Avoiding information leakage in the memory controller with fixed service policies

Avoiding information leakage in the memory controller with fixed service policies
复制标题

通过固定的服务策略避免内存控制器中的信息泄漏

DOI:
10.1145/2830772.2830795
复制
发表时间:
2015
期刊:
2015 48th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
通讯作者:
Mohit Tiwari
Mohit Tiwari
中科院分区:
--
文献类型:
--
作者:
Ali Shafiee;Akhila Gundu;Manjunath Shevgoor;R. Balasubramonian;Mohit Tiwari

文献摘要

被引文献

相似文献

受信任的应用程序经常与个人设备和云环境中的不受信任的应用程序一起执行。由于这些共同调度的应用程序共享硬件资源,因此不受信任的应用程序遇到的延迟会泄露有关受信任的应用程序是否正在访问共享资源的信息。先前的研究表明,此类信息泄漏可以被不受信任的应用程序用来破译密钥或发起隐蔽通道攻击。先前的工作还提出了消除各种共享资源中的信息泄漏的技术。消除内存系统中信息泄漏的最著名的解决方案会带来很高的性能损失。这项工作开发了一种综合方法来消除内存控制器中的时序通道,该方法具有两个关键要素:(i)我们塑造每个线程的内存访问行为,使其具有不变的内存访问模式。 (ii) 我们展示了如何构建有效的内存访问管道来处理结果内存访问,而不引入任何资源冲突。我们从数学上证明所提出的系统产生零信息泄漏。然后我们展示了各种页面映射策略可以影响我们的安全内存系统的吞吐量。我们还引入了对来自不同线程的请求进行重新排序的技术,以在不泄漏信息的情况下提高性能。我们的最佳解决方案提供的吞吐量比优化的非安全基线低 27%,比最知名的竞争方案高 69%。
Trusted applications frequently execute in tandem with untrusted applications on personal devices and in cloud environments. Since these co-scheduled applications share hardware resources, the latencies encountered by the untrusted application betray information about whether the trusted applications are accessing shared resources or not. Prior studies have shown that such information leaks can be used by the untrusted application to decipher keys or launch covert-channel attacks. Prior work has also proposed techniques to eliminate information leakage in various shared resources. The best known solution to eliminate information leakage in the memory system incurs high performance penalties. This work develops a comprehensive approach to eliminate timing channels in the memory controller that has two key elements: (i) We shape the memory access behavior of each thread so that it has an unchanging memory access pattern. (ii) We show how efficient memory access pipelines can be constructed to process the resulting memory accesses without introducing any resource conflicts. We mathematically show that the proposed system yields zero information leakage. We then show that various page mapping policies can impact the throughput of our secure memory system. We also introduce techniques to re-order requests from different threads to boost performance without leaking information. Our best solution offers throughput that is 27% lower than that of an optimized non-secure baseline, and that is 69% higher than the best known competing scheme.