2020/01/29 by Matteo Busi, Job Noorman, Busi, Matteo +11
Computer Science · Engineering · #Advanced Malware Detection Techniques #Advanced Memory and Neural Computing #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Physical Unclonable Functions (PUFs) and Hardware Security #Security and Verification in Computing
paper · pdf · doi:10.48550/arxiv.2001.10881
openalex publication_date 2020/01/29 · openalex created_date 2022/07/26 · openalex updated_date 2026/07/28
Computer systems often provide hardware support for isolation mechanisms like\nprivilege levels, virtual memory, or enclaved execution. Over the past years,\nseveral successful software-based side-channel attacks have been developed that\nbreak, or at least significantly weaken the isolation that these mechanisms\noffer. Extending a processor with new architectural or micro-architectural\nfeatures, brings a risk of introducing new such side-channel attacks.\n This paper studies the problem of extending a processor with new features\nwithout weakening the security of the isolation mechanisms that the processor\noffers. We propose to use full abstraction as a formal criterion for the\nsecurity of a processor extension, and we instantiate that criterion to the\nconcrete case of extending a microprocessor that supports enclaved execution\nwith secure interruptibility of these enclaves. This is a very relevant\ninstantiation as several recent papers have shown that interruptibility of\nenclaves leads to a variety of software-based side-channel attacks. We propose\na design for interruptible enclaves, and prove that it satisfies our security\ncriterion. We also implement the design on an open-source enclave-enabled\nmicroprocessor, and evaluate the cost of our design in terms of performance and\nhardware size.\n