A cache side-channel attack defense method based on data hiding
By setting up a data hiding buffer outside the cache hierarchy and using secure placement and replacement strategies to manage data, the problem that existing technologies cannot simultaneously defend against different types of cache side-channel attacks is solved, achieving efficient security defense and low performance overhead.
Patent Information
- Application Number
- CN202211718131.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2042-12-29
AI Technical Summary
Existing cache side-channel attack defense solutions cannot effectively defend against both refresh-based and conflict-based cache side-channel attacks, and usually require modifying the operating system or compromising system performance.
An independent data hiding buffer is set up outside the existing cache hierarchy to hide the evicted data blocks. The data in the buffer is managed through safe placement strategy, safe replacement strategy and fully associative data block search strategy to prevent attackers from exploiting time differences.
Without damaging system performance or modifying the operating system, it effectively defends against all types of cache side-channel attacks, introducing only 0.5% storage overhead.
Smart Images

Figure CN116055146B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cache security, and in particular relates to a cache side channel attack defense method based on data hiding. Background Art
[0002] Cache timing attacks exploit the difference in time between cache hits and cache misses to leak private information. Although the memory address space between different processes is not shared for security reasons, caches can still be shared between processes. All processes running on the same CPU core share the core's private cache. Furthermore, processes running on all CPU cores share the last-level cache. Therefore, cache state changes caused by one process accessing the cache can affect cache hits and misses for another process. By exploiting the significant time difference between cache hits and cache misses, an attacker can infer the victim's cache accesses by measuring their own cache access latency. Because cache accesses are triggered by memory access commands, an attacker can further infer the victim's memory access sequence based on the victim's cache accesses.
[0003] Caches are often used to launch side-channel attacks against victims. In cache-based side-channel attacks, attackers can obtain private information related to the victim, such as cryptographic keys, by monitoring the victim's cache access sequence (Winter is Here! A Decade of Cache-based Side-Channel Attacks, Detection & Mitigation for RSA, 2021). Side-channel attacks targeting the last-level cache can be used by attackers to leak data across CPU cores, posing a significant security threat to existing systems.
[0004] Side-channel attacks against the last-level cache typically have three phases: the attacker evicts the targeted address, waits for the victim to execute, and observes accesses to the targeted address. First, to ensure that the results observed in the third phase are the result of the victim's execution in the second phase, the attacker evicts the targeted address from the cache hierarchy. Then, the attacker waits for a predetermined period of time. During this period, the victim may or may not access the target address. If the victim accesses the targeted address, the evicted address is reloaded into the cache hierarchy. Conversely, if the victim does not access the target address, no trace remains in the cache hierarchy. In the third phase, the attacker executes specific memory access commands based on the cache attack characteristics to detect the presence of the target address in the cache, thereby inferring whether the victim accessed the targeted address during the wait phase. Yan et al. (Secure Hierarchy-Aware Cache Replacement Policy (SHARP): Defending Against Cache-Based Side Channel Attacks) show that each round of cache side-channel attacks typically takes between 2,500 and 10,000 clock cycles.
[0005] Based on how the attacker evicts the target address in the first stage, some papers have categorized existing cache side-channel attacks into flush-based and conflict-based attacks. Flush-based cache side-channel attacks include flush-reload and flush-flush. In these attacks, the target address is shared between the attacker and the victim. The attacker exploits the system's native flush instructions (such as clflush in the x86 architecture) to evict the cache copy of the victim's address. These instructions accept a virtual address as a parameter and, upon execution, flush the corresponding cache line from the cache hierarchy. Therefore, an attacker can use flush instructions within their own process to interfere with the state of the target address in the cache hierarchy and further exploit the victim's memory accesses. However, when a system lacks flush instructions, attackers often resort to conflict-based cache side-channel attacks. Conflict-based cache side-channel attacks include prime+probe, evict+reload, and evict+time attacks. In this type of attack, the attacker evicts the target address by priming the eviction set that maps to the same cache group as the victim address. For a cache with an associativity of w, the eviction set refers to w physical addresses that map to the same cache group. After the target address is replaced from the last-level cache, a back invalidation operation is triggered. This operation sends cache line clear commands carrying the target address to all private caches. These commands evict the target address from the victim's private cache.
[0006] Among existing defenses against last-level cache side-channel attacks, no solution has yet been proposed that is effective against both types of side-channel attacks and avoids damaging system performance or modifying the operating system. Currently, most existing defenses can only defend against a certain type of cache side-channel attack. The few defenses that are effective against both attacks not only require modifying the operating system but also damage system performance. From a hardware design perspective, there are currently three main types of defenses against cache side-channel attacks. The first type is based on randomization, such as those proposed by MK Qureshi (CEASER: Mitigating Conflict-Based Cache Attacks via Encrypted-Address and Remapping., MICRO, 2018) and Q. Tan et al. (Scattercache: Thwarting Cache Attacks via Cache Set Randomization, USENIX Security, 2019). The second category is based on methods that avoid cache backward eviction, such as those proposed by M. Yan et al. (Secure Hierarchy-Aware Cache Replacement Policy (SHARP): Defending Against Cache-Based Side Channel Attacks, ISCA, 2017), M. Kayaalp et al. (RIC: Relaxed Inclusion Caches for Mitigating LLC Side-Channel Attacks, DAC, 2017), and B. Panda (Fooling the Sense of Cross-core Last-level Cache Eviction-based Attacker by Prefetching Common Sense, PACT, 2019). The third category is based on cache partitioning, such as those proposed by Z. Zhou et al. (A Software Approach to Defeating Side Channels in Last-Level Caches, CCS, 2016) and V. Kiriansky et al. (DAWG: A Defense Against Cache Timing Attacks in Speculative Execution Processors, MICRO, 2016).
[0007] The first method uses a hash algorithm to randomize the mapping between physical addresses and cache groups. In conflict-based cache side-channel attacks, the attacker uses eviction sets to control the state of the victim cache line in the cache hierarchy. The eviction set construction algorithm needs to take advantage of the condition that "physical addresses and cache groups are associatively mapped." Using hash components to randomize the mapping between physical addresses and cache groups can greatly prolong the time it takes for an attacker to construct eviction sets, thereby preventing the attacker from using eviction sets in cache side-channel attacks. This type of scheme usually imposes a non-negligible performance overhead on the system. Secondly, because randomization-based cache side-channel defense schemes do not affect the use of refresh instructions, this type of scheme cannot defend against refresh-based cache side-channel attacks.
[0008] The second method is based on avoiding cache backward abolition. Its basic idea is to avoid the backward abolition of the copy of the cache line in the private cache after the cache line is replaced from the last-level cache. In order to achieve the above purpose, the designers of this type of defense scheme have proposed a cache line replacement strategy with the goal of avoiding backward abolition, relaxing the inclusiveness of some cache lines, and prefetching blocks that are backward abolitioned. This type of method can not only effectively defend against conflict-based cache side channel attacks, but may also improve system performance. However, since the refresh instruction does not rely on backward abolition to evict the copy of the target address in the victim's private cache, this type of method cannot defend against refresh-based cache side channel attacks.
[0009] The third approach is based on cache partitioning. Its basic concept is to divide the cache into mutually exclusive parts and assign them to different security domains, thereby preventing cache access by one security domain from affecting the cache line states of other security domains. Therefore, most cache partitioning-based schemes can effectively defend against conflict-based cache side-channel attacks. A few schemes that allow different security domains to simultaneously hold the same cache line in the cache (DAWG: A Defense Against Cache Timing Attacks in Speculative Execution Processors, MICRO, 2016) can also defend against refresh-based cache side-channel attacks. However, these side-channel defense schemes generally require operating system support for security domain partitioning. Furthermore, compared to the first two schemes, cache partitioning defense schemes often incur greater system performance penalties. Summary of the Invention
[0010] The present invention provides a cache side channel attack defense method based on data hiding, which can not only defend against two types of cache side channel attacks at the same time, but also avoid damaging performance and modifying the operating system.
