A Method and Device for Strengthening Concurrent Application Runtime
By using Intel TSX instruction set in concurrent applications, it provides transaction interval protection for the application, prevents preemption and rolls back to the initial state when it fails, solving the problem of preemption attacks and achieving effective security protection and compatibility.
Patent Information
- Application Number
- CN202110677805.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-18
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-06-18
AI Technical Summary
In the prior art, when the operating system is executed concurrently, it is vulnerable to preemptive attacks, resulting in problems such as secret data leakage and resource competition vulnerabilities that have not been effectively solved.
Using Intel TSX instruction set, it provides a transaction interval for application execution, prevents preemption in the instruction execution mode of transaction interval, and rolls back to the initial state after transaction execution fails, providing an isolation zone mode to protect application resources.
It realizes extensive compatibility protection for concurrent applications, can resist a variety of preemptive attacks, including side channel attacks and resource competition vulnerabilities, and the performance overhead is controlled within a reasonable range.
Smart Images

Figure CN113885887B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of software technology and information security technology, relates to security protection technology for concurrent applications, and particularly relates to a method and device for strengthening the runtime of concurrent applications. Background Art
[0002] Concurrency is a common manifestation form for modern operating systems to complete multitask response. Generally speaking, an operating system allows preemptive execution between different applications to complete concurrent execution among multiple applications. The reasons for an application to be preempted are diverse, including the lower priority of the application, long-term occupation of resources, waiting for input / output device response, etc. After an application is preempted, its execution context is saved, and at the same time its execution resources are relinquished for other tasks to use.
[0003] In a multitask concurrency scenario, the object to be preempted may be a certain section of code of a process or a thread. Although the operating system and the processor will protect most of the context of code execution, such as registers, instruction addresses, stack space, etc. However, some contents will inevitably be leaked to other tasks, such as caches. When a malicious process or thread successfully preempts the victim task through certain means and utilizes the leaked context, it may steal the secret data of the victim.
[0004] Generally speaking, an attacker may either directly steal the information left by the victim in the context or steal the secret information by tampering with the context and probing the execution traces of the victim. The types of attacks on concurrent applications using preemptive execution are also diverse, including resource competition vulnerability exploitation, cache and interrupt side-channel attacks, Spectre and Meltdown vulnerabilities, etc.
[0005] Intel TSX is short for Transactional Synchronization eXtension. The present invention is implemented based on the Intel TSX extended instruction set. The TSX instruction set can make the instruction execution in a transaction mode to prevent the application execution from being preempted. Summary of the Invention
[0006] The purpose of the present invention is to provide a method for strengthening the runtime of concurrent applications, which can provide protection for concurrent applications against preemptive attacks.
[0007] The technical solution adopted by the present invention is as follows:
[0008] A method for strengthening the runtime of concurrent applications includes the following steps:
[0009] Provide a transaction interval for application execution. The instruction execution mode in the transaction interval is called the transaction mode, and the transaction cannot be preempted by other tasks during its execution;
[0010] After the transaction execution fails, the application is rolled back to the state before the transaction execution, and the rollback count and the failure reason are recorded;
[0011] Provide an isolation area mode that temporarily exits the transaction range for instructions that cannot be executed in the transaction mode.
[0012] Furthermore, based on the Intel TSX instruction set, the instruction execution is in the transaction mode to prevent the application execution from being preempted.
[0013] Furthermore, the number of instructions in the transaction mode state is not greater than the number of instructions in a basic code block.
[0014] Furthermore, the operation steps for the instruction execution to enter the transaction mode and to be in the transaction mode include:
[0015] 1) Save the RAX register and the flag register;
[0016] 2) Execute the xbegin instruction to start the transaction mode and specify the processing code address when the transaction execution fails;
[0017] 3) Restore the RAX register and the flag register;
[0018] 4) Sequentially execute the original application instructions;
[0019] 5) Determine whether the instruction to be executed is a branch instruction. If so, execute step 6); otherwise, execute step 8);
[0020] 6) Execute the branch instruction to complete the jump;
[0021] 7) Execute the xend instruction to exit the transaction mode and execute step 1);
[0022] 8) Determine whether to enter the isolation area. If so, perform the isolation area operation; otherwise, execute step 9);
[0023] 9) Determine whether to end the transaction mode execution. If so, execute step 10); otherwise, execute step 4);
[0024] 10) Execute the xend instruction to end the transaction mode execution.
