Specification and Verification of Side Channel Declassification

Computer Science – Cryptography and Security

Scientific paper

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

Scientific paper

Side channel attacks have emerged as a serious threat to the security of both networked and embedded systems -- in particular through the implementations of cryptographic operations. Side channels can be difficult to model formally, but with careful coding and program transformation techniques it may be possible to verify security in the presence of specific side-channel attacks. But what if a program intentionally makes a tradeoff between security and efficiency and leaks some information through a side channel? In this paper we study such tradeoffs using ideas from recent research on declassification. We present a semantic model of security for programs which allow for declassification through side channels, and show how side-channel declassification can be verified using off-the-shelf software model checking tools. Finally, to make it simpler for verifiers to check that a program conforms to a particular side-channel declassification policy we introduce a further tradeoff between efficiency and verifiability: by writing programs in a particular "manifest form" security becomes considerably easier to verify.

No associations

LandOfFree

Say what you really think

Search LandOfFree.com for scientists and scientific papers. Rate them and share your experience with other people.

Rating

Specification and Verification of Side Channel Declassification does not yet have a rating. At this time, there are no reviews or comments for this scientific paper.

If you have personal experience with Specification and Verification of Side Channel Declassification, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Specification and Verification of Side Channel Declassification will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFWR-SCP-O-306199

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.