Efficient control flow integrity protection using approximate membership query filter

By introducing an approximate membership query filter (AMQ filter) into the processing core, the problem of difficulty in preventing failure attacks in the prior art is solved, and effective protection of computer systems and the integrity of instruction flow is achieved.

CN119989337APending Publication Date: 2025-05-13NXP BV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411360422.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-10
Filing Date
2024-09-27
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively defend against fault attacks, which can skip or change instructions, resulting in unstable operation of computer systems.

Method used

By introducing an approximate membership query filter (AMQ filter) into the processing core, this filter stores program counters with checks and determines the validity of the tuples through queries, thereby preventing failure attacks.

Benefits of technology

It realizes the protection and processing core of computer systems, effectively prevents fault attacks, and ensures the integrity of the instruction flow and the stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989337A_ABST
    Figure CN119989337A_ABST
Patent Text Reader

Abstract

A method includes: an instruction to extract a basic block of code at a program counter value; decoding is carried out on the instruction; updating a checksum value with a checksum of the instructions; and determining whether a tuple of the program counter value and the check sum value is in an approximate membership query filter (AMQ filter).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to protecting processing cores from fault attacks, and in particular to performing such protection with checksums. Background Art

[0002] Currently, attackers can apply fault attacks to the instruction stream to skip or change instructions to attack computer systems. Fault attacks are usually performed by changing the clock cycle or supply voltage in a short amount of time. Fault attacks can cause programmable cores to operate outside of the conditions for which they were designed, resulting in skipping or changing instructions. Summary of the invention

[0003] According to a first aspect of the present invention, there is provided a method comprising:

[0004] extracting the instructions of the basic block of code at the program counter value;

[0005] Decoding the instruction;

[0006] updating a checksum value with the checksum of the instruction; and

[0007] A determination is made as to whether a tuple of the program counter value and the checksum value is in an approximate membership query filter (AMQ filter).

[0008] In one or more embodiments, the method further comprises:

[0009] If the tuple is not in the AMQ filter, the program counter value is set to the exception handler address.

[0010] In one or more embodiments, the determining is performed by transmitting the tuple to the AMQ filter and receiving a response indicating that the tuple is not in the AMQ filter.

[0011] In one or more embodiments, the determining is performed if the instruction is the last instruction of the basic block.

[0012] In one or more embodiments, the method further comprises:

[0013] If the instruction is the first instruction of the basic block, the checksum value is reset.

[0014] In one or more embodiments, the method further comprises:

[0015] If the instruction is the first instruction of the basic block, resetting an instruction counter; and

[0016] The instruction counter is incremented corresponding to the fetch, wherein the determining is performed if the instruction counter exceeds a predetermined threshold.

[0017] In one or more embodiments, the method further comprises:

[0018] If the tuple is in the AMQ filter, the instruction is executed.

[0019] According to a second aspect of the present invention, there is provided a device comprising:

[0020] an approximate membership query filter (AMQ filter) that stores a tuple of a program counter and a checksum; and

[0021] A processing core that extracts instructions of a basic block of code at a program counter value, decodes the instructions, and updates a checksum value with a checksum of the instructions, wherein the AMQ filter is configured to determine whether a tuple of the program counter value and the checksum value is in the AMQ filter.

[0022] In one or more embodiments, the processing core is configured to set the program counter value to an exception handler address if the tuple is not in the AMQ filter.

[0023] In one or more embodiments, the processing core is configured to transmit the tuple to the AMQ filter and receive a response indicating that the tuple is not in the AMQ filter.

[0024] In one or more embodiments, the AMQ filter is configured to determine whether the tuple is in the AMQ filter if the instruction is the last instruction of the basic block.

[0025] In one or more embodiments, the processing core is configured to reset the checksum value if the instruction is a first instruction of the basic block.

[0026] In one or more embodiments, the processing core is configured to reset an instruction counter if the instruction is the first instruction of the basic block, and to increment the instruction counter in response to the processing core fetching the instruction, and the AMQ filter is configured to determine whether the tuple is in the AMQ filter if the instruction counter exceeds a predetermined threshold.

[0027] In one or more embodiments, the processing core is configured to execute the instruction if the tuple is in the AMQ filter.

[0028] According to a third aspect of the present invention, there is provided a device, comprising:

[0029] an instruction for fetching a basic block of code at a program counter value, means for decoding said instruction and for updating a checksum value with a checksum of said instruction; and

[0030] Means for determining whether a tuple of said program counter value and said checksum value is valid.

[0031] In one or more embodiments, the means for extracting sets the program counter value to an exception handler address if the tuple is invalid.

[0032] In one or more embodiments, the means for extracting transmits the tuple to the means for determining and receives a response indicating that the tuple is invalid.

[0033] In one or more embodiments, the means for determining determines whether the tuple is valid if the instruction is the last instruction of the basic block.

[0034] In one or more embodiments, the means for extracting resets the checksum value if the instruction is a first instruction of the basic block.

[0035] In one or more embodiments, the means for extracting executes the instructions if the tuple is valid.

[0036] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 An exemplary mapping between code and basic blocks is shown.

[0038] Figure 2 A computing device including a processing core augmented with an AMQ filter query is shown according to an embodiment of the present disclosure.

[0039] Figure 3 An algorithm for control flow integrity protection according to an embodiment of the present disclosure is shown.

[0040] Figure 4 An algorithm for generating an AMQ filter according to an embodiment of the present disclosure is shown.

[0041] Figure 5 A computing device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0042] Various embodiments of the present disclosure may employ a probabilistic approach using Approximate Membership Query Filters (AMQ Filters). AMQ Filters "store" checksum information where the risk of false positive results is small and adjustable.

