RISC-V ISA Extension for Control Flow Integrity
Book information
Description
Low-level programming languages such as C and C++ delegate memory management to the programmer. Incorrect memory handling may cause memory errors, which present a prime target for attackers. Currently wide deployed defense mechanisms provide good protection against certain classes of attacks. Many mechanisms are defeated by powerful attackers with arbitrary memory access, as they rely on secrets stored in memory. We recognize the need for defense measures that can cope with such attackers. With ARMv8.3-A ARM has introduced ARM PAC, hardware support for pointer authentication. A PAC is a Message Authentication Code bound to the pointer value, a context, and a secret key. The PAC is stored in the unused bits of the pointer. It allows reliable tamper detection. It can be used to enforce Control Flow Integrity, providing strong hardware-based protection against code-reuse attacks. In this work we present an adaption of ARM PAC on the RISC-V architecture. We develop an extension to the Instruction Set Architecture for hardware-based pointer authentication. We modify GCC to support return address protection using pointer authentication instructions. Our approach allows for protection against strong attackers with arbitrary memory access. Introduction......Page 7 Contributions......Page 8 RISC-V......Page 9 Code Reuse Attacks......Page 11 Control Flow Integrity......Page 12 Current Defense Mechanisms......Page 13 ARM Pointer Authentication......Page 14 Authenticating and Verifying Pointers......Page 15 QARMA......Page 16 Security Properties......Page 17 Pointer Authentication on RISC-V......Page 20 Authentication and Verification of Pointers......Page 21 Key Management......Page 22 Instructions......Page 23 Control Flow Integrity......Page 25 Protection of Generic Data Structures......Page 26 Hardware......Page 27 Instructions......Page 28 Control and Status Registers......Page 29 GCC......Page 30 Linux Binutils and GDB......Page 32 Code Reuse Attacks......Page 34 PAC Entropy......Page 35 Signing Gadgets......Page 36 Instructions......Page 37 Return address signing......Page 38 Compatibility......Page 39 Related Work......Page 40 Conclusion......Page 41 Creating PACs for other Privilege Levels......Page 42 Extending Software Support......Page 43 Acronyms......Page 46 auth Instruction Implementation......Page 47 vrfy Instruction Implementation......Page 48 strp Instruction Implementation......Page 49
Similar books
RISC-V Assembly Language
2019 · PDF
Law & Disorder: Rearming the 66mm Light Anti-Tank Weapon
1994 · PDF
Introduction to Reversible Computing
2013 · PDF
An Encyclopedia of Locks and Builders Hardware
1968 · PDF
ThinkPad T510, T510i, and W510 Hardware Maintenance Manual
2009 · PDF
Lenovo IdeaPad S9e, S10e, and S10 Hardware Maintenance Manual
2009 · PDF
ThinkPad® T61, R61, and R61i (14-inch Widescreen) Hardware Maintenance Manual
2011 · PDF
Lockwood Locks and Builders Hardware Catalogue No. 12B
1965 · PDF