{"id":"https://openalex.org/W4385080289","doi":"https://doi.org/10.1109/sp46215.2023.10179368","title":"SQUIP: Exploiting the Scheduler Queue Contention Side Channel","display_name":"SQUIP: Exploiting the Scheduler Queue Contention Side Channel","publication_year":2023,"publication_date":"2023-05-01","ids":{"openalex":"https://openalex.org/W4385080289","doi":"https://doi.org/10.1109/sp46215.2023.10179368"},"language":"en","primary_location":{"id":"doi:10.1109/sp46215.2023.10179368","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46215.2023.10179368","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072143806","display_name":"Stefan Gast","orcid":"https://orcid.org/0009-0007-1229-3962"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":true,"raw_author_name":"Stefan Gast","raw_affiliation_strings":["Lamarr Security Research","Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Lamarr Security Research","institution_ids":[]},{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090883929","display_name":"Jonas Juffinger","orcid":"https://orcid.org/0009-0002-0569-1704"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Jonas Juffinger","raw_affiliation_strings":["Lamarr Security Research","Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Lamarr Security Research","institution_ids":[]},{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051619555","display_name":"Martin Schwarzl","orcid":"https://orcid.org/0009-0002-3760-1929"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Martin Schwarzl","raw_affiliation_strings":["Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071514906","display_name":"Gururaj Saileshwar","orcid":"https://orcid.org/0000-0003-3542-2548"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gururaj Saileshwar","raw_affiliation_strings":["Georgia Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063363138","display_name":"Andreas Kogler","orcid":"https://orcid.org/0009-0003-7314-9033"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Andreas Kogler","raw_affiliation_strings":["Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092519516","display_name":"Simone Franza","orcid":"https://orcid.org/0009-0008-8150-7749"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Simone Franza","raw_affiliation_strings":["Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092519517","display_name":"Markus K\u00f6stl","orcid":null},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Markus K\u00f6stl","raw_affiliation_strings":["Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5066874310","display_name":"Daniel Gruss","orcid":"https://orcid.org/0000-0002-7977-3246"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Daniel Gruss","raw_affiliation_strings":["Graz University of Technology"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology","institution_ids":["https://openalex.org/I4092182"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5072143806"],"corresponding_institution_ids":["https://openalex.org/I4092182"],"apc_list":null,"apc_paid":null,"fwci":3.5682,"has_fulltext":false,"cited_by_count":20,"citation_normalized_percentile":{"value":0.94193851,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"2256","last_page":"2272"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9864000082015991,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9855999946594238,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8235710263252258},{"id":"https://openalex.org/keywords/side-channel-attack","display_name":"Side channel attack","score":0.6839173436164856},{"id":"https://openalex.org/keywords/queue","display_name":"Queue","score":0.5302861332893372},{"id":"https://openalex.org/keywords/scheduling","display_name":"Scheduling (production processes)","score":0.4846263825893402},{"id":"https://openalex.org/keywords/parallel-computing","display_name":"Parallel computing","score":0.4436548054218292},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.3722410798072815},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.3224886953830719},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.2099795937538147},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.1846117079257965},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.10464516282081604}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8235710263252258},{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.6839173436164856},{"id":"https://openalex.org/C160403385","wikidata":"https://www.wikidata.org/wiki/Q220543","display_name":"Queue","level":2,"score":0.5302861332893372},{"id":"https://openalex.org/C206729178","wikidata":"https://www.wikidata.org/wiki/Q2271896","display_name":"Scheduling (production processes)","level":2,"score":0.4846263825893402},{"id":"https://openalex.org/C173608175","wikidata":"https://www.wikidata.org/wiki/Q232661","display_name":"Parallel computing","level":1,"score":0.4436548054218292},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3722410798072815},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.3224886953830719},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.2099795937538147},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.1846117079257965},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.10464516282081604},{"id":"https://openalex.org/C21547014","wikidata":"https://www.wikidata.org/wiki/Q1423657","display_name":"Operations