CHERI: Privilege separation through multiprocess compartmentalisation
CHERI: Privilege separation through multiprocess compartmentalisation
批准号:
2107427
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
CHERI(Capability Hardware Enhanced RISC Instructions)是剑桥大学和SRI International之间的一个软硬件协同设计联合研究项目。该项目探索通过扩展现有RISC指令集架构(ISA)的功能来提高系统安全性,目的是通过改进计算机架构,编译器/编程语言和操作系统来从根本上提高系统安全性。在这个项目中使用的方法将是不同的指令集,探索对硬件设计和软件结构的影响,评估对硬件费用,软件性能,软件兼容性和安全性的影响。体系结构能力是不可伪造的令牌,它们本身证明它们的所有者有权访问资源,CHERI使用这个抽象概念来保护主存;能力是有关联权限的有界指针;每个指针在所描述的内存区域内有一个基址,长度和当前偏移量。没有指令提供创建比其输入具有更大界限或权限的功能的方法,并且处理器会跟踪每个功能的有效性以防止伪造。这提供了更好的保护,防止基于内存的漏洞,但也可以用来划分应用程序的部分,将任何成功的漏洞限制在该部分。目前,用于研究的CHERI版本是CHERI-MIPS,这是64位MIPS指令集的扩展。然而,MIPS不再被广泛使用,围绕架构和应用程序二进制接口(ABI)的各种历史决策意味着它作为基线并不能代表当代架构。因此,CHERI-RISC-V正在开发中,这是CHERI-MIPS现有工作的一种新的CHERI实现,并基于开源RISC-V指令集。这使得CHERI-RISC-V成为CHERI模型实验的理想试验场,重新审视关键设计选择,并灵活地在各种设计维度中选择多个点,评估每种变化。对于CHERI,需要考虑的一个重要方面是处理器需要能够保存功能的通用寄存器,就像整数和浮点数一样,以便能够使用它们执行操作。有两种方法可以实现这一点:可以添加一个全新的能力寄存器库(“分裂”寄存器文件),或者可以扩展现有的整数寄存器,以允许它们包含整数和能力(“合并”寄存器文件)。前者通常会提供更好的性能,因为更多的寄存器可供编译器分配,而不需要将变量溢出到堆栈,但这可能是昂贵的,需要大量的芯片空间,所以后一种方法更实用。由于CHERI-MIPS提供了一个分裂的寄存器文件,CHERI-RISC-V将提供一个合并的寄存器文件,以提供一个更实际的实现,但与分裂的寄存器文件的选项,以提供一个比较点。然而,对于合并的寄存器文件,不清楚是否每个寄存器都需要加宽,或者它们的更小子集是否足够。目的是探索CHERI-RISC-V寄存器文件的整个设计空间,研究使用合并寄存器文件而不是拆分寄存器文件的后果,以及只允许某些寄存器保持功能。这样的设计决策会影响整个堆栈中的系统软件,从管理处理器状态的内核,到实现ABI规定的调用约定的编译器、链接器和加载器,以及C运行时的特定于体系结构的部分。如果成功,该项目将降低硬件费用,提高软件性能,并提高软件兼容性,同时保留CHERI架构的关键安全目标。
英文摘要
CHERI (Capability Hardware Enhanced RISC Instructions) is a joint research project in hardware-software co-design between the University of Cambridge and SRI International. The project explores improving system security by extending existing RISC Instruction-Set Architectures (ISAs) with capabilities, with the aim of fundamentally improving system security through improvements in computer architecture, compilers/programming languages, and operating systems. The methodology used in this project will be to vary the instruction set, exploring the implications for hardware design and software structure, evaluating the impact on hardware expense, software performance, software compatibility, and security. Architectural capabilities are unforgeable tokens which themselves prove that their owner has the right to access a resource, and CHERI uses this abstract concept for protecting main memory; capabilities are bounded pointers with associated permissions; each pointer has a base, length and current offset within the described region of memory. No instruction provides a means to create a capability with greater bounds or permissions than its inputs, and the validity of every capability is tracked by the processor to prevent forgery. This provides greater protection against memory-based exploits, but can also be used to compartmentalise parts of applications, confining any successful exploit to just that compartment. Currently, the version of CHERI used for research is CHERI-MIPS, an extension of the 64-bit MIPS instruction set. However, MIPS is not used widely any more, and various historical decisions around the architecture and application binary interface (ABI) mean that as a baseline it is not so representative of contemporary architectures. Thus CHERI-RISC-V is being developed, a new implementation of CHERI informed by the existing work on CHERI-MIPS and based on top of the open-source RISC-V instruction set. This makes CHERI-RISC-V an ideal testing ground for experimentation with the CHERI model, revisiting key design choices with the flexibility to select multiple points in various design dimensions, evaluating each variation.With CHERI, one important aspect to consider is that the processor needs general-purpose registers able to hold capabilities, just like integers and floating point numbers, in order to be able to perform operations with them. There are two ways this can be achieved: either a whole new bank of capability registers can be added ("split" register file), or existing integer registers can be widened to allow them to contain both integers and capabilities ("merged" register file). The former will generally offer better performance as more registers are available to the compiler to allocate rather than needing to spill variables to the stack, but this can be costly and require a large amount of space on a chip, so the latter approach is more practical. Since CHERI-MIPS provided a split register file, CHERI-RISC-V will be offering a merged register file to give a more practical implementation, but with the option for a split register file in order to offer a point of comparison. However, for a merged register file, it is unclear whether every register needs to be widened or whether a more minimal subset of them is sufficient. The aim is to explore the whole design space around CHERI-RISC-V's register file, looking at the consequences of using a merged register file instead of a split register file, as well as only allowing some registers to hold capabilities. Such design decisions affect system software throughout the stack, from the kernel managing the processor state, through to compilers, linkers and loaders implementing the calling convention prescribed by the ABI, and architecture-specific parts of the C runtime. If successful, this project will lower the hardware expense, improve software performance, and improve software compatibility while retaining the key security objectives of the CHERI architecture.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金