Intel processors utilize the retirement to orderly retire the micro-ops that have been executed out of order. To enhance retirement utilization, the retirement is dynamically shared between two logical cores on the same physical core. However, this shared retirement mechanism creates a potential vulnerability wherein an attacker can exploit the competition for retirement to infer the data of a victim on another logical core on the same physical core. Based on this leakage, we propose two new covert channels: the Different Instructions (DI) covert channel using different instructions for information transmission, and the Same Instructions (SI) covert channel using the same instructions to transmit information. The DI covert channel can achieve 98.5% accuracy with a bandwidth of 1450 Kbps, while the SI covert channel can achieve 94.85% accuracy with a bandwidth of 483.33 Kbps. Furthermore, this paper explores additional applications of retirement: Firstly, retirement is applied to Spectre attacks, resulting in a new variant of Spectre v1, which can achieve 94.17% accuracy with a bandwidth of 29 Kbps; Secondly, retirement is leveraged to infer the programs being executed by the victim, which can infer 10 integer benchmarks of SPEC with 89.28% accuracy. Finally, we discuss possible protection against new covert channels.
翻译:英特尔处理器利用退役机制有序地回收已乱序执行的微操作。为提升退役利用率,同一物理核心上的两个逻辑核动态共享退役资源。然而,这种共享退役机制产生了潜在漏洞:攻击者可利用对退役资源的竞争,推断同一物理核心上另一逻辑核中受害者的数据。基于这一泄露,我们提出两种新型隐蔽信道:使用不同指令传输信息的不同指令(DI)隐蔽信道,以及使用相同指令传输信息的相同指令(SI)隐蔽信道。DI隐蔽信道在1450 Kbps带宽下可实现98.5%的准确率,而SI隐蔽信道在483.33 Kbps带宽下可实现94.85%的准确率。此外,本文探讨了退役机制的其他应用:首先,将退役机制应用于Spectre攻击,产生Spectre v1的新变种,在29 Kbps带宽下可实现94.17%的准确率;其次,利用退役机制推断受害者执行的程序,对SPEC的10个整数基准程序可实现89.28%的推断准确率。最后,我们讨论针对新型隐蔽信道可能的防御措施。