Branch predictor hardware Trojan horse design method based on RISC-V architecture processor
By implanting a hardware Trojan into the processor's branch predictor to interfere with its normal operation, the security vulnerability of the branch predictor is solved, achieving covert interference and performance degradation of the processor, and increasing the complexity and unpredictability of the attack.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- EAST CHINA NORMAL UNIV
- Filing Date
- 2025-12-29
- Publication Date
- 2026-04-24
AI Technical Summary
In existing technologies, processor branch predictors have potential security vulnerabilities, and their complexity increases the risk of malicious exploitation, affecting processor performance and reliability. This is especially true in high-performance computing applications where security and stability are paramount, where existing attack methods are difficult to effectively address.
Design a hardware Trojan horse, including an interference trigger module, an interference signal generator, and a control signal generator. By injecting interference signals into the branch predictor, it interferes with the normal operation of the processor and reduces its performance. Specific interference modes include random interference and targeted interference, so as to achieve covert interference and precise control of the processor.
Significantly reducing the accuracy of branch predictors leads to a decrease in processor performance, increases the unpredictability and stealth of attacks, makes traditional defenses difficult to counter, and enhances the complexity and targeting of attacks.
Smart Images

Figure CN121919871A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of processors and hardware Trojans, and is a hardware Trojan design method that can be used to attack processor branch predictors. Background Technology
[0002] In modern computer systems, processor performance is a core indicator of overall system computing power. With the continuous evolution of semiconductor technology and architecture design, processors have gradually developed from early simple sequential execution structures into highly efficient execution units integrating complex instruction pipelines and multi-level caches. Against this backdrop, RISC-V architecture processors, with their advantages of concise instruction sets, high modularity, and open-source scalability, have received widespread research and application globally in recent years. Especially in the field of high-performance computing, RISC-V-based processors have become an important research object and product.
[0003] With advancements in semiconductor technology, processor performance has significantly improved. This performance enhancement largely relies on continuous optimization of the processor's internal architecture, such as expanding the depth and width of the instruction pipeline and integrating multi-level caches. However, as processor architecture becomes increasingly complex, design engineers must balance performance gains with processor reliability and security. Complex processor architectures not only increase the difficulty of design and verification but may also make potential security vulnerabilities more concealed, thereby increasing the risk of malicious exploitation.
[0004] As modern applications place ever-increasing demands on processor performance, performance enhancement has become a core driving force for the development of computer technology. Especially in applications with extremely high real-time and accuracy requirements, such as financial trading systems, medical devices, and autonomous driving, a decline in processor performance can have a serious impact on business operations and social security. Furthermore, a decrease in processor performance can also indirectly lead to increased energy consumption, as the system needs to invest more time and computing resources to correct errors and compensate for performance losses.
[0005] Branch predictors are a core component of processors, their main function being to predict upcoming instruction branches, thereby reducing instruction pipeline latency and improving processor execution efficiency. Branch predictors are not only crucial to processor performance, but their security also directly impacts the stability and reliability of the computer system. As processor designs become increasingly complex, the implementation of branch predictors also becomes more complex, thus increasing the exposure to potential security vulnerabilities.
[0006] Hardware trojans, a significant issue in semiconductor security, are typically designed as hidden backdoors within integrated circuits. They activate only under specific triggering conditions and perform various malicious operations, including data leakage, logic corruption, and system crashes. While the attack potential of hardware trojans has been widely recognized, research on attacks targeting specific processor components, particularly branch predictors, remains scarce. As a critical execution unit of the processor, the security of the branch predictor directly impacts the reliability of the entire computing system.
