Dynamic information flow tracking processor architecture based on hardware security tags

By introducing hardware security tags and tag logic circuits into the processor core and storage modules, real-time tracking of information flow and safe isolation at the cache level are achieved, and problems such as insufficient tracking of information flow, incomplete coverage of stain data and great impact on cache performance in the prior art are solved, and system security and performance efficiency are improved.

CN114579477BActive Publication Date: 2025-05-23TSINGHUA UNIVERSITY

Patent Information

Application Number
CN202210112760.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-29
Publication Date
2025-05-23
Estimated Expiration
2042-01-29

AI Technical Summary

Technical Problem

The existing technology lacks tracking and monitoring of information flows of non-memory access instructions and program segments during program execution, which poses security risks; the incomplete coverage of dynamic taint propagation analysis may lead to abnormal misreport; cache invalidation and locking technologies have a great impact on the performance of the cache mechanism.

Method used

Design a dynamic information flow tracking processor structure based on hardware security tags. By setting tag bits and tag logic circuits in the processor core and storage modules, real-time and efficient tracking of information flow is achieved, and security isolation measures are introduced at the cache level to reduce the performance impact on the cache mechanism.

Benefits of technology

The full process security tracking and restriction of data, instructions and cache is realized, and the completeness of system security is improved; the security of each instruction and each data is monitored in real time through fine-grained Tag management, with higher accuracy; without affecting the cache mechanism, the cache side channel protection is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114579477B_ABST
    Figure CN114579477B_ABST
Patent Text Reader

Abstract

The present application discloses a dynamic information flow tracking processor structure based on hardware security tags. In the processor structure, security-related tag bits are added to the registers in the processor core and the memory in the storage module. By adding tag checking and transfer logic circuits to the processor core, real-time and efficient tracking of information flow is achieved. By adding security-related tag bits to the data cache in the storage module, protection against side channel attacks is achieved with little performance impact. Therefore, the present application uses the newly added tag bits to divide the security level of the program, formulates tag transfer rules in the processor core, defines abnormal behaviors that may destroy the security of the system, prevents side channel attacks that may use the cache, and ensures the standardization and security of program operation. Therefore, the problems of security risks and significant impact on the performance of the cache mechanism due to the lack of dynamic information flow tracking and monitoring are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of processor chip technology, and in particular to a dynamic information flow tracking processor structure based on hardware security tags. Background Art

[0002] In a broad sense, information flow refers to a group of information that moves and propagates in the same direction in space and time. They have the same source and destination, that is, the collection of all information transmitted from one source unit to another destination unit. In a narrow sense, information flow refers to the transmission movement of information through certain channels according to certain requirements. This movement is also the main object of modern information technology research.

[0003] Information flow tracking technology, in the field of computer security, specifically refers to the use of certain methods to track the flow of program information, in order to identify operations that may damage the information security (confidentiality, integrity, availability) of the system. Generally speaking, information flow tracking can be divided into two technical solutions: static information flow tracking and dynamic information flow tracking. Static information flow tracking tracks the information flow before and after the processor system works, that is, the system work and tracking analysis are performed separately; dynamic information flow tracking tracks the information flow during the operation of the processor system, that is, the system work and tracking analysis are performed simultaneously. Compared with static information flow tracking, dynamic information flow tracking has the advantages of accurate problem location and good real-time prevention. It can effectively detect potential malicious attacks during the system operation and take corresponding measures to prevent malicious attacks in a timely manner.

[0004] Dynamic information flow tracking, generally speaking, can be implemented by software or hardware. Regarding dynamic information flow tracking implemented by software, it mainly adds some tracking-related instruction segments or program segments to the original program to complete runtime tracking. These additional program contents are redundant to the original program and will not change the running steps and results of the original program. Regarding dynamic information flow tracking implemented by hardware, it mainly adds some tracking-related logic circuits to the system hardware to complete runtime tracking. These additional circuits are redundant to the original circuits and will not affect the working mode of the original circuit. Compared with dynamic information flow tracking implemented by software, dynamic information flow tracking implemented by hardware has the advantages of fast tracking speed and high processing authority. It can use dedicated logic circuits to implement tracking without adding redundant code, and has greater freedom to take preventive measures after discovering malicious attacks.

