Generation of the Optimal Program Variant
By generating and analyzing multiple variants of software programs, identifying and hiding or exposing control flow statements using greedy heuristics or genetic algorithms, the balance of data confidentiality and performance in cloud computing is solved, achieving the best trade-off in security and performance.
Patent Information
- Application Number
- CN202011523960.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-06
- Filing Date
- 2020-12-22
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-01-29
AI Technical Summary
The prior art is difficult to effectively balance data confidentiality and computing performance in cloud computing environments, especially in the aspects of side channel leakage and program run time, resulting in high computing costs and security risks.
By generating multiple variants of the software program, identifying and hiding or exposing different sets of sentences within the control flow, using greedy heuristics or genetic algorithms for security and performance trade-off analysis, determine Pareto optimal variants, and output optimal variant information.
It realizes the best tradeoff in security and performance of security and performance in cloud computing environments.
Smart Images

Figure CN113626834B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a computing system, method, and non-transitory computer-readable medium for generating optimal variants of a software program. Background Art
[0002] Cloud services provide on-demand access to cost-effective computing resources such as data storage and computing power. Generally, cloud services are available via a public network. Thus, data in the cloud may be at risk of being stolen by malicious users observing the cloud via side channels. For example, via side channels, unauthorized users (e.g., service providers, other users, etc.) may learn information about data files being stored, usage of the data files, usage of the services, and so on. As another example, a cloud provider may be hacked by malicious users. To ensure data confidentiality, encryption may be applied to the data before it is transferred to the cloud. In such a case, the cloud must operate on the encrypted data to maintain data confidentiality.
[0003] Cryptographic techniques such as Fully Homomorphic Encryption (FHE) support arbitrary computations on data without revealing any information about the data. However, computations on data encrypted by FHE suffer from high computational costs. Additionally, the effort to find a compromise is exponential in the number of control flow decisions. Thus, eliminating all data leakage via side channels increases the running time of the program. On the other hand, a Trusted Execution Environment (TEE) requires little computational overhead but is more vulnerable to side-channel attacks. Adding to the complexity, some applications have policies that require data attributes, variables, decisions, etc. to remain confidential. Summary of the Invention
[0004] Embodiments of the present disclosure are directed to a computing system, including: a storage device configured to store a set of statements within a control flow of a software program; and a processor configured to: generate a plurality of variants of the software program, the plurality of variants respectively including different subsets of statements within the control flow exposed to side channels; determine one or more Pareto optimal variants of the software program based on side-channel leakage values and performance values of the plurality of variants of the software program; and output information about the one or more Pareto optimal variants of the software program to a user device.
[0005] Embodiments of the present disclosure are directed to a method, including: identifying a set of statements within a control flow of a software program; generating a plurality of variants of the software program, the plurality of variants respectively including different subsets of statements of the control flow exposed to a side channel; determining one or more Pareto-optimal variants of the software program based on side-channel leakage values and performance values of the plurality of variants of the software program; and outputting information about the one or more Pareto-optimal variants of the software program to a user device.
[0006] Embodiments of the present disclosure are directed to a non-transitory computer-readable medium including instructions that, when executed by a processor, cause a computer to perform a method, the method including: identifying a set of statements within a control flow of a software program; generating a plurality of variants of the software program, the plurality of variants respectively including different subsets of statements of the control flow exposed to a side channel; determining one or more Pareto-optimal variants of the software program based on side-channel leakage values and performance values of the plurality of variants of the software program; and outputting information about the one or more Pareto-optimal variants of the software program to a user device. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Features and advantages of example embodiments, and ways in which the features and advantages are realized, will become more apparent with reference to the following detailed description in conjunction with the drawings.
[0008] Figure 1 is a diagram showing a computing environment for generating optimal variants of a software program according to an example embodiment.
[0009] Figure 2A is a diagram showing a control flow in which a subset of decisions is hidden from a side channel according to an example embodiment.
[0010] Figure 2B is a diagram showing a process of converting exposed program code to hidden program code according to an example embodiment.
[0011] Figure 3 is a diagram showing a process of performing a security and performance trade-off analysis according to an example embodiment.
[0012] Figures 4A - 4C is a diagram showing a graph of the security and performance of program variants according to an example embodiment.
[0013] Figure 5 is a diagram showing a method for determining one or more optimal variants of a software program according to an example embodiment.
[0014] Figure 6 is a diagram showing a computing system for examples herein according to an example embodiment.
