Cornell University
Library
Cornell UniversityLibrary

eCommons

Help
Log In(current)
  1. Home
  2. Cornell University Graduate School
  3. Cornell Theses and Dissertations
  4. Efficient and Verifiable Timing Channel Protection for Multi-Core Processors

Efficient and Verifiable Timing Channel Protection for Multi-Core Processors

File(s)
Wang_cornellgrad_0058F_10146.pdf (2.82 MB)
Permanent Link(s)
https://doi.org/10.7298/X49K487W
https://hdl.handle.net/1813/47878
Collections
Cornell Theses and Dissertations
Author
Wang, Yao
Abstract

Modern computing systems are becoming increasingly vulnerable to timing channel attacks that leak confidential information through the timing of microarchitectural events. Many timing channel attacks are caused by the interference between different programs in the shared resources of a multi-core processor. For example, an attacker program's cache lines can be evicted by a victim program, which allows the attacker to infer secret information about the victim. Timing channel attacks pose serious threats to contemporary computing systems because they can bypass traditional defense mechanisms such as access control. Previous studies have even demonstrated a practical timing channel attack to recover the keystrokes of a user in the commercial Amazon EC2 cloud. In this thesis, we explored new timing channel attacks and developed timing channel protection schemes for some of the hardware resources in a multi-core processor. Specifically, we discovered new timing channel attacks in the shared on-chip networks and memory controllers. We proposed multiple protection mechanisms for on-chip networks, caches and memory controllers. Our protection schemes cover three high-level approaches: bi-directional protections, uni-directional protections and protections that trade off security for performance. We evaluate our protection schemes and show that the proposed schemes are effective against timing channel attacks while achieving performance improvements over previous protection schemes. Finally, we implemented some of the protection mechanisms in RTL and used SecVerilog to verify the information flow control in hardware. The results show that the protection mechanisms indeed remove timing channels at the gate level.

Date Issued
2017-01-30
Keywords
Computer engineering
•
Computer science
•
Computer Architecture
•
Memory Controller
•
Security
•
SecVerilog
•
Timing Channel
•
cache
Committee Chair
Suh, Gookwon Edward
Committee Member
Myers, Andrew C.
Batten, Christopher
Degree Discipline
Electrical and Computer Engineering
Degree Name
Ph. D., Electrical and Computer Engineering
Degree Level
Doctor of Philosophy
Type
dissertation or thesis

Site Statistics | Help

About eCommons | Policies | Terms of use | Contact Us

copyright © 2002-2026 Cornell University Library | Privacy | Web Accessibility Assistance