Lune

HPCA2025Top-tier venue

SpecMPK: Efficient In-Process Isolation with Speculative and Secure Permission Update Instruction

Debpratim Adak, Huiyang Zhou, Eric Rotenberg, Amro Awad

2025Year
3Citations
1Top-tier citations

Abstract

In today’s digital landscape, software applications are susceptible to various threats arising from vulnerabilities in unsafe programming languages (C,C++\mathbf{C}, \mathrm{C}++) and speculative out-of-order cores in high-performance computers. Researchers recommended enhancements in both software and hardware for protection against such attacks. In-process isolation is a promising way to mitigate memoryrelated attacks. It compartmentalizes critical data and pointers in a separate memory region and enforces access control to this memory region. Any operation to such memory locations may require a permission adjustment before and after the operation, depending on the required access control. Memory Protection Keys, a recent architecture support, has been adopted by multiple processor vendors to allow access control changes in the user space, leading to lower performance overhead than the conventional system calls (e.g., mprotect). Still, this technology incurs significant performance overhead since the permission update instruction is serialized. Our research demonstrates significant performance improvement by allowing speculative permission updates. However, speculative execution of the permission update instruction may upgrade access permission transiently, leading to potential speculative execution attacks. To prevent such attacks, we propose Speculative Memory Protection Keys (SpecMPK), a lightweight microarchitecture enhancement to examine permission change and block transiently upgraded memory instructions until they become non-squashable. SpecMPK significantly improves performance compared to a serialized domain switch instruction. This work shows an average 12.21%\mathbf{1 2. 2 1 \%} performance improvement for selected SPEC workloads requiring frequent domain switches for various memory safety schemes using memory protection keys.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext a171808f-e80e-4613-97cc-72ae7a238702

Cited by top-tier papers1

Ask how each one uses it

Builds on30

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines