Hardware Resource Manager for Cache Side Channel Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer processors are vulnerable to cache side channel attacks, such as Meltdown and Spectre, which can be exploited by malicious software to bypass access controls and read restricted memory locations, and existing countermeasures can negatively impact performance.

Innovation Solution

A system that includes multiple computing devices and an analytics server for detecting and mitigating cache side channel attacks by monitoring resource usage data, identifying suspicious core activity, and restricting resource usage through a hardware resource manager, without requiring updates to operating system code or processor microcode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If operating system code and processor microcode are updated to counter Meltdown and Spectre vulnerabilities, then security against cache side channel attacks is improved, but device complexity and update requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidupdate requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a hardware resource manager as an intermediary component that monitors and controls resource usage between applications and processor resources. This mediator detects suspicious patterns indicative of cache side channel attacks and takes corrective actions without requiring changes to operating system code or processor microcode, thus resolving the contradiction by providing security through a separate hardware layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hardware resource manager performs self-service by autonomously monitoring resource usage patterns, detecting suspicious activity, and executing corrective actions without external intervention. The system automatically identifies applications attempting cache side channel attacks and restricts their resource access, eliminating the need for manual updates or external security management

Inventive Principle:
Principle #25Self-service

2Reliability

If countermeasures are implemented to protect against Meltdown and Spectre vulnerabilities, then security is improved, but performance is negatively impacted

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The hardware resource manager applies partial action by monitoring only specific resource usage patterns that indicate cache side channel attacks rather than implementing comprehensive security checks on all processor operations. By focusing detection efforts on suspicious patterns rather than all activity, the system maintains security while minimizing performance overhead

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent replaces software-based security countermeasures (which require extensive code updates and cause performance overhead) with a hardware-based resource manager that directly monitors and controls resource access. This substitution eliminates the need for complex software patches while maintaining security with minimal performance impact

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive monitoring of all computing devices is performed to detect cache side channel attacks, then detection capability is improved, but detection overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection overhead
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The hardware resource manager applies local quality by monitoring resource usage at the specific location where cache side channel attacks originate (within the processor's resource management hardware) rather than requiring system-wide monitoring. This localized approach enables precise detection of suspicious patterns while minimizing the energy and computational overhead associated with comprehensive system monitoring

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10860714B2Technologies for cache side channel attack detection and mitigation
Publication Date: 2020.12.08 INTEL CORP
  • US10860714B2 patent drawing
  • US10860714B2 patent drawing
  • US10860714B2 patent drawing

AI summary

Technologies for cache side channel attack detection and mitigation include an analytics server and one or more monitored computing devices. The analytics server polls each computing device for analytics counter data. The computing device generates the analytics counter data using a resource manager of a processor of the computing device. The analytics counter data may include last-level cache data or memory bandwidth data. The analytics server identifies suspicious core activity based on the analytics counter data and, if identified, deploys a detection process to the computing device. The computing device executes the detection process to identify suspicious application activity. If identified, the computing device may perform one or more corrective actions. Corrective actions include limiting resource usage by a suspicious process using the resource manager of the processor. The resource manager may limit cache occupancy or memory bandwidth used by the suspicious process. Other embodiments are described and claimed.