Method for relieving GPU instruction electromagnetic side channel leakage
By decomposing the loops in the GPU execution task and allowing the thread bundle to randomly execute different loops, the electromagnetic side channel leakage problem caused by the difference in GPU instruction execution is solved, effectively alleviating the electromagnetic side channel leakage and maintaining GPU performance.
Patent Information
- Application Number
- CN202510006895.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art cannot effectively alleviate electromagnetic side channel leakage caused by differences in GPU instruction execution, especially under multi-threaded execution, SAVAT metrics cannot be directly applied to GPUs, and there is a lack of mitigation methods for GPU architecture and microarchitecture levels.
A method for mitigating the electromagnetic side channel leakage of GPU instruction is proposed. By dividing a loop in the execution task of the target GPU into n different loops, each loop contains a different number of instruction pairs, and allowing different thread bundles to randomly execute different loops during program execution to weaken the strong electromagnetic signal at a single frequency point.
This method effectively reduces the detectability of electromagnetic signals and reduces the difficulty of electromagnetic side channel attacks without affecting the performance of GPUs. It provides an effective method to alleviate electromagnetic side channel leakage from the GPU architecture and micro architecture levels.
Smart Images

Figure CN119939679A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a method for alleviating electromagnetic side channel leakage of GPU instructions. Background Art
[0002] With the widespread use of GPUs and applications in areas such as high-performance computing, deep learning, and large language models that often process sensitive data, the accompanying security issues have become increasingly important. Side channel attacks have been shown to pose a huge security threat, among which electromagnetic (EM) side channel attacks are particularly worrying because they are non-invasive and can bypass traditional security checks. Changes in electronic current caused by program execution generate electromagnetic radiation. Each active component in a device generates and senses different types of electromagnetic radiation. These signals contain information about program activity within the system and provide multiple perspectives on events occurring within the device. If a specific instruction or event carries sensitive information, the emitted electromagnetic waves can be captured and analyzed by potential attackers, resulting in the leakage of sensitive information.
[0003] In the CPU field, the paper "R. Callan, A. Zajic, and M. Prvulovic, "A practical methodology for measuring the side-channel signal available to the attacker for instruction-level events," in 201447th Annual IEEE / ACM International Symposium on Microarchitecture, 2014, pp. 242–254" proposed a metric called SAVAT, which was originally designed to understand and quantify the severity of potential microarchitecture-level instruction-level EM side channel vulnerabilities. The SAVAT measurement method is as follows Figure 1 As shown, Figure 1The first line in the code is used to store the instruction base address calculation, which ensures that the addressing is not out of bounds and is spaced; the second to fifth lines are core codes used to generate target signals, and execute instruction A first, then instruction B, because the difference in the execution of instructions will generate a target signal. This method directly measures the difference between instructions A and B by creating an activity pattern (① and ②) in which instructions A and B are executed alternately. Then, by iteratively executing the above stages (③), a periodic electromagnetic signal is generated, that is, an electromagnetic side channel signal generated due to the difference in instruction execution, also known as a target signal. The frequency of the target signal (f = 1 / T) is determined by the execution time T of each stage. The total power (energy / second) of the periodic signal divided by the number of instruction pairs per second represents the energy of a single instruction pair due to execution differences, which is how the SAVAT value is measured.
[0004] However, there is currently no research that can propose a mitigation method at the instruction level from the GPU architecture and microarchitecture level to quantitatively understand, analyze and mitigate potential electromagnetic side channel exposure. This is of great help in clearly and intuitively understanding and analyzing what information electromagnetic signals can leak and the potential sources of leakage. It can allow designers and programmers to identify which vulnerabilities are more likely to be exploited by attackers, and then propose better EM side channel mitigation techniques.