[0005] In the scope of hardware implementation of dynamic information flow tracing, there are different hardware abstraction levels, including circuit level, gate netlist level (gate level for short), register transfer level (RTL), architecture level, algorithm level, and system level. Among them, hardware implementation at the gate level and architecture level is more mainstream, and of course there are also hardware implementations of dynamic information flow tracing at other abstraction levels. Regarding dynamic information flow tracing at the gate level abstraction, it is mainly to regard logic gates as carriers of information flow, pay attention to the impact of each logic gate on information flow, and design hardware to track information flow on logic gates. Regarding dynamic information flow tracing at the architecture level abstraction, it is mainly to regard instructions as carriers of information flow, pay attention to the impact of each instruction on information flow, and design hardware to track information flow on instructions. Compared with hardware implementation at the gate level abstraction, hardware implementation at the architecture level abstraction can complete more complete information flow tracing with fewer hardware resources. Implementing dynamic information flow tracing at this abstraction level can remove many relatively redundant hardware circuits, and can achieve good dynamic information flow tracing with relatively "core" hardware circuits, with higher implementation efficiency.

[0006] The memory management unit (MMU), also known as the storage management unit, is a hardware module specifically responsible for the processor's storage access requests. It is a relay control unit that connects the processor core to the cache and physical memory. Its main functions include virtual address to physical address conversion, storage protection, cache control, etc.

[0007] RISC-V is an open source instruction set architecture based on the principle of reduced instruction set. Its design is suitable for modern computing devices. It takes into account the reality of small, fast and low power consumption. It has the characteristics of full open source, simple architecture, easy operating system porting, modular design, complete tool chain, etc. It does not make excessive design for a specific micro-architecture and can be used to implement various customized designs and innovative explorations. The RISC-V instruction set architecture specifies three permission modes, namely machine mode (M-mode), supervisor mode (S-Mode) and user mode (U-mode). Among them, M-mode has the highest permission, S-mode has the second highest permission, and U-mode has the lowest permission.

[0008] In the related technology, a processor structure (TIMBER-V) based on the RISC-V instruction set architecture that uses tags for fine-grained storage isolation adds a 2-bit tag for every 32 bits of stored data or instructions in the memory, and combines the MMU to control the access permissions of the memory. In its solution, the original U-mode and S-mode are divided into general domains and trusted domains respectively, so the original U-mode is divided into the current "general U-mode" and "trusted U-mode" (TU-mode), and the original S-mode is divided into the current "general S-mode" and "trusted S-mode" (TS-mode). The newly added 2-bit tag has the same function as metadata (data describing data), and is used to indicate the security domain where the corresponding storage data or instruction is located. The specific security domains are divided as follows (the instruction itself is also regarded as data, so no distinction is made): the data in "general U-mode" and "general S-mode" is N-tag data, which has the lowest security; the data in TU-mode is TU-tag data, which has medium security; the data in TS-mode is TS-tag data, which has the highest security; TC-tag data is a special type of data, which is used as a call point or entry point for N-tag data to access TU-tag data or TS-tag data in the program, and also has the same highest security as TS-tag data. The only drawback is that the TIMBER-V technical solution only examines the tag at the memory end of the data access link, and lacks tracking and monitoring of the information flow of non-memory access instructions and program segments during program execution, which may have security vulnerabilities.

[0009] At the abstract level of the architecture, dynamic information flow tracking implemented by hardware mostly uses dynamic taint propagation analysis technology. The main principle of this technology is: during the program running process, the propagation of the program's taint data is monitored in real time to detect whether the taint data will affect security-sensitive operations. It is often necessary to customize the taint source, propagation rules and monitoring points according to different attack and defense scenarios. Dynamic taint propagation analysis is an effective technical solution that can determine whether the program information flow is safe, but its focus is on "certain taint data" and it tracks the propagation path of the defined taint data, which may result in underreporting when the taint data coverage is not comprehensive.

[0010] Cache invalidation technology and cache locking technology are two common technologies in cache side channel protection. Regarding cache invalidation technology, the purpose of side channel protection is mainly achieved by invalidating specific cache lines (cache lines). At this time, it is equivalent to that the specific cache line is bypassed, and the processor directly accesses the memory. Regarding cache locking technology, the purpose of side channel protection is mainly achieved by locking specific cache lines. At this time, it is equivalent to the content in the specific cache line being "solidified", and only constant cache hits (hit) and cache misses (miss) can be generated. Although the above two technologies can achieve effective side channel protection, their original cache mechanism is basically completely blocked, so their performance cost cannot be ignored. Summary of the invention

[0011] The present application provides a dynamic information flow tracking processor structure based on hardware security tags to solve the problems of lack of tracking and monitoring of the information flow of non-memory access instructions and program segments during program execution, which poses a security risk, incomplete coverage of tainted data, resulting in abnormal omissions, and a significant impact of security protection measures on the performance of the original cache mechanism.

[0012] The first aspect of the present application provides a dynamic information flow tracking processor structure based on hardware security tags, including the following steps: a processor core; a processor tag bit set on multiple registers in the processor core, used to indicate the security domain where the values ​​of the multiple registers are located; a processor core tag logic circuit set in the processor core, used to transfer the tag and check the rules of the dynamic information flow according to the tag transfer rules in the processor core; a storage module; a storage tag bit set in the storage module, used to perform storage isolation and cache isolation between different security domains.

