Helium: Quantifying Microarchitectural Side-Channel Leakage with Probabilistic Guarantees
Samantha Archer, Mohammad Rahmani Fadiheh, Caroline Trippel
摘要
Constant-time programming ensures zero leakage of program secrets via hardware side channels by preventing secrets from being passed to unsafe instructions. However, as microarchitectures employ more data-dependent optimizations to boost performance, more instructions become unsafe, and constant-time code incurs high performance cost. A promising alternative is bounding leakage according to application-specific requirements, but principled methods for doing so remain elusive. We present Helium, a three-part framework for quantifying hardware side-channel leakage of program secrets on specific microarchitectures. First, it leverages a new metric for expressing probabilistic privacy guarantees. Second, it employs a novel formalism for encoding how arbitrary hardware side channels give rise to attacker observations. Third, it provides two analysis techniques-symbolic (precise) and simulation (conservatively approximate)-to determine whether high-leakage observations occur with sufficiently low probability for a given victim program, secret input, microarchitecture, and attacker model. Through four case studies spanning cryptographic and image processing applications, Helium demonstrates the necessity of considering both program and microarchitecture when assessing security-performance trade-offs. In one case, improved performance does not imply worse security; in another, accepting small leakage risk enables significant performance overhead reduction compared to a recent zero-leakage software side-channel defense.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Towards a formally verified hardware root-of-trust for data-oblivious computingLucas Deutschmann, Johannes Müller, Mohammad Rahmani Fadiheh, Dominik Stoffel 等DAC 2022 · 被引用 11 次
- Declassiflow: A Static Analysis for Modeling Non-Speculative Knowledge to Relax Speculative Execution Security MeasuresRutvik Choudhary, Alan Wang, Zirui Neil Zhao, Adam Morrison 等CCS 2023 · 被引用 4 次
- SynthCT: Towards Portable Constant-Time CodeSushant Dinesh, Grant Garrett-Grossman, Christopher W. FletcherNDSS 2022
- Constant-time foundations for the new spectre eraSunjay Cauligi, Craig Disselkoen, Klaus von Gleissenthall, Dean M. Tullsen 等PLDI 2020 · 被引用 90 次
- Constantine: Automatic Side-Channel Resistance Using Efficient Control and Data Flow LinearizationPietro Borrello, Daniele Cono D'Elia, Leonardo Querzoni, Cristiano GiuffridaCCS 2021 · 被引用 43 次
