{"id":"https://openalex.org/W4400224051","doi":"https://doi.org/10.1145/3676641.3716015","title":"Protecting Cryptographic Code Against Spectre-RSB: (and, in Fact, All Known Spectre Variants)","display_name":"Protecting Cryptographic Code Against Spectre-RSB: (and, in Fact, All Known Spectre Variants)","publication_year":2025,"publication_date":"2025-03-27","ids":{"openalex":"https://openalex.org/W4400224051","doi":"https://doi.org/10.1145/3676641.3716015"},"language":"en","primary_location":{"id":"doi:10.1145/3676641.3716015","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3676641.3716015","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3676641.3716015","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072062100","display_name":"Santiago Arranz Olmos","orcid":null},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Santiago Arranz Olmos","raw_affiliation_strings":["MPI-SP, Bochum, Germany"],"affiliations":[{"raw_affiliation_string":"MPI-SP, Bochum, Germany","institution_ids":["https://openalex.org/I4210096592"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075577852","display_name":"Gilles Barthe","orcid":"https://orcid.org/0000-0002-3853-1777"},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]},{"id":"https://openalex.org/I4210162154","display_name":"IMDEA Software Institute","ror":"https://ror.org/04xvfkh51","country_code":"ES","type":"facility","lineage":["https://openalex.org/I105140100","https://openalex.org/I4210162154"]}],"countries":["DE","ES"],"is_corresponding":false,"raw_author_name":"Gilles Barthe","raw_affiliation_strings":["MPI-SP, Bochum, Germany and IMDEA Software Institute, Madrid, Spain"],"affiliations":[{"raw_affiliation_string":"MPI-SP, Bochum, Germany and IMDEA Software Institute, Madrid, Spain","institution_ids":["https://openalex.org/I4210162154","https://openalex.org/I4210096592"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091908047","display_name":"Chitchanok Chuengsatiansup","orcid":"https://orcid.org/0000-0002-0329-2681"},"institutions":[{"id":"https://openalex.org/I165779595","display_name":"The University of Melbourne","ror":"https://ror.org/01ej9dk98","country_code":"AU","type":"education","lineage":["https://openalex.org/I165779595"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Chitchanok Chuengsatiansup","raw_affiliation_strings":["University of Melbourne, Melbourne, Australia"],"affiliations":[{"raw_affiliation_string":"University of Melbourne, Melbourne, Australia","institution_ids":["https://openalex.org/I165779595"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103256238","display_name":"Benjamin Gr\u00e9goire","orcid":"https://orcid.org/0000-0001-6650-9924"},"institutions":[{"id":"https://openalex.org/I1326498283","display_name":"Institut national de recherche en sciences et technologies du num\u00e9rique","ror":"https://ror.org/02kvxyf05","country_code":"FR","type":"government","lineage":["https://openalex.org/I1326498283"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Benjamin Gregoire","raw_affiliation_strings":["Inria, Sophia Antipolis, France"],"affiliations":[{"raw_affiliation_string":"Inria, Sophia Antipolis, France","institution_ids":["https://openalex.org/I1326498283"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088318447","display_name":"Vincent Laporte","orcid":"https://orcid.org/0000-0002-3468-352X"},"institutions":[{"id":"https://openalex.org/I1294671590","display_name":"Centre National de la Recherche Scientifique","ror":"https://ror.org/02feahw73","country_code":"FR","type":"government","lineage":["https://openalex.org/I1294671590"]},{"id":"https://openalex.org/I4210121838","display_name":"Laboratoire Lorrain de Recherche en Informatique et ses Applications","ror":"https://ror.org/02vnf0c38","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I1294671590","https://openalex.org/I1326498283","https://openalex.org/I277688954","https://openalex.org/I4210107720","https://openalex.org/I4210121838","https://openalex.org/I4210159245","https://openalex.org/I90183372"]},{"id":"https://openalex.org/I90183372","display_name":"Universit\u00e9 de Lorraine","ror":"https://ror.org/04vfs2w97","country_code":"FR","type":"education","lineage":["https://openalex.org/I90183372"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Vincent