CN108427576A - 一种免受Spectre攻击的高性能推测执行算法 - Google Patents
一种免受Spectre攻击的高性能推测执行算法 Download PDFInfo
- Publication number
- CN108427576A CN108427576A CN201810144875.7A CN201810144875A CN108427576A CN 108427576 A CN108427576 A CN 108427576A CN 201810144875 A CN201810144875 A CN 201810144875A CN 108427576 A CN108427576 A CN 108427576A
- Authority
- CN
- China
- Prior art keywords
- instruction
- branch
- performance
- branch instruction
- executes
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 230000005540 biological transmission Effects 0.000 claims abstract 5
- 230000001419 dependent effect Effects 0.000 claims description 11
- 238000013461 design Methods 0.000 claims description 10
- 238000000034 method Methods 0.000 claims description 9
- 230000008569 process Effects 0.000 claims description 8
- 238000013507 mapping Methods 0.000 claims description 4
- 238000012545 processing Methods 0.000 claims description 4
- 230000009471 action Effects 0.000 claims description 3
- 238000012544 monitoring process Methods 0.000 claims 1
- 238000002834 transmittance Methods 0.000 claims 1
- 238000002955 isolation Methods 0.000 abstract description 8
- 230000007246 mechanism Effects 0.000 abstract description 5
- 238000001514 detection method Methods 0.000 abstract description 3
- 238000005516 engineering process Methods 0.000 abstract description 3
- 230000008439 repair process Effects 0.000 description 4
- 238000004040 coloring Methods 0.000 description 2
- 238000000605 extraction Methods 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 238000012546 transfer Methods 0.000 description 2
- 230000006978 adaptation Effects 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 230000007812 deficiency Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000036039 immunity Effects 0.000 description 1
- 230000000246 remedial effect Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/30—Arrangements for executing machine instructions, e.g. instruction decode
- G06F9/38—Concurrent instruction execution, e.g. pipeline or look ahead
- G06F9/3836—Instruction issuing, e.g. dynamic instruction scheduling or out of order instruction execution
- G06F9/3842—Speculative instruction execution
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/556—Detecting local intrusion or implementing counter-measures involving covert channels, i.e. data leakage between processes
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/30—Arrangements for executing machine instructions, e.g. instruction decode
- G06F9/38—Concurrent instruction execution, e.g. pipeline or look ahead
- G06F9/3836—Instruction issuing, e.g. dynamic instruction scheduling or out of order instruction execution
- G06F9/3838—Dependency mechanisms, e.g. register scoreboarding
- G06F9/384—Register renaming
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2143—Clearing memory, e.g. to prevent the data from being stolen
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Advance Control (AREA)
Abstract
Description
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810144875.7A CN108427576B (zh) | 2018-02-12 | 2018-02-12 | 一种免受Spectre攻击的高性能推测执行算法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810144875.7A CN108427576B (zh) | 2018-02-12 | 2018-02-12 | 一种免受Spectre攻击的高性能推测执行算法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108427576A true CN108427576A (zh) | 2018-08-21 |
CN108427576B CN108427576B (zh) | 2022-04-01 |
Family
ID=63156986
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810144875.7A Active CN108427576B (zh) | 2018-02-12 | 2018-02-12 | 一种免受Spectre攻击的高性能推测执行算法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108427576B (zh) |
