Side channel attack defense method and device based on dynamic memory remapping and cache cleaning
A side-channel attack and dynamic memory technology, applied in the field of network security, can solve problems such as cloud resource sharing, achieve the effect of preventing cache attacks, avoiding resource waste, and ensuring security
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2017-09-15
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention belongs to the technical field of network security, and in particular relates to a side channel attack defense method and device thereof based on dynamic memory remapping and cache clearing. Background technique
[0002] With the continuous development of the cloud computing industry, security issues in the cloud environment have received extensive attention. In order to improve resource utilization, cloud virtualization technology requires different tenants to share the underlying physical resources, so that one tenant can detect the behavior characteristics of another tenant accessing shared resources, speculate on the sensitive information of the target tenant, and implement side channel attacks. Among them, cache-based side-channel attacks are the most harmful due to their various implementation methods and reliable attack results. In recent years, experts in related fields have researched and implemented a variety of cache attacks, ...
Examples
Embodiment Construction
[0039] The present invention will be further clearly and completely described below in conjunction with the accompanying drawings and technical solutions. Apparently, the described embodiments are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.
[0040] An embodiment of the present invention provides a side channel attack defense method based on dynamic memory remapping and cache clearing, which is implemented based on a virtual machine monitor and a hardware multi-level cache architecture, see figure 1 As shown, the method contains the following:
[0041] Collect the virtual machine information running on the virtual machine monitor, the virtual machine information includes at least the physical pages occupied by each virtual machine, and the protect...