[0005] The original SAVAT metric is only designed to measure the difference in electromagnetic signals at the instruction level in a single-threaded CPU architecture. In contrast, GPUs are multi-core, multi-threaded architectures with massively parallel computing throughput. Therefore, SAVAT cannot be directly used to evaluate the electromagnetic leakage of GPU instructions under multi-threaded execution. Therefore, the calculation formula of the SAVAT metric and some definitions of the metric are not applicable to GPUs. In addition, the original SAVAT work uses far-field probes, which are not applicable to the more subtle micro-architecture-level electromagnetic leakage of the GPU hardware structure, so the original measurement hardware of the SAVAT metric is not universal. So in summary, the original SAVAT metric cannot provide direct help in proposing a method to mitigate EM side channel leakage at the instruction level on the GPU from the GPU architecture and micro-architecture level. More importantly, the original SAVAT work did not propose an effective solution to mitigate this EM leakage. Summary of the invention
[0006] In view of the lack of methods in the prior art that can mitigate electromagnetic side channel leakage caused by execution differences of GPU instructions at the instruction level from the architecture and micro-architecture level of the GPU, and the problem that the SAVAT metric applicable to the CPU cannot be directly used to guide the evaluation and mitigation of electromagnetic side channel leakage on the GPU under multi-threaded execution, the present invention proposes a mitigation method for electromagnetic side channel leakage of GPU instructions, and adaptively expands SAVAT for GPU, namely SAVAT-GPU metric, which is further used to discover potential EM side channel leakage points and evaluate the effectiveness of the mitigation method.
[0007] In order to solve the above technical problems, the present invention adopts the following technical solutions:
[0008] A method for mitigating electromagnetic side channel leakage of GPU instructions, the method comprising the following steps:
[0009] Step 1: Divide a loop in the execution task of the target GPU into n different loops, each loop contains a different number of instruction pairs in one iteration, corresponding to different execution time and target frequency, and ensures that the total number of instructions executed remains unchanged;
[0010] Step 2: During program execution, different thread warps are allowed to enter different loops for execution according to the calculated thread warp IDs, which specifically includes the following steps:
[0011] Step 2.1: Generate a random number m using a linear congruential generator through the first thread of each thread warp and broadcast it to the entire thread warp;
[0012] Step 2.2: According to the random number m, let all threads in the same thread warp recalculate the thread warp ID;
[0013] Step 2.3: Based on the calculated thread warp ID, the thread warp randomly executes one of the n loops until all threads are executed.
[0014] The method for mitigating electromagnetic side channel leakage caused by GPU instruction execution differences proposed in the present invention can weaken strong electromagnetic signals at a single frequency point by randomly assigning all instruction pairs to multiple frequency points at the thread bundle level, thereby reducing the detectability of the electromagnetic signal. The results of evaluating the effectiveness of the mitigation method show that the mitigation method effectively reduces the electromagnetic signal without affecting the performance of the GPU, and therefore can effectively mitigate electromagnetic side channel attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a flow chart of the SAVAT measurement method in the prior art;
[0016] Figure 2A flowchart of a method for mitigating electromagnetic side channel leakage of GPU instructions according to an embodiment of the present invention;
[0017] Figure 3 A comparison diagram of the signal-to-noise ratio values of several representative instruction pairs divided into different numbers of frequency points according to the mitigation method of the present invention;
[0018] Figure 4 A comparison diagram of the electromagnetic side channel signal suppression effect of the mitigation method of the present invention on several representative instruction pairs;
[0019] Figure 5 This is a comparison chart of the impact of the mitigation method of the present invention on GPU performance. DETAILED DESCRIPTION
[0020] The technical solution of the present invention will be described in detail below in conjunction with the accompanying drawings and preferred embodiments.
[0021] In one of the embodiments, the present invention proposes a method for mitigating electromagnetic side channel leakage caused by differences in GPU instruction execution, namely, the SPLEM algorithm, which is used to mitigate excessive electromagnetic signals at a single frequency point. The SAVAT metric is expanded according to the characteristics of the GPU, and the SAVAT-GPU metric is constructed to discover potential EM side channel leakage points and evaluate the effectiveness of the SPLEM algorithm. At the same time, the change in the number of cycles executed by the program is used to analyze the impact of the SPLEM algorithm on GPU performance, and the SNR metric is introduced to characterize the difficulty of an attacker launching an EM electromagnetic side channel attack and the effectiveness of the SPLEM algorithm.
