Cache row rollback-based processor architecture optimization method free from side channel attack
By introducing monitoring units and cache line rollback mechanisms into the processor, the problem of high performance overhead for existing processors when defending against side channel attacks is solved, and efficient side channel attack defense is achieved, and specific compiler support is not dependent on.
Patent Information
- Application Number
- CN202510231165.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-27
AI Technical Summary
Existing processors have high performance overhead when defending against side channel attacks, and existing optimization solutions require specific compiler support and ignore security within the same process.
By introducing a monitoring unit into the processor, the predicted results of the branch instructions are tracked and the memory fetch instructions in the speculative execution state are marked. When the cache misses, the detailed information of the replaced cache line is recorded, and a Rollback or Commit signal is issued based on the consistency of the predicted results of the branch instruction and the actual execution results, and the rollback or commit operation of the cache line is triggered.
Effective defense against side channel attacks, such as Spectre, reduces performance overhead, does not rely on specific compiler support, and enhances processor security.
Smart Images

Figure CN120217370A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the technical field of computer system security, and in particular, to a method for optimizing a processor architecture against side-channel attacks based on cache line rollback. Background Art
[0002] Since the open source release of the RISC-V instruction set architecture, high-performance processors based on the RISC-V architecture have been widely used in many industries such as the Internet of Things. However, the Spectre attack disclosed in 2018 exploited the inherent logical defects of the processor microarchitecture and hit many high-performance processors including RISC-V in terms of security. Compared with processors of the X86 and ARM architectures, the number of optimization solutions for the RISC-V platform is rarely reported. In addition, the existing optimization solutions also have deficiencies: the solutions for creating a trusted execution environment ignore the security within the same process, the solutions for optimizing the instruction set architecture require a specific compiler to support, and monitoring the instruction flow through software programs has too large a performance overhead on the processor. With the emergence of more and more Spectre-like attack variants, a hardware solution that balances performance and area has important research significance.
[0003] In the existing technology solutions, when dealing with speculative execution, global or local barrier instructions are usually used to prevent speculative execution, and these methods have a large overhead in terms of performance; the methods that rely on software patches to defend against side-channel attacks usually require the support of a specific compiler; while improving security, the performance of the processor is sacrificed, resulting in a decrease in the overall system efficiency.
[0004] Therefore, it is necessary to improve one or more problems existing in the above-mentioned related technical solutions.
[0005] It should be noted that this part aims to provide background or context for the technical solutions of the present disclosure stated in the claims. The description herein is not admitted to be prior art merely because it is included in this part. Summary of the Invention
[0006] The purpose of the embodiments of the present disclosure is to provide a method for optimizing a processor architecture against side-channel attacks based on cache line rollback, thereby at least to some extent overcoming one or more problems caused by the limitations and defects of the related technology.
[0007] According to the embodiments of the present disclosure, there is provided a method for optimizing a processor architecture against side-channel attacks based on cache line rollback, the method comprising: The monitoring unit tracks the prediction results of branch instructions through the internal bus of the processor and marks the memory access instructions in the speculative execution state; wherein, the monitoring unit includes an LSU module, a CAM module, a Cache module, and a Line Buffer module; When a memory access instruction in the speculative execution state accesses the data cache D-Cache and a cache miss occurs, record the detailed information of the replaced cache line into the Line Buffer module; After the branch instruction is executed, according to the consistency between the predicted result and the actual execution result of the branch instruction, the monitoring unit sends a Rollback signal or a Commit signal to the data cache D-Cache; If the Rollback signal is received, according to the information recorded in the Line Buffer module, perform a cache line rollback operation, roll back the replaced cache line to its original position, and restore the data and metadata; if the Commit signal is received, perform a commit operation and clear the corresponding recorded information in the Line Buffer module; among them, through the cache line rollback operation or the commit operation, eliminate the cache state change caused by speculative execution, thereby defending against side-channel attacks.
[0008] Furthermore, the entry structure of the Line Buffer module includes: Valid field, used to mark the validity of the entry information; dirty field, used to indicate whether the original cache line is in a modified state; Set and way fields, used to record the position of the replaced cache line in the data cache D-Cache; inst field, used to associate the memory access instruction that triggers the cache replacement and its branch prediction information; Cache Line field, used to store the complete data block of the replaced cache line.
[0009] Furthermore, the detailed information includes the position set and way of the replaced cache line, the data block Cache Line, the branch information inst, the validity flag Valid, and the dirty data flag dirty.
[0010] Furthermore, the method further includes: Establish an association relationship between the branch instruction and the memory access instruction in speculative execution, and cancel the association information after the branch instruction is executed.
