Fuzzy testing method for transient execution vulnerability detection of RISCV processor based on taint tracking
Through the fuzz testing method based on taint tracking, the problem of limited ability to detect transient vulnerabilities in RISCV processors is solved, and more efficient transient window triggering and confidential data leakage path analysis is achieved, improving the accuracy and efficiency of vulnerability detection.
Patent Information
- Application Number
- CN202510201900.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-13
AI Technical Summary
The existing fuzz testing technology has limited ability to detect transient execution vulnerabilities in RISCV processors, and cannot effectively trigger transient windows, and it is difficult to accurately judge the path of confidential data leakage, and there are false positive and false negative problems.
Using a fuzz testing method based on taint tracking, a test program is generated through the processor differential execution unit and the taint propagation network to trigger a transient window, and analyzing the leak path of confidential data through the taint propagation report, improving the accuracy and efficiency of vulnerability detection.
It improves the triggering ability of the transient window, accurately senses the leakage path of confidential data, accurately identifys the occurrence and cause of transient vulnerabilities, and reduces false positive and false negative problems.
Smart Images

Figure CN120145392A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of processor verification, and in particular, to a fuzz testing method for detecting transient execution vulnerabilities of a RISCV processor based on taint tracking. Background Art
[0002] Since the disclosure of transient execution vulnerabilities such as Spectre and Meltdown, various transient execution vulnerabilities such as ForeShadow, CacheOut, Ret2Spec, RIDL, MDS, and FPVI have emerged continuously - transient execution vulnerabilities have become critical vulnerabilities in modern CPUs. And because they exploit the most fundamental hardware vulnerabilities to launch attacks, any entity running on the CPU may become an attacker and a victim. Constrained by the irreparability of hardware vulnerabilities, it is crucial to discover transient execution vulnerabilities during the RTL development stage and repair them in a timely manner. As a booming emerging processor architecture, various manufacturers have increasingly emphasized the detection and protection of transient execution vulnerabilities during the RTL design and development stage of the RISCV processor.
[0003] Software fuzz testing technology has been widely used for vulnerability mining of software and has achieved great development. With the continuous maturity of software fuzz testing technology, this technology has been migrated and applied to the field of correctness verification and vulnerability detection in the development stage of the RISCV processor, and many influential hardware functional vulnerabilities and transient execution vulnerabilities have been discovered. However, the current fuzz testing technology for transient execution vulnerabilities still has the following multiple problems:
[0004] 1. The transient vulnerability mining ability of the existing fuzz testing technology is limited, the types of vulnerabilities that can be covered are limited, and the efficiency of mining transient vulnerabilities is low;
[0005] 2. The existing fuzz testing technology has poor control ability over the microarchitecture state of the processor, and there are problems such as low efficiency in triggering the transient execution window and a single type of triggered transient window;
[0006] 3. The existing fuzz testing technology has limited observation ability of the internal information of the processor and it is difficult to determine whether a transient vulnerability is triggered;
[0007] 4. The existing confidential data leakage detection technology based on taint transmission has problems such as control flow taint explosion, difficulty in verifying the effectiveness of tracking sensitive information, and high degrees of false positives and false negatives.
[0008] Therefore, a fuzz testing method for transient execution vulnerabilities of a RISCV processor is needed to improve the triggering ability of the transient window, more accurately perceive the leakage path of confidential data, and thus more accurately identify the occurrence and causes of transient vulnerabilities. Summary of the Invention
[0009] In view of the deficiencies of the prior art, the purpose of the embodiments of the present application is to provide a fuzz testing method for detecting transient execution vulnerabilities of RISCV processors based on taint tracking.