[0013] Optionally, in an embodiment of the present application, it also includes: a memory management unit, which is arranged between the processor core and the storage module, and is used to perform storage isolation between different users in the same security domain.

[0014] Optionally, in one embodiment of the present application, the processor core tag logic circuit includes: an instruction logic circuit, configured to monitor the security of the instruction stream within the processor core to ensure the safe execution of instructions;

[0015] The data logic circuit is used to complete the label transfer calculation of each instruction and monitor the security of the data flow to ensure the safe access of data.

[0016] Optionally, in one embodiment of the present application, a 2-bit tag is set on each 64-bit wide register.

[0017] Optionally, in one embodiment of the present application, the processor core tag logic circuit is arranged on the instruction pipeline and / or data path within the processor core.

[0018] Optionally, in one embodiment of the present application, a storage tag bit is set on an instruction buffer memory inside the storage module to store a tag provided to the processor core, wherein a 2-bit tag is added to each 32-bit storage instruction.

[0019] Optionally, in one embodiment of the present application, a storage tag bit is set on the data buffer memory inside the storage module, for isolating different security domains at the cache level, wherein a 2-bit tag is added to every 32 bits of stored data, and a 1-bit tag is added to each buffer block for isolating different processes in the same security domain at the cache level.

[0020] Optionally, in one embodiment of the present application, a memory tag logic circuit is provided on the data buffer memory, and is used to control secure access to the data buffer memory.

[0021] Optionally, in one embodiment of the present application, the storage tag bit is set on the physical memory inside the storage module, wherein a 2-bit tag is added to every 32 bits of stored data or instructions.

[0022] Optionally, in one embodiment of the present application, it further includes: an exception generation module, which is arranged inside the processor core, and the exception generation module is used to generate a trigger signal and corresponding exception information when the logic circuit detects an exception.

[0023] Therefore, this application has at least the following beneficial effects:

[0024] 1) Full-process security tracking and security restrictions of data at the memory, cache and processor core levels ensure complete system security to a large extent;

[0025] 2) The fine-grained tag management method can monitor the security of each instruction and each data in real time, which is conducive to more accurate information flow tracking;

[0026] 3) Divide the program into security levels so that a compromise can be made between execution speed and security when writing the program;

[0027] 4) The tag mechanism and storage management mechanism are independent of each other and can be used in combination to achieve more complete security or higher overall efficiency;

[0028] 5) The security isolation measures introduced at the cache level have little impact on the original cache mechanism and can achieve better cache side-channel protection at a lower performance cost.

[0029] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0031] Figure 1 A structural block diagram of a dynamic information flow tracking processor based on hardware security tags provided according to an embodiment of the present application;

[0032] Figure 2 An overall structural diagram of a dynamic information flow tracking processor structure based on hardware security tags provided according to an embodiment of the present application;

[0033] Figure 3 A schematic diagram of secure tracking of data by a dynamic information flow tracking processor structure based on hardware security tags according to an embodiment of the present application;

[0034] Figure 4 A schematic diagram of secure tracking of instructions by a dynamic information flow tracking processor structure based on hardware security tags provided according to an embodiment of the present application.

[0035] Description of reference numerals: processor core-100, storage module-200. DETAILED DESCRIPTION

[0036] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0037] The following describes a dynamic information flow tracking processor structure based on hardware security tags in an embodiment of the present application with reference to the accompanying drawings. In view of the related art mentioned in the above background technology, the tag bit is only examined at the memory end of the data access link, and the information flow of non-memory access instructions and program segments during program execution lacks tracking and monitoring, resulting in possible security vulnerabilities in program operation, and abnormal omissions are prone to occur when the tainted data coverage is not comprehensive. In addition, when protecting the side channel, the original cache mechanism is basically completely shielded, and the performance loss is serious. The present application provides a dynamic information flow tracking processor structure based on hardware security tags. In this structure, by adding security-related tag bits to the registers in the processor core and the memory in the storage module, and by adding tag checking and transmission logic circuits to the processor core, real-time and efficient tracking of the information flow is achieved. In addition, by adding security-related tag bits to the data cache in the storage module, protection against side channel attacks is achieved with little performance impact. At the same time, the embodiments of the present application make full use of the newly added tag bits, divide the security level of the program, formulate the tag transfer rules within the processor core, define abnormal behaviors that may damage the security of the system, prevent side channel attacks that may use the cache, and largely ensure the standardization and security of program operation. As a result, the lack of tracking and monitoring of the information flow of non-memory access instructions and program segments during program execution has solved the problems of potential security risks, incomplete coverage of tainted data, abnormal omissions, and the significant impact of security protection measures on the performance of the original cache mechanism.

