Interplay of Efficient Model Checking and Secure Processor Design: A Case Study on Secure Speculation
Tingzhen Dong, Qinhan Tan, Kunpeng Wang, Thomas Bourgeat, Yuheng Yang, Sharad Malik, Yu-Wei Fan, Mengjia Yan
Abstract
There is increasing use of model checking to verify the security of processors, including those with speculative execution. However, model checkers face scalability challenges and are limited in the scale of processors and specific security properties they can currently handle. This research shows how exploiting domain-specific information about the design of secure processors can be used to scale model checking and make it more efficient. Our key observation is that proofs of non-interference properties require both information-flow invariants and functionality-based invariants, while model checkers often spend substantial effort deriving functionality invariants that do not directly contribute to the final security proof. To address this problem, we introduce Uninterpreted Functions with History (HUF), a modular abstraction for sequential modules that preserves relevant information-flow properties while abstracting away security-irrelevant functionality. We further show that the same verification insight can guide hardware design: security mechanisms become significantly easier to verify when their security depends less on hard-toprove global functional correctness. We build a verification framework to automate the use of HUF abstractions in security verification. Practical demonstration of the verification methodology is conducted through case studies on BOOM processors for secure-speculation mitigations designed with the HUF-guided design guideline.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get dddf1123-f1a1-42dc-9f33-5653efd5c91aRelated papers
- INSIGHT: Automatic Generation of Explanations for Efficient Identification of Hardware Bugs and UnderspecificationsVincent Quentin Ulitzsch, Alessandro Bertani, Peter W. Deutsch, David Langus Rodriguez et al.S&P 2026
- A Formal Approach for Detecting Vulnerabilities to Transient Execution Attacks in Out-of-Order ProcessorsMohammad Rahmani Fadiheh, Johannes Müller, Raik Brinkmann, Subhasish Mitra et al.DAC 2020 · 38 citations
- Lost and Found in Speculation: Hybrid Speculative Vulnerability DetectionMohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen et al.DAC 2024 · 6 citations
- Interpretable noninterference measurement and its application to processor designsZiqiao Zhou, Michael K. ReiterOOPSLA 2021
- SpecLFB: Eliminating Cache Side Channels in Speculative ExecutionsXiaoyu Cheng, Fei Tong, Hongyu Wang, Zhe Zhou et al.USENIX Security 2024 · 7 citations
