《计算机应用》唯一官方网站

• •    下一篇

基于冲突的缓存侧信道攻击与驱逐集研究综述

姚梓豪1,马自强2,李扬2,魏良根1   

  1. 1. 宁夏大学 信息工程学院
    2. 宁夏大学信息工程学院
  • 收稿日期:2024-07-05 修回日期:2024-09-05 发布日期:2024-11-19 出版日期:2024-11-19
  • 通讯作者: 姚梓豪
  • 基金资助:
    基于机器学习技术的Cache侧信道攻击检测系统研究

Review of research on conflict-based cache side-channel attacks and eviction sets

  • Received:2024-07-05 Revised:2024-09-05 Online:2024-11-19 Published:2024-11-19
  • Supported by:
    Research on Cache Side Channel Attack Detection System Based on Machine Learning Technology

摘要: 缓存侧信道攻击是一种利用计算机缓存共享特性的侧信道攻击手段,对跨处理器、跨虚拟机的目标密码系统构成严重威胁。其中基于冲突的缓存侧信道攻击突破了使用特权指令的限制,构造一组与目标地址映射到同一缓存集的虚拟地址,即驱逐集,造成缓存冲突,最终获取目标隐私数据。构造驱逐集已成为基于冲突的缓存侧信道攻击和推测执行攻击的关键技术之一。首先介绍基于冲突的缓存侧信道攻击。其次,分类介绍驱逐集构造技术。然后,归纳驱逐集构造算法的影响因素。最后,提出利用系统设计的漏洞、提高算法的兼容性是基于冲突的缓存侧信道攻击和驱逐集构造算法的未来发展方向。

关键词: 系统安全, 缓存侧信道攻击, 驱逐集, 虚拟地址, 缓存替换策略

Abstract: Cache side-channel attacks exploit the shared characteristics of computer caches, posing serious threats to target cryptographic systems across processors and virtual machines. Conflict-based cache side-channel attacks overcome the limitations imposed of privileged instructions. They achieve this by constructing a set of virtual addresses, that map to the same cache set as the target address. This method allows attackers to infer the target's cache behavior, known as the eviction set, to cause cache conflicts and ultimately obtain the target's sensitive data. Constructing eviction set has become a key technique in conflict-based cache side-channel attacks and speculative execution attacks. Firstly, an introduction to conflict-based cache side-channel attacks is provided. Secondly, eviction set construction algorithms are categorized. Thirdly, the factors influencing eviction set construction algorithms are summarized. Finally, using system design vulnerabilities is a future direction for conflict-based cache side-channel attacks. Enhancing algorithm compatibility is crucial for eviction set construction algorithms.

Key words: system security, cache side channel attack, eviction set, virtual address, cache replacement policy

中图分类号: