OPTIMUS: A Security-Centric Dynamic Hardware Partitioning Scheme for Processors that Prevent Microarchitecture State Attacks

OPTIMUS: A Security-Centric Dynamic Hardware Partitioning Scheme for Processors that Prevent Microarchitecture State Attacks
复制标题

OPTIMUS:一种以安全为中心的动态硬件分区方案,用于防止微架构状态攻击的处理器

DOI:
10.1109/tc.2020.2996021
复制
发表时间:
2020
影响因子:
3.7
通讯作者:
Khan, Omer
Khan, Omer
中科院分区:
计算机科学2区
文献类型:
--
作者:
Omar, Hamza;Dagostino, Brandon;Khan, Omer

文献摘要

参考文献

被引文献

相似文献

硬件虚拟化允许多个安全关键和普通(不安全)进程在处理器上共同执行。这些进程在时间上共享硬件资源,并在微体系结构状态上承受许多安全威胁。最先进的安全处理器架构(如MI6和IRONHIDE)能够利用强隔离安全原语在硬件隔离的安全区中执行安全关键进程。MI6处理器清除每个安全区入口/出口上的小状态资源,并静态分区末级缓存和DRAM区域,以确保强大的隔离。IRONHIDE采用空间方法,在多核处理器中创建两个隔离的核心集群,以确保在飞地集群中执行的进程的强隔离。这两种架构都观察到由于共享硬件资源的静态分区而导致的性能下降。OPTIMUS提出了一种以安全为中心的动态硬件资源划分方案,该方案完全在运行时运行,并确保强隔离。它能够在应用级粒度上实现确定性资源分配,并限制硬件重新配置的次数,以确保通过定时和终止信道的有限信息泄漏。OPTIMUS的动态硬件资源分区功能可协同优化MI6和IRONHIDE架构的性能和安全性。
Hardware virtualization allows multiple security-critical and ordinary (insecure) processes to co-execute on a processor. These processes temporally share hardware resources and endure numerous security threats on the microarchitecture state. State-of-the-art secure processor architectures, such as MI6 and IRONHIDE enable capabilities to execute security-critical processes in hardware isolated enclaves utilizing thestrong isolationsecurity primitive. The MI6 processor purges small state resources on each enclave entry/exit and statically partitions the last-level cache and DRAM regions to ensure strong isolation. IRONHIDE takes a spatial approach and creates two isolated clusters of cores in a multicore processor to ensure strong isolation for processes executing in the enclave cluster. Both architectures observe performance degradation due to static partitioning of shared hardware resources. OPTIMUS proposes asecurity-centricdynamic hardware resource partitioning scheme that operates entirely at runtime and ensures strong isolation. It enablesdeterministicresource allocations at the application level granularity, and limits the number of hardware reconfigurations to ensureboundedinformation leakage via the timing and termination channels. The dynamic hardware resource partitioning capability of OPTIMUS is shown to co-optimize performance and security for the MI6 and IRONHIDE architectures.
DOI: 10.1007/11894063_16
发表时间: 2006-10
期刊: --
影响因子: --
作者:
Joseph Bonneau;Ilya Mironov
通讯作者: Joseph Bonneau;Ilya Mironov
IRONHIDE:一种安全多核,可有效缓解交互式应用程序的微架构状态攻击
DOI: 10.1109/hpca47549.2020.00019
发表时间: 2020
期刊: 2020 IEEE International Symposium on High Performance Computer Architecture (HPCA
影响因子: --
作者:
Omar, Hamza;Khan, Omer
通讯作者: Khan, Omer
打破 Oblivious-RAM 带宽墙
DOI: 10.1109/iccd.2018.00026
发表时间: 2018
期刊: 2018 IEEE 36th International Conference on Computer Design (ICCD
影响因子: --
作者:
Omar, Hamza;Haider, Syed Kamran;Ren, Ling;van Dijk, Marten;Khan, Omer
通讯作者: Khan, Omer
多核资源隔离可实现安全关键应用程序的确定性、弹性和安全并发执行
DOI: 10.1109/lca.2018.2874216
发表时间: 2018
影响因子: 2.3
作者:
Omar, Hamza;Dogan, Halit;Kahne, Brian;Khan, Omer
通讯作者: Khan, Omer