Pith. sign in

REVIEW 3 major objections 3 minor 298 references

Modern Hardware Security: A Review of Attacks and Countermeasures

T0 review · 3 major / 3 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read Modern hardware security cannot be patched piecemeal; the paper argues that a comprehensive map of attacks and countermeasures—from cache and power side channels to speculative execution, memory encryption, enclaves, secure boot, fault…

desk verdict A broad but uneven survey of hardware security: useful for newcomers in places, but the Meltdown/MDS taxonomy error and the Plundervolt citation mismatch undercut its value as a reliable reference until corrected. read the letter →

arxiv 2501.04394 v1 pith:KT6YJJ4E submitted 2025-01-08 cs.CR cs.AR

classification cs.CRcs.AR
keywords HardwareSecurityCacheSideChannelsSpeculativeExecutionPowerAnalysisAttacksMemoryEncryptionFaultInjectionSecureBootRISC-V
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper surveys the current state of hardware security across the main attack families and their countermeasures. It tries to establish that cache and power side channels, speculative execution flaws such as Spectre and Meltdown, memory encryption gaps, secure enclave weaknesses, secure boot failures, and fault injection are best treated as one connected landscape rather than isolated bugs. The authors argue that a comprehensive synthesis of these threats is a prerequisite for building hardware that resists both known and emerging attacks, and they give special attention to RISC-V as an open architecture where security features can be designed in directly. A sympathetic reader takes away a structured taxonomy: each attack is tied to the physical or microarchitectural channel it exploits and matched to the mitigation family proposed against it.

What carries the argument

The load-bearing object is the attack–countermeasure taxonomy. The paper partitions hardware security into named families, defines each sub-attack by the channel it reads (cache state, power trace, electromagnetic emission, fault response, boot-time trust anchor) and then attaches the mitigation families that interrupt that channel: serializing fences and taint tracking for speculation, partitioning and randomization for caches, masking and rekeying for power analysis, encryption and integrity trees for memory, isolation and attestation for enclaves, anchored verification for boot, and shielding/redundancy for fault injection. The RISC-V chapter shows the taxonomy being applied inside an open architecture, where defenses such as SpecTerminator's taint tracking, BasicBlocker's ISA change, and random dynamic frequency scaling can be implemented and benchmarked directly.

What would settle it

Take a specific taxonomy entry, such as the paper's classification of MDS/ZombieLoad as 'Meltdown Variant 4' in Section II.A.7, and compare it with the original ZombieLoad paper; if the original attack is a data-sampling flaw rather than a variant of Meltdown and does not use that numbering, the survey's classification is wrong and its reliability as a synthesis is called into question.

Watch

Extended reading notes

Core claim

The core claim is that modern hardware security is a connected, fast-evolving field whose defenses have to be planned holistically. The paper catalogs attacks by family—cache side channels (Prime+Probe, Flush+Reload, Evict+Reload, Prime+Abort, Flush+Flush), speculative execution (Spectre, Meltdown and their variants, LVI, Fallout, CacheOut, ZombieLoad, RIDL, NetSpectre), power analysis (SPA, DPA, CPA, template attacks, EMA), memory attacks (cold boot, remanence, rowhammer, DMA, bus snooping, ECC, MMU, thermal, timing), enclave attacks, secure boot attacks, and fault injection—and pairs each family with the countermeasures proposed in the literature, including memory fencing, cache partitioning and randomization, masking and rekeying, speculative taint tracking, secure boot chains, PUFs, and hardware monitoring. For RISC-V, it argues that the open ISA is both a testing ground for these defenses and a new attack surface, since extensibility and transparency invite scrutiny but also expose microarchitectural weaknesses. If the synthesis is correct, it provides a working map of what hardware designers and security engineers should defend against and which mitigation categories are available.

Load-bearing premise

The load-bearing premise is that every cited reference genuinely supports the claim it is attached to and that every attack is named and classified correctly; if any citation or classification is wrong, the synthesis built on it misleads.

Editorial extensions

If this is right

  • If the survey is correct, no single patch closes hardware security; defenses must combine speculation barriers, cache partitioning or randomization, masking and rekeying, memory encryption with integrity checks, secure boot, and fault-injection monitoring.
  • RISC-V systems should be expected to face the same attack families as x86 and ARM, so the open architecture needs built-in rather than retrofit countermeasures.
  • Design-time security integration—cryptographic ISAs, speculation controls, encrypted memory, PUF-based key storage—offers more durable protection than post-silicon microcode or software-only fixes.
  • Memory encryption alone is not sufficient because it does not stop fault injection or physical attacks; authenticity, integrity trees, and key management are required alongside confidentiality.
  • Machine-learning-based runtime detection of side-channel and speculative activity is a growing complement to hardware fixes, catching attacks that evade static defenses.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A practical extension would be a standardized benchmark that measures each mitigation's performance overhead and residual leakage on the same RISC-V core, allowing designers to compare defenses directly.
  • The taxonomy implicitly suggests a defense-in-depth principle: the same countermeasure categories (isolation, randomization, masking, monitoring) recur across attack families, so investments in cache partitioning and timing randomization may protect against speculative, power, and memory side channels simultaneously.
  • Because the survey's value depends on exact attack classification, readers should verify variant numbering against primary sources before using its taxonomy as a reference; a few labels in the text do not match the numbering of the original papers.
  • Open-source RISC-V hardware could accelerate the adoption of security extensions only if verification and formal-method tooling mature alongside them, since openness cuts both ways.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 3 minor

Summary. This manuscript is a broad survey of hardware security attacks and countermeasures, covering cache and power side channels, speculative execution, memory encryption, secure enclaves, cryptographic ISAs, secure boot, root of trust, PUFs, fault injection, and a dedicated section on RISC-V. The paper presents no new experimental or theoretical results; its contribution is a structured synthesis of existing literature, with the abstract claiming that the comprehensive analysis is essential for building resilient hardware security defenses.

Significance. If its taxonomy and citation fidelity were reliable, the survey would be a useful entry point for newcomers and a structured map of countermeasures across many hardware security areas. The RISC-V-focused section is a strength, as it consolidates recent work on speculative execution, power analysis, memory encryption, and cryptographic ISA extensions for an open architecture. However, because the value of a survey rests entirely on faithful synthesis, the concrete misclassifications and citation errors identified below directly undermine the central claim of reliability.

major comments (3)
  1. [II.A.7] The taxonomy in this subsection is incorrect in a way that is load-bearing for a survey. "Meltdown Variant 4 (Microarchitectural Data Sampling, MDS)" is not a Meltdown variant: ZombieLoad (reference [51]) belongs to the MDS/data-sampling family, and Section III.A later treats ZombieLoad, Fallout, and RIDL as separate speculative attacks without the Meltdown label. Likewise, "Meltdown Variant-RSB" is SpectreRSB, a Spectre-class attack targeting the return stack buffer (reference [52]), not a Meltdown variant. The numbering also conflicts with Section II.A.6, where "Spectre Variant 4" is Speculative Store Bypass. Because the paper's value is as a trustworthy synthesis, these misclassifications mislead readers about attack lineage and associated mitigations; they must be corrected.
  2. [III.L] The paragraph on Plundervolt mitigation cites reference [327], but the bibliography entry [327] is "V0ltpwn: Breaking SGX by Software-Controlled Voltage-Induced Faults," a different attack on SGX. Plundervolt is a separate software-controlled undervolting attack (Murdock et al., USENIX Security 2020). A reader relying on the survey to trace the Plundervolt countermeasure will be misdirected. This citation must be replaced with the correct Plundervolt reference.
  3. [III.K] The sentence listing "power supply noise injection, infrared fault injection, and acoustic fault injection" is supported by reference range [326]–[328], but [326] is an electromagnetic transient fault injection paper, [327] is V0ltpwn, and [328] is a masked dual-rail precharge logic paper. None of these supports the acoustic fault injection claim. The citation range should be narrowed or replaced with appropriate sources, since the survey's synthesis value depends on accurate references.
minor comments (3)
  1. [Abstract] The abstract contains typographical errors such as "Furthe rmore" and the wording "The comprehensive analysis presented in this paper is essential" is promotional for a survey; please copyedit and temper the claim.
  2. [Affiliation] The first author's affiliation contains "Bhubanes war" with a space; this should read "Bhubaneswar."
  3. [II.A.7] Even after correcting the MDS and SpectreRSB labels, the subsection would benefit from a sentence noting that MDS and Spectre are distinct families, to prevent future confusion.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the paper is a survey with no derivation chain, no fitted parameters, and no load-bearing self-citations, so its claims do not reduce to their own inputs.

full rationale

This manuscript is a review of external literature on hardware security attacks and countermeasures. It makes no new derivation, does not fit any parameter, and does not present a mathematical or empirical claim that could be equivalent to an input by construction. The authors do not cite their own prior work in any load-bearing role; the reference list contains no entries authored by Mishra or Sahay. The paper's value is a synthesis of published attacks and mitigations, which is self-contained with respect to the external sources it surveys. The skeptical concerns raised about the paper are accuracy issues, not circularity: Section II.A.7 labels MDS/ZombieLoad as 'Meltdown Variant 4' and SpectreRSB as 'Meltdown Variant-RSB,' and Section III.L discusses Plundervolt mitigation while citing V0ltpwn [327]. These are classification and citation-fidelity problems that affect the reliability of the survey, but they do not constitute a derivation chain that reduces to its own assumptions or to self-citations. Per the scoring rules, accuracy concerns belong to correctness risk rather than circularity, and a survey with external, independently checkable references should receive a score of 0-2. Here the appropriate finding is 0: no circular step is present.

Assumptions & free parameters 0 free parameters · 0 assumptions · 0 invented entities

This is a review paper. It has no free parameters, no unproved mathematical axioms, and no invented entities. All content is attributed to prior literature, so the ledger is empty.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Modern Hardware Security: A Review of Attacks and Countermeasures." pith.science (2026). https://pith.science/paper/KT6YJJ4E

@misc{pith2026250104394,
  author       = {Pith},
  title        = {Pith review of: Modern Hardware Security: A Review of Attacks and Countermeasures},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/KT6YJJ4E}},
  note         = {Machine review of arXiv:2501.04394}
}
read the original abstract

With the exponential rise in the use of cloud services, smart devices, and IoT devices, advanced cyber attacks have become increasingly sophisticated and ubiquitous. Furthermore, the rapid evolution of computing architectures and memory technologies has created an urgent need to understand and address hardware security vulnerabilities. In this paper, we review the current state of vulnerabilities and mitigation strategies in contemporary computing systems. We discuss cache side-channel attacks (including Spectre and Meltdown), power side-channel attacks (such as Simple Power Analysis, Differential Power Analysis, Correlation Power Analysis, and Template Attacks), and advanced techniques like Voltage Glitching and Electromagnetic Analysis to help understand and build robust cybersecurity defense systems and guide further research. We also examine memory encryption, focusing on confidentiality, granularity, key management, masking, and re-keying strategies. Additionally, we cover Cryptographic Instruction Set Architectures, Secure Boot, Root of Trust mechanisms, Physical Unclonable Functions, and hardware fault injection techniques. The paper concludes with an analysis of the RISC-V architecture's unique security challenges. The comprehensive analysis presented in this paper is essential for building resilient hardware security solutions that can protect against both current and emerging threats in an increasingly challenging security landscape.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

298 extracted references · 77 canonical work pages

  1. [51]

    Zombieload : Cross-privilege-boundary data sampling,

    M. Schwarz, M. Lipp, D. Moghimi, E. Koruyeh, D. Gruss, J. Krebbel, C. Maurice, D. Genkin, Y . Y arom, and S. Mangard, “Zombieload : Cross-privilege-boundary data sampling,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Secur ity, 2019, pp. 902–917

  2. [52]

    Spectre returns ! specula- tion attacks using the return stack buffer,

    E. Koruyeh, D. Moghimi, C. Easdon, D. Bhowmik, B. Ghena, A. Bhat- tacharya, S. Bagchi, and N. Abu-Ghazaleh, “Spectre returns ! specula- tion attacks using the return stack buffer,” in Proceedings of the 12th USENIX W orkshop on Offensive Technologies (WOOT 18) . USENIX Association, 2018

  3. [1]

    Improved side-c hannel re- sistance by dynamic fault-injection countermeasures,

    J. Richter-Brockmann and T. G¨ uneysu, “Improved side-c hannel re- sistance by dynamic fault-injection countermeasures,” in 2020 IEEE 31st International Conference on Application-specific Sys tems, Archi- tectures and Processors (ASAP) , 2020, pp. 117–124

  4. [2]

    Exploration of system-on-chip secure-boot vulnerability to fault-inj ection by side- channel analysis,

    C. Fanjas, D. Aboulkassimi, S. Ponti´ e, and J. Cl´ edi` er e, “Exploration of system-on-chip secure-boot vulnerability to fault-inj ection by side- channel analysis,” in 2023 IEEE International Symposium on Defect and Fault Tolerance in VLSI and Nanotechnology Systems (DFT ), 2023, pp. 1–6

  5. [3]

    Power analysis and fault attack s against secure can: How safe are your keys?

