{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:14:00Z","timestamp":1783008840013,"version":"3.54.5"},"reference-count":56,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2017,2,11]],"date-time":"2017-02-11T00:00:00Z","timestamp":1486771200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,2,11]],"date-time":"2017-02-11T00:00:00Z","timestamp":1486771200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1408734"],"award-info":[{"award-number":["CNS-1408734"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1505799"],"award-info":[{"award-number":["CNS-1505799"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1513671"],"award-info":[{"award-number":["CNS-1513671"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004351","name":"Cisco Systems","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004351","id-type":"DOI","asserted-by":"publisher"}]},{"name":"The Blavatnik Interdisciplinary Cyber Research Center"},{"name":"Check Point Institute for Information Security"},{"DOI":"10.13039\/100006785","name":"Google","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100005386","name":"Israeli Centers for Research Excellence","doi-asserted-by":"crossref","award":["Center 4\/11"],"award-info":[{"award-number":["Center 4\/11"]}],"id":[{"id":"10.13039\/501100005386","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100007028","name":"Leona M. and Harry B. Helmsley Charitable Trust","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100007028","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004415","name":"North Atlantic Treaty Organization","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004415","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2017,6]]},"DOI":"10.1007\/s13389-017-0152-y","type":"journal-article","created":{"date-parts":[[2017,2,11]],"date-time":"2017-02-11T19:22:35Z","timestamp":1486840955000},"page":"99-112","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":128,"title":["CacheBleed: a timing attack on OpenSSL constant-time RSA"],"prefix":"10.1007","volume":"7","author":[{"given":"Yuval","family":"Yarom","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Genkin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nadia","family":"Heninger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,2,11]]},"reference":[{"key":"152_CR1","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O.: Yet another microarchitectural attack: exploiting I-cache. In: CSAW, Fairfax, VA, US (2007)","DOI":"10.1145\/1314466.1314469"},{"key":"152_CR2","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O., Ko\u00e7, \u00c7.K.: Microarchitectural attacks and countermeasures. In: Cryptographic engineering, pp. 475\u2013504 (2009)","DOI":"10.1007\/978-0-387-71817-0_18"},{"key":"152_CR3","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O., Gueron, S., Seifert, J.-P.: New branch prediction vulnerabilities in OpenSSL and necessary software countermeasures. In: 11th IMA International Conference on Cryptography and Coding, pp. 185\u2013203. Cirencester, UK (2007a)","DOI":"10.1007\/978-3-540-77272-9_12"},{"key":"152_CR4","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O., Ko\u00e7, \u00c7.K., Seifert, J.-P.: Predicting secret keys via branch prediction. In: 2007 CT-RSA, pp. 225\u2013242. (2007b)","DOI":"10.1007\/11967668_15"},{"key":"152_CR5","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O., Brumley, B.B., Grabher, P.: New results on instruction cache attacks. In: CHES, Santa Barbara, CA, US (2010)","DOI":"10.1007\/978-3-642-15031-9_8"},{"key":"152_CR6","doi-asserted-by":"crossref","unstructured":"Ac\u0131i\u00e7mez, O., Seifert, J.