USENIX Security2024Top-tier venue
"These results must be false": A usability evaluation of constant-time analysis tools
Marcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt, Peter Schwabe, Gilles Barthe, Pierre-Alain Fouque, Yasemin Acar
Abstract
Cryptography secures our online interactions, transactions, and trust. To achieve this goal, not only do the cryptographic primitives and protocols need to be secure in theory, they also need to be securely implemented by cryptographic library developers in practice. However, implementing cryptographic algorithms securely is challenging, even for skilled professionals, which can lead to vulnerable implementations, especially to side-channel attacks. For timing attacks, a severe class of side-channel attacks, there exist a multitude of tools that are supposed to help cryptographic library developers assess whether their code is vulnerable to timing attacks. Previous work has established that despite an interest in writing constant-time code, cryptographic library developers do not routinely use these tools due to their general lack of usability. However, the precise factors affecting the usability of these tools remain unexplored. While many of the tools are developed in an academic context, we believe that it is worth exploring the factors that contribute to or hinder their effective use by cryptographic library developers [61] . To assess what contributes to and detracts from usability of tools that verify constant-timeness (CT), we conducted a two-part usability study with 24 (post) graduate student participants on 6 tools across diverse tasks that approximate real-world use cases for cryptographic library developers. We find that all studied tools are affected by similar usability issues to varying degrees, with no tool excelling in usability, and usability issues preventing their effective use. Based on our results, we recommend that effective tools for verifying CT need usable documentation, simple installation, easy to adapt examples, clear output corresponding to CT violations, and minimal noninvasive code markup. We contribute first steps to achieving these with limited academic resources, with our documentation, examples, and installation scripts 1 . 1. Timing attacks. Since Kocher's introduction of sidechannel vulnerabilities in 1996 [68], these threats have persisted despite significant efforts to address them. Considering the vast range of side-channel attacks, we will highlight a few pivotal moments with a focus on timing attacks. Kocher's seminal work highlighted vulnerabilities in asymmetric cryptographic algorithms like RSA and DSS through "Timing Attacks", emphasizing the potential for exploitation based on secret-dependent operation times. In 2002, Tsunoo et al. [104, 105] expanded timing attacks to symmetric cryptography, noting vulnerabilities in MISTY1, DES, and suggesting AES being vulnerable to cache-timing attacks. Independent work by Bernstein [13] and Osvik et al. [87] confirmed these AES vulnerabilities. In 2003, Brumley and Boneh [28] revealed that these attacks could be conducted remotely via network timings. Subsequent vulnerabilities were discovered in the SSL/TLS libraries [3, 27, 29, 44] and on hardwareassisted defenses, such as Yarom et al.'s "CacheBleed" [125]. Kaufman et al. [66] also warned of persistent vulnerabilities post-compilation. Despite these vulnerabilities and an emphasis on fixing them, side channels remain common in numerous platforms [19-21, 46-48, 79, 108, 109]. Some Common Criteria certified devices, despite their countermeasures, were found vulnerable [62] . Moreover, even recent post-quantum cryptographic efforts are affected [26, 54, 88, 89, 103, 113] . 2. Constant-time Analysis. In this paper, we focus on investigating usability aspects of tools that evaluate timing leakages 2
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b8166874-84ee-442f-a520-0d7236ff6320Cited by top-tier papers6
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler et al.NDSS 2026 · 4 citations
- Toward a Secure Fixed-Point Implementation of the Falcon Signature SchemeDaniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas PrestCRYPTO 2026 · 1 citation
- It Should Be Easy but... New Users' Experiences and Challenges with Secret Management ToolsLorenzo Neil, Deepthi Mungara, Laurie A. Williams, Yasemin Acar et al.CCS 2025
- BLACKOUT: Data-Oblivious Computation with Blinded CapabilitiesHossam ElAtali, Merve Gülmez, Thomas Nyman, N. AsokanCCS 2025
- Fact-Aligned and Template-Constrained Static Analyzer Rule Enhancement with LLMsZongze Jiang, Ming Wen, Ge Wen, Hai JinASE 2025
Builds on42
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 146 citations
Related papers
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt et al.S&P 2022 · 61 citations
- With Great Power Come Great Side Channels: Statistical Timing Side-Channel Analyses with Bounded Type-1 ErrorsMartin Dunsche, Marcel Maehren, Nurullah Erinola, Robert Merget et al.USENIX Security 2024 · 5 citations
- "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIsJuliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha FahlS&P 2025
- Enforcing Fine-grained Constant-time PoliciesBasavesh Ammanaghatta Shivakumar, Gilles Barthe, Benjamin Grégoire, Vincent Laporte et al.CCS 2022 · 11 citations
- Formal verification of a constant-time preserving C compilerGilles Barthe, Sandrine Blazy, Benjamin Grégoire, Rémi Hutin et al.POPL 2020 · 77 citations
