I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op Caches
Xida Ren, Logan Moody, Mohammadkazem Taram, Matthew Jordan, Dean M. Tullsen, Ashish Venkat
Abstract
Modern Intel, AMD, and ARM processors translate complex instructions into simpler internal micro-ops that are then cached in a dedicated on-chip structure called the micro-op cache. This work presents an in-depth characterization study of the micro-op cache, reverse-engineering many undocumented features, and further describes attacks that exploit the micro-op cache as a timing channel to transmit secret information. In particular, this paper describes three attacks – (1) a same thread cross-domain attack that leaks secrets across the user-kernel boundary, (2) a cross-SMT thread attack that transmits secrets across two SMT threads via the micro-op cache, and (3) transient execution attacks that have the ability to leak an unauthorized secret accessed along a misspeculated path, even before the transient instruction is dispatched to execution, breaking several existing invisible speculation and fencing-based solutions that mitigate Spectre.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers27
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe et al.S&P 2022 · 59 citations
- InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 32 citations
- Leaky Frontends: Security Vulnerabilities in Processor FrontendsShuwen Deng, Bowen Huang, Jakub SzeferHPCA 2022 · 27 citations
- No-FAT: Architectural Support for Low Overhead Memory Safety ChecksMohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Ryan Piersma et al.ISCA 2021 · 26 citations
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 18 citations
Builds on19
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- Leaky MDU: ARM Memory Disambiguation Unit Uncovered and Vulnerabilities ExposedChang Liu, Yongqiang Lyu, Haixia Wang, Pengfei Qiu et al.DAC 2023 · 5 citations
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 19 citations
- Leaking Information Through Cache LRU StatesWenjie Xiong, Jakub SzeferHPCA 2020 · 54 citations
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu et al.ASPLOS 2021 · 69 citations
- SPECRUN: The Danger of Speculative Runahead Execution in ProcessorsChaoqun Shen, Gang Qu, Jiliang ZhangDAC 2024 · 1 citation