Cited By (17)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109190382A (zh) * | 2018-09-11 | 2019-01-11 | 网御安全技术(深圳)有限公司 | 一种cpu信道检测方法、智能终端及存储介质 |
CN111061512A (zh) * | 2019-12-06 | 2020-04-24 | 湖北文理学院 | 分支指令的处理方法、装置、设备和存储介质 |
CN111241551A (zh) * | 2019-09-19 | 2020-06-05 | 中国科学院信息工程研究所 | 基于缓存命中状态的处理器芯片假安全依赖冲突的识别方法 |
CN111241599A (zh) * | 2019-09-19 | 2020-06-05 | 中国科学院信息工程研究所 | 一种处理器芯片安全依赖的动态识别及维护方法 |
CN111274573A (zh) * | 2019-09-19 | 2020-06-12 | 中国科学院信息工程研究所 | 一种基于访存请求序列的处理器芯片假安全依赖冲突的识别方法 |
CN111274198A (zh) * | 2020-01-17 | 2020-06-12 | 中国科学院计算技术研究所 | 一种微架构 |
CN111274584A (zh) * | 2020-01-17 | 2020-06-12 | 中国科学院计算技术研究所 | 一种基于缓存回滚以防御处理器瞬态攻击的装置 |
CN111444509A (zh) * | 2018-12-27 | 2020-07-24 | 北京奇虎科技有限公司 | 基于虚拟机实现的cpu漏洞检测方法及系统 |
CN111857815A (zh) * | 2019-04-24 | 2020-10-30 | 华为技术有限公司 | 指令处理的方法及装置 |
CN112256332A (zh) * | 2020-06-01 | 2021-01-22 | 中国科学院信息工程研究所 | 一种处理器芯片假安全依赖冲突的识别方法及系统 |
CN113127880A (zh) * | 2021-03-25 | 2021-07-16 | 华东师范大学 | 一种一级数据缓存中推测执行侧信道漏洞检测方法 |
CN113392407A (zh) * | 2021-07-13 | 2021-09-14 | 东南大学 | 一种面向高性能处理器的防Spectre攻击的架构优化方法 |
TWI783582B (zh) * | 2020-11-13 | 2022-11-11 | 美商聖圖爾科技公司 | 利用間接有效表的Spectre修復的方法和微處理器 |
US11783050B2 (en) | 2020-11-13 | 2023-10-10 | Centaur Technology, Inc. | Spectre fixes with predictor mode tag |
CN117077152A (zh) * | 2023-10-18 | 2023-11-17 | 中电科申泰信息科技有限公司 | 扰乱超标量处理器推测执行Spectre攻击的方法 |
CN117270972A (zh) * | 2023-11-21 | 2023-12-22 | 芯来智融半导体科技(上海)有限公司 | 指令处理方法、装置、设备和介质 |
CN119005118A (zh) * | 2024-07-31 | 2024-11-22 | 深圳奥维领芯科技有限公司 | 一种基于加载序列的硬件友好型推测加载电路的方法 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20140283040A1 (en) * | 2013-03-14 | 2014-09-18 | Daniel Shawcross Wilkerson | Hard Object: Lightweight Hardware Enforcement of Encapsulation, Unforgeability, and Transactionality |
CN106133705A (zh) * | 2014-03-14 | 2016-11-16 | 国际商业机器公司 | 指示事务状态的一致性协议增强 |
-
2018
- 2018-02-12 CN CN201810144875.7A patent/CN108427576B/zh active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20140283040A1 (en) * | 2013-03-14 | 2014-09-18 | Daniel Shawcross Wilkerson | Hard Object: Lightweight Hardware Enforcement of Encapsulation, Unforgeability, and Transactionality |
US20170126738A1 (en) * | 2013-03-14 | 2017-05-04 | Daniel Shawcross Wilkerson | Hard Object: Lightweight Hardware Enforcement of Encapsulation, Unforgeability, and Transactionality |
CN106133705A (zh) * | 2014-03-14 | 2016-11-16 | 国际商业机器公司 | 指示事务状态的一致性协议增强 |
Non-Patent Citations (1)
Title |
---|
STUDYSKILL: "spectre漏端代码分析", 《HTTPS://WWW.CNBLOGS.COM/STUDYSKILL/P/8276222.HTML》 * |
Cited By (26)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109190382A (zh) * | 2018-09-11 | 2019-01-11 | 网御安全技术(深圳)有限公司 | 一种cpu信道检测方法、智能终端及存储介质 |
CN111444509B (zh) * | 2018-12-27 | 2024-05-14 | 北京奇虎科技有限公司 | 基于虚拟机实现的cpu漏洞检测方法及系统 |
CN111444509A (zh) * | 2018-12-27 | 2020-07-24 | 北京奇虎科技有限公司 | 基于虚拟机实现的cpu漏洞检测方法及系统 |
CN111857815A (zh) * | 2019-04-24 | 2020-10-30 | 华为技术有限公司 | 指令处理的方法及装置 |
CN111241551A (zh) * | 2019-09-19 | 2020-06-05 | 中国科学院信息工程研究所 | 基于缓存命中状态的处理器芯片假安全依赖冲突的识别方法 |
CN111241599A (zh) * | 2019-09-19 | 2020-06-05 | 中国科学院信息工程研究所 | 一种处理器芯片安全依赖的动态识别及维护方法 |
CN111274573A (zh) * | 2019-09-19 | 2020-06-12 | 中国科学院信息工程研究所 | 一种基于访存请求序列的处理器芯片假安全依赖冲突的识别方法 |
CN111241599B (zh) * | 2019-09-19 | 2022-08-23 | 中国科学院信息工程研究所 | 一种处理器芯片安全依赖的动态识别及维护方法 |
CN111241551B (zh) * | 2019-09-19 | 2022-01-25 | 中国科学院信息工程研究所 | 基于缓存命中状态的处理器芯片假安全依赖冲突的识别方法 |
CN111061512A (zh) * | 2019-12-06 | 2020-04-24 | 湖北文理学院 | 分支指令的处理方法、装置、设备和存储介质 |
CN111061512B (zh) * | 2019-12-06 | 2022-11-15 | 湖北文理学院 | 分支指令的处理方法、装置、设备和存储介质 |
CN111274198B (zh) * | 2020-01-17 | 2021-11-19 | 中国科学院计算技术研究所 | 一种微架构 |
