SMT-COP: Defeating Side-Channel Attacks on Execution Units in SMT Processors

Daniel Townley, Dmitry Ponomarev · 2019

Recent advances in side-channel attacks put intoquestion the viability of Simultaneous Multithreading (SMT) architectures from the security standpoint. To address this problem, we propose SMT-COP-a system that eliminates all known side-channels through shared execution logic, including ports and functional units, on SMT processors. At the core of SMT-COP is a small modification to the instruction scheduling logic that allows support for both spatial and temporal partitioning of the execution units to prevent controllable contention for these resources that causes side-channel attacks. We demonstrate thatthe security benefits of SMT-COP are achieved with modest performance overhead and hardware complexity, and without relying on software support. Further performance improvements can be achieved when SMT-COP is applied selectively, and we consider three forms of such selective application: a) in response to detecting resource contention; b) in response to detecting manipulations with time measurement infrastructure; and c) in response to explicit requests by applications. This study represents a step towards making SMT processors more secure.

Read the paper · More papers on PaperTik