microSCALE: Static Analysis for Microarchitectural Side-channel Leakage Evaluation
Akshay Kumar E, Pranav Krishna N, Annapurna Valiveti, Pallavi Borkar, Aditi Roy, Chester Rebeiro
摘要
Developing cryptographic implementations that are resistant to side-channel attacks is challenging in modern CPUs. Data-dependent switching activity induces subtle transitions deep in the microarchitecture that can cause sensitive information to leak through the CPU's power consumption. Existing leakage detection tools largely rely on simulation-based testing, which is not only time-consuming but is also limited to the explored execution scenarios. We present microSCALE, a fully automated framework for detecting power side-channel leakages that occur due to transitions in the CPU's microarchitecture. By statically analyzing the CPU's RTL, microSCALE enables systematic exploration of microarchitectural leakage sources within seconds. It precisely localizes the origin of leakage in the hardware and traces it back to the corresponding software instructions. We evaluate microSCALE on several protected crypto-implementations, including GIFT, ASCON, PRESENT, and AES, running on an open-source RISC-V processor, and identify several leakage sources. For instance, we identify that a protected implementation of the GIFT cipher has about 80% of its instructions that leak on the Rocket Core. We show how microSCALE can help in hardening this implementation, reducing the side-channel leakage around 90.3%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Strong Non-Interference and Type-Directed Higher-Order MaskingGilles Barthe, Sonia Belaïd, François Dupressoir, Pierre-Alain Fouque 等CCS 2016 · 被引用 302 次
- Towards Practical Tools for Side Channel Aware Software Engineering: 'Grey Box' Modelling for Instruction LeakagesDavid McCann, Elisabeth Oswald, Carolyn WhitnallUSENIX Security 2017 · 被引用 99 次
- Coco: Co-Design and Co-Verification of Masked Software Implementations on CPUsBarbara Gigerl, Vedad Hadzic, Robert Primas, Stefan Mangard 等USENIX Security 2021 · 被引用 82 次
- Side-Channel Masking with Pseudo-Random GeneratorJean-Sébastien Coron, Aurélien Greuet, Rina ZeitounEUROCRYPT 2020 · 被引用 29 次
- Specification and Verification of Side-channel Security for Open-source Processors via Leakage ContractsZilong Wang, Gideon Mohr, Klaus von Gleissenthall, Jan Reineke 等CCS 2023 · 被引用 20 次
相关 Paper
- PSC-TG: RTL Power Side-Channel Leakage Assessment with Test Pattern GenerationTao Zhang, Jungmin Park, Mark Tehranipoor, Farimah FarahmandiDAC 2021 · 被引用 41 次
- EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel SignalsNader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos PrvulovicHPCA 2020 · 被引用 21 次
- Power Contracts: Provably Complete Power Leakage Models for ProcessorsRoderick Bloem, Barbara Gigerl, Marc Gourjon, Vedad Hadzic 等CCS 2022 · 被引用 6 次
- Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham 等USENIX Security 2022
- INTROSPECTRE: A Pre-Silicon Framework for Discovery and Analysis of Transient Execution VulnerabilitiesMoein Ghaniyoun, Kristin Barber, Yinqian Zhang, Radu TeodorescuISCA 2021 · 被引用 23 次