    C. O’Flynn and G. d’Eon, “Power analysis and fault attack s against secure can: How safe are your keys?” vol. 1, pp. 3–18, 2018

  6. [4]

    On the feasibility of fault injection attacks on risc-v device s,

    P . Cassano, M. Francalanza, C. D. Natale, and R. P . Jacobi , “On the feasibility of fault injection attacks on risc-v device s,” in IEEE International Symposium on Defect and Fault Tolerance in VL SI and Nanotechnology Systems (DFT) , 2022

  7. [5]

    Data leakage attacks on risc -v exploit- ing hardware vulnerabilities: A survey and data leakage ana lysis,

    A. Mulder and H. den Hartog, “Data leakage attacks on risc -v exploit- ing hardware vulnerabilities: A survey and data leakage ana lysis,” in Proceedings of the 56th Design Automation Conference (DAC) , 2019

  8. [6]

    Timing leakage in risc-v pro cessors,

    L. Jin, C. Wang, and X. Feng, “Timing leakage in risc-v pro cessors,” ACM Transactions on Architecture and Code Optimization , vol. 19, 2022

Show all 298 references
  1. [7]

    Microarchitectural atta cks on risc-v implementations,

    M. Nashimoto and K. Hayakawa, “Microarchitectural atta cks on risc-v implementations,” IACR Transactions on Cryptographic Hardware and Embedded Systems (TCHES) , vol. 2021, pp. 45–70, 2021

  2. [8]

    Secure embedded proces sor design using risc-v with enhanced side-channel attack resi stance,

    T. Le, R. Harrison, and K. Cheng, “Secure embedded proces sor design using risc-v with enhanced side-channel attack resi stance,” IEEE Access, vol. 9, pp. 112 233–112 246, 2021

  3. [9]

    Execut e on clear (eoc): Enhancing security for unsafe speculative i nstructions by precise identification and safe execution,

    X. Meng, Q. Y ang, Y . Ci, P . Zhao, S. Zhao, and M. Li, “Execut e on clear (eoc): Enhancing security for unsafe speculative i nstructions by precise identification and safe execution,” in 2023 IEEE 41st International Conference on Computer Design (ICCD) , 2023, pp. 587– 595

  4. [10]

    Mitigating speculation-based attacks through configurable hardware/ software co- design,

    A. Hajiabadi, A. Agarwal, A. Diavastos, and T. E. Carlso n, “Mitigating speculation-based attacks through configurable hardware/ software co- design,” ArXiv, vol. abs/2306.11291, 2023

  5. [11]

    Store vulnerability window (svw): Re-execut ion filtering for enhanced load optimization,

    A. Roth, “Store vulnerability window (svw): Re-execut ion filtering for enhanced load optimization,” in 32nd International Symposium on Computer Architecture (ISCA’05) , 2005, pp. 458–468

  6. [12]

    Reinforcing meltdown attack by u sing a return stack buffer,

    T. Kim and Y . joo Shin, “Reinforcing meltdown attack by u sing a return stack buffer,” IEEE Access , vol. 7, pp. 186 065–186 077, 2019

  7. [13]

    Cache memories,

    A. J. Smith, “Cache memories,” ACM Computing Surveys (CSUR) , vol. 14, no. 3, pp. 473–530, 1982

  8. [14]

    M ulti-level unified caches for probabilistically time analysable real- time systems,

    L. Kosmidis, J. Abella, E. Qui˜ nones, and F. Cazorla, “M ulti-level unified caches for probabilistically time analysable real- time systems,” in 2013 IEEE 34th Real-Time Systems Symposium , 2013, pp. 360–371

  9. [15]

    Relative performance of a multi-level ca che with last-level cache replacement: An analytic review,

    B. Paikaray, “Relative performance of a multi-level ca che with last-level cache replacement: An analytic review,” ArXiv, vol. abs/1307.6406, 2013, [Online]. Available: https://arxiv.org/abs/1307.6406

  10. [16]

    Differential power ana lysis,

    P . Kocher, J. Jaffe, and B. Jun, “Differential power ana lysis,” in Proceedings of the 19th Annual International Cryptology Co nference on Advances in Cryptology , ser. CRYPTO ’99. Springer-V erlag, 1999, pp. 388–397

  11. [17]

    Electromagnet ic analysis: Concrete results,

    K. Gandolfi, C. Mourtel, and F. Olivier, “Electromagnet ic analysis: Concrete results,” in Proceedings of the 3rd International W orkshop on Cryptographic Hardware and Embedded Systems , ser. CHES ’01. Springer-V erlag, 2001, pp. 251–261

  12. [18]

    Cache-timing attacks on aes,

    D. J. Bernstein, “Cache-timing attacks on aes,” Univer sity of Illinois at Chicago, Tech. Rep., 2005, preprint

  13. [19]

    Efficient cache at tacks on aes, and countermeasures,

    E. Tromer, D. A. Osvik, and A. Shamir, “Efficient cache at tacks on aes, and countermeasures,” Journal of Cryptology , vol. 23, no. 1, pp. 37–71, 2009

  14. [20]

    Access-driven c ache attack resistant and fast aes implementation,

    Y . Wan, X. Luo, Y . Qi, J. He, and Q. Wang, “Access-driven c ache attack resistant and fast aes implementation,” International Journal of Embedded Systems , vol. 10, pp. 32–40, 2018

  15. [21]

    An error-tolerant approach for efficient aes key retrieval in the pres- ence of cacheprefetching – experiments, results, analysis ,

    C. Ashokkumar, M. B. S. V enkatesh, R. Giri, B. Roy, and B. Menezes, “An error-tolerant approach for efficient aes key retrieval in the pres- ence of cacheprefetching – experiments, results, analysis ,” S¯ adhan¯ a, vol. 44, pp. 1–18, 2019

  16. [22]

    Modified cache t emplate attack on aes,

    M. Esfahani, H. Soleimany, and M. Aref, “Modified cache t emplate attack on aes,” IACR Cryptology ePrint Archive , vol. 2020, p. 1560, 2020

  17. [23]

    Advances on access-driven cach e attacks on aes,

    M. Neve and J. Seifert, “Advances on access-driven cach e attacks on aes,” in Proceedings of the International W orkshop on Cryptographi c Hardware and Embedded Systems (CHES) . Springer, 2006, pp. 147– 162

  18. [24]

    Cache games – b ringing access-based cache attacks on aes to practice,

    D. Gullasch, E. Bangerter, and S. Krenn, “Cache games – b ringing access-based cache attacks on aes to practice,” in Proceedings of the 2011 IEEE Symposium on Security and Privacy (SP) . IEEE, 2011, pp. 490–505

  19. [25]

    Highly efficien t algorithms for aes key retrieval in cache access attacks,

    C. Ashokkumar, R. Giri, and B. Menezes, “Highly efficien t algorithms for aes key retrieval in cache access attacks,” in 2016 IEEE European Symposium on Security and Privacy (EuroSP) . IEEE, 2016, pp. 261– 275

  20. [26]

    Last-le vel cache side-channel attacks are practical,

    F. Liu, Y . Y arom, Q. Ge, G. Heiser, and R. B. Lee, “Last-le vel cache side-channel attacks are practical,” in Proceedings of the 2015 IEEE Symposium on Security and Privacy (SP) . IEEE, 2015, pp. 605–622

  21. [27]

    Run-time detection of prime + probe side-ch annel attack on aes encryption algorithm,

    M. Mushtaq, A. Akram, M. K. Bhatti, R. N. B. Rais, V . Lapˆ o tre, and G. Gogniat, “Run-time detection of prime + probe side-ch annel attack on aes encryption algorithm,” in 2018 Global Information Infrastructure and Networking Symposium (GIIS) . IEEE, 2018, pp. 1–5

  22. [28]

    Flush+reload: A high resoluti on, low noise, l3 cache side-channel attack,

    Y . Y arom and K. Falkner, “Flush+reload: A high resoluti on, low noise, l3 cache side-channel attack,” in IACR Cryptol. ePrint Arch. , vol. 2013. IACR, 2014, p. 448

  23. [29]

    Flush, gauss, and reload: A cache attack on the bliss lattice-based signat ure scheme,

    L. G. Bruinderink, A. H¨ ulsing, T. Lange, and Y . Y arom, “ Flush, gauss, and reload: A cache attack on the bliss lattice-based signat ure scheme,” in IACR Cryptol. ePrint Arch. , vol. 2016. IACR, 2016, p. 300

  24. [30]

    Predicting s ecret keys via branch prediction,

    O. Aciicmez, C. K. Koc, and J.-P . Seifert, “Predicting s ecret keys via branch prediction,” in Proceedings of the 7th Cryptographers’ Track at the RSA Conference . Springer, 2007, pp. 225–242

  25. [31]

    Real-time detection of cach e side- channel attack using non-cache hardware events,

    H. Kim, C. Hahn, and J. Hur, “Real-time detection of cach e side- channel attack using non-cache hardware events,” in 2021 International Conference on Information Networking (ICOIN) . IEEE, 2021, pp. 28– 31

  26. [32]

    Deep learn ing-based detection for multiple cache side-channel attacks,

    H. Kim, C. Hahn, H. J. Kim, Y . Shin, and J. Hur, “Deep learn ing-based detection for multiple cache side-channel attacks,” IEEE Transactions on Information F orensics and Security , vol. 19, pp. 1672–1686, 2024

  27. [33]

    Flush+flush: A stea lthier last- level cache attack,

    D. Gruss, C. Maurice, and K. Wagner, “Flush+flush: A stea lthier last- level cache attack,” ArXiv, vol. abs/1511.04594, 2015

  28. [34]

    J. L. Hennessy and D. A. Patterson, Computer Architecture: A Quan- titative Approach, 6th ed. Morgan Kaufmann, 2017

  29. [35]

    Dynamic branch prediction with percep trons,

    D. A. Jim´ enez, “Dynamic branch prediction with percep trons,” in Pro- ceedings of the 7th International Symposium on Computer Arc hitecture (ISCA). IEEE, 2001, pp. 197–206

  30. [36]

    Speculative load forwardi ng attack on modern processors,

    H. Witharana and P . Mishra, “Speculative load forwardi ng attack on modern processors,” in Proceedings of the 41st IEEE/ACM Interna- tional Conference on Computer-Aided Design (ICCAD) . IEEE, 2022

  31. [37]

    Ret2spec: Speculative ex ecution using return stack buffers,

    G. Maisuradze and C. Rossow, “Ret2spec: Speculative ex ecution using return stack buffers,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . ACM, 2018

  32. [38]

    Spectre returns! speculation attacks using the return sta ck buffer,

    E. M. Koruyeh, K. N. Khasawneh, C. Song, and N. Abu-Ghaza leh, “Spectre returns! speculation attacks using the return sta ck buffer,” ArXiv, vol. abs/1807.07940, 2018

  33. [39]

    Spectre attacks: Exploiting speculative execution,

    P . Kocher, J. Horn, A. Fogh, D. Genkin, D. Gruss, W. Haas, M. Ham- burg, M. Lipp, S. Mangard, T. Prescher, M. Schwarz, and Y . Y ar om, “Spectre attacks: Exploiting speculative execution,” Communications of the ACM , vol. 63, pp. 93–101, 2020

  34. [40]

    Specsaf e: detecting cache side channels in a speculative world,

    R. Brotzman, D. Zhang, M. Kandemir, and G. Tan, “Specsaf e: detecting cache side channels in a speculative world,” in Proceedings of the ACM on Programming Languages , vol. 5, 2021, pp. 1–28

  35. [41]

    Y ou shall not bypass: Employing data dependencies to prevent bo unds check bypass,

    O. Oleksenko, B. Trach, T. Reiher, M. Silberstein, and C . Fetzer, “Y ou shall not bypass: Employing data dependencies to prevent bo unds check bypass,” in ArXiv, vol. abs/1805.08506, 2018

  36. [43]

    Y ou cannot always w in the race: Analyzing mitigations for branch target predicti on attacks,

    A. Milburn, K. Sun, and H. Kawakami, “Y ou cannot always w in the race: Analyzing mitigations for branch target predicti on attacks,” in 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P). IEEE, 2023, pp. 671–686