[0007] This invention proposes a hardware Trojan design method targeting branch predictors. As a critical component of the processor, the correctness of the branch predictor directly affects the processor's performance. The method of this invention, by implanting a hardware Trojan into the branch predictor, can achieve control and interference with the processor under specific triggering conditions. Summary of the Invention
[0008] This invention aims to provide a hardware Trojan design method for attacking the branch predictor of a processor component. The hardware Trojan designed in this invention consists of three parts: an interference trigger module, an interference signal generator, and a control signal generator. When the interference trigger module detects a predefined conditional trigger instruction, the interference signal generator injects a specific interference signal into the processor's branch predictor, thereby interfering with the normal operation of branch prediction and reducing processor performance. The core of this invention lies in proposing a conditional trigger-based hardware Trojan mechanism targeting the branch predictor. It designs multiple interference modes based on the working principle of the branch predictor and can uniformly control the strength and duration of the interference signal, thereby achieving covert interference with processor execution performance.
[0009] The hardware Trojan of this invention, once implanted into the target chip, will cause a significant decrease in the accuracy of branch prediction, thereby resulting in a significant reduction in processor performance.
[0010] The objective of this invention will be achieved through the following technical solution, which includes the following steps: selecting a suitable interference mode, hardware logic design, injecting and controlling interference signals, and evaluating the impact of hardware Trojans on processor performance.
[0011] To further explain, interference patterns can be divided into purposeless interference patterns and purposeful interference patterns from the perspective of attack objectives. Purposeless interference patterns include: (1) random interference patterns, which generate random interference signals on the branch history table or branch target buffer through an interference signal generator; and (2) branch history interference patterns, which interfere with the learning process of the branch predictor by modifying the contents of the branch history table, thereby reducing its prediction accuracy. Purposeful interference patterns involve modifying the contents of the branch target buffer to cause the instruction flow to deviate from the expected execution path, thereby interfering with the program execution of the processor.
[0012] The logic design of the hardware Trojan is the core component of this invention, and it is divided into three key functional modules: an interference triggering module, an interference signal generator, and a control signal generator. This design aims to ensure the precise implementation and flexible control of interference behavior. 1. Interference Trigger Module: This module operates during the processor's instruction parsing phase, primarily responsible for monitoring and identifying predefined trigger conditions, including the occurrence of specific instructions or the reaching of preset time points. This step is a prerequisite for activating interference behavior, ensuring that the interference action is targeted and timely. 2. Interference Signal Generator: This module is the key component for achieving the interference effect, and it is closely connected to the interference trigger module and the control signal generator. When the interference trigger module detects a predefined command or the control signal generator issues a control command, the interference signal generator immediately starts and generates the required interference signal. 3. Control Signal Generator: This module is responsible for issuing control commands, managing the switching between dormant and active states of the hardware Trojan, and controlling the injection of interference signals, thereby enhancing the stealth of the hardware Trojan.
[0013] Injection and Control of Interference Signals: The hardware Trojan of this invention is activated by detecting trigger commands through an interference triggering module. Depending on the selected interference mode, the output of the hardware Trojan is connected to key components of the processor's branch predictor, such as the branch history table or branch target buffer. When interference is triggered, the interference signal is injected into the key components of the branch predictor, causing a decrease in branch prediction accuracy or even malfunction, thereby affecting the normal operation of the processor.
[0014] Testing and Verification: The impact of the hardware Trojan of this invention on processor performance in different scenarios is evaluated by running a series of predefined test programs.
[0015] Beneficial effects: Compared with the prior art, the present invention has the following advantages:
[0016] (1) This invention is the first to propose a hardware Trojan attack method targeting the branch predictor inside the processor. Since the branch predictor is a key component affecting the performance of modern processors, this attack method will have a significant impact on the overall performance of the processor.
[0017] (2) By designing both purposeful and unpurposeful interference patterns, this invention provides a flexible attack method. The unpurposeful interference pattern disrupts the processor's branch prediction mechanism through random and branch history interference, thereby increasing the unpredictability of the attack and making the formulation of defense strategies more complex. The purposeful interference pattern, on the other hand, directly interferes with the normal operation of the processor by specifically modifying the contents of the branch target buffer.
[0018] (3) Compared with traditional attack methods, this invention allows attackers to set specific triggering conditions based on the actual operating state and environment of the system, thereby achieving precise control over the interference behavior. This triggering mechanism not only improves the concealment and targeting of hardware Trojans, but also significantly increases the complexity and unpredictability of attacks, making it difficult for traditional defense measures to effectively respond. Attached Figure Description
[0019] Figure 1 This is a flowchart of the technical solution of the present invention. Detailed Implementation
[0020] The following will combine Figure 1 The technical solution of the present invention will be described in more detail below.