[0011] A cache side-channel attack defense method based on data hiding is proposed. An independent data hiding buffer is set outside the existing cache hierarchy to hide data blocks evicted from the last-level cache.
[0012] The data hiding buffer includes buffered data blocks, a security status associated with each data block, a security placement strategy for screening buffered data blocks, a security replacement strategy for controlling data replacement in the buffer, and an index-based fully associative data block search strategy;
[0013] The secure state stores metadata needed to execute the secure replacement strategy in the data hiding buffer. The secure placement and replacement strategies are used when cache line eviction occurs in the last-level cache, and the fully associative data block search strategy is used when accessing the data hiding buffer in the event of a last-level cache miss.
[0014] The metadata records the owner information of each data block when it is first cached in the data hiding buffer, the number of data blocks already owned by each CPU core in the data hiding buffer, and the maximum number of data blocks that each CPU core can own in the data hiding buffer. The owner information indicates which CPU cores own a data block cached in the data hiding buffer, specifically including the sharer information and evictee information of the data block. The sharer information indicates which private caches have previously contained copies of the data block, and the evictee information indicates which CPU core has previously evicted the data block.
[0015] Furthermore, when a cache line is evicted from the last-level cache, a method for obtaining the sharer information is selected according to the reason why the last-level cache line is evicted, and the sharer information is obtained;
[0016] The obtained sharer information is first transmitted to the secure placement strategy of the data hiding buffer, which is used to filter out data blocks that meet the conditions for adding them into the data hiding buffer;
[0017] Before the filtered data blocks are finally placed into the data hiding buffer, if the number of data blocks owned by a CPU core reaches the maximum value or the physical space in the data hiding buffer is insufficient, the security replacement strategy will be triggered.
[0018] The specific method for obtaining the sharer information is as follows:
[0019] If a cache line is evicted by a flush instruction, each private cache will be asked in turn whether it has a copy of the cache line to obtain the sharer information of the cache line; if the cache line is replaced because the last-level cache is full, the acquisition of the sharer information will be embedded in the backward abolition process of the last-level cache.
[0020] The specific process of obtaining sharer information is as follows:
[0021] When a replacement occurs in the last-level cache, a backward invalidation command is sent to the CPU core listed in the directory. If the cache controller finds that the data block requested by the backward invalidation command exists in the private cache, it will reply with a data existence signal (ACK_EXIST) to the last-level cache. Conversely, if the requested data block does not exist in the private cache, the cache controller will reply with a data non-existence signal (ACK_NOTEXIST).
[0022] The last-level cache controller will summarize the received return signals and eventually obtain the accurate sharer information of the replaced cache line.
[0023] The secure placement policy defines two filtering conditions. Data blocks that meet any of the filtering conditions will be added to the data hiding buffer. Otherwise, the process of adding data blocks to the data hiding buffer will be terminated. The two filtering conditions defined are:
[0024] The first condition is that a cache line is evicted from the last-level cache when a copy exists in one or more private caches. The second condition is that a cache line in the last-level cache is replaced by a block from the data hiding buffer.
[0025] Data blocks that pass the safe placement policy will be owned by their evictee information and sharer information.
[0026] The process of the safe replacement policy is as follows:
[0027] If the number of data blocks owned by a CPU core reaches the maximum value, the ownership revocation routine (ownership_invalidation) is called to handle it. For those cores whose data block count is about to exceed the maximum value, the routine randomly selects one of the data blocks owned by these cores in turn to revoke the ownership of one of the data blocks owned by the core, and the corresponding data block count value is reduced by 1;
[0028] If the physical space in the data hiding buffer is insufficient, the secure eviction routine (secure_eviction) is called to handle the problem. This routine randomly selects a data block that is not owned by a CPU core in the data hiding buffer to replace it. The replaced data block will be effectively expelled from the data hiding buffer, and its corresponding security status in the data hiding buffer will also be cleared;
[0029] After the above two routines are executed, the data block will be added to the data hiding buffer.
