Analysis of Secure Caches Using a Three-Step Model for Timing-Based Attacks

Analysis of Secure Caches Using a Three-Step Model for Timing-Based Attacks
复制标题

DOI:
10.1007/s41635-019-00075-9
复制
发表时间:
2019-11
期刊:
Journal of Hardware and Systems Security
影响因子:
--
通讯作者:
Shuwen Deng;Wenjie Xiong;Jakub Szefer
Shuwen Deng;Wenjie Xiong;Jakub Szefer
中科院分区:
其他
文献类型:
--
作者:
Shuwen Deng;Wenjie Xiong;Jakub Szefer

文献摘要

相似文献

许多安全的缓存设计已经在文献中提出了减轻不同类型的缓存定时为基础的攻击的目的。然而,到目前为止,还没有系统的分析,这些安全的缓存设计可以,或不能,防止不同类型的基于时间的攻击。为了提供一种分析缓存的方法,本文提出了一种新的三步建模方法,用于详尽地列举所有可能的缓存定时为基础的漏洞。该模型不仅涵盖利用来自本地处理器核的高速缓存访问或刷新的攻击,而且涵盖利用由于来自远程核的该高速缓存一致性协议动作而导致的该高速缓存状态的改变的攻击。此外,传统的攻击和投机执行攻击被认为是。通过从三步模型中导出的所有可能的缓存定时漏洞列表,这项工作进一步手动分析了现有的安全缓存设计,以显示每个安全缓存可以减轻哪些类型的基于定时的侧通道漏洞。基于新的三步模型对现有的安全缓存设计进行了安全分析,进一步总结了安全缓存设计中的不同技术及其对不同类型的缓存定时漏洞的缓解能力。
Many secure cache designs have been proposed in literature with the aim of mitigating different types of cache timing–based attacks. However, there has so far been no systematic analysis of how these secure cache designs can, or cannot, protect against different types of the timing-based attacks. To provide a means of analyzing the caches, this paper presents a novel three-step modeling approach that is used to exhaustively enumerate all the possible cache timing–based vulnerabilities. The model covers not only attacks that leverage cache accesses or flushes from the local processor core, but also attacks that leverage changes in the cache state due to the cache coherence protocol actions from remote cores. Moreover, both conventional attacks and speculative execution attacks are considered. With the list of all possible cache timing vulnerabilities derived from the three-step model, this work further manually analyzes each of the existing secure cache designs to show which types of timing-based side-channel vulnerabilities each secure cache can mitigate. Based on the security analysis of the existing secure cache designs using the new three-step model, this paper further summarizes different techniques gleaned from the secure cache designs and their ability help mitigate different types of cache timing–based vulnerabilities.