USENIX Security2023Top-tier venue
HashTag: Hash-based Integrity Protection for Tagged Architectures
Lukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan Mangard
Abstract
Modern computing systems rely on error-correcting codes to ensure the integrity of DRAM data. Linear checksums allow for fast detection and correction of specific error patterns. However, they do not offer sufficient protection against complex errors distributed over multiple data words and chips. Depending on the code and the error pattern, linear codes may fail to detect or even miscorrect errors, thus leading to silent data corruption. In this work, we show how compact error-correcting codes based on low-latency hashing functions allow for strong probabilistic error detection and correction while facilitating ECC bit repurposing. Our proposed design drastically lowers the expected rate of undetected errors, regardless of the underlying error patterns. By tailoring the size of our codes to the required level of integrity protection, we are able to free bits that would otherwise be required to store ECC data. We showcase how our design facilitates the efficient implementation of tagged memory architectures such as CHERI, ARM MTE, and SPARC ADI by repurposing the freed bits in commodity ECC DRAM. Thus, we harden systems against data corruption due to DRAM faults while simultaneously allowing for memory tagging without introducing additional memory accesses. We present a systematic analysis of schemes that allow memory tagging on a cache line granularity while maintaining error detection and correction capabilities, even in multi-bit fault scenarios. We evaluate our integrity protection with tagging for different use cases and show that we can store 32 bits of additional tags per cache line, twice the amount needed to implement ARM's MTE, without significantly affecting error correction capabilities. We also show how up to 51 bits can be made available while maintaining single-bit error correction.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 47795508-a577-4aec-bdc0-4b5604a3a3d4Cited by top-tier papers4
- Cryptographically Enforced Memory SafetyMartin Unterguggenberger, David Schrammel, Lukas Lamster, Pascal Nasahl et al.CCS 2023 · 6 citations
- Voodoo: Memory Tagging, Authenticated Encryption, and Error Correction through MAGICLukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan MangardUSENIX Security 2024 · 5 citations
- Polymorphic Error CorrectionEvgeny Manzhosov, Simha SethumadhavanMICRO 2024 · 1 citation
- Beyond Tag Collision: Cluster-based Memory Management for Tag-based SanitizersMengfei Xie, Yan Lin, Hongtao Wu, Jianming Fu et al.CCS 2025
Builds on7
- RAMBleed: Reading Bits in Memory Without Accessing ThemAndrew Kwong, Daniel Genkin, Daniel Gruss, Yuval YaromS&P 2020 · 239 citations
- Exploiting Correcting Codes: On the Effectiveness of ECC Memory Against Rowhammer AttacksLucian Cojocar, Kaveh Razavi, Cristiano Giuffrida, Herbert BosS&P 2019 · 233 citations
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun et al.S&P 2016 · 146 citations
- BlockHammer: Preventing RowHammer at Low Cost by Blacklisting Rapidly-Accessed DRAM RowsAbdullah Giray Yaglikçi, Minesh Patel, Jeremie S. Kim, Roknoddin Azizi et al.HPCA 2021 · 124 citations
- ProTRR: Principled yet Optimal In-DRAM Target Row RefreshMichele Marazzi, Patrick Jattke, Flavien Solt, Kaveh RazaviS&P 2022 · 101 citations
Related papers
- Revisiting Residue Codes for Modern MemoriesEvgeny Manzhosov, Adam Hastings, Meghna Pancholi, Ryan Piersma et al.MICRO 2022 · 23 citations
- How to Kill the Second Bird with One ECC: The Pursuit of Row Hammer Resilient DRAMMichael Jaemin Kim, Minbok Wi, Jaehyun Park, Seoyoung Ko et al.MICRO 2023 · 16 citations
- Implicit Memory Tagging: No-Overhead Memory Safety Using Alias-Free Tagged ECCMichael B. Sullivan, Mohamed Tarek Ibn Ziad, Aamer Jaleel, Stephen W. KecklerISCA 2023 · 17 citations
- ECC Enabled Reliable and Performant Processing-in-MemoryJeageun Jung, Margaret Lee, Mattan ErezISCA 2026
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung et al.S&P 2025