[0010] The present invention is implemented through the following technical solutions:
[0011] The present invention is a fuzz testing method for detecting transient execution vulnerabilities of RISCV processors based on taint tracking. The testing method is implemented through the following device:
[0012] The device includes a processor differential execution unit. The processor differential execution unit includes a processor test unit. The processor test unit includes a RISCV processor circuit to be tested, a taint tracking network obtained by instrumentation, a switchable memory unit, and a RoB input / output event monitoring unit;
[0013] The taint tracking network is a topological network composed of a taint propagation unit and a taint validity unit. It obtains circuit signals from the RISCV processor circuit to be tested and taint signals from the switchable memory unit, calculates and propagates the taint signals within the network logic according to the circuit signals, and finally generates a taint propagation report according to the taint signal propagation situation; The taint propagation unit is a circuit unit corresponding one-to-one to the RTL unit of the RISCV processor circuit, obtains the taint signal from the previous taint propagation unit and the data input signal of the corresponding RTL unit, calculates the taint signal, and passes it to the subsequent taint propagation unit or the taint validity unit; The taint validity unit obtains the taint signal from the taint propagation unit and the taint validity signal of the RISCV processor circuit, and passes the calculated taint signal to the subsequent taint propagation unit;
[0014] The switchable memory unit is used as the memory unit of the processor test unit, and is composed of multiple groups of independent physical memories and a memory switching interface. It obtains memory read / write requests from the processor test unit and returns memory read / write results and taint signals; The memory switching interface obtains a memory switching request from the RISCV processor circuit and generates a new physical memory and physical address mapping layout and returns it to the RISCV processor circuit;
[0015] The RoB input / output event monitoring unit obtains the instruction enqueue enable signal, enqueued instruction signal, instruction dequeue enable signal, and dequeued instruction signal from the RoB unit inside the RISCV processor circuit, and generates an RTL execution log for the enqueue and dequeue time and content of the instruction; The testing method includes the following steps:
[0016] 1) Generate a new test program P1 that triggers the transient window using a semantic-based test program generation method, hand it over to the processor differential execution unit for simulation execution, and generate an execution log;
[0017] 2) Analyze the execution log to determine whether the test program P1 triggers a transient window. If successful, continue the execution; otherwise, return to the previous step to generate a new test program P1.
[0018] 3) Based on the semantic-based test program generation method, generate a new test program P2 that accesses confidential data in the transient window on the basis of test program P1, and hand it over to the processor differential execution unit for simulation execution to generate an execution log and a taint propagation report.
[0019] 4) Analyze the execution log and the taint propagation report to determine whether the test program P2 accesses secret data. If successful, continue the execution; otherwise, return to the previous steps to generate a new test program P1 or P2.
[0020] 5) Based on the semantic-based test program generation method, generate a new test program P3 that leaks confidential data in the transient window on the basis of test program P3, and hand it over to the processor differential execution unit for simulation execution to generate an execution log and a taint propagation report.
[0021] 6) Analyze the execution log and the taint propagation report to determine whether the test program P3 leaks confidential data. If the leakage is successful, analyze the corresponding reason for the confidential data leakage.
[0022] 7) Calculate the fuzz testing coverage rate according to the taint propagation report, guide mutation according to the fuzz testing coverage rate, and select to return to the above steps to regenerate the test program P1, P2 or P3.
[0023] As a further improvement, the taint propagation unit described in the present invention is specifically: for each type of RTL unit of the RISCV processor circuit, a corresponding type of taint propagation unit will be constructed. The taint propagation units are interconnected according to the topological network of the RTL units of the RISCV processor circuit to form a taint tracking network. The input of each taint propagation unit is the data input of the corresponding RTL component in two RISCV processor circuits inside the processor differential execution unit, and the corresponding taint input in the taint tracking network. The taint propagation unit calculates the data input and the taint input according to its own type to determine whether to propagate the taint to the subsequent taint propagation unit.
[0024] As a further improvement, the taint validity unit described in the present invention is specifically: the input of the taint validity unit is the taint output of the taint propagation unit and the data validity signal of the corresponding RTL unit of the taint propagation unit in the RISCV processor circuit. When the data validity signal is 1, the taint validity unit outputs the input taint signal; otherwise, it outputs 0.
