IP Library Granted Patent US 12,236,243
Granted Patent B2
US 12,236,243 · App. 18/138,591 · Granted Feb 25, 2025

Apparatuses and methods for speculative execution side channel mitigation

Inventors: Jason W. Brandt (Austin, TX); Deepak K. Gupta (Portland, OR); Rodrigo Branco (Hillsboro, OR); Joseph Nuzman (Haifa, IL); Robert S. Chappell (Portland, OR); Sergiu Ghetie (Hillsboro, OR); Wojciech Powiertowski (Beaverton, OR); Jared W. Stark, IV (Portland, OR); Ariel Sabba (Lavon, IL); Scott J. Cape (Portland, OR); Hisham Shafi (San Jose, CA); Lihu Rappoport (Haifa, IL); Yair Berger (Pardes-Hanna Karkur, IL); Scott P. Bobholz (Bolton, MA); Gilad Holzstein (Haifa, IL); Sagar V. Dalvi (Hillsboro, OR); Yogesh Bijlani (Portland, OR)
Assignee: Intel Corporation
G06F9/3844G06F9/30101G06F9/3806
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,236,243
App. No.
18/138,591
Granted
Feb 25, 2025
Kind
B2
Abstract

Methods and apparatuses relating to mitigations for speculative execution side channels are described. Speculative execution hardware and environments that utilize the mitigations are also described. For example, three indirect branch control mechanisms and their associated hardware are discussed herein: (i) indirect branch restricted speculation (IBRS) to restrict speculation of indirect branches, (ii) single thread indirect branch predictors (STIBP) to prevent indirect branch predictions from being controlled by a sibling thread, and (iii) indirect branch predictor barrier (IBPB) to prevent indirect branch predictions after the barrier from being controlled by software executed before the barrier.

Claims (43)

1. An apparatus comprising:

a core;

a register to store a capability bit that when set to a value of one indicates the core supports an always-on mode for indirect branch restricted speculation;

a hardware branch predictor to predict a target instruction of an indirect branch instruction; and

a model specific register to store an indirect branch restricted speculation bit for the core that when set to a value of one causes the hardware branch predictor to enable the always-on mode, wherein the always-on mode prevents branches predicted in a less privileged predictor mode from influencing branch predictions for indirect branches in a more privileged predictor mode, and stays enabled unless the apparatus is rebooted; and wherein the capability bit when set to a value of zero indicates the hardware branch predictor is to support another indirect branch restricted speculation mode that does not stay enabled unless the apparatus is rebooted.

2. The apparatus of claim 1 , wherein the always-on mode allows the hardware branch predictor in the more privileged predictor mode to, for the core, predict the target instruction of the indirect branch instruction based on software executed in the more privileged predictor mode.

3. The apparatus of claim 1 , wherein the another indirect branch restricted speculation mode is enableable and disableable by software.

4. The apparatus of claim 1 , wherein the more privileged predictor mode is a privilege level less than three.

5. The apparatus of claim 4 , wherein the less privileged predictor mode is a privilege level of three.

6. The apparatus of claim 1 , wherein the hardware branch predictor comprises a branch target buffer to include an entry for the target instruction predicted for the indirect branch instruction, and the always-on mode is to prevent new filling of the entry.

7. The apparatus of claim 1 , wherein the core is one of a plurality of cores of the apparatus.

8. A method comprising:

setting an indirect branch restricted speculation bit for a core of a processor, comprising a register storing a capability bit that when set to a value of one indicates the core supports an always-on mode for indirect branch restricted speculation, in a model specific register of the processor to a value of one to cause a branch predictor of the processor to enable the always-on mode, wherein the always-on mode prevents branches predicted in a less privileged predictor mode from influencing branch predictions for indirect branches in a more privileged predictor mode, and stays enabled unless the processor is rebooted;

transitioning the core of the processor to the more privileged predictor mode from the less privileged predictor mode;

and, when the capability bit is set to a value of zero, causing the branch predictor to enable another indirect branch restricted speculation mode that does not stay enabled unless the processor is rebooted.

9. The method of claim 8 , wherein the always-on mode allows the branch predictor in the more privileged predictor mode to, for the core, predict a target instruction of an indirect branch instruction based on software executed in the more privileged predictor mode.

10. The method of claim 8 , further comprising enabling and disabling the another indirect branch restricted speculation mode by software.

