{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T15:34:09Z","timestamp":1780673649749,"version":"3.54.1"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030549961","type":"print"},{"value":"9783030549978","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-54997-8_21","type":"book-chapter","created":{"date-parts":[[2020,8,10]],"date-time":"2020-08-10T20:11:50Z","timestamp":1597090310000},"page":"323-341","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["An Abstract Semantics of Speculative Execution for Reasoning About Security Vulnerabilities"],"prefix":"10.1007","author":[{"given":"Robert J.","family":"Colvin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kirsten","family":"Winter","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,8,11]]},"reference":[{"issue":"2","key":"21_CR1","doi-asserted-by":"publisher","first-page":"7:1","DOI":"10.1145\/2627752","volume":"36","author":"J Alglave","year":"2014","unstructured":"Alglave, J., Maranget, L., Tautschnig, M.: Herding cats: Modelling, simulation, testing, and data mining for weak memory. ACM Trans. Program. Lang. Syst. 36(2), 7:1\u20137:74 (2014)","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"21_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-19835-9_5","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"J Alglave","year":"2011","unstructured":"Alglave, J., Maranget, L., Sarkar, S., Sewell, P.: Litmus: running tests against hardware. In: Abdulla, P.A., Leino, K.R.M. (eds.) TACAS 2011. LNCS, vol. 6605, pp. 41\u201344. Springer, Heidelberg (2011). \nhttps:\/\/doi.org\/10.1007\/978-3-642-19835-9_5"},{"key":"21_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"367","DOI":"10.1007\/978-3-540-48654-1_28","volume-title":"CONCUR 1994: Concurrency Theory","author":"RJR Back","year":"1994","unstructured":"Back, R.J.R., von Wright, J.: Trace refinement of action systems. In: Jonsson, B., Parrow, J. (eds.) CONCUR 1994. LNCS, vol. 836, pp. 367\u2013384. Springer, Heidelberg (1994). \nhttps:\/\/doi.org\/10.1007\/978-3-540-48654-1_28"},{"key":"21_CR4","doi-asserted-by":"crossref","unstructured":"Bijo, S., Johnsen, E.B., Pun, K.I., Lizeth Tapia Tarifa, S.: An operational semantics of cache coherent multicore architectures. In: Proceedings of the 31st Annual ACM Symposium on Applied Computing, SAC 2016, pp. 1219\u20131224. ACM, New York (2016)","DOI":"10.1145\/2851613.2851718"},{"key":"21_CR5","unstructured":"Van Bulck, J., et al.: Foreshadow: extracting the keys to the intel SGX kingdom with transient out-of-order execution. In: USENIX Security Symposium (2018)"},{"key":"21_CR6","unstructured":"Chattopadhyay, S., Roychoudhury, A.: Symbolic verification of cache side-channel freedom. CoRR, abs\/1801.01203 (2018)"},{"key":"21_CR7","unstructured":"Cheang, K., Rasmussen, C., Seshia, S., Subramanyan, P.: A formal approach to secure speculation. Cryptology ePrint Archive, Report 2019\/310 (2019). \nhttps:\/\/eprint.iacr.org\/2019\/310"},{"issue":"2","key":"21_CR8","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1016\/S0304-3975(01)00359-0","volume":"285","author":"M Clavel","year":"2002","unstructured":"Clavel, M., et al.: Maude: specification and programming in rewriting logic. Theor. Comput. Sci. 285(2), 187\u2013243 (2002)","journal-title":"Theor. Comput. Sci."},{"key":"21_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1007\/978-3-642-00255-7_9","volume-title":"Integrated Formal Methods","author":"R Colvin","year":"2009","unstructured":"Colvin, R., Hayes, I.J.: CSP with hierarchical state. In: Leuschel, M., Wehrheim, H. (eds.) IFM 2009. LNCS, vol. 5423, pp. 118\u2013135. Springer, Heidelberg (2009). \nhttps:\/\/doi.org\/10.1007\/978-3-642-00255-7_9"},{"issue":"7","key":"21_CR10","doi-asserted-by":"publisher","first-page":"392","DOI":"10.1016\/j.jlap.2011.05.001","volume":"80","author":"RJ Colvin","year":"2011","unstructured":"Colvin, R.J., Hayes, I.J.: Structural operational semantics through context-dependent behaviour. J. Logic Algebraic Programm. 