[0030] When the last-level cache access is missed, the data request will be routed to the data hiding buffer for processing, and the search speed of data blocks in the data hiding buffer will be accelerated through the index-based fully associative data block search strategy.
[0031] The fully associative data block search strategy is specifically as follows:
[0032] The data blocks and security states in the data hiding buffer are organized in a fully associative manner and implemented using an SRAM array. A lookup table is designed for the data hiding buffer to convert the physical address of a data request into the index number of the corresponding data block in the data hiding buffer. The steps for accessing the data hiding buffer request command lookup are as follows:
[0033] (1) Extract the physical address in the data request and send it to the lookup table;
[0034] (2) If the physical address does not exist in the lookup table, the search ends; if the physical address does exist in the lookup table, the index number of the corresponding data block is obtained;
[0035] (3) The data hiding buffer controller uses the index number to access the data block and security status.
[0036] Compared with the prior art, the present invention has the following beneficial effects:
[0037] The defense method of the present invention requires only the introduction of a data-hiding buffer, independent of the existing cache hierarchy. This buffer hides data blocks that have been evicted from the last-level cache and are potentially exploitable by attackers. These hidden data blocks can quickly respond to data requests in the event of a last-level cache miss. The data-hiding buffer eliminates the significant time differences exploited by attackers in cache side-channel attacks. Using this method, all types of cache side-channel attacks can be defended against with only 0.5% storage overhead. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 This is a system architecture diagram of a cache side channel attack defense method based on data hiding according to the present invention;
[0039] Figure 2 The present invention provides a process for processing cache line eviction in the last level cache;
[0040] Figure 3 This is a process for obtaining information about sharers when a cache line is replaced due to a full last-level cache in the present invention;
[0041] Figure 4 This is the safe replacement strategy processing flow in the present invention. DETAILED DESCRIPTION
[0042] The present invention will be described in further detail below with reference to the accompanying drawings and examples. It should be noted that the following examples are intended to facilitate understanding of the present invention and do not have any limiting effect on the present invention.
[0043] A data-hiding-based defense method for cache side-channel attacks requires only the introduction of a data-hiding buffer, independent of the existing cache hierarchy. This buffer hides data blocks that have been evicted from the last-level cache and are potentially exploitable by attackers. These hidden data blocks can quickly respond to data requests in the event of a last-level cache miss, eliminating the significant time differences exploited by attackers in cache side-channel attacks.
[0044] like Figure 1 As shown, the data hiding buffer contains buffered data blocks, a security state associated with each data block, a secure placement policy for filtering buffered data blocks, a secure replacement policy for controlling data replacement within the buffer, and an index-based fully associative data block search policy. The security state stores metadata required for the data hiding buffer to execute the secure replacement policy. It records the owner information (security_domain_list) of each data block when it is first cached in the data hiding buffer, the number of data blocks each core already owns in the data hiding buffer (counter), and the maximum number of data blocks each core can own in the data hiding buffer (global_threshold). Owner information indicates which cores own a data block cached in the data hiding buffer and specifically includes the block's sharer information and evictor information. Sharer information indicates which private caches previously contained copies of the data block. Evictor information indicates which core previously evicted the data block. The secure placement policy and secure replacement policy are primarily used when a cache line is evicted from the last-level cache. The index-based fully associative data block search policy is primarily used when accessing the data hiding buffer following a last-level cache miss.
