节点文献
面向开源处理器设计的瞬态执行漏洞检测
Transient execution vulnerability detection for open source CPU designs
【摘要】 随着RISC-V处理器的快速发展,其面临的硬件安全问题正在变得逐渐突出。而在处理器面临的安全威胁中,瞬态执行漏洞有着易于触发且难以修复的特点而被重点研究。重点研究了现代RISC-V处理器微架构的特点,结合现有的模糊测试技术,探究了在RISC-V处理器上进行瞬态执行漏洞检测的方法,并提出了如何覆盖更多的测试样例控制流和处理器部件硬件状态的方法。实验结果表明,所提方法设计的检测工具相比以前的检测工具在测试覆盖率指标上提高了16.7%,而在发现漏洞上多发现了两类漏洞,针对开源RTL设计上的漏洞检测提出了新的可能,并可促进新一代开源处理器的安全设计。
【Abstract】 With the rapid development of RISC-V processors, the hardware security issues they face are becoming increasingly prominent. Among the security threats confronting processors, transient execution vulnerabilities have been a focal point of research due to their ease of triggering and difficulty of remediation. This research investigates the characteristics of modern RISC-V processor microarchitectures and explores methods for detecting transient execution vulnerabilities on RISC-V processors, integrating existing fuzzing techniques. Furthermore, a method was proposed to cover more test case control flows and hardware states of processor components. Experimental results demonstrate that the detection tool designed with the proposed method achieves a 16. 7% improvement in the test coverage metric compared to previous detection tools and discovered two additional categories of vulnerabilities. The proposed method presents new possibilities for vulnerability detection on open-source RTL designs and can promote the secure design of the next generation of open-source processors.
【Key words】 hardware security; microarchitecture; branch prediction; fuzzing; pre-silicon testing; RISC-V; transient execution;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2025年12期
- 【分类号】TP332;TP309
- 【下载频次】12