{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T18:23:36Z","timestamp":1740162216529,"version":"3.37.3"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2024,1,5]],"date-time":"2024-01-05T00:00:00Z","timestamp":1704412800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,5]],"date-time":"2024-01-05T00:00:00Z","timestamp":1704412800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2024,6]]},"DOI":"10.1007\/s13389-023-00344-y","type":"journal-article","created":{"date-parts":[[2024,1,5]],"date-time":"2024-01-05T16:02:52Z","timestamp":1704470572000},"page":"281-294","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Breaking KASLR on mobile devices without any use of cache memory (extended version)"],"prefix":"10.1007","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7340-5269","authenticated-orcid":false,"given":"Milad","family":"Seddigh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7674-7600","authenticated-orcid":false,"given":"Mahdi","family":"Esfahani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4190-2671","authenticated-orcid":false,"given":"Sarani","family":"Bhattacharya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4321-0345","authenticated-orcid":false,"given":"Mohammad Reza","family":"Aref","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3961-4988","authenticated-orcid":false,"given":"Hadi","family":"Soleimany","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,1,5]]},"reference":[{"key":"344_CR1","unstructured":"ARM LIMITED: Cortex-A57 MPCore Processor Revision: r1p3 Technical Reference Manual (2017). http:\/\/infocenter.arm.com\/help\/topic\/com"},{"key":"344_CR2","unstructured":"Arm Architecture Reference Manual Armv8, for A-profile architecture (2021a). https:\/\/developer.arm.com\/documentation\/ddi0487\/gb\/"},{"key":"344_CR3","unstructured":"Armv8.5-A CPU Updates\u2014Arm Developer (2021b). https:\/\/developer.arm.com"},{"key":"344_CR4","doi-asserted-by":"crossref","unstructured":"Canella, C., Schwarz, M., Haubenwallner, M., Schwarzl, M., Gruss, D.: KASLR: break it, fix it, repeat. In: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, pp. 481\u2013493 (2020)","DOI":"10.1145\/3320269.3384747"},{"key":"344_CR5","doi-asserted-by":"publisher","unstructured":"Evtyushkin, D., Ponomarev, D.V., Abu-Ghazaleh, N.B.: Jump over ASLR: attacking branch predictors to bypass ASLR. In: 49th Annual IEEE\/ACM International Symposium on Microarchitecture, MICRO: Taipei, Taiwan, October 15\u201319, 2016, vol. 40, no. 1\u201340, p. 13. IEEE Computer Society (2016). https:\/\/doi.org\/10.1109\/MICRO.2016.7783743","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"344_CR6","unstructured":"Gras, B., Razavi, K., Bos, H., Giuffrida, C.: Translation leak-aside buffer: defeating cache side-channel protections with TLB attacks. In: Enck, W., Felt, A.P. (eds.) 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15\u201317, 2018, pp. 955\u2013972. USENIX Association (2018). https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/gras"},{"key":"344_CR7","doi-asserted-by":"crossref","unstructured":"Gras, B., Razavi, K., Bosman, E., Bos, H., Giuffrida, C.: ASLR on the line: practical cache attacks on the MMU. In: NDSS, vol. 17, p. 26 (2017)","DOI":"10.14722\/ndss.2017.23271"},{"issue":"4","key":"344_CR8","first-page":"10","volume":"43","author":"D Gruss","year":"2018","unstructured":"Gruss, D., Hansen, D., Brendan, G.: Kernel isolation: from an academic idea to an efficient patch for every computer. Login USENIX Mag. 43(4), 10\u201314 (2018)","journal-title":"Login USENIX Mag."},{"key":"344_CR9","doi-asserted-by":"publisher","unstructured":"Gruss, D., Maurice, C., Fogh, A., Lipp, M., Mangard, S.: Prefetch side-channel attacks: bypassing SMAP and kernel ASLR. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, October 24\u201328, pp. 368\u2013379. ACM (2016). https:\/\/doi.org\/10.1145\/2976749.2978356","DOI":"10.1145\/2976749.2978356"},{"key":"344_CR10","unstructured":"Hansen, D.: KAISER: unmap most of the kernel from userspace page table. Linux Kernel Mailing List (2017)"},{"key":"344_CR11","doi-asserted-by":"publisher","unstructured":"Hund, R., Willems, C., Holz, T.: Practical timing side channel attacks against kernel space ASLR. In: 2013 IEEE Symposium on Security and Privacy, SP 2013, Berkeley, CA, USA, May 19\u201322, pp. 191\u2013205. IEEE Computer Society (2013). https:\/\/doi.org\/10.1109\/SP.2013.23","DOI":"10.1109\/SP.2013.23"},{"key":"344_CR12","doi-asserted-by":"publisher","unstructured":"Jang, Y., Lee, S., Kim, T.: Breaking kernel address space layout randomization with intel TSX. