Non deterministic caches: a simple and effective defense against side channel attacks

Non deterministic caches: a simple and effective defense against side channel attacks
复制标题

DOI:
10.1007/s10617-008-9018-y
复制
发表时间:
2008-09
影响因子:
1.4
通讯作者:
G. Keramidas;Alexandros Antonopoulos;D. Serpanos;S. Kaxiras
G. Keramidas;Alexandros Antonopoulos;D. Serpanos;S. Kaxiras
中科院分区:
计算机科学4区
文献类型:
--
作者:
G. Keramidas;Alexandros Antonopoulos;D. Serpanos;S. Kaxiras

文献摘要

被引文献

相似文献

侧信道密码分析最近受到了极大的关注,因为它提供了一种低成本和便捷的方式来揭示安全计算系统中持有的秘密信息。一种特殊类型的侧通道攻击被称为基于高速缓存的侧通道攻击,其目的是通过观察微处理器的高速缓冲存储器的数据依赖行为来推断关于密码算法或其密钥的状态的信息。事实证明,这些攻击是成功的,而且很难防范。在本文中,我们介绍了使用缓存延迟方法来帮助防范基于缓存的侧通道攻击。高速缓存衰减控制高速缓存项的寿命(称为衰减间隔),最初是为了节省高速缓存漏电而提出的。通过随机选择缓存的衰减间隔,我们实际上创建了具有关于其统计信息的非确定性行为的缓存。因此,正如我们所演示的那样,相同算法的多次运行(在相同的输入上执行)将导致不同的缓存统计信息,从而防御攻击者并加强系统提供的保护。在我们的工作中,我们使用了一个基于周期的处理器模拟器,并进行了必要的修改,以评估我们的方案,并表明我们的技术可以有效地防止基于缓存的旁路攻击。
Side channel cryptanalysishas received significant attention lately, because it provides a low-cost and facile way to reveal the secret information held on a secure computing system. One particular type of side channel attacks, calledcache-based side channel attacks, aims to deduce information about the state of a cryptographic algorithm or its key by observing the data-dependent behavior of a microprocessor’s cache memory. These attacks have been proven successful and very hard to protect against. In this paper, we introduce the use of theCache Decayapproach as an aid to guard against cache-based side channel attacks. Cache Decay controls the lifetime (calleddecay interval) of the cache items and was initially proposed for cache power leakage savings. By randomly selecting the decay interval of the cache, we actually create caches withnon-deterministicbehavior in regard to their statistics. Thus, as we demonstrate, multiple runs of the same algorithm (performing on the same input) will result in different cache statistics, defending against the attacker and reinforcing the protection offered by the system. In our work, we use a cycle-based processor simulator, enhanced with the required modifications, in order to evaluate our proposal and show that our technique can be used effectively to protect against cache-based side channel attacks.