[0022] In the electromagnetic side channel signal leakage model caused by the difference in GPU instruction execution, the electromagnetic signals generated by the differences in all instruction pairs are at one frequency point (that is, the time required to execute all instructions in one iteration of the loop corresponds to the frequency point of the signals generated by the differences in instruction execution, and all instruction pairs are in the same loop), resulting in the signal at this frequency point being too strong and vulnerable to electromagnetic side channel attacks. The SPLEM algorithm can perform loop decomposition in the code writing stage or the compilation stage. Specifically, Figure 2 As shown, the method for mitigating electromagnetic side channel leakage of GPU instructions proposed in this embodiment includes the following steps:
[0023] Step 1: Divide a loop in the execution task (i.e., kernel function) of the target GPU into n different loops, each loop contains a different number of instruction pairs in one iteration, these instruction pairs correspond to different execution times and target frequencies, and ensure that the total number of executed instructions remains unchanged;
[0024] Step 2: During program execution, different thread warps are allowed to enter different loops for execution according to the calculated thread warp IDs, which specifically includes the following steps:
[0025] Step 2.1: Generate a random number m using a linear congruential generator through the first thread of each thread warp and broadcast it to the entire thread warp;
[0026] Step 2.2: According to the obtained random number m, all threads in the same warp are asked to recalculate the warp ID (ie, warp_id). For example, the warp ID may be calculated by adding the original warp ID to the random number m.
[0027] Step 2.3: Based on the calculated thread warp ID, the thread warp randomly executes one of the n loops until all threads are executed.
[0028] In this embodiment, the SPLEM algorithm first divides a loop in a multi-threaded execution task of the target GPU into n different loops, each loop containing a different number of instruction pairs in one iteration, corresponding to different execution times and target frequencies. The total number of instructions executed remains unchanged to ensure execution correctness. In this way, each loop has a different target frequency, which is determined by the execution time of one iteration. Then, the thread bundles are assigned to different loop executions during program execution. Specifically, when the thread bundles are assigned to different loop executions, a random number m is first generated by the first thread of each thread bundle using a linear congruential generator (LCG) and broadcast to the entire thread bundle. Then the thread bundle ID is recalculated, and then according to the thread bundle ID, the thread bundle randomly executes one of the n loops until all threads are executed. The SPLEM algorithm can be implemented by application developers in the program source code or during program compilation.
[0029] Furthermore, after step 2, the effectiveness of the mitigation method is evaluated:
[0030] Step 3.1: Based on the existing SAVAT index, the SAVAT-GPU metric is constructed according to the GPU characteristics. The SAVAT-GPU metric uses a near-field measurement method different from SAVAT and considers the cumulative effect of GPU multi-threading to measure the electromagnetic side channel leakage before and after the SPLEM algorithm is used. The calculation formula of the SAVAT-GPU metric is:
[0031] SAVAT-GPU=[∑ Freq-band Signal(x)]·T measured (1)
[0032] Where SAVAT-GPU represents the total energy of the target signal; Signal(x) represents the signal power at frequency point x; Freq-band represents the frequency band; ∑ Freq-band Signal(x) represents the power value of each frequency point accumulated within the frequency band to simulate the integration process of the signal curve within the frequency band, thereby calculating the total power of the target signal; T meassured Represents the time window within the frequency band in which the target signal is measured.
[0033] Step 3.2: Next, the target signal generated by the GPU instruction when the target GPU is executing the task is measured using the near-field probe, and the corresponding SAVAT-GPU metric index value is calculated according to formula (1), and then the threat level of electromagnetic side channel leakage generated by the difference in GPU instruction execution when the target GPU is executing the task is evaluated according to the obtained SAVAT-GPU metric index value. Optionally, the near-field probe can be a SIGLENT SRF5030T20mm H-field near-field probe of the SIGLENT SSA 3075X PLUS spectrum analyzer.