11. The method of claim 8 , wherein the more privileged predictor mode is a privilege level less than three.

12. The method of claim 11 , wherein the less privileged predictor mode is a privilege level of three.

13. The method of claim 8 , wherein the branch predictor comprises a branch target buffer to include an entry for a target instruction predicted for an indirect branch instruction, and the always-on mode is to prevent new filling of the entry.

14. The method of claim 8 , wherein the core is one of a plurality of cores of the processor.

15. A non-transitory machine readable medium that stores code that when executed by a machine causes the machine to perform a method comprising:

setting an indirect branch restricted speculation bit for a core of a processor, comprising a register storing a capability bit that when set to a value of one indicates the core supports an always-on mode for indirect branch restricted speculation, in a model specific register of the processor to a value of one to cause a branch predictor of the processor to enable the always-on mode, wherein the always-on mode prevents branches predicted in a less privileged predictor mode from influencing branch predictions for indirect branches in a more privileged predictor mode, and stays enabled unless the processor is rebooted;

transitioning the core of the processor to the more privileged predictor mode from the less privileged predictor mode;

and, when the capability bit is set to a value of zero, causing the core to enable another indirect branch restricted speculation mode that does not stay enabled unless the processor is rebooted.

16. The non-transitory machine readable medium of claim 15 , wherein the always-on mode allows the branch predictor in the more privileged predictor mode to, for the core, predict a target instruction of an indirect branch instruction based on software executed in the more privileged predictor mode.

17. The non-transitory machine readable medium of claim 15 , wherein the method further comprises enabling and disabling the another indirect branch restricted speculation mode by software.

18. The non-transitory machine readable medium of claim 15 , wherein the more privileged predictor mode is a privilege level less than three.

19. The non-transitory machine readable medium of claim 18 , wherein the less privileged predictor mode is a privilege level of three.

20. The non-transitory machine readable medium of claim 15 , wherein the branch predictor comprises a branch target buffer to include an entry for a target instruction predicted for an indirect branch instruction, and the always-on mode is to prevent new filling of the entry.

21. The non-transitory machine readable medium of claim 15 , wherein the core is one of a plurality of cores of the processor.

22. An apparatus comprising:

a core;

a register to store a capability bit that when set to a value of one indicates the core supports an always-on mode for indirect branch restricted speculation that stays enabled unless the apparatus is rebooted;

a hardware branch predictor to predict a target instruction of an indirect branch instruction; and

a model specific register to store an indirect branch restricted speculation bit for the core that when set to a value of one causes the hardware branch predictor to enable the always-on mode, in which predicted targets of indirect branches executed cannot be influenced by software executed in a less privileged predictor mode;

wherein the capability bit when set to a value of zero indicates the hardware branch predictor is to support another indirect branch restricted speculation mode that does not stay enabled unless the apparatus is rebooted.

23. The apparatus of claim 22 , wherein the always-on mode allows the hardware branch predictor to, for the core, predict the target instruction of the indirect branch instruction based on software executed in a more privileged predictor mode.

24. The apparatus of claim 23 , wherein the more privileged predictor mode is a privilege level less than three.

25. The apparatus of claim 22 , wherein the another indirect branch restricted speculation mode is enableable and disableable by software.

26. The apparatus of claim 22 , wherein the less privileged predictor mode is a privilege level of three.

27. The apparatus of claim 22 , wherein the hardware branch predictor comprises a branch target buffer to include an entry for the target instruction predicted for the indirect branch instruction, and the always-on mode is to prevent new filling of the entry.

