Hardware defense method for speculative cache side channel attack
By designing hardware tracking solutions and delay strategies for unsafe inferred memory access instructions in the processor, the existing defense solutions cannot effectively solve the problem of speculative cache-side channel attacks, achieving comprehensive protection of speculative cache-side channel attacks, and verifying its effectiveness on real hardware prototypes.
Patent Information
- Application Number
- CN202510037065.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-13
AI Technical Summary
Existing defense solutions cannot effectively solve the problem of speculative cache-side channel attacks, especially inadequate performance and hardware resource trade-offs, and lack real hardware prototype verification.
A cache-side channel elimination method based on inferred execution is proposed. By clarifying the conditions of the inferred window, classifying the inferred cache-side channel, designing hardware tracking schemes and delay strategies for unsafe inferred memory access instructions, combining different hardware delay strategies to propose hardware defense schemes for single-core and multi-core processors, and verifying them on the GEM5 simulation platform and FPGA hardware prototype.
It effectively narrows the scope of protection instructions, reduces instructions affected by defense solutions, reduces performance overhead, realizes comprehensive protection of speculative cache-side channel attacks, and verifies its practicality in real scenarios.
Smart Images

Figure CN119989341A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of processor architecture, and in particular relates to a hardware defense method for speculative cache side channels. Background Art
[0002] Speculative execution is one of the basic technologies for implementing instruction-level parallelism in modern high-performance processors. It can predict the execution direction of the instruction flow in the program to reduce pipeline pauses and thus improve program execution efficiency and processor performance. However, incorrect speculation can cause the processor to execute instructions that violate the architectural semantics, resulting in serious security vulnerabilities. Side channel attacks that rely on shared microarchitectural states and behaviors to leak information have been widely known and exploited for many years. The Spectre attack and its variants disclosed in 2017 demonstrated a new side channel attack dimension introduced by speculative execution: the combination of speculative execution and cache side channels can allow attackers to leak arbitrary data from the victim's memory space. In a speculative cache side channel attack, the victim will execute instructions that trigger incorrect speculation under the malicious training of the attacker, and execute instructions that load secret data along the wrong speculation path within the speculation window, thereby encoding the secret data on the cache side channel by changing the state of the cache system. Speculative cache side channel attacks expose serious security vulnerabilities of processors. To date, more and more variants of speculative cache side channel attacks continue to emerge, and have not been effectively addressed in commercial processors. As the security foundation of confidential computing and the cornerstone of network security, threats to chip security may endanger the stable operation of the entire information society and the security of personal privacy data.
[0003] However, existing solutions for mitigating speculative cache side channel attacks still have limitations. This is because software patches can usually only defend against specific attacks, cannot fundamentally solve the problem, and require recompilation. The defense solutions currently proposed mainly focus on hardware and are divided into two categories: invisible speculative execution and selective speculative execution. The invisible speculative execution scheme makes the results of speculative execution invisible to the cache hierarchy, preventing secret data from being encoded into the cache side channel, but similar schemes require additional data structures to store the results of speculative execution. When most of the speculations are correct, data reinstallation operations need to be performed for all speculative execution load instructions, resulting in a large performance overhead. In addition, these schemes only consider side channels established based on Dcache or TLB, while ignoring the security of other microarchitectural components in the cache system. The selective speculative execution scheme prevents the establishment of all side channels by delaying unsafe speculative execution, but the hardware taint tracking technology used in this type of scheme and the delay of a large number of unnecessary speculative instructions also bring significant hardware resources and performance overhead. In addition, the above-mentioned defense solutions lack real hardware prototypes. Most of the defense solutions are only verified through architecture simulation platforms (such as Gem5). A few solutions are verified through register-transfer level (RTL) simulation, but not through real board-level implementation with software operating system. Therefore, their practicality in real scenarios cannot be verified.
