SeMPE: Secure Multi Path Execution Architecture for Removing Conditional Branch Side Channels
Andrea Mondelli, Paul Gazzillo, Yan Solihin
Abstract
One of the most prevalent source of side channel vulnerabilities is the secret-dependent behavior of conditional branches (SDBCB). The state-of-the-art solution relies on Constant-Time Expressions, which require high programming effort and incur high performance overheads. In this paper, we propose SeMPE, an approach that relies on architecture support to eliminate SDBCB without requiring much programming effort while incurring low performance overheads. The key idea is that when a secret-dependent branch is encountered, the SeMPE microarchitecture fetches, executes, and commits both paths of the branch, preventing the adversary from inferring secret values from the branching behavior of the program. To enable that, SeMPE relies on an architecture that is capable of safely executing both branch paths sequentially. Through microbenchmarks and an evaluation of a real-world library, we show that SeMPE incurs near ideal execution time overheads, which is the sum of the execution time of all branch paths of secret-dependent branches. SeMPE outperforms code generated by FaCT, a constant-time expression language, by up to a factor of 18×.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 89e1fb5a-1ff1-459b-9881-96684df5eccbBuilds on2
Related papers
- Towards a formally verified hardware root-of-trust for data-oblivious computingLucas Deutschmann, Johannes Müller, Mohammad Rahmani Fadiheh, Dominik Stoffel et al.DAC 2022 · 11 citations
- Cassandra: Efficient Enforcement of Sequential Execution for Cryptographic ProgramsAli Hajiabadi, Trevor E. CarlsonISCA 2025 · 2 citations
- SynthCT: Towards Portable Constant-Time CodeSushant Dinesh, Grant Garrett-Grossman, Christopher W. FletcherNDSS 2022
- HoBBy: Hardening Unbalanced Branches against Control Flow Attacks on Intel SGX and AMD SEVChang Liu, Shuaihu Feng, Yuan Li, Dongsheng Wang et al.DAC 2025 · 2 citations
- Declassiflow: A Static Analysis for Modeling Non-Speculative Knowledge to Relax Speculative Execution Security MeasuresRutvik Choudhary, Alan Wang, Zirui Neil Zhao, Adam Morrison et al.CCS 2023 · 4 citations