  37. [44]

    Speccfi: Mitigating spectre attacks usin g cfi in- formed speculation,

    E. M. Koruyeh, S. H. A. Shirazi, K. N. Khasawneh, C. Song, and N. Abu-Ghazaleh, “Speccfi: Mitigating spectre attacks usin g cfi in- formed speculation,” in 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 2019, pp. 39–53

  38. [45]

    Timed speculative attacks exploiting st ore-to-load forwarding bypassing cache-based countermeasures,

    A. Chakraborty, N. Singh, S. Bhattacharya, C. Rebeiro, and D. Mukhopadhyay, “Timed speculative attacks exploiting st ore-to-load forwarding bypassing cache-based countermeasures,” in Proceedings of the 59th ACM/IEEE Design Automation Conference . ACM, 2022

  39. [46]

    Speculative buffer o verflows: At- tacks and defenses,

    V . Kiriansky and C. Waldspurger, “Speculative buffer o verflows: At- tacks and defenses,” 2018

  40. [47]

    Netspec tre: Read arbitrary memory over network,

    M. Schwarz, M. Schwarzl, M. Lipp, and D. Gruss, “Netspec tre: Read arbitrary memory over network,” ArXiv, vol. abs/1807.10535, 2018

  41. [48]

    Meltdown: Reading kernel memory from user space,

    M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, S. Ma ngard, P . Kocher, D. Genkin, Y . Y arom, and M. Hamburg, “Meltdown: Reading kernel memory from user space,” in Proceedings of the 27th USENIX Security Symposium . USENIX Association, 2018, pp. 973– 990

  42. [49]

    Meltdownprim e and spec- treprime: Automatically-synthesized attacks exploiting invalidation- based coherence protocols,

    C. Trippel, D. Lustig, and M. Martonosi, “Meltdownprim e and spec- treprime: Automatically-synthesized attacks exploiting invalidation- based coherence protocols,” in ArXiv, vol. abs/1802.03802, 2018

  43. [50]

    Breaking virtual memory protection and the sgx ecosystem with foreshadow,

    J. V . Bulck, M. Minkin, O. Weisse, D. Genkin, B. Kasikci, F. Piessens, M. Silberstein, T. Wenisch, Y . Y arom, and R. Strackx, “Breaking virtual memory protection and the sgx ecosystem with foreshadow,” IEEE Micro, vol. 39, pp. 66–74, 2019

  44. [53]

    Electromagnet ic analysis: Concrete results,

    K. Gandolfi, C. Mourtel, and F. Olivier, “Electromagnet ic analysis: Concrete results,” in Proceedings of the 3rd International W orkshop on Cryptographic Hardware and Embedded Systems (CHES 2001) . Springer-V erlag, 2001, pp. 251–261

  45. [54]

    Mangard, E

    S. Mangard, E. Oswald, and T. Popp, Power Analysis Attacks: Reveal- ing the Secrets of Smart Cards . Springer-V erlag, 2008

  46. [55]

    Differential power ana lysis,

    P . Kocher, J. Jaffe, and B. Jun, “Differential power ana lysis,” in Proceedings of the 19th Annual International Cryptology Co nference on Advances in Cryptology (CRYPTO ’99) . Springer-V erlag, 1999, pp. 388–397

  47. [56]

    Investigati ons of power analysis attacks on smartcards,

    T. S. Messerges, E. Dabbish, and R. Sloan, “Investigati ons of power analysis attacks on smartcards,” in Proceedings of the USENIX W ork- shop on Smartcard Technology , 1999, pp. 151–161

  48. [57]

    Research on differentia l power analysis attack on rsa algorithm,

    Z. yuan Li, H. Gao, and K. Rong, “Research on differentia l power analysis attack on rsa algorithm,” in 2012 International Conference on Electronics, Information and Communication Engineering , 2012, pp. 1150–1153

  49. [58]

    Performance and power trade-offs for cryptographic applications in emb edded processors,

    C. Datsios, G. Keramidas, D. Serpanos, and P . Soufrilas , “Performance and power trade-offs for cryptographic applications in emb edded processors,” in IEEE International Symposium on Signal Processing and Information Technology , 2013, pp. 92–95

  50. [60]

    Towards an aes crypto-chip resistant to diffe rential power analysis,

    N. Pramstaller, F. Gurkaynak, S. Haene, H. Kaeslin, N. F elber, and W. Fichtner, “Towards an aes crypto-chip resistant to diffe rential power analysis,” in Proceedings of the 30th European Solid-State Circuits Conference, 2004, pp. 307–310

  51. [61]

    Implementation of aes algorithm resistant to differential power analysis,

    M. Strachacki and S. Szczepa´ nski, “Implementation of aes algorithm resistant to differential power analysis,” in 2008 15th IEEE Interna- tional Conference on Electronics, Circuits and Systems , 2008, pp. 214– 217

  52. [62]

    Power analysis attack against encryption devices: a c omprehen- sive analysis of aes, des, and bc3,

    S. D. Putra, M. Y udhiprawira, S. Sutikno, Y . Kurniawan, and A. S. Ah- mad, “Power analysis attack against encryption devices: a c omprehen- sive analysis of aes, des, and bc3,” TELKOMNIKA (Telecommunication Computing Electronics and Control) , no. 2, p. 64, 2019

  53. [63]

    Simulation of correlation power analysis aga inst aes cryp- tographic chip,

    R. Fang, “Simulation of correlation power analysis aga inst aes cryp- tographic chip,” Computer Engineering and Design , pp. 142 062– 142 072, 2010

  54. [64]

    Amplified template att ack of cryptographic algorithms,

    D. Shanbehzadeh and M. Bagheri, “Amplified template att ack of cryptographic algorithms,” in 2017 7th International Conference on Computer and Knowledge Engineering (ICCKE) . IEEE, 2017, pp. 142–147

  55. [65]

    Template attacks based on static powe r analysis of block ciphers in 45-nm cmos environment,

    J. Xu and H. Heys, “Template attacks based on static powe r analysis of block ciphers in 45-nm cmos environment,” in 2017 IEEE 60th International Midwest Symposium on Circuits and Systems (M WSCAS). IEEE, 2017, pp. 1256–1259

  56. [66]

    Template a ttacks with a power model,

    M. A. Elaabid, S. Guilley, and P . Hoogvorst, “Template a ttacks with a power model,” IACR Cryptol. ePrint Arch. , vol. 2007, p. 443, 2007

  57. [67]

    Low-cost attacks on tampe r resistant devices,

    R. J. Anderson and M. G. Kuhn, “Low-cost attacks on tampe r resistant devices,” in Security Protocols, 5th International W orkshop. Springer- V erlag, 1997, pp. 125–136

  58. [68]

    Fault injection atta cks on aes,

    M. Tunstall and S. Skorobogatov, “Fault injection atta cks on aes,” in Cryptographic Hardware and Embedded Systems – CHES 2007, 8t h International W orkshop. Springer-V erlag, 2007, pp. 112–124

  59. [69]

    Electromagnetic anal ysis (ema): Measures and counter-measures for smart cards,

    J.-J. Quisquater and D. Samyde, “Electromagnetic anal ysis (ema): Measures and counter-measures for smart cards,” in Proceedings of the International Conference on Research in Smart Cards: Sm art Card Programming and Security (E-SMART 2001) . Springer-V erlag, 2001, pp. 200–210

  60. [70]

    The em side-chann el(s): Attacks and assessment methodologies,

    D. Agrawal, J. R. Rao, and P . Rohatgi, “The em side-chann el(s): Attacks and assessment methodologies,” in Proceedings of the 4th International W orkshop on Cryptographic Hardware and Embe dded Systems (CHES 2002) . Springer-V erlag, 2002, pp. 29–45

  61. [71]

    Lest we remember: Cold boot attacks on encryption keys,

    J. A. Halderman, S. D. Schoen, N. Heninger, W. Clarkson, W. Paul, J. A. Calandrino, A. J. Feldman, J. Appelbaum, and E. W. Felte n, “Lest we remember: Cold boot attacks on encryption keys,” in Proceedings of the 2008 USENIX Security Symposium . USENIX Association, 2008, pp. 45–60

  62. [72]

    A comparison stud y of intel sgx and amd memory encryption technology,

    S. Mofrad, F. Zhang, S. Lu, and W. Shi, “A comparison stud y of intel sgx and amd memory encryption technology,” in Proceedings of the 7th International W orkshop on Hardware and Architectural S upport for Security and Privacy , 2018

  63. [73]

    Memory encryption for general-purpose pro cessors,

    S. Gueron, “Memory encryption for general-purpose pro cessors,” IEEE Security & Privacy , vol. 14, pp. 54–62, 2016

  64. [74]

    Distributed memory integrity t rees,

    O. Shwartz and Y . Birk, “Distributed memory integrity t rees,” IEEE Computer Architecture Letters , vol. 17, pp. 159–162, 2018

  65. [75]

    Tec-tree: A low-cost, parallelizable tree f or efficient defense against memory replay attacks,

    R. Elbaz, D. Champagne, R. Lee, L. Torres, G. Sassatelli , and P . Guillemin, “Tec-tree: A low-cost, parallelizable tree f or efficient defense against memory replay attacks,” in Lecture Notes in Computer Science, 2007, pp. 289–302

  66. [76]

    Protecting secrets of pers istent systems with volatility,

    V . Sartakov and R. Kapitza, “Protecting secrets of pers istent systems with volatility,” in 2019 15th European Dependable Computing Con- ference (EDCC) , 2019, pp. 89–96

  67. [77]

    Protocols for public key cryptosystems,

    R. C. Merkle, “Protocols for public key cryptosystems, ” in Proceedings of the IEEE Symposium on Security and Privacy . Springer, 1980, pp. 47–53

  68. [78]

    Key manageme nt for multicast: Issues and architectures,

    D. M. Wallner, E. J. Harder, and R. C. Agee, “Key manageme nt for multicast: Issues and architectures,” RFC 2627, June 1997

  69. [79]

    Towards sound appro aches to counteract power-analysis attacks,

    S. Chari, J. R. Rao, and P . Rohatgi, “Towards sound appro aches to counteract power-analysis attacks,” in Advances in Cryptology — CRYPTO ’99 . Springer, 1999, pp. 398–412

  70. [80]

    Power analysis attacks and counterme asures for cryptographic algorithms,

    T. S. Messerges, “Power analysis attacks and counterme asures for cryptographic algorithms,” in Proceedings of the 2nd International W orkshop on Cryptographic Hardware and Embedded Systems (C HES 2000). Springer-V erlag, 2002, pp. 13–15

  71. [81]

    Mangard, E

    S. Mangard, E. Oswald, and T. Popp, Power Analysis Attacks: Reveal- ing the Secrets of Smart Cards . Springer-V erlag, 2007

  72. [82]

    Dpa attacks and masking strategies,

    E. Prouff, “Dpa attacks and masking strategies,” in Proceedings of the 13th International W orkshop on Cryptographic Hardware and Embedded Systems (CHES 2011) . Springer-V erlag, 2011, pp. 142– 160

  73. [83]

    Efficient dpa-resist ant public key cryptography using multibit randomizing techniques,

    D. Kim, S.-M. Hong, and J.-H. Lee, “Efficient dpa-resist ant public key cryptography using multibit randomizing techniques,” in Proceedings of the 16th IEEE Symposium on High Performance Computer Arch i- tecture (HPCA 2010) . IEEE, 2010, pp. 285–294

  74. [84]

    A forward-secure pu blic-key encryption scheme,

    R. Canetti, S. Halevi, and J. Katz, “A forward-secure pu blic-key encryption scheme,” in Proceedings of the 2003 International Con- ference on the Theory and Applications of Cryptographic Tec hniques (EUROCRYPT 2003). Springer, 2003, pp. 255–271

  75. [85]

    Moving target defen se mech- anism for side-channel attacks,

    S. Vuppala, A. Mady, and A. Kuenzi, “Moving target defen se mech- anism for side-channel attacks,” IEEE Systems Journal , vol. 14, pp. 1810–1819, 2020

  76. [86]

    Identity-based encryption f rom the weil pairing,

    D. Boneh and M. Franklin, “Identity-based encryption f rom the weil pairing,” in Proceedings of the 23rd Annual International Cryptology Conference (CRYPTO 2001) . Springer-V erlag, 2001, pp. 213–229

  77. [87]

    Innovative instructio ns and software model for isolated execution,

    F. McKeen, I. Alexandrovich, A. Berenzon, C. V . Rozas, H . Shafi, V . Shanbhogue, and U. Savagaonkar, “Innovative instructio ns and software model for isolated execution,” in Proceedings of the 2nd International W orkshop on Hardware and Architectural Supp ort for Security and...

