Instruction pointer stride prefetcher side channel attack defense method based on prefetch interception
By introducing a response bit field in the instruction pointer stride prefetcher and updating the strategy, the problem that existing defense schemes cannot effectively defend against side channel and covert channel attacks is solved, and an efficient and low-overhead defense effect is achieved, while the functionality of the prefetcher is retained to the maximum extent.
Patent Information
- Application Number
- CN202510698747.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-09-05
AI Technical Summary
Existing hardware prefetcher defense solutions cannot effectively defend against side channel and covert channel attacks on the instruction pointer stride prefetcher, and existing software and hardware defense methods have performance losses or additional burdens.
A response bit field is added to the storage structure of the instruction pointer stride prefetcher. By updating the strategy, only potentially risky unauthorized prefetching behaviors are intercepted after the context switch, and the confidence and stride fields are combined to determine whether to trigger the prefetch request.
It achieves efficient defense against instruction pointer stride prefetcher side channel attacks with extremely low space and performance overhead, reduces the impact range of defense measures, maximizes the functionality of the prefetcher, and prevents information leakage.
Smart Images

Figure CN120602068A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer micro-architecture security, and in particular to a method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception. Background Art
[0002] In recent years, the security of hardware prefetchers has gradually come into the spotlight. Hardware prefetchers are a crucial component of improving performance efficiency in modern computer design. At different memory levels, corresponding hardware registers are designed based on a variety of memory access patterns. Among these, Intel's instruction pointer stride prefetcher, with its flexible prefetching mechanism and large prefetch range, has become a promising medium for side-channel and covert channel attacks. The instruction pointer stride prefetcher tracks the stride between data requested by load instructions that record the same instruction address, and resets or accumulates confidence levels based on a comparison of the current stride with historical strides. When the confidence level reaches a set threshold, the instruction pointer stride prefetcher prefetches the next data based on the learned pattern. The address of this data is the sum of the current address and the recorded stride.
[0003] Previous work has shown that attackers can use side-channel attacks to steal the private key of the elliptic curve Diffie-Hellman algorithm and the key of the AES symmetric encryption algorithm through the instruction pointer stride prefetcher. In addition, there is also work that uses the instruction pointer stride prefetcher to construct a covert channel attack. However, these works did not find a way to observe the internal state of the instruction pointer stride prefetcher, and still used the cache time side channel to indirectly observe the prefetcher state. During the attack, they used traditional cache-based attack techniques such as flush+reload attacks or frequently cleared the corresponding cache blocks. This resulted in existing defense methods and attack detection schemes designed for cache attacks still being effective against this type of hardware prefetcher attack. Designing new prefetcher-based hardware defense schemes for these attacks is not urgent. Correspondingly, unlike these attacks that are difficult to establish independently from cache side-channel attacks, the afterimage attack proposed by Chen et al. (Chen Y, PeiL, Carlson T E. AfterImage: Leaking control flow data and tracking load operations via the hardware prefetcher[C] / / Proceedings of the 28th ACMInternational Conference on Architectural Support for Programming Languagesand Operating Systems, Volume 2. 2023: 16-32.) invented a new prefetcher state detection method (PSC). This makes the afterimage attack effective without performing any cache cross-privilege operations, thereby bypassing defense and detection methods that focus on cache primitives, making it impossible to defend against it with previous defenses against cache attacks.
[0004] Afterimage attacks specifically include two attack modes: side-channel attacks and covert channel attacks. Their attack surface targets load instructions in user space and the kernel, particularly a series of load instructions whose execution depends on branches. Side-channel attacks exploit the fact that the instruction pointer stride prefetcher is shared by users of the same physical core. They exploit a vulnerability in the prefetcher that uses the lower eight bits of the load instruction address for indexing. By maliciously constructing a load instruction address index collision, the victim can trigger entries with the same index trained in advance by the attacker across threads, processes, and security domains, thereby stealing the victim's secret information and control flow information. In covert channel attacks, the sender and receiver use stride values to transmit hidden information.