[0025] As a further improvement, the method for generating a test program based on semantics according to the present invention is specifically as follows: Design a semantic-level primitive mutation configuration range according to the semantics of the test program. Each time a test program is generated, a primitive configuration is randomly mutated, and then a corresponding test program is generated according to the primitive configuration. The generated test program includes a set of binary segments and a configuration file recording the physical address range of each binary segment, and different binary segments are allowed to have the same physical address range.
[0026] As a further improvement, the simulation execution of the processor differential execution unit according to the present invention includes but is not limited to the following steps:
[0027] 1) Compile the processor differential execution unit into an executable program using a hardware simulator;
[0028] 2) Deliver the binary segments and configuration file of the generated test program P1 or P2 or P3 to the executable program for execution;
[0029] 3) The switchable memory unit simulated by the executable program generates a memory layout according to the binary segments and configuration file of the test program;
[0030] 4) The RISCV processor circuit to be tested simulated by the executable program executes the binary program according to the memory layout and generates a corresponding processor execution flow;
[0031] 5) The RoB input / output time monitoring module simulated by the executable program detects the instruction enqueue and dequeue information in the RoB according to the processor execution flow and generates an execution log;
[0032] 6) The taint simulated by the executable program calculates and transmits the taint according to the processor execution flow and generates a corresponding taint propagation report.
[0033] As a further improvement, the method for determining the leakage of confidential data according to the present invention includes but is not limited to the following steps:
[0034] 1) Analyze the execution log. If the two RTL execution times of the execution simulation program are inconsistent, confidential data is leaked through the time side channel;
[0035] 2) If the execution times are consistent, analyze the taint propagation report and locate the component that leaks confidential data according to the taint distribution of each component.
[0036] Calculating the fuzz testing coverage rate according to the taint propagation report and guiding the mutation according to the fuzz testing coverage rate is specifically as follows: Use the number of taints of each sub-component recorded in the taint propagation report as the coverage rate index, count the number of newly covered ones, and use the ratio of the newly added coverage rate to the average newly added coverage rate during the fuzz testing as the index for fuzz testing exploration. Select to re-mutate P1, P2, and P3 according to the size of this index.
[0037] Compared with the prior art, the technical innovation points of the present invention are as follows:
[0038] 1. Taint propagation technology, which generates taint transfer units with different functions for different RTL components. By specifically redesigning the taint propagation unit, the accuracy of taint propagation is improved, and problems such as false positives and false negatives are reduced. By considering the data differences existing in differential execution, the taint transfer is filtered to reduce the false positive problem of taint propagation.
[0039] 2. Taint validity unit, according to the RTL semantics, uses the RTL signal representing data validity to represent the taint validity of the taint propagation unit generated by instrumentation, so that the taint is only valid when the corresponding data is valid. By this method, the taints corresponding to invalid data can be effectively filtered, reducing the false positives of taint propagation.
[0040] 3. Test program generation method, designs the meta-language mutation configuration range at the semantic level according to the test program semantics. Each time a test program is generated, a meta-language configuration is randomly mutated, and then the corresponding test program is generated according to the meta-language configuration. The generated test program allows different program segments to execute on the same physical address. This method enables the test program to meet various complex program constraints at the semantic level, improves the ability of the test program to execute complex functions, and improves the ability to trigger transient windows and leak confidential data.
[0041] 4. Simulation of the processor differential execution unit, this method enables the taint tracking network to simultaneously accept the execution results from two RISCV processor circuits, and more accurate taint propagation is obtained by analyzing the result differences between the two, reducing the false positive and false negative problems of taint propagation.
[0042] 5. Method for judging the leakage of confidential data, determines the components that leak confidential data according to the taint distribution of each component. By using the taint tracking of the propagation of internal confidential data in the processor, the propagation path of the confidential data can be accurately observed, and then the occurrence of transient attacks, the components where confidential data is leaked, and the reasons for the occurrence of transient attacks can be more accurately confirmed.
