Lune

S&P2026顶会

RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache Incoherence

Fabian Thomas, Michael Schwarz

2026年份
1被引次数

摘要

Caches have long been known to leak information across isolation boundaries, with classic attacks relying on timing to distinguish cache hits and misses. However, modern CPUs and operating systems increasingly limit timer resolution or restrict access to cycle counters, making such attacks less reliable in practice. As an alternative, architectural side channels replace timing with instruction sequences whose architectural outcome depends on cache state, offering higher robustness.

In this paper, we introduce I 2 SC, a generic timer-free architectural cache side channel that exploits instruction/data-cache incoherence on RISC-V, ARM, and LoongArch. I 2 SC leverages a widespread RISC property: stores through the data path are invisible to instruction fetch when the instruction cache holds stale lines, yielding architecturally distinct outcomes that reveal cache state. Unlike prior work that targets only instruction caches, I 2 SC generalizes this behavior into a timerfree oracle for both instruction and data caches via a transientexecution-based cache-state transfer gadget. We evaluate I 2 SC on 18 microarchitectures, finding that 12 microarchitectures are affected. To demonstrate the security impact of I 2 SC, we mount three end-to-end attacks: a timer-free AES keyrecovery, a Spectre variant with architectural leakage across all three architectures, achieving reliability on par with or exceeding prior timing-based methods, and a classical sidechannel attack on Android shared libraries recovering finegrained touch-event timing. Finally, we discuss both software and hardware mitigations, noting that full prevention likely requires hardware changes.

• We propose I 2 SC, an unprivileged timer-free architectural cache side channel that exploits instruction/data cache incoherence on RISC-V, ARM, and LoongArch.

• We identify two main building blocks for I 2 SC and evaluate their prevalence on 18 microarchitectures, finding that 12 microarchitectures are affected by I 2 SC, including recent high-performance cores deployed in smartphones, servers, and domestic ISAs.

• We present Spectral attacks and architectural sidechannel attacks on AES T-tables on all three ISAs. Further, we show an architectural side-channel attack on shared Android libraries recovering touch-event timing, such as taps and swipes, on the Google Pixel 9 running Android 16.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper36

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