[0038] Specifically, Figure 1 A structural block diagram of a dynamic information flow tracking processor based on hardware security tags provided in an embodiment of the present application.

[0039] like Figure 1 As shown, the dynamic information flow tracking processor structure 10 based on hardware security tags includes: a processor core 100 and a storage module 200.

[0040] Specifically, the processor core 100 includes a controller, an arithmetic unit, a register group, etc. Among them, the controller is composed of an instruction register, an instruction decoder, a program counter and corresponding circuits. The arithmetic unit is composed of an arithmetic logic unit ALU (Arithmetic Logic Unit), an accumulator and a flag register. The register group usually includes general registers such as an instruction register and an address register.

[0041] Optionally, in an embodiment of the present application, the processor core 100 further includes: a processor tag bit set on a plurality of registers in the processor core 100, for indicating the security domain where the values ​​of the plurality of registers are located.

[0042] It should be understood that the embodiment of the present application adds a 2-bit tag to the registers in the processor core 100, and these additional tags are "hardware security tags". Taking into account the granularity of the data and the degree of matching with the TIMBER-V technical solution, the embodiment of the present application adds a 2-bit tag to each 64-bit wide register (including general registers visible to instructions and PC registers invisible to instructions) to indicate the security domain where the corresponding register value is located, thereby achieving finer-grained information flow tracking.

[0043] In the embodiments of the present application, Tag refers to the newly added tag bit in the embodiments of the present application.

[0044] The security domain represented by the specific value of the above 2-bit tag is defined as follows: "0b00" represents the N-tag domain, "0b01" represents the TC-tag domain, "0b10" represents the TU-tag domain, and "0b11" represents the TS-tag domain. The tags of all instructions and static data involved in the program are marked when the program is initialized, and the dynamic data that appears during the program running will be marked in real time according to the current instruction execution status. It is worth mentioning that TC-tag does not represent an actual security domain, but only serves as an entry for the safe transition from the N-tag domain to the TU-tag domain or the TS-tag domain. When the tag is transferred within the processor core 100, the tag of the TC-tag instruction will be set to TU-tag (TC-tag is the entry of TU-tag at this time) or TS-tag (TC-tag is the entry of TS-tag at this time) according to the tag of the next sequential instruction. In other words, the TC-tag tag will not actually appear during the process of tag transfer within the core.

[0045] Optionally, in an embodiment of the present application, the processor core 100 further includes: a processor core 100 label logic circuit disposed in the processor core 100, for performing label delivery and rule checking on dynamic information flows according to label delivery rules in the processor core 100.

[0046] It should be understood that the above-mentioned label transfer rules include data-oriented label transfer rules and control-oriented label transfer rules. The embodiment of the present application performs dynamic information flow tracking based on the RISC-V RV64I instruction set, analyzes the impact of each instruction in the instruction set on the flow of information, and then adapts the tracking-related logic circuit based on the label transfer rule for each instruction according to the analysis results.

[0047] It should be noted that the embodiments of the present application perform dynamic information flow tracking at the instruction set level, which belongs to the architectural level of abstraction. Gate-level abstraction and other abstraction levels are not yet involved in this application.

[0048] In order to facilitate the understanding of the tag transfer rules, the embodiments of the present application first divide the instructions in the instruction set into three categories: the first category of instructions are instructions that only access the registers in the core (category I instructions), including integer calculation instructions and control transfer instructions; the second category of instructions are instructions that need to access the external memory (category II instructions), specifically load (Load) and store (Store) instructions; the third category of instructions are instructions that neither access the registers in the core nor the external memory (category III instructions), including storage sequencing instructions and some system instructions. At the same time, the present application stipulates that the tag of the immediate operand in the instruction is the same as the tag of the instruction itself.

[0049] The specific rules for data-oriented label transmission are as follows:

[0050] 1) For integer calculation instructions in Class I instructions, the source operand is an immediate number or a general register, and the destination operand is only a general register. The tag transfer rule is: "The tag of low-security data is dominant, and the tag of the instruction does not affect the tag of the data", that is, when high-security data and low-security data are calculated to generate output data, the tag of the output data is marked as the tag of the low-security data, and the tag of the instruction itself does not affect the tag of the output data.

[0051] 2) For control transfer instructions in Class I instructions, the source operand is an immediate number or a general register. Since the transfer behavior generated by the instruction can be regarded as rewriting the value of the PC register, the destination operand is the PC register or a general register. Among them, when the destination operand is the PC register, the label transfer rule is "the tag of the low-security data or instruction is dominant", that is, whether it is to determine whether to generate a transfer behavior by comparing two data or directly generating a transfer behavior, the PC tag must be determined based on the tag of the instruction itself, and the tag with the lowest security indicated is taken as the PC tag. When the destination operand is a general register, the label transfer rule is "the tag of the low-security instruction is dominant", that is, if the security of the instruction is lower than that of the target instruction, the tag of the register is the tag of the instruction, otherwise it is the tag of the target instruction.