[0011] Furthermore, the triggering condition of the Rollback signal is that the result of the branch prediction is a failure, and the triggering condition of the Commit signal is that the result of the branch prediction is a success; The Rollback signal and the Commit signal are generated by the processor's LSU module and transmitted to the D-Cache.
[0012] Furthermore, the cache line rollback operation includes: Locate the original position of the replaced cache line according to the set and way fields; If the dirty field is in a valid state, write the data in the Cache Line field back to the main memory; Overwrite the data of the replaced cache line on the current cache line and restore it to the state before branch prediction.
[0013] Furthermore, the cache line rollback operation is an atomic operation to ensure that the cache coherence protocol is not damaged.
[0014] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects: In the embodiments of the present disclosure, through the above-mentioned processor architecture optimization method for protecting against side-channel attacks based on cache line rollback, on the one hand, an instruction correlation between branches and memory accesses is established in the monitoring unit of the processor for branch registration. Check whether the speculative execution of the memory access instruction is consistent with the actual result; issue a Rollback or Commit signal according to the result of branch prediction and the actual result of branch jump to trigger the rollback or commit operation of the cache line. On the other hand, when the memory access instruction is in a speculative execution state and a Cache miss occurs, record the detailed information of the replaced cache line in the Line Buffer, including the cache line position, data, and branch information of the memory access instruction. On the third hand, when receiving the Rollback signal, use the information stored in the Line Buffer to restore the cache line to the state before branch prediction, including restoring the cache line replaced by the speculatively executed instruction to its original position and restoring its data; when receiving the Commit signal, confirm that the previous speculative execution is correct, and the corresponding cache line can continue to be retained or updated, thereby effectively defending against side-channel attacks such as Spectre. Fourthly, the monitoring unit design integrated in the processor, the additional tag bit design, and the mechanism for quickly identifying and restoring the cache line. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0016] Figure 1 A step diagram showing a processor architecture optimization method for protecting against side-channel attacks based on cache line rollback in an exemplary embodiment of the present disclosure; Figure 2 A schematic structural diagram showing a monitoring unit in an exemplary embodiment of the present disclosure; Figure 3Schematic diagram showing the position of the monitoring unit in the processor in an exemplary embodiment of the present disclosure; Figure 4 Flowchart of the branch registration of the LSU module in the monitoring unit in an exemplary embodiment of the present disclosure; Figure 5 Flowchart of the Cache miss determination in an exemplary embodiment of the present disclosure; Figure 6 Schematic diagram of the Line buffer entry information in the monitoring unit in an exemplary embodiment of the present disclosure; Figure 7 Flowchart of the information rollback of the D-cache through the line buffer in the monitoring unit in an exemplary embodiment of the present disclosure; Figure 8 Optimized architecture based on the BOOM cache system in an exemplary embodiment of the present disclosure Figure 1 ; Figure 9 Optimized architecture based on the BOOM cache system in an exemplary embodiment of the present disclosure Figure 2 . Detailed implementation manners
[0017] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.
[0018] In addition, the accompanying drawings are only schematic illustrations of the embodiments of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities.
[0019] In this example embodiment, an optimization method for a processor architecture against side-channel attacks based on cache line rollback is provided. As shown in Figure 1 , the optimization method for the processor architecture against side-channel attacks based on cache line rollback may include: step S101 to step S104.
[0020] Step S101: The monitoring unit tracks the prediction result of the branch instruction through the internal bus of the processor and marks the memory access instructions in the speculative execution state; wherein, the monitoring unit includes an LSU module, a CAM module, a Cache module, and a Line Buffer module; Step S102: When a memory access instruction in the speculative execution state accesses the data cache D-Cache and a cache miss occurs, record the detailed information of the replaced cache line into the Line Buffer module; Step S103: After the branch instruction is executed, according to the consistency between the predicted result and the actual execution result of the branch instruction, the monitoring unit sends a Rollback signal or a Commit signal to the data cache D-Cache; Step S104: If the Rollback signal is received, perform a cache line rollback operation according to the information recorded in the Line Buffer module, roll back the replaced cache line to its original position, and restore the data and metadata; if the Commit signal is received, perform a commit operation and clear the corresponding recorded information in the Line Buffer module; among them, through the cache line rollback operation or the commit operation, eliminate the cache state change caused by speculative execution, so as to defend against side-channel attacks.
