AI 中文总结
本研究提出新CPU指令dfence,结合SLH泛化后可在最少硬件支持下同时缓解Spectre-PHT与Spectre-STL,在Proteus CPU中实现后平均性能开销低于1%,还设计类型系统验证其指令放置以保障安全便捷应用。
AI 中文摘要
Spectre-PHT和Spectre-STL等推测执行攻击仍是现代处理器的关键安全隐患。尽管基于软件的缓解措施如推测加载硬化(SLH)能有效防护Spectre-PHT,但其范围有限且需要软件管理的推测掩码,易出错且成本高昂。针对Spectre-STL的防护措施如推测存储旁路禁用位(SSBD)会带来额外性能开销且缺乏细粒度控制。本研究提出dfence,一款新的CPU指令,它将SLH泛化,以最少的硬件支持同时缓解Spectre-PHT和Spectre-STL。dfence允许开发者标注敏感寄存器,硬件确保这些值不会瞬态泄露。我们在Proteus CPU中实现了dfence并评估其安全性与性能,基准测试显示其平均性能开销低于1%。此外,为支持便捷且安全的采用,我们设计了一个类型系统,用于静态验证代码中dfence指令的正确放置。
英文摘要
Speculative execution attacks such as Spectre-PHT and Spectre-STL remain a critical security concern in modern processors. While software-based mitigations like Speculative Load Hardening (SLH) offer effective protection against Spectre-PHT, they are limited in scope and require software-managed speculative masks, which can be error-prone and costly. Defenses against Spectre-STL, such as the Speculative Store Bypass Disable bit (SSBD), incur additional performance overhead and lack fine-grained control. In this work, we introduce dfence, a new CPU instruction that generalizes SLH to mitigate both Spectre-PHT and Spectre-STL with minimal hardware support. dfence enables developers to annotate sensitive registers, with the hardware ensuring that these values do not leak transiently. We implement dfence in the Proteus CPU and evaluate its security and performance, demonstrating less than 1% average performance overhead for our benchmarks. In addition, to support easy and secure adoption, we design a type system that statically verifies the correct placement of dfence instructions in code.