Spectre vulnerability defense method based on conditional branch security implementation
By optimizing conditional branch instructions and using the return stack buffer (RSB), the defense problem of the first phase of Spectre attacks is solved, achieving effective defense against Spectre variant 1 and variant 2, reducing performance loss, and mitigating BTB-based side-channel attacks.
Patent Information
- Application Number
- CN202410598167.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-14
- Publication Date
- 2025-11-14
AI Technical Summary
Existing technologies lack effective defenses against Spectre attacks, especially in the first phase. This allows attackers to leak private data through conditional branch instructions and exploit speculative execution optimization techniques to carry out attacks. Furthermore, existing methods have a significant impact on performance.
By optimizing conditional branch instructions and replacing the original instructions with cmp+cmove+jmp instructions, the addresses of potentially executed instructions are masked, and the addresses of secure instructions are loaded into the return stack buffer (RSB). Combined with a multi-branch structure, secure access is achieved, preventing attackers from obtaining private data.
Effectively defends against Spectre variant 1 and variant 2 attacks, reduces performance loss, and mitigates BTB-based side-channel attacks with a performance loss of up to 34%.
Smart Images

Figure CN120951328A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computers, and more particularly to a speculative execution-based Spectre attack method in hardware security. Background Technology
[0002] The processor is the core of a computer system, and its security is the cornerstone of the entire system's security. As users expect to utilize more and more applications and functions, processor performance faces immense pressure. To address this issue, modern processors have introduced various performance optimization techniques to improve performance, such as out-of-order execution and speculative execution. While processor performance has significantly improved, security considerations have been lacking. To ensure the correct execution of performance optimization techniques, the processor performs a permission check at the final stage of each instruction's execution. During the permission check, the processor assesses the execution permissions of the instruction. If the requirements are met, the processor submits the instruction's execution result and continues execution; if not, it rolls back the execution state to before the instruction's execution and executes other qualified instructions. At the architectural level, we see that the rollback restores the state to before the instruction's execution. However, at the microarchitecture level, all altered states are not rolled back. The execution results of instructions already executed and the related data are retained in the microarchitecture components. These results and data may contain sensitive information. Attackers can exploit this mechanism to create hardware vulnerabilities, thereby obtaining sensitive information from the processor and ultimately compromising its security from within.
[0003] Among the most representative processor security vulnerabilities caused by high performance issues are Meltdown and Spectre, disclosed in 2018. Meltdown exploits out-of-order execution techniques to bypass memory isolation permission checks, allowing attackers to leak private data in the kernel space, or even all information in the entire memory space, from user space without access. While Meltdown has a significant impact on processor security, its threat can be effectively mitigated using kernel page-table isolation (KPTI) and KAISER. Spectre poses a similar level of threat to Meltdown, but unlike the mitigation methods for Meltdown, Spectre's mitigation is more complex and difficult, and all these solutions have a significant impact on processor performance.
[0004] Spectre attacks trick victims into speculatively performing actions that wouldn't occur during proper program execution. These actions leak the victim's personal information to the attacker via side-channels. Spectre generally consists of three phases: the first is the data preparation phase, where the attacker uses speculative execution to load confidential data from memory; the second is the data transfer phase, where the processor speculatively executes instructions, transferring confidential information from the victim's context to a covert channel within the microarchitecture; and the third is the data recovery phase, where the attacker uses side-channel information stored at the microarchitecture level to recover the confidential information.
[0005] Currently, defenses against Spectre attacks mainly fall into two categories: software and hardware. At the software level, the `lfence` instruction is typically used to serialize branch instruction execution, avoiding branch prediction using a branch prediction unit, but this significantly reduces program execution efficiency. To mitigate this impact, security researchers have designed defense technologies such as Retpoline and SpectreCFI to defend against microarchitectural attacks like Spectre. At the hardware level, security researchers have designed defenses such as The Indirect Branch Predictor Barrier (IBPB), SafeSpec, and InvisiSpec. Despite these mitigation methods, Spectre attacks can still be successfully implemented on the latest processors. Our summary reveals that mitigation schemes against Spectre primarily target the second and third phases of the attack, with less research on the first phase. However, the first phase is a crucial step in the entire Spectre attack, therefore, defenses against the first phase of Spectre attacks are necessary. Summary of the Invention
[0006] This invention implements a Spectre vulnerability defense method based on conditional branch security, which can improve the security of conditional branch instructions and effectively defend against Spectre-type attacks (including Spectre variant 1 and Spectre variant 2) while maximizing performance and minimizing overhead. Simultaneously, this invention can also mitigate BTB-based side-channel attacks. This invention first loads the corresponding addresses into different registers. After the condition is evaluated, secure instruction execution is achieved using a return stack buffer (RSB). Furthermore, this invention extends the basic conditional branch security implementation to multi-branch structures to achieve secure access within multiple loops.