[0045] like Figure 2 As shown in the figure, when a cache line is evicted from the last level cache, the system first needs to obtain the sharer information of the evicted cache line. This information will be passed as input to the safe placement strategy and the safe replacement strategy. The system will select a method for obtaining the sharer information based on the reason why the last level cache line is evicted. If the cache line is evicted by a flush instruction, the system will sequentially ask each private cache whether there is a copy of the cache line to obtain the sharer information of the cache line. If the cache line is replaced because the last level cache is full, the acquisition of the sharer information will be embedded in the backward abolition process of the last level cache. As shown in the figure, Figure 3 As shown, when a replacement occurs in the last-level cache, a backward destroy command is sent to the CPU core recorded in the directory. Figure 3In the BAK_INV instruction, BAK_INV indicates a return invalidation. When the cache controller detects that the data block requested by the backward invalidation command exists in the private cache, it responds with a data presence signal (ACK_EXIST) to the last-level cache. Conversely, if the requested data block does not exist in the private cache, the cache controller responds with a data absence signal (ACK_NOTEXIST). The last-level cache controller aggregates the received response signals to ultimately obtain the precise sharer information for the replaced cache line.
[0046] The sharer information will first be passed to the secure placement policy of the data hiding buffer. This policy is used to decide whether to add the data blocks evicted from the last-level cache into the data hiding buffer. The secure placement policy defines two conditions. Data blocks that meet any of the conditions will be considered for addition to the data hiding buffer, otherwise the process of adding data blocks to the data hiding buffer will be terminated. The first condition defined by the secure placement policy is that when a cache line is evicted from the last-level cache, there is a copy in one or more private caches. Another condition defined by the secure placement policy is that the cache line of the last-level cache is replaced by a block from the data hiding buffer. Data blocks that pass the secure placement policy screening will be owned by their evictees and sharers. Owner information will be Figure 2 After the process is executed, it is recorded in the security status corresponding to the cached data block.
[0047] Before finally placing the data block into the data hiding buffer, the safe replacement strategy will be triggered when the number of data blocks owned by a core, counter, reaches the maximum value (global_threshold) or the physical space in the data hiding buffer is insufficient. Figure 4 The processing flow of the secure replacement strategy is shown. When the first situation occurs, the present invention will call the ownership release routine (ownership_invalidation) to handle it. For those cores whose counter values are about to exceed the global_threshold, the routine will randomly select one of the data blocks owned by these cores in turn to release the core's ownership of a certain data block it already owns, and the corresponding counter value will be reduced by 1. When the second situation occurs, the present invention will call another routine---secure eviction routine (secure_eviction) to handle it. This routine will randomly select a data block that is not owned by a core in the data hiding buffer for replacement. The replaced data block will be essentially expelled from the data hiding buffer, and its corresponding security status in the data hiding buffer will also be cleared. After the above two routines are executed, the data block will be added to the data hiding buffer.
[0048] When the last-level cache access is missed, the data request will be routed to the data hiding buffer for processing. The present invention designs an index-based fully associative data block search strategy to speed up the search speed of data blocks in the data hiding buffer. The data blocks and security states in the data hiding buffer are organized in a fully associative mode, which can be implemented using an SRAM array. The present invention designs a jump table for the data hiding buffer. The jump table can convert the physical address of the data request into the index number of the corresponding data block in the data hiding buffer. The steps for searching the request command to access the data hiding buffer are as follows:
[0049] (1) Extract the physical address in the data request and send it to the lookup table.
[0050] (2) If the corresponding relationship of the physical address does not exist in the lookup table, the search ends; if the corresponding relationship of the physical address does exist in the lookup table, the index number of the corresponding data block is obtained.
[0051] (3) The data hiding buffer controller uses the index number to access the data block and security status.
[0052] To verify the effectiveness of the present invention, the method was run in the gem5 simulator environment, using the simulator's Ruby mode to simulate a multi-core CPU using the MESI protocol for cache coherence. The present invention implemented a data hiding buffer for evicted blocks in the last-level cache on gem5. The core module includes a data hiding buffer placement strategy, a replacement strategy, and an index-based fully associative data block search strategy.
[0053] The simulator implementation specifically includes the following steps:
[0054] (1) Add ACK_NOTEXIST to CoherenceResponseType. The original ACK signal is treated as ACK_EXIST. The MESI_Three_Level-L1cache.sm file selects one of the two actions, fi_sendInvAck_Exist and fin_sendInvAck_NotExist, to respond based on the existence of the data block.