[0025] Furthermore, the determination of whether to enter the isolation area includes: if it is found that the instruction needs to trigger an interrupt or enter a privilege level, enter the isolation area; if no instruction that will trigger an interrupt or enter a privilege level is found, do not enter the isolation area.
[0026] Furthermore, the operation steps for the instruction execution to enter the isolation area mode, to be in the isolation area mode, and to exit the isolation area mode include:
[0027] (1) Save the transaction execution mode context, including function parameters and memory variables;
[0028] (2) Execute the xend instruction to exit the transaction mode and then enter the isolation area mode;
[0029] (3) Execute the original application instructions;
[0030] (4) Execute the xbegin instruction to resume the transaction execution mode and specify the processing code address when the transaction fails;
[0031] (5) Restore the transaction execution mode context;
[0032] (6) Check whether the protected application resources are damaged. If so, end the application execution; otherwise, execute step 4) to end the isolation area mode and return to the transaction mode.
[0033] Further, the operation steps after the transaction execution fails include:
[0034] [1] Jump to the processing code location specified in step 2) when the transaction fails;
[0035] [2] Obtain the transaction failure count t;
[0036] [3] t = t + 1;
[0037] [4] Determine whether t > N, where N is a set large rollback count. If so, exit the application execution; otherwise, execute step [5];
[0038] [5] Obtain the binary value of the RAX register, denoted as r. If the second lowest bit of r is 1, execute step [6]; otherwise, execute step [7];
[0039] [6] Return to the start position of the transaction mode and execute step 1);
[0040] [7] Report the value of r to the user and exit the application execution.
[0041] A concurrent application runtime hardening device adopting the above method, which includes:
[0042] A transaction execution module, which is used to provide a transaction interval for the application execution. The instruction execution mode within the transaction interval is called the transaction mode, and it cannot be preempted by other tasks during the transaction execution;
[0043] A transaction execution failure handling module, which is used to roll back the application to the state before the transaction execution and record the rollback count and the failure reason after the transaction execution fails;
[0044] An isolation area mode operation module, which is used to provide an isolation area mode for temporarily exiting the transaction interval for instructions that cannot be executed in the transaction mode.
[0045] Compared with the prior art, the positive effects of the present invention are as follows:
[0046] The present invention can be automatically deployed in a software compiler, has relatively wide compatibility, can provide protection against preemptive attacks for concurrent applications, and can resist most attacks based on preemptive execution, including various side-channel attacks and resource competition vulnerabilities, etc. Description of the Drawings
[0047] Figure 1 It is the overall flowchart of the method of the present invention.
[0048] Figure 2 It is the flowchart of the enclave operation.
[0049] Figure 3 It is the flowchart of the processing after the transaction execution fails.
[0050] Figure 4 It is the graph of the performance overhead test results in the embodiments of the present invention. Detailed Embodiments
[0051] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described below through specific embodiments and the accompanying drawings.
[0052] 1. The present invention includes the following key points:
[0053] 1.1) It is implemented based on the Intel TSX (Transactional Synchronization eXtensions) instruction set extension.
[0054] 1.2) Provide a transaction interval for the application execution. The instruction execution mode within the transaction interval is called the transaction mode, and the instructions during the transaction execution cannot be preempted by other tasks. Among them, "transaction" refers to a set of instruction operations completed by the central processing unit at one time, "transaction interval" refers to the time period during which the central processing unit completes the transaction, "instruction execution" refers to the execution of the instructions of the application, and "transaction execution" refers to the instruction execution in the transaction mode.
[0055] 1.3) The number of instructions in the transaction mode state is not greater than the number of instructions in a basic code block. Among them, "basic code block" refers to a set of instructions that does not contain branch instructions. In the basic code block, the instruction addresses are adjacent.
[0056] 1.4) After the transaction execution fails, the application rolls back to the state before the transaction execution, and records the number of rollbacks and the reason for the failure.
[0057] 1.5) Provide an isolation area mode that temporarily exits the transaction range for instructions that cannot be executed in transaction mode.
[0058] 2. As described in key points 1.2), 1.3), 1.4), and 1.5), when the instruction execution enters the transaction mode and is in the transaction mode, as Figure 1 shown, it includes the following steps:
[0059] 2.1) Save the RAX register and the flag register.