  78. [88]

    Trustzone: Integrated hardware and softwa re security,

    P . Kinney, “Trustzone: Integrated hardware and softwa re security,” in ARM Technical White Paper , 2004

  79. [89]

    Intel sgx explained,

    V . Costan and S. Devadas, “Intel sgx explained,” in Cryptology ePrint Archive, Report 2016/086 , 2016, pp. 1–118

  80. [90]

    Scone : Secure computing on nodes with intel sgx,

    S. Arnautov, B. Trach, F. Gregor, T. Knauth, A. Martin, C . Priebe, J. Lind, D. Muthukumaran, D. O’Keeffe, M. L. Stillwell, D. Go ltzsche, D. M. Eyers, R. Kapitza, P . R. Pietzuch, and C. Fetzer, “Scone : Secure computing on nodes with intel sgx,” in Proceedings of the 12th US...

  81. [91]

    Secure serverless computing using dynamic trusted execution environments,

    S. Christensen and K. V an der Merwe, “Secure serverless computing using dynamic trusted execution environments,” Proceedings of the 14th USENIX Symposium on Networked Systems Design and Imple - mentation (NSDI 2017) , pp. 583–599, 2017

  82. [92]

    I nnovative technology for cpu based attestation and sealing,

    I. Anati, S. Gueron, S. P . Johnson, and V . R. Scarlata, “I nnovative technology for cpu based attestation and sealing,” in Proceedings of the 2nd International W orkshop on Hardware and Architectural S upport for Security and Privacy (HASP 2013) . ACM, 2013, pp. 10:1–10:8

  83. [93]

    Vc3: Trustworthy data analytics in the cloud using sgx,

    F. Schuster, M. Costa, C. Fournet, C. Gkantsidis, M. Pei nado, G. Mainar-Ruiz, and M. Russinovich, “Vc3: Trustworthy data analytics in the cloud using sgx,” in Proceedings of the 2015 IEEE Symposium on Security and Privacy (S&P 2015) . IEEE, 2015, pp. 38–54

  84. [94]

    T-sgx: Eradicat ing controlled-channel attacks against enclave programs,

    M. Shih, S. Lee, T. Kim, and M. Peinado, “T-sgx: Eradicat ing controlled-channel attacks against enclave programs,” 20 17, pp. 15– 18

  85. [95]

    Hyperwall: Protecting sy stem se- curity from untrusted hypervisors,

    A. Azab, P . Ning, and A. Shah, “Hyperwall: Protecting sy stem se- curity from untrusted hypervisors,” in Proceedings of the 19th ACM International Conference on Architectural Support for Pro gramming Languages and Operating Systems (ASPLOS 2014) . ACM, 2014, pp. 1–14

  86. [96]

    Intel advanced encryption standard (aes) i nstructions set,

    S. Gueron, “Intel advanced encryption standard (aes) i nstructions set,” Journal of Cryptographic Engineering , pp. 2–3, 2010

  87. [97]

    Efficient cryptography on the risc-v arc hitecture,

    K. Stoffelen, “Efficient cryptography on the risc-v arc hitecture,” pp. 323–340, 2019

  88. [98]

    The design of scalar aes instruction set extensions for ris c-v,

    B. Marshall, G. R. Newell, D. Page, M.-J. O. Saarinen, an d C. Wolf, “The design of scalar aes instruction set extensions for ris c-v,” IACR Trans. Cryptogr . Hardw. Embed. Syst., pp. 109–136, 2020

  89. [99]

    Power analysis resista nt aes implemen- tation with instruction set extensions,

    S. Tillich and J. Großsch¨ adl, “Power analysis resista nt aes implemen- tation with instruction set extensions,” pp. 303–319, 2007

  90. [100]

    Introduction to the arm cryptographic exte nsion,

    C. Baker, “Introduction to the arm cryptographic exte nsion,” in Pro- ceedings of the 2013 ACM Conference on Embedded Computing Systems, 2013, pp. 71–78

  91. [101]

    Efficient software implementations of aes on int el’s aes-ni,

    X. Guo, R. Ramaswamy, M. Duraiswamy, T. Ristenpart, an d M. T. Goodrich, “Efficient software implementations of aes on int el’s aes-ni,” in Proceedings of the 2010 International Conference on Inform ation and Communications Security (ICICS 2010) . Springer, 2010, pp. 69– 83

  92. [102]

    Cryptographic ex tensions in the risc-v architecture: Flexibility and efficiency,

    Z. Shaolin, H. Guo, X. Liu, and M. Xu, “Cryptographic ex tensions in the risc-v architecture: Flexibility and efficiency,” Journal of Crypto- graphic Engineering , pp. 78–90, 2020

  93. [103]

    Optimizing cryptographic operations us ing asimd on armv8 devices,

    M. Albahar, “Optimizing cryptographic operations us ing asimd on armv8 devices,” in Proceedings of the 2016 IEEE International Sym- posium on High-Performance Computer Architecture (HPCA) . IEEE, 2016, pp. 188–195

  94. [104]

    A reconfigurable ieee 1363-based dom ain specific cryptographic processor for secure applications,

    C.-C. Chang, Y .-L. Huang, Y .-C. Hung, C.-W. Wu, W.-S. Y eh, L.- W. Lin, and Y .-C. Chen, “A reconfigurable ieee 1363-based dom ain specific cryptographic processor for secure applications, ” IEEE Trans- actions on Circuits and Systems I: Regular Papers , pp. 2334–2345, 2007

  95. [105]

    Elliptic curve cr yptography over binary finite fields on arm isa: Word-level multiplication in structions for efficient ecc operations,

    O. Gallais, R. Ribot, and M. Fugere, “Elliptic curve cr yptography over binary finite fields on arm isa: Word-level multiplication in structions for efficient ecc operations,” IEEE Transactions on Computers , pp. 1125–1136, 2008

  96. [106]

    Galois field isa extensions for efficient c ryptographic and error-correction processing on risc-v,

    H. Kaeslin, “Galois field isa extensions for efficient c ryptographic and error-correction processing on risc-v,” IEEE Transactions on Comput- ers, pp. 2350–2361, 2019

  97. [107]

    Lightweight cryptography on risc-v: Optimizing gift cipher using bitslicing and fixsl icing,

    G. Bansod, S. Limaye, and A. Srivastava, “Lightweight cryptography on risc-v: Optimizing gift cipher using bitslicing and fixsl icing,” in Proceedings of the 2017 IEEE International Symposium on Cir cuits and Systems (ISCAS) . IEEE, 2017, pp. 1–4

  98. [108]

    Algorithm-agile cry ptographic coprocessor on fpga with dynamic reconfigurability,

    H. Li, Y . Xu, X. Y ang, and T. Wang, “Algorithm-agile cry ptographic coprocessor on fpga with dynamic reconfigurability,” in Proceedings of the 2018 IEEE Symposium on Field-Programmable Custom Compu ting Machines (FCCM) . IEEE, 2018, pp. 112–119

  99. [109]

    Attacking intel bios,

    R. Wojtczuk and J. Rutkowska, “Attacking intel bios,” in Proceedings of the Black Hat DC 2011 , 2011

  100. [110]

    Intel® uefi secure boot implementati on,

    I. Corporation, “Intel® uefi secure boot implementati on,” 2013

  101. [111]

    Android security: The role of the locked bootloader,

    S. Markon and A. Tso, “Android security: The role of the locked bootloader,” in Proceedings of the 2014 Black Hat USA , 2014

  102. [112]

    Grawrock, The Intel Safer Computing Initiative

    D. Grawrock, The Intel Safer Computing Initiative . Intel Press, 2006

  103. [113]

    The trusted platform module and h ow it enables security in computing systems,

    R. Joseph and Y . Liu, “The trusted platform module and h ow it enables security in computing systems,” IEEE Security & Privacy , vol. 15, no. 3, pp. 24–31, 2017

  104. [114]

    Using tpm to improve boot securi ty at bios layer,

    K. Lin and C.-Y . Wang, “Using tpm to improve boot securi ty at bios layer,” in 2012 IEEE International Conference on Consumer Electronics (ICCE) , 2012, pp. 376–377

  105. [115]

    Amd memory encryp tion,

    D. Kaplan, J. Powell, and T. Woller, “Amd memory encryp tion,” in Advanced Micro Devices White Paper , 2016

  106. [116]

    Providing root of trust for arm trustzone using on-chip sram,

    S. Zhao, Q. Zhang, G. Hu, Y . Qin, and D. Feng, “Providing root of trust for arm trustzone using on-chip sram,” 2014, pp. 25–36

  107. [117]

    Intel sgx explained,

    C. Costan and S. Devadas, “Intel sgx explained,” IACR Cryptology ePrint Archive , vol. 2016, p. 86, 2016. [Online]. Available: https://eprint.iacr.org/2016/086

  108. [118]

    Sil icon physical random functions,

    B. Gassend, D. Clarke, M. van Dijk, and S. Devadas, “Sil icon physical random functions,” in Proceedings of the 9th ACM Conference on Computer and Communications Security (CCS) , 2002, pp. 148–160

  109. [119]

    Countering the effects of silicon aging on sram pufs,

    R. Maes and V . van der Leest, “Countering the effects of silicon aging on sram pufs,” in Proceedings of the 5th W orkshop on Cryptographic Hardware and Embedded Systems (CHES) , 2010, pp. 407–422

  110. [120]

    F pga intrinsic pufs and their use for ip protection,

    J. Guajardo, S. Kumar, G.-J. Schrijen, and P . Tuyls, “F pga intrinsic pufs and their use for ip protection,” in Proceedings of the 9th International W orkshop on Cryptographic Hardware and Embe dded Systems (CHES) , 2007, pp. 63–80

  111. [121]

    Physi cal unclonable functions and applications: A tutorial,

    C. Herder, L. Y u, F. Koushanfar, and S. Devadas, “Physi cal unclonable functions and applications: A tutorial,” Proceedings of the IEEE , vol. 102, no. 8, pp. 1126–1141, 2014

  112. [122]

    Maes, Physically Unclonable Functions: Constructions, Propert ies and Applications

    R. Maes, Physically Unclonable Functions: Constructions, Propert ies and Applications . Springer, 2013

  113. [123]

    Phy sical one-way functions,

    R. Pappu, B. Recht, J. Taylor, and N. Gershenfeld, “Phy sical one-way functions,” Science, vol. 297, no. 5589, pp. 2026–2030, 2002

  114. [124]

    Machine-learning attacks on polypuf, ob -puf, rpuf, and puf–fsm,

    J. Delvaux, “Machine-learning attacks on polypuf, ob -puf, rpuf, and puf–fsm,” IEEE Transactions on Information F orensics and Security , vol. 13, no. 10, pp. 2574–2589, 2018

  115. [125]

    M. M. Tehranipoor, C. Wang, and M. Gorman, Introduction to Hard- ware Security and Trust . Springer, 2014

  116. [126]

    De - sign and implementation of puf-based

    S. Devadas, D. Lim, R. Sowell, M. van Dijk, and C. Gu, “De - sign and implementation of puf-based ”unclonable” rfid ics f or anti- counterfeiting and security applications,” in 2008 IEEE International Conference on RFID , 2008, pp. 58–64

  117. [127]

    V oltage glitching for ic fault inje ction and analysis,

    S. Skorobogatov, “V oltage glitching for ic fault inje ction and analysis,” in Proceedings of the IEEE International Symposium on Hardwar e- Oriented Security and Trust (HOST) , 2012, pp. 101–106

  118. [128]

    A clock glitch-based fault injection technique,

    I. Karaklaji´ c and et al., “A clock glitch-based fault injection technique,” in Proceedings of the ACM Conference on Computer and Communi- cations Security (CCS) , 2013, pp. 543–555

  119. [129]

    Electromagnetic fault inject ion: A review of the art,

    H. Schroder and et al., “Electromagnetic fault inject ion: A review of the art,” IEEE Transactions on Electromagnetic Compatibility , vol. 57, no. 3, pp. 447–462, 2015

  120. [130]

    Optical fault induc tion attacks,

    S. Skorobogatov and R. Anderson, “Optical fault induc tion attacks,” in Proceedings of the IEEE International Symposium on Hardwar e- Oriented Security and Trust (HOST) , 2010, pp. 13–19

  121. [131]

    Soft errors in advanced computer syste ms,

    R. C. Baumann, “Soft errors in advanced computer syste ms,” IEEE Design & Test of Computers , vol. 22, no. 3, pp. 258–266, 2005

