arrow
Return

Do Compilers Break Constant-Time Guarantees?

delete2026-01-01
delete0
PRE
AI
L
Lukas Gerlach *
R
Robert Pietsch
M
Michael Schwarz
DOI:10.1007/978-3-032-07035-7_20delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Side-channel attacks are a significant concern for the implementation of cryptographic algorithms. Data-oblivious programming is a discipline that helps mitigate side-channel attacks by preventing data leakage over side channels. However, due to various optimizations in modern compilers, data-obliviousness cannot be guaranteed in high-level languages. This work investigates to which extent compiler optimizations violate data-obliviousness. To this end, we present data-oblivious compiler checker (DOCC), an automated binary testing pipeline for detecting data-obliviousness violations under different compiler configurations. We show that DOCC is applicable across 6 widely used compilers. Additionally, DOCC can retrofit existing analysis tools with advanced leakage models, such as data-dependent instruction execution times and data-obliviousness under speculation. We evaluate DOCC on 5 major cryptographic libraries and the recently proposed NIST lightweight cryptography primitives. We reveal data-obliviousness violations in 93 out of the 127 tested algorithms and 1845 out of the 12917 test cases across different cryptographic libraries, building blocks, and programming languages. We demonstrate that the choice of compiler and optimizations heavily influences the resulting binary's properties.
Keywords:
data-obliviousness
side-channel attacks
compiler optimizations
constant-time guarantees
cryptographic implementations

Journal

F
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2025, PT II
IF:
0
Papers:
20
Citations:
0

Organization

S
saarland university
Scholars:
1.0K
Papers: 459
Citations: 0