Branch Prediction Buffer Security IDs for Speculative Execution Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The inclusion of context or program ID in branch prediction mechanisms leads to an enormous circuit scale, increasing area and power consumption in microprocessors, and existing solutions fail to address the vulnerability of speculative execution to malicious attacks.

Innovation Solution

A microprocessor design that incorporates an instruction address generator, a context table storing execution contexts with a branch prediction mechanism, and a branch prediction mechanism that includes a branch prediction mechanism, which includes a branch prediction mechanism, which includes a branch prediction mechanism, and a branch prediction mechanism that includes a branch prediction mechanism, and a prefetch controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If context or program ID is included in branch prediction mechanism, then security against malicious attacks is improved, but circuit scale and power consumption increase enormously

Engineering Contradiction:
ImprovesecurityVSAvoidcircuit scale
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the branch prediction mechanism into multiple independent buffers (first branch prediction buffer and second branch prediction buffer) with different security levels. Each buffer stores branch history information for specific security contexts, allowing security differentiation without requiring a single enormous buffer that would consume excessive area and power.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security level dimension to the branch prediction mechanism by classifying branches into different security levels (first security level and second security level). This dimensional addition allows the system to achieve security through structural organization rather than through increasing the size of individual components.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If context or program ID is included in branch prediction mechanism, then security against malicious attacks is improved, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent divides the branch prediction mechanism into multiple smaller buffers handling different security levels independently. This segmentation reduces the power consumption of each individual buffer compared to a single large buffer, while collectively providing the required security through differentiated handling of security-sensitive branches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security levels to different branches based on their sensitivity requirements. Not all branches receive the same level of security processing - only those requiring higher security are routed through the first branch prediction buffer, while others use the second buffer. This local differentiation reduces overall power consumption by avoiding unnecessary security processing for non-sensitive branches.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250377896A1Microprocessor and processing method of microprocessor
Publication Date: 2025.12.11 FUJITSU LTD
  • US20250377896A1 patent drawing
  • US20250377896A1 patent drawing
  • US20250377896A1 patent drawing

AI summary

The present invention is to prevent speculative execution by a malicious program and reduce a size of a branch prediction buffer. Security IDs of several bits associated with an execution context are registered in a context table, and an instruction address executed in the past and a security ID at the time of execution are stored in a branch prediction buffer. The branch prediction mechanism searches for an entry in the branch prediction buffer with the instruction address of the branch prediction target and the security ID associated with the execution context at the time of branch prediction, and responds to an instruction address generator with a branch target address of the matching entry. The number of bits of the security ID is smaller than the number of bits of the execution context and a program ID that identifies a process included in the execution context.