MCU-Wide Timing Side Channels and Their Detection
Johannes Müller, Anna Lena Duque Antón, Lucas Deutschmann, Dino Mehmedagic, Cristiano Rodrigues, Daniel Oliveira, Mohammad Rahmani Fadiheh, Keerthikumara Devarajegowda, Sandro Pinto, Dominik Stoffel, Wolfgang Kunz
摘要
Microarchitectural timing side channels have been thoroughly investigated as a security threat in hardware designs featuring shared buffers (e.g., caches) and/or parallelism between attacker and victim task execution. However, contradicting common intuitions, recent activities demonstrate that this threat is real even in microcontroller SoCs without such features. In this paper, we describe SoC-wide timing side channels previously neglected by security analysis and present a new formal method to close this gap. In a case study on the RISC-V Pulpissimo SoC, our method detected a vulnerability to a previously unknown attack variant that allows an attacker to obtain information about a victim's memory access behavior. After implementing a conservative fix, we were able to verify that the SoC is now secure w.r.t. the considered class of timing side channels.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 被引用 141 次
- Mind the Gap: Studying the Insecurity of Provably Secure Embedded Trusted Execution ArchitecturesMarton Bognar, Jo Van Bulck, Frank PiessensS&P 2022 · 被引用 21 次
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 被引用 15 次
- A Formal Approach to Confidentiality Verification in SoCs at the Register Transfer LevelJohannes Müller, Mohammad Rahmani Fadiheh, Anna Lena Duque Antón, Thomas Eisenbarth 等DAC 2021 · 被引用 11 次
- Towards a formally verified hardware root-of-trust for data-oblivious computingLucas Deutschmann, Johannes Müller, Mohammad Rahmani Fadiheh, Dominik Stoffel 等DAC 2022 · 被引用 11 次
相关 Paper
- It's About Time: Detecting Timing Side-Channel Vulnerabilities in High-Level Synthesis DesignsDenis Zuppiger, Katharina Ceesay-Seitz, Jiahui Xu, Lana Josipović 等CCS 2026
- Formalising the Prevention of Microarchitectural Timing Channels by Operating SystemsRobert Sison, Scott Buckley, Toby Murray, Gerwin Klein 等FM 2023 · 被引用 2 次
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 被引用 1 次
- Specification and Verification of Strong Timing Isolation of Hardware EnclavesStella Lau, Thomas Bourgeat, Clément Pit-Claudel, Adam ChlipalaCCS 2024 · 被引用 1 次
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu 等CCS 2025
