USENIX Security2021Top-tier venue
Coco: Co-Design and Co-Verification of Masked Software Implementations on CPUs
Barbara Gigerl, Vedad Hadzic, Robert Primas, Stefan Mangard, Roderick Bloem
Abstract
The protection of cryptographic implementations against power analysis attacks is of critical importance for many applications in embedded systems. The typical approach of protecting against these attacks is to implement algorithmic countermeasures, like masking. However, implementing these countermeasures in a secure and correct manner is challenging. Masking schemes require the independent processing of secret shares, which is a property that is often violated by CPU microarchitectures in practice. In order to write leakage-free code, the typical approach in practice is to iteratively explore instruction sequences and to empirically verify whether there is leakage caused by the hardware for this instruction sequence or not. Clearly, this approach is neither efficient, nor does it lead to rigorous security statements. In this paper, we overcome the current situation and present the first approach for co-design and co-verification of masked software implementations on CPUs. First, we present COCO, a tool that allows us to provide security proofs at the gate-level for the execution of a masked software implementation on a concrete CPU. Using COCO, we analyze the popular 32-bit RISC-V IBEX core, identify all design aspects that violate the security of our tested masked software implementations and perform corrections, mostly in hardware. The resulting secured IBEX core has an area overhead around 10%, the runtime of software on this core is largely unaffected, and the formal verification with COCO of an, e.g., first-order masked Keccak S-box running on the secured IBEX core takes around 156 seconds. To demonstrate the effectiveness of our suggested design modifications, we perform practical leakage assessments using an FPGA evaluation board.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d2922c8e-2ad8-4ba2-8346-cb7916514294Cited by top-tier papers6
- IronMask: Versatile Verification of Masking SecuritySonia Belaïd, Darius Mercadier, Matthieu Rivain, Abdul Rahman TalebS&P 2022 · 30 citations
- Rosita++: Automatic Higher-Order Leakage Elimination from Cryptographic CodeMadura A. Shelton, Lukasz Chmielewski, Niels Samwel, Markus Wagner et al.CCS 2021 · 11 citations
- Power Contracts: Provably Complete Power Leakage Models for ProcessorsRoderick Bloem, Barbara Gigerl, Marc Gourjon, Vedad Hadzic et al.CCS 2022 · 6 citations
- Compositional Verification of Efficient Masking Countermeasures against Side-Channel AttacksPengfei Gao, Yedi Zhang, Fu Song, Taolue Chen et al.OOPSLA 2023 · 4 citations
- microSCALE: Static Analysis for Microarchitectural Side-channel Leakage EvaluationAkshay Kumar E, Pranav Krishna N, Annapurna Valiveti, Pallavi Borkar et al.USENIX Security 2026
Builds on1
Related papers
- PERSEUS - Probabilistic Evaluation of Random Probing SEcurity Using Efficient SamplingSonia Belaïd, Gaëtan CassiersEUROCRYPT 2026
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque et al.CCS 2016 · 302 citations
- Automated Verification of Correctness for Masked Arithmetic ProgramsMingyang Liu, Fu Song, Taolue ChenCAV 2023 · 1 citation
- On the Unpredictability of SPICE Simulations for Side-Channel Leakage Verification of Masked Cryptographic CircuitsKazuki Monta, Makoto Nagata, Josep Balasch, Ingrid VerbauwhedeDAC 2023 · 3 citations
- PathFinder: side channel protection through automatic leaky paths identification and obfuscationHaocheng Ma, Qizhi Zhang, Ya Gao, Jiaji He et al.DAC 2022 · 6 citations
