{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T09:50:57Z","timestamp":1781949057701,"version":"3.54.5"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T00:00:00Z","timestamp":1779753600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T00:00:00Z","timestamp":1779753600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2026,6]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Cryptographic software following sound, modern practices and adhering to recommendations for writing constant-time code (e.g., RFC 7748) may yet leak secret data via the most na\u00efve kind of timing side channels when a \u201csecure\u201d implementation in a high-level language gets compiled down to assembly instructions. This paper shows that it is not only aggressive optimization done by smart compilers that leads to such vulnerabilities, as previously often thought, but also inherent limitations of the target CPU architecture that the compiler must work around, coupled with dangerous recommendations for instruction idioms found in the architecture documentation. The popular customizable IP core, Xtensa, is identified to be affected by the problem, and its particular vulnerability is studied and exploited. Key-recovery attacks are conducted against Xtensa-based ESP32 chips running ephemeral-static X25519 implementations found in wolfSSL and CycloneCRYPTO, both advertised as resistant against timing attacks and using two unrelated implementation strategies. The attacks are four orders of magnitude more effective than a similar attack against a related vulnerability in the MSVC compiler known in the literature. A resolution of the compiler bug responsible for the vulnerability is proposed. Finally, an optimized implementation of X25519 (Ed25519) and X448 (Ed448) field arithmetic for Xtensa, leveraging a DSP extension to the core instruction set, is proposed.<\/jats:p>","DOI":"10.1007\/s13389-026-00394-y","type":"journal-article","created":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T12:58:17Z","timestamp":1779800297000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["On timing side channels in \u201cconstant-time implementations\u201d"],"prefix":"10.1007","volume":"16","author":[{"given":"Adrian","family":"Cinal","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,26]]},"reference":[{"key":"394_CR1","doi-asserted-by":"crossref","unstructured":"Kocher, P.C.: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In: Koblitz, N. (ed.) Advances in Cryptology \u2013 CRYPTO \u201996, pp. 104\u2013113. Springer, Berlin, Heidelberg (1996)","DOI":"10.1007\/3-540-68697-5_9"},{"key":"394_CR2","doi-asserted-by":"crossref","unstructured":"Dhem, J.-F., Koeune, F., Leroux, P.-A., Mestr\u00e9, P., Quisquater, J.-J., Willems, J.-L.: A practical implementation of the timing attack. In: Quisquater, J.-J., Schneier, B. (eds.) Smart Card Research and Applications, pp. 167\u2013182. Springer, Berlin, Heidelberg (2000)","DOI":"10.1007\/10721064_15"},{"key":"394_CR3","unstructured":"Brumley, D., Boneh, D.: Remote timing attacks are practical. In: 12th USENIX Security Symposium (USENIX Security 03). USENIX Association, Washington, D.C. (2003). https:\/\/www.usenix.org\/conference\/12th-usenix-security-symposium\/remote-timing-attacks-are-practical"},{"issue":"4","key":"394_CR4","first-page":"305","volume":"18","author":"DJ Bernstein","year":"2005","unstructured":"Bernstein, D.J.: Cache-timing attacks on AES. J. Cryptol. 18(4), 305\u2013325 (2005)","journal-title":"J. Cryptol."},{"key":"394_CR5","doi-asserted-by":"crossref","unstructured":"Osvik, D.A., Shamir, A., Tromer, E.: Cache attacks and countermeasures: the case of AES. In: International Workshop on Cryptographic Hardware and Embedded Systems, pp. 1\u201320 (2006). Springer","DOI":"10.1007\/11605805_1"},{"key":"394_CR6","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J.: Curve25519: New Diffie-Hellman speed records. In: Yung, M., Dodis, Y., Kiayias, A., Malkin, T. (eds.) Public Key Cryptography - PKC 2006, pp. 207\u2013228. Springer, Berlin, Heidelberg (2006)","DOI":"10.1007\/11745853_14"},{"key":"394_CR7","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Duif, N., Lange, T., Schwabe, P., Yang, B.-Y.: High-speed high-security signatures. In: Preneel, B., Takagi, T. (eds.) Cryptographic Hardware and Embedded Systems - CHES 2011, pp. 124\u2013142. Springer, Berlin, Heidelberg (2011)","DOI":"10.1007\/978-3-642-23951-9_9"},{"key":"394_CR8","unstructured":"Xu, J., Lu, K., Du, Z., Ding, Z., Li, L., Wu, Q., Payer, M., Mao, B.: Silent bugs matter: A study of compiler-introduced security bugs. In: Proceedings of the 32nd USENIX Security Symposium (2023)"},{"key":"394_CR9","doi-asserted-by":"publisher","unstructured":"D\u2019Silva, V., Payer, M., Song, D.: The correctness-security gap in compiler optimization. In: 2015 IEEE Security and Privacy Workshops, pp. 73\u201387 (2015). https:\/\/doi.org\/10.1109\/SPW.2015.33","DOI":"10.1109\/SPW.2015.33"},{"key":"394_CR10","unstructured":"Scott, M.: On the Deployment of curve based cryptography for the Internet of Things. Cryptology ePrint