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, October 24\u201328, pp. 380\u2013392. ACM (2016). https:\/\/doi.org\/10.1145\/2976749.2978321","DOI":"10.1145\/2976749.2978321"},{"key":"344_CR13","unstructured":"Johnson, K.: KVA Shadow: Mitigating Meltdown on Windows (2018)"},{"key":"344_CR14","doi-asserted-by":"publisher","unstructured":"Kocher, P., Horn, J., Fogh, A., Genkin, D., Gruss, D., Haas, W., Hamburg, M., Lipp, M., Mangard, S., Prescher, T., Schwarz, M.: Spectre attacks: exploiting speculative execution. In: 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May 19\u201323, pp. 1\u201319. IEEE (2019). https:\/\/doi.org\/10.1109\/SP.2019.00002","DOI":"10.1109\/SP.2019.00002"},{"key":"344_CR15","unstructured":"Linux: Complete Virtual Memory Map with 4-Level Page Tables (2019). https:\/\/www.kernel.org\/doc\/Documentation\/x86\/x86_64\/mm.txt"},{"key":"344_CR16","unstructured":"Lipp, M., Gruss, D., Spreitzer, R., Maurice, C., Mangard, S.: ARMageddon: cache attacks on mobile devices. In: Holz, T., Savage, S. (eds.) 25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10\u201312, pp. 549\u2013564. USENIX Association (2016). https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/lipp"},{"key":"344_CR17","doi-asserted-by":"crossref","unstructured":"Lipp, M., Kogler, A., Oswald, D., Schwarz, M., Easdon, C., Canella, C., Gruss, D.: PLATYPUS: Software-based power side-channel attacks on x86. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 355\u2013371. IEEE (2021)","DOI":"10.1109\/SP40001.2021.00063"},{"issue":"6","key":"344_CR18","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1145\/3357033","volume":"63","author":"M Lipp","year":"2020","unstructured":"Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Horn, J., Mangard, S., Kocher, P., Genkin, D., Yarom, Y., Hamburg, M., Strackx, R.: Meltdown: reading kernel memory from user space. Commun. ACM 63(6), 46\u201356 (2020). https:\/\/doi.org\/10.1145\/3357033","journal-title":"Commun. ACM"},{"key":"344_CR19","unstructured":"Minkin, M., Moghimi, D., Lipp, M., Schwarz, M., Van Bulck, J., Genkin, D., Gruss, D., Piessens, F., Sunar, B., Yarom, Y.: Fallout: Reading Kernel Writes From User Space (2019). arXiv:1905.12701"},{"key":"344_CR20","doi-asserted-by":"crossref","unstructured":"Oren, Y., Kemerlis, V.P., Sethumadhavan, S., Keromytis, A.D.: The spy in the sandbox: practical cache attacks in Javascript and their implications. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1406\u20131418 (2015)","DOI":"10.1145\/2810103.2813708"},{"key":"344_CR21","unstructured":"Schwarz, M., Canella, C., Giner, L., Gruss, D.: Store-to-Leak Forwarding: Leaking Data on Meltdown-resistant CPUs. CoRR (2019a). arXiv:1905.05725"},{"key":"344_CR22","doi-asserted-by":"publisher","unstructured":"Schwarz, M., Lipp, M., Moghimi, D., Van Bulck, J., Stecklina, J., Prescher, T., Gruss, D.: ZombieLoad: cross-privilege-boundary data sampling. In: Cavallaro, L., Kinder, J., Wang, X., Katz, J. (eds.) Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, CCS 2019, London, UK, November 11\u201315, pp. 753\u2013768. ACM (2019b). https:\/\/doi.org\/10.1145\/3319535.3354252","DOI":"10.1145\/3319535.3354252"},{"key":"344_CR23","doi-asserted-by":"crossref","unstructured":"Schwarz, M., Maurice, C., Gruss, D., Mangard, S.: Fantastic timers and where to find them: high-resolution microarchitectural attacks in JavaScript. In: International Conference on Financial Cryptography and Data Security, pp. 247\u2013267. Springer (2017)","DOI":"10.1007\/978-3-319-70972-7_13"},{"key":"344_CR24","doi-asserted-by":"publisher","unstructured":"van Schaik, S., Milburn, A., \u00d6sterlund, S., Frigo, P., Maisuradze, G., Razavi, K., Bos, H., Giuffrida, C.: RIDL: Rogue In-Flight Data Load, pp. 88\u2013105 (2019). https:\/\/doi.org\/10.1109\/SP.2019.00087","DOI":"10.1109\/SP.2019.00087"},{"key":"344_CR25","unstructured":"Vulnerability of Speculative Processors to Cache Timing Side-Channel Mechanism (2021). https:\/\/developer.arm.com\/support\/arm-security-updates\/speculative-processor-vulnerability"},{"key":"344_CR26","unstructured":"Williamson: Line allocation in multi-level hierarchical data stores. Patent US8271733 B2, ARM Limited. In: 26th USENIX Security Symposium, USENIX Security 2017, Vancouver, BC, Canada, August 16\u201318, pp. 1075\u20131091. USENIX Association (2012)"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-023-00344-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-023-00344-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-023-00344-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,4]],"date-time":"2024-07-04T09:39:38Z","timestamp":1720085978000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-023-00344-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,5]]},"references-count":26,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,6]]}},"alternative-id":["344"],"URL":"https:\/\/doi.org\/10.1007\/s13389-023-00344-y","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"type":"print","value":"2190-8508"},{"type":"electronic","value":"2190-8516"}],"subject":[],"published":{"date-parts":[[2024,1,5]]},"assertion":[{"value":"23 June 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 November 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 January 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}