Cache-Out: Leaking Cache Memory Using Hardware Trojan

Cache-Out: Leaking Cache Memory Using Hardware Trojan
复制标题

DOI:
10.1109/tvlsi.2020.2982188
复制
发表时间:
2020-06-01
影响因子:
2.8
通讯作者:
Ghosh, Swaroop
Ghosh, Swaroop
中科院分区:
工程技术2区
文献类型:
--
作者:
Khan, Mohammad Nasim Imtaiz;De, Asmit;Ghosh, Swaroop

文献摘要

被引文献

相似文献

数据泄露是当前系统中一个重要的安全问题。现有的数据泄露防护技术假设底层硬件平台是安全且不可篡改的。在这项工作中,我们提出了 Cache-Out,这是一类涉及硬件被 CPU 中嵌入的特洛伊木马入侵的系统攻击。我们假设 L1 d-cache 中存在内存木马触发器,如果​​ L1 d-cache 的一个特定地址被特定数据模式攻击一定次数,该触发器就会被激活。一旦木马被触发,访问其他地址就会产生读干扰、写干扰、保留失败、信息泄露等负载。我们主要利用纳米高速缓存外围设备中采用的先进电路功能,例如用于静态 RAM (SRAM) 的字线欠驱动 (WLUD)(防止读干扰)和负位线 (NBL)(辅助写入)来传递有效负载。仿真表明 WLUD 和 NBL 操作可以分别注入读取和写入失败。我们还表明,写入操作期间 WLUD 激活可能会注入写入失败。此外,NBL 和列复用也可以用来窃取数据。我们使用 GEM5 架构模拟器验证了 Cache-Out。我们提出 L1 地址混淆、读/写验证、加扰纠错码 (ECC) 位和可信 ECC 作为对策。结果表明,在 64 位字大小的 22 纳米技术中,读/写验证需要 7.56 μ m(2) 的面积和 0.1 μW/91.3 μW 的静态/动态功耗。
Data leakage is an important security concern in current systems. Existing data leakage prevention techniques assume that the underlying hardware platform is secure and free from tampering. In this work, we present Cache-Out, a class of system attacks involving hardware compromised with a Trojan embedded in the CPU. We assume that a memory Trojan trigger is present in L1 d-cache and gets activated if one particular address of L1 d- cache is hammered with a particular data pattern for a certain number of times. Once the Trojan is triggered, accessing another address delivers payloads, such as, read disturb, write disturb, retention failure, and information leakage. We mainly exploit the advanced circuit features employed in the peripherals of nanometer cache memories, such as wordline underdrive (WLUD) (prevents read disturb) and negative bitline (NBL) (assists write) for static RAM (SRAM) to deliver the payloads. Simulation indicates that WLUD and NBL manipulation can inject read and write failures, respectively. We also show that WLUD activation during write operation can inject write failure. Furthermore, NBL along with column multiplexing can also be leveraged to steal data. We validated Cache-Out using GEM5 architectural simulator. We propose L1 address obfuscation, read/write verification, scrambling error correcting code (ECC) bits, and trusted ECC as countermeasures. Results indicate that read/write verification incurs 7.56 mu m(2) of area and 0.1 mu W/91.3 mu W of static/dynamic power in 22-nm technology for a 64-bit word size.