[0043] 6. Calculate the fuzz testing coverage rate according to the taint propagation report, use the number of taints of each sub-component as the coverage rate index, count the number of newly covered ones, and according to the ratio of the newly increased coverage rate and the average newly increased coverage rate during fuzz testing, select re-mutation according to the threshold range. By guiding the mutation through the evaluation of the coverage rate growth speed, it is beneficial to improve the exploration efficiency of fuzz testing, and then improve the mining efficiency of transient vulnerabilities. Description of the Drawings
[0044] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0045] Figure 1 It is a unit diagram of a processor differential execution unit used in a fuzz testing method for transient execution vulnerability detection of a RISCV processor based on taint tracking shown according to an exemplary embodiment;
[0046] Figure 2 It is a flowchart of a fuzz testing method for transient execution vulnerability detection of a RISCV processor based on taint tracking shown according to an exemplary embodiment. Detailed implementation manners
[0047] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application.
[0048] The terms used in this application are only for the purpose of describing specific embodiments and are not intended to limit this application. The singular forms "a" and "the" used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0049] It should be understood that although terms such as first, second, and third may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0050] The invention discloses a fuzz testing method for transient execution vulnerability detection of a RISCV processor based on taint tracking. Figure 1 It is a unit diagram of a processor differential execution unit for a fuzz testing method for transient execution vulnerability detection of a RISCV processor. Referring to Figure 1 , the device may include:
[0051] The device includes a processor differential execution unit, which includes a processor test unit. The processor test unit includes a RISCV processor circuit to be tested, a taint tracking network obtained by instrumentation, a switchable memory unit, and a RoB input / output event monitoring unit.
[0052] The taint tracking network is a topological network composed of a taint propagation unit and a taint validity unit. It obtains circuit signals from the RISCV processor circuit to be tested and taint signals from the switchable memory unit, calculates and propagates the taint signals inside the network logic according to the circuit signals, and finally generates a taint propagation report based on the taint signal propagation situation. The taint propagation unit is a circuit unit corresponding one-to-one to the RTL unit of the RISCV processor circuit. It obtains the taint signal from the previous taint propagation unit and the data input signal of the corresponding RTL unit, calculates the taint signal, and then passes it to the subsequent taint propagation unit or the taint validity unit. The taint validity unit obtains the taint signal from the taint propagation unit and the taint validity signal of the RISCV processor circuit, calculates the taint signal, and then passes it to the subsequent taint propagation unit.
[0053] The switchable memory unit is used as the memory unit of the processor test unit and is composed of multiple groups of independent physical memories and a memory switching interface. It obtains memory read / write requests from the processor test unit and returns memory read / write results and taint signals. The memory switching interface obtains a memory switching request from the RISCV processor circuit and generates a new physical memory and physical address mapping layout to return to the RISCV processor circuit.
[0054] The RoB input / output event monitoring unit obtains the instruction enqueue enable signal, enqueued instruction signal, instruction dequeue enable signal, and dequeued instruction signal from the internal RoB unit of the RISCV processor circuit, and generates an RTL execution log of the instruction enqueue / dequeue time and content.
[0055] This application provides an embodiment of a fuzz testing method for detecting transient execution vulnerabilities of RISCV processors.
[0056] Figure 2 It is a flowchart of a fuzz testing method for detecting transient execution vulnerabilities of RISCV processors based on taint tracking shown according to an exemplary embodiment, as Figure 1 shown. This method is applied to a terminal and may include the following steps:
[0057] Step 1. Use the semantic-based test program generation method to generate a new test program P1 for triggering the transient window, and hand it over to the processor differential execution unit for simulation execution to generate an execution log. This method first randomly generates transient window trigger instructions according to the transient window trigger types in the seeds. These transient window trigger instructions cover the entire basic instruction set, including sequential execution instructions (e.g., integer or floating-point arithmetic operations, valid memory accesses), control transfer instructions (e.g., branches, indirect jumps, and returns), and instructions that trigger exceptions (e.g., illegal instructions, memory access violations). Next, this method generates a virtual transient window filled with nop instructions as the target window triggered by the transient window trigger instructions. For sequential execution instructions and exceptions, by default, the transient window is placed after the trigger instruction; for control transfer instructions, this method randomly selects whether to place the transient window immediately after the trigger instruction. Finally, this method uses an instruction set simulator to calculate the operands required to trigger the transient window and generate the relevant register initialization instructions. This constitutes the code execution flow for triggering the transient window.
