Citadel: Simple Spectre-Safe Isolation For Real-World Programs That Share Memory

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Drean, Jules, Gomez-Garcia, Miguel, Jepsen, Fisher, Bourgeat, Thomas, Devadas, Srinivas
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915141722832896
author Drean, Jules
Gomez-Garcia, Miguel
Jepsen, Fisher
Bourgeat, Thomas
Devadas, Srinivas
author_facet Drean, Jules
Gomez-Garcia, Miguel
Jepsen, Fisher
Bourgeat, Thomas
Devadas, Srinivas
contents Transient execution side-channel attacks, such as Spectre, have been shown to break almost all isolation primitives. We introduce a new security property we call relaxed microarchitectural isolation (RMI) that allows sensitive programs that are not-constant-time to share memory with an attacker while restricting the information leakage to that of non-speculative execution. Although this type of speculative security property is typically challenging to enforce, we show that we can leverage the enclave setup to achieve it. In particular, we use microarchitectural isolation to restrict attacker's observations in conjunction with straightforward hardware mechanisms to limit speculation. This new design point presents a compelling trade-off between security, usability, and performance, making it possible to efficiently enforce RMI for any program. We demonstrate our approach by implementing and evaluating two simple defense mechanisms that satisfy RMI: (1) Safe mode, which disables speculative accesses to shared memory, and (2) Burst mode, a localized performance optimization that requires simple program analysis on small code snippets. Our end-to-end prototype, Citadel, consists of an FPGA-based multicore processor that boots Linux and runs secure applications, including cryptographic libraries and private inference, with less than 5% performance overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2306_14882
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Citadel: Simple Spectre-Safe Isolation For Real-World Programs That Share Memory
Drean, Jules
Gomez-Garcia, Miguel
Jepsen, Fisher
Bourgeat, Thomas
Devadas, Srinivas
Cryptography and Security
Hardware Architecture
Transient execution side-channel attacks, such as Spectre, have been shown to break almost all isolation primitives. We introduce a new security property we call relaxed microarchitectural isolation (RMI) that allows sensitive programs that are not-constant-time to share memory with an attacker while restricting the information leakage to that of non-speculative execution. Although this type of speculative security property is typically challenging to enforce, we show that we can leverage the enclave setup to achieve it. In particular, we use microarchitectural isolation to restrict attacker's observations in conjunction with straightforward hardware mechanisms to limit speculation. This new design point presents a compelling trade-off between security, usability, and performance, making it possible to efficiently enforce RMI for any program. We demonstrate our approach by implementing and evaluating two simple defense mechanisms that satisfy RMI: (1) Safe mode, which disables speculative accesses to shared memory, and (2) Burst mode, a localized performance optimization that requires simple program analysis on small code snippets. Our end-to-end prototype, Citadel, consists of an FPGA-based multicore processor that boots Linux and runs secure applications, including cryptographic libraries and private inference, with less than 5% performance overhead.
title Citadel: Simple Spectre-Safe Isolation For Real-World Programs That Share Memory
topic Cryptography and Security
Hardware Architecture
url https://arxiv.org/abs/2306.14882