SpecMPK: Efficient In-Process Isolation with Speculative and Secure Permission Update Instruction
Debpratim Adak, Huiyang Zhou, Eric Rotenberg, Amro Awad
Abstract
In today’s digital landscape, software applications are susceptible to various threats arising from vulnerabilities in unsafe programming languages () and speculative out-of-order cores in high-performance computers. Researchers recommended enhancements in both software and hardware for protection against such attacks. In-process isolation is a promising way to mitigate memoryrelated attacks. It compartmentalizes critical data and pointers in a separate memory region and enforces access control to this memory region. Any operation to such memory locations may require a permission adjustment before and after the operation, depending on the required access control. Memory Protection Keys, a recent architecture support, has been adopted by multiple processor vendors to allow access control changes in the user space, leading to lower performance overhead than the conventional system calls (e.g., mprotect). Still, this technology incurs significant performance overhead since the permission update instruction is serialized. Our research demonstrates significant performance improvement by allowing speculative permission updates. However, speculative execution of the permission update instruction may upgrade access permission transiently, leading to potential speculative execution attacks. To prevent such attacks, we propose Speculative Memory Protection Keys (SpecMPK), a lightweight microarchitecture enhancement to examine permission change and block transiently upgraded memory instructions until they become non-squashable. SpecMPK significantly improves performance compared to a serialized domain switch instruction. This work shows an average performance improvement for selected SPEC workloads requiring frequent domain switches for various memory safety schemes using memory protection keys.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a171808f-e80e-4613-97cc-72ae7a238702Cited by top-tier papers1
Ask how each one uses itBuilds on30
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
Related papers
- EPK: Scalable and Efficient Memory Protection KeysJinyu Gu, Hao Li, Wentai Li, Yubin Xia et al.USENIX ATC 2022
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 33 citations
- Hardware-Based Domain Virtualization for Intra-Process Isolation of Persistent Memory ObjectsYuanchao Xu, Chencheng Ye, Yan Solihin, Xipeng ShenISCA 2020 · 24 citations
- PKU Pitfalls: Attacks on PKU-based Memory Isolation SystemsR. Joseph Connor, Tyler McDaniel, Jared M. Smith, Max SchuchardUSENIX Security 2020
- TME-Box: Scalable In-Process Isolation through Intel TME-MK Memory EncryptionMartin Unterguggenberger, Lukas Lamster, David Schrammel, Martin Schwarzl et al.NDSS 2025