  122. [132]

    Single event effects and multipl e bit upsets in electronic memories,

    J.-Y . Liu and et al., “Single event effects and multipl e bit upsets in electronic memories,” in Proceedings of the IEEE International Reliability Physics Symposium (IRPS) , 2004, pp. 53–58

  123. [133]

    Modeling the effect of trans ient faults on microprocessor performance,

    P . Shivakumar and et al., “Modeling the effect of trans ient faults on microprocessor performance,” in Proceedings of the International Conference on Dependable Systems and Networks (DSN) , 2002, pp. 37–46

  124. [134]

    Low-power digital design: Li mits and oppor- tunities for pushing the limits of cmos technology,

    B. H. Calhoun and et al., “Low-power digital design: Li mits and oppor- tunities for pushing the limits of cmos technology,” IEEE Transactions on Device and Materials Reliability , vol. 6, no. 3, pp. 321–335, 2008

  125. [135]

    Spectre a t- tacks: Exploiting speculative execution,

    P . Kocher, D. Genkin, D. Gruss, W. Haas, M. Hamburg, M. L ipp, S. Mangard, T. Prescher, M. Schwarz, and Y . Y arom, “Spectre a t- tacks: Exploiting speculative execution,” Communications of the ACM , vol. 62, no. 7, pp. 93–101, 2019

  126. [136]

    Retpoline: A software construct for preve nting branch- target-injection,

    J. Turner, “Retpoline: A software construct for preve nting branch- target-injection,” Google White Paper , pp. 1–2, 2018

  127. [137]

    Spectre mitigation update,

    I. Corporation, “Spectre mitigation update,” in Intel White Paper, 2018

  128. [138]

    Speculative buff er overflows: Attacks and defenses,

    V . Kiriansky and C. A. Waldspurger, “Speculative buff er overflows: Attacks and defenses,” ArXiv, vol. abs/1807.03757, 2018

  129. [139]

    Spectre returns! speculation attacks using the return stack buffer ,

    E. Koruyeh, K. Khasawneh, C. Song, and N. Abu-Ghazaleh , “Spectre returns! speculation attacks using the return stack buffer ,” in Proceed- ings of the 12th USENIX W orkshop on Offensive Technologies (WOOT), 2018, pp. 1–10

  130. [140]

    Intel: Return stack buffer (rsb) und erflow advisory,

    I. Corporation, “Intel: Return stack buffer (rsb) und erflow advisory,” https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/adviso ry-guidance/return-stack-buffer-underflow.html, 2019, accessed: 2024-09-10

  131. [141]

    A systematic evaluation of transient execution attacks and defenses,

    M. S. M. L. B. v. B. P . O. F. P . D. E. D. G. Claudio Canella, J o V an Bulck, “A systematic evaluation of transient execution attacks and defenses,” in Proceedings of the 28th USENIX Security Symposium , 2019, pp. 249–266

  132. [142]

    Intel analysis of speculative execu tion,

    I. Corporation, “Intel analysis of speculative execu tion,” 2019

  133. [143]

    Leaking secrets through modern branch predictors in the speculative world,

    M. H. I. Chowdhury and F. Y ao, “Leaking secrets through modern branch predictors in the speculative world,” IEEE Transactions on Computers, vol. 71, pp. 2059–2072, 2021

  134. [144]

    Intel enhancements to branch predic tion algorithms,

    I. Corporation, “Intel enhancements to branch predic tion algorithms,” 2019

  135. [145]

    Nda: Preventing s peculative execution attacks at their source,

    K. L. T. W. B. K. Ofir Weisse, Ian Neal, “Nda: Preventing s peculative execution attacks at their source,” in Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture , 2019, pp. 1–10

  136. [146]

    Bra nchscope: A new side-channel attack on directional branch predictor,

    N. B. A.-G. D. P . Dmitry Evtyushkin, Ryan D. Riley, “Bra nchscope: A new side-channel attack on directional branch predictor,” in Proceed- ings of the 23rd International Conference on Architectural Support for Programming Languages and Operating Systems , 2018, pp. 693–707

  137. [147]

    Micro- scope: Enabling microarchitectural replay attacks,

    B. G. R. S.-J. T. C. W. F. Dimitrios Skarlatos, Mengjia Y an, “Micro- scope: Enabling microarchitectural replay attacks,” vol. 40, 2020, pp. 91–98

  138. [148]

    Delay-on- squash: Stopping microarchitectural replay attacks in their tracks,

    M. S. Christos Sakalis, Stefanos Kaxiras, “Delay-on- squash: Stopping microarchitectural replay attacks in their tracks,” ACM Transactions on Architecture and Code Optimization , vol. 20, pp. 1–24, 2022

  139. [149]

    Smotherspectre: Exploiting speculative execution throu gh port con- tention,

    M. N. A. S.-B. F. M. P . A. K. Atri Bhattacharyya, A. Sandu lescu, “Smotherspectre: Exploiting speculative execution throu gh port con- tention,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , 2019, pp. 1–14

  140. [150]

    Lvi: Hijacking transient execution throu gh microar- chitectural load value injection,

    M. S. M. L. M. M. D. G. Y . Y . B. S. D. G. F. P . Jo V an Bulck, Daniel Moghimi, “Lvi: Hijacking transient execution throu gh microar- chitectural load value injection,” IEEE Symposium on Security and Privacy (SP) , pp. 54–72, 2020

  141. [151]

    Fallout: Lea king data on meltdown-resistant cpus,

    M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, S. M angard, P . Kocher, D. Genkin, Y . Y arom, and M. Hamburg, “Fallout: Lea king data on meltdown-resistant cpus,” Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , pp. 769–784, 2019

  142. [152]

    Cacheout: Leaking data on intel cpus via cache evictions,

    S. V . Schaik, M. Minkin, A. Kwong, D. Genkin, and Y . Y aro m, “Cacheout: Leaking data on intel cpus via cache evictions,” 2021 IEEE Symposium on Security and Privacy (SP) , pp. 339–354, 2020

  143. [153]

    Noise-free se curity assessment of eviction set construction algorithms with ra ndomized caches,

    G. D. N. Amine Jaamoum, Thomas Hiscock, “Noise-free se curity assessment of eviction set construction algorithms with ra ndomized caches,” 2022

  144. [154]

    Zombiel oad: Cross- privilege-boundary data sampling,

    M. Schwarz, M. Lipp, D. Gruss, and S. Mangard, “Zombiel oad: Cross- privilege-boundary data sampling,” Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , pp. 753–768, 2019

  145. [155]

    Ridl: Rogue in-flight da ta load,

    S. V an Schaik, A. Milburn, D. Evtyushkin, F. Schuster, L. Austgen, H. Bos, C. Giuffrida, and K. Razavi, “Ridl: Rogue in-flight da ta load,” IEEE Symposium on Security and Privacy (SP) , pp. 88–105, 2019

  146. [156]

    Netspec tre: Read arbitrary memory over network,

    M. Schwarz, M. Lipp, D. Gruss, and S. Mangard, “Netspec tre: Read arbitrary memory over network,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , 2018, pp. 1053–1066

  147. [157]

    Branchspec : In- formation leakage attacks exploiting speculative branch i nstruction executions,

    F. Y . Md Hafizul Islam Chowdhury, Hang Liu, “Branchspec : In- formation leakage attacks exploiting speculative branch i nstruction executions,” in 2020 IEEE 38th International Conference on Computer Design (ICCD) , 2020, pp. 529–536

  148. [158]

    Y ou cannot always win the race: Analyzing mitigations for branch target prediction attack s,

    H. K. Alyssa Milburn, Ke Sun, “Y ou cannot always win the race: Analyzing mitigations for branch target prediction attack s,” in 2023 IEEE 8th European Symposium on Security and Privacy (EuroS& P), 2023, pp. 671–686

  149. [159]

    Meltdown: Reading kernel memory from user space,

    M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, S. M angard, P . Kocher, D. Genkin, Y . Y arom, and M. Hamburg, “Meltdown: Reading kernel memory from user space,” in Proceedings of the 27th USENIX Security Symposium , 2018, pp. 973–990

  150. [160]

    Kpti: A novel app roach to mitigating meltdown,

    M. S. S. M. Daniel Gruss, Moritz Lipp, “Kpti: A novel app roach to mitigating meltdown,” IEEE Security & Privacy , vol. 16, no. 3, pp. 70–77, 2018

  151. [161]

    Meltdow n-rw: Exploiting speculative write loads for data leakage,

    C. Canella, M. Schwarz, M. Lipp, and D. Gruss, “Meltdow n-rw: Exploiting speculative write loads for data leakage,” in Proceedings of the 28th USENIX Security Symposium (USENIX Security 19) , 2019, pp. 1237–1251

  152. [162]

    Meltdown-br: Explo iting bounds check bypass for data leakage,

    B. K. Ofir Weisse, Kevin Loughlin, “Meltdown-br: Explo iting bounds check bypass for data leakage,” in Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture , 2019, pp. 123–135

  153. [163]

    Meltdown-pk: By passing memory protection keys with speculative execution,

    C. Canella, M. Schwarz, and D. Gruss, “Meltdown-pk: By passing memory protection keys with speculative execution,” in Proceedings of the 28th USENIX Security Symposium (USENIX Security 19) , 2019, pp. 1261–1272

  154. [164]

    Y ou cannot always win the race: Analyzing the lfence/jmp mitigation for branch targe t injection,

    A. Milburn, K. Sun, and H. Kawakami, “Y ou cannot always win the race: Analyzing the lfence/jmp mitigation for branch targe t injection,” in ArXiv, 2022

  155. [165]

    Restrictin g control flow during speculative execution,

    Z. Shen, J. Zhou, D. Ojha, and J. Criswell, “Restrictin g control flow during speculative execution,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , 2018

  156. [166]

    Spectre a ttacks: Exploiting speculative execution,

    P . Kocher, D. Genkin, D. Gruss, W. Haas, M. Hamburg, M. L ipp, S. Mangard, T. Prescher, M. Schwarz, and Y . Y arom, “Spectre a ttacks: Exploiting speculative execution,” in 2019 IEEE Symposium on Secu- rity and Privacy (SP) , 2018, pp. 1–19

  157. [167]

    Nda: Preventing speculative execution attacks at their source,

    O. Weisse, I. Neal, K. Loughlin, T. Wenisch, and B. Kasi kci, “Nda: Preventing speculative execution attacks at their source, ” in Proceed- ings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture, 2019

  158. [168]

    Speculative taint tracking (stt): A comprehens ive protection for speculatively accessed data,

    J. Y u, M. Y an, A. Khyzha, A. Morrison, J. Torrellas, and C. W. Fletcher, “Speculative taint tracking (stt): A comprehens ive protection for speculatively accessed data,” IEEE Micro, vol. 40, pp. 81–90, 2019

  159. [169]

    Condition al speculation: An effective approach to safeguard out-of-or der execution against spectre attacks,

    P . Li, L. Zhao, R. Hou, L. Zhang, and D. Meng, “Condition al speculation: An effective approach to safeguard out-of-or der execution against spectre attacks,” in 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA) , 2019, pp. 264–276

  160. [170]

    Context-sensiti ve fencing: Se- curing speculative execution via microcode customization ,

    M. Taram, A. V enkat, and D. Tullsen, “Context-sensiti ve fencing: Se- curing speculative execution via microcode customization ,” in Proceed- ings of the Twenty-F ourth International Conference on Arch itectural Support for Programming Languages and Operating Systems , 2019

  161. [171]

    Retpoline technique for mitiga ting spectre attack,

    M. F. A. Kadir, J. Wong, F. A. Wahab, A. F. A. A. Bharun, M. A. Mohamed, and A. H. Zakaria, “Retpoline technique for mitiga ting spectre attack,” in 2019 6th International Conference on Electrical and Electronics Engineering (ICEEE) , 2019, pp. 96–101

  162. [172]

    Microcfi: Microarchitecture-lev el control-flow restrictions for spectre mitigation,

    H. Jang and Y . Shin, “Microcfi: Microarchitecture-lev el control-flow restrictions for spectre mitigation,” IEEE Access, vol. 11, pp. 138 699– 138 711, 2023

  163. [173]

    Lightweight and secure branch predictors against spectre attacks,

    C. Chen, C. Shen, and J. Zhang, “Lightweight and secure branch predictors against spectre attacks,” in 2022 27th Asia and South Pacific Design Automation Conference (ASP-DAC) , 2022, pp. 25–30

  164. [174]

    Speculative data-oblivious execution: Mobilizing safe p rediction for safe and efficient speculative execution,