[0004] In summary, the existing defense schemes for speculative cache side channel vulnerabilities cannot meet the needs of high-performance processors, and mainly have the following deficiencies: 1) The defense scheme fails to be organically integrated with the processor microarchitecture components. At present, the scheme based on the idea of invisible speculative execution requires additional data structures and data movement operations, while the scheme based on the idea of selective speculative execution requires hardware taint tracking technology that brings complex logical calculations, all of which lead to large performance and hardware resource overhead; 2) Security and performance overhead cannot be reasonably balanced. Some defense schemes focus on defending against speculative execution instructions. Although these schemes fundamentally guarantee security, the defense scope is too large (that is, safe speculative instructions will also be defended) because only the conditions for speculative execution are considered, thereby increasing performance overhead. On the other hand, some defense schemes are insufficient in comprehensively considering the conditions for establishing cache side channels. Although these schemes narrow the defense scope, they do not fully consider the various possibilities of cache side channels, resulting in insufficient security; 3) The system evaluation lacks a real hardware prototype, and cannot provide a true evaluation of hardware mitigation measures and verification of their practicality in actual scenarios. In view of the technical problems existing in the existing schemes, the present invention provides a cache side channel elimination method based on speculative execution. This method fully considers the necessary conditions for establishing a speculative cache side channel—the triggering of the speculation window and the change of the cache system state. On the basis of solving the two key problems of the protection time and protection range of unsafe speculative memory access instructions, a hardware tracking scheme and a delay scheme for unsafe speculative memory access instructions are proposed. The delay scheme is based on the speculative memory access instructions. The changes in different states of the cache system are targeted at delaying different stages of the memory access pipeline. Finally, for the different security threats to the cache system in multi-core and single-core processors, this method implements two defense schemes based on the x86 architecture out-of-order processor model of the GEM5 simulation platform and the RISC-V open source architecture BOOM, and develops the corresponding FPGA hardware prototype.
[0005] A cache side channel elimination method based on speculative execution includes the following steps:
[0006] Step 1: Based on the speculation sources existing in the processor, clarify the start and end conditions of different speculation windows of the processor,
[0007] Step 2: Classify the speculative cache side channels according to the changes in different states of the cache system caused by the memory access instructions in the speculation window, and analyze the characteristics and protection scope of unsafe speculative memory access instructions in different types of speculative cache side channels.
[0008] Step 3: According to the different speculation windows of the processor, a hardware tracking solution for unsafe speculative memory access instructions is designed based on the processor's reorder buffer.
[0009] Step 4: Design a hardware delay strategy in a targeted manner based on the characteristics and scope of unsafe speculative memory access instructions in different types of speculative cache side channels.
[0010] Step 5: According to the different security threats faced by the cache systems in multi-core and single-core processors, hardware defense solutions combined with different hardware delay strategies are proposed respectively.
[0011] Furthermore, based on the three speculation sources of control flow prediction, memory access order prediction and value prediction inside the processor, the speculation window is divided into control flow speculation window, memory access order speculation window and value speculation window. According to the working principle of these speculation sources inside the processor, the start and end conditions of the three speculation windows are analyzed.
[0012] The conditions for starting and ending the three speculation windows in step 1 are as follows:
[0013] 1-1) Control flow speculation window: It is triggered by the control flow prediction in the processor. The control flow prediction predicts the execution direction of unresolved control instructions in the instruction stream by using the processor branch prediction unit. The control flow speculation window starts when the control instruction enters the reorder buffer (ROB) and ends when the control instruction is resolved, that is, when the branch condition or jump target address can be verified by the processor;
[0014] 1-2) Memory access order speculation window: triggered by the memory access order prediction in the processor. The memory access order prediction predicts the memory dependency between the load instruction and the unresolved store instruction in the instruction stream, i.e., the store instruction whose memory address is not returned, by using the branch disambiguator in the processor, so as to perform speculative store bypass or store-to-load forwarding. The memory access order speculation window starts when the unresolved store instruction enters the ROB and ends when the memory address of the store instruction is returned.
[0015] 1-3) Value speculation window: triggered by value prediction in the processor. Value prediction predicts the operands of the instruction being executed based on the instruction execution history by using the value predictor in the processor. The value speculation window starts when the instruction that depends on the predicted operands enters the ROB and ends when the processor can verify the prediction result of the value predictor, that is, when the execution of the instruction that the relevant operands depend on is completed.
