Skip to main navigation Skip to search Skip to main content

Specification and Verification of Side-channel Security for Open-source Processors via Leakage Contracts

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Leakage contracts have recently been proposed as a new security abstraction at the Instruction Set Architecture (ISA) level. Leakage contracts aim to capture the information that processors leak through their microarchitectural implementations. However, so far, we lack a methodology to verify that a processor actually satisfies a given leakage contract. In this paper, we address this challenge by developing LeaVe, the first tool for verifying register-transfer-level (RTL) processor designs against ISA-level leakage contracts. To this end, we show how to decouple security and functional correctness concerns. LeaVe leverages this decoupling to make verification of contract satisfaction practical. To scale to realistic processor designs, LeaVe further employs inductive reasoning on relational abstractions. Using LeaVe, we precisely characterize the side-channel security guarantees of three open-source RISC-V processors, thereby obtaining the first proofs of contract satisfaction for RTL processor designs.
Original languageEnglish
Title of host publicationCCS 2023
Subtitle of host publicationProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery, Inc
Pages2128-2142
Number of pages15
ISBN (Electronic)9798400700507
DOIs
Publication statusPublished - 2023
Event30th ACM SIGSAC Conference on Computer and Communications Security, CCS 2023 - Copenhagen, Denmark
Duration: 26 Nov 202330 Nov 2023

Conference

Conference30th ACM SIGSAC Conference on Computer and Communications Security, CCS 2023
Country/TerritoryDenmark
CityCopenhagen
Period26/11/2330/11/23

Funding

We would like to thank Alastair Reid and Piotr Sapiecha for feedback and discussions. This project has received funding from the European Research Council under the European Union's Horizon 2020 research and innovation programme (grant agreement No. 101020415), from the Spanish Ministry of Science and Innovation under the project TED2021-132464B-I00 PRODIGY, from the Spanish Ministry of Science and Innovation under the Ramón y Cajal grant RYC2021-032614-I, from the Spanish Ministry of Science and Innovation under the project PID2022-142290OB-I00 ESPADA, and from a gift by Intel Corporation. We would like to thank Alastair Reid and Piotr Sapiecha for feedback and discussions. This project has received funding from the European Research Council under the European Union’s Horizon 2020 research and innovation programme (grant agreement No. 101020415), from the Spanish Ministry of Science and Innovation under the project TED2021-132464B-I00 PRODIGY, from the Spanish Ministry of Science and Innovation under the Ramón y Cajal grant RYC2021-032614-I, from the Spanish Ministry of Science and Innovation under the project PID2022-142290OB-I00 ESPADA, and from a gift by Intel Corporation.

FundersFunder number
Intel Corporation
European Research Council
Horizon 2020
???publication-publication-funding-organisation-not-added???101020415
Ministerio de Ciencia e InnovaciónRYC2021-032614-I, PID2022-142290OB-I00 ESPADA, TED2021-132464B-I00

    Fingerprint

    Dive into the research topics of 'Specification and Verification of Side-channel Security for Open-source Processors via Leakage Contracts'. Together they form a unique fingerprint.

    Cite this