arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SCHERI:CHERI 在恒定时间策略下可证明安全的推测执行(扩展版)

SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version)

Shixin Song, Davide Davoli, Elias Storme, Marton Bognar, Dominique Devriese, Frank Piessens, Tamara Rezk

arXiv 2609.17399首次发表:更新:

发表机构

Massachusetts Institute of Technology; MPI-SP; DistriNet, KU Leuven; Inria(麻省理工学院; 马克斯·普朗克安全与隐私研究所; 荷语鲁汶大学分布式网络研究中心; 法国国家信息与自动化研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出 SCHERI,一种为 CHERI 架构提供可证明安全的推测执行的处理器设计,通过形式化框架联合推理能力安全与信息流,确保恒定时间策略下的端到端安全,抵御 Spectre 攻击。

AI 中文摘要

基于能力的架构(如 CHERI)为软件组件的架构隔离提供了强有力的支持。为了进一步防止微架构信息泄露,软件可以采用恒定时间风格编写。然而,现代处理器严重依赖推测执行,这可能破坏恒定时间的保证,并瞬时泄露隔离的秘密。在这项工作中,我们表明为 CHERI 提供安全推测并非易事,且现有方案未能保持机密性保证。我们开发了一个形式化框架,用于联合推理能力安全、推测执行和信息流安全,并利用该框架演示潜在泄露。随后,我们提出了 SCHERI,一种在该框架内的新处理器设计,并正式证明其为恒定时间策略提供了端到端的安全推测保证。我们的结果为构建未来能够抵御 Spectre 攻击(针对恒定时间程序)的基于能力的处理器提供了形式化基础和实用指导。

英文摘要

Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components. To additionally protect against microarchitectural leakage, software can be written in a constant-time fashion. Modern processors, however, rely heavily on speculative execution, which can invalidate the constant-time guarantees and leak isolated secrets transiently. In this work, we show that providing secure speculation for CHERI is non-trivial, and that existing proposals fail to preserve the confidentiality guarantees. We develop a formal framework for reasoning jointly about capability safety, speculative execution, and information-flow security, and use it to demonstrate potential leaks. We then present SCHERI, a new processor design within this framework, and formally prove that it provides end-to-end secure speculation guarantees for the constant-time policy. Our results provide formal foundations and practical guidance for building future capability-based processors, which are resilient to Spectre attacks for constant-time programs.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