Archive, Paper 2020\/514. https:\/\/eprint.iacr.org\/2020\/514 (2020)"},{"key":"394_CR11","doi-asserted-by":"publisher","unstructured":"Simon, L., Chisnall, D., Anderson, R.: What you get is what you C: Controlling side effects in mainstream C compilers. In: 2018 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 1\u201315 (2018). https:\/\/doi.org\/10.1109\/EuroSP.2018.00009","DOI":"10.1109\/EuroSP.2018.00009"},{"key":"394_CR12","doi-asserted-by":"crossref","unstructured":"Kaufmann, T., Pelletier, H., Vaudenay, S., Villegas, K.: When constant-time source yields variable-time binary: Exploiting curve25519-donna built with MSVC 2015. In: Foresti, S., Persiano, G. (eds.) Cryptology and Network Security, pp. 573\u2013582. Springer, Cham (2016)","DOI":"10.1007\/978-3-319-48965-0_36"},{"key":"394_CR13","unstructured":"Zhang, Z., Barthe, G.: CT-LLVM: Automatic Large-Scale Constant-Time Analysis. Cryptology ePrint Archive, Paper 2025\/338 (2025). https:\/\/eprint.iacr.org\/2025\/338"},{"key":"394_CR14","unstructured":"Geimer, A., Maurice, C.: Fun with flags: How Compilers Break and Fix Constant-Time Code (2025). arxiv:2507.06112"},{"key":"394_CR15","doi-asserted-by":"crossref","unstructured":"Wall, S., Arranz\u00a0Olmos, S., Barthe, G., Blatter, L., Bouzid, Y., Zhang, Z.: Decompiling for constant-time analysis. In: Proceedings of the ACM SIGPLAN Workshop on Programming Languages and Analysis for Security (PriSC 2026), Rennes, France (2026). Co-located with POPL 2026","DOI":"10.1145\/3798201"},{"key":"394_CR16","doi-asserted-by":"crossref","unstructured":"Gerlach, L., Pietsch, R., Schwarz, M.: Do compilers break constant-time guarantees? In: Garman, C., Moreno-Sanchez, P. (eds.) Financial Cryptography and Data Security, pp. 327\u2013344. Springer, Cham (2026)","DOI":"10.1007\/978-3-032-07035-7_20"},{"key":"394_CR17","doi-asserted-by":"crossref","unstructured":"Langley, A., Hamburg, M., Turner, S.: Elliptic Curves for Security. RFC 7748. Available at https:\/\/www.rfc-editor.org\/info\/rfc7748 (2016)","DOI":"10.17487\/RFC7748"},{"key":"394_CR18","unstructured":"Inc, T.: Xtensa Instruction Set Architecture. (ISA), Reference Manual (2010)"},{"key":"394_CR19","unstructured":"Inc, C.D.S.: Xtensa Instruction Set Architecture. (ISA), Summary (2022)"},{"key":"394_CR20","unstructured":"Killian, E.: Xtensa: A New ISA and Approach. http:\/\/bwrcs.eecs.berkeley.edu\/Classes\/CS252\/Notes\/xtensa_022400.pdf Accessed 3 November 2023"},{"issue":"3","key":"394_CR21","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/s13389-017-0157-6","volume":"8","author":"C Costello","year":"2018","unstructured":"Costello, C., Smith, B.: Montgomery curves and their arithmetic. J. Cryptogr. Eng. 8(3), 227\u2013240 (2018). https:\/\/doi.org\/10.1007\/s13389-017-0157-6","journal-title":"J. Cryptogr. Eng."},{"key":"394_CR22","doi-asserted-by":"crossref","unstructured":"Brumley, B.B., Tuveri, N.: Remote timing attacks are still practical. In: Atluri, V., Diaz, C. (eds.) Computer Security - ESORICS 2011, pp. 355\u2013371. Springer, Berlin, Heidelberg (2011)","DOI":"10.1007\/978-3-642-23822-2_20"},{"key":"394_CR23","doi-asserted-by":"crossref","unstructured":"Joye, M., Tymen, C.: Protections against differential analysis for elliptic curve cryptography \u2013 an algebraic approach \u2013. In: Ko\u00e7, \u00c7.K., Naccache, D., Paar, C. (eds.) Cryptographic Hardware and Embedded Systems \u2013 CHES 2001, pp. 377\u2013390. Springer, Berlin, Heidelberg (2001)","DOI":"10.1007\/3-540-44709-1_31"},{"issue":"143","key":"394_CR24","first-page":"918","volume":"32","author":"JM Pollard","year":"1978","unstructured":"Pollard, J.M.: Monte Carlo methods for index computation (mod p). Math. Comput. 32(143), 918\u2013924 (1978)","journal-title":"Math. Comput."},{"key":"394_CR25","doi-asserted-by":"publisher","unstructured":"Micheli, G.D., Heninger, N.: Survey: Recovering cryptographic keys from partial information, by example. IACR Communications in Cryptology 1(1) (2024) https:\/\/doi.org\/10.62056\/ahjbksdja","DOI":"10.62056\/ahjbksdja"},{"key":"394_CR26","unstructured":"Hansen, T., 3rd, D.E.E.: US Secure Hash Algorithms (SHA and SHA-based HMAC and HKDF). RFC 6234 (2011). https:\/\/www.rfc-editor.org\/info\/rfc6234"},{"key":"394_CR27","unstructured":"Hamburg, M.: Ed448-Goldilocks, a new elliptic curve. Cryptology ePrint Archive, Paper 2015\/625. https:\/\/eprint.iacr.org\/2015\/625 (2015)"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-026-00394-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-026-00394-y","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-026-00394-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T09:18:33Z","timestamp":1781947113000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-026-00394-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,26]]},"references-count":27,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["394"],"URL":"https:\/\/doi.org\/10.1007\/s13389-026-00394-y","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,26]]},"assertion":[{"value":"17 June 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"9"}}