[0021] The embodiments described herein are intended to illustrate the design of the invention in order to better understand its principles and operation. It should be understood that the scope of protection of this invention is broad, covering not only the following embodiments but also all applications directly derived from the principles of this invention.
[0022] The specific implementation of the present invention can be divided into the following steps:
[0023] Step 1: Select an appropriate interference mode based on the characteristics and design purpose of the branch predictor in the target processor. First, the working mechanism and performance indicators of the branch predictor in the target processor are analyzed, including the evaluation of branch prediction accuracy and the evaluation of the overall processor performance, in order to determine the specific target of the interference mode. Subsequently, the design purpose of the hardware Trojan was clarified, namely the expected changes in processor performance after the hardware Trojan was implanted, so as to evaluate whether the performance changes of the branch predictor under interference met the design purpose in subsequent experiments. Based on the above analysis and objectives, selecting a suitable interference mode can involve choosing from the following modes (you can also modify the attack target or triggering method yourself): 1.1 Random Interference Mode: In this mode, the interference signal will randomly apply to the branch history table or branch target buffer, launching an unpredictable attack on the branch predictor. The generation of the interference signal does not follow any fixed or predictable pattern, but exhibits completely random characteristics, thus disguising hardware Trojan attacks as noise interference during system operation. 1.2 Branch History Interference Mode: This mode disrupts the learning mechanism of the branch predictor by modifying the contents of the branch history table. Branch predictors typically rely on historical information to make predictions, but this mode modifies this historical information, preventing the branch predictor from learning effective instruction branch patterns from historical data. 1.3 Intentional Interference Pattern: This pattern redirects branch predictions to incorrect paths by modifying specific entries in the branch target buffer. This modification can be triggered under specific conditions, such as when the program executes a critical function or a specific system state is detected.
[0024] Step 2: Design the hardware logic, including an interference trigger module, an interference signal generator, and a control signal generator. The interference trigger module operates during the processor's instruction parsing process, responsible for identifying predefined interference trigger instructions. The interference signal generator is connected to the interference trigger module and generates an interference signal when the module detects the trigger instruction. The control signal generator is used to switch the hardware Trojan's sleep and active states, controlling the injection of interference signals. When the interference trigger module identifies a predefined trigger instruction, the interference signal generator generates the corresponding interference signal according to the selected interference mode. In random interference mode, it generates random signals to disrupt the branch history table or branch target buffer; in branch history interference mode, it generates specific signals to modify the content of the branch history table; and in targeted interference mode, it constructs signals to change the content of the branch target buffer.
[0025] Step 3: The hardware Trojan is implanted into the target processor to inject and control interference signals. The hardware Trojan is activated by detecting trigger commands through the interference trigger module. Depending on the selected interference mode, the output of the hardware Trojan is connected to the corresponding component of the branch predictor within the processor, such as the branch history table or the branch target buffer.
[0026] Step 4: Testing and Verification. Evaluate the impact of this hardware Trojan on processor performance in different scenarios by running predefined test programs.
[0027] The effectiveness of the present invention was verified through the following experiments:
[0028] The experimental testing environment used the VCS (Verilog Compiler Simulator) simulation tool to run the XuanTie processor OpenC910 based on the RISC-V architecture. CoreMark, a standardized processor performance benchmark, was chosen as the test case to ensure the accuracy and comparability of the results. By testing the performance data of the XuanTie processor when executing the CoreMark program, the specific impact of this hardware Trojan on processor performance can be quantitatively evaluated. Before the hardware Trojan was implanted, the processor's CoreMark test result was 6.35MHz.