[0060] 2.2) Execute the xbegin instruction to start the transaction mode and specify the processing code address when the transaction execution fails.
[0061] 2.3) Restore the RAX register and the flag register.
[0062] 2.4) Sequentially execute the original application instructions.
[0063] 2.5) Determine whether the instruction to be executed is a branch instruction. If so, execute step 2.6); otherwise, execute step 2.8).
[0064] 2.6) Execute the branch instruction to complete the jump.
[0065] 2.7) Execute the xend instruction to exit the transaction mode and execute step 2.1).
[0066] 2.8) Determine whether to enter the isolation area. If so, execute the isolation area operation 3.1); otherwise, execute step 2.9).
[0067] The method for determining whether to enter the isolation area is as follows: If it is found that the instruction needs to trigger an interrupt or needs to enter a privilege level (the privilege level refers to the permission level for kernel operations), then enter the isolation area; if no instruction that will trigger an interrupt or enter a privilege level is found, then do not enter the isolation area.
[0068] 2.9) Determine whether to end the transaction mode execution. If so, execute step 2.10); otherwise, execute step 2.4).
[0069] 2.10) Execute the xend instruction to end the transaction mode execution.
[0070] 3. As described in step 2.8), the isolation area operation process for the instruction execution to enter the isolation area mode, be in the isolation area mode, and exit the isolation area mode is as Figure 2 shown, and it includes the following steps:
[0071] 3.1) Save the transaction execution mode context, including function parameters, memory variables, etc.
[0072] 3.2) Execute the xend instruction to exit the transaction mode and then enter the isolation area mode.
[0073] 3.3) Execute the original application instruction.
[0074] 3.4) Execute the xbegin instruction to resume the transaction execution mode and specify the processing code address when the transaction fails.
[0075] 3.5) Resume the transaction execution mode context.
[0076] 3.6) Check whether the protected application resources are damaged. If so, end the application execution; otherwise, execute step 2.4) to end the enclave mode and return to the transaction mode.
[0077] In the present invention, the "enclave" specifically refers to a section of instruction execution interval that allows an application to trigger an interrupt or enter a privileged level, and the security of application resources will be checked when this interval ends.
[0078] 4. As described in step 1.4), the processing flow after the transaction execution fails is as Figure 3 shown, including the following steps:
[0079] 4.1) Jump to the processing code location when the transaction fails specified in step 2.2).
[0080] 4.2) Obtain the transaction failure count t.
[0081] 4.3) t = t + 1, that is, record the rollback count.
[0082] 4.4) Determine whether t > N, where N is a set large rollback count. If so, exit the application execution; otherwise, execute step 4.5). In this embodiment, the value of N is 10, and in other embodiments, it can also be other numbers, which can be modified according to specific situations.
[0083] 4.5) Obtain the binary value of the RAX register, denoted as r. If the second - lowest bit of r is 1, execute step 4.6); otherwise, execute step 4.7). The second - lowest bit of r is the failure reason, and the value of r is automatically generated by the central processing unit according to the transaction situation.
[0084] 4.6) Return to the start position of the transaction mode and execute step 2.1).
[0085] 4.7) Report the value of r to the user and exit the application execution.
[0086] Experimental data: In ten typical scenarios, the performance overhead test results of the present invention are shown in the appendix Figure 4 , where the highest is 28.97%, the lowest is 0.03%, five are below 1%, seven are below 10%, and the average value is 7.11%.
[0087] Another embodiment of the present invention is a concurrent application runtime hardening device using the above method, which includes:
[0088] A transaction execution module, which is used to provide a transaction interval for the execution of an application. The instruction execution mode within the transaction interval is called the transaction mode, and it cannot be preempted by other tasks during transaction execution.
[0089] A transaction execution failure handling module, which is used to roll back the application to the state before transaction execution and record the rollback times and failure reasons after the transaction execution fails.
[0090] An isolation area mode operation module, which is used to provide an isolation area mode for instructions that cannot be executed in the transaction mode to temporarily exit the transaction interval.
[0091] Another embodiment of the present invention provides an electronic device (such as a computer, a server, a smart phone, etc.), which includes a memory and a processor. The memory stores a computer program, and the computer program is configured to be executed by the processor. The computer program includes instructions for executing each step in the method of the present invention.
