• Home
  • Search
  • From hardware to software: An end-to-end side-channel attack surface analysis
  • https://doi.org/10.5463/thesis.330Copy DOI Icon

From hardware to software: An end-to-end side-channel attack surface analysis

  • Jan 8, 2025
  • Alyssa Anne Milburn
Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Computers are complicated, and the security of modern software often depends on programmers anticipating and mitigating a dizzying assortment of vulnerability classes. Both researchers and adversaries continue to add additional complications based on hardware behavior to this mix, such as data-dependant power consumption, fault injection, cache timing attacks and transient execution - adding new attack surface which needs to be taken into account when building secure systems. In this dissertation, we look beyond the traditional attack surface, and find that many mitigations - across a variety of layers, from hardware to software - are compromised by faulty assumptions about the actual behavior of hardware. We begin close to the hardware, discovering that the relationship between two different forms of hardware attack - Fault Injection and Side-Channel Analysis - is so strong that we can find ways to apply power side-channel attack techniques directly to the results of voltage fault injection campaigns, without the need for an attacker to obtain power measurements. Next, we move to microarchitectural attacks - which rely on hardware behavior, but can be performed by software. By combining transient execution with unexpected - and unintended - CPU pipeline behavior, we show that the scope of software side-channel attacks can be expanded far beyond previous work, allowing both in-flight and 'stale' data to be stolen from the pipeline by an attacker, bypassing software mitigations by ignoring security domains entirely. Such attacks can be mitigated by isolating workloads on different cores - which do not share a pipeline. Unfortunately, we find that even this level of isolation can fail to prevent attackers from being able to leak critical data using side-channel attacks - such as random numbers used when generating cryptographic keys. Hence, these attacks must be mitigated in hardware. Finally, we investigate defenses against transient execution attacks such as Spectre which depend only on well-understood hardware behavior, but require software mitigations. We show that we can build efficient and practical software-based defenses which not only mitigate many Spectre attacks, but even harden software against architectural information leaks.

Similar Papers
  • Conference Article
  • Citations17

EVAX: Towards a Practical, Pro-active & Adaptive Architecture for High Performance & Security

  • Oct 01, 2022
  • Samira Mirbagher Ajorpaz +5
  • Conference Article
  • Citations8

You can detect but you cannot hide: Fault Assisted Side Channel Analysis on Protected Software-based Block Ciphers

  • Jan 01, 2020
  • Athanasios Papadimitriou +4
  • Research Article
  • Citations1

Cache-timing attack against aes crypto system - countermeasures review

  • Mar 25, 2015
  • Australasian Journal of Paramedicine
  • Yaseen H Taha +3
  • Research Article
  • Citations21

Side channels as building blocks

  • Sep 14, 2012
  • Journal of Cryptographic Engineering
  • Markus Kasper +6
  • Conference Article
  • Citations11

Secure and Efficient RNS Software Implementation for Elliptic Curve Cryptography

  • Apr 01, 2017
  • Apostolos P Fournaris +2
  • Research Article
  • Citations1

Design of Deep Learning Techniques for Side-Channel Attacks on Masked 128-bit AES Implementations

  • Mar 14, 2024
  • AlKadhim Journal for Computer Science
  • Mohammed Saeb Nahi +3
  • Research Article
  • Citations49

Side-Channel Analysis of Chaos-Based Substitution Box Structures

  • Jan 01, 2019
  • IEEE Access
  • Mehmet Sahin Acikkapi +2
  • Conference Article

Implementation of Cache Timing Attack Based on Present Algorithm

  • Sep 01, 2022
  • Chen Lin +1
  • Conference Article
  • Citations31

“They’re not that hard to mitigate”: What Cryptographic Library Developers Think About Timing Attacks

  • May 01, 2022
  • Jan Jancar +7
  • Research Article
  • Citations2

Variety of Scalable Shuffling Countermeasures against Side Channel Attacks

  • Oct 13, 2016
  • Journal of Cyber Security and Mobility
  • Nikita Veshchikov +2
  • Book Chapter
  • Citations1

Impact of Sboxes Size upon Side Channel Resistance and Block Cipher Design

  • Jan 01, 2013
  • Louis Goubin +2
  • Conference Article
  • Citations3

XDIVINSA: eXtended DIVersifying INStruction Agent to Mitigate Power Side-Channel Leakage

  • Jul 01, 2021
  • Thinh Hung Pham +4
  • Research Article
  • Citations82

Side-channel and Fault-injection attacks over Lattice-based Post-quantum Schemes (Kyber, Dilithium): Survey and New Results

  • Mar 28, 2024
  • ACM Transactions on Embedded Computing Systems
  • Prasanna Ravi +3
  • Book Chapter

Mitigate the Side Channel Attack Using Random Generation with Reconfigurable Architecture

  • Jan 01, 2022
  • A E Sathis Kumar +1
  • Research Article
  • Citations19

Using templates to distinguish multiplications from squaring operations

  • May 27, 2011
  • International Journal of Information Security
  • Neil Hanley +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.