[0016] Furthermore, based on the changes in different states of the cache system caused by memory access instructions during the speculation window, speculative cache side channels are divided into: speculative cache side channels based on occupancy state, speculative cache side channels based on consistency state, and speculative cache side channels based on replacement metadata. The characteristics and protection scope of unsafe speculative memory access instructions in different types of cache side channels are summarized;
[0017] Furthermore, the speculative cache side channels based on occupancy status are further divided into speculative cache side channels based on Dcache occupancy status, based on TLB occupancy status, and based on MSHR / LFB occupancy status;
[0018] Furthermore, the characteristics of unsafe speculative memory access instructions in different types of speculative cache side channels are as follows:
[0019] 2-1) In the speculative cache side channel based on occache status, load instructions that generate Dcache or TLB misses and store instructions that generate TLB misses are unsafe;
[0020] 2-2) In the speculative cache side channel based on MSHR / LFB occupancy status, the unsafe load instruction that can be exploited by the attacker needs to be dispatched earlier to the (old) unexecuted load instruction in the ROB queue;
[0021] 2-3) In the speculative cache side channel based on the consistency state, the load instruction that generates the Dcache miss is unsafe;
[0022] 2-4) In the speculative cache side channel based on replacement metadata, memory access instructions that generate Dcache or TLB hits are unsafe;
[0023] Furthermore, the unsafe speculative instruction hardware tracking solution includes the following steps:
[0024] 3-1) Set an unsafe attribute for each instruction of the processor architecture. When an instruction is tracked as unsafe, its unsafe attribute is set to 1;
[0025] 3-2) According to the start and end conditions of different speculation windows in step 1, the speculative nature of instructions is tracked in the reorder buffer, wherein instructions belonging to any speculation window are speculative instructions;
[0026] 3-3) According to the working principle of the speculative cache side channel, among the speculative instructions tracked in step 3-2), the initial load instruction is regarded as a secret access instruction, and the subsequent memory access instructions, including load instructions and store instructions, are regarded as possible secret transmission instructions, and their insecurity attribute is set to 1;
[0027] Furthermore, step 4 is based on the characteristics and protection scopes of the unsafe speculative memory access instructions in different types of cache side channels obtained in step 2, and is targeted at delaying the execution of speculative memory access instructions with different security threats at different stages of the memory access pipeline;
[0028] Furthermore, the different hardware delay strategies designed for unsafe speculative memory access instructions in different types of speculative cache side channels include:
[0029] 4-1) For speculative cache side channels based on TLB occupancy status, unsafe speculative load and store instructions that cause TLB misses are delayed in the address generation stage of the memory access pipeline;
[0030] 4-2) For speculative cache side channels based on Dcache occupancy status, cache refill of unsafe speculative load instructions that cause Dcache misses is delayed in the data cache stage of the memory access pipeline;
[0031] 4-3) For the speculative cache side channel based on MSHR / LFB occupancy status, the issuance of the miss request of the unsafe speculative load instruction is delayed in the data cache stage of the memory access pipeline. The delayed unsafe speculative load instruction must also meet the following conditions: (1) generate a Dcache miss; (2) there is an old load instruction that has not been executed before it;
[0032] 4-4) For the speculative cache side channel based on the consistency state, delay the issuance of all miss requests that generate Dcache miss unsafe speculative load instructions in the data cache stage of the memory access pipeline;
[0033] 4-5) For speculative cache side channels based on replacement metadata, the update of replacement policy related data by unsafe speculative memory access instructions that generate Dcache or TLB hits in the memory access pipeline is delayed until the memory access instruction enters the commit stage; further, in step 5, the cache system in the single-core processor has two security threats, namely, speculative cache side channels based on occupancy state and speculative cache side channels based on replacement metadata, while the cache system in the multi-core processor has three security threats including speculative cache side channels based on consistency state;
[0034] Furthermore, the hardware defense scheme for single-core and multi-core processors is as follows:
[0035] 5-1) According to the security threats faced by the cache system in a single core, for the impact of unsafe speculative instructions in the speculative cache side channel based on occupancy status on the occupancy status of different components of the cache system, the delay schemes of 4-1), 4-2), and 4-3) are respectively adopted, and for the speculative cache side channel based on replacement metadata, the delay scheme of 4-5) is adopted;
[0036] 5-2) According to the security threats faced by cache systems in multi-cores, the delay scheme of 4-4) is adopted for speculative cache side channels based on occupancy status and speculative cache side channels based on consistency status, and the delay scheme of 4-5) is adopted for speculative cache side channels based on replacement metadata.
