Towards Efficient Verification of Constant-Time Cryptographic Implementations

Author:

Cai Luwei1ORCID,Song Fu2ORCID,Chen Taolue3ORCID

Affiliation:

1. ShanghaiTech University, Shanghai, China

2. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing, China / University of Chinese Academy of Sciences, Beijing, China / Nanjing Institute of Software Technology, Nanjing, China

3. Birkbeck University of London, London, United Kingdom

Abstract

Timing side-channel attacks exploit secret-dependent execution time to fully or partially recover secrets of cryptographic implementations, posing a severe threat to software security. Constant-time programming discipline is an effective software-based countermeasure against timing side-channel attacks, but developing constant-time implementations turns out to be challenging and error-prone. Current verification approaches/tools suffer from scalability and precision issues when applied to production software in practice. In this paper, we put forward practical verification approaches based on a novel synergy of taint analysis and safety verification of self-composed programs. Specifically, we first use an IFDS-based lightweight taint analysis to prove that a large number of potential (timing) side-channel sources do not actually leak secrets. We then resort to a precise taint analysis and a safety verification approach to determine whether the remaining potential side-channel sources can actually leak secrets. These include novel constructions of taint-directed semi-cross-product of the original program and its Boolean abstraction, and a taint-directed self-composition of the program. Our approach is implemented as a cross-platform and fully automated tool CT-Prover. The experiments confirm its efficiency and effectiveness in verifying real-world benchmarks from modern cryptographic and SSL/TLS libraries. In particular, CT-Prover identify new, confirmed vulnerabilities of open-source SSL libraries (e.g., Mbed SSL, BearSSL) and significantly outperforms the state-of-the-art tools.

Funder

CAS Project for Young Scientists in Basic Research

ISCAS New Cultivation Project

ISCAS Fundamental Research Project

National Natural Science Foundation of China

State Key Laboratory of Novel Software Technology, Nanjing University

Birkbeck BEI School Project

Publisher

Association for Computing Machinery (ACM)

Reference84 articles.

1. 2023. curve25519-donna. https://github.com/agl/curve25519-donna

2. 2023. HACL*. https://github.com/hacl-star/hacl-star

3. 2023. libsodium. https://doc.libsodium.org/

4. 2023. OpenSSL. https://www.openssl.org

5. 2023. Tongsuo. https://github.com/Tongsuo-Project/Tongsuo

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3