[0052] 3) For Class II instructions, the source operand is an immediate number or a general register, and the destination operand is only a general register. Although its form is similar to the integer calculation instructions in Class I instructions, the data it actually needs to access is located in the off-core memory, so there will be memory access operations that are different from integer calculation instructions; the tag passing rules related to immediate numbers and registers are similar to integer calculation instructions, and the tag passing rules related to memory are "the tag can be passed normally when the security of the memory access address or instruction is not lower than the security of the memory access data", that is, Load and Store instructions need to first derive the tag of the memory access address based on the tag of the immediate number and the tag of the register, and then combine the tag of the instruction itself to determine whether the tag of the memory access data can be passed normally. The corresponding memory access operation can be performed when the lowest security indicated by the two is not lower than the security indicated by the tag of the memory access data.

[0053] 4) For Class III instructions, since they do not affect the in-core registers and out-of-core memory, there are no label transfer rules.

[0054] like Figure 2 As shown, the structure of the internal pipeline of the processor core 100 is shown, and the location of the tag and tag logic in the data path is indicated. Figure 2 In the example, a Tag logic is added next to the general logic such as ALU and LSU to complete the tag transfer calculation of each instruction and monitor the security of the data flow to ensure the safe access of data. This Tag logic is mainly a specific circuit implementation of the above-mentioned data-oriented tag transfer rules and the following memory access rules.

[0055] The above-mentioned tag transfer rules are all data-oriented tag transfer rules, that is, the focus is on the impact of the function of the instruction itself on the register and memory. The focus of the control-oriented tag transfer rules is on the execution order between instructions. Specifically, in the processor core 100, the tag logic will maintain a tag representing the instruction execution status of the processor core 100, that is, the tag of the PC register, which is independent of the tag of the fetched instruction. Its tag transfer rule is "the security of the current instruction is generally the same as the security of the next instruction. The current instruction with low security can be transferred to the next instruction with high security through the next TC-tag instruction, and the current instruction with high security can be directly transferred to the next instruction with low security", that is, the security indicated by the tag of the current instruction shall not be lower than the security indicated by the tag of the next instruction, unless the TC-tag instruction is used to transition from the low security domain to the high security domain, and the tag of the PC register is compared with the tag of the fetched instruction itself. Only when the above conditions are met can the tag of the PC register be updated to the tag of the fetched instruction itself. It should be noted that the calculation result of the control transfer instruction in the I-type instruction can change the value of the PC register, but it is also within the scope of the label transfer rule.

[0056] For example, Figure 2 As shown in the figure, a 2-bit tag is added to each 64-bit wide PC register and general register to indicate the security domain of the data therein; a tag logic is added next to the instruction fetch unit to monitor the security of the instruction stream and ensure the safe execution of instructions. This tag logic is mainly a specific circuit implementation of the above-mentioned control-oriented tag transfer rules and the following execution rules.

[0057] It should be noted that the tag of the PC register may be updated by the tag logic next to the instruction fetch unit (sequential execution) or by the execution result of the control transfer instruction (transfer execution). In fact, the PC register and its tag are updated almost at the same time, but Figure 2 The flag for updating the PC register is omitted. The tag of the general register can only be updated by the write-back operation of the instruction. The tag value written back is calculated by the tag logic next to the general logic. In fact, the general register and its tag are updated almost at the same time, but Figure 2 The flags for updating general registers are omitted.

[0058] Optionally, in an embodiment of the present application, the tag logic circuit of the processor core 100 includes: an instruction logic circuit for monitoring the security of the instruction flow in the processor core 100 to ensure the safe execution of the instruction; a data logic circuit for completing the tag transfer calculation of each instruction and monitoring the security of the data flow to ensure the safe access of the data. In the specific execution process, the tag logic circuit of the embodiment of the present application can be set on the instruction pipeline and / or data path in the processor core 100.

[0059] It is understandable that the information flow mentioned in the embodiments of the present application specifically refers to the information flow of the processor program running covered by the narrow information flow, and the structure of the embodiments of the present application is only for dynamic information flow tracking, and does not involve static information flow tracking. The dynamic information flow tracking processor structure described in the embodiments of the present application is a dynamic information flow tracking implemented by hardware. Compared with the dynamic information flow tracking implemented by software, the dynamic information flow tracking implemented by hardware has the advantages of fast tracking speed and high processing authority. It can use a dedicated logic circuit to implement tracking without adding redundant code, and has greater freedom to take preventive measures after discovering malicious attacks. Therefore, the embodiments of the present application add a logic circuit (Tag logic) specifically used for processing Tags to the instruction pipeline and data path in the processor core 100, which needs to be responsible for the tag transfer and rule checking of the tag in the core according to the tag transfer rules in the core.