[0058] This method uses the layout of the transient window trigger instructions to help generate the microarchitecture state training code execution flow. Each training code execution flow contains a microarchitecture training operation consisting of a small number of instructions. This method generates multiple independent training code execution flows in this step. This method first randomly generates training code for components such as branch prediction or memory hierarchy. Then, this method aligns the instruction addresses of the training part with the instruction addresses of the instructions that trigger the transient window by inserting nop instructions. This method also adjusts the control flow of the training operation to match the position of the planned transient window, improving the training effectiveness of branch prediction. The binary and configuration files corresponding to the above code execution flow for triggering the transient window and the code execution flow for microarchitecture state training constitute the test program P1. Hand the test program P1 over to the processor differential execution unit for simulation execution to generate an execution log.
[0059] Step 2. Analyze the execution log to determine whether the test program P1 triggers the transient window. This method analyzes the instruction input and output events in the processor's RoB (reorder buffer) from the execution log obtained by the processor differential execution unit. If the number of instructions entering the RoB exceeds the number of instructions it has committed, it means that the transient window has been successfully triggered. If the execution is successful, proceed to the next step; otherwise, return to the previous step.
[0060] Step 3: Based on the semantic-based test program generation method, generate a new test program P2 that accesses confidential data in the transient window on the basis of test program P1, and hand it over to the processor differential execution unit for simulation execution to generate an execution log and a taint propagation report. This method replaces the virtual transient window with a real payload and generates additional required training execution flows to complete the test case. This method generates a secret access block in the window part. In the secret access block, in addition to the fixed instructions for accessing sensitive data, it also randomly masks the high-order bits of the address in an attempt to conceal MDS-type bugs. Similar to triggering the transient window execution flow, this method also generates a window training execution flow for the confidential data access block. This method attempts to pre-load sensitive data into the internal buffers of the processor in advance, such as the data cache and the load / store buffer. The generated window training code execution flow is arranged before the trigger training code execution flow in the swap plan to avoid affecting the triggering of the transient window. This method simulates the execution of the above test execution flow as a payload to generate a corresponding taint propagation report, which records the taint distribution of each component in each clock cycle.
[0061] Step 4: Analyze the execution log and the taint propagation report to determine whether test program P2 accesses secret data. By analyzing the taint propagation report, if it is found that the total taint inside the processor increases within the time range after entering the transient window, it indicates that the processor has indeed successfully accessed secret data. Therefore, it is considered that test program P2 has successfully accessed secret data and enters the next stage. Otherwise, the access to secret data fails, and return to the previous stage to mutate P1 or P2 again.
[0062] Step 5: Based on the semantic-based test program generation method, generate a new test program P3 that leaks confidential data in the transient window on the basis of test program P3, and hand it over to the processor differential execution unit for simulation execution to generate an execution log and a taint propagation report. This method generates a secret encoding block in the window part. In the secret encoding block, this method randomly generates instructions that depend on the secret in order to spread the secret throughout the microarchitecture. This method simulates the execution of the above test execution flow as a payload to generate a corresponding taint propagation report, which records the taint distribution of each component in each clock cycle.
[0063] Step 6: Analyze the execution log and the taint propagation report to determine whether the test program P3 leaks confidential data. It first compares the execution times of the transient windows between the processors of two execution flows that execute different confidential data. If they are inconsistent, it indicates that sensitive data may be leaked through the timing side channel during the transient window, such as port contention. This method directly reports these test cases as potential vulnerabilities. Although test cases with a constant transient execution time cannot directly leak secrets through the timing side channel, the encoded sensitive data may still be leaked through other covert channels. Since accessing sensitive data during the training process also generates taint propagation, this method replaces the confidential data encoding block in the transient window trigger execution flow with nop instructions and re-runs the simulation. By comparing the replaced taint log with the original taint log, it determines whether the confidential data encoding block can cause the leakage of confidential data. If the leakage is successful, it analyzes the corresponding reasons for the leakage of confidential data.
