MCU-Wide Timing Side Channels and Their Detection
Johannes Müller, Anna Lena Duque Antón, Lucas Deutschmann, Dino Mehmedagic, Cristiano Rodrigues, Daniel Oliveira, Mohammad Rahmani Fadiheh, Keerthikumara Devarajegowda, Sandro Pinto, Dominik Stoffel, Wolfgang Kunz
Abstract
Microarchitectural timing side channels have been thoroughly investigated as a security threat in hardware designs featuring shared buffers (e.g., caches) and/or parallelism between attacker and victim task execution. However, contradicting common intuitions, recent activities demonstrate that this threat is real even in microcontroller SoCs without such features. In this paper, we describe SoC-wide timing side channels previously neglected by security analysis and present a new formal method to close this gap. In a case study on the RISC-V Pulpissimo SoC, our method detected a vulnerability to a previously unknown attack variant that allows an attacker to obtain information about a victim's memory access behavior. After implementing a conservative fix, we were able to verify that the SoC is now secure w.r.t. the considered class of timing side channels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 46873df9-99ba-486f-90bf-38d573f3feb6Builds on7
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 141 citations
- Mind the Gap: Studying the Insecurity of Provably Secure Embedded Trusted Execution ArchitecturesMarton Bognar, Jo Van Bulck, Frank PiessensS&P 2022 · 21 citations
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 15 citations
- A Formal Approach to Confidentiality Verification in SoCs at the Register Transfer LevelJohannes Müller, Mohammad Rahmani Fadiheh, Anna Lena Duque Antón, Thomas Eisenbarth et al.DAC 2021 · 11 citations
- Towards a formally verified hardware root-of-trust for data-oblivious computingLucas Deutschmann, Johannes Müller, Mohammad Rahmani Fadiheh, Dominik Stoffel et al.DAC 2022 · 11 citations
Related papers
- It's About Time: Detecting Timing Side-Channel Vulnerabilities in High-Level Synthesis DesignsDenis Zuppiger, Katharina Ceesay-Seitz, Jiahui Xu, Lana Josipović et al.CCS 2026
- Formalising the Prevention of Microarchitectural Timing Channels by Operating SystemsRobert Sison, Scott Buckley, Toby Murray, Gerwin Klein et al.FM 2023 · 2 citations
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 1 citation
- Specification and Verification of Strong Timing Isolation of Hardware EnclavesStella Lau, Thomas Bourgeat, Clément Pit-Claudel, Adam ChlipalaCCS 2024 · 1 citation
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu et al.CCS 2025
