首页> 外文期刊>Computer architecture news >New Cache Designs for Thwarting Software Cache-based Side Channel Attacks
【24h】

New Cache Designs for Thwarting Software Cache-based Side Channel Attacks

机译:新的缓存设计可阻止基于软件缓存的侧通道攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Software cache-based side channel attacks are a serious new class of threats for computers. Unlike physical side channel attacks that mostly target embedded cryptographic devices, cache-based side channel attacks can also undermine general purpose systems. The attacks are easy to perform, effective on most platforms, and do not require special instruments or excessive computation power. In recently demonstrated attacks on software implementations of ciphers like AES and RSA, the full key can be recovered by an unprivileged user program performing simple timing measurements based on cache misses.rnWe first analyze these attacks, identifying cache interference as the root cause of these attacks. We identify two basic mitigation approaches: the partition-based approach eliminates cache interference whereas the randomization-based approach randomizes cache interference so that zero information can be inferred. We present new security-aware cache designs, the Partition-Locked cache (PLcache) and Random Permutation cache (RPcache), analyze and prove their security, and evaluate their performance. Our results show that our new cache designs with built-in security can defend against cache-based side channel attacks in general - rather than only specific attacks on a given cryptographic algorithm - with very little performance degradation and hardware cost.
机译:基于软件缓存的侧通道攻击是计算机的一种严重的新型威胁。与主要针对嵌入式加密设备的物理侧通道攻击不同,基于缓存的侧通道攻击也会破坏通用系统。这些攻击易于执行,在大多数平台上均有效,并且不需要特殊的工具或过多的计算能力。在最近展示的针对AES和RSA等密码软件实现的攻击中,可以通过无特权的用户程序根据缓存未命中执行简单的时序测量来恢复完整密钥。我们首先分析这些攻击,将缓存干扰确定为这些攻击的根本原因。我们确定了两种基本的缓解方法:基于分区的方法消除了缓存干扰,而基于随机化的方法则使缓存干扰随机化,因此可以推断出零信息。我们提出了新的具有安全意识的缓存设计,分区锁定缓存(PLcache)和随机排列缓存(RPcache),分析并证明了它们的安全性,并评估了它们的性能。我们的结果表明,具有内置安全性的新缓存设计通常可以抵御基于缓存的边信道攻击,而不仅仅是针对给定密码算法的特定攻击,而性能下降和硬件成本却很少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号