Helium: Quantifying Microarchitectural Side-Channel Leakage with Probabilistic Guarantees
Samantha Archer, Mohammad Rahmani Fadiheh, Caroline Trippel
Abstract
Constant-time programming ensures zero leakage of program secrets via hardware side channels by preventing secrets from being passed to unsafe instructions. However, as microarchitectures employ more data-dependent optimizations to boost performance, more instructions become unsafe, and constant-time code incurs high performance cost. A promising alternative is bounding leakage according to application-specific requirements, but principled methods for doing so remain elusive. We present Helium, a three-part framework for quantifying hardware side-channel leakage of program secrets on specific microarchitectures. First, it leverages a new metric for expressing probabilistic privacy guarantees. Second, it employs a novel formalism for encoding how arbitrary hardware side channels give rise to attacker observations. Third, it provides two analysis techniques-symbolic (precise) and simulation (conservatively approximate)-to determine whether high-leakage observations occur with sufficiently low probability for a given victim program, secret input, microarchitecture, and attacker model. Through four case studies spanning cryptographic and image processing applications, Helium demonstrates the necessity of considering both program and microarchitecture when assessing security-performance trade-offs. In one case, improved performance does not imply worse security; in another, accepting small leakage risk enables significant performance overhead reduction compared to a recent zero-leakage software side-channel defense.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4ae2cf5d-9e76-4af5-b2a1-2c0aabcd73c0Related papers
- Towards a formally verified hardware root-of-trust for data-oblivious computingLucas Deutschmann, Johannes Müller, Mohammad Rahmani Fadiheh, Dominik Stoffel et al.DAC 2022 · 11 citations
- Declassiflow: A Static Analysis for Modeling Non-Speculative Knowledge to Relax Speculative Execution Security MeasuresRutvik Choudhary, Alan Wang, Zirui Neil Zhao, Adam Morrison et al.CCS 2023 · 4 citations
- SynthCT: Towards Portable Constant-Time CodeSushant Dinesh, Grant Garrett-Grossman, Christopher W. FletcherNDSS 2022
- Constant-time foundations for the new spectre eraSunjay Cauligi, Craig Disselkoen, Klaus von Gleissenthall, Dean M. Tullsen et al.PLDI 2020 · 90 citations
- Constantine: Automatic Side-Channel Resistance Using Efficient Control and Data Flow LinearizationPietro Borrello, Daniele Cono D'Elia, Leonardo Querzoni, Cristiano GiuffridaCCS 2021 · 43 citations