[0015] Throughout the drawings and the detailed description, unless otherwise described, the same reference numerals will be understood to refer to the same elements, features, and structures. The relative sizes of these elements and the depiction thereof may be exaggerated or adjusted for clarity, illustration, and / or convenience. Detailed Description
[0016] In the following description, specific details are set forth in order to provide a thorough understanding of various example embodiments. It should be understood that various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the disclosure. Additionally, in the following description, numerous details are set forth for purposes of explanation. However, those of ordinary skill in the art should understand that the embodiments may be practiced without the use of these specific details. In other instances, well-known structures and processes are not shown or described in order not to obscure the description with unnecessary detail. Accordingly, the disclosure is not intended to be limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.
[0017] Example embodiments are directed to a system that can generate multiple variants of a software program, where the variants have different numbers of hidden (concealed) control flow statements. The system can measure the security (e.g., bit leakage via side channels, etc.) and performance (e.g., program runtime, etc.) of the variants of the software program. Additionally, the system can analyze the variants of the software program and identify one or more optimal variants of the program via a security and performance trade-off analysis. This analysis helps a developer make decisions regarding which statements within the hidden control flow (decisions) and which statements are allowed to be observed via side channels (decisions). Accordingly, the system can provide a set of variants of the program that includes different Pareto-optimal combinations of the security and performance of the software program with different policies, information flows, data, etc.
[0018] The security and performance trade-off analysis can be performed using various algorithms, including greedy heuristic algorithms and genetic algorithms. In some cases, based on user selection, only one algorithm may be used, or two algorithms may be used. The better algorithm may depend on the size of the program, the speed at which the program is to be analyzed, etc. Additionally, a user (developer) can provide a predefined security policy for the software program, which identifies specific variables, statements, etc. that must remain hidden. Variants can be generated and the analysis can be performed based on the predefined security policy.
[0019] For some software programs, meaningful security can only be achieved when all side-channel exposures are eliminated. For example, cryptographic primitives in public-key cryptography (such as the square and multiply algorithm for modular exponentiation) may require this level of security. In such cases, if private key bits are leaked through side channels, all security that depends on the secrecy of the private key is lost.
[0020] A wide class of side channels can be avoided by generating constant-time code based on secret data that does not have memory access or control flow decisions. However, for more complex operations, avoiding memory access or control flow decisions results in suppressed performance gains. For example, Dantzig's simplex algorithm terminates when the objective value of the current solution cannot be improved any further. It is extremely efficient in practice, but its worst-case running time is exponential in the problem size. To eliminate the side channel in this example, the system must also prevent the termination condition from leaking. This essentially creates an exponential gain in running time.
[0021] Due to the prohibitively high cost of running time, in many cases, eliminating all side channels is impractical. Example embodiments provide a mechanism that can generate variants of a software program that include some side-channel leaks and also include some hidden control flow decisions. The system can identify which variants provide an optimal trade-off between security and performance. Thus, the system can automatically select the control flow decisions to hide and the control flow decisions that can be leaked, saving the developer from making this choice manually. Here, based on the number of control flow decisions that can be hidden, the number of variants grows exponentially. Therefore, it is impractical for a human to perform this trade-off analysis. The trade-off analysis can identify one or more variants of the software program that are optimal in terms of both security and performance relative to all variants created by the system.
[0022] Figure 1 A computing environment 100 for generating an optimal variant of a software program 130 according to an example embodiment is shown. Refer to Figure 1, the user can develop a software program 130 via the user device 110 and upload the optimal variant 130K of the software program to the host system 120. Here, the user device 110 may include an Integrated Development Environment (IDE), etc., which allows the user to write / develop the software program 130. In addition, once developed, the user can connect to the host system 120 via a network to upload the executable file of the developed variant 130K of the software program. For example, the user device 110 may be a desktop computer, a laptop, a mobile device, a tablet, a server, etc., which is connected to the host system 120 via a network (such as the Internet). The host system 120 may be a cloud platform, a web server, a database, etc. The software program 130 may be written in a programming language (such as Java, etc.).
[0023] There may be a control flow within the software program 130. The control flow is the order in which the programming statements, instructions, function calls, etc. of the software program 130 are executed or evaluated. There may be various decisions within the control flow. For example, a decision (also known as a transition, etc.) is a programming statement that results in a choice being made as to which of two or more paths to follow within the control flow. Examples of decisions are shown and described with respect to Figure 2B . Some examples of decisions within the control flow include "if" statements, "while" statements, "for" loops, "break" statements, "continue" statements, and other conditions.
[0024] According to various embodiments, the user device 110 may include software tools therein (e.g., embedded within the IDE, etc.), which may perform security and performance trade-off analysis. The software tool may identify a list of decisions within the control flow of the software program 130. Here, the user device 110 may generate multiple variants of the software program 130, where different subsets of decisions are hidden and different subsets are exposed to side channels. The results of these variants are different levels of security and performance. In addition, the software tool may measure the security of each of the variants and measure the performance value (such as runtime) of each of the variants. Then, the software tool may perform a security and performance trade-off analysis, which identifies one or more optimal variants of the software program that include the Pareto optimal values of security and performance.