management","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46215.2023.10179368","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46215.2023.10179368","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":42,"referenced_works":["https://openalex.org/W1488058190","https://openalex.org/W1494212869","https://openalex.org/W1589576271","https://openalex.org/W1660562555","https://openalex.org/W1934458198","https://openalex.org/W2037322308","https://openalex.org/W2056778557","https://openalex.org/W2104182023","https://openalex.org/W2109235078","https://openalex.org/W2119028650","https://openalex.org/W2502815150","https://openalex.org/W2586555532","https://openalex.org/W2612454599","https://openalex.org/W2770572532","https://openalex.org/W2775990858","https://openalex.org/W2782868422","https://openalex.org/W2793118248","https://openalex.org/W2903035991","https://openalex.org/W2934166125","https://openalex.org/W2954241526","https://openalex.org/W2963311060","https://openalex.org/W2976763854","https://openalex.org/W2999057964","https://openalex.org/W3008086078","https://openalex.org/W3029114445","https://openalex.org/W3036003802","https://openalex.org/W3153001680","https://openalex.org/W3210302253","https://openalex.org/W4230470671","https://openalex.org/W4238305024","https://openalex.org/W4281401510","https://openalex.org/W4288086178","https://openalex.org/W4299301436","https://openalex.org/W6628261430","https://openalex.org/W6631841752","https://openalex.org/W6635166818","https://openalex.org/W6720892955","https://openalex.org/W6754306559","https://openalex.org/W6778029803","https://openalex.org/W6801391798","https://openalex.org/W6902533906","https://openalex.org/W7071262805"],"related_works":["https://openalex.org/W4323824501","https://openalex.org/W4200321003","https://openalex.org/W2355552010","https://openalex.org/W4236373173","https://openalex.org/W2136687465","https://openalex.org/W5280335","https://openalex.org/W4252980856","https://openalex.org/W3215861253","https://openalex.org/W4200163172","https://openalex.org/W2981727040"],"abstract_inverted_index":{"Modern":[0],"superscalar":[1,65],"CPUs":[2,81,131],"have":[3,69,83,113],"multiple":[4],"execution":[5,27,118],"units":[6],"that":[7,19,134],"independently":[8],"execute":[9],"operations":[10],"from":[11,148,173,188],"the":[12,42,45,57,94,99,103,123,126,145,150,160,163,202],"instruction":[13],"stream.":[14],"Previous":[15],"work":[16],"has":[17],"shown":[18],"numerous":[20],"side":[21,75,203],"channels":[22],"exist":[23],"around":[24],"these":[25,130],"out-of-order":[26],"pipelines,":[28],"particularly":[29],"for":[30,55,248],"an":[31,35,179,193,206],"attacker":[32],"running":[33],"on":[34,49,129,205,240],"SMT":[36,156],"core.In":[37],"this":[38],"paper,":[39],"we":[40,243],"present":[41],"SQUIP":[43,142,164],"attack,":[44],"first":[46,121],"side-channel":[47],"attack":[48,143,165,222],"scheduler":[50,86,115,127],"queues,":[51],"which":[52],"are":[53],"critical":[54],"deciding":[56],"schedule":[58],"of":[59,98,125,162],"instructions":[60],"to":[61,236,255],"be":[62,92,137],"executed":[63],"in":[64,166,211,216],"CPUs.":[66],"Scheduler":[67],"queues":[68,116,128],"not":[70],"been":[71],"explored":[72],"as":[73,79,96],"a":[74,84,167,174,189,212,217],"channel":[76,204],"so":[77],"far,":[78],"Intel":[80],"only":[82,228],"single":[85],"queue,":[87],"and":[88,109,132,139,154,185,215,232,251],"contention":[89,97],"thereof":[90],"would":[91],"virtually":[93],"same":[95,151],"reorder":[100],"buffer.":[101],"However,":[102],"Apple":[104],"M1,":[105],"AMD":[106],"Zen":[107,110,249,252],"2,":[108],"3":[111,253],"microarchitectures":[112],"separate":[114],"per":[117],"unit.":[119],"We":[120,158,199],"reverse-engineer":[122],"behavior":[124],"show":[133],"they":[135],"can":[136],"primed":[138],"probed.":[140],"The":[141],"observes":[144],"occupancy":[146],"level":[147],"within":[149],"hardware":[152],"core":[153],"across":[155],"threads.":[157],"evaluate":[159],"performance":[161],"covert":[168],"channel,":[169],"exfiltrating":[170],"0.89":[171],"Mbit/s":[172,187],"co-located":[175,190,213,218],"virtual":[176,219],"machine":[177],"at":[178,192],"error":[180,194],"rate":[181,195],"below":[182,196],"0.8":[183,197],"%,":[184],"2.70":[186],"process":[191,210,214],"%.":[198],"then":[200],"demonstrate":[201],"mbedTLS":[207],"RSA":[208],"signature":[209],"machine.":[220],"Our":[221],"recovers":[223],"full":[224],"RSA-4096":[225],"keys":[226],"with":[227],"50":[229],"500":[230],"traces":[231],"less":[233],"than":[234],"5":[235],"18":[237],"bit":[238],"errors":[239],"average.":[241],"Finally,":[242],"discuss":[244],"mitigations":[245],"necessary,":[246],"especially":[247],"2":[250],"systems,":[254],"prevent":[256],"our":[257],"attacks.":[258]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":9},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":1}],"updated_date":"2026-03-06T13:50:29.536080","created_date":"2025-10-10T00:00:00"}