[0060] It can be understood that, based on the TIMBER-V technical solution, the embodiments of the present application add tags inside the processor to track the information flow of the entire process. On the one hand, security issues in the execution of non-memory access instructions can be discovered; on the other hand, tag information can be used to more accurately perform security protection and improve the energy efficiency of the operation of the security mechanism. At the same time, it adopts an idea similar to dynamic taint propagation analysis, and also tracks the flow path of information based on certain propagation rules, but the focus is on the "entire system" rather than "certain data". It tracks the information transmission of the entire system with security domain divisions, focusing on whether there is unreasonable cross-security domain information flow behavior during system operation, and has a high degree of completeness.

[0061] In addition, the dynamic information flow tracking processor structure proposed in the embodiment of the present application also includes a storage module 200, Figure 2 The storage structure of the storage module 200 is shown in FIG. Figure 2 As shown, the storage module 200 generally includes: a main memory, namely a physical memory, and a cache memory Cache, etc., wherein the cache memory Cache is separated into an instruction cache (ICache) and a data cache (DCache), and the position of the Tag therein is indicated.

[0062] Optionally, in an embodiment of the present application, the storage module 200 further includes: a storage tag bit set in the storage module 200, for performing storage isolation and cache isolation between different security domains.

[0063] Optionally, in an embodiment of the present application, the storage tag bit is set on the instruction buffer memory inside the storage module 200, for storing the tag provided to the processor core 100, wherein a 2-bit tag is added to each 32-bit storage instruction.

[0064] Specifically, ICache is dedicated to caching instructions, in which a 2-bit tag is added to each 32-bit storage instruction. The tag bits added here are only used to temporarily store the tags that need to be provided to the processor core 100. No other security circuits that operate on the tags are added to the ICache.

[0065] Optionally, in an embodiment of the present application, a storage tag bit is set on the data buffer memory inside the storage module 200, which is used to isolate different security domains at the cache level, wherein a 2-bit tag is added to every 32 bits of storage data, and a 1-bit tag is added to each buffer block for isolating different processes in the same security domain at the cache level.

[0066] It should be noted that the present application introduces the tag-based security domain isolation mechanism into the data cache, which is dedicated to data caching. In the data cache, a 2-bit tag is added for every 32 bits of cache data. The specific meaning of this 2-bit tag is the same as the specific meaning of the register tag in the processor core 100, that is, it is used for isolation between different security domains. A 1-bit tag TV-tag is added to each cacheline to achieve mutual isolation between different processes in the same security domain (TU-tag) at the cache level. In addition, a tightly coupled Tag logic is added to the DCache to control secure access to the DCache. The TV-tag only acts on the TU-tag security domain, and program segments in other security domains are not affected by the TV-tag.

[0067] Among them, the TV-tag label is used to indicate whether the corresponding cacheline is valid for the currently running TU-tag process, that is, it is invalid when the value is 0 and valid when the value is 1; if the currently running TU-tag process accesses a cacheline, if the corresponding TV-tag label is 0, it means that the process is accessing this cacheline for the first time during this operation, so a miss access is generated, and the TV-tag is set to 1 after the access is completed; if the corresponding TV-tag label is 1, it means that this process is not accessing this cacheline for the first time during this operation, so a normal access is generated (hit or miss is generated depending on whether the required data exists in the cacheline); when the TU-tag process is interrupted or its normal operation ends, the TV-tag labels of all cachelines are reset to 0.

[0068] In short, this additional TV-tag label is similar to the original valid bit in the cache structure, but the difference is that the valid bit is "global" (that is, all processes share the valid bit), while the TV-tag label is "local" (that is, each TU-tag process has its own TV-tag label).

[0069] Optionally, in an embodiment of the present application, a memory tag logic circuit on the data buffer memory is used to control secure access to the data buffer memory.

[0070] Specifically, the cache access of program segments with different security levels is described as follows: when the Load / Store instruction of a low-security program accesses a cacheline that has just been used by a high-security program, even if its identification bit can be matched, a miss will occur because the total security of the memory access instruction is lower than the security of the corresponding cacheline. At this time, the information left by the high-security program in the cache is not leaked to the low-security program, and the direction of the security information flow is not violated; when the Load / Store instruction of a high-security program accesses a cacheline that has just been used by a low-security program, if its identification bit can be matched, and because the total security of the memory access instruction is not lower than the security of the corresponding cacheline, this cache access can generate a hit, which is in line with the direction of the security information flow.