80(7), 392\u2013426 (2011)","journal-title":"J. Logic Algebraic Programm."},{"key":"21_CR11","unstructured":"Colvin, R.J., Smith, G.: A high-level operational semantics for hardware weak memory models. CoRR, abs\/1812.00996 (2018)"},{"key":"21_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-319-95582-7_14","volume-title":"Formal Methods","author":"RJ Colvin","year":"2018","unstructured":"Colvin, R.J., Smith, G.: A wide-spectrum language for verification of programs on weak memory models. In: Havelund, K., Peleska, J., Roscoe, B., de Vink, E. (eds.) FM 2018. LNCS, vol. 10951, pp. 240\u2013257. Springer, Cham (2018). \nhttps:\/\/doi.org\/10.1007\/978-3-319-95582-7_14"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Disselkoen, C., Jagadeesan, R., Jeffrey, A., Riely, J.: Code that never ran: modeling attacks on speculative evaluation. In: Proceedings of IEEE Symposium on Security and Privacy (S&P) (2019)","DOI":"10.1109\/SP.2019.00047"},{"issue":"1","key":"21_CR14","doi-asserted-by":"publisher","first-page":"4:1","DOI":"10.1145\/2756550","volume":"18","author":"G Doychev","year":"2015","unstructured":"Doychev, G., K\u00f6pf, B., Mauborgne, L., Reineke, J.: CacheAudit: a tool for the static analysis of cache side channels. ACM Trans. Inf. Syst. Secur. 18(1), 4:1\u20134:32 (2015)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"21_CR15","doi-asserted-by":"crossref","unstructured":"Flur, S., et al.: Modelling the ARMv8 architecture, operationally: concurrency and ISA. In: Proceedings of the 43rd Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, POPL 2016, pp. 608\u2013621. ACM, New York (2016)","DOI":"10.1145\/2837614.2837615"},{"issue":"1","key":"21_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s13389-016-0141-6","volume":"8","author":"Q Ge","year":"2016","unstructured":"Ge, Q., Yarom, Y., Cock, D., Heiser, G.: A survey of microarchitectural timing attacks and countermeasures on contemporary hardware. J. Cryptographic Eng. 8(1), 1\u201327 (2016). \nhttps:\/\/doi.org\/10.1007\/s13389-016-0141-6","journal-title":"J. Cryptographic Eng."},{"key":"21_CR17","unstructured":"Gruss, D., Spreitzer, R., Mangard, S.: Cache template attacks: automating attacks on inclusive last-level caches. In: 24th USENIX Security Symposium (USENIX Security 15), pp. 897\u2013912. USENIX Association (2015)"},{"key":"21_CR18","unstructured":"Guarnieri, M., K\u00f6pf, B., Morales, J.F., Reineke, J., S\u00e1nchez, A.: SPECTECTOR: principled detection of speculative information flows. CoRR, abs\/1812.08639 (2018)"},{"key":"21_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/3-540-16442-1_14","volume-title":"ESOP 1986","author":"J He","year":"1986","unstructured":"He, J., Hoare, C.A.R., Sanders, J.W.: Data refinement refined resume. In: Robinet, B., Wilhelm, R. (eds.) ESOP 1986. LNCS, vol. 213, pp. 187\u2013196. Springer, Heidelberg (1986). \nhttps:\/\/doi.org\/10.1007\/3-540-16442-1_14"},{"key":"21_CR20","volume-title":"Communicating Sequential Processes","author":"CAR Hoare","year":"1985","unstructured":"Hoare, C.A.R.: Communicating Sequential Processes. Prentice-Hall Inc, Upper Saddle River (1985)"},{"key":"21_CR21","unstructured":"Intel. Intel 64 and IA-32 Architectures Software Developers Manual, January 2019"},{"key":"21_CR22","unstructured":"Islam, S., et al.: SPOILER: Speculative Load Hazards Boost Rowhammer And Cache Attacks (2019)"},{"key":"21_CR23","doi-asserted-by":"crossref","unstructured":"Kang, J., Hur, C.