Global Microprocessor Correctness in the Presence of Transient Execution

📅 2025-06-20
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Transient-execution attacks (e.g., Spectre, Meltdown) expose a fundamental lack of global correctness in modern microprocessors—stemming from informal ISA specifications that cannot rigorously capture conformance to both functional and security properties under microarchitectural optimizations. Method: We propose the first formal theory of global correctness for transient execution. Our approach introduces two novel refinement relations: *action-skipping refinement* and *shared-resource commitment refinement*, enabling a modular, verifiable specification framework. It integrates bit-level and cycle-accurate executable models, property-driven testing, and noninterference-based modeling. Contribution/Results: The framework enables precise, cross-microarchitecture ISA conformance checking under transient execution, uncovering inherent vulnerabilities in mainstream processors. It supports lightweight, automated vulnerability verification and provides both theoretical foundations and practical tools for secure microarchitecture design and formal verification.

Technology Category

Constraint Satisfaction and Optimization: Satisfiability Modulo TheoriesMachine Learning: Hardware-aware MLApplication Domains: Security

Application Category

Security and Privacy: Data transparency and provenanceSystems and Infrastructure for Web, Mobile and WoT: Web performance, measurement, and characterizationUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systems
📝 Abstract
Correctness for microprocessors is generally understood to be conformance with the associated instruction set architecture (ISA). This is the basis for one of the most important abstractions in computer science, allowing hardware designers to develop highly-optimized processors that are functionally"equivalent"to an ideal processor that executes instructions atomically. This specification is almost always informal, e.g., commercial microprocessors generally do not come with conformance specifications. In this paper, we advocate for the use of formal specifications, using the theory of refinement. We introduce notions of correctness that can be used to deal with transient execution attacks, including Meltdown and Spectre. Such attacks have shown that ubiquitous microprocessor optimizations, appearing in numerous processors for decades, are inherently buggy. Unlike alternative approaches that use non-interference properties, our notion of correctness is global, meaning it is single specification that: formalizes conformance, includes functional correctness and is parameterized by an microarchitecture. We introduce action skipping refinement, a new type of refinement and we describe how our notions of refinement can be decomposed into properties that are more amenable to automated verification using the the concept of shared-resource commitment refinement maps. We do this in the context of formal, fully executable bit- and cycle-accurate models of an ISA and a microprocessor. Finally, we show how light-weight formal methods based on property-based testing can be used to identify transient execution bugs.
Problem

Research questions and friction points this paper is trying to address.

Formalize microprocessor correctness against transient execution attacks
Develop global correctness specification including functional aspects
Enable automated verification using refinement-based methods
Innovation

Methods, ideas, or system contributions that make the work stand out.

Formal specifications using refinement theory
Action skipping refinement for correctness
Light-weight formal methods for bug detection
A
Andrew T. Walter
Northeastern University, Boston, Massachusetts, USA
K
Konstantinos Athanasiou
The MathWorks, Natick, Massachusetts, USA
P
Panagiotis Manolios
Northeastern University, Boston, Massachusetts, USA