[0043] In various embodiments, the code compiler fills the AMQ filter with the program counter and the checksum tuple, and then the AMQ filter can be added as a hardware module to augment the processor core. The processor sends the tuple of the program counter value and the checksum value to the AMQ filter, and the AMQ filter determines whether the tuple is a member of the AMQ filter. Therefore, selecting an implementation scheme can implement protection with lower performance overhead and code size overhead. In addition, the AMQ filter can allow a fine-grained compromise between security and code size overhead. For example, for lower performance overhead and memory storage overhead, some implementation schemes can further increase the small risk of false positives, thereby potentially improving performance and reducing costs.

[0044] Some current countermeasures address fault attacks based on basic blocks of code. A basic block is typically a straight-line sequence of code with no jumps to or from the middle of a basic block. Therefore, one countermeasure is to compute a checksum, such as a cyclic redundancy check (CRC), over the instructions in a basic block.

[0045] The last instruction of a basic block is typically a jump, branch, call, or return instruction. This disclosure refers to such instructions as "trigger instructions." After the trigger instruction is executed at runtime, the countermeasure compares the checksum with the expected checksum value. If the checksum is different from the expected checksum value, it is concluded that a fault attack has been applied and appropriate action is taken.

[0046] In this class of countermeasures, an expected checksum value computed at compile time is passed to the hardware so that the hardware can perform the check. Typically, the expected checksum value is passed in the instruction stream. This embedding is costly in terms of performance and code size.

[0047] Fault attacks can be prevented by embedding the expected checksum value of a basic block in the instruction stream. Then, it is determined whether the actual checksum of the basic block matches the expected checksum. Such deterministic methods can be slow and memory intensive.

[0048] Typically, the instruction content of each basic block is different. Conventionally, fault attack prevention measures provide each basic block with an expected checksum value for verification by the triggering instruction of the block. Alternatively, the system can be configured for a fixed expected checksum, and the checksum can be initialized with a basic block specific value at the beginning of the corresponding basic block. In both cases, at least one instruction is added to each basic block, which is costly in terms of performance and code size. The reason is that most basic blocks are small, averaging about 4 to 5 instructions. Therefore, adding instructions to basic blocks for fault attack protection is costly because it increases the size of the average block by about 20%.

[0049] There are additional problems with adding instructions to the instruction stream for fault protection. Specifically, these instructions should be as small as possible to reduce code size overhead, but should still carry large immediate values. As a result, such protection is also costly in terms of instruction encoding space. This cost may also be problematic when protection is combined with other extensions that use space in the instruction encoding space.

[0050] Many embodiments of the present disclosure do not add instructions to the instruction stream to carry the expected checksum value. In fact, various embodiments can use AMQ filters to query the validity of the pair of the PC (program counter) (e.g., address) of the triggering instruction and the expected checksum value at the triggering instruction.

[0051] AMQ filter is a memory efficient data structure that provides membership query with limited number of false positives. AMQ filter can be implemented at least in part in hardware. In various embodiments, AMQ filter is filled with valid PC and checksum value pairs by code compiler or another software tool.

[0052] To achieve high storage efficiency, AMQ filters usually do not actually store PC and checksum value pairs. In fact, many AMQ filters are implemented via hashing. Therefore, AMQ filters cannot return PC and checksum value pairs. In fact, AMQ filters can only tell whether a particular PC and checksum tuple has been added to the AMQ filter, that is, its membership.

[0053] In several embodiments of the present disclosure, the processor core passes the current PC and the current checksum value at each trigger instruction to the AMQ filter. The AMQ filter then performs a query to verify whether the checksum is valid for the provided PC by querying the tuple (PC, checksum) in the AMQ filter. Under normal circumstances, the query reports that the provided PC and checksum pair are in the AMQ filter. Under a fault attack, the provided PC and checksum pair are likely not in the AMQ filter. The AMQ filter can report this non-existence to the processing core, which can then take appropriate action for the fault attack.

[0054] Because the AMQ filter does not actually store the PC and checksum value pairs, the storage efficiency of the AMQ filter comes at the expense of a manageable false positive rate. That is, under low probability circumstances, the AMQ filter may report that a certain PC and checksum tuple is a member of the AMQ filter, while the tuple is not actually a member of the AMQ filter. On the other hand, a conventional AMQ filter will never generate a false negative result: that is, when querying for a PC and checksum value pair that should be in the AMQ filter, the conventional AMQ filter always correctly reports that the pair is a member of the AMQ filter.

[0055] In the event of such a false positive by the AMQ filter, the attack may go unnoticed. The AMQ filter may be configured so that the probability of a false positive is acceptably low.

[0056] In fact, even conventional methods can sometimes produce false positives. That is, even in conventional methods without AMQ filters, some faults will not be detected. For example, a conventional fault attack prevention measure uses a fixed expected checksum. The attacker may know that in such a system, basic blocks are protected by CRCs of a specific width. Therefore, the attacker may be able to manipulate the instructions of his malicious code so that the instruction stream has the same CRC value. In this case, conventional prevention measures will produce false positives.

[0057] Therefore, fault attack protection can be achieved by both the code compiler and the AMQ filter hardware extension to the programmable core. The compiler usually builds an internal data structure called a control flow graph for each function it is compiling. The nodes in this graph represent basic blocks that include instructions that are executed in sequence.

[0058] Figure 1 An exemplary mapping 100 between code and basic blocks is shown. Figure 1In the example of , the code corresponds to four basic blocks of code. The first basic block 120 is formed by the code ending with an IF evaluation. The IF evaluation can be considered as a trigger instruction. The second basic block 140 is formed by the code as a result of the IF evaluation. The third basic block 160 is formed by the code as an alternative to the IF evaluation. The fourth basic block 180 is the code after the IF evaluation.

[0059] like Figure 1 As shown, there is no jump to a location in the middle of a basic block, and there is no jump from a location to the middle of a basic block.