[0055] (2) The last-level cache controller uses rts_recordTrueSharer to record the sharer information of the data block, and sets tbe.Buffer based on the summarized sharer information to decide whether to safely place the data block evicted from the last-level cache.
[0056] (3) Add cacheAvail, which is used to determine whether the data hiding buffer meets the conditions of the secure replacement protocol before caching data.
[0057] (4) Create m_address_index to implement the index-based fully associative data block search strategy.
[0058] The performance of the present invention was tested using the SPEC CPU 2017 benchmark. When evaluating the single-core performance of the invention, 2 billion instructions were executed for each benchmark. The first 1 billion instructions were used to warm up the system, and the last 1 billion instructions were used to collect performance data of the invention. In addition, when evaluating the performance of the invention on a multi-core system (the number of cores is n), n were randomly selected from all the benchmarks and assigned to n CPU cores for execution. The system was not warmed up and data collection was not started until all CPU cores had executed at least 1 billion instructions. Afterwards, data collection ended when the slowest benchmark had run 2 billion instructions.
[0059] The performance of the present invention is measured using two key performance indicators: instructions per cycle (IPC) and misses per thousand instructions (MPKI) of the last-level cache. A higher IPC or a lower MPKI indicates better performance. A system without a data hiding buffer is used as a baseline system, and the performance indicators measured by the present invention are compared with those of the baseline system. Experimental results show that the present invention can bring an IPC improvement of 0.03% to 0.06% and an MPKI reduction of 0.35% to 7.08% to the system in single-core and dual-core systems. This shows that the present invention provides security for the system without introducing performance overhead like other defense solutions.
[0060] Then, the performance of the present invention in a dual-core system was measured in turn when global_threshold took different values. This parameter value determines the size of the data hiding buffer. The larger the data hiding buffer, the stronger the protection provided. The experimental results show that when global_threshold is 64 to 512, the IPC of the present invention can be improved by 0.06% to 0.09% compared with the baseline system, and MPKI can be reduced by 6.40% to 8.29%. This means that as long as the system using the present invention can tolerate the storage overhead brought about by the increase of global_threshold, it can be considered to increase global_threshold to obtain stronger security guarantees and better performance.
[0061] Finally, we measured the performance of our invention with increasing core counts. Increasing the number of cores to 4 and 8 revealed a 0.27% to 0.28% improvement in IPC and a 8.98% to 11.27% decrease in MPKI. The performance of our invention improved with increasing core counts, demonstrating its suitability for large-scale applications.
[0062] The above test results show that the present invention is not only safe, but also has the advantages of not damaging system performance and not modifying the operating system, so that practical problems can be solved.
[0063] The embodiments described above provide a detailed description of the technical solutions and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not intended to limit the present invention. Any modifications, supplements and equivalent substitutions made within the scope of the principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A cache side channel attack defense method based on data hiding, characterized in that: An independent data hiding buffer is set outside the existing cache hierarchy to hide data blocks evicted from the last-level cache; The data hiding buffer includes buffered data blocks, a security status associated with each data block, a security placement strategy for screening buffered data blocks, a security replacement strategy for controlling data replacement in the buffer, and an index-based fully associative data block search strategy; The secure state stores metadata needed to execute the secure replacement strategy in the data hiding buffer. The secure placement and replacement strategies are used when cache line eviction occurs in the last-level cache, and the fully associative data block search strategy is used when accessing the data hiding buffer in the event of a last-level cache miss. The metadata records the owner information of each data block when it is first cached in the data hiding buffer, the number of data blocks already owned by each CPU core in the data hiding buffer, and the maximum number of data blocks that each CPU core can own in the data hiding buffer. The owner information indicates which CPU cores own a data block cached in the data hiding buffer, specifically including the sharer information and evictee information of the data block. The sharer information indicates which private caches have previously contained copies of the data block, and the evictee information indicates which CPU core has previously evicted the data block.