[0005] Hardware prefetchers are an emerging hardware security vulnerability, and existing methods for defending against these attacks are limited. At the software level, Till et al. proposed the PreFence method (Schlüter T, Tippenhauer N O. AScheduling-Aware Defense Against Prefetching-Based Side-Channel Attacks[J].arXiv preprint arXiv:2410.00452, 2024.). PreFetch is a software-based defense against side-channel attacks against hardware prefetchers. By modifying the operating system, it allows users to disable the hardware prefetcher when running high-security processes. However, the high-security phase requires manual marking by the user or programmer, so this measure can only prevent side-channel attacks, not covert channel attacks. Furthermore, this method clearly imposes additional cognitive burden and workload on programmers. Chen et al. proposed another hardware-based defense (Chen Y, Pei L, Carlson T E. AfterImage: Leaking control flow data and tracking load operations via the hardware prefetcher[C] / / Proceedings of the 28th ACM International Conference on Architectural Support for ProgrammingLanguages and Operating Systems, Volume 2. 2023: 16-32.). They added a clear-ip-prefetcher instruction to the instruction set, which is called during each context switch to clear all entries in the instruction pointer stride prefetcher, thereby achieving process isolation. While this approach is effective, ensuring that the instruction pointer stride prefetcher only contains entries related to the currently executing process, preventing it from becoming a shared platform across processes and thus preventing attackers from transferring or stealing information across processes, its disadvantage is that the entries in the prefetcher have a training cost. Crudely clearing all entries means that the prefetcher needs to be retrained after each context switch. Each prefetch failure caused by this will introduce more time difference between accessing the cache and accessing the memory, which is a performance loss that cannot be ignored. Summary of the Invention
[0006] The present invention provides an instruction pointer stride prefetcher side channel attack defense method based on prefetch interception, which can achieve security defense against instruction pointer stride prefetcher side channel attacks on the basis of extremely low space and performance overhead.
[0007] A method for defending against side-channel attacks on an instruction pointer stride prefetcher based on prefetch interception, comprising: The existing instruction pointer stride prefetcher structure is expanded by adding a response bit field to each entry in its storage structure to mark whether each entry has information leakage risk and the response status; When a context switch occurs in the computer system and the instruction pointer stride prefetcher is accessed, the response bit field is updated according to the current field value; When the extended instruction pointer stride prefetcher is accessed, it determines whether to send a prefetch request and whether to update the original stride field based on the stride value of this access, combined with the original confidence field, stride field and the newly added response bit field.
[0008] This invention makes subtle modifications to the existing instruction pointer stride prefetcher update strategy, successfully limiting the attack risk to the first access to each entry in the prefetcher storage structure after a context switch. This invention intercepts only these potentially risky unauthorized prefetches. Compared to existing defenses, this approach eliminates the need to modify software infrastructure such as the operating system, narrowing the scope of the defense measures and achieving a more precise and efficient defense against side-channel attacks based on the instruction pointer stride prefetcher.
[0009] Furthermore, the response bit field occupies 1 bit in each entry and has a value of 0 or 1.
[0010] When a context switch occurs in the computer system, all response bit field values are set to 0.
[0011] When the computer system accesses the instruction pointer stride prefetcher, if the computer system access entry does not hit the prefetcher, a new entry is created in the prefetcher storage structure according to the access information, and the response bit field value of the entry is initialized to 1.
[0012] When the computer system accesses the instruction pointer stride prefetcher, if the computer system accesses an entry that hits the prefetcher, if the response bit field value of the accessed entry is 0, then after the access, the response bit field value of the entry is set to 1. If the response bit field value of the accessed entry is 1, then after the access, the response bit field value of the entry remains 1.
[0013] When the extended instruction pointer stride prefetcher is accessed, if the response bit field value of the accessed entry is 0 and the access stride value is equal to the stride field value recorded in the entry, then the prefetch will not be triggered at this time, the confidence field value will be incremented by 1 until it reaches its maximum value, the stride field value of the entry will not be updated in this access, and the response bit field value will be updated to 1 after the access; If the response bit field value of the accessed entry is 0, and the access stride value is not equal to the stride field value recorded in the entry, prefetching will not be triggered at this time, the confidence field value will be reset, the stride field value of the entry will not be updated in this access, and the response bit field value will be updated to 1 after the access.