[0064] Step 7: Calculate the fuzzing coverage based on the taint propagation report and guide mutation according to the fuzzing coverage. This method introduces the first confidential data propagation coverage metric designed for transient execution vulnerabilities. Within the taint coverage, the total number of taints in a local component is used as an independent coverage point. Specifically, this method inserts a new register array bitmap into each RTL module. In each clock cycle, this method uses the number of registers marked as tainted within the module as an index and sets the corresponding slot. After transient execution, this method collects the slot indices in the bitmap of each module. This method evaluates the quality of the generated test program based on the total number of "module, index" pairs collected. If the coverage increase is less than the average increase or no sensitive data is propagated, this method will change the seed to regenerate the window part. If the result still shows insufficient coverage growth after multiple attempts, this method will discard the test program mutation and return to the previous step to regenerate the new test programs P1 and P2. Otherwise, it continues to mutate based on P3.
[0065] Those skilled in the art will readily conceive of other embodiments of the present application after considering the specification and practicing the content disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application.
Claims
1. A fuzzy testing method for transient execution vulnerability detection of RISC-V processor based on taint tracking, characterized in that: The test method is implemented by the following device: The device includes a processor differential execution unit, the processor differential execution unit includes a processor test unit, the processor test unit includes a RISCV processor circuit to be tested, a taint tracking network obtained by inserting a pile, a switchable memory unit, and a RoB input and output event monitoring unit; The taint tracking network is a topological network composed of a taint propagation unit and a taint validity unit, which obtains a circuit signal from a RISCV processor circuit to be tested and a taint signal from a switchable memory unit, calculates and propagates the taint signal within the network logic according to the circuit signal, and finally generates a taint propagation report according to the propagation of the taint signal; the taint propagation unit is a circuit unit corresponding to the RTL unit of the RISCV processor circuit one by one, obtains the taint signal from the previous taint propagation unit and the data input signal of the corresponding RTL unit, calculates the taint signal, and transmits it to the subsequent taint propagation unit or the taint validity unit; The taint validity unit obtains the taint signal from the taint propagation unit and the taint validity signal of the RISCV processor circuit, and calculates and transmits the taint signal to the subsequent taint propagation unit; The switchable memory unit is used as a memory unit of the processor test unit, and is composed of multiple sets of independent physical memories and a memory switching interface, which obtains memory read and write requests from the processor test unit and returns memory read and write results and taint signals; The memory switching interface receives a memory switching request from the RISCV processor circuit, generates a new physical memory and physical address mapping layout and returns it to the RISCV processor circuit; The RoB input and output event monitoring unit obtains the instruction enqueue enable signal, the enqueue instruction signal, the instruction dequeue enable signal, and the dequeue instruction signal from the RoB unit inside the RISCV processor circuit, and generates an RTL execution log with the instruction enqueue and dequeue time and content; The testing method comprises the following steps: 1) Generate a new test program P1 that triggers the transient window using a semantic-based test program generation method, and send it to the processor differential execution unit for simulation execution to generate an execution log; 2) Analyze the execution log to determine whether the test program P1 triggers the transient window. If successful, continue to execute. Otherwise, return to the previous step to generate a new test program P1; 3) Using the semantic-based test program generation method, a new test program P2 for accessing confidential data in the transient window is generated based on the test program P1, and the new test program P2 is sent to the processor differential execution unit for simulation execution, and an execution log and a taint propagation report are generated; 4) Analyze the execution log and taint propagation report to determine whether the test program P2 accesses secret data. If successful, continue to execute. Otherwise, return to the previous step to generate a new test program P1 or P2; 5) Using the semantic-based test program generation method, a new test program P3 that leaks confidential data in the transient window is generated based on the test program P3, and the new test program P3 is sent to the processor differential execution unit for simulation execution, and an execution log and a taint propagation report are generated; 6) Analyze the execution log and taint propagation report to determine whether the test program P3 leaks confidential data. If so, analyze the corresponding confidential data leakage cause; 7) Calculate the fuzz test coverage according to the taint propagation report, guide mutation according to the fuzz test coverage, choose to return to the above steps, and regenerate the test program P1, P2 or P3.