28. The apparatus of claim 22 , wherein the core is one of a plurality of cores of the apparatus.

Continuity (2)
Continuation 16177028 · Oct 31, 2018
Related Publication 20230342156A1 · Oct 26, 2023
References Cited (91)
US 5721855A · Hinton et al. · 1998 [cited by applicant]
US 5721945A · Mills · 1998 [cited by examiner]
US 6158676A · Hughes · 2000 [cited by applicant]
US 6185676B1 · Poplingher et al. · 2001 [cited by applicant]
US 7272831B2 · Cota-Robles et al. · 2007 [cited by applicant]
US 7769964B2 · Newburn et al. · 2010 [cited by applicant]
US 10394716B1 · Piry et al. · 2019 [cited by applicant]
US 10642744B2 · Boggs et al. · 2020 [cited by applicant]
US 10909046B2 · Murphy · 2021 [cited by applicant]
US 11010067B2 · Durham · 2021 [cited by applicant]
US 11403394B2 · O'Farrell · 2022 [cited by applicant]
US 11635965B2 · Brandt · 2023 [cited by examiner]
US 20030009692A1 · Smith et al. · 2003 [cited by applicant]
US 20030033510A1 · Dice · 2003 [cited by applicant]
US 20040010702A1 · Lewis · 2004 [cited by examiner]
US 20060031679A1 · Soltis · 2006 [cited by examiner]
US 20060143485A1 · Naveh et al. · 2006 [cited by applicant]
US 20080046668A1 · Newburn et al. · 2008 [cited by applicant]
US 20080052499A1 · Koc · 2008 [cited by applicant]
US 20080109625A1 · Erlingsson et al. · 2008 [cited by applicant]
US 20080155679A1 · Sebot et al. · 2008 [cited by applicant]
US 20090089564A1 · Brickell et al. · 2009 [cited by applicant]
US 20100293342A1 · Morfey · 2010 [cited by examiner]
US 20120278598A1 · Wang · 2012 [cited by examiner]
US 20140189302A1 · Subbareddy et al. · 2014 [cited by applicant]
US 20150178513A1 · Conti et al. · 2015 [cited by applicant]
US 20160170769A1 · Lemay · 2016 [cited by applicant]
US 20160285896A1 · Caprioli · 2016 [cited by applicant]
US 20190004961A1 · Boggs et al. · 2019 [cited by applicant]
US 20190042263A1 · Sukhomlinov et al. · 2019 [cited by applicant]
US 20190050230A1 · Branco et al. · 2019 [cited by applicant]
US 20190114422A1 · Johnson et al. · 2019 [cited by applicant]
US 20190205142A1 · Ghosh · 2019 [cited by applicant]
US 20190227804A1 · Mukherjee et al. · 2019 [cited by applicant]
US 20190272239A1 · Hagersten et al. · 2019 [cited by applicant]
US 20190286443A1 · Solomatnikov · 2019 [cited by examiner]
US 20190303161A1 · Nassi et al. · 2019 [cited by applicant]
US 20190324756A1 · Chappell et al. · 2019 [cited by applicant]
US 20190339977A1 · Wallach · 2019 [cited by applicant]
US 20190347102A1 · Okazaki · 2019 [cited by applicant]
US 20190354368A1 · Okazaki · 2019 [cited by applicant]
US 20190377677A1 · Kamikubo et al. · 2019 [cited by applicant]
US 20190384726A1 · Murphy · 2019 [cited by applicant]
US 20200133679A1 · Brandt et al. · 2020 [cited by applicant]
US 20200210070A1 · Durham · 2020 [cited by applicant]
US 20200372129A1 · Gupta · 2020 [cited by applicant]
US 20210081530A1 · O'Farrell · 2021 [cited by applicant]
US 20210349634A1 · Durham · 2021 [cited by applicant]
GB 2574270A · 2019 [cited by applicant]
WO 2019212579A1 · 2019 [cited by applicant]
Horn “Project Zero: Reading privileged memory with a side-channel” Jan. 3, 2018 “https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html” Accessed May 2, 2024. 29 Pages. (Year: 2018). [cited by examiner]
AMD, “Software Techniques for Managing Speculation on AMD Processors,” White Paper, Revision Jan. 24, 2018, Retrieved from: https://developer.amd.com/wp-content/resources/Managing-Speculation-on-AMD-Processors.pdf, Jan.… [cited by applicant]
AMD, “Software Techniques for Managing Speculation on AMD Processors,” White Paper, Revision Jul. 10, 2018, Retrieved from https://developer.amd.com/wp-content/resources/90343-B_SoftwareTechniquesforManagingSpeculalion_… [cited by applicant]
Anonymous, “Disabling Indirect Branch Prediction (and thus speculation after indirect branch . . . Hacker News”, Jan. 4, 2018, Available Online at <https://news.ycombinator.com/item?id=16069950>, Retrieved on Mar. 19, 2… [cited by applicant]
Arm, “Arm V8.5—A CPU Updates,” Version 1.1, Oct. 23, 2018, pp. 1-12. [cited by applicant]
Arm, “Whitepaper—Cache Speculation Side-channels,” Version 2.4, Oct. 12, 2018, pp. 1-21. [cited by applicant]
Arm, “Whitepaper-Addressing Spectre Variant 1 (CVE-2017-5753) in Software,” Version 1.0, Oct. 12, 2018, pp. 1-14. [cited by applicant]