CN111274198A (zh) * | 2020-01-17 | 2020-06-12 | 中国科学院计算技术研究所 | 一种微架构 |
CN111274584A (zh) * | 2020-01-17 | 2020-06-12 | 中国科学院计算技术研究所 | 一种基于缓存回滚以防御处理器瞬态攻击的装置 |
CN112256332A (zh) * | 2020-06-01 | 2021-01-22 | 中国科学院信息工程研究所 | 一种处理器芯片假安全依赖冲突的识别方法及系统 |
US11783050B2 (en) | 2020-11-13 | 2023-10-10 | Centaur Technology, Inc. | Spectre fixes with predictor mode tag |
TWI783582B (zh) * | 2020-11-13 | 2022-11-11 | 美商聖圖爾科技公司 | 利用間接有效表的Spectre修復的方法和微處理器 |
US11500643B2 (en) | 2020-11-13 | 2022-11-15 | Centaur Technology, Inc. | Spectre fixes with indirect valid table |
CN113127880A (zh) * | 2021-03-25 | 2021-07-16 | 华东师范大学 | 一种一级数据缓存中推测执行侧信道漏洞检测方法 |
CN113392407B (zh) * | 2021-07-13 | 2022-11-01 | 东南大学 | 一种面向高性能处理器的防Spectre攻击的架构优化方法 |
CN113392407A (zh) * | 2021-07-13 | 2021-09-14 | 东南大学 | 一种面向高性能处理器的防Spectre攻击的架构优化方法 |
CN117077152A (zh) * | 2023-10-18 | 2023-11-17 | 中电科申泰信息科技有限公司 | 扰乱超标量处理器推测执行Spectre攻击的方法 |
CN117077152B (zh) * | 2023-10-18 | 2024-01-23 | 中电科申泰信息科技有限公司 | 扰乱超标量处理器推测执行Spectre攻击的方法 |
CN117270972A (zh) * | 2023-11-21 | 2023-12-22 | 芯来智融半导体科技(上海)有限公司 | 指令处理方法、装置、设备和介质 |
CN117270972B (zh) * | 2023-11-21 | 2024-03-15 | 芯来智融半导体科技(上海)有限公司 | 指令处理方法、装置、设备和介质 |
CN119005118A (zh) * | 2024-07-31 | 2024-11-22 | 深圳奥维领芯科技有限公司 | 一种基于加载序列的硬件友好型推测加载电路的方法 |
Also Published As
Publication number | Publication date |
---|---|
CN108427576B (zh) | 2022-04-01 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108427576A (zh) | 一种免受Spectre攻击的高性能推测执行算法 | |
Lipp et al. | Meltdown: Reading kernel memory from user space | |
Lipp et al. | Meltdown | |
US11681533B2 (en) | Restricted speculative execution mode to prevent observable side effects | |
US11989286B2 (en) | Conditioning store-to-load forwarding (STLF) on past observations of STLF propriety | |
JP7443641B2 (ja) | 命令の機密としての動的な指定 | |
US9524162B2 (en) | Apparatus and method for memory copy at a processor | |
US8627047B2 (en) | Store data forwarding with no memory model restrictions | |
US20220229667A1 (en) | Pipelines for Secure Multithread Execution | |
US20210303303A1 (en) | Speculative execution following a state transition instruction | |
US11099849B2 (en) | Method for reducing fetch cycles for return-type instructions | |
CN110968349B (zh) | 一种抵御投机执行侧信道攻击的处理器缓存技术方案 | |
US11340901B2 (en) | Apparatus and method for controlling allocation of instructions into an instruction cache storage | |
CN111241599B (zh) | 一种处理器芯片安全依赖的动态识别及维护方法 | |
CN111936968B (zh) | 一种指令执行方法及装置 | |
US20240086526A1 (en) | Mitigating pointer authentication code (pac) attacks in processor-based devices | |
US11263015B1 (en) | Microarchitectural sensitive tag flow | |
CN111045731B (zh) | 用于执行在推测屏障指令之后的分支指令的方法及装置 | |
CN110889147B (zh) | 一种利用填充缓存抵御Cache边信道攻击的方法 | |
CN111274573B (zh) | 一种基于访存请求序列的处理器芯片假安全依赖冲突的识别方法 | |
US10387311B2 (en) | Cache directory that determines current state of a translation in a microprocessor core cache | |
CN111241551A (zh) | 基于缓存命中状态的处理器芯片假安全依赖冲突的识别方法 | |
Mangard et al. | Moritz Lipp1, Michael Schwarz, Daniel Gruss, Thomas Prescher 2, Werner Haas 2 | |
Mishra | Adversarial Assertions |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20241104 Address after: Room 232, 19th Floor, No. 10 Xitucheng Road, Haidian District, Beijing 100876 Patentee after: Beijing Beiyou Anbosheng Communication Technology Co.,Ltd. Country or region after: China Address before: 100176 unit 4014, building 36, yard 1, Desheng North Street, Beijing Economic and Technological Development Zone, Daxing District, Beijing (centralized office area) Patentee before: HUAXIAXIN (BEIJING) GENERAL PROCESSOR TECHNOLOGY Co.,Ltd. Country or region before: China |
|
TR01 | Transfer of patent right |