-P.: Cheap hardware parallelism implies cheap security. In: Fourth International Workshop on Fault Diagnosis and Tolerance in Cryptography, pp. 80\u201391. Vienna, AT (2007)","DOI":"10.1109\/FDTC.2007.16"},{"key":"152_CR7","unstructured":"Alpert, D.B., Choudhury, M.R., Mills, J.D.: Interleaved cache for multiple accesses per clock cycle in a microprocessor. US Patent 5,559,986, Sept 1996"},{"key":"152_CR8","unstructured":"AMD. http:\/\/www.amd.com\/en-gb\/innovations\/software-technologies\/zen-cpu"},{"key":"152_CR9","unstructured":"Bernstein, D.J.: Cache-timing attacks on AES. Preprint http:\/\/cr.yp.to\/papers.html#cachetiming (2005)"},{"key":"152_CR10","unstructured":"Bernstein, D.J., Schwabe, P.: A word of warning. In: CHES\u201913 Rump Session (2013)"},{"key":"152_CR11","doi-asserted-by":"crossref","unstructured":"Bl\u00f6mer, J., May, A.: New partial key exposure attacks on RSA. In: Advances in Cryptology\u2013CRYPTO 2003: 23rd Annual International Cryptology Conference, pp. 27\u201343. Berlin, Heidelberg (2003)","DOI":"10.1007\/978-3-540-45146-4_2"},{"key":"152_CR12","unstructured":"BoringSSL. https:\/\/boringssl.googlesource.com\/boringssl\/"},{"key":"152_CR13","doi-asserted-by":"crossref","unstructured":"Bos, J., Coster, M.: Addition chain heuristics. In: CRYPTO\u201989, pp. 400\u2013407. Santa Barbara, CA, US (1989)","DOI":"10.1007\/0-387-34805-0_37"},{"key":"152_CR14","unstructured":"Brickell, E.: Technologies to improve platform security. In: CHES\u201911 Invited Talk. URL http:\/\/www.iacr.org\/workshops\/ches\/ches2011\/presentations\/Invited%201\/CHES2011_Invited_1.pdf (2011)"},{"key":"152_CR15","unstructured":"Brickell, Ernie: The impact of cryptography on platform security. In: CT-RSA\u201912 Invited Talk. URL http:\/\/www.rsaconference.com\/writable\/presentations\/file_upload\/cryp-106.pdf (2012)"},{"key":"152_CR16","unstructured":"Brickell, E., Graunke, G., Seifert, J.-P.: Mitigating cache\/timing based side-channels in AES and RSA software implementations. In: RSA Conference 2006 session DEV-203, (2006)"},{"key":"152_CR17","doi-asserted-by":"crossref","unstructured":"Brumley, B.B., Hakala, R.M.: Cache-timing template attacks. In: 15th ASIACRYPT, pp. 667\u2013684. Tokyo (2009)","DOI":"10.1007\/978-3-642-10366-7_39"},{"key":"152_CR18","doi-asserted-by":"crossref","unstructured":"Brumley, B.B., Tuveri, N.: Remote timing attacks are still practical. In: 16th ESORICS, Leuven, BE (2011)","DOI":"10.1007\/978-3-642-23822-2_20"},{"key":"152_CR19","unstructured":"Brumley, D., Boneh, D.: Remote timing attacks are practical. In: 12th USENIX Security, pp. 1\u201314. Washington, DC, US (2003)"},{"key":"152_CR20","unstructured":"Fog, A.: How to optimize for the Pentium processor. https:\/\/notendur.hi.is\/hh\/kennsla\/sti\/h96\/pentopt.txt (1996)"},{"key":"152_CR21","unstructured":"Fog, A.: How to optimize for the Pentium family of microprocessors. https:\/\/cr.yp.to\/2005-590\/fog.pdf (2004)"},{"key":"152_CR22","unstructured":"Fog, A.: The microarchitecture of Intel, AMD and VIA CPUs: an optimization guide for assembly programmers and compiler makers. http:\/\/www.agner.org\/optimize\/microarchitecture.pdf (2016)"},{"issue":"2","key":"152_CR23","doi-asserted-by":"publisher","first-page":"140","DOI":"10.1109\/TEC.1959.5219515","volume":"EC\u20138","author":"HL Garner","year":"1959","unstructured":"Garner, H.L.: The residue number system. IRE Trans. Electron. Comput. EC\u20138(2), 140\u2013147 (1959)","journal-title":"IRE Trans. Electron. Comput."},{"key":"152_CR24","doi-asserted-by":"publisher","unstructured":"Ge, Q., Yarom, Y., Cock, D., Heiser, G.: A survey of microarchitectural timing attacks and countermeasures on contemporary hardware. J. Cryptogr. Eng. doi: 10.1007\/s13389-016-0141-6","DOI":"10.1007\/s13389-016-0141-6"},{"key":"152_CR25","doi-asserted-by":"crossref","unstructured":"Genkin, D., Shamir, A., Tromer, E.: RSA key extraction via low-bandwidth acoustic cryptanalysis. In: CRYPTO 2014, pp. 444\u2013461. Santa Barbara, CA, US (2014)","DOI":"10.1007\/978-3-662-44371-2_25"},{"key":"152_CR26","unstructured":"Gopal, V., Guilford, J., Ozturk, E., Feghali, W., Wolrich, G., Dixon, M.: Fast and constant-time implementation of modular exponentiation. In: Embedded Systems and Communications Security, Niagara Falls, NY, US (2009)"},{"issue":"1","key":"152_CR27","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/s13389-012-0031-5","volume":"2","author":"Shay Gueron","year":"2012","unstructured":"Gueron, Shay: Efficient software implementations of modular exponentiation. J. Cryptogr. Eng. 2(1), 31\u201343 (2012)","journal-title":"J. Cryptogr. Eng."