[0025] In Figure 1In the example, the software tool identifies a subset of variants of software program 130 that have an optimal trade-off between security and performance. In this example, the optimal subset of variants includes variants 130C, 130F, and 130K. The optimal subset of variants 130C, 130F, and 130K may include different trade-offs between security and performance. A user of user device 110 may select which variant (e.g., variant 130K, etc.) to send to host system 120. Although host system 120 is shown separate from user device 110, it should be understood that all features of the example embodiments may be embodied in a single device including logic for performing security and performance trade-off analysis and a user environment for generating software programs. Additionally, it is not necessary for the software tool to be embedded within an IDE. As another example, the software tool may be a stand-alone service or embedded within another software application.
[0026] Figure 2A An example of the control flow of software program 200 in which some of the decisions are hidden from side channels according to an example embodiment is shown. Referring to Figure 2A , software program 200 includes source code having a plurality of decisions 211-219. Decisions 211-219 are program statements at which program choices are made. Each choice may represent a choice between two or more different paths within a software application. In some cases, decisions 211-219 may include variables being operated on. When determining different variants of software program 200, a host system (e.g., Figure 1 host system 120 in ) may selectively obscure / hide various decisions 211-219 of software program 200. For example, decisions 211-219 may include if / then statements, while statements, continue statements, break statements, for loops, etc.
[0027] Each variant of software program 200 may include a different subset of hidden decisions. In the Figure 2A variant of software program 200 shown in, decisions 211, 214, 217, and 218 are hidden, while decisions 212, 213, 215, 216, and 219 are left exposed to side channels. It should be understood that being "exposed" to a side channel does not necessarily mean that the entire decision content is available to the side channel. In some cases, a decision may be represented using a predetermined number of bits (e.g., 64 bits, etc.), and bits may be used to measure leakage. For example, if an observer can determine that a variable is not zero (e.g., it must be greater than or less than zero), this may be referred to as 1 bit of data out of 64 possible bits being exposed to the side channel. The more data of a decision that can be observed / obtained, the more bits are revealed.
[0028] Not all program data is equally sensitive. Thus, revealing data from one decision to a side channel may not be equivalent to revealing data from another decision to a side channel. Additionally, a user may provide a security policy that specifies particular decisions / variables that must remain hidden. The choice of which of decisions 211-219 to hide can be based on the security policy such that each variable satisfies the security policy.
[0029] According to various embodiments, a tradeoff of software program 200 can be determined based on different variants of software program 200 in which different subsets of decisions 211-219 are hidden and different subsets are revealed. Since the number of variants of a software program grows exponentially based on the number of decisions in the control flow, and not all decisions have the same impact on security, it is impractical for a user to make such a choice manually. The analysis performed by the host system described herein helps a developer determine which of decisions 211-219 to reveal and which to hide. In Figure 2A the variant of software program 200 shown in, a security value 222, which represents the amount of bit leakage of that variant of software program 200, can be measured by the host system. Additionally, a performance value 224 represents the runtime of that variant of software program 200. The security value 222 and the performance value 224 will change by changing which of decisions 211-219 are revealed and which are hidden. As further described with reference to Figure 3 the security value 222 and the performance value 224 can be measured using subroutines triggered by the host system during a tradeoff analysis.
[0030] Figure 2B is a diagram showing a process 200B of converting exposed program code 240 to hidden program code 250 according to an example embodiment. Referring to Figure 2B , the exposed program code 240 includes program code of decisions within the control flow of the program. For example, the program code 240 can represent Figure 2A the decision 211 shown in. In this example, the program code 240 includes the boolean result of a conditional expression "e" that is revealed to an attacker who can observe the executed control flow. Based on the result of "e", only "f" or "g" is computed. The decision of choosing "f" or "g" is observable from the program code 240.
[0031] Meanwhile, the hidden program code 250 can be generated by converting the program code 240 into a semantically equivalent form that does not reveal the decision. For example, the host system can rewrite the program code 240 into the form of the hidden program code 250. In this case, the hidden program code 250 computes both "f" and "g" and combines the results by calling an oblivious choice function. However, since the attacker does not learn the result of "e", no control flow decision is observable. Instead, the selection statement conceals this feature from the side channel. Therefore, the security value of the hidden program code 250 will be greater than the security value of the program code 240. However, a disadvantage of the hidden program code 250 is that the system has to perform c(f) + c(g) computations. In contrast, when executing the program code 240, the system only needs to perform the maximum of c(f) and c(g) computations. Therefore, the hidden program code 250 can have a longer running time (worse performance value).