[0007] This invention provides the following Spectre vulnerability defense method based on conditional branch security implementation:
[0008] A method for defending against Spectre Variant 1 attacks is presented. This method first focuses on how to protect secret data within if conditional branches. Traditional Spectre Variant 1 attacks exploit processor speculative execution to load the victim's secret data. Therefore, the execution of conditional branch instructions presents two security risks that allow attackers to successfully implement Spectre Variant 1 attacks. The first risk is that the execution of conditional branch instructions leaks the address of each instruction, which attackers can directly exploit. The second risk is that conditional branch instructions employ speculative execution optimization techniques, which may lead to the premature execution of instructions that do not meet the conditions; these instructions could be attack instructions that access sensitive data.
[0009] To address the security risks posed by speculative execution of conditional branch instructions, this method implements two optimizations to the original conditional branch instructions. The first optimization is to mask potentially executed instructions. This method first divides the instructions to be executed on different conditional branches into two code blocks. During the conditional branch evaluation, the addresses of these two code blocks are loaded into registers respectively. This method ensures that in subsequent execution, it only operates on the addresses of the code blocks, not the addresses of the instructions within them. This method also prevents attackers from directly accessing secret addresses.
[0010] The second optimization method replaces the original instruction execution process with cmp+cmove+jmp instructions. The cmp instruction adds an execution dependency to the cmov instruction, so the cmove instruction can only be executed after the cmp condition check is completed. Therefore, the cmove instruction is forcibly serialized during execution, which prevents attackers from loading the victim's secret data before the condition branch check is completed. After the cmove instruction completes execution, this method uses the jmp instruction to jump to the address of the subsequent instruction.
[0011] A method for defending against Spectre Variant 2 attacks. To address the threat of Spectre Variant 2 attacks caused by the jmp instruction, this method replaces the jmp instruction with a call+ret instruction. The idea behind this method is to select a safe instruction (such as the pause instruction) to replace the vulnerable instruction, and then use a call instruction to load the address of this safe instruction into the return stack buffer (RSB). When the ret instruction is executed, the processor will speculatively execute the address of the safe instruction previously loaded into the RSB. Through this design, this method can effectively prevent attackers from using the transient window opened by the jmp instruction to obtain data, thereby mitigating the Spectre Variant 2 threat.
[0012] A method for defending against BTB-based side-channel attacks is presented. The security conditional branch designed in this method not only mitigates the threats of Spectre variants 1 and 2, but also effectively mitigates BTB-based side-channel attacks. This is because we introduce the `cmove` instruction when mitigating Spectre variant 1. The `cmove` instruction prevents Spectre attacks from filling the BTB-based state and prevents attackers from carrying out attacks by monitoring changes in the BTB-based state.
[0013] A Spectre vulnerability defense method based on multi-branch conditional branch security implementation. This method extends the basic single-branch conditional security implementation design to multiple branches, enabling Spectre variant 1 attacks, Spectre variant 2 attacks, and attacks based on the BTB side channel. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some examples of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0015] Figure 1 This describes the Spectre vulnerability defense process based on conditional branching security.
[0016] Figure 2 The execution process modified to ensure the safety of the basic conditional branch implementation;
[0017] Figure 3 The modified execution process is implemented to ensure safety across multiple branches;
[0018] Figure 4 For evaluating the execution time of synthetic workloads;
[0019] Figure 5 Evaluation time for conditional branch instructions; Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Figure 1This paper describes a Spectre vulnerability defense process based on conditional branch security. The program first divides the possible executable instructions of a multi-branch conditional branch instruction into blocks and stores the addresses of the three blocks in three different registers. Then, during condition judgment, the instruction flow is adjusted by adding a dependency on the `cmp` instruction for the `cmove` instruction, ensuring that data retrieval is only performed after the condition judgment is complete, thus guaranteeing data security. This method selects a fixed default register, loads the address of the execution block that meets the execution conditions into the default register, and uses it for the next step of loading onto the execution stack. By executing the `call` instruction, the address of the instruction following the `call` instruction is placed into the RSB. This method loads the correct branch execution address stored in the default register onto the execution stack and uses the RSB to control the transient execution window.
[0022] Figure 2 This describes the modified execution process under the basic conditional branch security implementation. The first step is instruction masking. This method first masks conditional branch instructions in two cases (lines 16-19). The second step is executing Spectre variant 1 mitigation (lines 5-6). This method uses the `cmp` instruction to add a dependency to the `cmove` instruction, preventing attackers from using conditional branch speculative execution to load the victim's secret data. Simultaneously, this method also uses these two lines of instructions to mitigate BTB-based side-channel attacks. The third step is executing Spectre variant 2 mitigation (lines 7-12). By calling instructions, this method loads pause instructions into the RSB. Through the instruction in line 11, this method pushes the address of the code block to be executed onto the stack. When executing line 12, the `ret` instruction retrieves the address from the top of the RSB stack and compares it with the address pushed onto the stack in line 11. When these two addresses do not match, the processor considers an error to have occurred in the RSB speculative execution and selects to execute the instruction pushed onto the stack in line 11. In this way, this method can control the transient execution window during RSB speculative execution, preventing attackers from achieving their goals.
