Skip to main navigation Skip to search Skip to main content

XcptProof: Formal Verification of CPU Exception Transient Execution Security via Leakage Contracts

  • Shixuan Zhang
  • , Yujia Zhang
  • , Kexin Gong
  • , Hongpeng Wang*
  • , Haixia Wang*
  • , Dongsheng Wang
  • *Corresponding author for this work
  • Harbin Institute of Technology Shenzhen
  • Pengcheng Laboratory
  • Tsinghua University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Transient execution attacks triggered by CPU exceptions, such as Meltdown and MDS-type attacks, have compromised system security. Unfortunately, no prior work has conducted a formalized analysis of the CPU exception transient execution security. To bridge this gap, we propose a framework, XcptProof, which primarily consists of two components: (1) defining exception-related hardware-software contracts to model the CPU's leakage capabilities, and (2) utilizing a formal verification methods to exhaustively analyze the CPU's satisfiability of given contracts. We introduce a miter-circuit based detection model and further incorporate a frontend-backend decoupling approach to optimize efficiency. XcptProof successfully verifies 49 contracts on the BOOM processor and confirms the effectiveness of the frontend-backend decoupling optimization.

Original languageEnglish
Title of host publicationGLSVLSI 2026 - Proceedings of the Great Lakes Symposium on VLSI 2026
EditorsFan Chen, Peipei Zhou, Jie Gu, Amit R. Trivedi, Xiaoxuan Yang
PublisherAssociation for Computing Machinery, Inc
Pages665-671
Number of pages7
ISBN (Electronic)9798400724312
DOIs
StatePublished - 22 Jun 2026
Externally publishedYes
Event36th Great Lakes Symposium on VLSI, GLSVLSI 2026 - Canandaigua, United States
Duration: 22 Jun 202624 Jun 2026

Publication series

NameGLSVLSI 2026 - Proceedings of the Great Lakes Symposium on VLSI 2026

Conference

Conference36th Great Lakes Symposium on VLSI, GLSVLSI 2026
Country/TerritoryUnited States
CityCanandaigua
Period22/06/2624/06/26

Keywords

  • CPU exception
  • Microarchitectural security
  • formal hardware verification
  • leakage contract
  • transient execution attack

Fingerprint

Dive into the research topics of 'XcptProof: Formal Verification of CPU Exception Transient Execution Security via Leakage Contracts'. Together they form a unique fingerprint.

Cite this