Avoiding Instruction-Centric Microarchitectural Timing Channels Via Binary-Code Transformations
Michael Flanders, Reshabh K. Sharma, Alexandra E. Michael, Dan Grossman, David Kohlbrenner
Abstract
With the end of Moore's Law-based scaling, novel microarchitectural optimizations are being patented, researched, and implemented at an increasing rate. Previous research has examined recently published patents and papers and demonstrated ways these upcoming optimizations present new security risks via novel side channels. As these side channels are introduced by microarchitectural optimization, they are not generically solvable in source code.
In this paper, we build program analysis and transformation tools for automatically mitigating the security risks introduced by future instruction-centric microarchitectural optimizations. We focus on two classes of optimizations that are not yet deployed: silent stores and computation simplification. Silent stores are known to leak secret data being written to memory by dropping in-flight stores that will have no effect. Computation simplification is known to leak operands to arithmetic instructions by shortcutting trivial computations at execution time. This presents problems that classical constant-time techniques cannot handle: register spills, address calculations, and the micro-ops of complex instructions are all potentially leaky. To address these problems, we design, implement, and evaluate a process and tool, cio, for detecting and mitigating these types of side channels in cryptographic code. cio is a backstop, providing verified mitigation for novel microarchitectural side-channels when more specialized and efficient hardware or software tools, such as microcode patches, are not yet available.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5cd2a0de-ca97-42ee-95d2-c11cc74a66d9Cited by top-tier papers4
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt et al.USENIX Security 2024 · 15 citations
- H-Houdini: Scalable Invariant LearningSushant Dinesh, Yongye Zhu, Christopher W. FletcherASPLOS 2025 · 7 citations
- Testing Side-channel Security of Cryptographic Implementations against Future MicroarchitecturesGilles Barthe, Marcel Böhme, Sunjay Cauligi, Chitchanok Chuengsatiansup et al.CCS 2024 · 6 citations
- Protecting Cryptographic Code Against Spectre-RSB: (and, in Fact, All Known Spectre Variants)Santiago Arranz-Olmos, Gilles Barthe, Chitchanok Chuengsatiansup, Benjamin Grégoire et al.ASPLOS 2025 · 1 citation
Builds on17
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss et al.CCS 2019 · 289 citations
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
Related papers
- Opening Pandora's Box: A Systematic Study of New Ways Microarchitecture Can Leak Private DataJose Rodrigo Sanchez Vicarte, Pradyumna Shome, Nandeeka Nayak, Caroline Trippel et al.ISCA 2021 · 29 citations
- SynthCT: Towards Portable Constant-Time CodeSushant Dinesh, Grant Garrett-Grossman, Christopher W. FletcherNDSS 2022
- Formal verification of a constant-time preserving C compilerGilles Barthe, Sandrine Blazy, Benjamin Grégoire, Rémi Hutin et al.POPL 2020 · 77 citations
- Constantine: Automatic Side-Channel Resistance Using Efficient Control and Data Flow LinearizationPietro Borrello, Daniele Cono D'Elia, Leonardo Querzoni, Cristiano GiuffridaCCS 2021 · 43 citations
- microSCALE: Static Analysis for Microarchitectural Side-channel Leakage EvaluationAkshay Kumar E, Pranav Krishna N, Annapurna Valiveti, Pallavi Borkar et al.USENIX Security 2026