-K., Lahav, O., Vafeiadis, V., Dreyer, D.: A promising semantics for relaxed-memory concurrency. In Proceedings of the 44th ACM SIGPLAN Symposium on Principles of Programming Languages, POPL 2017, pp. 175\u2013189. ACM, New York (2017)","DOI":"10.1145\/3009837.3009850"},{"key":"21_CR24","doi-asserted-by":"crossref","unstructured":"Kocher, P., et al.: Spectre attacks: exploiting speculative execution. In 40th IEEE Symposium on Security and Privacy (S&P 2019) (2019)","DOI":"10.1109\/SP.2019.00002"},{"key":"21_CR25","doi-asserted-by":"crossref","unstructured":"Li, P., Zhao, L., Hou, R., Zhang, L., Meng, D.: Conditional speculation: an effective approach to safeguard out-of-order execution against Spectre attacks. In: 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA), pp. 264\u2013276, February 2019","DOI":"10.1109\/HPCA.2019.00043"},{"key":"21_CR26","unstructured":"Lipp, M., Gruss, D., Spreitzer, R., Maurice, C., Mangard, S.: Armageddon: cache attacks on mobile devices. In: 25th USENIX Security Symposium (USENIX Security 2016), pp. 549\u2013564. USENIX Association (2016)"},{"key":"21_CR27","unstructured":"Lipp, M., et al.: Meltdown: reading kernel memory from user space. In USENIX Security Symposium (2018)"},{"key":"21_CR28","doi-asserted-by":"crossref","unstructured":"Lustig, D., Pellauer, M., Martonosi, M.: PipeCheck: specifying and verifying microarchitectural enforcement of memory consistency models. In: Proceedings of the 47th Annual IEEE\/ACM International Symposium on Microarchitecture, MICRO-47, pp. 635\u2013646, Washington, DC, USA. IEEE Computer Society (2014)","DOI":"10.1109\/MICRO.2014.38"},{"key":"21_CR29","unstructured":"Mcilroy, R., Sevcik, J., Tebbi, T., Titzer, B.L., Verwaest, B.L.: Spectre is here to stay: an analysis of side-channels and speculative execution. CoRR, abs\/1902.05178 (2019)"},{"key":"21_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-10235-3","volume-title":"A Calculus of Communicating Systems","author":"R Milner","year":"1980","unstructured":"Milner, R.: A Calculus of Communicating Systems. LNCS, vol. 92. Springer, Heidelberg (1980). \nhttps:\/\/doi.org\/10.1007\/3-540-10235-3"},{"key":"21_CR31","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/BF00277386","volume":"27","author":"C Morgan","year":"1990","unstructured":"Morgan, C., Gardiner, P.: Data refinement by calculation. Acta Informatica 27, 481\u2013503 (1990)","journal-title":"Acta Informatica"},{"key":"21_CR32","doi-asserted-by":"crossref","unstructured":"Murray, T.C., Sison, R., Engelhardt, K.: COVERN: a logic for compositional verification of information flow control. In: 2018 IEEE European Symposium on Security and Privacy, EuroS&P 2018, pp. 16\u201330. IEEE (2018)","DOI":"10.1109\/EuroSP.2018.00010"},{"key":"21_CR33","doi-asserted-by":"crossref","unstructured":"Murray, T.C., Sison, R., Pierzchalski, E., Rizkallah, C.: Compositional verification and refinement of concurrent value-dependent noninterference. In: IEEE 29th Computer Security Foundations Symposium, CSF 2016, pp. 417\u2013431. IEEE Computer Society (2016)","DOI":"10.1109\/CSF.2016.36"},{"key":"21_CR34","first-page":"17","volume":"60\u201361","author":"GD Plotkin","year":"2004","unstructured":"Plotkin, G.D.: A structural approach to operational semantics. J. Logic Algebraic Program. 60\u201361, 17\u2013139 (2004)","journal-title":"J. Logic Algebraic Program."},{"issue":"6","key":"21_CR35","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1145\/1993316.1993520","volume":"46","author":"S Sarkar","year":"2011","unstructured":"Sarkar, S., Sewell, P., Alglave, J., Maranget, L., Williams, D.: Understanding POWER multiprocessors. SIGPLAN Not. 46(6), 175\u2013186 (2011)","journal-title":"SIGPLAN Not."},{"issue":"7","key":"21_CR36","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1145\/1785414.1785443","volume":"53","author":"P Sewell","year":"2010","unstructured":"Sewell, P., Sarkar, S., Owens, S., Nardelli, F.Z., Myreen, M.O.: X86-TSO: a rigorous and usable programmer\u2019s model for x86 multiprocessors. Commun. ACM 53(7), 89\u201397 (2010)","journal-title":"Commun. ACM"},{"key":"21_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"539","DOI":"10.1007\/978-3-030-30942-8_32","volume-title":"Formal Methods \u2013 The Next 30 Years","author":"G Smith","year":"2019","unstructured":"Smith, G., Coughlin, N., Murray, T.: Value-dependent information-flow security on weak memory models. In: ter Beek, M.H., McIver, A., Oliveira, J.N. (eds.) FM 2019. LNCS, vol. 11800, pp. 539\u2013555. Springer, Cham (2019). \nhttps:\/\/doi.org\/10.1007\/978-3-030-30942-8_32"},{"issue":"POPL","key":"21_CR38","doi-asserted-by":"publisher","first-page":"54:1","DOI":"10.1145\/3290367","volume":"3","author":"V Touzeau","year":"2019","unstructured":"Touzeau, V., Ma\u00efza, C., Monniaux, D., Reineke, J.: Fast and exact analysis for LRU caches. Proc. ACM Program. Lang. 3(POPL), 54:1\u201354:29 (2019)","journal-title":"Proc. ACM Program. Lang."},{"key":"21_CR39","doi-asserted-by":"crossref","unstructured":"Trippel, C., Lustig, D., Martonosi, M.: Checkmate: automated synthesis of hardware exploits and security litmus tests. In: 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO), pp. 947\u2013960 (2018)","DOI":"10.1109\/MICRO.2018.00081"},{"key":"21_CR40","unstructured":"Trippel, C., Lustig, D., Martonosi, M.: MeltdownPrime and SpectrePrime: automatically-synthesized attacks exploiting invalidation-based coherence protocols. CoRR, abs\/1802.03802 (2018)"},{"issue":"1\u20132","key":"21_CR41","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1016\/j.jlap.2005.09.008","volume":"67","author":"A Verdejo","year":"2006","unstructured":"Verdejo, A., Mart-Oliet, N.: Executable structural operational semantics in Maude. J. Logic Algebraic Programm. 67(1\u20132), 226\u2013293 (2006)","journal-title":"J. Logic Algebraic Programm."},{"key":"21_CR42","unstructured":"Wang, G., Chattopadhyay, S., Gotovchits, I., Mitra, T., Roychoudhury, A.: oo7: low-overhead defense against spectre attacks via binary analysis. CoRR, abs\/1807.05843 (2018)"},{"key":"21_CR43","unstructured":"Wang, S., Wang, P., Liu, X., Zhang, D., Wu, D.: CacheD: identifying cache-based timing channels in production software. In: 26th USENIX Security Symposium (USENIX Security 2017), pp. 235\u2013252. USENIX Association (2017)"},{"key":"21_CR44","doi-asserted-by":"crossref","unstructured":"Wu, M., Wang, C.: Abstract interpretation under speculative execution. In: Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2019, pp. 802\u2013815. ACM, New York (2019)","DOI":"10.1145\/3314221.3314647"},{"key":"21_CR45","unstructured":"Yarom, Y., Falkner, K.: FLUSH+RELOAD: a high resolution, low noise, L3 cache side-channel attack. In: USENIX Security Symposium (USENIX Security 2014), pp. 719\u2013732. USENIX Association (2014)"},{"key":"21_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, Y.: Cache side channels: state of the art and research opportunities. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, pp. 2617\u20132619. ACM (2017)","DOI":"10.1145\/3133956.3136064"}],"container-title":["Lecture Notes in Computer Science","Formal Methods. FM 2019 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-54997-8_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,8,10]],"date-time":"2020-08-10T20:17:08Z","timestamp":1597090628000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-54997-8_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030549961","9783030549978"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-54997-8_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"11 August 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Formal Methods","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Porto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 October 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 October 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"fm2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/formalmethods2019.inesctec.pt\/?page_id=84","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"129","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"44","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"34% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5,5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}