[0037] The present invention solves two key problems of protection time and protection range for defending against speculative cache side channels, and provides a theoretical basis for further narrowing the scope of protected instructions, reducing the instructions affected by the defense scheme, and reducing the performance overhead of the defense scheme.
[0038] The present invention designs an efficient hardware unsafe speculative memory access instruction tracing solution, which has low hardware overhead and instant security status update compared to the previous unsafe speculative instruction tracing solution.
[0039] The present invention designs different hardware delay schemes according to the characteristics of unsafe speculative memory access instructions in different types of speculative cache side channels, delays at different stages of the memory access pipeline, and comprehensively prevents unsafe memory access instructions from changing the cache system state during the speculation window while minimizing the impact on other irrelevant instructions.
[0040] In general, the present invention achieves comprehensive protection against speculative cache side channel attacks while causing less overhead. In terms of security, the present invention prevents attackers from establishing speculative cache side channels from the attack principle by preventing memory access instructions from changing the cache system state during speculative execution. In terms of performance and hardware resources, the present invention deeply explores the inherent mechanism connection between the attack principle of speculative cache side channels and the working principle of processor pipelines, designs innovative delay strategies, integrates hardware defense solutions into the memory access pipeline, and delays the execution of unsafe speculative memory access instructions at different stages of the pipeline based on their impact on the cache system state, avoiding the impact on other irrelevant instructions and bringing less performance and hardware resource overhead. The present invention has been verified on a real FPGA hardware prototype and has high feasibility. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 Schematic diagram of the hardware delay scheme for three unsafe speculative memory access instructions. DETAILED DESCRIPTION
[0042] In order to make the purpose, technical solution and advantages of the present invention clearer, the present invention is further described in detail below through specific embodiments and drawings. It should be understood that the specific embodiments described here are only used to explain the present invention and are not used to limit the present invention.
[0043] The speculation windows in the present invention are mainly classified and defined according to the working principle of the speculation sources existing in the processor:
[0044] 1) Control flow speculation window: triggered by control flow prediction in the processor. Control flow prediction uses the processor branch prediction unit to predict the execution direction of unresolved control instructions in the instruction stream, such as branches with no return conditions or jump instructions with no determined target address. The control flow speculation window starts when the control instruction enters the ROB and ends when the control instruction is resolved, that is, when the branch condition and target address can be verified by the processor;
[0045] 2) Memory access order speculation window: triggered by the memory access order prediction in the processor. The memory access order prediction predicts the memory dependency between the load instruction and the unresolved store instruction in the instruction stream, i.e., the store instruction whose memory address is not returned, by using the branch disambiguator in the processor, so as to perform speculative store bypass or store-to-load forwarding. The memory access order speculation window starts when the unresolved store instruction enters the ROB and ends when the memory address of the store instruction is returned;
[0046] 3) Value speculation window: triggered by value prediction in the processor. Value prediction predicts the operands of the instruction being executed by using the value predictor in the processor based on the instruction execution history. The value speculation window starts when the instruction that depends on the predicted operands enters the ROB and ends when the processor can verify the prediction result of the value predictor, that is, when the instruction that the relevant operand depends on is executed.
[0047] The hardware unsafe speculative memory access instruction tracking scheme of the present invention is based on the definition of different speculation windows in the processor, uses ROB to track speculative instructions, and further marks unsafe instructions according to the principle of speculative cache side channel attack.
[0048] Table 1 shows the unsafe speculative memory access instruction tracking scheme. The unsafe speculative memory access instructions are tracked in the ROB instruction sequence. Table 1:
[0049]
[0050] As shown in example (a) in Table 1, an unresolved control instruction in the ROB means that the control flow speculation window is triggered, and all subsequent instructions are considered speculative instructions in the control flow speculation window until the relevant control flow instruction is resolved. As shown in example (b) in Table 1, an unresolved storage instruction in the ROB means that the memory access order speculation window is triggered, and all subsequent instructions are considered speculative instructions in the memory access order speculation window until the relevant storage instruction is resolved. In addition, according to the attack principle of the speculative cache side channel, the secret data needs to be accessed by the attacker through the load instruction before it can be further transmitted to the cache side channel. Therefore, only the memory access instruction after the initial load instruction in the speculation window will be marked as an unsafe instruction.