[0092] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, a disk, an optical disc). The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, each step of the method of the present invention is implemented.
[0093] In addition to being deployable in a software compiler, the present invention can also be deployed in a decompiler, a dynamic link library, or a static link library. Different deployment methods do not affect the execution process of the solution described in the specification.
[0094] The specific embodiments of the present invention disclosed above are intended to help understand the content of the present invention and implement it accordingly. Those of ordinary skill in the art can understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the content disclosed in the embodiments of this specification, and the protection scope of the present invention is subject to the scope defined by the claims.
Claims
1. A method for strengthening concurrent application runtime, characterized in that It includes the following steps: Provide a transaction interval for application execution. The instruction execution mode within the transaction interval is called the transaction mode, and it cannot be preempted by other tasks during transaction execution; After the transaction execution fails, roll back the application to the state before the transaction execution, and record the number of rollbacks and the reason for failure; Provide an isolation area mode for temporarily exiting the transaction interval for instructions that cannot be executed in the transaction mode; Based on the Intel TSX instruction set, make the instruction execution in the transaction mode to prevent the application execution from being preempted; The operation steps for the instruction execution to enter the transaction mode and be in the transaction mode include: 1) Save the RAX register and the flag register; 2) Execute the xbegin instruction to start the transaction mode and specify the processing code address when the transaction execution fails; 3) Restore the RAX register and the flag register; 4) Sequentially execute the original application instructions; 5) Determine whether the instruction to be executed is a branch instruction. If so, execute step 6), otherwise execute step 8); 6) Execute the branch instruction to complete the jump; 7) Execute the xend instruction to exit the transaction mode and execute step 1); 8) Determine whether to enter the isolation area. If so, perform the isolation area operation, otherwise execute step 9); 9) Determine whether to end the transaction mode execution. If so, execute step 10), otherwise execute step 4); 10) Execute the xend instruction to end the transaction mode execution; The operation steps for the instruction execution to enter the isolation area mode, be in the isolation area mode, and exit the isolation area mode include: (1) Save the transaction execution mode context, including function parameters and memory variables; (2) Execute the xend instruction to exit the transaction mode and then enter the isolation area mode; (3) Execute the original application instructions; (4) Execute the xbegin instruction to restore the transaction execution mode and specify the processing code address when the transaction fails; (5) Restore the transaction execution mode context; (6) Check whether the protected application resources are damaged. If so, end the application execution, otherwise execute step 4) to end the isolation area mode and return to the transaction mode; The operation steps after the transaction execution fails include: [1] Jump to the processing code location specified in step 2) when the transaction execution fails; [2] Obtain the transaction failure count t; [3] t = t + 1; [4] Determine whether t > N, where N is the set number of rollbacks. If so, exit the application execution, otherwise execute step [5]; [5] Obtain the binary value of the RAX register, denoted as r. If the second lowest bit of r is 1, execute step [6], otherwise execute step [7]; [6] Return to the start position of the transaction mode and execute step 1); [7] Report the value of r to the user and exit the application execution.
2. The method according to claim 1, wherein The number of instructions in the state of the transaction mode does not exceed the number of instructions in a basic code block.
3. The method according to claim 1, characterized in that, The determination of whether to enter the isolation area includes: if it is found that the instruction needs to trigger an interrupt or enter a privilege level, enter the isolation area; if no instruction that will trigger an interrupt or enter a privilege level is found, do not enter the isolation area.
4. A concurrent application runtime reinforcement device adopting the method described in any one of claims 1 to 3, characterized in that, It includes: A transaction execution module, which is used to provide a transaction interval for application execution. The instruction execution mode within the transaction interval is called the transaction mode, and it cannot be preempted by other tasks during transaction execution; A transaction execution failure handling module, which is used to roll back the application to the state before transaction execution and record the rollback times and failure reasons after the transaction execution fails; An isolation area mode operation module, which is used to provide an isolation area mode for temporarily exiting the transaction interval for instructions that cannot be executed in the transaction mode.
5. An electronic device, characterized in that, It includes a memory and a processor. The memory stores a computer program, and the computer program is configured to be executed by the processor. The computer program includes instructions for executing the method described in any one of claims 1 to 3.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method described in any one of claims 1 to 3 is implemented.
Citation Information
Patent Citations
Defending Against Speculative Execution Exploits
US20200372129A1