[0029] Example 1: The attack employs a random interference mode, targeting the addrgen module of the branch predictor within the processor. This module stores crucial information regarding the correctness of the current branch prediction. By interfering with the addrgen module, the normal operation of the branch predictor can be effectively disrupted. The interference triggering module uses a timed triggering mechanism, set to release the interference signal every four clock cycles. The interference signal generator, connected to the addrgen module, uses a random number generator circuit to generate random signals that modify the branch prediction results, thereby achieving the interference attack.
[0030] In Example 1, after the hardware Trojan was implanted, the processor's performance test result was 5.87MHz, a performance decrease of 7.56%.
[0031] Example 2: The attack employs a branch history interference mode, targeting the branch history table of the processor's branch predictor. The interference trigger module identifies special instructions, releasing an interference signal upon detecting the instruction "JAL". "JAL" was chosen as the trigger instruction because of its high frequency of occurrence in programs, effectively triggering hardware Trojan interference behavior in common programs. The interference signal generator is connected to the branch history table, using a random number generator circuit to generate an obfuscation mask. The generated random number sequence is then used to perform AND operations on the entries in the branch history table.
[0032] In Example 2, after the hardware Trojan was implanted, the processor's performance test result was 5.45MHz, a performance decrease of 14.56%.
[0033] The experimental results of the two embodiments are shown in Table 1: Table 1 Experimental Results
[0034] Experimental data shows that the hardware Trojan of this invention can cause a decrease in processor performance when using both random interference mode and branch history interference mode, with the branch history interference mode having a more significant impact on processor performance. The results indicate that the hardware Trojan designed in this invention can effectively attack the branch predictor, thereby affecting the overall performance of the processor.
[0035] The above embodiments are a detailed description of the present invention, but it should not be considered that the present invention is limited to the above embodiments. For those skilled in the art, any simple substitutions and reasoning calculations made based on the present invention should be considered to fall within the protection scope of the present invention.
Claims
1. A method for designing a branch predictor hardware Trojan based on a RISC-V architecture processor, characterized in that, Includes the following steps: Step 1: Design and implement an interference triggering module. This module operates during the processor's instruction parsing stage and is used to monitor and identify predefined interference triggering instructions. Step 2: Design and implement an interference signal generator, which is connected to the interference triggering module to generate an interference signal when the interference triggering module recognizes the trigger command; Step 3: Design and implement a control signal generator to switch the hardware Trojan between dormant and active states and control the injection of interference signals.
2. The branch predictor hardware Trojan design method according to claim 1, characterized in that, Selectable interference modes include: (2.1) Purposeless interference patterns: including random interference patterns and branch history interference patterns; (2.2) Intentional interference mode: Modify the contents of the branch target buffer to lead the branch prediction to the wrong path.
3. The branch predictor hardware Trojan design method according to claim 1, characterized in that, Hardware logic design includes: (3.1) Logic design of the interference triggering module: The interference triggering module can accurately identify specific interference triggering commands; (3.2) Logic design of interference signal generator: When the interference triggering module recognizes the interference triggering command, the interference signal generator can generate the corresponding interference signal; (3.3) Logic design of the control signal generator: The control signal generator can control the start and stop of interference signal injection.
4. The branch predictor hardware Trojan design method according to claim 1, characterized in that, Control of interference signals includes: (4.1) Set the specific conditions for interference triggering according to the actual operating environment of the processor; (4.2) Set the strength and duration of the interference signal according to the performance indicators of the processor.
5. A method for designing a branch predictor hardware Trojan based on a RISC-V architecture processor, characterized in that, The specific implementation steps include the following: (5.1) Select a suitable interference mode; (5.2) Conduct hardware logic design for hardware Trojans, including the design of interference triggering modules, interference signal generators, and control signal generators; (5.3) Hardware Trojans are implanted into the processor to inject and control the interference signals generated by the interference mode; (5.4) Run the test program on the processor to evaluate the impact of the hardware Trojan on the processor performance.
6. The branch predictor hardware Trojan implementation method according to claim 5, characterized in that, The testing steps include: (6.1) Run predefined test programs to test processor performance, thereby verifying the attack effect of hardware Trojans; (6.2) Evaluate the specific impact of hardware Trojans on processor performance and optimize the interference strategy accordingly.