[0051] The hardware delay strategy of the present invention delays these instructions at different stages of the memory access pipeline according to the changes of different states of the cache system caused by unsafe speculative memory access instructions. Figure 1 It is a schematic diagram of the defense scheme for single-core and multi-core processor cache systems composed of different hardware delay schemes. The specific process is as follows:
[0052] 1) Some defense solutions for single-core processor cache systems are as follows: Figure 1 As shown in (a), in the address translation stage of the memory access pipeline, the memory access instruction that generates a TLB miss will undergo a security check ①. The security check ① determines whether the instruction is an unsafe speculative instruction based on the result of the hardware unsafe speculative memory access instruction tracking scheme, that is, whether the unsafe_speculative_μop parameter is 1. If the memory access instruction is an unsafe speculative instruction, the memory access instruction that generates a TLB miss will be delayed at this stage. After the TLB miss of the delayed instruction is ignored, it will be treated as a blocked memory access instruction and enter the blocking queue to wait for re-issuance into the memory access pipeline for execution.
[0053] The memory access instructions that pass the security check ① will enter the cache data stage of the memory access pipeline. In this stage, Dcache will determine whether a cache miss has occurred through tag checking. If a load instruction has caused a cache miss, the load instruction will go through the security check ②. The security check ② determines whether the instruction is an unsafe speculative instruction and whether it can be used to build a side channel based on the MSHR / LFB occupancy status, that is, whether the possible_contention_load parameter is 1. The value of the possible_contention_load parameter is determined by traversing the ROB to check whether there is an unfinished load instruction before the current load instruction. If there is, it means that the current load instruction may compete with other load instructions for the MSHR / LFB entry, and possible_contention_load is set to 1. Otherwise, possible_contention_load is set to 0. If the unsafe_speculative_μop parameter and the possible_contention_load parameter are both 1, the issuance of the cache miss request of the load instruction is blocked, and the delayed load instruction enters the blocking queue and waits for re-issuance. Instructions delayed by safety check ① and safety check ② can be re-issued when their related speculation windows end and they are verified as instructions under the correct speculation branch, that is, when unsafe_speculative_μop becomes 0. Instructions delayed by safety check ① need to restart execution from the address translation stage, while instructions delayed by safety check ② re-enter the data cache stage to issue a cache miss request when possible_contention_load is 0.
[0054] Instructions that pass security check ② can issue cache miss requests. When obtaining cache lines requested from low-level cache or memory, security check ③ will check whether the relevant load instructions are unsafe speculative memory access instructions. If so, these cache lines cannot be refilled into the current cache level through LFB until the end of the speculation window. If the load instruction is verified as an instruction that is incorrectly speculatively executed at the end of the speculation window, it will be flushed by the pipeline and the relevant LFB entry will be set invalid.
[0055] 2) Some defense solutions for multi-core processor cache systems, such as Figure 1As shown in (b), similar to a single-core processor, the execution of a memory access instruction that generates a TLB miss and fails to pass the security check ① will be delayed from the address generation stage, while the load instruction that enters the data cache stage will undergo the security check ②. The security check ② determines whether the instruction is an unsafe speculative instruction. If the load instruction is an unsafe speculative load instruction, the issuance of its cache miss request is blocked and the execution is delayed. The delayed load instruction will enter the blocking queue and can re-enter the data cache stage and issue a cache miss request only when unsafe_speculative_μop becomes 0.
