Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance Computing

Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance Computing
复制标题

DOI:
10.14722/ndss.2019.23061
复制
发表时间:
2018
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Jiyong Yu;Lucas Hsiung;Mohamad El Hajj;Christopher W. Fletcher
Jiyong Yu;Lucas Hsiung;Mohamad El Hajj;Christopher W. Fletcher
中科院分区:
其他
文献类型:
--
作者:
Jiyong Yu;Lucas Hsiung;Mohamad El Hajj;Christopher W. Fletcher

文献摘要

被引文献

相似文献

封锁微体系(数字)侧渠道是当今硬件安全性最紧迫的挑战之一。敏感的数据依赖于共享资源,但是,当今现代机器上的数据目标程序是不安全的,首先是在当今的ISAS中的某些说明,而当今没有提供此类保证,以避免数据依赖数据的行为是固有的高性能开销。目前的ISA设计原则可以阻止微体系侧渠道,并在能够在性能方面安全执行现有数据的具体ISA中体现这些想法。现代硬件优化,例如,在常见的情况下,我们提供了一个完整的硬件原型,以启用我们的想法。并证明OISA可以通过对抽象繁荣式机器进行正式分析来提供广告安全性,我们评估支持我们原型所需的硬件机制的开销,并提供性能实验除了提高其安全性和可移植性外,遗忘代码(包括“恒定时间”密码学和记忆遗忘的数据结构)。
Blocking microarchitectural (digital) side channels is one of the most pressing challenges in hardware security today. Recently, there has been a surge of effort that attempts to block these leakages by writing programs data obliviously. In this model, programs are written to avoid placing sensitive data-dependent pressure on shared resources. Despite recent efforts, however, running data oblivious programs on modern machines today is insecure and low performance. First, writing programs obliviously assumes certain instructions in today’s ISAs will not leak privacy, whereas today’s ISAs and hardware provide no such guarantees. Second, writing programs to avoid data-dependent behavior is inherently high performance overhead. This paper tackles both the security and performance aspects of this problem by proposing a Data Oblivious ISA extension (OISA). On the security side, we present ISA design principles to block microarchitectural side channels, and embody these ideas in a concrete ISA capable of safely executing existing data oblivious programs. On the performance side, we design the OISA with support for efficient memory oblivious computation, and with safety features that allow modern hardware optimizations, e.g., out-of-order speculative execution, to remain enabled in the common case. We provide a complete hardware prototype of our ideas, built on top of the RISC-V out-of-order, speculative BOOM processor, and prove that the OISA can provide the advertised security through a formal analysis of an abstract BOOM-style machine. We evaluate area overhead of hardware mechanisms needed to support our prototype, and provide performance experiments showing how the OISA speeds up a variety of existing data oblivious codes (including “constant time” cryptography and memory oblivious data structures), in addition to improving their security and portability.