🤖 AI Summary
This work addresses the challenge of efficiently emulating the anti-tampering properties of self-modifying code (SMC) in untrusted environments while preserving both timing and microarchitectural behavioral consistency—a task where conventional non-self-modifying code falls short. The paper presents the first systematic integration of timing observability, microarchitectural state, and SMC to formulate a tamper-resistant model that tightly binds integrity checks to program execution behavior. By leveraging introspective and polymorphic SMC, runtime timing predicates, cross-page code modification, and x86-64 instruction-level self-patching mechanisms, the approach enables a hybrid static-dynamic code generation strategy. Experimental results demonstrate that this method achieves strong tamper detection capabilities with significantly reduced performance overhead, offering an efficient and practical solution for deploying trusted execution in adversarial settings.
📝 Abstract
Classical computability theory tells us that self-modifying code (SMC) on a deterministic universal Turing machine can be simulated by non-SMC code on the same model. That abstraction, however, omits the external timing inputs, concurrency, and microarchitectural state that dominate practical execution on modern processors. We argue that once timing, ordering, and self-introspective effects are treated as observables, a practically faithful non-SMC reproduction of timed SMC becomes detectably expensive on commodity systems. We present a tamper-proofing model that combines introspective and polymorphic SMC, reliable clocks, and runtime timing predicates to bind integrity checks to execution behavior. We distinguish static and dynamic SMC generation, characterize the timing semantics needed to avoid catastrophic pipeline clears, and give x86-64 design primitives for checksum-driven self-patching. We also report timer measurements, performance comparisons, and performance-monitoring counter evidence showing that careful engineering -- especially loop unrolling and cross-page modification -- substantially reduces the overhead of SMC while preserving its tamper-detection value. The paper concludes with an efficiency analysis, a threat model, and deployment guidance for trusted code executing in untrusted environments.