    J. Y u, N. Mantri, J. Torrellas, A. Morrison, and C. W. Fl etcher, “Speculative data-oblivious execution: Mobilizing safe p rediction for safe and efficient speculative execution,” in 2020 ACM/IEEE 47th Annual International Symposium on Computer Architecture ( ISCA), 2020, pp. 707–720

  165. [175]

    Invisispec: Making speculative execution i nvisible in the cache hierarchy,

    M. Y an, J. Choi, D. Skarlatos, A. Morrison, C. W. Fletch er, and J. Torrellas, “Invisispec: Making speculative execution i nvisible in the cache hierarchy,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO) , 2018, pp. 428–441

  166. [176]

    Dawg: A defense against cache timing attacks in spe culative execution processors,

    V . Kiriansky, I. A. Lebedev, S. P . Amarasinghe, S. Deva das, and J. Emer, “Dawg: A defense against cache timing attacks in spe culative execution processors,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO) , 2018, pp. 974–987

  167. [177]

    Cyclone: Detecting contention-based cache information l eaks through cyclic interference,

    A. Harris, S. Wei, P . Sahu, P . Kumar, T. Austin, and M. Ti wari, “Cyclone: Detecting contention-based cache information l eaks through cyclic interference,” in Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture , 2019

  168. [178]

    New attacks and defense for encrypted- address cache,

    M. K. Qureshi, “New attacks and defense for encrypted- address cache,” in 2019 ACM/IEEE 46th Annual International Symposium on Compu ter Architecture (ISCA), 2019, pp. 360–371

  169. [179]

    Guard cach e: Creating noisy side-channels,

    F. Mosquera, K. Kavi, G. Mehta, and L. John, “Guard cach e: Creating noisy side-channels,” IEEE Computer Architecture Letters , vol. 22, pp. 97–100, 2023

  170. [180]

    Protecting cache states against bo th spec- ulative execution attacks and side-channel attacks,

    G. Hu and R. B. Lee, “Protecting cache states against bo th spec- ulative execution attacks and side-channel attacks,” ArXiv, vol. abs/2302.00732, 2023

  171. [181]

    Random and safe cache architecture to defeat cach e timing attacks,

    ——, “Random and safe cache architecture to defeat cach e timing attacks,” ArXiv, vol. abs/2309.16172, 2023

  172. [182]

    Revice: Reusing victim cache to prevent speculative cache leakage,

    S. Kim, F. Mahmud, J. Huang, P . Majumder, N. Christou, A . Muza- hid, C. che Tsai, and E. J. Kim, “Revice: Reusing victim cache to prevent speculative cache leakage,” in 2020 IEEE Secure Development (SecDev), 2020, pp. 96–107

  173. [183]

    Ceaser: Mitigating conflict-based cac he attacks via encrypted-address and remapping,

    M. K. Qureshi, “Ceaser: Mitigating conflict-based cac he attacks via encrypted-address and remapping,” in 2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO) , 2018, pp. 775–787

  174. [184]

    Random ized last-level caches are still vulnerable to cache side-chann el attacks! but we can fix it,

    W. Song, B. Li, Z. Xue, Z. Li, W. Wang, and P . Liu, “Random ized last-level caches are still vulnerable to cache side-chann el attacks! but we can fix it,” in 2021 IEEE Symposium on Security and Privacy (SP) , 2021, pp. 955–969

  175. [185]

    New a ttacks and defenses for randomized caches,

    K. Ramkrishnan, A. Zhai, S. McCamant, and P . Y ew, “New a ttacks and defenses for randomized caches,” ArXiv, vol. abs/1909.12302, 2019

  176. [186]

    Theory and practice of finding eviction sets,

    P . Vila, B. K¨ opf, and J. Morales, “Theory and practice of finding eviction sets,” in 2019 IEEE Symposium on Security and Privacy (SP) , 2018, pp. 39–54

  177. [187]

    Comprehensive evaluation of rsb and spectre vulnerabilit y on modern processors,

    F. Taheri, S. B. Sarmadi, A. Sadeghpour, and S. P . T. Mor sal, “Comprehensive evaluation of rsb and spectre vulnerabilit y on modern processors,” ArXiv, vol. abs/2302.09544, 2023

  178. [188]

    ret2spec: Speculative e xecution using return stack buffers,

    G. Maisuradze and C. Rossow, “ret2spec: Speculative e xecution using return stack buffers,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , 2018

  179. [189]

    Restrictin g con- trol flow during speculative execution with venkman,

    Z. Shen, J. Zhou, D. Ojha, and J. Criswell, “Restrictin g con- trol flow during speculative execution with venkman,” ArXiv, vol. abs/1903.10651, 2019

  180. [190]

    Ridl: Rogue in-flight da ta load,

    S. V . Schaik, A. Milburn, S. ¨Osterlund, P . Frigo, G. Maisuradze, K. Razavi, H. Bos, and C. Giuffrida, “Ridl: Rogue in-flight da ta load,” 2019 IEEE Symposium on Security and Privacy (SP) , pp. 88–105, 2019

  181. [191]

    Lvi: Hijacking transient execution through microarchitectural load value injectio n,

    J. V . Bulck, D. Moghimi, M. Schwarz, M. Lipp, M. Minkin, D. Genkin, Y . Y arom, B. Sunar, D. Gruss, and F. Piessens, “Lvi: Hijacking transient execution through microarchitectural load value injectio n,” in 2020 IEEE Symposium on Security and Privacy (SP) , 2020, pp. 54–72

  182. [192]

    Breaking and fixing speculative load hardening,

    Z. Zhang, G. Barthe, C. Chuengsatiansup, P . Schwabe, a nd Y . Y arom, “Breaking and fixing speculative load hardening,” IACR Cryptol. ePrint Arch., vol. 2022, p. 715, 2022

  183. [193]

    By- passing data execution prevention on microsoft windows xp s p2,

    N. Stojanovski, M. Gusev, D. Gligoroski, and S. J. Knap skog, “By- passing data execution prevention on microsoft windows xp s p2,” in The Second International Conference on Availability, Reli ability and Security (ARES’07) , 2007, pp. 1222–1226

  184. [194]

    Sok: Hardware defenses agai nst speculative execution attacks,

    G. Hu, Z. He, and R. B. Lee, “Sok: Hardware defenses agai nst speculative execution attacks,” in 2021 International Symposium on Secure and Private Execution Environment Design (SEED) , 2021, pp. 108–120

  185. [195]

    Codarr: Continuous data space randomization against data -only at- tacks,

    P . Rajasekaran, S. Crane, D. Gens, Y . Na, S. V olckaert, and M. Franz, “Codarr: Continuous data space randomization against data -only at- tacks,” in Proceedings of the 15th ACM Asia Conference on Computer and Communications Security , 2020

  186. [196]

    Entrybleed: A uni versal kaslr bypass against kpti on linux,

    W. Liu, J. Ravichandran, and M. Y an, “Entrybleed: A uni versal kaslr bypass against kpti on linux,” in Proceedings of the 12th International W orkshop on Hardware and Architectural Support for Securit y and Privacy, 2023

  187. [197]

    Defeating specu lative- execution attacks on sgx with hyperrace,

    G. Chen, M. Li, F. Zhang, and Y . Zhang, “Defeating specu lative- execution attacks on sgx with hyperrace,” in 2019 IEEE Conference on Dependable and Secure Computing (DSC) , 2019, pp. 1–8

  188. [198]

    Performance statistics and lea rning-based detection of exploitative speculative attacks,

    S. Dutta and S. Sinha, “Performance statistics and lea rning-based detection of exploitative speculative attacks,” in Proceedings of the 16th ACM International Conference on Computing Frontiers , 2019

  189. [199]

    Speculative taint tracking (stt),

    J. Y u, M. Y an, A. Khyzha, A. Morrison, J. Torrellas, and C. W. Fletcher, “Speculative taint tracking (stt),” Communications of the ACM , vol. 64, pp. 105–112, 2019

  190. [200]

    Specul arizer: Detecting speculative execution attacks via performance t racing,

    W. Wang, G. Chen, Y . Cheng, Y . Zhang, and Z. Lin, “Specul arizer: Detecting speculative execution attacks via performance t racing,” in 2021 IEEE Symposium on Security and Privacy , 2021, pp. 151–172

  191. [201]

    Laser: A d eep learning approach for speculative execution and replicati on of deadline- critical jobs in cloud,

    M. Xu, S. Alamro, T. Lan, and S. Subramaniam, “Laser: A d eep learning approach for speculative execution and replicati on of deadline- critical jobs in cloud,” in 2017 26th International Conference on Computer Communication and Networks (ICCCN) , 2017, pp. 1–8

  192. [202]

    Methodology for simulated p ower analysis attacks on aes,

    K. Smith and M. Lukowiak, “Methodology for simulated p ower analysis attacks on aes,” in 2010 - MILCOM 2010 MILITARY COM- MUNICATIONS CONFERENCE , 2010, pp. 1292–1297

  193. [203]

    Gpu accelerated different ial power analysis,

    H. J. Patel and R. Baldwin, “Gpu accelerated different ial power analysis,” in MILCOM 2012 - 2012 IEEE Military Communications Conference, 2012, pp. 1–5

  194. [204]

    Anatomy of differential power analysis for aes,

    J. A. Ambrose, N. Aldon, A. Ignjatovi´ c, and S. Parames waran, “Anatomy of differential power analysis for aes,” in 2008 10th Interna- tional Symposium on Symbolic and Numeric Algorithms for Sci entific Computing, 2008, pp. 459–466

  195. [205]

    Power anal- ysis attacks against fpga implementations of the des,

    F.-X. Standaert, S. Y alcin, J. Quisquater, and B. Pren eel, “Power anal- ysis attacks against fpga implementations of the des,” in Proceedings of CHES 2004 , 2004, pp. 84–94

  196. [206]

    Performance enhancement of differential power analysis attacks with signal compand ing methods,

    J. Ryoo, D.-G. Han, S.-K. Kim, and S. Lee, “Performance enhancement of differential power analysis attacks with signal compand ing methods,” IEEE Signal Processing Letters , vol. 15, pp. 625–628, 2008

  197. [207]

    Research on differenti al power analysis attack on rsa algorithm,

    K. R. Zhi-yuan Li, Haikuo Gao, “Research on differenti al power analysis attack on rsa algorithm,” pp. 1150–1153, 2012

  198. [208]

    Differential power analysis and counter measure for rsa,

    S. Hai-tao, “Differential power analysis and counter measure for rsa,” Journal of Jilin University , 2009

  199. [209]

    Differential power analysi s resistant hardware implementation of the rsa cryptosystem,

    K. A. Bayam and S. Y alcin, “Differential power analysi s resistant hardware implementation of the rsa cryptosystem,” 2008, pp . 3314– 3317

  200. [210]

    Practical secon d-order correlation power analysis on the message blinding method a nd its novel countermeasure for rsa,

    H. Kim, T. H. Kim, J. Y oon, and S. Hong, “Practical secon d-order correlation power analysis on the message blinding method a nd its novel countermeasure for rsa,” ETRI Journal, 2010

  201. [211]

    Differential power analysis (dpa) attack on dual field ecc processor for cryptographic applications,

    S. Suresh, “Differential power analysis (dpa) attack on dual field ecc processor for cryptographic applications,” 2014, pp. 1–5

  202. [212]

    A robust algorithm for dpa -resistant ecc,

    Y . E. Wang and L. M. Douglas, “A robust algorithm for dpa -resistant ecc,” in Proceedings of the 2009 12th International Symposium on Integrated Circuits, 2009, pp. 667–670

  203. [213]

    Power analysis attacks and countermeasure s for ecc,

    G. Liang, “Power analysis attacks and countermeasure s for ecc,” Computer Knowledge and Technology , 2007

  204. [214]

    Side channel analysis of s ome hash based macs: A response to sha-3 requirements,

    P . Gauravaram and K. Okeya, “Side channel analysis of s ome hash based macs: A response to sha-3 requirements,” 2008

  205. [215]

    Differenti al fault analysis of sha-3,

    N. Bagheri, N. Ghaedi, and S. K. Sanadhya, “Differenti al fault analysis of sha-3,” 2015

  206. [216]

    Two step power attack on sha -3 based mac,

    C.-Y . Chu and M. Lukowiak, “Two step power attack on sha -3 based mac,” in 2018 25th International Conference on Mixed Design of Integrated Circuits and Systems (MIXDES) , 2018, pp. 209–214

  207. [217]

    Optimized dpa attack on trivium stream cipher using correlation shape distinguishers,