[0032] Figure 3 FIG. 3 illustrates a process 300 for performing a security and performance trade-off analysis according to an example embodiment. Referring Figure 3 , the host system 320 includes an analysis algorithm 322 that performs a security and performance trade-off analysis of multiple variants of the software program 310. For example, the host system 320 can be a user device, a server, a database, a cloud platform, and so on. The host system 320 can generate multiple variants. Here, the host system 320 can start with a fully hidden program code in which no bits leak through the side channel. Then, the host system 320 can incrementally reveal decisions to generate variants. However, other search methods are possible. For example, the host system 320 can start with some decisions hidden and some decisions revealed. In some embodiments, the host system 320 can receive a security policy 330 that specifies one or more decisions, variables, etc. that must be kept hidden. Here, the host system 320 can generate variants while taking into account the decisions, etc. that must be kept hidden.
[0033] The host system 320 can execute different variants. Here, the analysis algorithm 322 can perform a security and performance trade-off analysis of different variants based on the conditions within the security policy 330. Additionally, during runtime, the security subroutine 324 can measure the amount of bits leaked by the variant, and the performance subroutine 326 can measure the runtime of the variant. The security value and the performance value can be fed back to the analysis algorithm 322 for performing the trade-off analysis. As further described below, the analysis algorithm 322 can be a greedy heuristic algorithm that identifies one or more Pareto-optimal variants of the software program 310. As another example, the analysis algorithm 322 can be a genetic algorithm that identifies one or more Pareto-optimal variants of the software program 310.
[0034] In this example, the host system 320 can output information about three optimal variants (variants 311, 312, and 313) of a software program to the user device. Here, the host system 320 can output code, metrics (security value and performance value), etc. Thus, the developer can receive the proposed code changes and the reasons for the proposed code changes.
[0035] The analysis system described herein can include processes that can measure security and performance. The security value and performance value can be determined by a cost function. For example, the security metric can measure the amount of data bit leakage observed from the executed program. For example, the performance metric can be the running time of the program variant. An adversary model can learn the initial state of the program. The adversary model describes the capabilities of the adversary and, furthermore, against which adversary the program can be protected.
[0036] To evaluate the security of a program, the system can rely on established Quantitative Information Flow (QIF) techniques and information theory. QIF analysis can be decomposed into two steps, including algebraic interpretation, followed by numerical evaluation. Then, the system can capture the view of the adversary model as an equivalence relation of the initial state of the program. Then, the system can quantify the equivalence relation to obtain a numerical value representing the adversarial information flow when the program is executed.
[0037] The system can use numerical metrics such as entropy calculation to quantify how many bits can be observed from a predefined amount of bits. The resulting metric can include a measurement of the average information flow leaked from the program during program execution, in bits. The system can model the information flow from the program to the observer obtained from the execution of the program as an equivalence relation in the initial state of the program. If an observer of the control flow cannot distinguish between two states, then they are equivalent. The higher the number of equivalence classes and the smaller the classes, the more information is revealed to the attacker. In the extreme case of a single set, the observer cannot distinguish between any of the states and thus learns no information. On the other hand, if a singleton set is observed, the attacker has perfect knowledge of the initial state.
[0038] Meanwhile, the performance metric can measure the time taken to run the software program. The security metric and the performance metric can be implemented as subroutines. It should also be understood that any security metric and performance metric can be used as is well known in the art.
[0039] Figures 4A - 4C Graphs 410, 420, and 430 showing the security values and performance values of program variants according to an example embodiment are referenced. Figure 4A, graph 410 shows a graph of performance values (running time) regarding the number of hidden decisions within a program. As can be seen from graph 410, the more hidden decisions there are, the greater the running time. At the same time, graph 420 shows a graph of bit leakage regarding the number of hidden decisions within the program. As can be seen from graph 420, the bit leakage decreases as more decisions are hidden. Graph 420 is a special case of the program where the removal of each control flow decision results in a similar amount of security increment and a similar amount of performance loss. Generally speaking, this is not the case because different control flow decisions have different impacts on security and performance. Additionally, graph 430 shows graph 410 superimposed on graph 420. Identifying the Pareto optimal solution can identify the optimal values for both bit leakage and running time. In this example, each solution is a Pareto optimal solution. Here, a Pareto optimum is achieved if no other solution has a strictly better (i.e., lower) value in at least one dimension and no other dimension has a worse (i.e., higher) value. Accordingly, if a solution is not dominated by another solution (i.e., another solution is not strictly better), then the solution is Pareto optimal. Graph 430 does not show the entire space of solutions, but rather a subset of solutions that gives the impression of different trade-offs, and all of these solutions are Pareto optimal.