},{"key":"152_CR28","doi-asserted-by":"crossref","unstructured":"Heninger, N., Shacham, H.: Reconstructing RSA private keys from random key bits. In: CRYPTO 2009, pp. 1\u201317, Santa Barbara, CA, US (2009)","DOI":"10.1007\/978-3-642-03356-8_1"},{"key":"152_CR29","unstructured":"Hily, S., Zhang, Z., Hammarlund, P.: Resolving false dependencies of speculative load instructions. U.S. Patent 7,603,527, Oct 2009"},{"key":"152_CR30","doi-asserted-by":"crossref","unstructured":"Hu, W.-M.: Reducing timing channels with fuzzy time. In: 1991 Computer Society Symposium. Research Security and Privacy, pp. 8\u201320. Oakland, CA, US (1991)","DOI":"10.1109\/RISP.1991.130768"},{"key":"152_CR31","unstructured":"\u0130nci, M.S., G\u00fclmezo\u011flu, B., Irazoqui, G., Eisenbarth, T., Sunar, B.: Seriously, get off my cloud! Cross-VM RSA key recovery in a public cloud. IACR Cryptology ePrint Archive, Report 2015\/898 (2015)"},{"key":"152_CR32","unstructured":"Intel 64 & IA-32 AORM. Intel 64 and IA-32 Architectures Optimization Reference Manual. Intel Corporation (2012)"},{"key":"152_CR33","doi-asserted-by":"crossref","unstructured":"Irazoqui, G., Eisenbarth, T., Sunar, B.: S$A: A shared cache attack that works across cores and defies VM sandboxing\u2014and its application to AES. In: S&P, San Jose, CA, US (2015a)","DOI":"10.1109\/SP.2015.42"},{"key":"152_CR34","doi-asserted-by":"crossref","unstructured":"Irazoqui, G., Eisenbarth, T., Sunar, B.: Systematic reverse engineering of cache slice selection in Intel processors. In: Euromicro Conference on Digital System Design, Funchal, Madeira, Portugal (2015b)","DOI":"10.1109\/DSD.2015.56"},{"key":"152_CR35","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., Jun, B.: Differential power analysis. In: CRYPTO, vol. 1666, LNCS, pp. 388\u2013397 (1999)","DOI":"10.1007\/3-540-48405-1_25"},{"key":"152_CR36","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/s13389-011-0006-y","volume":"1","author":"P Kocher","year":"2011","unstructured":"Kocher, P., Jaffe, J., Jun, B., Rohatgi, P.: Introduction to differential power analysis. J. Cryptogr. Eng. 1, 5\u201327 (2011)","journal-title":"J. Cryptogr. Eng."},{"key":"152_CR37","doi-asserted-by":"crossref","unstructured":"Kocher, P.C.: Timing attacks on implementations of Diffie\u2013Hellman, RSA, DSS, and other systems. In: 16th Annual International Cryptology Conference on Advances in Cryptology, pp. 104\u2013113. Springer (1996)","DOI":"10.1007\/3-540-68697-5_9"},{"key":"152_CR38","doi-asserted-by":"publisher","first-page":"613","DOI":"10.1145\/362375.362389","volume":"16","author":"BW Lampson","year":"1973","unstructured":"Lampson, B.W.: A note on the confinement problem. CACM 16, 613\u2013615 (1973)","journal-title":"CACM"},{"key":"152_CR39","unstructured":"LibreSSL Project. https:\/\/www.libressl.org"},{"key":"152_CR40","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., Lee, R.B.: Last-level cache side-channel attacks are practical. In: S&P, pp. 605\u2013622. San Jose, CA, US (2015)","DOI":"10.1109\/SP.2015.43"},{"key":"152_CR41","doi-asserted-by":"crossref","unstructured":"Maurice, C., Le Scouarnec, N., Neumann, C., Heen, O., Francillon, A.: Reverse engineering Intel last-level cache complex addressing using performance counters. In: RAID, Kyoto, Japan (2015)","DOI":"10.1007\/978-3-319-26362-5_3"},{"key":"152_CR42","unstructured":"Mozilla. Network security services. https:\/\/developer.mozilla.org\/en-US\/docs\/Mozilla\/Projects\/NSS"},{"key":"152_CR43","unstructured":"Neve, M., Seifert, J.