Leaking Information Through Cache LRU States in Commercial Processors and Secure Caches

Leaking Information Through Cache LRU States in Commercial Processors and Secure Caches
复制标题

DOI:
10.1109/tc.2021.3059531
复制
发表时间:
2021-04
影响因子:
3.7
通讯作者:
Wenjie Xiong;S. Katzenbeisser;Jakub Szefer
Wenjie Xiong;S. Katzenbeisser;Jakub Szefer
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wenjie Xiong;S. Katzenbeisser;Jakub Szefer

文献摘要

相似文献

最近最少使用(LRU)缓存替换策略及其变体广泛部署在现代处理器中。本文详细说明了缓存的LRU状态可以用来泄露信息:发送方对缓存的任何访问都会修改LRU状态,而接收方可以通过定时测量来观察这一点。本文介绍了当发送者和接收者可以访问共享内存时基于LRU定时的通道,例如,共享库,以及当它们是没有共享内存的独立进程时。此外,在发送方和接收方在超线程设置和时间片设置中共享该高速缓存的情况下,在Intel和AMD处理器上演示了新的基于LRU定时的通道。在超线程设置中,LRU通道的传输速率最高可达每个缓存集600 Kbps。与大多数现有的高速缓存通道需要发送方触发高速缓存未命中不同,新的LRU通道只与具有高速缓存命中的发送方一起工作,使通道更快和更隐蔽。本文进一步讨论了新的LRU通道对许多安全缓存设计的有效性。特别是,LRU通道被证明对两个代表性的安全缓存,分区锁定(PL)缓存和随机填充(RF)缓存,在gem 5模拟器中,显示可能的安全缓存设计中的漏洞,其中的替换状态的安全性没有得到适当的保护。
The Least-Recently Used (LRU) cache replacement policy and its variants are widely deployed in modern processors. This article shows in detail that the LRU states of caches can be used to leak information: any access to a cache by a sender will modify the LRU state, and the receiver is able to observe this through a timing measurement. This article presents LRU timing-based channels both when the sender and the receiver have access to shared memory, e.g., shared library, and when they are separate processes without shared memory. In addition, the new LRU timing-based channels are demonstrated on both Intel and AMD processors in scenarios where the sender and the receiver are sharing the cache in both hyper-threaded setting and time-sliced setting. The transmission rates of the LRU channels can be up to 600 Kbps per cache set in the hyper-threaded setting. Different from the majority of existing cache channels which require the sender to trigger cache misses, the new LRU channels work with the sender only having cache hits, making the channel faster and stealthier. This article further discusses the effectiveness of the new LRU channels against a number of secure cache designs. Especially, the LRU channels are demonstrated to work against two representative secure caches, Partition-Locked (PL) cache and Random Fill (RF) cache, in the gem5 simulator, showing possible vulnerabilities in the secure cache designs in which the security of the replacement state is not protected properly.