[0040] In some embodiments, the system can identify leaks to support qualitative information flow strategies. Qualitative information flow strategies specify whether the information flow to an observer during program execution for each program variable is tolerable. For example, taint flow analysis can be performed to determine whether the program conforms to the qualitative information flow strategy. For example, program P is associated with policy Φ. The system can construct a taint flow analysis where control flow transitions (decisions) are sinks in the taint flow analysis. The system can build an initial set of taint variables from φ. Then, the taint can spread to other variables. The analysis returns a set of flows as tuples (v, τ) consisting of the taint source variable "v" and the sink transition "τ". In this example, P conforms to φ if and only if the analysis outputs an empty set.
[0041] As another example, if the adversary flow of a program does not exceed the quantitative information flow strategy of any variable, the system can consider whether the program conforms to the quantitative information flow strategy. Here, the quantitative information flow strategy can define an upper bound on the adversary information flow of a variable, and the system can use worst-case information flow measurements.
[0042] It is possible for program P to initially violate a given quantitative information flow policy Ψ. In such a case, the system can transform the program into a variant that does conform to the quantitative information flow policy Ψ. In this case, if the program does not conform to Ψ, there exists a variable where the adversary information flow to the observer exceeds a predefined threshold for that variable. To make P conform, the adversary information flow of the variable must be reduced by removing control flow statements (such as those shown in the example of Figure 2B ). The control flow removal algorithm can rewrite the program code in a way that masks, or otherwise obscures, the decisions within the program code.
[0043] Next, the system can perform a security-performance trade-off analysis. In some embodiments, a combination of decisions for a given variant (e.g., hide, reveal, hide, hide, reveal, etc.) can be interpreted as a particular choice of such a trade-off. In the following equation, this particular choice is represented as a binary vector (t). The problem of finding the transformation corresponding to a conforming program with optimal security and performance can be represented as an optimization problem with the following optimization function.
[0044] Equation 1:
[0045]
[0046] More specifically, the system can determine the argument minimum of the cost function f(t) such that the program T(P,t) conforms to the quantitative information flow policy Ψ. This describes the transformation of the original program P with respect to the binary vector t in the following way. If the i-th entry of t is 0, then the i-th control flow decision is removed. Otherwise, the new program still includes this decision. Formally:
[0047] Equation 2:
[0048] arg min f(t)
[0049] s.t. T(P,t) conforms to Ψ
[0050] t ∈ {0, 1} |T|
[0051] Since f has multiple objectives, solving this optimization problem may not yield a single optimal solution, but rather a set of Pareto optimal solutions. The system can output the solutions in this set in ascending order with respect to μ p .
[0052] The first analysis algorithm for performing security and performance trade-off analysis is the greedy heuristic algorithm. The greedy heuristic algorithm provides fast / efficient convergence. The starting point of the greedy heuristic algorithm is the transformation of the initial program that does not contain any revealed control flow decisions. In other words, all decisions are hidden. This is called the fully hidden program. This program is clearly compliant with the quantitative information flow policy Ψ because it does not involve any adversary information flow at all. Based on the fully hidden program, the system can iteratively reveal control flow decisions until revealing any more decisions will result in non-compliance with the quantitative information flow policy Ψ. By incrementally revealing control flow decisions, the system gradually obtains a policy-compliant program with better performance and lower security.
[0053] The greedy heuristic can take as input a program P and a quantitative information flow policy Ψ and output the non-dominated set of the program P. This algorithm, being a heuristic, only provides an approximation of the actual solution. At each iteration step, the heuristic can consider the base program, starting with the fully hidden program in the first step, and the set of bit vectors B corresponding to programs with one additional control flow transition revealed. The system can filter any policy-compliant and non-dominated programs and add their corresponding bit vectors to the current set of bit vectors B. If each program is non-compliant or dominated by the programs in the solution set, or if there are no more transitions to reveal, the greedy heuristic algorithm terminates. Add each program corresponding to the elements of B to the solution set. Randomly select one of these programs as the basis for the next iteration step. Filtering non-dominated programs is achieved through a subroutine that outputs the maximum subset of non-dominated programs.
[0054] Rather than starting with the fully hidden program and revealing control flow decisions, the system can start with the fully revealed program (i.e., the original program) and remove control flow transitions. However, this may be more difficult. For example, it is unlikely that the fully revealed program is already policy-compliant. Therefore, the system must somehow establish policy compliance by investigating other program variants. To do so, it may have to investigate a large number of non-compliant programs.
[0055] As another example, policy-based security and performance trade-off analysis can be performed using genetic algorithms. For example, genetic algorithms can include heuristic methods for solving optimization problems based on genetic metaheuristics. Genetic algorithms do not require any prior knowledge about the structure of the search space, so they are well-suited to the problems described in the example embodiments. In contrast to the greedy heuristic algorithm, the entire set of solutions (i.e., the so-called population), which may not necessarily be policy-compliant, is considered and used to generate new solutions via genetic algorithms.