-P.: Advances on access-driven cache attacks on AES. In: 13th International Workshop on Selected Areas in Cryptography, Montreal, CA (2006)"},{"key":"152_CR44","unstructured":"OpenSSL Project. https:\/\/openssl.org"},{"key":"152_CR45","doi-asserted-by":"crossref","unstructured":"Osvik, D.A., Shamir, A., Tromer, E.: Cache attacks and countermeasures: the case of AES. In: 2006 CT-RSA (2006)","DOI":"10.1007\/11605805_1"},{"key":"152_CR46","unstructured":"Percival, C.: Cache missing for fun and profit. In: BSDCan 2005, Ottawa, CA (2005)"},{"key":"152_CR47","unstructured":"Pessl, P., Gruss, D., Maurice, C., Schwarz, M., Mangard, S.: Reverse engineering Intel DRAM addressing and exploitation. arXiv preprint arXiv:1511.08756 (2015)"},{"key":"152_CR48","doi-asserted-by":"crossref","unstructured":"Quisquater, J.-J., Samyde, D.: Electromagnetic analysis (EMA): measures and counter-measures for smart cards. In: E-Smart\u201901, pp. 200\u2013210. Cannes, FR (2001)","DOI":"10.1007\/3-540-45418-7_17"},{"key":"152_CR49","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1145\/359340.359342","volume":"21","author":"RL Rivest","year":"1978","unstructured":"Rivest, R.L., Shamir, A., Adleman, L.: A method for obtaining digital signatures and public-key cryptosystems. CACM 21, 120\u2013126 (1978)","journal-title":"CACM"},{"issue":"1","key":"152_CR50","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/s00145-009-9049-y","volume":"23","author":"E Tromer","year":"2010","unstructured":"Tromer, E., Osvik, D.A., Shamir, A.: Efficient cache attacks on AES, and countermeasures. J. Cryptol. 23(1), 37\u201371 (2010)","journal-title":"J. Cryptol."},{"key":"152_CR51","doi-asserted-by":"crossref","unstructured":"van\u00a0de Pol, J., Smart, N.P., Yarom, Y.: Just a little bit more. In: 2015 CT-RSA, pp. 3\u201321. San Francisco, CA, USA (2015)","DOI":"10.1007\/978-3-319-16715-2_1"},{"key":"152_CR52","doi-asserted-by":"crossref","unstructured":"Wang, Y., Suh, G.E.: Efficient timing channel protection for on-chip networks. In: 6th NoCS, pp. 142\u2013151, Lyngby, Denmark (2012)","DOI":"10.1109\/NOCS.2012.24"},{"key":"152_CR53","unstructured":"Wu, Z., Xu, Z., Wang, H.: Whispers in the hyper-space: high-speed covert channel attacks in the cloud. In: 21st USENIX Security, Bellevue, WA, US (2012)"},{"key":"152_CR54","unstructured":"Yarom, Y., Falkner, K.: Flush+Reload: a high resolution, low noise, L3 cache side-channel attack. In: 23rd USENIX Security, pp. 719\u2013732. San Diego, CA, US (2014)"},{"key":"152_CR55","unstructured":"Yarom, Y., Ge, Q., Liu, F., Lee, R.B., Heiser, G.: Mapping the Intel last-level cache. http:\/\/eprint.iacr.org\/ (2015)"},{"key":"152_CR56","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-VM side channels and their use to extract private keys. In: 19th CCS, pp. 305\u2013316. Raleigh, NC, US (2012)","DOI":"10.1145\/2382196.2382230"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-017-0152-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s13389-017-0152-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-017-0152-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,15]],"date-time":"2025-06-15T08:23:36Z","timestamp":1749975816000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s13389-017-0152-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,11]]},"references-count":56,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2017,6]]}},"alternative-id":["152"],"URL":"https:\/\/doi.org\/10.1007\/s13389-017-0152-y","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,11]]},"assertion":[{"value":"15 November 2016","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 January 2017","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 February 2017","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}