[0060] To understand the concept of basic blocks easily, Figure 1 The basic blocks of are written using relatively high-level code. Therefore, some of these basic blocks do not explicitly include triggering instructions. In fact, before execution, Figure 1 High-level code is often compiled into relatively low-level code. For example, for the 64-bit ARM instruction set, the code "if(x>z)" may be compiled into two instructions "cmp w1,w2" and "b.ge". The first instruction "cmp w1,w2" compares the contents of register w1 with the contents of register w2. Here, register w1 may include the value x, and register w2 may include the value z. The second instruction "b.ge" performs a jump if the previous comparison instruction (here "cmp w1,w2") tests that the contents of register w1 are greater than the contents of register w2. Therefore, "b.ge" is an example of a triggering instruction for the first basic block, but "b.ge" does not explicitly appear in the Figure 1 In the first basic block.

[0061] Another example of a basic block from the ARM instruction set might look as follows.

[0062]

[0063] In this case, b.ge is a branch instruction, and is therefore the triggering instruction for this basic block. Many embodiments of the present disclosure work by computing a checksum of the instructions of a basic block at compile time and at run time. An example of a suitable checksum is a cyclic redundancy check (CRC) checksum.

[0064] Thus, the checksum is calculated at compile time and at run time by d2800024, f8647845, ... 54ffff8a. Then, at run time, the run-time checksum is checked for equality with the compile-time checksum based at least in part on the PC of the triggering instruction. If the two checksum values ​​are not equal, then the attacker has somehow injected a fault into the instruction stream.

[0065] In many embodiments, at compile time, the code compiler communicates the calculated checksum value to the hardware of each basic block. This communication should be done efficiently to limit the cost of protection. Therefore, according to various embodiments of the present disclosure, the compiler (or another software tool) builds an AMQ filter that, for each triggering instruction, keeps a tuple of its program counter (e.g., its address) and the expected checksum value. The AMQ filter can store this information in memory very efficiently.

[0066] Referring to the previous basic block example, if the CRC of d2800024, f8647845, ... 54ffff8a is 5dc028e, then the tuple (5770, 5dc028e) can be added to the AMQ filter. As shown above, 5770 is the address of the triggering instruction.

[0067] Figure 2 2 shows a computing device 200 including a processing core 220 augmented with an AMQ filter according to an embodiment of the present disclosure. The computing device 200 may also include a memory 260 and a memory 280. Figure 2 In the example, the AMQ filter is implemented as an AMQ filter query module 240 hardware extension.

[0068] Processing core 220 may send a tuple of its program counter (PC) and the calculated checksum value (CRC in this case) to AMQ filter query module 240. In a selected embodiment, processing core 220 may send a tuple of PC and checksum at each trigger instruction encountered by processing core 220.

[0069] Processing core 220 is an example of a component for fetching instructions of a basic block of code at a program counter value, for decoding the instructions, and for updating a checksum value with a checksum of the instructions.

[0070] The AMQ filter query module 240 can determine whether the tuple of the program counter value and the checksum value is valid. In some embodiments, the AMQ filter query module 240 applies one or more hash functions to generate a hash value based at least in part on the tuple of the PC and the checksum. In order to perform the one or more hash functions, the AMQ filter query module 240 performs multiple operations to read data from the memory 280, and performs multiple hash operations based on the data. The additional operations performed by the AMQ filter can be specific to the AMQ filter. Such operations may include one or more XOR operations and / or comparison operations.

[0071] The one or more hash functions may be implemented in a variety of ways. In many embodiments, these hash functions are quickly and easily implemented in hardware. In certain embodiments, a secure hash function may be implemented, but implementing a secure hash function is typically expensive. The AMQ filter query module 240 may perform membership queries for tuples based on hash values.

[0072] like Figure 2 As shown, processing core 220 may transmit a request to memory 260 via one or more master interfaces. Such a request may include a program counter value. Memory 260 may return instructions and data under the program counter value via the communication infrastructure of memory 260. The response may include the instructions and the data.

[0073] In various embodiments, the AMQ filter query module 240 is implemented in logic written in Verilog or VHDL. The AMQ filter query module 240 can use data structures stored in memory 280 that tell whether a tuple is valid (e.g., a member of a set) with a probability of a false positive.

[0074] In addition, via the main interface, the AMQ filter query module 240 can request data from the memory 280 to perform the AMQ test. The data requested by the AMQ filter query module 240 can depend on the type of the AMQ filter. For example, in an embodiment where the AMQ filter is a Bloom filter, the AMQ filter query module 240 can load multiple unit values ​​from the memory 280. In an embodiment where the AMQ filter is an XOR filter or a binary fusion filter, the AMQ filter query module 240 can load multiple hash values ​​from the memory 280. In an embodiment where the AMQ filter is a cuckoo filter, the AMQ filter query module 240 can load a bucket from the memory 280, where a bucket is defined as a small set of hash values.

[0075] In some embodiments, memory 280 is dedicated to AMQ filter query module 240. In selected embodiments, memory 280 is integrated into (e.g., within) AMQ filter query module 240. In another embodiment, memory 280 may be merged with memory 260 such that processing core 220 and AMQ filter query module 240 operate with the same memory.

[0076] If the AMQ filter query module 240 determines that the PC-checksum tuple is invalid (e.g., not a member of the AMQ filter), the AMQ filter query module 240 may transmit an error to the processing core 220. In this case, the AMQ filter query module 240 has detected a fault attack. If the AMQ filter query module 240 determines that the PC-checksum tuple is valid (e.g., is a member of the AMQ filter), the AMQ filter query module 240 does not transmit an error to the processing core 220.