[0021] Through the above processor architecture optimization method for protecting against side-channel attacks based on cache line rollback, on the one hand, establish the instruction correlation between branches and memory accesses in the monitoring unit of the processor, and perform branch registration. Check whether the speculative execution of the memory access instruction is consistent with the actual result; issue a Rollback or Commit signal according to the result of the branch prediction and the actual result of the branch jump to trigger the rollback or commit operation of the cache line. On the other hand, when the memory access instruction is in the speculative execution state and a Cache miss occurs, record the detailed information of the replaced cache line in the Line Buffer, including the cache line position, data, and the branch information of the memory access instruction. On the third hand, when the Rollback signal is received, use the information stored in the LineBuffer to restore the cache line to the state before the branch prediction, including restoring the cache line replaced by the speculatively executed instruction to its original position and restoring its data; when the Commit signal is received, confirm that the previous speculative execution is correct, and the corresponding cache line can continue to be retained or updated, thus effectively defending against side-channel attacks such as Spectre. On the fourth hand, the design of the monitoring unit integrated in the processor, the design of additional tag bits, and the mechanism for quickly identifying and restoring cache lines.
[0022] Next, with reference to Figures 1 to 9 Each step of the above processor architecture optimization method for protecting against side-channel attacks based on cache line rollback in the present exemplary embodiment will be described in more detail.
[0023] In one embodiment, the present application aims to introduce a cache line rollback mechanism through the memory access path at the processor hardware level to effectively defend against side-channel attacks such as Spectre, while maintaining processor performance, reducing the performance overhead brought by security protection measures, and reducing the dependence on additional storage resources.
[0024] 1. Technical solutions adopted by the present application The present application integrates a dedicated monitoring unit in the processor, such as Figure 2 and Figure 3 As shown, it contains various small modules such as LSU, CAM, Cache, and Line_buffer. The monitoring unit is one of the core components of the present application. It integrates multiple small modules, such as LSU, CAM, Cache, and Line Buffer. The monitoring unit tracks the results of branch prediction through the internal bus of the processor, records all memory access instructions under speculative execution, as well as the replaced line and its position of the cache line replacement caused by Cache miss. After the branch instruction ends, the monitoring unit cancels the registered branch. If the speculative execution fails, the monitoring unit rolls back the replaced line to its original cache position.
[0025] Line Buffer is an important module in the monitoring unit, which is used to record the detailed information of the replaced cache line. The Line Buffer entry information includes a Valid field, a dirty field, set and way fields, an inst field, and a Cache Line field. Among them, the Valid field stores the validity of the entry information; the dirty field stores whether the original Cache Line is a non-empty cache line; the set and way fields store the position of the original Cache Line in the D-Cache; the inst field stores the branch correlation of the memory access instruction that causes Cache miss; and the Cache Line stores the Victim Cache Line itself.
[0026] The monitoring unit tracks the results of branch prediction (i.e., branch registration) through the internal bus of the processor, such as TileLink; records all memory access instructions under speculative execution; records the replaced line and its position of the cache line replacement caused by Cache miss; cancels the registered branch after the branch instruction ends; and if the speculative execution fails, rolls back the replaced line to its original cache position.
[0027] When the CPU executes a branch jump instruction, the branch predictor will speculate on the execution result of the instruction branch jump instruction. Whether the actual execution result of the branch jump instruction is consistent with the predicted result is the key to determining whether to trigger the security mechanism. If they are consistent, the processor normally executes the subsequent instructions; if they are inconsistent, the processor rolls back and triggers the security mechanism.
[0028] The monitoring unit issues a rollback signal to the D-Cache, and the D-Cache retrieves all the replaced cache lines generated by the memory access instructions under speculative execution. The memory access instructions under speculative execution are registered in the monitoring unit, recording this instruction and the branch jump instruction that triggered the execution of this instruction. After the cache line is rolled back, the monitoring unit cancels these rolled-back memory access instructions and restores the processor state.
[0029] When the monitoring unit issues a commit signal to the D-Cache, the monitoring unit cancels the committed memory access instructions, and the D-Cache removes the replaced cache lines generated by the memory access instructions under the branch jump instruction.
[0030] 1.1 Branch Registration and Information Recording Instruction correlations between branches and memory accesses are established in the monitoring unit of the processor. Specifically, dedicated logic is added to the monitoring unit of the processor to mark whether each memory access instruction is under speculative execution. This is achieved by tracking the results of branch predictions. If a branch prediction is marked as speculative execution, then subsequent memory access instructions will also be marked accordingly.
[0031] There are two queues in the LSU in the monitoring unit, which are respectively used to store information about load instructions store and memory access load instructions under speculative execution, and issue a commit / rollback indication signal to the D-Cache after the branch jump instruction is executed; as Figure 4 shown, it is the branch registration flowchart of the LSU module in the monitoring unit.