[0034] This embodiment designs and constructs a new SAVAT-GPU metric. The calculated SAVAT-GPU metric value of the target signal is accumulated by the differences when all instruction pairs are executed. Therefore, the SAVAT-GPU metric value shows the aggregation of electromagnetic signals at a frequency point during the execution of the instruction pair, thereby achieving more accurate quantitative measurement and evaluation of GPU side channel electromagnetic leakage from the GPU architecture and microarchitecture level. The SPLEM algorithm randomly distributes the target signal to multiple frequency points, while the total signal energy remains unchanged, so that the SAVAT-GPU metric value at each target frequency point can be reduced to a level that is difficult to detect.
[0035] Furthermore, the signal-to-noise ratio (SNR) indicator is used to quantify the difference between the target signal and the background noise signal, and the SNR indicator can be used to measure the difficulty of the attacker to distinguish and measure the target signal from the spectrum, that is, the difficulty of launching an EM side channel attack, and the mitigation effect of the SPLEM algorithm. Specifically, after the corresponding target signal generated by the GPU instruction of the target GPU after the mitigation method is adopted is measured by the near-field probe, the following steps are performed:
[0036] Step 4.1: Calculate the signal-to-noise ratio (SNR) between the measured target signal and the background noise signal. The calculation formula is as follows:
[0037]
[0038] Among them, P targetis the target signal power, P noise is the noise floor signal power, Δt is the target signal measurement time (consistent with the noise floor signal measurement time), SAVAT-GPU target is the SAVAT-GPU metric value of the target signal, SAVAT-GPU noise is the SAVAT-GPU metric value of the background noise signal;
[0039] Step 4.2: Measure the mitigation effect of the mitigation method according to the calculated SNR index value.
[0040] The SNR calculation formula shown in formula (2) extends the traditional SNR calculation method to multiply by the same time duration Δt, which is the time that the spectrum analyzer captures the target signal and the background noise at the same time (the time taken to capture the target signal and the background noise is the same, Δt). Therefore, the SNR index value is the ratio of the SAVAT-GPU metric value of the target signal to the SAVAT-GPU metric value of the background noise signal. Taking SNR=1 as the benchmark, in this case, the target signal and the background noise signal completely overlap and cannot be distinguished. The closer the SNR value is to the benchmark, the more difficult it is to measure the target signal.
[0041] The present invention also carried out a measurement experiment, and the results of the measurement experiment are as follows Figure 3-Figure 5 shown.
[0042] Figure 3 The signal-to-noise ratio (SNR) values of several representative instruction pairs divided into different numbers of frequency points are shown, and the standard deviation of all frequency points is also shown. On average, the SNR values divided into 1, 2, 3 and 4 frequency points are 2.19, 1.43, 1.22 and 1.07, respectively. For all instruction pairs, when the signal is scattered at 4 frequency points, the SNR value does not exceed 10% of the baseline, and the target signal and background noise are very close at this time. Therefore, it can be concluded that as long as the SNR value does not exceed 10% of the baseline, it is difficult for the attacker to collect enough valuable signals. This also verifies that the present invention is very effective in alleviating electromagnetic side channel leakage caused by differences in the execution of GPU instructions, making it extremely difficult to collect target signals and extremely difficult for attackers to launch electromagnetic side channel attacks.
[0043] Figure 4The electromagnetic side channel signal suppression effect of the mitigation method of the present invention on several representative instruction pairs is demonstrated. The results of SAVAT-GPU are averaged over all frequency points and then normalized to the baseline SAVAT-GPU when dividing a frequency point. The standard deviation of all frequency points is also shown. When a loop is divided into more loops (i.e., more frequency points), the SAVAT-GPU metric value of each frequency point will become smaller. Typically, the SAVAT-GPU metric value of each frequency point is approximately the original SAVAT-GPU metric value divided by the number of divided loops.
