USENIX Security2026Top-tier venue
microSCALE: Static Analysis for Microarchitectural Side-channel Leakage Evaluation
Akshay Kumar E, Pranav Krishna N, Annapurna Valiveti, Pallavi Borkar, Aditi Roy, Chester Rebeiro
Abstract
Developing cryptographic implementations that are resistant to side-channel attacks is challenging in modern CPUs. Data-dependent switching activity induces subtle transitions deep in the microarchitecture that can cause sensitive information to leak through the CPU's power consumption. Existing leakage detection tools largely rely on simulation-based testing, which is not only time-consuming but is also limited to the explored execution scenarios. We present microSCALE, a fully automated framework for detecting power side-channel leakages that occur due to transitions in the CPU's microarchitecture. By statically analyzing the CPU's RTL, microSCALE enables systematic exploration of microarchitectural leakage sources within seconds. It precisely localizes the origin of leakage in the hardware and traces it back to the corresponding software instructions. We evaluate microSCALE on several protected crypto-implementations, including GIFT, ASCON, PRESENT, and AES, running on an open-source RISC-V processor, and identify several leakage sources. For instance, we identify that a protected implementation of the GIFT cipher has about 80% of its instructions that leak on the Rocket Core. We show how microSCALE can help in hardening this implementation, reducing the side-channel leakage around 90.3%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on7
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque et al.CCS 2016 · 302 citations
- Towards Practical Tools for Side Channel Aware Software Engineering: 'Grey Box' Modelling for Instruction LeakagesDavid McCann, Elisabeth Oswald, Carolyn WhitnallUSENIX Security 2017 · 99 citations
- Coco: Co-Design and Co-Verification of Masked Software Implementations on CPUsBarbara Gigerl, Vedad Hadzic, Robert Primas, Stefan Mangard et al.USENIX Security 2021 · 82 citations
- Side-Channel Masking with Pseudo-Random GeneratorJean-Sébastien Coron, Aurélien Greuet, Rina ZeitounEUROCRYPT 2020 · 29 citations
- Specification and Verification of Side-channel Security for Open-source Processors via Leakage ContractsZilong Wang, Gideon Mohr, Klaus von Gleissenthall, Jan Reineke et al.CCS 2023 · 20 citations
Related papers
- PSC-TG: RTL Power Side-Channel Leakage Assessment with Test Pattern GenerationTao Zhang, Jungmin Park, Mark Tehranipoor, Farimah FarahmandiDAC 2021 · 41 citations
- EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel SignalsNader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos PrvulovicHPCA 2020 · 21 citations
- Power Contracts: Provably Complete Power Leakage Models for ProcessorsRoderick Bloem, Barbara Gigerl, Marc Gourjon, Vedad Hadzic et al.CCS 2022 · 6 citations
- Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham et al.USENIX Security 2022
- INTROSPECTRE: A Pre-Silicon Framework for Discovery and Analysis of Transient Execution VulnerabilitiesMoein Ghaniyoun, Kristin Barber, Yinqian Zhang, Radu TeodorescuISCA 2021 · 23 citations