[0056] For example, the fittest individuals, i.e., binary vectors of size T, can be selected from the population according to a fitness function. Based on the selected individuals, new individuals are generated by using so-called crossover and mutation, which replace the least fit individuals in the population. This process is repeated until a sufficiently large number of non-dominated solutions are found or the running time limit has been reached. The genetic algorithm can use a population size N determined by the developer. For a program P and a quantitative information flow policy Ψ, the algorithm outputs a non-dominated set of programs that conform to the policy and have a size of at most N. Since the genetic algorithm can converge to a solution, in order to give the developer a wide selection of solutions, the genetic algorithm uses a niching method.
[0057] In this example, the fitness function F is based on a ranking that takes policy compliance into account. For an individual i, if it is dominated by k individuals in the current population, the algorithm can assign F i := N - k. If the program is not policy compliant, the algorithm can assign F i := 0 to penalize such a solution and prefer compliant programs. Additionally, in the context of the genetic algorithm, each component of an individual is called a gene. Two individuals can be obtained by crossover by swapping the first halves of the genes of the parents. For those individuals, mutation is applied with a probability based on the reciprocal of the population size.
[0058] In some embodiments, a niching method can be used. Niching can be recommended for multi-objective optimization. If two individuals in the population are in the same niche (i.e., their distance is below a threshold sharing parameter σ), their fitness is shared. In this example, an unambiguous solution can be represented by Equation 3.
[0059] Equation 3:
[0060]
[0061] In this example, M1, M2, m1, and m2 are scalars that are calculated once at the start of the algorithm. They represent the boundaries of the search space. Here, the system can use those characteristics of two well-known programs to approximate the boundaries of the search space. A fully revealing program will have a high leakage but good performance, while a fully hiding program will have no leakage but poor performance. By determining the distance between two points, the system does not weight the influence of one dimension over another because they may have different scales. Instead, the system can normalize the two dimensions with respect to the maximum values of the above programs. This can result in the following parameters shown in Equation 4.
[0062] Equation 4:
[0063]
[0064]
[0065] where μ s describes a security measurement, and μ p describes a performance measurement, and describes all hidden programs. Herein, hereinafter, the system may represent a scaling factor as shown in Equation 5.
[0066] Equation 5:
[0067]
[0068] Now, the fitness is shared with other individuals in the same niche. Here, the system may define a sharing function as shown in Equation 6.
[0069] Equation 6:
[0070] sh: [0, inf] → [0, 1]
[0071] where
[0072]
[0073] where d describes the metric of two points in the search space. The Euclidean distance metric may be used, as shown in Equation 7 below. Based on a simple fitness function, the system defines a shared fitness function F.T that takes as parameters an individual "i" and a matrix "M" with individuals of the population as columns.
[0074] Equation 7:
[0075]
[0076] Based on the shared fitness function, the evolutionary process is repeated until the maximum number of iterations is reached or the convergence criterion is satisfied. The system may use the maximum allowable Pareto percentage as the convergence criterion. Here, if the percentage of non-dominated individuals in the current population exceeds a user-defined threshold, the algorithm terminates.
[0077] Figure 5 A method 500 for determining one or more Pareto optimal variants of a software program according to an example embodiment is shown. For example, the method 500 may be performed by a software program (such as an application, a service, or other program) executing on a cloud platform, a server, a database node, a computing system (user device), a combination of devices / nodes, etc. Referring to Figure 5 , at 510, the method may include identifying a set of decisions within the control flow of the software program. For example, the decisions may include "if" statements, "while" statements, "break" statements, etc., which correspond to choices between different paths within the program.
[0078] In 520, the method may include generating multiple variants of a software program, the multiple variants including different subsets of decisions that are respectively partially exposed to side channels and satisfy a predetermined security specification of the software program. The variants may include different subsets of hidden decisions and exposed decisions. Here, the exposure of a decision does not necessarily reflect the exposure of all program code. Instead, the exposure may be represented at the bit level, where different levels of information indicating that different amounts of bits are leaked can be obtained. In some embodiments, the generating may include converting a code snippet of a decision within a control flow into a semantically equivalent code that does not identify the decision result. In some embodiments, the converting may include combining a bitwise operation of a decision with a constant-time conditional assignment operation. In some embodiments, the decision may include a conditional instruction within the source code of a software program, and the conditional instruction is executed on encrypted data.
[0079] In 530, the method may include determining one or more Pareto-optimal variants of a software program based on side-channel leakage values and performance values of the multiple variants of the software program. Further, in 540, the method may include outputting information about one or more Pareto-optimal variants of the software program to a user device.