[0044] Finally, the present invention further evaluates the impact of the mitigation method of the present invention on GPU performance based on the number of program execution cycles, where the number of execution cycles is obtained using Nvidia's performance monitoring tool, Nsight Compute. Figure 5 The impact of the mitigation method of the present invention on GPU performance is shown by the normalized program execution cycle relative to the baseline. Overall, the mitigation method of the present invention has no significant impact on GPU performance. On average, the execution time is 100.13%, 99.09% and 100.18% of the baseline when divided into 2, 3 and 4 frequency points, respectively. This is because SPLEM does not change the total number of instructions or the control flow at the thread warp level in all loops. Other changes have minimal impact on overall performance.
[0045] The method for mitigating electromagnetic side channel leakage of GPU instructions proposed in this embodiment can weaken strong electromagnetic signals by randomly assigning all instruction pairs to multiple frequency points at the thread warp level, thereby reducing the detectability of electromagnetic signals. The results of evaluating the effectiveness of the mitigation method show that the mitigation method effectively reduces electromagnetic signals without affecting the performance of the GPU, and therefore can effectively mitigate electromagnetic side channel attacks.
[0046] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0047] The above-mentioned embodiments only express several implementation methods of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
Claims
1. A method for mitigating electromagnetic side channel leakage of GPU instructions, characterized in that: The following steps are involved: Step 1: Divide a loop in the execution task of the target GPU into n different loops, each loop contains a different number of instruction pairs in one iteration, corresponding to different execution time and target frequency, and ensures that the total number of instructions executed remains unchanged; Step 2: During program execution, different thread warps are allowed to enter different loops for execution according to the calculated thread warp IDs, which specifically includes the following steps: Step 2.1: Generate a random number m using a linear congruential generator through the first thread of each thread warp and broadcast it to the entire thread warp; Step 2.2: According to the random number m, let all threads in the same thread warp recalculate the thread warp ID; Step 2.3: Based on the calculated thread warp ID, the thread warp randomly executes one of the n loops until all threads are executed.
2. A method for mitigating electromagnetic side channel leakage of GPU instructions according to claim 1, characterized in that: After step 2, the effectiveness of the mitigation method is evaluated: Step 3.1: Construct a SAVAT-GPU metric. The calculation formula of the SAVAT-GPU metric is: SAVAT-GPU=[∑ Freq-band Signal(x)]·T measured (1) Where SAVAT-GPU represents the total energy of the target signal; Signal(x) represents the signal power at frequency point x; Freq-band represents the frequency band; ∑ Freq-band Signal(x) represents the power value accumulated at each frequency point in the frequency band; T meassured represents the time window within the frequency band for measuring the target signal; Step 3.2: Use a near-field probe to measure the target signal generated by the GPU instruction when the target GPU is executing the task, and calculate the corresponding SAVAT-GPU metric index value according to formula (1), and evaluate the threat level of electromagnetic side channel leakage of the target GPU according to the SAVAT-GPU metric index value.
3. A method for mitigating electromagnetic side channel leakage of GPU instructions according to claim 2, characterized in that: The near-field probe is a SIGLENT SRF5030T 20mm H-field near-field probe of a SIGLENT SSA 3075X PLUS spectrum analyzer.
4. A method for mitigating electromagnetic side channel leakage of GPU instructions according to claim 2 or 3, characterized in that: After step 3, the following steps are also included: Step 4.1: Calculate the signal-to-noise ratio (SNR) of the target signal and the background noise signal. The calculation formula is as follows: Among them, P target is the target signal power, P noise is the noise floor signal power, Δt is the target signal measurement time, SAVAT-GPU target is the SAVAT-GPU metric value of the target signal, SAVAT-GPU noise is the SAVAT-GPU metric value of the background noise signal; Step 4.2: Measure the mitigation effect of the mitigation method according to the calculated SNR index value.