[0056] 3) For memory access instructions that have TLB and Dcache hits, the defense schemes in both multi-core and single-core processors adopt the strategy of delaying the replacement of metadata updates. Figure 1 (b) Take the update of cache replacement metadata by delaying Dcache hit as an example. The memory access instruction that generates the Dcache hit needs to pass security check ④. Security check ④ will check whether the related load instruction is an unsafe speculative memory access instruction. The invention sets an update_metadata attribute for each memory access operation. For the Dcache hit operation of the unsafe speculative memory access instruction, its update_metadata will be set to 0, indicating that the operation cannot update the related replacement metadata of the access cache line. If the memory access operation whose update replacement metadata is delayed enters the commit phase, a memory access that does not need to be written back will be re-executed, which is only used to update the replacement metadata.
[0057] The above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit the same. Relevant technicians in the field may modify or replace the technical solutions of the present invention with equivalents without departing from the spirit and scope of the present invention. The protection scope of the present invention shall be based on the claims.
Claims
1. A hardware defense method against speculative cache side channel attacks, characterized in that: The following steps are involved: Step 1: Based on the speculation sources existing in the processor, clarify the start and end conditions of different speculation windows of the processor, Step 2: Classify the speculative cache side channels according to the changes in different states of the cache system caused by the memory access instructions in the speculation window, and analyze the characteristics and protection scope of unsafe speculative memory access instructions in different types of speculative cache side channels. Step 3: According to the different speculation windows of the processor, a hardware tracking solution for unsafe speculative memory access instructions is designed based on the processor's reorder buffer. Step 4: Design a hardware delay strategy in a targeted manner based on the characteristics and scope of unsafe speculative memory access instructions in different types of speculative cache side channels. Step 5: According to the different security threats faced by the cache systems in multi-core and single-core processors, hardware defense solutions combined with different hardware delay strategies are proposed respectively.
2. The hardware defense method against speculative cache side channel attacks according to claim 1, characterized in that: Step 1 divides the speculation window into control flow speculation window, memory access order speculation window, and value speculation window based on the three speculation sources inside the processor: control flow prediction, memory access order prediction, and value prediction. According to the working principles of these speculation sources inside the processor, the start and end conditions of the three speculation windows are analyzed.
3. The hardware defense method against speculative cache side channel attacks according to claim 2, characterized in that: The conditions for starting and ending the three speculation windows in step 1 are as follows: 1-1) Control flow speculation window: It is triggered by the control flow prediction in the processor. The control flow prediction predicts the execution direction of unresolved control instructions in the instruction stream by using the processor branch prediction unit. The control flow speculation window starts when the control instruction enters the reorder buffer (ROB) and ends when the control instruction is resolved, that is, when the branch condition or jump target address can be verified by the processor; 1-2) Memory access order speculation window: triggered by the memory access order prediction in the processor. The memory access order prediction predicts the memory dependency between the load instruction and the unresolved store instruction in the instruction stream, i.e., the store instruction whose memory address is not returned, by using the branch disambiguator in the processor, so as to perform speculative store bypass or store-to-load forwarding. The memory access order speculation window starts when the unresolved store instruction enters the ROB and ends when the memory address of the store instruction is returned. 1-3) Value speculation window: triggered by value prediction in the processor. Value prediction predicts the operands of the instruction being executed based on the instruction execution history by using the value predictor in the processor. The value speculation window starts when the instruction that depends on the predicted operands enters the ROB and ends when the processor can verify the prediction result of the value predictor, that is, when the execution of the instruction that the relevant operands depend on is completed.
4. The hardware defense method against speculative cache side channel attacks according to claim 1, characterized in that: Step 2 divides the speculative cache side channels into the following types: speculative cache side channels based on occupancy state, speculative cache side channels based on consistency state, and speculative cache side channels based on replacement metadata, based on the changes in different states of the cache system caused by memory access instructions during the speculation window. The characteristics and protection scope of unsafe speculative memory access instructions in different types of cache side channels are summarized.
5. The hardware defense method against speculative cache side channel attacks according to claim 4, characterized in that: The speculative cache side channels based on occupancy status can be divided into speculative cache side channels based on data cache (Data Cache, Dcache) occupancy status, based on translation lookside buffer (Translation Lookside Buffer, TLB) occupancy status, and based on missing status holding register (Missing Status Holding Register, MSHR) or line fill buffer (Line Fill Buffer, LFB) occupancy status according to different micro-architecture components in the processor cache system.
