防范物理攻击:Xbox One的故事 (2019)
Guarding Against Physical Attacks: The Xbox One Story (2019)

原始链接: https://www.platformsecuritysummit.com/2019/speaker/chen/

## Xbox One 安全性:抗盗版设计 在游戏历史上,Xbox One(和PS4)在上市近六年时间里,一直未被破解用于盗版和作弊。Tony Chen 的本次演示详细介绍了微软如何取得这一突破。 核心策略侧重于主动防御*物理*攻击,认识到所有数据源——闪存、硬盘,甚至内存——都可能被攻破。这涉及与AMD合作开发的定制系统级芯片 (SoC),其构建基于多虚拟机架构、强大的密钥管理和安全启动流程等关键安全原则。 至关重要的是,该设计假定数据不可信,并实施措施通过认证来验证系统完整性。这些硬件和软件的改变协同工作,以保护游戏机和在其上运行的游戏,代表着游戏机安全性的一次重大飞跃,并打破了以往被破解的历史循环。

一个黑客新闻的讨论强调了2019年关于Xbox One针对物理攻击的安全措施的报告——这通常被认为是安全领域的“游戏结束”。微软采取了重大措施来防止盗版和作弊芯片,尽管用户拥有对主机的完全物理访问权限。 讨论指出,这些技术超越了游戏领域的重要性,尤其是在企业安全方面(保护笔记本电脑免受间谍活动),因为物理访问风险是真实存在的。虽然有决心的攻击者*可以*构建自己的硬件,但对于具备相应技能的人来说,这种努力通常不值得。 讨论的时间点与最近的PlayStation 4黑客事件以及PS5加密密钥泄露事件相呼应,强调了硬件安全领域持续的斗争。参与者认为,随着物联网设备的增长,该领域将变得越来越重要。还提供了一个指向先前关于该主题的更广泛讨论的链接。
相关文章

原文

Guarding Against Physical Attacks: The Xbox One Story

Tony Chen
Microsoft

Every game console since the first Atari was more or less designed to prevent the piracy of games and yet every single game console has been successfully modified to enable piracy. However, this trend has come to an end. Both the Xbox One and the PS4 have now been on the market for close to 6 years, without hackers being able to crack the system to enable piracy or cheating. This is the first time in history that game consoles have lasted this long without being cracked to enable piracy.

In this talk, we will discuss how we achieved this for the Xbox One. We will first describe the Xbox security design goals and why it needs to guard against hardware attacks, followed by descriptions of the hardware and software architecture to keep the Xbox secure. This includes details about the custom SoC we built with AMD and how we addressed the fact that all data read from flash, the hard drive, and even DRAM cannot be trusted. We will also discuss the corresponding software changes we made to keep the system and the games secure.

Resources

Supply Chain

Reviews

Research

联系我们 contact @ memedata.com