利用行间压缩 LLC 中的解压缩延迟构建隐蔽信道
Exploiting Decompression Latency for Covert Channels in Inter-Line-Compressed LLCs
浏览论文内容
中文总结 AI 辅助
针对 XOR 缓存中解压缩延迟不对称性,提出隐蔽信道攻击,利用压缩状态编码比特,实现 2.9 Mbps 带宽,较 Prime+Probe 提升 13.1 倍。
中文摘要 AI 辅助
最近提出的 XOR 缓存是一种行间压缩的最后一级缓存(LLC),它利用私有缓存与 LLC 之间的数据包含关系,通过异或操作将两个缓存行压缩为一个。该架构依赖缓存一致性协议进行数据解压缩。在本文中,我们证明这一机制——具体而言,未压缩行与压缩行上的缓存命中之间的延迟不对称性——引入了微架构漏洞。基于这一观察,我们提出了一种针对 XOR 缓存的隐蔽信道攻击。共谋的发送方通过向伙伴缓存行发起定向写请求来触发解压缩,从而控制接收方的访问延迟。通过利用 XOR 缓存的数据依赖压缩行为,发送方和接收方使用预先约定的数据值建立信道。该信道实现比 Prime+Probe 基线更高的带宽,原因有二:首先,每个比特编码在单个行的压缩状态中,而非缓存集的占用情况,因此单个集合可携带多个比特;其次,每个比特通过操纵一致性协议状态来解析,而非强制共享缓存逐出,因此相比 Prime+Probe 消耗更少的 LLC 访问和缺失。全系统模拟显示,在传输 50,000 比特时,观测到的比特错误率(BER)为 0.98%,带宽为 2.9 Mbps,在相同的低于 1% BER 选择规则下,带宽是 Prime+Probe 的 13.1 倍。
英文摘要
The recently proposed XOR cache is an inter-line-compressed last-level cache (LLC) that leverages the data-inclusion relationship between the private caches and the LLC, compressing two cache lines into one by XORing them. The architecture relies on the cache coherence protocol for data decompression. In this paper, we demonstrate that this mechanism - specifically the latency asymmetry between a cache hit on an uncompressed vs. compressed line - introduces microarchitectural vulnerabilities. Based on this observation, we propose a covert channel attack targeting the XOR cache. A colluding sender controls the receiver's access latency by triggering decompression through targeted write requests to partner cache lines. By exploiting the data-dependent compression behavior of the XOR cache, the sender and receiver establish the channel using pre-agreed data values. The channel achieves higher bandwidth than the Prime+Probe baseline for two reasons: first, each bit is encoded in the compression state of an individual line rather than the occupancy of a cache set, so a single set carries multiple bits; second, each bit is resolved by manipulating coherence-protocol state rather than forcing shared-cache evictions, so it costs fewer LLC accesses and demand misses than Prime+Probe. Full-system simulations show a bandwidth of 2.9 Mbps at an observed 0.98% bit-error rate (BER) over 50,000 transmitted bits, 13.1 times the bandwidth of Prime+Probe under the same sub-1%-BER selection rule.