[0071] In summary, the newly added "hardware security tag" in the data cache implements the security domain isolation mechanism at the cache level, and performs security domain isolation between low-security program segments and high-security program segments, and between each TU-tag process, without causing a major impact on the original cache mechanism.

[0072] Optionally, in an embodiment of the present application, the storage tag bit is set on the physical memory inside the storage module 200, wherein a 2-bit tag is added to every 32 bits of stored data or instructions.

[0073] It should be noted that in the memory end of the embodiment of the present application, the physical memory uses the storage structure and isolation method of TIMBER-V, that is, every 32 bits of stored data or instructions have 2 extra tags, but the added circuit for security isolation is not drawn in the attached figure. Different security domains are isolated by extra tags, and different user processes in the same security domain are isolated by MMU.

[0074] Through the above-mentioned embodiments, the hardware circuit of the embodiment of the present application mainly includes two modules: a processor core 100 and a storage module 200, and also includes a relay control unit MMU as a processor core 100 and a storage module 200. Figure 2 As shown. This unit is a hardware module specifically responsible for the processor's storage access request. It is a relay control unit that connects the processor core to the cache and physical memory. Its main functions include virtual address to physical address conversion, storage protection, cache control, etc. When the processor core 100 accesses storage through the MMU memory access interface, and when the storage module 200 responds to the processor core 100's memory access request through its memory access interface, both need to be controlled by the MMU. In addition, the MMU also undertakes part of the physical memory security isolation work.

[0075] Optionally, in an embodiment of the present application, it also includes: an exception generation module, which is arranged inside the processor core 100, and the exception generation module is used to generate a trigger signal and corresponding exception information when the logic circuit detects an exception.

[0076] It should be noted that this application defines a series of security rules for data and instruction tags. Behaviors that violate security rules are defined as abnormal behaviors. If abnormal behaviors occur, it means that there may be operations that undermine the security of the system. At this time, certain measures need to be taken to prevent them.

[0077] Specifically, the defined security rules include execution rules and memory access rules. The former are rules about instruction execution, and the latter are rules about memory data access. The corresponding violations are called abnormal execution and abnormal memory access.

[0078] The specific implementation rules are as follows:

[0079] 1) A certain instruction → an instruction with the same security as “a certain instruction”;

[0080] 2) Low-security instruction → TC-tag instruction → high-security instruction;

[0081] 3) High security instructions → low security instructions.

[0082] During the instruction execution process of the processor, a low-security instruction needs to execute an instruction tagged with TC-tag first to become a high-security instruction. Conversely, if a "low-security instruction (without TC-tag instruction) → high-security instruction" appears, the security of the program running fragment is improved without going through the trusted entry point. This behavior violates the security execution rules. Specifically, the tag of the PC register cannot be updated according to its tag transfer rules and is defined as abnormal execution.

[0083] The specific memory access rules are as follows:

[0084] 1) Certain data → A security domain with the same security as “certain data”;

[0085] 2) Low security data → high security domain.

[0086] Information can only flow between security domains with the same security or from a low security domain to a high security domain. If the "overall security of the Load / Store instruction (generated after comparison of the security of the memory access address and the security of the instruction itself) is lower than the security of the accessed data", that is, a low-security instruction accesses high-security data, this behavior violates the security access rules. Specifically, the tags involved in the Class II instructions fail to be updated according to their tag transfer rules and are defined as abnormal memory access. In the hardware circuit, the processor's instruction fetch unit and the tag logic of the memory access unit (LSU) will check the above two security rules. When abnormal execution or abnormal memory access is detected, the corresponding operation will be refused to execute and an "exception" will be triggered at the same time. The programmer can define the handling measures in the exception handler.

[0087] The working process of a dynamic information flow tracking processor structure based on hardware security tags of the present application is described in detail below through a specific embodiment.

[0088] Figure 3 Schematic diagram of secure data tracking by a dynamic information flow tracking processor structure based on hardware security tags. Figure 3 Omitted Figure 2 Most of the structures in the diagram have little impact on data flow tracking, showing the specific process of hardware circuits to track data safely. Figure 3As shown, first, data A is read into the general register A of the processor core 100 through the Load instruction, and the corresponding Tag is also read into the processor core 100 from the storage module 200; in the process of data A entering the processor core 100 through the memory access interface, its Tag will be checked by the Tag logic according to the security rules to determine whether the Load is safe. Secondly, the data in the general register A is calculated in various ways through the general logic, and the final calculation result is stored in the general register B; at the same time, the corresponding Tag is also calculated according to the tag transfer rule through the Tag logic, and the final calculation result is stored in the Tag bit of the general register B. Finally, the data B in the general register B is written into the physical memory through the Store instruction, and the corresponding Tag is also written into the storage module 200 from the processor core 100; in the process of data B entering the storage module 200 through the memory access interface, its Tag will be checked by the Tag logic according to the security rules to determine whether the Store is safe. If the tag logic detects an unsafe operation in the above process, it will provide a trigger signal and corresponding exception information to the exception generation module, and then the exception generation module will cause the processor core 100 to generate an exception.

