USENIX Security2017Top-tier venue
Reverse Engineering x86 Processor Microcode
Philipp Koppe, Benjamin Kollenda, Marc Fyrbiak, Christian Kison, Robert Gawlik, Christof Paar, Thorsten Holz
Abstract
Microcode is an abstraction layer on top of the physical components of a CPU and present in most general-purpose CPUs today. In addition to facilitate complex and vast instruction sets, it also provides an update mechanism that allows CPUs to be patched in-place without requiring any special hardware. While it is well-known that CPUs are regularly updated with this mechanism, very little is known about its inner workings given that microcode and the update mechanism are proprietary and have not been throughly analyzed yet. In this paper, we reverse engineer the microcode semantics and inner workings of its update mechanism of conventional COTS CPUs on the example of AMD's K8 and K10 microarchitectures. Furthermore, we demonstrate how to develop custom microcode updates. We describe the microcode semantics and additionally present a set of microprograms that demonstrate the possibilities offered by this technology. To this end, our microprograms range from CPU-assisted instrumentation to microcoded Trojans that can even be reached from within a web browser and enable remote code execution and cryptographic implementation attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- CacheQuery: learning replacement policies from hardware cachesPepe Vila, Pierre Ganty, Marco Guarnieri, Boris KöpfPLDI 2020 · 38 citations
- CacheWarp: Software-based Fault Injection using Selective State ResetRuiyi Zhang, Lukas Gerlach, Daniel Weber, Lorenz Hetterich et al.USENIX Security 2024 · 36 citations
- CHEx86: Context-Sensitive Enforcement of Memory Safety via Microcode-Enabled CapabilitiesRasool Sharifi, Ashish VenkatISCA 2020 · 28 citations
- An Exploratory Analysis of Microcode as a Building Block for System DefensesBenjamin Kollenda, Philipp Koppe, Marc Fyrbiak, Christian Kison et al.CCS 2018 · 13 citations
- RemembERR: Leveraging Microprocessor Errata for Design Testing and ValidationFlavien Solt, Patrick Jattke, Kaveh RazaviMICRO 2022 · 12 citations
Related papers
- On the Design and Misuse of Microcoded (Embedded) Processors - A Cautionary NoteNils Albartus, Clemens Nasenberg, Florian Stolz, Marc Fyrbiak et al.USENIX Security 2021
- I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op CachesXida Ren, Logan Moody, Mohammadkazem Taram, Matthew Jordan et al.ISCA 2021 · 59 citations
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 32 citations
- Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPUPietro Frigo, Cristiano Giuffrida, Herbert Bos, Kaveh RazaviS&P 2018 · 178 citations
- Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address LeakageMikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz et al.S&P 2025
