoring Unit (PMU) that could be exploited to extract security-sensitive data from SGX enclaves. To address this security threat, Intel has introduced anti side-channel interface (ASCI) that disables the PMU when an SGX enclave is running. However, little attention has been paid to performing the security evaluation of the ASCI feature, leaving the possibility of reviving such an attack. In this paper, we study if Intel's ASCI feature truly hides the internal execution state of SGX enclaves from the PMU to completely eliminate PMU-driven attack surfaces. To achieve this, we design a novel framework that investigates the effect of the running enclave on all possible performance monitoring events. The key idea of our framework is to (i) analyze the linearity between the number of instructions executed within an enclave and the corresponding measured events and (ii) perform single-stepping and zero-stepping attacks with performance monitoring events. Our security evaluation demonstrates that SGX enclave does not leave any footprint on PMUs, except for opt-in (i.e., debug) enclave where a hardware-based protection mechanism is not supported.
Woomin Lee, Young-joo Shin
AsiaCCS1