MCU-Wide Timing Side Channels and Their Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Müller, Johannes, Antón, Anna Lena Duque, Deutschmann, Lucas, Mehmedagić, Dino, Rodrigues, Cristiano, Oliveira, Daniel, Devarajegowda, Keerthikumara, Fadiheh, Mohammad Rahmani, Pinto, Sandro, Stoffel, Dominik, Kunz, Wolfgang
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911959767580672
author Müller, Johannes
Antón, Anna Lena Duque
Deutschmann, Lucas
Mehmedagić, Dino
Rodrigues, Cristiano
Oliveira, Daniel
Devarajegowda, Keerthikumara
Fadiheh, Mohammad Rahmani
Pinto, Sandro
Stoffel, Dominik
Kunz, Wolfgang
author_facet Müller, Johannes
Antón, Anna Lena Duque
Deutschmann, Lucas
Mehmedagić, Dino
Rodrigues, Cristiano
Oliveira, Daniel
Devarajegowda, Keerthikumara
Fadiheh, Mohammad Rahmani
Pinto, Sandro
Stoffel, Dominik
Kunz, Wolfgang
contents Microarchitectural timing side channels have been thoroughly investigated as a security threat in hardware designs featuring shared buffers (e.g., caches) or parallelism between attacker and victim task execution. However, contradicting common intuitions, recent activities demonstrate that this threat is real even in microcontroller SoCs without such features. In this paper, we describe SoC-wide timing side channels previously neglected by security analysis and present a new formal method to close this gap. In a case study on the RISC-V Pulpissimo SoC, our method detected a vulnerability to a previously unknown attack variant that allows an attacker to obtain information about a victim's memory access behavior. After implementing a conservative fix, we were able to verify that the SoC is now secure w.r.t. the considered class of timing side channels.
format Preprint
id arxiv_https___arxiv_org_abs_2309_12925
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle MCU-Wide Timing Side Channels and Their Detection
Müller, Johannes
Antón, Anna Lena Duque
Deutschmann, Lucas
Mehmedagić, Dino
Rodrigues, Cristiano
Oliveira, Daniel
Devarajegowda, Keerthikumara
Fadiheh, Mohammad Rahmani
Pinto, Sandro
Stoffel, Dominik
Kunz, Wolfgang
Cryptography and Security
Microarchitectural timing side channels have been thoroughly investigated as a security threat in hardware designs featuring shared buffers (e.g., caches) or parallelism between attacker and victim task execution. However, contradicting common intuitions, recent activities demonstrate that this threat is real even in microcontroller SoCs without such features. In this paper, we describe SoC-wide timing side channels previously neglected by security analysis and present a new formal method to close this gap. In a case study on the RISC-V Pulpissimo SoC, our method detected a vulnerability to a previously unknown attack variant that allows an attacker to obtain information about a victim's memory access behavior. After implementing a conservative fix, we were able to verify that the SoC is now secure w.r.t. the considered class of timing side channels.
title MCU-Wide Timing Side Channels and Their Detection
topic Cryptography and Security
url https://arxiv.org/abs/2309.12925