2. The fuzzy testing method for transient execution vulnerability detection of RISCV processor based on taint tracking according to claim 1 is characterized in that: The taint propagation unit is specifically: for each type of RTL unit of the RISCV processor circuit, a corresponding type of taint propagation unit is constructed. The taint propagation units are interconnected according to the topological network of the RTL unit of the RISCV processor circuit to form a taint tracking network. The input of each taint propagation unit is the data input of the corresponding RTL components in the two RISCV processor circuits inside the processor differential execution unit, and the corresponding taint input in the taint tracking network. The taint propagation unit calculates the data input and the taint input according to its own type to determine whether to propagate the taint to the subsequent taint propagation unit.
3. The fuzzy testing method for transient execution vulnerability detection of RISCV processor based on taint tracking according to claim 1 is characterized in that: The taint validity unit is specifically: the input of the taint validity unit is the taint output of the taint propagation unit, and the data validity signal of the RTL unit corresponding to the taint propagation unit in the RISCV processor circuit. When the data validity signal is 1, the taint validity unit outputs the input taint signal, otherwise it outputs 0.
4. The fuzz testing method for transient execution vulnerability detection of RISCV processor based on taint tracking according to claim 1, 2 or 3, characterized in that: The semantics-based test program generation method is specifically as follows: a semantic-level meta-language mutation configuration range is designed according to the test program semantics, a meta-language configuration is randomly mutated each time a test program is generated, and then a corresponding test program is generated according to the meta-language configuration. The generated test program includes a set of binary fragments and a configuration file that records the physical address range of each binary fragment, allowing different binary fragments to have the same physical address range.
5. According to the fuzzy testing method for transient execution vulnerability detection of RISC-V processor based on taint tracking as claimed in claim 4, the simulation execution of the processor differential execution unit includes but is not limited to the following steps: 1) Compile the processor differential execution unit into an executable program using a hardware simulator; 2) delivering the generated binary fragment and configuration file of the test program P1, P2 or P3 to the executable program for execution; 3) The switchable memory unit simulated by the executable program generates a memory layout based on the binary fragment and configuration file of the test program; 4) The RISC V processor circuit to be tested simulated by the executable program executes the binary program according to the memory layout and generates a corresponding processor execution flow; 5) The RoB input and output time monitoring module simulated by the executable program detects the instruction enqueue and dequeue information in the RoB according to the processor execution flow and generates an execution log; 6) The taint simulated by the executable program is calculated and transmitted according to the processor execution flow, and a corresponding taint propagation report is generated.
6. The fuzzy testing method for transient execution vulnerability detection of RISCV processor based on taint tracking according to claim 1, 2, 3 or 5, characterized in that: The method for determining the leakage of confidential data includes but is not limited to the following steps: 1) Analyze the execution log. If the execution times of the two RTLs executing the simulation program are inconsistent, confidential data will be leaked through the time side channel. 2) If the execution time is consistent, analyze the taint propagation report and locate the component that leaks confidential data based on the taint distribution of each component.
7. The fuzzy testing method for transient execution vulnerability detection of RISCV processor based on taint tracking according to claim 6 is characterized in that: The method of calculating the fuzz test coverage based on the taint propagation report and guiding mutation based on the fuzz test coverage is as follows: using the number of taints of each sub-component recorded in the taint propagation report as the coverage indicator, counting the number of newly added coverage, and using the ratio of the newly added coverage to the average newly added coverage during the fuzz test as the indicator of fuzz test exploration, and selecting P1, P2, and P3 for re-mutation based on the size of the indicator.