[0032] When the current memory access operation is under speculative execution, it is judged whether the address of the current memory access causes a Cache miss in the D-Cache. If the above is true, then enter the subsequent steps; otherwise, the current memory access operation will not leak information and will not enter the subsequent steps. As Figure 5 shown, it is the Cache miss judgment flowchart.
[0033] The LSU stores the branch correlations of the memory access instructions under speculative execution. After the branch instruction is executed, the LSU will issue a Rollback / Commit (R / C) doorbell signal to initiate the recovery / commit operation; The module name of the replaced line stored in the monitoring unit is Line Buffer. All entries in the Line Buffer need to listen for this signal for matching and perform corresponding rollback / delete operations.
[0034] 1.2 Line buffer Cache Line Rollback The Line Buffer in the monitoring unit records the detailed information of the replaced cache line, specifically: The Line Buffer entry information includes a Valid field, a dirty field, set and way fields, an inst field, and a Cache Line field. The Valid field stores the validity of the entry information; the dirty field stores whether the original Cache Line is a non-empty cache line; the set and way fields store the position of the original Cache Line in the D-Cache; the inst field stores the branch correlation of the memory access instruction that causes a Cache miss; and the Cache Line stores the Victim Cache Line itself. As Figure 6 shown, it is the Line buffer entry information in the monitoring unit.
[0035] An additional tag bit (valid) is added to each cache line to indicate whether the line is affected by a speculated instruction (inst), and the states before and after the operation (dirty) are recorded, the cache line (Cache line) that needs to be rolled back, and the position of the cache line (set, way). After receiving the doorbell signal sent by the monitoring module LSU, the D-Cache finally restores the cache line to the state before prediction through this information in the Line buffer. When the processor memory access instruction accesses the D-Cache, it first determines whether the D-Cache hits. If it hits, the cache is updated; if it does not hit, the replaced cache line is selected. Then, it is determined whether the memory access instruction is speculated execution. If it is not speculated execution, the relevant information is not recorded; if it is speculated execution, the position and data block of the replaced cache line are recorded.
[0036] After the speculated execution is completed, it is determined whether the speculation is correct. If the speculation is correct, a Commit signal is received, and the relevant replaced cache in the LineBuffer is cleared; if the speculation is incorrect, a Rollback signal is received, and the relevant replaced cache in the Line Buffer starts to roll back. The position of the cache line is determined according to the set and way in the Line Buffer entry, and the state of the cache line is determined by the dirty signal. Finally, the Cache Line is overwritten, so that the cache line is restored to the state before prediction. As Figure 7 shown, it is the flowchart of the D-cache in the monitoring unit rolling back through the information of the line buffer In a specific embodiment, to enable those skilled in the art to better understand the present application, the detailed process is summarized below, and a detailed example and a detailed description are given in combination with the specific implementation manner to further elaborate on the present application.
[0037] It should be noted that: The examples to be introduced next are only some specific examples, and do not limit that the embodiments of this application must be the following specific steps, numerical values, conditions, data, order, etc. Those skilled in the art can use the concept of this application by reading this specification to construct more embodiments not mentioned in this specification.
[0038] Referring to the following detailed process, steps 1 to 13 of a processor architecture optimization method for protecting against side-channel attacks based on cache line rollback provided by this application are respectively: Detailed process description Step 1. The processor memory access instruction accesses the D-Cache When the processor executes a memory access instruction, it first accesses the D-Cache. The D-Cache is the data cache in the processor, which is used to store the recently accessed data to improve the data access speed. The memory access instruction can be a load instruction or a store instruction, and the target of these instructions is to read or write data in the memory.
[0039] Step 2. Whether the D-Cache hits When the memory access instruction accesses the D-Cache, it is first necessary to determine whether the D-Cache hits. A D-Cache hit means that the required data is already in the cache and can be directly accessed without accessing the main memory, and does not enter the subsequent steps. A D-Cache miss means that the required data is not in the cache and the data needs to be loaded from the main memory.
[0040] Step 3. Update the cache and select the cache line to be replaced If the D-Cache hits, the processor can directly update the data in the cache. If the D-Cache misses, the processor needs to load the data from the main memory and put it into the D-Cache. When loading new data, it may be necessary to replace the old data in the cache. At this time, the cache line to be replaced needs to be selected.
[0041] Step 4. Whether the memory access instruction is speculative execution When the D-Cache misses and a cache line needs to be replaced, it is necessary to determine whether the current memory access instruction is speculative execution. Speculative execution is a performance optimization technique in modern processors that allows the processor to execute instructions in advance based on branch prediction. If the memory access instruction is not speculative execution, it does not enter the subsequent steps. If the memory access instruction is speculative execution, then the detailed information of the cache line to be replaced needs to be recorded for subsequent rollback operations.
