ShadowBinding: Realizing Effective Microarchitectures for In-Core Secure Speculation Schemes
Amund Bergland Kvalsvik, Magnus Själander
摘要
Secure speculation schemes have shown great promise in the war against speculative side-channel attacks, and will be a key building block for developing secure, high-performance architectures moving forward. As the field matures, the need for rigorous microarchitectures, and corresponding performance and cost analysis, become critical for evaluating secure schemes and for enabling their future adoption.
In ShadowBinding, we present effective microarchitectures for two state-of-the-art secure schemes, uncovering and mitigating fundamental microarchitectural limitations within the analyzed schemes, and provide important design characteristics. We uncover that Speculative Taint Tracking's (STT's) rename-based taint computation must be completed in a single cycle, creating an expensive dependency chain which greatly limits performance for wider processor cores. We also introduce a novel michroarchitectural approach for STT, named STT-Issue, which, by delaying the taint computation to the issue stage, eliminates the dependency chain, achieving better instructions per cycle (IPC), timing, area, and performance results.
Through a comprehensive evaluation of our STT and Non-Speculative Data Access (NDA) microarchitectural designs on the RISC-V Berkeley Out-of-Order Machine, we find that the IPC impact of in-core secure schemes is higher than previously estimated, close to 20% for the highest performance core. With insights into timing from our RTL evaluation, the performance loss, created by the combined impact of IPC and timing, becomes even greater, at 35%, 27%, and 22% for STT-Rename, STT-Issue, and NDA, respectively. If these trends were to hold for leading processor core designs, the performance impact would be well over 30%, even for the bestperforming scheme.
Through these findings, research sentiments of Spectre being solvable by in-core secure schemes at low performance costs are challenged. ShadowBinding serves as a call to arms for more indepth evaluation of secure speculation schemes, and further work into in-core methods and optimizations, which can help mitigate the high performance cost of current state-of-the-art schemes, without requiring extensive and expensive modifications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper23
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti 等CCS 2019 · 被引用 267 次
相关 Paper
- Speculative Data-Oblivious Execution: Mobilizing Safe Prediction For Safe and Efficient Speculative ExecutionJiyong Yu, Namrata Mantri, Josep Torrellas, Adam Morrison 等ISCA 2020 · 被引用 50 次
- Doppelganger Loads: A Safe, Complexity-Effective Optimization for Secure Speculation SchemesAmund Bergland Kvalsvik, Pavlos Aimoniotis, Stefanos Kaxiras, Magnus SjälanderISCA 2023 · 被引用 9 次
- Secure Prefetching for Secure Cache SystemsSumon Nath, Agustín Navarro-Torres, Alberto Ros, Biswabandan PandaMICRO 2024 · 被引用 5 次
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu 等ASPLOS 2021 · 被引用 69 次
- Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFIDaniël Trujillo, Jagadish Kotra, David Kaplan, Mengjia YanS&P 2026 · 被引用 1 次
