EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel Signals
Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos Prvulovic
Abstract
Side-channel attacks have become a serious security concern for computing systems, especially for embedded devices, where the device is often located in, or in proximity to, a public place, and yet the system contains sensitive information. To design systems that are highly resilient to such attacks, an accurate and efficient design-stage quantitative analysis of side-channel leakage is needed. For many systems properties (e.g., performance, power, etc.), cycle-accurate simulation can provide such an efficient-yet-accurate design-stage estimate. Unfortunately, for an important class of side-channels, electromagnetic emanations, such a model does not exist, and there has not even been much quantitative evidence about what level of modeling detail (e.g., hardware, microarchitecture, etc.) would be needed for high accuracy. This paper presents EMSim, an approach that enables simulation of the electromagnetic (EM) side-channel signals cycle-by-cycle using a detailed micro-architectural model of the device. To evaluate EMSim, we compare its signals against actual EM signals emanated from real hardware (FPGA-based RISC-V processor), and find that they match very closely. To gain further insights, we also experimentally identify how the accuracy of the simulation degrades when key microarchitectural features (e.g., pipeline stall, cache-miss, etc.) and other hardware behaviors (e.g., data-dependent switching activity) are omitted from the simulation model. We further evaluate how robust the simulation-based results are, by comparing them to real signals collected in different conditions (manufacturing, distance, etc.). Finally, to show the applicability of EMSim, we demonstrate how it can be used to measure side-channel leakage through simulation at design-stage.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a4da220f-2b0c-4b86-ae87-57d2d0a2cf0dCited by top-tier papers2
- Rosita++: Automatic Higher-Order Leakage Elimination from Cryptographic CodeMadura A. Shelton, Lukasz Chmielewski, Niels Samwel, Markus Wagner et al.CCS 2021 · 11 citations
- Rosita: Towards Automatic Elimination of Power-Analysis Leakage in CiphersMadura A. Shelton, Niels Samwel, Lejla Batina, Francesco Regazzoni et al.NDSS 2021
Related papers
- microSCALE: Static Analysis for Microarchitectural Side-channel Leakage EvaluationAkshay Kumar E, Pranav Krishna N, Annapurna Valiveti, Pallavi Borkar et al.USENIX Security 2026
- Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware NonlinearityHaoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang et al.USENIX Security 2026
- MCU-Wide Timing Side Channels and Their DetectionJohannes Müller, Anna Lena Duque Antón, Lucas Deutschmann, Dino Mehmedagic et al.DAC 2024 · 1 citation
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes et al.CCS 2018 · 186 citations
- Towards Practical Tools for Side Channel Aware Software Engineering: 'Grey Box' Modelling for Instruction LeakagesDavid McCann, Elisabeth Oswald, Carolyn WhitnallUSENIX Security 2017 · 99 citations