Decision to Grant, EP App. No. 20208101.4, Sep. 29, 2022, 2 pages. [cited by applicant]
European Search Report and Search Opinion, EP App. No. 19183503.2, Apr. 3, 2020, 9 pages. [cited by applicant]
European Search Report and Search Opinion, EP App. No. 20208101.4, May 17, 2021, 08 pages. [cited by applicant]
European Search Report and Search Opinion, EP App. No. 22203480.3, Feb. 1, 2023, 9 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/177,028, Feb. 22, 2022, 10 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/177,028, Feb. 23, 2021, 52 pages. [cited by applicant]
Intel, “Control-Flow Enforcement Technology Preview,” Revision 2.0, Document No. 334525-002, Jun. 2017, 145 pages. [cited by applicant]
Intel, “Deep Dive: Managed Runtime Speculative Execution Side Channel Mitigations”, Developer Zone, Available Online at <https://web.archive.org/web/20190514204814/https://software.intel.com/security-software-guidance/i… [cited by applicant]
Intel, “Intel (Registered) 64 and IA-32 Architectures Software Developer Manuals,” Oct. 12, 2016, Updated—May 18, 2018, 19 pages. [cited by applicant]
Intel, “Intel (Registered) Architecture Instruction Set Extensions and Future Features Programming Reference,” Ref. No. 319433-034, May 2018, 145 pages. [cited by applicant]
Intel, “Intel Analysis of Speculative Execution Side Channels,” White paper, Revision 1.0, Document No. 336983-001, Jan. 2018, 12 pages. [cited by applicant]
Intel, “Intel(registered) 64 and IA-32 Architectures Software Developer's Manual”, Order No. 325462-071US, Available Online at <https://software.intel.com/sites/default/files/managed/39/c5/325462-sdm-vol-1-2abcd-3abcd.p… [cited by applicant]
Intel, “Intel(registered) Software Guard Extensions (Intel(registered) SGX)”, Developer Guide, Available Online at <https://software.intel.com/sites/default/files/managed/33/70/intel-sgx-developer-guide.pdf>, 2020, pp. … [cited by applicant]
Intel, “Intel® Architecture Instruction Set Extensions and Future Features Programming Reference”, Reference No. 319433-032, Jan. 2018, 137 pages. [cited by applicant]
Intel, “Speculative Execution Side Channel Mitigations,” Revision 1.0, Jan. 2018, 15 pages. [cited by applicant]
Intel, “Speculative Execution Side Channel Mitigations,” Revision 2.0, May 2018, 21 pages. [cited by applicant]
Intel, “Speculative Execution Side Channel Mitigations,” Revision 3.0, May 2018, 23 pages. [cited by applicant]
Intention to grant, EP App. No. 19183503.2, May 17, 2022, 6 pages. [cited by applicant]
Intention to grant, EP App. No. 20208101.4, Jun. 1, 2022, 7 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/177,028, Aug. 5, 2020, 47 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/177,028, Aug. 9, 2021, 44 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/177,028, Aug. 16, 2022, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/833,478, Mar. 26, 2021, 5 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/177,028, Dec. 12, 2022, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/177,028, Mar. 9, 2023, 2 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/833,478, Feb. 3, 2021, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/341,068, Sep. 1, 2022, 10 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/341,068, Sep. 14, 2022, 5 pages. [cited by applicant]
Office Action, EP App. No. 19183503.2, Dec. 22, 2020, 9 pages. [cited by applicant]
Paolo Bonzini, “Reading privileged memory with a side-channel | Hacker News”, Jan. 4, 2018 (Jan. 4, 2018), Retrieved from the Internet: URL:https://news.ycombinator.com/item?id=16065845 [retrieved on May 13, 2020], 23 p… [cited by applicant]
S. Lee, M. Shih, P. Gera, T. Kim, H. Kim, and M. Peinado, “Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing,” in USENIX Security Symposium, 19 pages; Aug. 16-18, 2017 (Year: 2017). [cited by applicant]
Swiat, “Mitigating speculative execution side channel hardware vulnerabilities”, Microsoft Security Response Center, Security Research & Defense, Mar. 15, 2018, pp. 1-14. [cited by applicant]
Valles et al. “Performance Insights to Intel Hyper-Threading Technology”; 2009; 14 pages; Accessed on Oct. 27, 2015 at: https://software.intel.com/en-us/articles/performance-insights-to-intel-hyper-threading-technology … [cited by applicant]
Office Action, EP App. No. 22203480.3, Feb. 26, 2024, 04 pages. [cited by applicant]