首页> 外文会议>International conference on Parallel architectures and compilation techniques >A low-cost memory remapping scheme for address bus protection
【24h】

A low-cost memory remapping scheme for address bus protection

机译:用于地址总线保护的低成本存储器重映射方案

获取原文

摘要

The address sequence on the processor-memory bus can reveal abundant information about the control flow of a program. This can lead to critical information leakage such as encryption keys or proprietary algorithms. Addresses can be observed by attaching a hardware device on the bus that passively monitors the bus transaction. Such side-channel attacks should be given rising attention especially in a distributed computing environment, where remote servers running sensitive programs are not within the physical control of the client. Two previously proposed hardware techniques tackled this problem through randomizing address patterns on the bus. One proposal permutes a set of contiguous memory blocks under certain conditions, while the other approach randomly swaps two blocks when necessary. In this paper, we present an anatomy of these attempts and show that they impose great pressure on both the memory and the disk. This leaves them less scalable in high-performance systems where the bandwidth of the bus and memory are critical resources. We propose a lightweight solution to alleviating the pressure without compromising the security strength. The results show that our technique can reduce the memory traffic by a factor of 10 compared with the prior scheme, while keeping almost the same page fault rate as a baseline system with no security protection.
机译:处理器内存总线上的地址序列可以揭示有关程序控制流的大量信息。这可能导致严重的信息泄漏,例如加密密钥或专有算法。可以通过在总线上连接一个硬件设备来监视地址,该设备可以被动地监视总线事务。尤其在分布式计算环境中,运行敏感程序的远程服务器不在客户端的物理控制范围之内,这种侧信道攻击应引起越来越多的关注。先前提出的两种硬件技术通过随机化总线上的地址模式来解决此问题。一个建议在某些条件下置换一组连续的内存块,而另一种方法则在必要时随机交换两个块。在本文中,我们对这些尝试进行了剖析,并表明它们对内存和磁盘都施加了很大的压力。这使得它们在总线和内存带宽是关键资源的高性能系统中扩展性较差。我们提出了一种轻量级的解决方案,以减轻压力而不损害安全强度。结果表明,与现有方案相比,我们的技术可以将内存流量减少10倍,同时保持与没有安全保护功能的基准系统几乎相同的页面错误率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号