抗Spectre攻击的软硬协同系统级防御技术研究
批准号:
61902398
项目类别:
青年科学基金项目
资助金额:
27.0 万元
负责人:
屠晨阳
依托单位:
学科分类:
F0205.网络与系统安全
结题年份:
2022
批准年份:
2019
项目状态:
已结题
项目参与者:
--
国基评审专家1V1指导 中标率高出同行96.8%
结合最新热点,提供专业选题建议
深度指导申报书撰写,确保创新可行
指导项目中标800+,快速提高中标率
微信扫码咨询
中文摘要
Spectre攻击对物联网设备造成严重的安全威胁,亟需有效的防御手段。然而,一方面现有打补丁式的防御措施难以对Spectre攻击及其变种进行全面防御,并且通常对系统及CPU性能影响很大;另一方面,改进或设计新CPU架构的防御方法对现有设备无能为力。为解决上述难题,本课题拟开展抗Spectre攻击的软硬协同系统级防御技术研究,为基于全可编程SoC的物联网设备提供解决方案。其主要研究内容包括:全可编程SoC系统级防御安全架构的构建,针对Spectre攻击的软硬协同防御方法的设计,以及软硬协同防御系统的实现。课题的实施不仅可以为现有设备提供解决方案,而且也能够为全可编程SoC安全设计技术改进奠定先进的技术基础。
英文摘要
Spectre attacks pose a serious security threat to IoT devices, thus IoT devices need effective defense mechanisms. However, there are problems to be solved in existing countermeasures. On the one hand, patches countermeasures are difficult to fully defend against Spectre attacks and many variants, and often have a significant impact on system and CPU performance. On the other hand, the countermeasures based on improving or designing a new CPU architecture are powerless for existing devices. In order to solve these problems, our research will focus on system level countermeasure based on orchestration of hardware and software against Spectre attacks, and provide solutions for IoT devices based on all programmable SoC. Our research include the construction of the system level defense security architecture on all programmable SoC, the design of the defense method based on the orchestration of hardware and software orchestrate for Spectre attacks, and the realization of the hardware and software orchestrating defense system. Our research can not only provide solutions for existing IoT devices, but also can lay an advanced technical foundation for the improvement of all programmable SOC security design.
Spectre攻击对物联网设备造成严重的安全威胁,亟需有效的防御手段。然而,一方面现有打补丁式的防御措施难以对Spectre攻击及其变种进行全面防御,并且通常对系统及CPU性能影响很大;另一方面,改进或设计新CPU架构的防御方法对现有设备无能为力。本课题围绕抗Spectre攻击的软硬协同系统级防御技术,提出了一系列理论先进、实际有效的防御技术方案,为基于全可编程SoC的物联网设备提供解决方案,部分成果发表在高水平学术期刊和会议上。.首先,本课题针对Spectre攻击的防御措施存在的缺陷,指出可以利用全可编程SoC系统具有软硬件协同的特点,给出具有防御Spectre攻击能力的软硬协同系统级防御安全架构。其次,本课题针对不同Spectre攻击变种的不同flush操作行为采用不同的响应方式,给出适用于上述架构的不同防御方法,满足不同安全策略和实际情况的需要。最后,本课题提出一个可行的抗Spectre攻击的软硬协同防御系统的设计实现方法,并给出全可编程SoC软硬协同防御原型系统。至此,本课题针对抗Spectre攻击的软硬协同防御技术进行了全面、深入并卓有成效的研究,可以指导并促进国内物联网设备高安全设计技术的改进。
期刊论文列表
专著列表
科研奖励列表
会议论文列表
专利列表
MACM: How to Reduce the Multi-Round SCA to the Single-Round Attack on the Feistel-SP Networks
MACM:如何将 Feistel-SP 网络上的多轮 SCA 减少为单轮攻击
DOI:10.1109/tifs.2019.2959910
发表时间:2020
期刊:IEEE Transactions on Information Forensics and Security (TIFS)
影响因子:--
作者:Chenyang Tu;Zeyi Liu;Neng Gao;Cunqing Ma;Jingquan Ge;Lingchen Zhang
通讯作者:Lingchen Zhang
国内基金
海外基金















{{item.name}}会员