    E. Tena-S´ anchez and A. Acosta, “Optimized dpa attack on trivium stream cipher using correlation shape distinguishers,” in 2015 Confer- ence on Design of Circuits and Integrated Systems (DCIS) , 2015, pp. 1–6

  208. [218]

    Co mbined side-channel and fault analysis attack on protected grain f amily of stream ciphers,

    A. Chakraborty, B. Mazumdar, and D. Mukhopadhyay, “Co mbined side-channel and fault analysis attack on protected grain f amily of stream ciphers,” IACR Cryptol. ePrint Arch. , vol. 2015, p. 602, 2015

  209. [219]

    On dpa- resistive implementation of fsr-based stream ciphers usin g sabl logic styles,

    R. E. Atani, S. Mirzakuchaki, S. E. Atani, and W. Meier, “On dpa- resistive implementation of fsr-based stream ciphers usin g sabl logic styles,” Int. J. Comput. Commun. Control , vol. 3, pp. 324–335, 2008

  210. [220]

    A simple power analysis a ttack on the twofish key schedule,

    J. J. G. Ortiz and K. Compton, “A simple power analysis a ttack on the twofish key schedule,” ArXiv, 2016

  211. [221]

    A differe ntial-linear attack on 12-round serpent,

    O. Dunkelman, S. Indesteege, and N. Keller, “A differe ntial-linear attack on 12-round serpent,” 2008

  212. [222]

    Key dependent operation a nd algorithm specific complexity of statistical side channel attacks,

    J. R¨ udinger and A. Finger, “Key dependent operation a nd algorithm specific complexity of statistical side channel attacks,” i n 2009 Inter- national Conference on Telecommunications , 2009

  213. [223]

    Dynamic voltag e and fre- quency scaling (dvfs) in cryptographic processors to mitig ate power analysis attacks,

    S. Guilley, A. Heuser, and M. Loughry, “Dynamic voltag e and fre- quency scaling (dvfs) in cryptographic processors to mitig ate power analysis attacks,” IEEE Transactions on Computers , vol. 55, pp. 1604– 1611, 2006

  214. [224]

    Power analy sis attacks and countermeasures for hardware implementations of the ae s,

    T. S. Messerges, E. Dabbish, and R. Sloan, “Power analy sis attacks and countermeasures for hardware implementations of the ae s,” in Proceedings of CHES 1999 , 1999, pp. 344–358

  215. [225]

    A dynamic a nd differential power analysis resistant logic with dual-rail precharge lo gic styles,

    K. Tiri, P . Schaumont, and I. V erbauwhede, “A dynamic a nd differential power analysis resistant logic with dual-rail precharge lo gic styles,” in Proceedings of CHES 2004 , 2004, pp. 292–304

  216. [226]

    Power profile obfuscation using nanoscale memristive devices to counter dpa attacks,

    G. Khedkar, D. Kudithipudi, and G. Rose, “Power profile obfuscation using nanoscale memristive devices to counter dpa attacks, ” IEEE Transactions on Nanotechnology , vol. 14, pp. 26–35, 2015

  217. [227]

    Hardware-based noise gener- ation to mitigate differential power analysis attacks,

    L. Zhou, M. Koushanfar, and R. Karri, “Hardware-based noise gener- ation to mitigate differential power analysis attacks,” in Proceedings of the IEEE Symposium on Hardware-Oriented Security and Tru st (HOST), 2005, pp. 54–61

  218. [228]

    A statistical mod el for higher order dpa on masked devices,

    A. Ding, L. Zhang, Y . Fei, and P . Luo, “A statistical mod el for higher order dpa on masked devices,” in Lecture Notes in Computer Science , 2014, pp. 147–169

  219. [229]

    Isap - towards side-channel secure authenticated e ncryption,

    C. Dobraunig, M. Eichlseder, S. Mangard, F. Mendel, an d T. Unterlug- gauer, “Isap - towards side-channel secure authenticated e ncryption,” IACR Trans. Symmetric Cryptol. , vol. 2017, pp. 80–105, 2017

  220. [230]

    Higher- order threshold implementations,

    B. Bilgin, B. Gierlichs, S. Nikova, V . Nikov, and V . Rij men, “Higher- order threshold implementations,” IACR Cryptol. ePrint Arch. , vol. 2014, p. 751, 2014

  221. [231]

    Desi gn of adiabatic dynamic differential logic for dpa-resistant secure integ rated circuits,

    J. L. Matthew Morrison, Nagarajan Ranganathan, “Desi gn of adiabatic dynamic differential logic for dpa-resistant secure integ rated circuits,” in IEEE Transactions on V ery Large Scale Integration (VLSI) Sy stems, vol. 23, 2015, pp. 1381–1389

  222. [232]

    Improving the random ized initial point countermeasure against dpa,

    K. Itoh, T. Izu, and M. Takenaka, “Improving the random ized initial point countermeasure against dpa,” Lecture Notes in Computer Science , vol. 4004, pp. 459–469, 2006

  223. [233]

    Evaluation of rando m delay insertion against dpa on fpgas,

    Y . Lu, M. O’Neill, and J. McCanny, “Evaluation of rando m delay insertion against dpa on fpgas,” ACM Trans. Reconfigurable Technology and Systems , vol. 4, pp. 11:1–11:20, 2010

  224. [234]

    On randomizing private keys to c ounteract dpa attacks,

    N. Ebeid and A. Hasan, “On randomizing private keys to c ounteract dpa attacks,” in Progress in Cryptology - INDOCRYPT 2003 , 2003, pp. 58–72

  225. [235]

    Correlated powe r noise generator as a low-cost dpa countermeasure to secure hardwa re aes cipher,

    N. Kamoun, L. Bossuet, and A. Ghazel, “Correlated powe r noise generator as a low-cost dpa countermeasure to secure hardwa re aes cipher,” 2009 3rd International Conference on Signals, Circuits and Systems (SCS) , pp. 1–6, 2009

  226. [236]

    Randomized multitopol- ogy logic against differential power analysis,

    M. Avital, H. Dagan, O. Keren, and A. Fish, “Randomized multitopol- ogy logic against differential power analysis,” IEEE Transactions on V ery Large Scale Integration (VLSI) Systems , vol. 23, pp. 702–711, 2015

  227. [237]

    Artificial noise injection fo r securing single- antenna systems,

    B. He, Y . She, and V . Lau, “Artificial noise injection fo r securing single- antenna systems,” IEEE Transactions on V ehicular Technology, vol. 66, pp. 9577–9581, 2017

  228. [238]

    Efficient count ermeasures against rpa, dpa, and spa,

    H. Mamiya, A. Miyaji, and H. Morimoto, “Efficient count ermeasures against rpa, dpa, and spa,” in Cryptographic Hardware and Embedded Systems, 2004, pp. 343–356

  229. [239]

    Zkpdl: A language- based system for efficient zero-knowledge proofs and electr onic cash,

    R. Gennaro, J. Katz, H. Krawczyk, and T. Rabin, “Zkpdl: A language- based system for efficient zero-knowledge proofs and electr onic cash,” in Proceedings of the ACM Conference on Computer and Communi- cations Security , 2012, pp. 366–385

  230. [240]

    Fully homomorphic encryption using ideal lattices,

    C. Gentry, “Fully homomorphic encryption using ideal lattices,” in Pro- ceedings of the 41st Annual ACM Symposium on Theory of Comput ing, 2009, pp. 169–178

  231. [241]

    Authenticated encryption,

    P . Rogaway, “Authenticated encryption,” in Fast Software Encryption , 2011

  232. [242]

    New directions in cryptograp hy,

    W. Diffie and M. Hellman, “New directions in cryptograp hy,” IEEE Transactions on Information Theory , vol. 22, pp. 644–654, 1976

  233. [243]

    Cold bo ot attacks are still hot: Security analysis of memory scramblers in mod ern processors,

    S. F. Yitbarek, M. T. Aga, R. Das, and T. Austin, “Cold bo ot attacks are still hot: Security analysis of memory scramblers in mod ern processors,” 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA) , pp. 313–324, 2017

  234. [244]

    Fpga-a ccelerated key search for cold-boot attacks against aes,

    H. Riebler, T. Kenter, C. Sorge, and C. Plessl, “Fpga-a ccelerated key search for cold-boot attacks against aes,” 2013 International Conference on Field-Programmable Technology (FPT) , pp. 386–389, 2013

  235. [245]

    Amnesiac dra m: A proactive defense mechanism against cold boot attacks,

    H. Seol, M. Kim, T. Kim, Y . Kim, and L. Kim, “Amnesiac dra m: A proactive defense mechanism against cold boot attacks,” IEEE Transactions on Computers , vol. 70, pp. 539–551, 2019

  236. [246]

    Lest we remember: cold-boot attacks on encryption keys,

    J. A. Halderman, S. D. Schoen, N. Heninger, W. Clarkson , W. Paul, J. A. Calandrino, A. J. Feldman, J. Appelbaum, and E. Felten, “Lest we remember: cold-boot attacks on encryption keys,” pp. 45– 60, 2008

  237. [247]

    Low-temperature data remanence a ttacks against intrinsic sram pufs,

    N. Anagnostopoulos, S. Katzenbeisser, M. Rosenstihl , A. Schaller, S. Gabmeyer, and T. Arul, “Low-temperature data remanence a ttacks against intrinsic sram pufs,” 2018 21st Euromicro Conference on Digital System Design (DSD) , pp. 581–585, 2018

  238. [248]

    Security strate gy of powered- off sram for resisting physical attack to data remanence,

    Y . Kai, X. Zou, Y . Guoyi, and W. Weixu, “Security strate gy of powered- off sram for resisting physical attack to data remanence,” Journal of Semiconductors, vol. 30, p. 095010, 2009

  239. [249]

    Data remanence in flash memory devic es,

    S. Skorobogatov, “Data remanence in flash memory devic es,” pp. 339– 353, 2005

  240. [250]

    Drammer: Dete rmin- istic rowhammer attacks on mobile platforms,

    V . V . D. V een, Y . Fratantonio, M. Lindorfer, D. Gruss, C . Maurice, G. Vigna, H. Bos, K. Razavi, and C. Giuffrida, “Drammer: Dete rmin- istic rowhammer attacks on mobile platforms,” Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Secur ity, 2016

  241. [251]

    Quantify- ing rowhammer vulnerability for dram security,

    Y . Jiang, H. Zhu, D. Sullivan, X. Guo, X. Zhang, and Y . Ji n, “Quantify- ing rowhammer vulnerability for dram security,” 2021 58th ACM/IEEE Design Automation Conference (DAC) , pp. 73–78, 2021

  242. [252]

    A retrospective and futurespective of rowhammer at tacks and defenses on dram,

    Z.-L. Zhang, J. Qi, Y . Cheng, S. Jiang, Y . Lin, Y . Gao, S. Nepal, and Y . Zou, “A retrospective and futurespective of rowhammer at tacks and defenses on dram,” ArXiv, vol. abs/2201.02986, 2022

  243. [253]

    A primitive for revealing stealthy periph eral-based attacks on the computing platform’s main memory,

    P . Stewin, “A primitive for revealing stealthy periph eral-based attacks on the computing platform’s main memory,” Lecture Notes in Computer Science, pp. 1–20, 2013

  244. [254]

    Characterizing, exploiting, and dete cting dma code injection vulnerabilities in the presence of an iommu,

    A. Markuze, S. V argaftik, G. Kupfer, B. Pismenny, N. Am it, A. Morri- son, and D. Tsafrir, “Characterizing, exploiting, and dete cting dma code injection vulnerabilities in the presence of an iommu,” Proceedings of the Sixteenth European Conference on Computer Systems , 2021

  245. [255]

    B ypassing iommu protection against i/o attacks,

    B. Morgan, E. Alata, V . Nicomette, and M. Kaˆ aniche, “B ypassing iommu protection against i/o attacks,” 2016 Seventh Latin-American Symposium on Dependable Computing (LADC) , pp. 145–150, 2016

  246. [256]

    Detecting and preventing kernel rootkit attacks with bus s nooping,

    H. Moon, H. Lee, I. Heo, K. Kim, Y . Paek, and B. B. Kang, “Detecting and preventing kernel rootkit attacks with bus s nooping,” IEEE Transactions on Dependable and Secure Computing , vol. 14, pp. 145–157, 2017

  247. [257]

    Runtime detecti on of probing/tampering on interconnecting buses,

    Z. Xu, T. Mauldin, Q. Y ang, and T. Wei, “Runtime detecti on of probing/tampering on interconnecting buses,” 2021 IEEE 29th Annual International Symposium on Field-Programmable Custom Com puting Machines (FCCM) , pp. 247–251, 2021

  248. [258]

