Secure TLBs

Secure TLBs
复制标题

DOI:
10.1145/3307650.3322238
复制
发表时间:
2019-06
期刊:
2019 ACM/IEEE 46th Annual International Symposium on Computer Architecture (ISCA)
影响因子:
--
通讯作者:
Shuwen Deng;Wenjie Xiong;Jakub Szefer
Shuwen Deng;Wenjie Xiong;Jakub Szefer
中科院分区:
其他
文献类型:
--
作者:
Shuwen Deng;Wenjie Xiong;Jakub Szefer

文献摘要

被引文献

相似文献

本文重点介绍了现代处理器中的新攻击向量:基于计时的侧面和秘密通道攻击,这是由于翻译台式缓冲区(TLB)。本文首先提出了一种新颖的三步建模方法,该方法用于详尽地列举所有可能的基于TLB的基于TLB的漏洞。然后,本文以三步模型为基础,然后展示了如何自动生成测试TLB漏洞的微型安全基准。显示出标准TLB的不安全感后,提出了两个新的安全TLB设计:静态分区(SP)TLB和一个随机填充(RF)TLB。使用两种新设计增强了RISC-V处理器体系结构的Rocket Core实现,对新的安全TLB进行了评估。三步模型和安全基准用于分析模拟中新设计的安全性。基于分析,拟议的安全TLB不仅可以防御先前宣传的攻击,还可以抵抗使用新的三步模型发现的TLB中其他基于时机的攻击。在基于FPGA的设置上评估了性能开销,例如,在捍卫所有攻击时,RF TLB的开销小于10%。
This paper focuses on a new attack vector in modern processors: the timing-based side and covert channel attacks due to the Translation Look-aside Buffers (TLBs). This paper first presents a novel three-step modeling approach that is used to exhaustively enumerate all possible TLB timing-based vulnerabilities. Building on the three-step model, this paper then shows how to automatically generate micro security benchmarks that test for the TLB vulnerabilities. After showing the insecurity of standard TLBs, two new secure TLB designs are presented: a Static-Partition (SP) TLB and a Random-Fill (RF) TLB. The new secure TLBs are evaluated using the Rocket Core implementation of the RISC-V processor architecture enhanced with the two new designs. The three-step model and the security benchmarks are used to analyze the security of the new designs in simulation. Based on the analysis, the proposed secure TLBs can defend not only against the previously publicized attacks but also against other new timing-based attacks in TLBs found using the new three-step model. The performance overhead is evaluated on an FPGA-based setup, and, for example, shows that the RF TLB has less than 10% overhead while defending all the attacks.