[0042] Step 5. Record the position and data block of the cache line to be replaced If the memory access instruction is speculatively executed, the Line Buffer will record the detailed information of the replaced cache line. This information includes the position of the cache line (set and way), the data block (Cache Line), and the branch information (inst) related to the memory access instruction. This information will be used for subsequent cache line rollback operations.
[0043] Step 6. Whether the speculative execution is correct After the memory access instruction is executed, it is necessary to determine whether the speculative execution is correct. By comparing the result of branch prediction with the actual execution result. If the speculative execution is correct, then the cache line can be continued to be retained or updated, and proceed to Step 9. If the speculative execution is incorrect, a rollback operation needs to be triggered, and proceed to Step 7.
[0044] Step 8. Receive the Rollback signal If the speculative execution is incorrect, the monitoring unit will issue a Rollback signal. The Rollback signal notifies the D-Cache that it needs to roll back the cache line and restore it to the state before branch prediction.
[0045] Step 8. The relevant replaced cache in the Line Buffer starts to roll back After receiving the Rollback signal, the replaced cache line recorded in the Line Buffer starts the rollback operation. The purpose of the rollback operation is to restore the cache line to the state before branch prediction, including restoring the cache line replaced by the speculatively executed instruction to its original position and restoring its data, and then proceed to Step 11.
[0046] Step 9. Receive the Commit signal If the speculative execution is correct, the monitoring unit will issue a Commit signal. The Commit signal notifies the D-Cache that it can continue to retain or update the cache line, confirming that the previous speculative execution is correct.
[0047] Step 10. Clear the relevant replaced cache in the Line Buffer After receiving the Commit signal, the replaced cache line recorded in the Line Buffer will be cleared. This indicates that the state of the cache line has been confirmed and no rollback operation is required. Do not proceed to the subsequent steps.
[0048] Step 11. Determine the cache line position according to the set and way in the Line Buffer entry In the rollback or commit operation, it is necessary to determine the position of the cache line according to the set and way fields in the Line Buffer entry. The set and way fields store the specific position of the cache line in the D-Cache, which helps to accurately locate and operate on the cache line.
[0049] Step 12. Determine the cache line status using the dirty signal The dirty field is used to determine the status of the cache line. If the dirty field is 1, it indicates that the data in the cache line has been modified and needs to be written back to the main memory. If the dirty field is 0, it means the data in the cache line has not been modified and can be directly discarded or replaced.
[0050] Step 13. Finally, overwrite the Cache Line In the rollback operation, according to the Cache Line field in the Line Buffer entry, the replaced cache line is restored to its original position and overwrites the original data. This ensures that the status of the cache line is restored to the state before branch prediction, thus preventing side-channel attacks.
[0051] Detailed process example Example 1: D-Cache hit and the memory access instruction is non-speculative execution (non-aggressive) 1. The processor's memory access instruction accesses the D-Cache: The processor executes a load instruction with an access address of 0x1000.
[0052] 2. Does the D-Cache hit? The D-Cache hits, and the required data is already in the cache.
[0053] 3. Update the cache: The processor directly reads the data from the D-Cache without accessing the main memory.
[0054] 4. Is the memory access instruction speculative execution? This memory access instruction is not speculative execution.
[0055] 5. Record the position and data block of the replaced cache line: Not applicable because this memory access instruction is not speculative execution.
[0056] 6. Is the speculative execution correctly speculated? Not applicable because this memory access instruction is not speculative execution.
[0057] 7. Receive the Rollback signal: Not applicable because this memory access instruction is not speculative execution.
[0058] 8. The relevant replaced cache in the Line Buffer starts to roll back: Not applicable because this memory access instruction is not speculative execution.
[0059] 9. Receive the Commit signal: Not applicable because this memory access instruction is not speculative execution.
[0060] 10. Clear the relevant replaced cache in the Line Buffer: Not applicable because this memory access instruction is not speculative execution.
[0061] 11. Determine the cache line position according to the set and way in the Line Buffer entry: Not applicable because the memory access instruction is not speculative execution.
[0062] 12. Determine the cache line status by the dirty signal: Not applicable because the memory access instruction is not speculative execution.
[0063] 13. Finally, overwrite the Cache Line: Not applicable because the memory access instruction is not speculative execution.
[0064] Example 2: D-Cache hit and the memory access instruction is speculative execution (non-aggressive) 1. The processor's memory access instruction accesses the D-Cache: The processor executes a load instruction with an access address of 0x1000.
[0065] 2. Whether the D-Cache hits: The D-Cache hits and the required data is already in the cache.