[0077] In one embodiment, the processing core 220 waits for an indication from the AMQ filter query module 240. In such embodiments, the indication may indicate the presence of an error (e.g., the tuple does not exist in the AMQ filter query module 240). The indication may also indicate that the AMQ filter query module 240 believes that the tuple exists in the AMQ filter query module 240 (e.g., the tuple exists, or the AMQ filter query module 240 is returning a false positive). Other embodiments are possible, as discussed later.

[0078] AMQ filter query module 240 is an example of a component for determining whether a tuple of a program counter value and a checksum value is valid.

[0079] In some cases, failures lead to false-positive query results, allowing the failure to go undetected. The probability of such failures is usually tolerably low, because AMQ filters have parameters that allow the developer to select the probability of false positives. However, lower false positive rates come at the cost of more storage for AMQ filters.

[0080] In many embodiments, the AMQ filter query module 240 has configuration options that control the tradeoff between the false positive rate and memory requirements of the AMQ filter. To achieve a higher level of security, the false positive rate can be reduced, resulting in additional memory usage. On the other hand, to reduce costs, memory usage can be reduced at the expense of lower security.

[0081] A person of ordinary skill in the art can implement many AMQ filter query functions in hardware. Suitable hardware may include, for example, a Bloom filter, a Cuckoo filter, an XOR filter, or a 3-wise binary fuse filter. A 3-wise binary fuse filter includes calculating four simple hash functions, performing three memory read operations, and then XORing and comparing the results. A 3-wise binary fuse filter is particularly suitable for implementations that include 10,000 or more tuples.

[0082] Figure 3 An algorithm 300 for control flow integrity protection is shown according to an embodiment of the present disclosure.

[0083] Algorithm 300 begins at 305 and proceeds to 310 .

[0084] At 310 , a processing core (eg, processing core 220 ) fetches instructions for a basic block at a current program counter (PC) value. Algorithm 300 then proceeds to 315 .

[0085] At 315 , the processing core decodes the instruction. Algorithm 300 then proceeds to 320 .

[0086] At 320, the processing core determines whether the instruction is the first (e.g., initial) instruction of the basic block. If the processing core determines that the instruction is the first instruction of the basic block, the algorithm 300 proceeds to 325. If the processing core determines that the instruction is not the first instruction of the basic block, the algorithm 300 proceeds to 335.

[0087] At 325 , the processing core resets the checksum value of the basic block. For example, the checksum value may be reset to 0. Algorithm 300 then proceeds to 330 .

[0088] At 330 , the processing core optionally resets the instruction counter of the basic block. For example, the instruction counter may be reset to 0. Algorithm 300 then proceeds to 335 .

[0089] At 335 , the processing core updates the checksum value with the value of the checksum for the instruction under the current PC. The processing core may perform this update, for example, by adding the value of the checksum for the instruction to the current checksum value. Algorithm 300 then proceeds to 340 .

[0090] At 340 , the processing core optionally increments an instruction counter. Algorithm 300 then proceeds to 345 .

[0091] At 345 , the processing core determines whether to query the validity of the tuple of the program counter and the checksum value (eg, membership of the tuple in an AMQ filter).

[0092] For example, the processing core can determine whether the instruction is the last instruction of the basic block. For example, the processing core can determine whether the next line of code concludes the case, as indicated by the delimiter. The programming language of the basic block determines the characters that can be used as delimiters. Figure 1 In the example above, the character "}" is an example of a delimiter.

[0093] In another example, the processing core may determine whether the instruction is a trigger instruction. In this case, the type of instruction indicates the end of the basic block. For example, the instruction may be an If, Else, Else If, ​​Jump, Branch, Call, or Return instruction. In an exemplary embodiment involving a 64-bit ARM instruction set, the trigger instruction may include "b" (unconditional branch), "b.eq" (conditional branch), "bl" (function call), and "ret" (function return).

[0094] Thus, in several embodiments, the processing core determines the validity of the query tuple if the next line of code concludes the case or if the current instruction is a triggering instruction.

[0095] In addition, to provide additional and / or independent protection, the processing core may also or alternatively determine whether the instruction counter exceeds a predetermined threshold. For example, some embodiments may query the validity of the tuple after executing a predetermined number of lines of code (e.g., 10 lines of code). If the processing core determines that the instruction counter exceeds the predetermined threshold, then in selected embodiments, the processing core determines to query the validity of the tuple. Alternatively or in addition, in the event that the instruction counter exceeds the predetermined threshold, the AMQ filter may report an error to the processing core to indicate that the instruction counter has exceeded the predetermined threshold.

[0096] If the processing core determines to query the validity of the tuple, the algorithm 300 proceeds to 350. If the processing core determines not to query the validity of the tuple, the algorithm 300 proceeds to 355.

[0097] At 350, the AMQ filter (e.g., the AMQ filter query module 240) determines whether the tuple of the PC and the checksum value is valid. For example, the AMQ filter may query whether the tuple of the PC and the checksum value exists within the AMQ filter. In one embodiment, the AMQ filter retrieves a hash value from a memory (e.g., the memory 280) to perform this query. If the AMQ filter determines that the tuple of the PC and the checksum value is valid (e.g., exists in the AMQ filter), the algorithm 300 proceeds to 355. If the AMQ filter determines that the tuple of the PC and the checksum value is invalid (e.g., does not exist in the AMQ filter), the algorithm 300 proceeds to 365.

[0098] At 355 , the processing core executes the instruction. Algorithm 300 then proceeds to 360 .

[0099] At 360 , the processing core determines the next program counter value and advances to that program counter value. The algorithm 300 then returns to 310 .

[0100] In 365, the processing core sets the program counter value equal to the exception handler address and advances to the address. Thus, the processing core can perform appropriate operations to resolve the fault attack. One such operation is to reset the processing core. Another such operation is to reset the entire chip, thereby resetting the processing core. Resetting the entire chip also resets the other processor cores on the chip and the memory on the chip. Another such operation is to erase the keys stored in the system.