6. The hardware defense method against speculative cache side channel attacks according to claim 4, characterized in that: The characteristics of the unsafe speculative memory access instructions in different types of speculative cache side channels in step 2 are as follows: 2-1) In the speculative cache side channel based on occache status, load instructions that generate Dcache or TLB misses and store instructions that generate TLB misses are unsafe; 2-2) In the speculative cache side channel based on MSHR / LFB occupancy status, the unsafe load instruction that can be exploited by the attacker needs to have an earlier (old) unexecuted load instruction that was dispatched into the ROB queue; 2-3) In the speculative cache side channel based on the consistency state, the load instruction that generates the Dcache miss is unsafe; 2-4) In the speculative cache side channel based on replacement metadata, memory access instructions that generate Dcache or TLB hits are unsafe.
7. The hardware defense method against speculative cache side channel attacks according to claim 1, characterized in that: The hardware tracking solution for the unsafe speculative memory access instruction in step 3 includes the following steps: 3-1) Set an unsafe attribute for each instruction of the processor architecture. When an instruction is tracked as unsafe, its unsafe attribute is set to 1; 3-2) According to the start and end conditions of different speculation windows in step 1, the speculative nature of instructions is tracked in the ROB, where instructions belonging to any speculation window are speculative instructions; 3-3) According to the working principle of the speculative cache side channel, the initial load instruction in the speculative instructions of 3-2) is regarded as a secret access instruction, and the subsequent memory access instructions, including load instructions and store instructions, are regarded as possible secret transmission instructions, and their insecurity attribute is set to 1.
8. The hardware defense method against speculative cache side channel attacks according to claim 1, characterized in that: The step 4 is based on the characteristics and protection scope of the unsafe speculative memory access instructions in the different types of cache side channels obtained in step 2, and specifically designs a hardware delay strategy to delay the execution of speculative memory access instructions with different security threats at different stages of the memory access pipeline.
9. The hardware defense method against speculative cache side channel attacks according to claim 8, characterized in that: The different hardware delay strategies designed in step 4 for unsafe speculative memory access instructions in different types of speculative cache side channels include: 4-1) For speculative cache side channels based on TLB occupancy status, unsafe speculative load and store instructions that cause TLB misses are delayed in the address generation stage of the memory access pipeline; 4-2) For speculative cache side channels based on Dcache occupancy status, cache refill of unsafe speculative load instructions that cause Dcache misses is delayed in the data cache stage of the memory access pipeline; 4-3) For the speculative cache side channel based on MSHR / LFB occupancy status, the issuance of the miss request of the unsafe speculative load instruction is delayed in the data cache stage of the memory access pipeline. The delayed unsafe speculative load instruction must also meet the following conditions: 1) generate a Dcache miss; 2) there is an old unfinished load instruction before it; 4-4) For the speculative cache side channel based on the consistency state, delay the issuance of all miss requests that generate Dcache miss unsafe speculative load instructions in the data cache stage of the memory access pipeline; 4-5) For speculative cache side channels based on replacement metadata, the update of replacement policy related data by unsafe speculative memory access instructions that generate Dcache or TLB hits in the memory access pipeline is delayed until the memory access instruction enters the commit stage.
10. The hardware defense method against speculative cache side channel attacks according to claim 1, characterized in that: In step 5, the cache system in the single-core processor has two security threats: a speculative cache side channel based on occupancy state and a speculative cache side channel based on replacement metadata, and the cache system in the multi-core processor has three security threats including a speculative cache side channel based on consistency state; The step 5 proposes a hardware defense solution for single-core and multi-core processors based on the hardware delay strategy of step 4 as follows: 5-1) According to the security threats faced by the cache system in a single core, for the impact of unsafe speculative instructions in the speculative cache side channel based on occupancy status on the occupancy status of different components of the cache system, the delay schemes of 4-1), 4-2), and 4-3) are respectively adopted, and for the speculative cache side channel based on replacement metadata, the delay scheme of 4-5) is adopted; 5-2) According to the security threats faced by cache systems in multi-cores, the delay scheme of 4-4) is adopted for speculative cache side channels based on occupancy status and speculative cache side channels based on consistency status, and the delay scheme of 4-5) is adopted for speculative cache side channels based on replacement metadata.