[0066] 3. Update the cache: The processor directly reads the data from the D-Cache without accessing the main memory.
[0067] 4. Whether the memory access instruction is speculative execution: The memory access instruction is speculative execution.
[0068] 5. Record the position and data block of the replaced cache line: Not applicable because the D-Cache hits and there is no replaced line.
[0069] 6. Whether the speculative execution is correctly speculated: Not applicable because the D-Cache hits and there is no replaced line.
[0070] 7. Receive the Rollback signal: Not applicable because the D-Cache hits and there is no replaced line.
[0071] 8. The relevant replaced cache in the Line Buffer starts to roll back: Not applicable because the D-Cache hits and there is no replaced line.
[0072] 9. Receive the Commit signal: Not applicable because the D-Cache hits and there is no replaced line.
[0073] 10. Clear the relevant replaced cache in the Line Buffer: Not applicable because the D-Cache hits and there is no replaced line.
[0074] 11. Determine the cache line position according to the set and way in the Line Buffer entry: Not applicable because the D-Cache hits and there is no replaced line.
[0075] 12. The dirty signal determines the cache line status: Not applicable because there is no replaced line in the D-Cache hit.
[0076] 13. Finally, overwrite the cache line: Not applicable because there is no replaced line in the D-Cache hit.
[0077] Example 3: D-Cache miss and the memory access instruction is speculative execution, speculative execution error (aggressive) 1. The processor's memory access instruction accesses the D-Cache: The processor executes a load instruction with an access address of 0x2000.
[0078] 2. Does the D-Cache hit? The D-Cache misses, and the required data is not in the cache.
[0079] 3. Update the cache and select the replaced cache line: The processor loads data from the main memory and places it in the D-Cache. When loading new data, the old data in the cache needs to be replaced, and the replaced cache line is selected.
[0080] 4. Is the memory access instruction speculative execution? This memory access instruction is speculative execution.
[0081] 5. Record the location and data block of the replaced cache line: The Line Buffer records the detailed information of the replaced cache line, including the location of the cache line (set and way), the data block (Cache Line), and the branch information (inst) related to this memory access instruction.
[0082] 6. Is the speculative execution correct? After the memory access instruction is executed, it is necessary to determine whether the speculative execution is correct. Assume that the speculative execution is incorrect.
[0083] 7. Receive the Rollback signal: The monitoring unit issues the Rollback signal, notifying the D-Cache that it needs to roll back the cache line and restore it to the state before branch prediction.
[0084] 8. The relevant replaced cache in the Line Buffer starts to roll back: The replaced cache line recorded in the Line Buffer starts the rollback operation. The purpose of the rollback operation is to restore the cache line to the state before branch prediction, including restoring the cache line replaced by the speculatively executed instruction to its original position and restoring its data.
[0085] 9. Receive the Commit signal: Not applicable because the speculative execution is incorrect.
[0086] 10. Clear the relevant replaced cache in the Line Buffer: Not applicable because the speculative execution is incorrect.
[0087] 11. Determine the cache line position according to the set and way in the Line Buffer entry: In the rollback operation, determine the position of the cache line according to the set and way fields in the LineBuffer entry. The set and way fields store the specific position of the cache line in the D-Cache, which helps to accurately locate and operate on the cache line.
[0088] 12. The dirty signal determines the cache line status: The dirty field is used to determine the status of the cache line. If the dirty field is 1, it means that the data in the cache line has been modified and needs to be written back to the main memory. If the dirty field is 0, it means that the data in the cache line has not been modified and can be directly discarded or replaced.
[0089] 13. Finally, overwrite the Cache Line: In the rollback operation, according to the CacheLine field in the Line Buffer entry, restore the replaced cache line to its original position and overwrite the original data. This ensures that the status of the cache line is restored to the state before branch prediction, thus preventing side-channel attacks.
[0090] Example 4: D-Cache miss and the memory access instruction is speculatively executed, and the speculative execution is correct (non-aggressive) 1. The processor's memory access instruction accesses the D-Cache: The processor executes a load instruction to access the address 0x3000.
[0091] 2. Whether the D-Cache is hit: The D-Cache misses, and the required data is not in the cache.
[0092] 3. Update the cache and select the replaced cache line: The processor loads data from the main memory and puts it into the D-Cache. When loading new data, it is necessary to replace the old data in the cache and select the replaced cache line.
[0093] 4. Whether the memory access instruction is speculatively executed: This memory access instruction is speculatively executed.
[0094] 5. Record the position and data block of the replaced cache line: The Line Buffer records the detailed information of the replaced cache line, including the position of the cache line (set and way), the data block (Cache Line), and the branch information (inst) related to this memory access instruction.