[0101] Algorithm 300 then returns to 310 .

[0102] Figure 3 An embodiment is shown in which the processing core waits for an indication from the AMQ filter as to whether a tuple exists in the AMQ filter. In another embodiment, the processing core continues to execute Figure 3 The other operations (e.g., fetching instructions at 310 and executing instructions at 355) of the AMQ filter are performed until the processing core receives an error from the AMQ filter. In such an embodiment, operation 350 can be implemented as an interrupt, for example. That is, operation 350 (and operation 365, if appropriate) can be performed at any time. Figure 3 If the processing core receives an error from the AMQ filter, the algorithm 300 proceeds to 365 from its current operation.

[0103] Furthermore, in some embodiments, the operations in 365 may alternatively be or additionally include a signal external to the processing core. Thus, the AMQ filter may generate such an external signal as a reaction to a negative membership query. Another processing core in the system may receive the external signal and reset the processing core (e.g., processing core 220) that transmitted the negative tuple, reset the system including the two processing cores and the AMQ filter, erase the stored key, or perform another suitable action. In a selected embodiment, the AMQ filter may transmit the external signal to a reset module on the chip.

[0104] Figure 4 An algorithm 400 for generating an AMQ filter according to an embodiment of the present disclosure is shown. The algorithm 400 may be implemented using a computing device. The algorithm 400 starts at 410 and proceeds to 420.

[0105] At 420 , a processor of the computing device executes a compiler to compile an application including a plurality of basic blocks into a binary image. This processor is different from the processing core 220 that is protected from fault attacks by the AMQ filter. The algorithm 400 then proceeds to 430 .

[0106] At 430, the processor determines basic blocks in the binary image generated at 420. For example, the processor may determine a first instruction and a trigger instruction for each basic block, where applicable. Algorithm 400 then proceeds to 440.

[0107] At 440, the processor calculates a checksum for each basic block in the binary image. For example, the checksum may be based on the corresponding first instruction and the corresponding trigger instruction. In embodiments where the AMQ filter is to be checked after a predetermined number of instructions, the processor may calculate a tuple of the last program counter of a group of predetermined number of instructions and the checksum over the group. Algorithm 400 then proceeds to 450.

[0108] In 450, the processor adds to the AMQ filter a tuple of the last program counter in the basic block and the checksum on the basic block. The processor adds this tuple for each basic block in the application. As discussed above, for example, the checksum can be a CRC.

[0109] Algorithm 400 then proceeds to 460 .

[0110] At 460, the AMQ filter is loaded with the binary image. Algorithm 400 then proceeds to 470 and ends.

[0111] Therefore, according to some embodiments of the present disclosure, the expected checksum value of the trigger instruction is combined with the PC. The tuple resulting from this combination is then stored in the AMQ filter.

[0112] There are several possible modifications to the embodiments discussed above. For example, some embodiments may include a buffer located between the processing core and the AMQ filter.

[0113] In various embodiments, when the processing core determines that the trigger instruction has been decoded, the processing core transmits a tuple of the PC and the checksum of the trigger instruction to a buffer. The buffer stores the tuple. The AMQ filter can retrieve the tuple from the buffer. When the AMQ filter retrieves the tuple, the buffer can clear the tuple from its memory.

[0114] If a processing core executes multiple trigger instructions immediately after each other, the buffer may become full.

[0115] In some embodiments, when the buffer is full, the buffer may assert or transmit a full buffer signal to the processing core. Upon receiving the full buffer signal, the processing core may suspend execution of instructions (e.g., at 355). When the buffer is no longer full, the buffer may counter (e.g., stop asserting) the full buffer signal or may transmit a not full buffer signal. When the full buffer signal is no longer asserted or when the not full buffer signal is received, the processing core may resume execution of instructions. Thus, if the AMQ filter is busy with a previous check, the processing core may continue to process instructions as long as there is space available in the buffer.

[0116] In another embodiment, when the buffer receives a tuple of a PC and a checksum, the buffer may determine whether the buffer is storing the tuple. If the buffer determines that the buffer is already storing the tuple, the buffer may discard (e.g., not store it additionally) the received tuple. If the buffer determines that the buffer has not yet stored the tuple, the buffer may store the tuple.

[0117] Thus, if the buffer is already storing received tuples, the AMQ filter may skip checking further received instances of the tuple.Such a buffer may reduce the work performed by the AMQ filter, and therefore may also reduce the number of memory requests made by the AMQ filter.

[0118] In another embodiment, such a buffer can predict potential future basic blocks and generate a tuple of the program counter of the future basic block and the checksum of the future basic block. If the processing core 220 enters the future basic block (or when this occurs), the processing core 220 can transmit a signal to the buffer. After receiving the signal, the buffer can send the PC and the checksum tuple to the AMQ filter query module 240. Therefore, the AMQ filter query module 240 can return an error response to the processing core 220 faster, thereby potentially preventing the processing core 220 from being attacked by a fault at an earlier time. Multiple valid checksum values ​​can also be associated with the trigger instruction. Then, a tuple with each checksum value in n checksum values ​​(PC, cs1) ... (PC, csn) can be stored in the AMQ filter. In the case where the corresponding basic block can be entered by falling from its previous basic block in the memory and by jumping, this association is meaningful.

[0119] Figure 5 Computing device 500 is shown according to an embodiment of the present disclosure. Computing device 200 may be included in and / or implemented by computing device 500.

[0120] The computing device 500 may include a network interface 510 , a user input interface 520 , a memory 530 , a program 540 , a kernel 550 , an AMQ filter query module 555 , a user output interface 560 , and a bus 570 .