Laporte","raw_affiliation_strings":["Universit\u00e9 de Lorraine, CNRS, Inria, LORIA, Nancy, France"],"affiliations":[{"raw_affiliation_string":"Universit\u00e9 de Lorraine, CNRS, Inria, LORIA, Nancy, France","institution_ids":["https://openalex.org/I90183372","https://openalex.org/I4210121838","https://openalex.org/I1294671590"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085787959","display_name":"Tiago Oliveira","orcid":"https://orcid.org/0000-0001-7395-3070"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tiago Oliveira","raw_affiliation_strings":["Sandbox AQ, Palo Alto, CA, USA"],"affiliations":[{"raw_affiliation_string":"Sandbox AQ, Palo Alto, CA, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074344027","display_name":"Peter Schwabe","orcid":"https://orcid.org/0000-0002-1310-0997"},"institutions":[{"id":"https://openalex.org/I145872427","display_name":"Radboud University Nijmegen","ror":"https://ror.org/016xsfp80","country_code":"NL","type":"education","lineage":["https://openalex.org/I145872427"]},{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]}],"countries":["DE","NL"],"is_corresponding":false,"raw_author_name":"Peter Schwabe","raw_affiliation_strings":["MPI-SP, Bochum, Germany and Radboud University, Nijmegen, Netherlands"],"affiliations":[{"raw_affiliation_string":"MPI-SP, Bochum, Germany and Radboud University, Nijmegen, Netherlands","institution_ids":["https://openalex.org/I4210096592","https://openalex.org/I145872427"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056484605","display_name":"Yuval Yarom","orcid":"https://orcid.org/0000-0003-0401-4197"},"institutions":[{"id":"https://openalex.org/I904495901","display_name":"Ruhr University Bochum","ror":"https://ror.org/04tsk2644","country_code":"DE","type":"education","lineage":["https://openalex.org/I904495901"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Yuval Yarom","raw_affiliation_strings":["Ruhr University Bochum, Bochum, Germany"],"affiliations":[{"raw_affiliation_string":"Ruhr University Bochum, Bochum, Germany","institution_ids":["https://openalex.org/I904495901"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100403360","display_name":"Zhiyuan Zhang","orcid":"https://orcid.org/0009-0000-2669-5654"},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Zhiyuan Zhang","raw_affiliation_strings":["MPI-SP, Bochum, Germany"],"affiliations":[{"raw_affiliation_string":"MPI-SP, Bochum, Germany","institution_ids":["https://openalex.org/I4210096592"]}]}],"institutions":[],"countries_distinct_count":5,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5072062100"],"corresponding_institution_ids":["https://openalex.org/I4210096592"],"apc_list":null,"apc_paid":null,"fwci":2.2948,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.87252357,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"933","last_page":"948"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6885076761245728},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.656635046005249},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4837524890899658},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4456876218318939},{"id":"https://openalex.org/keywords/cryptographic-protocol","display_name":"Cryptographic protocol","score":0.4103221893310547},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.19626131653785706}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6885076761245728},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.656635046005249},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4837524890899658},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4456876218318939},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.4103221893310547},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.19626131653785706},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3676641.3716015","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3676641.3716015","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","raw_type":"proceedings-article"},{"id":"pmh:oai:HAL:hal-04632106v1","is_oa":true,"landing_page_url":"https://inria.hal.science/hal-04632106","pdf_url":"https://inria.hal.science/hal-04632106/document","source":{"id":"https://openalex.org/S4406922454","display_name":"SPIRE - Sciences Po Institutional REpository","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"ASPLOS '25: 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Mar 2025, Rotterdam, Netherlands. pp.933-948, &#x27E8;10.1145/3676641.3716015&#x27E9;","raw_type":"Conference papers"},{"id":"pmh:oai:repository.ubn.ru.nl:2066/318170","is_oa":true,"landing_page_url":"https://hdl.handle.net/2066/318170","pdf_url":"https://repository.ubn.ru.nl//bitstream/handle/2066/318170/318170.pdf","source":{"id":"https://openalex.org/S4306401067","display_name":"Radboud Repository (Radboud University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I145872427","host_organization_name":"Radboud University Nijmegen","host_organization_lineage":["https://openalex.org/I145872427"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Article in monograph or in proceedings"}],"best_oa_location":{"id":"doi:10.1145/3676641.3716015","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3676641.3716015","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1718986858","display_name":null,"funder_award_id":"ANR-22-PECY-000","funder_id":"https://openalex.org/F4320320883","funder_display_name":"Agence Nationale de la Recherche"},{"id":"https://openalex.org/G18682879","display_name":null,"funder_award_id":"390781972","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"},{"id":"https://openalex.org/G3507816311","display_name":null,"funder_award_id":"Excellence Strategy of the German Federal and Stat","funder_id":"https://openalex.org/F4320321114","funder_display_name":"Bundesministerium f\u00fcr Bildung und Forschung"},{"id":"https://openalex.org/G352791218","display_name":null,"funder_award_id":"(BMBF)","funder_id":"https://openalex.org/F4320321114","funder_display_name":"Bundesministerium f\u00fcr Bildung und Forschung"},{"id":"https://openalex.org/G4041451713","display_name":null,"funder_award_id":"ANR-22-PECY-0006","funder_id":"https://openalex.org/F4320320883","funder_display_name":"Agence Nationale de la Recherche"},{"id":"https://openalex.org/G4409308110","display_name":null,"funder_award_id":"Excellence Strategy of the German Federal and State Governments","funder_id":"https://openalex.org/F4320321114","funder_display_name":"Bundesministerium f\u00fcr Bildung und Forschung"},{"id":"https://openalex.org/G5106512922","display_name":null,"funder_award_id":"Deutsche Forschungsgemeinschaft (DFG","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"},{"id":"https://openalex.org/G5168466499","display_name":null,"funder_award_id":"Project","funder_id":"https://openalex.org/F4320321114","funder_display_name":"Bundesministerium f\u00fcr Bildung und Forschung"},{"id":"https://openalex.org/G5246431558","display_name":null,"funder_award_id":"805031","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G5717916917","display_name":null,"funder_award_id":"39078197","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"},{"id":"https://openalex.org/G5856086275","display_name":null,"funder_award_id":"EXC 2092 CASA - 390781972","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"},{"id":"https://openalex.org/G6364093981","display_name":null,"funder_award_id":"16KISK038","funder_id":"https://openalex.org/F4320321114","funder_display_name":"Bundesministerium f\u00fcr Bildung und Forschung"},{"id":"https://openalex.org/G6851345361","display_name":null,"funder_award_id":"Grant","funder_id":"https://openalex.org/F4320320883","funder_display_name":"Agence Nationale de la Recherche"},{"id":"https://openalex.org/G7231494579","display_name":null,"funder_award_id":"ANR-22-PECY-0006","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"},{"id":"https://openalex.org/G762232396","display_name":null,"funder_award_id":"Project","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"},{"id":"https://openalex.org/G7838977372","display_name":null,"funder_award_id":"805031","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"},{"id":"https://openalex.org/G8051717526","display_name":null,"funder_award_id":"Grant","funder_id":"https://openalex.org/F4320320300","funder_display_name":"European