🤖 AI Summary
Traditional redundancy mechanisms are vulnerable to common-mode failures because replicated program instances share identical memory layouts and code. To address this limitation, this work proposes a structured address space decorrelation approach that generates multiple semantically equivalent program variants through independent compilation, each exhibiting distinct memory layouts. At runtime, the method extracts normalized instruction traces—comprising opcodes, registers, operands, and results—while eliminating address dependencies, and performs cross-variant comparison to detect faults. This technique effectively identifies common-mode errors induced by arbitrary program counter jumps or data pointer corruptions, thereby significantly enhancing the capability of runtime semantic consistency verification.
📝 Abstract
Traditional redundancy (lockstep, TMR) executes identical binaries with identical memory layouts. A single correlated fault - for example, an arbitrary program counter value or a perturbation delta-PC in all replicas - redirects all replicas along the same incorrect path. The same applies to corruption of data pointers. Both types of faults, regardless of their origin (deliberate tampering, software bug, compilation bug, or physical disturbance), cause silent data corruption and erroneous program execution. This work presents Divergent Multi-Version Execution (DME), a runtime semantic consistency verifier for diversified executions. Each replica is compiled independently, producing different code and data memory layouts while preserving identical semantics. Faults are detected by comparing canonical instruction traces, which include opcodes, register identifiers, loaded/stored values, and results, while discarding layout-dependent addresses.