节点文献

分支指令安全优化设计

Security-oriented optimization design for branch instructions

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 蓝泽如邱朋飞王春露汪东升

【Author】 LAN Ze-ru;QIU Peng-fei;WANG Chun-lu;WANG Dong-sheng;School of Cyberspace Security, Beijing University of Posts and Telecommunications;Key Laboratory of Trustworthy Distributed Computing and Service, Ministry of Education, Beijing University of Posts and Telecommunications;Zhongguancun Laboratory;Department of Computer Science and Technology,Tsinghua University;

【通讯作者】 邱朋飞;

【机构】 北京邮电大学网络空间安全学院北京邮电大学可信分布式计算与服务教育部重点实验室中关村实验室清华大学计算机科学与技术系

【摘要】 基于Spectre类漏洞主要由处理器中分支指令的不安全执行造成的事实,提出了一种新型分支指令安全优化机制,可有效防御Spectre V1与Spectre V2攻击。为便于部署和推广,实现了一个自动化安全工具,可在编译阶段自动识别并修改不安全的分支指令,以提升分支指令的安全性。实验结果表明,所提方法在保障安全性的同时,对处理器性能影响较小,且在硬件资源消耗方面优于现有多种典型的Spectre攻击缓解方案,展现出良好的通用性与实用性。

【Abstract】 Based on the fact that Spectre-type vulnerabilities are primarily caused by the unsafe execution of branch instructions in processors, a novel security optimization mechanism for branch instructions was proposed, which can effectively defend against attacks such as Spectre V1 and Spectre V2. An automated security tool was implemented to automatically identify and modify insecure branch instructions during the compilation phase, thereby enhancing the security of branch instructions, for the purpose of facilitating deployment and promotion. Experimental results demonstrate that the proposed method ensures security while imposing minimal impact on processor performance. It outperforms several existing typical Spectre attack mitigation schemes regarding hardware resource consumption, showing good versatility and practicality.

【基金】 国家重点研发计划青年科学家基金项目(2023YFB4403000);北京市自然科学基金面上基金项目(4242026);国家自然科学基金面上基金项目(62372258);中央高校基本科研业务费专项资金基金项目(2023RC71)
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2025年12期
  • 【分类号】TP309
  • 【下载频次】21
节点文献中: 

本文链接的文献网络图示:

本文的引文网络