[0023] Figure 3 The execution process of modifications under a multi-branch safety implementation is described. Figure 2 Building upon the previous method, this approach enhances the safety of multi-branch conditional branch instructions by extending the basic branch structure to a multi-branch structure, as shown in Listing 2. This method divides the three branches into three code blocks and loads the addresses of these code blocks into three registers. Then, the addresses that satisfy the execution conditions are loaded onto the stack. Finally, the processor continues executing subsequent instructions.
[0024] Figure 4The execution time evaluation of the synthetic workload is presented. The benchmark consists of two parts: the first part is the client workload (S), and the second part is the background communication activity (C) using the AES algorithm for data encryption. 90S / 10C indicates that 90% of the time is spent on the first part and 10% on the second. The figure shows that our method significantly outperforms the lfence-based method. Experiments demonstrate that our method saves 34% of the execution time compared to the lfence-based method. Furthermore, in many cases, the performance of our method is closer to Retpoline, which is the most effective method for mitigating Spectre variant 2 attacks. However, our method not only mitigates Spectre variant 2 attacks but also Spectre variant 1 attacks and BTB-based side-channel attacks.
[0025] Figure 5 The evaluation time for conditional branch instructions is shown. This method uses two schemes to test the performance of executed conditional branch instructions. The first scheme tests the total time consumed by the entire program when executing a large number of instructions. This method executes approximately 30,000 instructions and performs 100 runs to calculate the average. The second scheme is the average time for executing if branch instructions. This method calculates the execution time of 10,000 identical instructions and then takes the average. To prevent microarchitectural components such as caches from affecting the evaluation results, this method refreshes the microarchitectural remnants before each instruction execution to eliminate noise. The figure shows that compared to the lfence-based method, this method saves 39% of the total time when executing 30,000 instructions and an average of 24% of the time per instruction. This minimizes performance loss because this method forcibly reduces latency. Compared to Retpoline, our method takes longer, but this is expected. This is because our method requires some time to mitigate Spectre variant 1 attacks and BTB-based side-channel attacks, which Retpoline cannot do.
[0026] Those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims and their equivalents, this invention is also intended to include these modifications and variations.
Claims
1. A method for defending against Spectre variant 1 attacks based on conditional branch security, characterized in that, The defense method is based on adjusting the instruction flow during conditional branch execution. It serializes some related instructions by adding dependencies to the instruction flow. By serializing the instruction flow, conditional branches avoid speculative execution and preloading of private information during execution. The process includes: The program first divides the possible executable instructions of the conditional branch instruction into blocks and stores the addresses of each block into different registers. Then, during the condition evaluation, the instruction flow is adjusted to add a dependency on the cmp instruction to the cmove instruction, ensuring that data is retrieved only after the condition evaluation is completed, thus guaranteeing data security.
2. A method for defending against Spectre variant 2 attacks based on conditional branch security. Its characteristics are: Implemented in C, the application of a return stack buffer (RSB) coordinates and offsets the trainable transient execution window introduced by the traditional jmp instruction, effectively mitigating the security impact of Spectre variant 2 attacks. The process includes: The program first executes the `call` instruction and places the address of the instruction following the `call` instruction into the RSB. In this method, we choose the `pause` instruction to control the size of the transient execution window, thus avoiding its impact. This method loads the execution address of the correct branch after the conditional branch judgment in the previous step onto the execution stack. It compares the address pointed to by the RSB stack top pointer with the address pointed to by the execution stack top pointer. If the results are different, the processor discards the result pointed to by the RSB stack top pointer and executes the instruction at the address pointed to by the execution stack top pointer.
3. A BTB side-channel attack defense method based on conditional branch security, characterized in that, Similar to the first method for defending against Spectre variant 1 attacks, this method also ensures data security by adding dependencies between instructions. By adding instruction dependencies, information injection into the BTB can be avoided, and modification of the BTB information can be prevented, thus achieving protection of side-channel information.
4. A Spectre vulnerability defense method based on multi-branch conditional branch security implementation, characterized in that, The Spectre vulnerability defense method, based on single-branch security implementation, is extended to multiple branches, making it more universal. The process includes: The program first divides the possible executable instructions of a multi-branch conditional branch instruction into blocks and stores the addresses of the three blocks into three different registers. Then, during condition evaluation, the instruction flow is adjusted by adding a dependency on the `cmp` instruction for the `cmove` instruction, ensuring that data retrieval is only performed after the condition evaluation is complete, thus guaranteeing data safety. This method selects a fixed default register, loads the address of the execution block that meets the execution conditions into the default register, and uses it for the next step of loading onto the execution stack. By executing the `call` instruction, the address of the instruction following the `call` instruction is placed into the RSB. This method loads the correct branch execution address stored in the default register onto the execution stack, using the RSB to control the transient execution window.