[0095] 6. Whether the speculative execution is correct: After the memory access instruction is executed, it is necessary to determine whether the speculative execution is correct. Assume that the speculative execution is correct.
[0096] 7. Receive the Rollback signal: Not applicable because the speculative execution is correct.
[0097] 8. Rollback of the relevant replaced cache in the Line Buffer: Not applicable because speculative execution is correct.
[0098] 9. Receiving the Commit signal: The monitoring unit issues the Commit signal to notify the D-Cache that it can continue to retain or update the cache line, confirming that the previous speculative execution was correct.
[0099] 10. Clearing the relevant replaced cache in the Line Buffer: The replaced cache line recorded in the Line Buffer is cleared. This indicates that the status of the cache line has been confirmed and no rollback operation is required.
[0100] 11. Determining the cache line position based on the set and way in the Line Buffer entry: Not applicable because speculative execution is correct.
[0101] 12. Determining the cache line status using the dirty signal: Not applicable because speculative execution is correct.
[0102] 13. Finally, overwriting the Cache Line: Not applicable because speculative execution is correct.
[0103] In a specific embodiment, as Figure 8 shown, it is an optimized architecture based on the BOOM cache system Figure 1 ; Figure 8 uses priority sorting to perform read-write conflict and priority judgment on rollback requests and normal memory access requests, and is suitable for superscalar memory access structures. Figure 9 dedicates one read-write port of the D-Cache to rollback and the other read-write port to normal memory access, which is more suitable for single-issue memory access structures. As Figure 9 shown, it is an optimized architecture based on the BOOM cache system Figure 2 . Figure 9 dedicates one read-write port of the D-Cache to rollback and the other read-write port to normal memory access, which is more suitable for single-issue memory access structures.
[0104] The effects of this application can be further illustrated by the following simulation experiments.
[0105] Simulation conditions: This application is simulated on the Chipyard platform with a central processing unit of BOOM (Berkeley Out-of-Order Machine) and an Ubuntu 16.04 operating system. The attack function is written in C language referring to the Spectre literature.
[0106] Simulation content: As described in the specific implementation manner of the present application, the Spectre attack function is executed to prove the effectiveness of the attack function on the processor before optimization. Then, the two schemes are respectively deployed on the BOOM processor and compared with the performance overhead of the BOOM processor before optimization. The results are shown in Table 1.
[0107] Table 1 Execution Results of Spectre Attack Function
[0108] The performance overhead brought by the present application is 2.5%, which is better than the similar scheme InvisiSpec. The additional introduction of 3.1% of hardware resources on the D-Cache is also less than that of InvisiSpec. It can be seen that the scheme of the present application has the security indicators of similar schemes in terms of security, and the scheme of this article has advantages after considering the comprehensive performance and hardware resource consumption.
[0109] Through the above-mentioned method for optimizing the processor architecture against side-channel attacks based on cache line rollback, the present application introduces a cache line rollback mechanism and adds dedicated logic in the memory access unit (LSU) of the processor to mark whether each memory access instruction is in the speculative execution state. This is achieved by tracking the results of branch prediction. If a branch prediction is marked as speculative execution, subsequent memory access instructions will also be marked accordingly. For memory access instructions in the speculative execution state, when they access the cache and a Cache miss occurs, detailed information about these operations will be recorded in the Line Buffer, including but not limited to: the original cache line position (set and way), the data and metadata of the cache line (data and meta), and the branch information of the instruction to associate the memory access operation with its branch prediction result. Once the result of the branch prediction is confirmed (i.e., after the branch instruction is actually executed), the LSU will issue a Rollback or Commit signal according to the correctness of the branch prediction. If the branch prediction fails (i.e., a misprediction occurs), the LSU issues a Rollback signal to trigger the cache line rollback operation. If the branch prediction is successful, the LSU issues a Commit signal to confirm that the previous speculative execution is correct, and the corresponding cache line can continue to be retained or updated. After receiving the Rollback signal, the cache line information stored in the Line Buffer is used to restore the cache state to the exact state before the branch prediction. Specifically, the cache line replaced by the instruction that was previously speculatively executed is restored to its original position, and its data and metadata are restored. This process is atomic, ensuring the cache consistency and system stability.