    Memory trace oblivious pr ogram exe- cution,

    C. Liu, M. Hicks, and E. Shi, “Memory trace oblivious pr ogram exe- cution,” 2013 IEEE 26th Computer Security F oundations Symposium , pp. 51–65, 2013

  249. [259]

    Explo iting correct- ing codes: On the effectiveness of ecc memory against rowham mer attacks,

    L. Cojocar, K. Razavi, C. Giuffrida, and H. Bos, “Explo iting correct- ing codes: On the effectiveness of ecc memory against rowham mer attacks,” 2019 IEEE Symposium on Security and Privacy (SP) , pp. 55– 71, 2019

  250. [260]

    Product code sch emes for error correction in mlc nand flash memories,

    C. Y ang, Y . Emre, and C. Chakrabarti, “Product code sch emes for error correction in mlc nand flash memories,” IEEE Transactions on V ery Large Scale Integration (VLSI) Systems , vol. 20, pp. 2302–2314, 2012

  251. [261]

    On-line software-based self-test for ecc of embedded ram memories,

    M. Restifo, P . Bernardi, S. D. Luca, and A. Sansonetti, “On-line software-based self-test for ecc of embedded ram memories, ” 2017 IEEE International Symposium on Defect and Fault Tolerance in VLSI and Nanotechnology Systems (DFT) , pp. 1–6, 2017

  252. [262]

    Aslr on the line: Practical cache attacks on the mmu,

    B. Gras, K. Razavi, E. Bosman, H. Bos, and C. Giuffrida, “Aslr on the line: Practical cache attacks on the mmu,” Proceedings of the 2017 Network and Distributed System Security Symposium (NDSS) , 2017

  253. [263]

    Devious: Device-driven side-channel attacks on the iommu ,

    T. Kim, H.-M. Park, S. Lee, S. Shin, J. Hur, and Y . joo Shi n, “Devious: Device-driven side-channel attacks on the iommu ,” 2023 IEEE Symposium on Security and Privacy (SP) , pp. 2288–2305, 2023

  254. [264]

    Thermal imaging attacks on key pad security systems,

    W. Wodo and L. Hanzlik, “Thermal imaging attacks on key pad security systems,” 2016 International Conference on Consumer Electronics (ICCE), pp. 458–464, 2016

  255. [265]

    Detection of unusual thermal a ctivities in a semiconductor chip using backside infrared thermal imagin g,

    S. S. Salvi and A. Jain, “Detection of unusual thermal a ctivities in a semiconductor chip using backside infrared thermal imagin g,” Journal of Electronic Packaging , 2020

  256. [266]

    Key extraction using thermal laser stimulation,

    H. Lohrke, S. Tajik, T. Krachenfels, C. Boit, and J.-P . Seifert, “Key extraction using thermal laser stimulation,” IACR Transactions on Cryptographic Hardware and Embedded Systems , pp. 573–595, 2018

  257. [267]

    Information leakage through pa ssive timing attacks on rsa decryption system,

    T. Hirata and Y . Kaji, “Information leakage through pa ssive timing attacks on rsa decryption system,” 2020 International Symposium on Information Theory and Its Applications (ISITA) , pp. 392–396, 2020

  258. [268]

    A novel side-channel ti ming attack on gpus,

    Z. Jiang, Y . Fei, and D. Kaeli, “A novel side-channel ti ming attack on gpus,” Proceedings of the on Great Lakes Symposium on VLSI 2017 , 2017

  259. [269]

    Cache-timing attack against hqc,

    S. Huang, R. Q. Sim, C. Chuengsatiansup, Q. Guo, and T. J ohansson, “Cache-timing attack against hqc,” IACR Trans. Cryptogr . Hardw. Embed. Syst. , vol. 2023, pp. 136–163, 2023

  260. [270]

    Towards h igh- performance memory encryption in hardware,

    J. H. A. Muhammad Hosein Mofrad and N. S. Kim, “Towards h igh- performance memory encryption in hardware,” IEEE Transactions on Computers, 2018

  261. [271]

    Memory encryption for general-purpose pr ocessors,

    S. Gueron, “Memory encryption for general-purpose pr ocessors,” IEEE Security & Privacy , 2016

  262. [272]

    Implication s of hardware- based memory encryption for vms,

    Y . L. Xiaolin Li, Mingkai Dong and Y . Fan, “Implication s of hardware- based memory encryption for vms,” IEEE Transactions on Cloud Computing, 2022

  263. [273]

    Fau lt attacks on encrypted general-purpose compute platforms,

    T. E. Robert Buhren, Jonas Degeling and A. Moradi, “Fau lt attacks on encrypted general-purpose compute platforms,” in Proceedings of the 2016 W orkshop on Fault Injection and Dependability , 2016

  264. [274]

    Scalable memory encryption e ngine for large-scale systems,

    H. Inoue and Y . Iwasaki, “Scalable memory encryption e ngine for large-scale systems,” IEEE Micro, 2022

  265. [275]

    Protecting your own private key in cloud: Security, scalab ility and performance,

    J. W. C. W. L. G. W. L. B. C. H. K. T. B. W. Wenqian Y u, Ping Y u , “Protecting your own private key in cloud: Security, scalab ility and performance,” 2018 IEEE Conference on Communications and Network Security (CNS) , 2018

  266. [276]

    Low-cost distribute d key manage- ment,

    J. C. V . Gopal, Shikha Fadnavis, “Low-cost distribute d key manage- ment,” 2018 IEEE W orld Congress on Services (SERVICES) , 2018

  267. [277]

    Cryptographic key protect ion in a crypto- processor,

    N. Rajitha and R. Sridevi, “Cryptographic key protect ion in a crypto- processor,” Procedia Computer Science , vol. 78, 2016

  268. [278]

    An embedd ed key management system for puf-based security enclosures,

    M. H. G. S. J. Obermaier, Florian Hauschild, “An embedd ed key management system for puf-based security enclosures,” 2018 7th Mediterranean Conference on Embedded Computing (MECO) , 2018

  269. [279]

    V erify memory i ntegrity basing on hash tree and mac combined approach,

    Y . T. J. L. Fangyong Hou, Zhiying Wang, “V erify memory i ntegrity basing on hash tree and mac combined approach,” in International Conference on Embedded and Ubiquitous Computing , 2004, pp. 869– 878

  270. [280]

    Memory integrity verifying based on hash tre e hot-window,

    H. Fang, “Memory integrity verifying based on hash tre e hot-window,” in Chinese Journal of Computers , 2004

  271. [281]

    Dynamic skewed tree for fast me mory integrity verification,

    J. G. Vig, S. and S. Lam, “Dynamic skewed tree for fast me mory integrity verification,” in 2018 Design, Automation & Test in Europe Conference & Exhibition (DATE) , 2018, pp. 642–647

  272. [282]

    Detection of software-indu ced rowhammer attacks via static analysis,

    I. Lee, H. Kim, and S. Lee, “Detection of software-indu ced rowhammer attacks via static analysis,” in IEEE Symposium on Security and Privacy, 2021

  273. [283]

    Ec cploit: Ecc memory’s rowhammer vulnerability,

    D. G. K. R. H. B. L. Cojocar, M. Lipp and C. Giuffrida, “Ec cploit: Ecc memory’s rowhammer vulnerability,” in IEEE Symposium on Security and Privacy (SP) , 2019

  274. [284]

    Dagguise: Mitigating memory timing side channels,

    T. B. J. D. J. E. Peter W. Deutsch, Y uheng Y ang and M. Y an, “Dagguise: Mitigating memory timing side channels,” in Proceedings of the 49th Annual International Symposium on Computer Arch itecture, 2022

  275. [285]

    Mempoline: Mitigati ng memory- based side-channel attacks through memory access obfuscat ion,

    A. D. Z. Jiang, Y . Fei and T. Wahl, “Mempoline: Mitigati ng memory- based side-channel attacks through memory access obfuscat ion,” IACR Cryptology ePrint Archive , vol. 2020, p. 653, 2020

  276. [286]

    Mitigating rev erse engineering attacks on deep neural networks,

    D. D.-S. Y untao Liu and A. Srivastava, “Mitigating rev erse engineering attacks on deep neural networks,” in 2019 IEEE Computer Society Annual Symposium on VLSI (ISVLSI) , 2019, pp. 657–662

  277. [287]

    Rcoal: Mitigating gpu timing attack via subwarp-based randomized coalescing technique s,

    D. Z. Gurunath Kadam and A. Jog, “Rcoal: Mitigating gpu timing attack via subwarp-based randomized coalescing technique s,” in 2018 IEEE International Symposium on High Performance Computer Archi- tecture (HPCA) , 2018, pp. 156–167

  278. [288]

    Reliability o f scrubbing recovery-techniques for memory systems,

    A. M. Saleh, J. J. Serrano, and J. Patel, “Reliability o f scrubbing recovery-techniques for memory systems,” IEEE Transactions on Re- liability, vol. 39, pp. 114–122, 1990

  279. [289]

    Optimizing s crubbing sequences for advanced computer memories,

    P . Reviriego, J. A. Maestro, and S. Baeg, “Optimizing s crubbing sequences for advanced computer memories,” IEEE Transactions on Device and Materials Reliability , vol. 10, pp. 192–200, 2010

  280. [290]

    Reliability models for sec/ded memory with scrubbing in fpga-based designs,

    Y . Li, B. Nelson, and M. Wirthlin, “Reliability models for sec/ded memory with scrubbing in fpga-based designs,” IEEE Transactions on Nuclear Science , vol. 60, pp. 2720–2727, 2013

  281. [291]

    Energy efficie nt frame- level redundancy scrubbing technique for sram-based fpgas ,

    J. Tonfat, F. Kastensmidt, and R. Reis, “Energy efficie nt frame- level redundancy scrubbing technique for sram-based fpgas ,” in 2015 NASA/ESA Conference on Adaptive Hardware and Systems (AHS) , 2015, pp. 1–8

  282. [292]

    Coin attac ks: On insecurity of enclave untrusted interfaces in sgx,

    M. Khandaker, Y . Cheng, Z. Wang, and T. Wei, “Coin attac ks: On insecurity of enclave untrusted interfaces in sgx,” in Proceedings of the Twenty-Fifth International Conference on Architectur al Support for Programming Languages and Operating Systems , 2020

  283. [293]

    Protecting enclaves from intra-core side-channel attacks through physical isolation,

    M. van der Maas and S. Moore, “Protecting enclaves from intra-core side-channel attacks through physical isolation,” in Proceedings of the 2nd W orkshop on Cyber-Security Arms Race , 2020

  284. [294]

    S gxpectre attacks: Leaking enclave secrets via speculative executio n,

    G. Chen, S. Chen, Y . Xiao, Y . Zhang, Z. Lin, and T. Lai, “S gxpectre attacks: Leaking enclave secrets via speculative executio n,” in ArXiv, vol. abs/1802.09085, 2018

  285. [295]

    Copycat: Controlled instruction-level attacks on enclav es for maximal key extraction,

    D. Moghimi, J. V an Bulck, N. Heninger, F. Piessens, and B. Sunar, “Copycat: Controlled instruction-level attacks on enclav es for maximal key extraction,” in ArXiv, vol. abs/2002.08437, 2020

  286. [296]

    Autarky : closing controlled channels with self-paging enclaves,

    M. Orenbach, A. Baumann, and M. Silberstein, “Autarky : closing controlled channels with self-paging enclaves,” in Proceedings of the Fifteenth European Conference on Computer Systems , 2020

  287. [297]

    V erifying the security of enclaved exec ution against interrupt-based side-channel attacks,

    F. Piessens, “V erifying the security of enclaved exec ution against interrupt-based side-channel attacks,” in Proceedings of ACM W orkshop on Theory of Implementation Security W orkshop , 2019

  288. [298]

    Stacco: Differen tially analyzing side-channel traces for detecting ssl/tls vulne rabilities in secure enclaves,

    Y . Xiao, M. Li, S. Chen, and Y . Zhang, “Stacco: Differen tially analyzing side-channel traces for detecting ssl/tls vulne rabilities in secure enclaves,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security , 2017

  289. [299]

    Practical enclav e malware with intel sgx,

    M. Schwarz, S. Weiser, and D. Gruss, “Practical enclav e malware with intel sgx,” in ArXiv, 2019

  290. [300]

    Platypus: Software-based power side-channe l attacks on x86,

    M. Lipp, A. Kogler, D. F. Oswald, M. Schwarz, C. Easdon, C. Canella, and D. Gruss, “Platypus: Software-based power side-channe l attacks on x86,” in 2021 IEEE Symposium on Security and Privacy (SP) , 2021

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.