Transient Architectural Execution: From Weird Gates to Weird Programs
Ping-Lun Wang, Fraser Brown, Riccardo Paccagnella, Eyal Ronen, Riad S. Wahby, Yuval Yarom
Abstract
An emerging body of work has explored the construction of weird gates-code segments computing on microarchitectural state not exposed by the instruction set architecture. Weird gates abstract microarchitectural state (e.g., CPU cache residency) as Boolean values and compute logical functions over these values. Researchers have used weird gates in applications like side-channel amplification and malware obfuscation. Indeed, in principle, the computational model of weird gates-a Boolean circuit of bounded size-can perform (bounded) arbitrary computation. In practice, however, this model is less efficient (both asymptotically and concretely) than the standard processor model, which supports conditional execution, indexed memory, and richer data types.
In this paper, we show how to build weird computation in the processor model rather than the circuit model. The primitive that makes this possible is transient architectural execution: transiently loading microarchitectural state into registers, computing on it, and storing the results back into microarchitectural state-without exposing any state architecturally. Transient architectural execution, a generalization of prior weird gates and transient execution attacks, allows us to wield the full computational capability of the processor to operate on microarchitectural state. We also show how to use the state of the branch predictor to emulate wide variables of up to 16 bits. As a result, our weird programs are over two orders of magnitude faster than weird gates and can compute functions that are impractical using prior approaches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 40fe5dda-2811-4174-a7ef-bee22a502223Builds on76
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
Related papers
- Computing with time: microarchitectural weird machinesDmitry Evtyushkin, Thomas Benjamin, Jesse Elwell, Jeffrey A. Eitel et al.ASPLOS 2021 · 14 citations
- The Gates of Time: Improving Cache Attacks with Transient ExecutionDaniel Katzman, William Kosasih, Chitchanok Chuengsatiansup, Eyal Ronen et al.USENIX Security 2023
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 32 citations
- Bending microarchitectural weird machines towards practicalityPing-Lun Wang, Riccardo Paccagnella, Riad S. Wahby, Fraser BrownUSENIX Security 2024 · 2 citations
- SPECRUN: The Danger of Speculative Runahead Execution in ProcessorsChaoqun Shen, Gang Qu, Jiliang ZhangDAC 2024 · 1 citation
