Title
Hardware-Software Integrated Approaches To Defend Against Software Cache-Based Side Channel Attacks
Abstract
Software cache-based side channel attacks present serious threats to modern computer systems. Using caches as a side channel, these attacks are able to derive secret keys used in cryptographic operations through legitimate activities. Among existing countermeasures, software solutions are typically application specific and incur substantial performance overhead. Recent hardware proposals including the Partition-Locked cache (PLcache) and Random-Permutation cache (RPcache) [23], although very effective in reducing performance overhead while enhancing the security level, may still be vulnerable to advanced cache attacks. In this paper, we propose three hardware-software approaches to defend against software cache-based attacks - they present different tradeoffs between hardware complexity and performance overhead. First, we propose to use preloading to secure the PLcache. Second, we leverage informing loads, which is a lightweight architectural support originally proposed to improve memory performance, to protect the RPcache. Third, we propose novel software permutation to replace the random permutation hardware in the RPcache. This way, regular caches can be protected with hardware support for informing loads. In our experiments, we analyze various processor models for their vulnerability to cache attacks and demonstrate that even to the processor model that is most vulnerable to cache attacks, our proposed software-hardware integrated schemes provide strong security protection. © 2008 IEEE.
Publication Date
1-1-2009
Publication Title
Proceedings - International Symposium on High-Performance Computer Architecture
Number of Pages
393-404
Document Type
Article; Proceedings Paper
Personal Identifier
scopus
DOI Link
https://doi.org/10.1109/HPCA.2009.4798277
Copyright Status
Unknown
Socpus ID
64949105813 (Scopus)
Source API URL
https://api.elsevier.com/content/abstract/scopus_id/64949105813
STARS Citation
Kong, Jingfei; Aciiçmez, Onur; Seifert, Jean Pierre; and Zhou, Huiyang, "Hardware-Software Integrated Approaches To Defend Against Software Cache-Based Side Channel Attacks" (2009). Scopus Export 2000s. 12728.
https://stars.library.ucf.edu/scopus2000/12728