Hardware Resource Manager for Cache Side Channel Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer processors are vulnerable to cache side channel attacks, such as Meltdown and Spectre, which can be exploited by malicious software to bypass access controls and read restricted memory locations, and existing countermeasures can negatively impact performance.
Innovation Solution
A system that includes multiple computing devices and an analytics server for detecting and mitigating cache side channel attacks by monitoring resource usage data, identifying suspicious core activity, and restricting resource usage through a hardware resource manager, without requiring updates to operating system code or processor microcode.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If operating system code and processor microcode are updated to counter Meltdown and Spectre vulnerabilities, then security against cache side channel attacks is improved, but device complexity and update requirements increase
Solution Approach 1:
The patent introduces a hardware resource manager as an intermediary component that monitors and controls resource usage between applications and processor resources. This mediator detects suspicious patterns indicative of cache side channel attacks and takes corrective actions without requiring changes to operating system code or processor microcode, thus resolving the contradiction by providing security through a separate hardware layer
Solution Approach 2:
The hardware resource manager performs self-service by autonomously monitoring resource usage patterns, detecting suspicious activity, and executing corrective actions without external intervention. The system automatically identifies applications attempting cache side channel attacks and restricts their resource access, eliminating the need for manual updates or external security management
2Reliability
If countermeasures are implemented to protect against Meltdown and Spectre vulnerabilities, then security is improved, but performance is negatively impacted
Solution Approach 1:
The hardware resource manager applies partial action by monitoring only specific resource usage patterns that indicate cache side channel attacks rather than implementing comprehensive security checks on all processor operations. By focusing detection efforts on suspicious patterns rather than all activity, the system maintains security while minimizing performance overhead
Solution Approach 2:
The patent replaces software-based security countermeasures (which require extensive code updates and cause performance overhead) with a hardware-based resource manager that directly monitors and controls resource access. This substitution eliminates the need for complex software patches while maintaining security with minimal performance impact
3Measurement precision
If comprehensive monitoring of all computing devices is performed to detect cache side channel attacks, then detection capability is improved, but detection overhead increases
Solution Approach 1:
The hardware resource manager applies local quality by monitoring resource usage at the specific location where cache side channel attacks originate (within the processor's resource management hardware) rather than requiring system-wide monitoring. This localized approach enables precise detection of suspicious patterns while minimizing the energy and computational overhead associated with comprehensive system monitoring
Data Source
AI summary
Technologies for cache side channel attack detection and mitigation include an analytics server and one or more monitored computing devices. The analytics server polls each computing device for analytics counter data. The computing device generates the analytics counter data using a resource manager of a processor of the computing device. The analytics counter data may include last-level cache data or memory bandwidth data. The analytics server identifies suspicious core activity based on the analytics counter data and, if identified, deploys a detection process to the computing device. The computing device executes the detection process to identify suspicious application activity. If identified, the computing device may perform one or more corrective actions. Corrective actions include limiting resource usage by a suspicious process using the resource manager of the processor. The resource manager may limit cache occupancy or memory bandwidth used by the suspicious process. Other embodiments are described and claimed.