[0080] In some embodiments, the determining may be performed via a greedy heuristic algorithm that identifies one or more Pareto-optimal variants of a software program based on side-channel leakage values and performance values. In some embodiments, the determining may be performed via a genetic algorithm that determines one or more Pareto-optimal variants of a software program based on side-channel leakage values and performance values. In some embodiments, the determining may include determining one or more optimal variants of a software program based on the implementation of a predefined security policy of the software program, the predefined security policy requiring that one or more predefined decisions be hidden. For example, the side-channel leakage value of a variant of a software program may indicate how many bits are exposed through the side channel. As another example, the performance value of a variant of a software program represents the running time of the variant.
[0081] Figure 6 A computing system 600 is shown that may be used in any of the methods and processes described herein according to an example embodiment. For example, the computing system 600 may be a database node, a server, a cloud platform, etc. In some embodiments, the computing system 600 may be distributed across multiple computing devices (such as multiple database nodes). Referring Figure 6 , the computing system 600 includes a network interface 610, a processor 620, an input / output 630, and a storage device 640 (such as a memory storage), etc. Although in Figure 6Although not shown, the computing system 600 may also include or be electrically connected to other components, such as a display, (one or more) input units, a receiver, a transmitter, a persistent disk, etc. The processor 620 may control other components of the computing system 600.
[0082] The network interface 610 may send and receive data over a network (such as the Internet, a private network, a public network, an enterprise network, etc.). The network interface 610 may be a wireless interface, a wired interface, or a combination thereof. The processor 620 may include one or more processing devices, each processing device including one or more processing cores. In some examples, the processor 620 is a multi-core processor or multiple multi-core processors. Also, the processor 620 may be fixed, or it may be reconfigurable. The input / output 630 may include interfaces, ports, cables, buses, boards, wires, etc. for inputting data into and outputting data from the computing system 600. For example, data may be output to an embedded display of the computing system 600, an externally connected display, a cloud-connected display, another device, etc. The network interface 610, the input / output 630, the storage device 640, or a combination thereof may interact with applications executing on other devices.
[0083] The storage device 640 is not limited to a specific storage device and may include any known memory device, such as RAM, ROM, a hard disk, etc., and may or may not be included within a database system, a cloud environment, a network server, etc. The storage device 640 may store software modules or other instructions that may be executed by the processor 620 to perform Figure 5 the methods shown. According to various embodiments, the storage device 640 may include a data store having multiple tables, partitions, and sub-partitions. The storage device 640 may be used to store database records, items, entries, etc. In some embodiments, the storage device 640 may be configured to store instructions for managing a configuration repository of a distributed system.
[0084] As will be appreciated based on the foregoing specification, the above examples of the present disclosure may be implemented using computer programming or engineering techniques that include computer software, firmware, hardware, or any combination or subset thereof. Any such resulting program, having computer-readable code, may be embodied or provided within one or more non-transitory computer-readable media, thereby manufacturing a computer program product, i.e., an article of manufacture, in accordance with the examples discussed in the present disclosure. For example, the non-transitory computer-readable media may be, but are not limited to, fixed drives, floppy disks, optical disks, magnetic tapes, flash memories, external drives, semiconductor memories such as read-only memory (ROM), random-access memory (RAM), and / or any other non-transitory sending and / or receiving media such as the Internet, cloud storage, the Internet of Things (IoT), or other communication networks or links. An article of manufacture containing computer code may be manufactured and / or used by executing the code directly from one medium, by copying the code from one medium to another, or by sending the code over a network.
[0085] A computer program (also referred to as a program, software, software application, “app”, or code) may include machine instructions for a programmable processor and may be implemented in a high-level procedural and / or object-oriented programming language, and / or in assembly / machine language. As used herein, the terms “machine-readable medium” and “computer-readable medium” refer to any computer program product, apparatus, cloud storage, IoT, and / or device (e.g., a disk, an optical disk, a memory, a programmable logic device (PLD)) that provides machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. However, the “machine-readable medium” and “computer-readable medium” do not include transitory signals. The term “machine-readable signal” refers to any signal that can be used to provide machine instructions and / or any other kind of data to a programmable processor.
[0086] The foregoing description and illustration of the processes herein should not be considered as implying a fixed order for performing the process steps. Instead, the process steps may be performed in any practicable order, including the simultaneous performance of at least some steps. Although the present disclosure has been described in connection with specific examples, it should be understood that various changes, substitutions, and alterations that are obvious to those skilled in the art may be made to the disclosed embodiments without departing from the spirit and scope of the present disclosure as set forth in the appended claims.
Claims
1. A computing system, comprising: A storage device configured to store a set of statements within a control flow of a software program; And A processor configured to: Generate a plurality of variants of the software program, the plurality of variants conforming to a quantitative information flow policy that defines an upper bound of an adversary information flow of one or more variables in the software program, wherein the plurality of variants respectively include a plurality of different subsets of statements within the control flow exposed to a side channel; Determine one or more Pareto optimal variants of the software program based on side channel leakage values and performance values of the plurality of variants of the software program, wherein Pareto optimality is achieved if there is no other solution with a lower value in at least one dimension and no other dimension with a higher value; Output information about one or more Pareto optimal variants of the software program to a user device, and Based on the output information, decide which statements within the control flow to hide and which statements to allow to be observed through the side channel.