[0014] When the extended instruction pointer stride prefetcher is accessed, if the response bit field value of the accessed entry is 1, the access stride value is equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry plus 1 is greater than or equal to the threshold, then this access will trigger prefetch, the stride field value remains unchanged, the confidence field value increases by 1 until it reaches its maximum value, and the response bit field value remains 1 after the access; If the response bit field value of the accessed entry is 1, the access stride value is equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry plus 1 is less than the threshold, then this access will not trigger prefetching, the stride field value remains unchanged, the confidence field value increases by 1, and the response bit field value remains 1 after the access; If the response bit field value of the accessed entry is 1, the access stride value is not equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry is greater than or equal to the threshold, then this access will trigger prefetch, the stride field value will be updated to the stride value of this access, the confidence field value will be reset, and the response bit field value will remain 1 after the access; If the response bit field value of the accessed entry is 1, the access stride value is not equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry is less than the threshold, then this access will not trigger prefetching, the stride field value is updated to the stride value of this access, the confidence field is reset, and the response bit field value remains 1 after the access.
[0015] The maximum value of the confidence field is 3, the initial value when creating an entry is 0, the value of the stride field is reset to 1 when it is updated, and the threshold is 2.
[0016] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention introduces a response bit to change the prefetch update strategy of the instruction pointer stride prefetcher, successfully reducing the scope of attack risks without affecting the original function of the prefetcher, thereby making it possible to effectively defend against side-channel attacks against the instruction pointer prefetcher.
[0017] 2. The present invention only expands the storage of one bit per entry based on the original storage structure of the instruction pointer stride prefetcher. Compared with the defense scheme that uses the complete load instruction address for indexing, the present invention effectively controls the space overhead of implementing the security defense scheme.
[0018] 3. The present invention only intercepts the first access to each entry in the prefetcher storage structure after the context switch. Compared with the existing solutions of disabling the prefetcher and refreshing the prefetcher, the present invention retains the complete functionality of the instruction pointer prefetcher to the greatest extent, minimizing the loss of computer performance caused by the defense solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 This is the internal structure of the instruction pointer stride prefetcher and the data prefetching implementation method in an embodiment of the present invention.
[0020] Figure 2 This is a flowchart of the algorithm for prefetching and updating strategies of the instruction pointer stride prefetcher in an embodiment of the present invention. DETAILED DESCRIPTION
[0021] The present invention will be described in further detail below with reference to the accompanying drawings and examples. It should be noted that the following examples are intended to facilitate understanding of the present invention and do not have any limiting effect on the present invention.
[0022] The key structural difference between the present invention and traditional instruction pointer stride prefetchers lies in the addition of a response bit field to each entry. The basic structure of the instruction pointer stride prefetcher in the present invention is shown in Figure 1. This prefetcher is equipped with a dedicated memory to record the strides of load instructions at different instruction pointers. The total number of entries is determined by the requirements of different processor architectures. Entries are indexed using the lower eight bits of the load instruction's instruction pointer (IP), rather than the entire IP. In addition to the index, each entry also stores four other important fields: the last accessed address, stride, confidence, and response bit. The last accessed address field stores the address accessed by the most recent load instruction at the same IP. The stride field stores the offset (the last accessed address minus the last accessed address) of the load instruction. It occupies 13 bits, with the first bit indicating the sign of the offset, and the last 12 bits storing the absolute value of the offset. This field can store a maximum offset of 2 KiB. Furthermore, the stride value recorded in the entry does not need to be aligned with the cache line size. The confidence field indicates the cumulative confidence of the load address stride in the corresponding entry. It is represented by two bits and has a maximum value of 3. When a load instruction at the same IP address is executed and the calculated stride matches the stride recorded in the entry, the confidence field value in the corresponding entry is incremented by 1. The confidence level determines whether a prefetch is triggered; a prefetch is triggered when the confidence level is greater than or equal to a threshold of 2. The response bit field records whether the corresponding entry has been accessed since the last process switch. Each entry has a separate response bit, occupying one bit, and it also indicates whether a prefetch triggered by the access of the corresponding entry will be responded to. The response bit can have two values: 0 and 1. When the response bit value of an entry is 0, it means that the entry has not been accessed since the last process switch. Any access to this entry will not trigger a prefetch. The stride field of this entry is also locked and will not be updated with the latest access. When the response bit value of an entry is 1, it means that the process currently occupying the CPU has accessed the entry at least once since the last process switch. At this time, the update of the entry and the response to the access can be carried out normally.