[0110] This application provides a solution at the pure hardware level, aiming to optimize the memory access path of the processor. Since the memory access paths of various instruction set architectures are basically similar, it does not need to rely on specific software or compiler support, and can provide consistent protection across different processor instruction set architectures, enhancing generality and security. Specifically, this application integrates a dedicated monitoring unit in the processor to track the results of branch prediction and mark all subsequent instructions that depend on this prediction. At the same time, for each cache line, additional tag bits are added to indicate whether the line is affected by speculatively executed instructions, and the states before and after the operation are recorded, so that after the branch prediction result is confirmed, the cache lines that need to be rolled back can be quickly identified and the cache lines can be quickly restored to the state before the prediction. This design allows the processor to obtain protection through a unified hardware interface when facing side-channel attacks, reduces the dependence on software and instruction set architectures, improves the compatibility and efficiency of the solution, and at the same time ensures that the processor performance is not affected too much.
[0111] This application has a unique cache line management mechanism that can effectively defend against Spectre attacks without sacrificing processor performance. Specifically, this application realizes precise control of cache lines by introducing a novel cache line recording and recovery strategy in the cache system of the processor. In this strategy, whenever a cache line is evicted due to a new data access, the system not only saves the data of the cache line, but also records its original position and coherence state. This record includes the set and way information where the cache line is located, as well as the relevant state tags under the cache coherence protocol. When the processor completes the verification of a branch prediction and finds that the previous speculative execution was based on an incorrect prediction, the mechanism of this application will trigger a cache line rollback operation. This operation uses the previously recorded original position and coherence state information to accurately restore the evicted cache line to its original position, and at the same time updates the cache coherence state to ensure the accuracy and consistency of the cache data. This process is completely automated and tightly integrated with the execution pipeline of the processor, thus minimizing the impact on processor performance.
[0112] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example" or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present disclosure. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0113] Other embodiments of the present disclosure will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common general knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.
Claims
1. A method for optimizing processor architecture to avoid side channel attacks based on cache line rollback, characterized in that: The method includes: The monitoring unit tracks the prediction results of branch instructions through the internal bus of the processor and marks the memory access instructions in the speculative execution state; wherein the monitoring unit includes an LSU module, a CAM module, a Cache module, and a Line Buffer module; When a memory access instruction in the speculative execution state accesses the data cache D-Cache and a cache miss occurs, the detailed information of the replaced cache line is recorded to the Line Buffer module; After the branch instruction is executed, the monitoring unit sends a Rollback signal or a Commit signal to the data cache D-Cache according to the consistency between the predicted result and the actual execution result of the branch instruction; If a Rollback signal is received, a cache line rollback operation is performed according to the information recorded in the Line Buffer module, the replaced cache line is rolled back to its original position, and the data and metadata are restored; if a Commit signal is received, a commit operation is performed to clear the corresponding record information in the Line Buffer module; wherein, through the cache line rollback operation or commit operation, the cache state change caused by speculative execution is eliminated, thereby defending against side channel attacks.
2. The method for optimizing processor architecture to avoid side channel attacks based on cache line rollback according to claim 1, characterized in that: The table structure of the Line Buffer module includes: The Valid field is used to mark the validity of the entry information; The dirty field is used to indicate whether the original cache line has been modified; The Set and Way fields are used to record the location of the replaced cache line in the data cache D-Cache; The inst field is used to associate the memory access instruction that triggers cache replacement and its branch prediction information; The Cache Line field is used to store the complete data block of the replaced cache line.
3. The method for optimizing processor architecture to avoid side channel attacks based on cache line rollback according to claim 2, characterized in that: The detailed information includes the location set and way of the replaced cache line, the data block Cache Line, the branch information inst, the validity mark Valid and the dirty data mark dirty.
4. The method for optimizing processor architecture to avoid side channel attacks based on cache line rollback according to claim 3, characterized in that: The method further includes: An association relationship is established between a branch instruction and a speculatively executed memory access instruction, and the association information is cancelled after the branch instruction is executed.
5. The method for optimizing processor architecture to avoid side channel attacks based on cache line rollback according to claim 4, characterized in that: The triggering condition of the Rollback signal is that the result of the branch prediction is a failure, and the triggering condition of the Commit signal is that the result of the branch prediction is a success; The Rollback signal and Commit signal are generated by the LSU module of the processor and transmitted to the D-Cache.
6. The method for optimizing processor architecture to avoid side channel attacks based on cache line rollback according to claim 5, characterized in that: The cache line rollback operation includes: Locate the original location of the replaced cache line based on the set and way fields; If the dirty domain is in a valid state, the data in the Cache Line domain is written back to the main memory; The data of the replaced cache line overwrites the current cache line and restores it to the state before branch prediction.
7. The method for optimizing processor architecture to avoid side channel attacks based on cache line rollback according to claim 6, characterized in that: The cache line rollback operation is an atomic operation, ensuring that the cache coherence protocol is not violated.
Citation Information
Cited By
CPU security defense method and device and electronic equipment
CN121256788A