Skip to main navigation Skip to search Skip to main content

SpecVerif: RTL formal verification for detecting speculative execution trigger mechanisms

  • Shixuan Zhang
  • , Kexin Gong
  • , Yujia Zhang
  • , Hongpeng Wang*
  • , Mufan Cui
  • , Haixia Wang
  • , Dongsheng Wang
  • *Corresponding author for this work
  • Harbin Institute of Technology
  • Peng Cheng Laboratory
  • National Computer Network Emergency Response Technical Team/Coordination Center of China
  • Tsinghua University

Research output: Contribution to journalArticlepeer-review

Abstract

The continuous emergence of speculative execution vulnerabilities has posed a significant threat to processor security in recent years. It is imperative for hardware architects to conduct a comprehensive analysis of pre-silicon CPU designs for these vulnerabilities. However, formally verifying a complete speculative attack is challenging, because an end-to-end attack chain involves trigger generation, transient execution, covert-channel encoding, and secret reconstruction, which can lead to severe state-space explosion. This paper proposes SpecVerif, a formal verification framework for detecting misprediction-driven speculative execution trigger mechanisms. The key insight of SpecVerif is to decouple the trigger phase of speculative execution from covert-channel construction and secret leakage during formal analysis, thereby reducing the length of the checked attack chain. This allows the framework to focus on identifying instructions or RTL mechanisms that can open a transient execution window, rather than proving end-to-end exploitability. To realize this insight, we introduce an instruction-oriented differential verification scheme and a PC-based operand injection mechanism that injects controlled differences into the instruction under verification. We evaluated SpecVerif on two open-source RISC-V CPUs, BOOM and CVA6. Experimental results demonstrate that SpecVerif can effectively identify instructions capable of triggering speculative execution and provide bounded non-reachability evidence for instructions that do not violate the security property. Moreover, the framework requires only minimal manual annotations from the user. Our analysis also reveals a new potential speculative execution trigger mechanism in CVA6, which we term Spectre-JT.

Original languageEnglish
Article number103916
JournalJournal of Systems Architecture
Volume179
DOIs
StatePublished - Oct 2026
Externally publishedYes

Keywords

  • Formal verification
  • Microarchitectural security
  • Side-channel attack
  • Speculative execution vulnerabilities

Fingerprint

Dive into the research topics of 'SpecVerif: RTL formal verification for detecting speculative execution trigger mechanisms'. Together they form a unique fingerprint.

Cite this