[0023] After the response bit is introduced, the update and prefetching strategy of the instruction pointer stride prefetcher in the present invention is as follows: Figure 2As shown in Figure 2. When a load instruction executes, the instruction pointer IP and the currently requested data address CA are passed to the prefetcher. The prefetcher first searches for a matching IP in memory. If not, it creates a new entry with its confidence and stride initialized to 0 and its response bit initialized to 1. If the corresponding IP already exists, the difference between the addresses accessed by the current and previous load instructions for this IP is calculated, which becomes the stride d for this access. The response bit of the corresponding entry is then checked. If the response bit is 0, this access will not generate a prefetch signal. The stride value s recorded in the entry is compared with the calculated stride d, and the confidence value is updated based on the comparison result. Conversely, if the response bit is 1, the confidence value of this entry is further checked. If the confidence value is greater than or equal to the threshold of 2, the prefetcher issues a prefetch signal, requesting the data at CA + s to be prefetched. The calculated stride d is then compared with the stride s recorded in the entry to see if they are equal, and the confidence and stride values are updated based on the comparison result. If the confidence is less than 2 at this time, the confidence field and stride field of the entry will be updated first according to the comparison result of stride d and stride s. After the update, it is judged again whether the confidence at this time is equal to 2. If it reaches the threshold 2, it will trigger prefetching and request to obtain the data at CA+s.
[0024] To illustrate the effectiveness of the present invention in defending against covert channel attacks and side channel attacks proposed by afterimage attacks, we first introduce afterimage attacks. In covert channel attacks, the sender and receiver use stride values to transmit secret information, and the workflow of each round of information transmission is divided into the following three steps: 1. Preparation phase: The sender and receiver agree on the lowest 8 bits of the IP address to be used and each constructs a corresponding load instruction for training or triggering the prefetcher. For ease of description, we assume the agreed value is IP1.
[0025] 2. Sending phase: The sender selects different stride values based on the secret information value it wants to send. Suppose the sender sets the stride value to s1. Then, the sender uses the load instruction at s1 and IP1 to train the prefetcher entry so that its confidence reaches the threshold.
[0026] 3. Receiving stage: The receiver executes the load instruction at IP1 prepared in the first step to trigger the entry trained by the sender, and then detects the cache status after the trigger prefetch and decodes the corresponding stride value.
[0027] In a side-channel attack, the attacker targets load instructions in user space and the kernel, specifically a series of load instructions that are executed based on a branch. For ease of description, we assume that the attack target is a branch instruction in the victim program, which has two branches, "if" and "else," each with a load instruction. The lower 8 bits of the instruction pointer for the load instruction are IP1 and IP2, respectively. This branch is controlled by a secret value, "secret." When "secret" is 0, the program executes the "if" branch; when "secret" is 1, the program executes the "else" branch. For this attack target, a side-channel attack is divided into the following four steps: 1. Preparation Phase: In this phase, the attacker locates the load instruction in the victim as the target of the attack. This involves obtaining the instruction pointers IP1 and IP2 of the load instructions in the two branches. The attacker then constructs a load instruction locally with the same lowest 8 bits of IP, thereby sharing entries in the instruction pointer stride prefetcher with the victim.
[0028] 2. Training phase: The attacker uses the load instruction constructed in the previous step locally and executes it multiple times with specific step sizes s1 and s2 until the confidence reaches the threshold, completing the training of the two entries.
[0029] 3. Triggering Phase: After the victim executes the corresponding target load instruction, it will execute different load instructions based on the secret value, triggering one of the attacker's trained prefetcher entries. For ease of description, we assume that the victim executes the if branch, and the prefetcher entry indexed by IP1 is triggered.
[0030] 4. Decryption Phase: The victim's prefetch triggers the corresponding data into the cache, thereby changing the cache state. At this point, the attacker can exploit traditional cache side-channel attacks, such as Flush+Reload (Yarom Y, Falkner K. FLUSH+ RELOAD: A high resolution, low noise, L3 cache Side-Channelattack[C] / / 23rd USENIX security symposium (USENIX security 14). 2014: 719-732.), to obtain the stride value of the triggered entry, thereby determining which entry was triggered and inferring the victim's secret value. Specifically, in afterimage attacks, the attacker can also determine which entry was triggered through prefetcher state checking (PSC). Based on the prefetcher entry update strategy, after the victim triggers an attacker-trained entry, the confidence value of the corresponding entry in the prefetcher is reset to 1 because the stride of the victim's load instruction differs from the attacker's training stride. The attacker will observe that executing the load instruction mapped to this entry again fails to trigger the prefetch. Using this method, the attacker only needs to measure the latency of a single destination address to obtain information.
