Abstract:
To address the speculative execution side-channel risks in the Core i7 processor adopted by the central control unit of urban rail transit platform system, this paper designed and implemented a side-channel attack detection system based on the speculative execution mechanism. The paper described the system architecture and constructed three modules including test case generation, execution, and result analysis around key speculative components including the Pattern History Table (PHT), Branch Target Buffer (BTB), and Return Stack Buffer (RSB). The system automatically generates diverse instruction sequences and achieves high-coverage testing of speculative components by combining genetic algorithms and instruction block management strategies. Experimental results showed that the system automatically constructed and efficiently executed various branch test cases, accurately identified speculative pollution and abnormal speculative execution paths, and revealed the structural speculative bias of different branch instructions and the Spectre V2-like potential risks of RET instructions. This system provides strong support for accurate risk assessment and active protection against speculative execution