Mastodon Mastodon Mastodon Mastodon

Side-Channel Attack

Updated: · CyberSecureFox Editorial Team

A side-channel attack extracts secrets not by breaking an algorithm, but by observing physical effects of a system such as timing, power consumption, electromagnetic emissions or cache behaviour.

How side-channel attacks work

Even mathematically strong encryption runs on real hardware. Operations that depend on secret data may take slightly different time, draw different power or leave traces in the processor cache. By measuring these effects many times and analysing them statistically, an attacker can reconstruct keys or other secrets. Main types:

  • Timing attacks – Paul Kocher showed in 1996 that the time needed for cryptographic operations can leak private keys.
  • Power and electromagnetic analysis – used against smart cards, hardware wallets and embedded devices.
  • Cache attacks – processes on the same CPU infer what another process is doing from cache access patterns.
  • Acoustic and optical channels – keyboard sounds, fan noise or LED flicker.

Why it matters

In 2018 the Spectre and Meltdown disclosures showed that speculative execution in almost all modern processors could be abused through cache side channels to read memory across security boundaries – between processes, virtual machines and the kernel. Fixes required firmware (microcode), operating system and browser updates and cost performance. New variants are still found regularly, making side channels a lasting class of hardware vulnerabilities, especially for cloud providers that run many customers on shared hardware.

How to defend

  • Use cryptographic libraries with constant-time implementations; compare secrets and hashes in constant time.
  • Install CPU microcode, OS and hypervisor updates.
  • Isolate sensitive workloads on dedicated hardware or cores.
  • For hardware devices, use certified secure elements with side-channel countermeasures.
Synonyms:
side channel attack