...
首页> 外文期刊>IEEE Micro >Creating Foundations for Secure Microarchitectures With Data-Oblivious ISA Extensions
【24h】

Creating Foundations for Secure Microarchitectures With Data-Oblivious ISA Extensions

机译:使用数据忽略的ISA扩展创建安全微架构的基础

获取原文
获取原文并翻译 | 示例
           

摘要

It is not possible to write microarchitectural side channel-free code on commercial processors today. Even when we try, the resulting code is low performance. This article's goal is to lay an ISA-level foundation, called a Data-Oblivious ISA (OISA) extension, to address these problems. The key idea with an OISA is to explicitly but abstractly specify security policy, so that the policy can be decoupled from the microarchitecture and even the threat model. Analogous to a traditional ISA, this enables an OISA to serve as a portable security-centric abstraction for software while enabling security-aware implementation and optimization flexibility for hardware. The article starts by giving a deep-dive in OISA principles and formal definitions underpinning OISA security. We also provide a concrete OISA built on top of RISC-V, an implementation prototype on the RISC-V BOOM microarchitecture, a formal analysis and security argument, and finally extensive performance evaluation on a range of data-oblivious benchmarks.
机译:目前无法在商业处理器上编写免费的无线轴建筑侧通道代码。即使我们尝试,结果代码也很低。本文的目标是为ISA级基金会奠定名为Data-Ovevious ISA(OISA)扩展,以解决这些问题。与OISA的关键想法是明确但抽象地指定安全策略,以便策略可以从微架构甚至威胁模型解耦。类似于传统的ISA,这使得OISA能够成为软件的便携式安全的抽象,同时启用安全感知的实现和用于硬件的优化灵活性。本文首先在潜水的原则和正式定义中致力于支撑OISA安全性。我们还提供了一个基于RISC-V之上的混凝土OISA,在RISC-V繁荣微架构,正式分析和安全性论证上进行了一个实践原型,最后对一系列数据忽视基准进行了广泛的性能评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号