arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.10634cs.CRcs.AR

HermiCache:面向可信执行环境的围栏感知缓存替换策略

HermiCache: Enclave-Aware Cache Replacement for Trusted Execution Environments

  • ENSTA(法国国立高等先进技术学校)
  • Université Bretagne-Sud(南布列塔尼大学)

机构由 AI 辅助整理,请以论文原文为准。

Oussama Elmnaouri, Pascal Cotret, Vianney Lapôtre, Loïc Lagadec

AI总结:

针对TEE缓存侧信道攻击,提出围栏感知缓存替换策略HermiCache,在RISC-V CVA6内核实现,面积开销仅6%,提供细粒度确定性保护。

AI中文摘要:

可信执行环境(TEEs)保护围栏内存免受不可信软件的攻击,但由于共享微架构资源,仍易受到基于缓存的侧信道攻击。现有对策使用缓存分区或随机化等技术:如果设计者希望实现细粒度配置和确定性保护,这些解决方案并不理想。在本文中,我们介绍了HermiCache,它正是为满足这些需求而提出的。HermiCache专为RISC-V内核设计,并已在OpenHwGroup CVA6内核中实现,软件层采用Keystone TEE。该方案在处理器核心上的面积开销为6%。

英文摘要:

Trusted Execution Environments (TEEs) protect enclave memory from untrusted software but remain vulnerable to cache-based side-channel attacks due to shared microarchitectural resources. Existing countermeasures use techniques such as cache partitioning or randomization: these solutions are not ideal if a designer wants fine-grained configurations and a deterministic protection. In this paper, we introduce HermiCache which is an answer to these requirements. HermiCache is designed for RISC-V cores and has been implemented in the OpenHwGroup CVA6 core with a Keystone TEE for the software layer. The solution has an area overhead of 6% on the processor core.

↑