[0031] After deploying this application's defense method, for covert channel attacks, in the third receiving phase, after the receiver first accesses the entry with the pre-agreed IP1 index, due to the effects of this application, the entry's response bit is 0, the triggered prefetch fails to take effect, and the stride field is locked and not updated. Furthermore, because the receiver does not have prior knowledge of the secret information s1, the stride value used in this access does not match the stride value s1 recorded in the entry, and the confidence level is reset to 1. After the first access, the response bit is set to 1. Because the receiver did not obtain the specific value of the secret information s1 during the first access, if the receiver accesses the entry a second time, the stride value used still does not match s1. At this point, the stride field is updated, and the confidence level is reset to 1. During this second access, no prefetch is triggered. Furthermore, due to the updated stride field, the secret information the sender wishes to transmit no longer exists in the prefetcher entry. Therefore, the receiver cannot obtain information not contained in the microarchitecture through subsequent operations. Therefore, this invention successfully prevents covert channel attacks.
[0032] After deploying the defense method of this application, for side-channel attacks, in the third triggering phase, after the victim accesses the entry indexed by IP1, the confidence is reset to 1 because the stride used at this time is different from s1. However, the stride field will not be updated under the influence of this application and will remain s1. In the fourth decryption phase, when the attacker observes the secret information by accessing two entries, in the first access, because the attacker will still use the access mode trained in the second step, the stride value of this access will still be s1 and s2. After the access, the stride fields of the two entries will not change. The confidence value of the entry indexed by IP1 will increase by 1 to become 2, and the confidence value of the entry indexed by IP2 will remain unchanged because it is already the maximum value of 3. At this time, the triggered prefetch will be intercepted and the victim's information will not be leaked. If the attacker continues to access for the second time, the confidence of both entries will have reached the threshold, and both can trigger prefetch, and the victim's information will still not be leaked. In summary, the present invention successfully prevents side-channel attacks.
[0033] Compared with existing defense solutions, the present invention has significant advantages in performance. Here we compare and analyze the performance advantages of the present invention compared to the clear-ip-prefetcher defense, as well as the performance gap compared to the original instruction pointer stride prefetcher that does not deploy defense measures. First of all, it should be emphasized that the purpose of the prefetcher is to record regular accesses and prefetch according to the rules to improve performance. For irregular accesses, the prefetcher cannot play a role in improving performance. Therefore, our performance analysis below is based on regular access. Specifically for the instruction pointer stride prefetcher, we only focus on the case where program access follows a regular stride.
[0034] The present invention and the clear-ip-prefetcher method are both closely related to context switching. Now consider that after the context switch, an entry is accessed regularly. Depending on whether the stride matches, there are two situations. If the stride value of the regular access at this time is not equal to the value originally recorded in the stride field in the entry, both defense schemes need to be re-accessed twice for retraining. In the other case, the strides match. In the present invention, only the first prefetch of this entry needs to be intercepted, and subsequent prefetches can proceed smoothly. As for the clear-ip-prefetcher method, it refreshes all entries when the context switches, resulting in the need for retraining, so that prefetching can be triggered normally on the third access. Compared with our method, it loses one more prefetching opportunity.
[0035] Compared to the original instruction pointer stride prefetcher without defensive measures, the discussion continues from the above two scenarios. After the context, if the program still accesses the entry with the original stride, the present invention will lose the prefetch triggered by the first access compared to the original prefetcher. If the program uses the new stride value to access the corresponding entry, the original prefetcher will perform a prefetch with the original stride on the first access and then update the stride value and confidence. However, it is foreseeable that this access behavior is inconsistent with the current access pattern, and the acquired data will not be used in the near future, so it is a redundant prefetch. Only when the entry is accessed for the second time with the new stride will the original prefetch perform a prefetch with the new stride. With the present invention, the first two accesses are used to update the stride value and confidence for retraining, and no prefetch is triggered with the original stride value. Only on the third access will a prefetch be triggered with the new stride. In other words, compared to the prefetcher without defensive measures, the present invention will miss at most one correct prefetch.