Commission"},{"id":"https://openalex.org/G8413167928","display_name":null,"funder_award_id":"Excellence Strategy","funder_id":"https://openalex.org/F4320321114","funder_display_name":"Bundesministerium f\u00fcr Bildung und Forschung"},{"id":"https://openalex.org/G975799825","display_name":null,"funder_award_id":"France 2030 prog","funder_id":"https://openalex.org/F4320320883","funder_display_name":"Agence Nationale de la Recherche"}],"funders":[{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320320879","display_name":"Deutsche Forschungsgemeinschaft","ror":"https://ror.org/018mejw64"},{"id":"https://openalex.org/F4320320883","display_name":"Agence Nationale de la Recherche","ror":"https://ror.org/00rbzpz17"},{"id":"https://openalex.org/F4320321114","display_name":"Bundesministerium f\u00fcr Bildung und Forschung","ror":"https://ror.org/04pz7b180"},{"id":"https://openalex.org/F4320323817","display_name":"Universitas Brawijaya","ror":"https://ror.org/01wk3d929"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":23,"referenced_works":["https://openalex.org/W1910751411","https://openalex.org/W1965722902","https://openalex.org/W2027963645","https://openalex.org/W2089448621","https://openalex.org/W2095390121","https://openalex.org/W2121468041","https://openalex.org/W2123991163","https://openalex.org/W2162800072","https://openalex.org/W2766545755","https://openalex.org/W2866028610","https://openalex.org/W2884163605","https://openalex.org/W2963311060","https://openalex.org/W2982615885","https://openalex.org/W3003637591","https://openalex.org/W3015276542","https://openalex.org/W3034103899","https://openalex.org/W3211894565","https://openalex.org/W3214883374","https://openalex.org/W4252890599","https://openalex.org/W4385080320","https://openalex.org/W4385187318","https://openalex.org/W4386651309","https://openalex.org/W4401604096"],"related_works":["https://openalex.org/W2060145807","https://openalex.org/W4248806346","https://openalex.org/W2289378658","https://openalex.org/W1531360494","https://openalex.org/W2093529019","https://openalex.org/W1982325601","https://openalex.org/W4240432851","https://openalex.org/W154233216","https://openalex.org/W2626486901","https://openalex.org/W1988007309"],"abstract_inverted_index":{"Spectre":[0,39,62,139],"attacks":[1,26],"void":[2],"the":[3,33,94,101,104,108,111,115,125,134,154],"guarantees":[4],"of":[5,35,61,103,110],"constant-time":[6],"cryptographic":[7,55,146],"code":[8,20,56],"by":[9,137],"leaking":[10],"secrets":[11,80],"during":[12],"speculative":[13,84],"execution.":[14],"Recent":[15],"research":[16],"shows":[17],"that":[18,76,78,90,133],"such":[19],"can":[21],"be":[22],"protected":[23],"from":[24],"Spectre-v1":[25],"with":[27],"minimal":[28],"overhead,":[29],"but":[30],"leaves":[31],"open":[32],"question":[34],"protecting":[36],"against":[37,57],"other":[38],"variants.":[40],"In":[41],"this":[42],"work,":[43],"we":[44],"design,":[45],"validate,":[46],"implement,":[47],"and":[48,86,107,131,148],"verify":[49],"a":[50,70,87],"new":[51,71],"approach":[52,68,123],"to":[53],"protect":[54],"all":[58,138],"known":[59],"classes":[60],"attacks,":[63],"in":[64,124],"particular":[65],"Spectre-RSB.":[66],"Our":[67],"combines":[69],"value-dependent":[72],"information-flow":[73],"type":[74,105],"system":[75,106],"ensures":[77],"no":[79],"leak":[81],"even":[82],"under":[83],"execution":[85],"compiler":[88,112],"transformation":[89,113],"enables":[91],"it":[92],"on":[93],"generated":[95],"low-level":[96],"code.":[97],"We":[98,119],"first":[99],"prove":[100],"soundness":[102],"correctness":[109],"using":[114],"Coq":[116],"proof":[117],"assistant.":[118],"then":[120],"implement":[121],"our":[122],"Jasmin":[126],"framework":[127],"for":[128,144,153],"high-assurance":[129],"cryptography":[130],"demonstrate":[132],"overhead":[135],"incurred":[136],"protections":[140],"is":[141],"below":[142],"2%":[143],"most":[145],"primitives":[147],"reaches":[149],"only":[150],"about":[151],"5--7%":[152],"more":[155],"complex":[156],"post-quantum":[157],"key-encapsulationkmechanism":[158],"Kyber.":[159]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-04-14T08:04:32.555800","created_date":"2024-07-02T00:00:00"}
