USENIX Security2023Top-tier venue
Synchronization Storage Channels (S2C): Timer-less Cache Side-Channel Attacks on the Apple M1 via Hardware Synchronization Instructions
Jiyong Yu, Aishani Dutta, Trent Jaeger, David Kohlbrenner, Christopher W. Fletcher
Abstract
Shared caches have been a prime target for mounting crossprocess/core side-channel attacks. Fundamentally, these attacks require a mechanism to accurately observe changes in cache state. Most cache attacks rely on timing measurements to indirectly infer cache state changes, and attack success hinges on the reliability/availability of accurate timing sources. Far fewer techniques have been proposed to directly observe cache state changes without reliance on timers. Further, none of said 'timer-less' techniques are accessible to userspace attackers targeting modern CPUs. This paper proposes a novel technique for mounting timerless cache attacks targeting Apple M1 CPUs named Synchronization Storage Channels (S 2 C). The key observation is that the implementation of synchronization instructions, specifically Load-Linked/Store-Conditional (LL/SC), makes architectural state changes when L1 cache evictions occur. This by itself is a useful starting point for attacks, however faces multiple technical challenges when being used to perpetrate cross-core cache attacks. Specifically, LL/SC only observes L1 evictions (not shared L2 cache evictions). Further, each attacker thread can only simultaneously monitor one address at a time through LL/SC (as opposed to many). We propose a suite of techniques and reverse engineering to overcome these limitations, and demonstrate how a single-threaded userspace attacker can use LL/SC to simultaneously monitor multiple (up to 11) victim L2 sets and succeed at standard cache-attack applications, such as breaking cryptographic implementations and constructing covert channels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 643e3978-9e8d-4635-9e5a-bf8c2085d39cCited by top-tier papers24
- GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent PrefetchersBoru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher et al.USENIX Security 2024 · 52 citations
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 17 citations
- Invalidate+Compare: A Timer-Free GPU Cache Attack PrimitiveZhenkai Zhang, Kunbei Cai, Yanan Guo, Fan Yao et al.USENIX Security 2024 · 15 citations
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 6 citations
- Controlled Preemption: Amplifying Side-Channel Attacks from UserspaceYongye Zhu, Boru Chen, Zirui Neil Zhao, Christopher W. FletcherASPLOS 2025 · 5 citations
Builds on26
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta et al.USENIX Security 2016 · 594 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- ZeroTrace : Oblivious Memory Primitives from Intel SGXSajin Sasy, Sergey Gorbunov, Christopher W. FletcherNDSS 2018 · 244 citations
Related papers
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 1 citation
- Charting the Cache Side-Channel Frontier: A Systematic Study of Eviction Set Construction on Apple SiliconHan Wang, Yakun Wu, Yusi Feng, Yinqian ZhangUSENIX Security 2026
- SQUIP: Exploiting the Scheduler Queue Contention Side ChannelStefan Gast, Jonas Juffinger, Martin Schwarzl, Gururaj Saileshwar et al.S&P 2023
- Uncovering Software-Based Power Side-Channel Attacks on Apple M1/M2 SystemsNikhil Chawla, Chen Liu, Abhishek Chakraborty, Igor Chervatyuk et al.DAC 2024 · 2 citations
- SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple SiliconTianhong Xu, Saion Kumar Roy, Ruyi Ding, A. Adam Ding et al.CCS 2026