[0089] Figure 4 Schematic diagram of secure tracking of instructions by a dynamic information flow tracking processor architecture based on hardware security tags. Figure 4 Omitted Figure 2 Most of the structures in the code have little impact on instruction flow tracking, showing the specific process of hardware circuits to track instructions safely. Figure 4 As shown, from Figure 4 Starting from the black dot on the PC register, the PC decoding first finds the location of instruction A and its Tag in the physical memory, and then fetches instruction A and its Tag at the same time. Instruction A is sent to the general logic in the processor core 100 and its Tag is sent to the Tag logic. Next, according to the tag transmission rule, combined with the tag of the PC register maintained by the processor core 100 itself, the Tag logic will perform a security check on this instruction fetch. If the security check passes, the tag of the PC register will be updated. After that, the general logic can calculate and generate the next PC based on the instruction fetched, and the generated new PC can find the location of instruction B and its Tag in the physical memory through decoding, so the program continues to run according to the above steps. If the Tag logic detects an unsafe operation in the above process, it will provide a trigger signal and corresponding exception information to the exception generation module, and then the exception generation module will cause the processor core 100 to generate an exception.

[0090] According to a dynamic information flow tracking processor structure based on hardware security tags proposed in the embodiment of the present application, by adding security-related tag bits to the registers in the processor core and the memory in the storage module, adding tag checking and transmission logic circuits to the processor core, and adding security-related tag bits to the data cache in the storage module, the security level of the program is divided, the tag transmission rules in the processor core are formulated, and abnormal behaviors that may damage the security of the system are defined. Thus, the information flow of the program running is tracked quickly and efficiently in real time using tags to immediately discover potential malicious operations and attacks that damage the security of the system. At the same time, the tags are also used to improve the security isolation mechanism of the data cache, and better cache side channel protection is achieved at a relatively low performance cost, ensuring the standardization and security of program operation.

[0091] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0092] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0093] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.

[0094] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above embodiment, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0095] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

Claims

1. A dynamic information flow tracking processor structure based on a hardware security label, characterized in that, it includes: a processor core; processor label bits set on multiple registers within the processor core, used to represent the security domains where the values of the multiple registers are located; a processor core label logic circuit set within the processor core, used to perform label transfer and rule checking on the dynamic information flow according to the label transfer rules within the processor core; a storage module; storage label bits set within the storage module, used to perform storage isolation and cache isolation between different security domains; wherein, the storage label bits are set on the data buffer memory within the storage module, used to isolate different security domains at the cache level, wherein, 2 bits of labels are added to every 32-bit storage data, and 1 bit of label is added to each buffer block for isolating different processes within the same security domain at the cache level; The dynamic information flow tracking processor structure based on a hardware security label further includes: a memory label logic circuit set on the data buffer memory, used to control secure access to the data buffer memory.

2. The structure according to claim 1, characterized in that, it further includes: a memory management unit, set between the processor core and the storage module, used to perform storage isolation between different users within the same security domain.

3. The structure according to claim 1, characterized in that, the processor core label logic circuit includes: an instruction logic circuit, used to monitor the security of the instruction flow within the processor core to ensure the secure execution of instructions; a data logic circuit, used to complete label transfer calculations for each instruction and monitor the security of the data flow to ensure the secure access of data.

4. The structure according to claim 1, characterized in that, wherein, 2 bits of labels are set on each 64-bit wide register.

5. The structure according to claim 1, characterized in that, the processor core label logic circuit is set on the instruction pipeline and / or data path within the processor core.

6. The structure according to claim 1, characterized in that, the storage label bits are set on the instruction buffer memory within the storage module, used to store the labels provided to the processor core, wherein, 2 bits of labels are added to every 32-bit storage instruction.

7. The structure according to claim 1, characterized in that, the storage label bits are set on the physical memory within the storage module, wherein, 2 bits of labels are added to every 32-bit storage data or instruction.

8. The structure according to any one of claims 1-7, characterized in that, it further includes: an exception generation module, set within the processor core, the exception generation module is used to generate a trigger signal and corresponding exception information when the logic circuit detects an exception.

Citation Information

Patent Citations

  • Information flow tracking model generation method of a programmable logic device

    CN109492337A

  • Hardware security vulnerability detection method based on gate-level pollution label tracking model

    CN112650638A

Cited By

  • Remote certification and verification method for data destruction

    CN121786892A