BasicBlocker: ISA Redesign to Make Spectre-Immune CPUs Faster
arXiv:2007.15919 · doi:10.1145/3471621.3471857
Abstract
Recent research has revealed an ever-growing class of microarchitectural attacks that exploit speculative execution, a standard feature in modern processors. Proposed and deployed countermeasures involve a variety of compiler updates, firmware updates, and hardware updates. None of the deployed countermeasures have convincing security arguments, and many of them have already been broken. The obvious way to simplify the analysis of speculative-execution attacks is to eliminate speculative execution. This is normally dismissed as being unacceptably expensive, but the underlying cost analyses consider only software written for current instruction-set architectures, so they do not rule out the possibility of a new instruction-set architecture providing acceptable performance without speculative execution. A new ISA requires compiler and hardware updates, but these are happening in any case. This paper introduces BasicBlocker, a generic ISA modification that works for all common ISAs and that allows non-speculative CPUs to obtain most of the performance benefit that would have been provided by speculative execution. To demonstrate the feasibility of BasicBlocker, this paper defines a variant of the RISC-V ISA called BBRISC-V and provides a thorough evaluation on both a 5-stage in-order soft core and a superscalar out-of-order processor using an associated compiler and a variety of benchmark programs.
Preprint
References in corpus (6)
- ConTExT: Leakage-Free Transient Execution
- Prevention of Microarchitectural Covert Channels on an Open-Source 64-bit RISC-V Core
- A Lightweight Isolation Mechanism for Secure Branch Predictors
- Frontal Attack: Leaking Control-Flow in SGX via the CPU Frontend
- Flushgeist: Cache Leaks from Beyond the Flush
- Speculative Leakage in ARM Cortex-A53