[0121] Although shown in a single housing, the computing device 500 can be distributed across multiple housings or subsystems that execute program instructions cooperatively. In some embodiments, the computing device 500 can be or include one or more blade server devices, stand-alone server devices, personal computers (including laptops and tablet computers), routers, hubs, switches, bridges, firewall devices, intrusion detection devices, mainframe computers, network-attached storage devices, smart phones and other mobile phones, and other computing devices. In many embodiments, the computing device 500 can execute Windows OS, macOS, Android, or Linux, and the device hardware can be configured according to a symmetric multiprocessing (SMP) architecture or a non-uniform memory access (NUMA) architecture.

[0122] The network interface 510 may provide one or more communication connections and / or one or more devices that allow the computing device 500 to communicate with other computing systems (not shown) over a communication network, a collection of networks, or over the air to support the control flow integrity protection outlined herein. The network interface 510 may communicate using a variety of networks (including both internal and external networks), such as near field communication (NFC), Wi-Fi, and the like. TM , Bluetooth, Ethernet, cellular (e.g., 3G, 4G, 5G), white space, 802.11x, satellite, LTE, GSM / HSPA, CDMA / EVDO, DSRC, CAN, GPS, fax, or any other wired or wireless interface. Other interfaces may include physical ports (e.g., Ethernet, USB, HDMI, etc.), interfaces for wired and wireless internal subsystems, etc. Similarly, the nodes and user equipment (e.g., mobile devices) of the system may also include suitable interfaces for receiving, transmitting and / or otherwise communicating data or information in a network environment.

[0123] The user input interface 520 may receive one or more inputs from a human. The user input interface may be or include a mouse, touch pad, keyboard, touch screen, trackball, camera, microphone, joystick, game controller, scanner, or any other input device.

[0124] Memory 530 (also referred to as "storage device") may include or be one or more computer-readable storage media that can be read by processing core 550 and store software. Memory 530 may be implemented as one storage device, or across multiple co-located or distributed storage devices or subsystems. Memory 530 may include additional elements that communicate with processing core 550, such as a controller. Memory 530 may also include storage devices and / or subsystems that store data and / or instructions. Computing device 500 may access one or more storage resources to access information to implement the present disclosure and in particular in Figure 3-4 Any process indicated in .

[0125] In various embodiments, memory 530 stores program 540 to execute Figure 3-4 In addition, program 540, when executed by computing device 500 in general and / or processing core 550 in particular, can direct the execution of operations for control flow integrity protection, as well as other functions, as described herein.

[0126] Memory 530 may be or include a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), a random access memory (RAM), a dynamic RAM (DRAM), a static RAM (SRAM), a field programmable gate array (FPGA), a hard drive, a cache memory, a flash memory, a removable disk, or a magnetic tape reel. Memory 530 may be or include resistive RAM (RRAM) or magnetoresistive RAM (MRAM). Based on the particular embodiment, the information tracked, sent, received, or stored in the communication system may be provided in any database, register, table, cache, queue, control list, or storage structure, all of which may be referenced in any suitable time frame.

[0127] Processing core 550 (e.g., a processor) may be or include one or more hardware processors and / or other circuitry that retrieves and executes software (particularly program 540) from memory 530. Processing core 550 may be implemented within one processing device, chip, or package, and may also be distributed across multiple processing devices, chips, packages, or subsystems that cooperate. In some embodiments, processing core 550 is or includes a graphics processing unit (GPU).

[0128] Processing core 550 may have any register size, such as 32-bit registers or 64-bit registers, etc. Processing core 550 may include or interface with multiple cores. Embodiments of processing core 550 are not limited to any particular number of threads. Processing core 550 may be manufactured using any process technology, such as 14 nm process technology.

[0129] The AMQ filter query module 555 may be or include the AMQ filter query module 240. The AMQ filter query module 555 may send and receive information to and from the memory 530 via the bus 570.

[0130] The user output interface 560 can output information to a human user. The user output interface 560 can be or include a display (e.g., a screen), a touch screen, a speaker, a printer, or a tactile feedback unit. In many embodiments, the user output interface 560 can be combined with the user input interface 520. For example, some such embodiments include a touch screen, a head mounted device including headphones and a microphone, or a joystick with tactile feedback.

[0131] In embodiments including multiple computing devices, the server or (in serverless embodiments) peers of the system may use one or more communication networks that facilitate communication between computing devices to achieve control flow integrity protection, as outlined herein. For example, the one or more communication networks may include or be a local area network (LAN) or wide area network (WAN) that facilitates communication between computing devices. One or more direct communication links may be included between computing devices. Additionally, in some cases, computing devices may be installed at geographically distributed locations. In other cases, multiple computing devices may be installed at a geographic location, such as a server farm or office.

[0132] As used herein, the terms "storage media" or "computer-readable storage media" may refer to non-transitory storage media, such as non-limiting examples of hard drives, memory chips, ASICs, and cache memories, and may refer to transitory storage media, such as carrier waves or propagated signals.

[0133] Aspects of the computing device can be implemented in various ways, for example, as a method, a system, a computer program product, or one or more computer-readable storage media. Therefore, aspects of the present disclosure can take the form of a hardware implementation or a combination of software and hardware implementations, which can be generally referred to as "modules" or "systems" herein. The functions described in the present disclosure can be implemented as algorithms executed by one or more hardware processing units (e.g., processing core 550). In various embodiments, the different operations of the described algorithms and parts of the operations can be performed by different processing units. In some embodiments, the operations can be implemented by software interaction between a processor and an AMQ filter. In addition, aspects of the present disclosure can take the form of one or more computer-readable media, which have computer-readable program codes implemented thereon (e.g., encoded or stored). In various embodiments, such computer programs can be, for example, downloaded (or updated) to existing devices and systems, or stored when these devices and systems are manufactured.

