Gaussian Elimination of Side-Channels: Linear Algebra for Memory Coloring
Jana Hofmann, Cédric Fournet, Boris Köpf, Stavros Volos
摘要
Memory coloring is a software-based technique to ensure microarchitectural isolation between trust domains sharing a CPU. Prior coloring schemes target individual microarchitectural components and thus provide only partial solutions. In this paper, we provide theoretical foundations and practical algorithms to infer comprehensive coloring schemes for modern cloud CPUs. To this end, we first formulate the requirements for effective memory coloring schemes in a set-theoretic model, including definitions for simultaneous isolation of shared components and uniform utilization of private components. We then algebraically characterize these requirements for microarchitectural components that are indexed by linear functions, which is the prevalent case in today's CPUs. Based on this, we develop efficient algorithms for computing multi-resource coloring schemes from linear indexing functions, and for reverse-engineering unknown linear indexing functions under minimal assumptions. In a case study, we use our algorithms to compute coloring schemes for recent Intel CPUs, and we show how to design indexing functions that maximize the number of supported trust domains. CCS Concepts • Security and privacy → Formal security models; Side-channel analysis and countermeasures; Hardware reverse engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Principled Microarchitectural Isolation on Cloud CPUsStavros Volos, Cédric Fournet, Jana Hofmann, Boris Köpf 等CCS 2024 · 被引用 5 次
- Principled Design of Indexing Functions for Memory ColoringStephan Dübler, Jana Hofmann, Boris Köpf, Stavros VolosUSENIX Security 2026
它引用的顶会 Paper12
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive WorldMengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher W. Fletcher 等S&P 2019 · 被引用 201 次
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos 等S&P 2021 · 被引用 162 次
- Theory and Practice of Finding Eviction SetsPepe Vila, Boris Köpf, José F. MoralesS&P 2019 · 被引用 145 次
- SMASH: Synchronized Many-sided Rowhammer Attacks from JavaScriptFinn de Ridder, Pietro Frigo, Emanuele Vannacci, Herbert Bos 等USENIX Security 2021 · 被引用 124 次
相关 Paper
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 被引用 155 次
- Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address LeakageMikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz 等S&P 2025
- Enter, Exit, Page Fault, Leak : Testing Isolation Boundaries for Microarchitectural LeaksOleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann 等S&P 2026 · 被引用 4 次
- Efficient and Generic Microarchitectural Hash-Function RecoveryLukas Gerlach, Simon Schwarz, Nicolas Faroß, Michael SchwarzS&P 2024 · 被引用 14 次
- TME-Box: Scalable In-Process Isolation through Intel TME-MK Memory EncryptionMartin Unterguggenberger, Lukas Lamster, David Schrammel, Martin Schwarzl 等NDSS 2025