[0036] This paper uses the Gem5 simulator to verify security and demonstrate performance. Gem5 is a clock-cycle-level simulator widely used in computer architecture research. Based on previous work on the reverse engineering of the commercial Intel instruction pointer stride prefetcher (Chen Y, Pei L, Carlson T E. AfterImage: Leaking control flowdata and tracking load operations via the hardware prefetcher[C] / / Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2. 2023: 16-32.), we implemented the corresponding functions of the original instruction pointer stride prefetcher. On this basis, we implemented the defense method of this paper, as well as a defense method based on adding the clear-ip-prefetcher instruction for performance comparison. We used the SPECspeed 2017 Integer and SPECspeed 2017 Floating Point suites as benchmark examples to test the performance of the three prefetchers.
[0037] Experimental results demonstrate that this invention effectively defends against afterimage attacks based on the instruction pointer stride prefetcher. This invention not only protects against prefetcher attacks that require cache side-channel attack techniques like flush+reload, but also against instruction pointer stride prefetcher side-channel attacks that extract information through prefetcher state checks (PSC). Compared to flush defenses, this invention offers significant performance improvements, achieving comparable performance to the original instruction pointer stride prefetcher.
[0038] The embodiments described above provide a detailed description of the technical solutions and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not intended to limit the present invention. Any modifications, supplements and equivalent substitutions made within the scope of the principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for defending against side channel attacks on instruction pointer stride prefetchers based on prefetch interception, characterized in that: include: The existing instruction pointer stride prefetcher structure is extended by adding a response bit field in each entry in its storage structure; When a context switch occurs in the computer system and the instruction pointer stride prefetcher is accessed, the response bit field is updated according to the current field value; When the extended instruction pointer stride prefetcher is accessed, it determines whether to send a prefetch request and whether to update the original stride field based on the stride value of this access, combined with the original confidence field, stride field and the newly added response bit field.
2. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 1, characterized in that: The response bit field occupies 1 bit in each entry and has a value of 0 or 1.
3. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 1, characterized in that: When a context switch occurs in the computer system, all response bit field values are set to 0.
4. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 1, wherein: When the computer system accesses the instruction pointer stride prefetcher, if the computer system access entry does not hit the prefetcher, a new entry is created in the prefetcher storage structure according to the access information, and the response bit field value of the entry is initialized to 1.
5. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 1, characterized in that: When the computer system accesses the instruction pointer stride prefetcher, if the computer system accesses an entry that hits the prefetcher, if the response bit field value of the accessed entry is 0, then after the access, the response bit field value of the entry is set to 1. If the response bit field value of the accessed entry is 1, then after the access, the response bit field value of the entry remains 1.
6. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 1, characterized in that: When the extended instruction pointer stride prefetcher is accessed, if the response bit field value of the accessed entry is 0 and the access stride value is equal to the stride field value recorded in the entry, then the prefetch will not be triggered at this time, the confidence field value will be incremented by 1 until it reaches its maximum value, the stride field value of the entry will not be updated in this access, and the response bit field value will be updated to 1 after the access; If the response bit field value of the accessed entry is 0, and the access stride value is not equal to the stride field value recorded in the entry, prefetching will not be triggered at this time, the confidence field value will be reset, the stride field value of the entry will not be updated in this access, and the response bit field value will be updated to 1 after the access.
7. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 6, characterized in that: When the extended instruction pointer stride prefetcher is accessed, if the response bit field value of the accessed entry is 1, the access stride value is equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry plus 1 is greater than or equal to the threshold, then this access will trigger prefetch, the stride field value remains unchanged, the confidence field value increases by 1 until it reaches its maximum value, and the response bit field value remains 1 after the access; If the response bit field value of the accessed entry is 1, the access stride value is equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry plus 1 is less than the threshold, then this access will not trigger prefetching, the stride field value remains unchanged, the confidence field value increases by 1, and the response bit field value remains 1 after the access; If the response bit field value of the accessed entry is 1, the access stride value is not equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry is greater than or equal to the threshold, then this access will trigger prefetching, the stride field value will be updated to the stride value of this access, the confidence field value will be reset, and the response bit field value will remain 1 after the access; If the response bit field value of the accessed entry is 1, the access stride value is not equal to the stride field value recorded in the entry, and the confidence field value recorded in the entry is less than the threshold, then this access will not trigger prefetching, the stride field value is updated to the stride value of this access, the confidence field value is reset, and the response bit field value remains 1 after the access.
8. The method for defending against side channel attacks of an instruction pointer stride prefetcher based on prefetch interception according to claim 7, characterized in that: The maximum value of the confidence field is 3, the stride field is reset to 1 when updated, and the threshold is 2.