{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/117716"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/117716","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Evaluating the security of novel microarchitecture","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-04-12 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2023-04-12 without embargo terms","abstract_has_math":false,"creators":["Sanchez Vicarte, Jose Rodrigo"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Fletcher, Christopher W","Bailey, Michael","Levchenko, Kirill","Mohan, Sibin","Valamehr, Jonathan"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-12","date_published":"2022-12","updated_at":"2026-07-22T22:24:56Z","subjects":["Microarchitectural Security","Microarchitectural Side Channels","Data At Rest"],"languages":["en","eng"],"rights":["Copyright 2022 Jose Sanchez Vicarte"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/117716","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Fletcher, Christopher W","Bailey, Michael","Levchenko, Kirill","Mohan, Sibin","Valamehr, Jonathan"]},{"key":"dc:creator","label":"Author","values":["Sanchez Vicarte, Jose Rodrigo"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2022-12","2022-09-19"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Microarchitectural Security","Microarchitectural Side Channels","Data At Rest"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2022 Jose Sanchez Vicarte"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/117716"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-04-12 without embargo terms","The student, Jose Sanchez Vicarte, accepted the attached license on 2022-09-02 at 11:51.","The student, Jose Sanchez Vicarte, submitted this Dissertation for approval on 2022-09-06 at 10:59.","This Dissertation was approved for publication on 2022-09-19 at 14:30.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18477 on 2023-04-12 at 07:23:15","Microarchitectural attacks have plunged Computer Architecture into a security crisis. Yet, as the slowing of Moore’s law justifies the use of ever more exotic microarchitecture, it is likely we have only seen the tip of the iceberg. Without transistor scaling, it follows that microarchitects will employ ever more exotic microarchitectural optimizations to improve performance. If the past is any indicator of the future, it stands to reason that these optimizations will have novel — if not devastating — security implications. To better anticipate this security crisis, this work performs the first systematic security-centric analysis of the Computer Architecture literature. Our rationale is that when implementing current and future processors, microarchitects will (quite reasonably) look to previously-proposed ideas. Further, beyond “simply” impacting future processors, it is likely the case that some such microarchitecture already exists in current hardware, creating la- tent, not-yet-discovered vulnerabilities. Examining the deluge of exploits which have come out in the last few years, it is clear that processor complexity has already outpaced attacker bandwidth to find zero days. However, current approaches to microarchitectural security today research limit our ability to study the security implications of microarchitecture before it is deployed. Conventional attack research methodology combines a specific microarchitectural optimization (as found on an already-deployed processor) with a convenient threat model and victim program to demonstrate an “at- tack” (usually key extraction for a specific cryptographic algorithm). This approach entangles the specific microarchitectural implementation with a specific threat model and a specific victim program. Making matters worse, this approach does not begin studying novel microarchitecture until after it is found on an already-deployed processor. While seemingly obvious, in vitro (design time) security evaluations are not common practice in the literature because it isn’t obvious how to study microarchitecture so early in the design process. Current approaches to microarchitectural security research provide limited utility at this stage because it is not clear how they can be used to study microarchitecture across all possible threat models and victim programs. We must start by decoupling a microarchitectural optimization from any single threat model and victim program. To address this problem, this work develops a novel abstraction which precisely and concisely captures microarchitectural leakage while abstract- ing away the victim program and threat model. Using this abstraction, this work performs the first broad, systematic study, of the microarchitecture literature to characterize the the security implications of both known and new (theorized) microarchitectural optimizations in an apples-to-apples fashion. Through discoveries made during this study, this work answers two major open questions in the field of microarchitectural security. First, this work discovers the first microarchitecture (outside of speculative execution) which is capable of leaking all of program memory (i.e., forms a “universal read gadget”). Second, this work discovers the first microarchitectural optimization, deployed on real processors today, capable of leaking data without even being read by the processor core (i.e., “at rest”)."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Evaluating the security of novel microarchitecture"]}]}],"canonical_facts":{"dc:contributor":["Fletcher, Christopher W","Bailey, Michael","Levchenko, Kirill","Mohan, Sibin","Valamehr, Jonathan"],"dc:creator":["Sanchez Vicarte, Jose Rodrigo"],"dc:date":["2022-12","2022-09-19"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-04-12 without embargo terms","The student, Jose Sanchez Vicarte, accepted the attached license on 2022-09-02 at 11:51.","The student, Jose Sanchez Vicarte, submitted this Dissertation for approval on 2022-09-06 at 10:59.","This Dissertation was approved for publication on 2022-09-19 at 14:30.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18477 on 2023-04-12 at 07:23:15","Microarchitectural attacks have plunged Computer Architecture into a security crisis. Yet, as the slowing of Moore’s law justifies the use of ever more exotic microarchitecture, it is likely we have only seen the tip of the iceberg. Without transistor scaling, it follows that microarchitects will employ ever more exotic microarchitectural optimizations to improve performance. If the past is any indicator of the future, it stands to reason that these optimizations will have novel — if not devastating — security implications. To better anticipate this security crisis, this work performs the first systematic security-centric analysis of the Computer Architecture literature. Our rationale is that when implementing current and future processors, microarchitects will (quite reasonably) look to previously-proposed ideas. Further, beyond “simply” impacting future processors, it is likely the case that some such microarchitecture already exists in current hardware, creating la- tent, not-yet-discovered vulnerabilities. Examining the deluge of exploits which have come out in the last few years, it is clear that processor complexity has already outpaced attacker bandwidth to find zero days. However, current approaches to microarchitectural security today research limit our ability to study the security implications of microarchitecture before it is deployed. Conventional attack research methodology combines a specific microarchitectural optimization (as found on an already-deployed processor) with a convenient threat model and victim program to demonstrate an “at- tack” (usually key extraction for a specific cryptographic algorithm). This approach entangles the specific microarchitectural implementation with a specific threat model and a specific victim program. Making matters worse, this approach does not begin studying novel microarchitecture until after it is found on an already-deployed processor. While seemingly obvious, in vitro (design time) security evaluations are not common practice in the literature because it isn’t obvious how to study microarchitecture so early in the design process. Current approaches to microarchitectural security research provide limited utility at this stage because it is not clear how they can be used to study microarchitecture across all possible threat models and victim programs. We must start by decoupling a microarchitectural optimization from any single threat model and victim program. To address this problem, this work develops a novel abstraction which precisely and concisely captures microarchitectural leakage while abstract- ing away the victim program and threat model. Using this abstraction, this work performs the first broad, systematic study, of the microarchitecture literature to characterize the the security implications of both known and new (theorized) microarchitectural optimizations in an apples-to-apples fashion. Through discoveries made during this study, this work answers two major open questions in the field of microarchitectural security. First, this work discovers the first microarchitecture (outside of speculative execution) which is capable of leaking all of program memory (i.e., forms a “universal read gadget”). Second, this work discovers the first microarchitectural optimization, deployed on real processors today, capable of leaking data without even being read by the processor core (i.e., “at rest”)."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/117716"],"dc:language":["en","eng"],"dc:rights":["Copyright 2022 Jose Sanchez Vicarte"],"dc:subject":["Microarchitectural Security","Microarchitectural Side Channels","Data At Rest"],"dc:title":["Evaluating the security of novel microarchitecture"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:56Z"}