CryptoBTB: A Secure Hierarchical BTB for Diverse Instruction Footprint Workloads
Debpratim Adak, Eric Rotenberg, Amro Awad, Huiyang Zhou
Abstract
Timing attacks leveraging shared resources on a CPU are a growing concern. Branch Target Buffer (BTB), a crucial component of highperformance processors, is shared among threads and privileged spaces. Recently, researchers discovered numerous vulnerabilities in the BTB, allowing an adversary to maliciously infer a victim's BTB update and mistrain the BTB. Such attacks can successfully bypass privilege-level and secure enclave protection, as well as address space isolation. Randomizing BTB through encrypted addressing to prevent these attacks suffers from high performance overhead due to exposed encryption latency in the pipeline. Prior works address this by using encryption schemes that are either not fully secure or require frequent flush. The most recent proposal, HyBP [79], uses stronger encryption schemes. However, it suffers from high overhead since it underutilizes the BTB and suffers from higher collisions within the same thread.
In this work, we propose CryptoBTB, a secure BTB, specifically designed for an exclusive BTB hierarchy. Our proposal decouples the index encryption from the index itself, enabling low-latency index encryption to obscure BTB set mapping. Additionally, unlike earlier secure BTB proposals, this scheme is well-suited for applications with a higher instruction footprint where performance is sensitive to the BTB capacity. We evaluated CryptoBTB on various classes of workloads that stress the BTB differently. Our results show that CryptoBTB incurs 4.27% performance overhead for these workloads, while HyBP experiences 31.89% overhead. Moreover, CryptoBTB requires 22.57% lower hardware overhead than HyBP.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cba5b67a-25f3-4521-aaa0-442ef0055aceBuilds on23
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz et al.USENIX Security 2019 · 221 citations
Related papers
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 18 citations
- HyBP: Hybrid Isolation-Randomization Secure Branch PredictorLutan Zhao, Peinan Li, Rui Hou, Michael C. Huang et al.HPCA 2022 · 10 citations
- OCCUPY+PROBE: Cross-Privilege Branch Target Buffer Side-Channel Attacks at Instruction GranularityKaiyuan Rong, Junqi Fang, Haixia Wang, Dapeng Ju et al.NDSS 2026
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- A Lightweight Isolation Mechanism for Secure Branch PredictorsLutan Zhao, Peinan Li, Rui Hou, Michael C. Huang et al.DAC 2021 · 29 citations