[0134] Any suitable arrangement may be applied to the physical implementation, including the design of the communication network in which the system is implemented. In one embodiment, bus 570 may share hardware resources with memory 530 and processing core 550. In this alternative embodiment, computing device 500 is equipped with separate hardware resources, including one or more processing cores, AMQ filters, and memory elements.

[0135] In an example embodiment, the various other components of computing device 500 may be installed in different physical areas or may be installed as a single unit.

[0136] The communication system may be configured to facilitate communication with machine devices (e.g., vehicle sensors, instruments, electronic control units (ECUs), embedded devices, actuators, displays, etc.) via bus 570. Other suitable communication interfaces may also be provided for an Internet Protocol (IP) network, a User Datagram Protocol (UDP) network, or any other suitable protocol or communication architecture that enables network communications with machine devices.

[0137] The innovations in this specific embodiment can be implemented in a variety of different ways, for example, as defined and covered by the claims and / or selected examples. In the specification, reference is made to the accompanying drawings, in which the same reference numerals may indicate the same or functionally similar elements. The elements in the accompanying drawings are not necessarily drawn to scale. In addition, some embodiments may include more elements than those shown in the accompanying drawings and / or a subset of the elements shown in the accompanying drawings. In addition, some embodiments may incorporate suitable combinations of features from two or more drawings.

[0138] The present disclosure describes various illustrative embodiments and examples for implementing the features and functions of the present disclosure. Components, arrangements and / or features are described in conjunction with various embodiments and are merely examples to simplify the present disclosure and are not intended to be restrictive. In the development of actual embodiments, implementation-specific decisions may be made to achieve specific goals, including compliance with system, business and / or legal constraints that may vary from implementation to implementation. In addition, although the work of such development may be complex and time-consuming, the work is nothing more than routine work for those of ordinary skill in the art who benefit from the present disclosure.

[0139] The systems, methods, and devices of the present disclosure have several innovative aspects, no single aspect of which is solely responsible for all of the attributes disclosed herein. Some objectives or advantages may not be achieved by the embodiments described herein. Thus, for example, certain embodiments may operate in a manner that achieves or optimizes one advantage or set of advantages as taught herein rather than other objectives or advantages as taught or suggested herein.

[0140] In an example embodiment, the circuit of the accompanying drawings can be implemented on the board of the associated electronic device. The board can be a general circuit board, which can hold various components of the internal electronic system of the electronic device, and further provide connectors for other peripheral devices. More specifically, the board can provide an electrical connection, and other components of the system can communicate electrically through the electrical connection. Any processor (including a digital signal processor, a microprocessor, a support chipset, etc.) and a computer-readable non-transient memory element can be coupled to the board based on configuration, processing requirements and computer design. For example, other components such as external memory, other sensors, controllers for audio / video display and peripheral devices can be attached to the board via a cable as a plug-in card, or integrated into the board itself. In various embodiments, some of the functionality described herein can be implemented in a simulated form as software or firmware running in one or more configurable (e.g., programmable) elements arranged in a structure to support these functions. Non-transient computer-readable storage media can include instructions that allow one or more processors to implement simulation.

[0141] In another example embodiment, the circuit of the accompanying drawings can be implemented as a stand-alone module (e.g., a device with associated components and circuit systems configured to perform a specific application or function) or as a plug-in module in the dedicated hardware of an electronic device. The embodiments of the present disclosure can be easily included in a system on chip (SOC) package. SOC represents an integrated circuit (IC) that integrates the components of a computer or other electronic system into a chip. SOC can include digital, analog, mixed signal and generally radio frequency functions on a chip substrate. Other embodiments may include a multi-chip module (MCM), wherein multiple separate ICs are located in an electronic package and interact via the electronic package. In various other embodiments, the processor can be implemented in one or more silicon cores in an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a programmable array logic (PAL), a general array logic (GAL) and other semiconductor chips.

[0142] The specifications, dimensions, and relationships (e.g., the number of processors and logical operations) outlined herein are provided for non-limiting purposes of example and teaching. For example, various modifications and changes may be made to the arrangement of components. Accordingly, the specification and drawings should be regarded as illustrative rather than restrictive.

[0143] For clarity and example, many examples provided herein describe interactions about two, three or more electrical components. Systems can be integrated in any manner. The components, modules and elements shown in the accompanying drawings can be combined in various possible configurations within the scope of the present disclosure together with similar design alternatives. In some cases, one or more of the functionalities of a given set of processes can be more clearly described by reference to a limited number of electrical components. The circuits of the accompanying drawings can be easily scaled and can accommodate many components and more complex / precise arrangements and configurations. Therefore, the examples provided do not limit the scope or inhibit the teaching of circuits that may be applied to countless other architectures.

[0144] In the present disclosure, references to various features (e.g., elements, structures, modules, components, steps, operations, characteristics, etc.) included in "one embodiment," "example embodiment," "an embodiment," "another embodiment," "some embodiments," "various embodiments," "other embodiments," "alternative embodiments," etc., are intended to mean that any such features may be included in one or more embodiments of the present disclosure, and may or may not necessarily be combined in the same embodiment. Where appropriate, some operations may be deleted or omitted, or may be substantially modified or changed. In addition, the timing of these operations may be substantially changed. The foregoing operational flows are provided for purposes of example and discussion. The embodiments described herein provide flexibility in that any suitable arrangements, time structures, configurations, and timing mechanisms may be provided.

[0145] example

[0146] In Example M1, a method includes: extracting instructions of a basic block of code under a program counter value; decoding the instructions; updating a checksum value with a checksum of the instructions; and determining whether a tuple of the program counter value and the checksum value is in an approximate membership query filter (AMQ filter).

[0147] Example M2 is the method of Example M1, further comprising: if the tuple is not in the AMQ filter, setting the program counter value to an exception handler address.

