USENIX Security2024Top-tier venue
SpecLFB: Eliminating Cache Side Channels in Speculative Executions
Xiaoyu Cheng, Fei Tong, Hongyu Wang, Zhe Zhou, Fang Jiang, Yuxing Mao
Abstract
Cache side-channel attacks based on speculative executions are powerful and difficult to mitigate. Existing hardware defense schemes often require additional hardware data structures, data movement operations and/or complex logical computations, resulting in excessive overhead of both processor performance and hardware resources. To this end, this paper proposes SpecLFB, which utilizes the microarchitecture component, Line-Fill-Buffer, integrated with a proposed mechanism for load security check to prevent the establishment of cache side channels in speculative executions. To ensure the correctness and immediacy of load security check, a structure called ROB unsafe mask is designed for SpecLFB to track instruction state. To further reduce processor performance overhead, SpecLFB narrows down the protection scope of unsafe speculative loads and determines the time at which they can be deprotected as early as possible. SpecLFB has been implemented in the open-source RISC-V core, Sonic-BOOM, as well as in Gem5. For the enhanced SonicBOOM, its register-transfer-level (RTL) code is generated, and an FPGA hardware prototype burned with the core and running a Linux-kernel-based operating system is developed. Based on the evaluations in terms of security guarantee, performance overhead, and hardware resource overhead through RTL simulation, FPGA prototype experiment, and Gem5 simulation, it shows that SpecLFB effectively defends against attacks. It leads to a hardware resource overhead of only 0.6% and the performance overhead of only 1.85% and 3.20% in the FPGA prototype experiment and Gem5 simulation, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c0535462-f72f-4c29-8a6c-4aa3641b9fddCited by top-tier papers5
- AMuLeT: Automated Design-Time Testing of Secure Speculation CountermeasuresBo Fu, Leo Tenenbaum, David Adler, Assaf Klein et al.ASPLOS 2025 · 3 citations
- dfence: Fine-Grained Speculation Barriers for Efficient and Effective Hardware-Software Protection in the Spectre EraDavide Davoli, Marton Bognar, Lesly-Ann Daniel, Benjamin Gregoire et al.CCS 2026 · 1 citation
- Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order ProcessorsLukas Gerlach, Marton Bognar, Daniel Weber, Michael Schwarz et al.USENIX Security 2026
- Exploiting Hidden Resource Contention in Selective Speculation DefensesXiaoyu Cheng, Fei Tong, Zhenyu Lei, Fang Jiang et al.USENIX Security 2026
- LeakLess: Selective Data Protection against Memory Leakage Attacks for Serverless PlatformsMaryam Rostamipoor, Seyedhamed Ghavamnia, Michalis PolychronakisNDSS 2025
Builds on12
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti et al.CCS 2019 · 267 citations
Related papers
- Data Oblivious CPU: Microarchitectural Side-channel Leakage-Resilient ProcessorBehnam Omidi, Ihsen Alouani, Khaled N. KhasawnehDAC 2025
- ProSpeCT: Provably Secure Speculation for the Constant-Time PolicyLesly-Ann Daniel, Marton Bognar, Job Noorman, Sébastien Bardin et al.USENIX Security 2023
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu et al.DAC 2022 · 1 citation
- unXpec: Breaking Undo-based Safe SpeculationMengming Li, Chenlu Miao, Yilong Yang, Kai BuHPCA 2022 · 9 citations
- Levioso: Efficient Compiler-Informed Secure SpeculationAli Hajiabadi, Archit Agarwal, Andreas Diavastos, Trevor E. CarlsonDAC 2024 · 1 citation