2. The computing system according to claim 1, wherein The processor is configured to convert a code snippet of a statement within the control flow into a semantically equivalent code that does not recognize the result of the statement.
3. The computing system according to claim 2, wherein, The processor is configured to combine bitwise operations of a statement with constant-time conditional assignment operations.
4. The computing system according to claim 1, wherein, The statement includes a conditional instruction within the source code of the software program, and the conditional instruction is executed on encrypted data.
5. The computing system according to claim 1, wherein, The side channel leakage value of a variant of the software program represents how many bits are exposed through the side channel.
6. The computing system according to claim 1, wherein, The performance value of a variant of the software program represents the running time of the variant.
7. The computing system according to claim 1, wherein, The processor is configured to determine one or more Pareto optimal variants via a greedy heuristic algorithm that identifies one or more Pareto optimal variants of the software program based on side channel leakage values and performance values.
8. The computing system according to claim 1, wherein The processor is configured to determine one or more Pareto optimal variants via a genetic algorithm that determines one or more Pareto optimal variants of the software program based on side channel leakage values and performance values.
9. The computing system according to claim 1, wherein The processor is configured to determine one or more Pareto optimal variants of the software program based on the implementation of a predefined security policy of the software program, the predefined security policy requiring one or more predefined statements to be hidden.
10. A method, comprising: Identify a set of statements within a control flow of a software program; Generate a plurality of variants of the software program, the plurality of variants conforming to a quantitative information flow policy that defines an upper bound of an adversary information flow of one or more variables in the software program, wherein the plurality of variants respectively include a plurality of different subsets of statements within the control flow exposed to a side channel; Determine one or more Pareto optimal variants of the software program based on side channel leakage values and performance values of the plurality of variants of the software program, wherein Pareto optimality is achieved if there is no other solution with a lower value in at least one dimension and no other dimension with a higher value; Output information about one or more Pareto optimal variants of the software program to a user device; and Based on the output information, decide which statements within the control flow to hide and which statements to allow to be observed through the side channel.
11. The method according to claim 10, wherein, The generation includes converting a code snippet of a statement within a control flow into a semantically equivalent code that does not recognize the result of the statement.
12. The method according to claim 11, wherein, The conversion includes combining a bitwise operation of a statement with a constant-time conditional assignment operation.
13. The method according to claim 10, wherein The statement includes a conditional instruction within the source code of the software program, and the conditional instruction is executed on encrypted data.
14. The method according to claim 10, wherein, The side-channel leakage value of a variant of the software program indicates how many bits are exposed through the side-channel.
15. The method according to claim 10, wherein, The performance value of a variant of the software program represents the running time of the variant.
16. The method according to claim 10, wherein, The determination is performed via a greedy heuristic algorithm that identifies one or more Pareto-optimal variants of the software program based on the side-channel leakage value and the performance value.
17. The method according to claim 10, wherein, The determination is performed via a genetic algorithm that determines one or more Pareto-optimal variants of the software program based on the side-channel leakage value and the performance value.
18. The method according to claim 10, wherein, The determination includes determining one or more Pareto-optimal variants of the software program based on the implementation of a predefined security policy of the software program, where the predefined security policy requires that one or more predefined statements be hidden.
19. A non-transitory computer-readable medium including instructions that, when executed by a processor, cause the computer to perform a method, the method including: Identifying a set of statements within the control flow of a software program; Generating a plurality of variants of the software program, the plurality of variants conforming to a quantitative information flow policy that defines an upper bound on the adversary information flow of one or more variables in the software program, wherein the plurality of variants each include a different subset of the statements of the control flow exposed to the side-channel; Determining one or more Pareto-optimal variants of the software program based on the side-channel leakage values and performance values of the plurality of variants of the software program, where Pareto optimality is achieved if there is no other solution with a lower value in at least one dimension and no other dimension with a higher value; Outputting information about one or more Pareto-optimal variants of the software program to a user device; and Based on the output information, deciding which statements within the control flow to hide and which statements to allow to be observed through the side-channel.
20. The non-transitory computer-readable medium according to claim 19, wherein, The generation includes converting a code snippet of a statement within a control flow into a semantically equivalent code that does not recognize the result of the statement.
Citation Information
Patent Citations
Side-channel leakage evaluator and analysis kit
US20160140340A1
Secure code optimization method and system
US20190005233A1
Reconfigurable system-on-chip security architecture
US20190180041A1