[0148] Example M3 is the method of example M2, wherein the determining is performed by transmitting the tuple to the AMQ filter and receiving a response indicating that the tuple is not in the AMQ filter.

[0149] Example M4 is a method according to any of Examples M1 to M3, wherein the determining is performed if the instruction is the last instruction of the basic block.

[0150] Example M5 is a method according to any one of Examples M1 to M4, further comprising: resetting the checksum value if the instruction is the first instruction of the basic block.

[0151] Example M6 is a method according to any one of Examples M1 to M5, further comprising: resetting an instruction counter if the instruction is the first instruction of the basic block; and incrementing the instruction counter corresponding to the extraction, wherein the determination is performed if the instruction counter exceeds a predetermined threshold.

[0152] Example M7 is a method according to any one of Examples M1 to M6, further comprising: executing the instruction if the tuple is in the AMQ filter.

[0153] In Example A1, a device includes: an approximate membership query filter (AMQ filter), which stores a tuple of a program counter and a checksum; and a processing core, which extracts instructions of a basic block of code under a program counter value, decodes the instructions, and updates the checksum value with a checksum of the instructions, wherein the AMQ filter is configured to determine whether the tuple of the program counter value and the checksum value is in the AMQ filter.

[0154] Example A2 is the apparatus of Example A1, wherein the processing core is configured to set the program counter value to an exception handler address if the tuple is not in the AMQ filter.

[0155] Example A3 is the apparatus of Example A2, wherein the processing core is configured to transmit the tuple to the AMQ filter and receive a response indicating that the tuple is not in the AMQ filter.

[0156] Example A4 is an apparatus according to any of Examples A1 to A3, wherein the AMQ filter is configured to determine whether the tuple is in the AMQ filter if the instruction is the last instruction of the basic block.

[0157] Example A5 is the apparatus of any of Examples A1 to A4, wherein the processing core is configured to reset the checksum value if the instruction is a first instruction of the basic block.

[0158] Example A6 is a device according to any one of Examples A1 to A5, wherein the processing core is configured to reset an instruction counter when the instruction is the first instruction of the basic block, and increment the instruction counter in response to the processing core extracting the instruction, and the processing core is configured to determine whether the tuple is in the AMQ filter when the instruction counter exceeds a predetermined threshold.

[0159] Example A7 is the apparatus of any of Examples A1 to A6, wherein the processing core is configured to execute the instruction if the tuple is in the AMQ filter.

[0160] In Example F1, an apparatus includes: instructions for extracting a basic block of code under a program counter value, means for decoding the instruction, and means for updating a checksum value with a checksum of the instruction; and means for determining the validity of a tuple of the program counter value and the checksum value.

[0161] Example F2 is the apparatus of Example F1, wherein the means for extracting sets the program counter value to an exception handler address if the tuple is invalid.

[0162] Example F3 is the apparatus of Example F2, wherein the means for extracting transmits the tuple to the means for determining and receives a response indicating that the tuple is invalid.

[0163] Example F4 is the apparatus of any of Examples F1 to F3, wherein the means for determining determines whether the tuple is valid if the instruction is a last instruction of the basic block.

[0164] Example F5 is the apparatus of any of Examples F1 to F4, wherein the means for extracting resets the checksum value if the instruction is a first instruction of the basic block.

[0165] Example F6 is an apparatus according to any one of Examples F1 to F5, wherein the means for extracting resets an instruction counter if the instruction is the first instruction of the basic block and increments the instruction counter corresponding to extracting the instruction, and the means for determining determines whether the tuple is valid if the instruction counter exceeds a predetermined threshold.

[0166] Example F7 is an apparatus according to any of Examples F1 to F6, wherein the means for extracting executes the instruction if the tuple is valid.

Claims

1. A method, characterized in that include: extracting the instructions of the basic block of code at the program counter value; Decoding the instruction; updating a checksum value with a checksum of the instruction; as well as A determination is made as to whether a tuple of the program counter value and the checksum value is in an approximate membership query filter (AMQ filter).

2. The method according to claim 1, characterized in that Also includes: If the tuple is not in the AMQ filter, the program counter value is set to the exception handler address.

3. The method according to claim 2, characterized in that The determining is performed by transmitting the tuple to the AMQ filter and receiving a response indicating that the tuple is not in the AMQ filter.

4. The method according to claim 1, characterized in that: If the instruction is the last instruction of the basic block, the determination is performed.

5. The method according to claim 1, characterized in that Also includes: If the instruction is the first instruction of the basic block, the checksum value is reset.

6. The method according to claim 1, characterized in that Also includes: If the instruction is the first instruction of the basic block, resetting an instruction counter; as well as The instruction counter is incremented corresponding to the fetch, wherein the determining is performed if the instruction counter exceeds a predetermined threshold.

7. The method according to claim 1, characterized in that Also includes: If the tuple is in the AMQ filter, the instruction is executed.

8. A device, characterized in that include: an approximate membership query filter (AMQ filter) that stores a tuple of a program counter and a checksum; as well as A processing core that extracts instructions of a basic block of code at a program counter value, decodes the instructions, and updates a checksum value with a checksum of the instructions, wherein the AMQ filter is configured to determine whether a tuple of the program counter value and the checksum value is in the AMQ filter.

9. The device according to claim 8, characterized in that The processing core is configured to reset an instruction counter if the instruction is the first instruction of the basic block and to increment the instruction counter in response to the processing core fetching the instruction, and the AMQ filter is configured to determine whether the tuple is in the AMQ filter if the instruction counter exceeds a predetermined threshold.

10. A device, characterized in that: include: an instruction for fetching a basic block of code at a program counter value, means for decoding said instruction and for updating a checksum value with a checksum of said instruction; as well as Means for determining whether a tuple of said program counter value and said checksum value is valid.