2. The cache side channel attack defense method based on data hiding according to claim 1, characterized in that: When a cache line is evicted from the last-level cache, a method for obtaining the sharer information is selected according to the reason why the last-level cache line is evicted, and the sharer information is obtained; The obtained sharer information is first transmitted to the secure placement strategy of the data hiding buffer, which is used to filter out data blocks that meet the conditions for adding them into the data hiding buffer; Before the filtered data blocks are finally placed into the data hiding buffer, if the number of data blocks owned by a CPU core reaches the maximum value or the physical space in the data hiding buffer is insufficient, the security replacement strategy will be triggered.
3. The cache side channel attack defense method based on data hiding according to claim 2, characterized in that: The specific method for obtaining the sharer information is as follows: If a cache line is evicted by a flush instruction, each private cache will be asked in turn whether it has a copy of the cache line to obtain the sharer information of the cache line; if the cache line is replaced because the last-level cache is full, the acquisition of the sharer information will be embedded in the backward abolition process of the last-level cache.
4. The cache side channel attack defense method based on data hiding according to claim 3 is characterized in that: The specific process of obtaining sharer information is as follows: When a replacement occurs in the last-level cache, a backward invalidation command is sent to the CPU core listed in the directory. If the cache controller finds that the data block requested by the backward invalidation command exists in the private cache, it will reply with a data presence signal to the last-level cache. Conversely, if the requested data block does not exist in the private cache, the cache controller will reply with a data absence signal. The last-level cache controller will summarize the received return signals and eventually obtain the accurate sharer information of the replaced cache line.
5. The cache side channel attack defense method based on data hiding according to claim 2, characterized in that: The secure placement policy defines two filtering conditions. Data blocks that meet any of the filtering conditions will be added to the data hiding buffer. Otherwise, the process of adding data blocks to the data hiding buffer will be terminated. The two filtering conditions defined are: The first condition is that a cache line is evicted from the last-level cache when a copy exists in one or more private caches. The second condition is that a cache line in the last-level cache is replaced by a block from the data hiding buffer.
6. The cache side channel attack defense method based on data hiding according to claim 5, characterized in that: Data blocks that pass the safe placement policy will be owned by their evictee information and sharer information.
7. The cache side channel attack defense method based on data hiding according to claim 2, characterized in that: The process of the safe replacement policy is as follows: If the number of data blocks owned by a CPU core reaches the maximum value, the ownership release routine is called to handle it. For those cores whose data block counts are about to exceed the maximum value, the routine randomly selects one of the data blocks owned by these cores in turn to release the ownership of one of the data blocks owned by the core, and the corresponding data block count value is reduced by 1; If the physical space in the data hiding buffer is insufficient, the security eviction routine is called to handle the problem. The routine randomly selects a data block that is not owned by the CPU core in the data hiding buffer to replace it. The replaced data block will be essentially expelled from the data hiding buffer, and its corresponding security status in the data hiding buffer will also be cleared; After the above two routines are executed, the data block will be added to the data hiding buffer.
8. The cache side channel attack defense method based on data hiding according to claim 2, characterized in that: When the last-level cache access is missed, the data request will be routed to the data hiding buffer for processing, and the search speed of data blocks in the data hiding buffer will be accelerated through the index-based fully associative data block search strategy.
9. The cache side channel attack defense method based on data hiding according to claim 8, characterized in that: The fully associative data block search strategy is specifically as follows: The data blocks and security states in the data hiding buffer are organized in a fully associative manner and implemented using an SRAM array. A lookup table is designed for the data hiding buffer to convert the physical address of a data request into the index number of the corresponding data block in the data hiding buffer. The steps for accessing the data hiding buffer request command lookup are as follows: (1) Extract the physical address in the data request and send it to the lookup table; (2) If the physical address does not exist in the lookup table, the search ends; if the physical address does exist in the lookup table, the index number of the corresponding data block is obtained; (3) The data hiding buffer controller uses the index number to access the data block and security status.
Citation Information
Patent Citations
Method and apparatus for improving computer cache performance and for protecting memory systems against some side channel attacks
US20120297110A1
Device, method and system to supplement a skewed cache with a victim cache
US20220200783A1