On Borrowed Time – Preventing Static Side-Channel Analysis
Robert Dumitru
Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Side Channels 2
Overview
In the realm of hardware security, physical side channel analysis remains a potent threat, particularly against cryptographic implementations. This talk, "On Borrowed Time," presented by Robert Dumitru, introduces a novel hardware countermeasure designed to prevent static side-channel analysis. The core problem addressed is the violation of the blackbox assumption inherent in secure hardware, where physical observations like power consumption can inadvertently leak sensitive internal data during computation. While dynamic power analysis has historically received significant attention, static attacks, which exploit a circuit's quiescent state, are emerging as a critical and less-addressed vulnerability.
Key moments
- 0:00 Introduction to static side-channel analysis
- 2:20 Understanding the static power analysis attack model
- 3:45 Demonstrating static CPA leakage on AES
- 5:30 Proposed countermeasure: preventing static state conditions
- 6:05 Borrowed Time countermeasure: detect clock stop, clear registers
- 6:35 Two countermeasure variants: PLL and asynchronous
- 7:00 Detailed design of asynchronous clock sensor
On Borrowed Time – Preventing Static Side-Channel Analysis
Speakers: Robert Dumitru
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=YCwLFmjW3hg
Overview
In the realm of hardware security, physical side channel analysis remains a potent threat, particularly against cryptographic implementations. This talk, "On Borrowed Time," presented by Robert Dumitru, introduces a novel hardware countermeasure designed to prevent static side-channel analysis. The core problem addressed is the violation of the blackbox assumption inherent in secure hardware, where physical observations like power consumption can inadvertently leak sensitive internal data during computation. While dynamic power analysis has historically received significant attention, static attacks, which exploit a circuit's quiescent state, are emerging as a critical and less-addressed vulnerability.
The presentation delves into the mechanisms of static side-channel attacks, demonstrating their effectiveness against a vulnerable AES implementation. Crucially, it then unveils "Borrowed Time," an on-chip countermeasure meticulously engineered to detect when a circuit's clock has been halted by an adversary and promptly clear any sensitive registers with random data. This innovative approach aims to eliminate the conditions necessary for static leakage, thereby fortifying the security of devices against a growing class of sophisticated hardware attacks.
The significance of this work lies in its proactive hardware-level defense against an increasingly relevant attack vector. As embedded systems and IoT devices become ubiquitous, protecting their underlying cryptographic operations from even advanced physical probing becomes paramount. "Borrowed Time" offers a practical, low-overhead solution that can be integrated directly into chip designs, providing a robust line of defense that complements existing security measures and ensures the integrity of sensitive computations.
Background
▶ Watch: Introduction to static side-channel analysis (0:00)
Any computation performed by hardware inevitably involves physical processes, leading to observable phenomena such as power consumption, heat dissipation, electromagnetic emissions, and acoustic noise. Physical side channel analysis exploits these unintentional emanations to infer internal data or operations. Among these, power side channel analysis has historically been the most information-rich and thus widely studied. The power consumed by a chip comprises two main components: static power and dynamic power.
Static power is consumed in maintaining a circuit's state, such as holding the values in registers or powering signal lines. For instance, high voltage signals representing '1's and low voltage signals representing '0's continuously draw static current. In contrast, dynamic power consumption occurs during transitions between states, specifically when internal circuit elements switch due to an active clock edge. During these transitions, a significant spike in power activity is observed as charges move and gates switch.
Most traditional power analysis research has focused on dynamic power analysis. This involves sampling the power consumption at very high frequencies, precisely around the active clock edges. By capturing these transient power spikes, attackers can gain insights into the switching behavior of internal circuit elements, which is often correlated with the data being processed. Countermeasures for dynamic attacks typically involve techniques like masking or shuffling to obscure data-dependent transitions.
However, a less-explored but increasingly relevant threat model is static side-channel analysis. In this scenario, an attacker induces a static state in the circuit, most commonly by halting the clock signal provided to the target. Once the clock is stopped, the attacker waits for a sufficient period (e.g., 20 milliseconds in prior literature) for all dynamic effects from the last transitions to subside. After this quiescent period, a measurement is taken over a longer duration, and the average power consumption is recorded as a single value. This averaged value represents a remarkably clean, noise-free snapshot of the circuit's static state, including the data held in its registers. The challenge for defenders is that traditional dynamic countermeasures are often ineffective against these static measurements, as they target transient behavior rather than persistent state. The problem exists because standard hardware designs do not inherently clear sensitive data from registers when the clock is stopped, leaving them vulnerable to prolonged static observation.
Key Findings
▶ Watch: Demonstrating static CPA leakage on AES (3:45)
The research underpinning "On Borrowed Time" began with a crucial case study to quantify the leakage susceptible to static side-channel analysis and to establish a baseline for evaluating countermeasures. The researchers performed static correlation power analysis (CPA) against an FPGA implementation of the Advanced Encryption Standard (AES). This particular AES implementation was intentionally designed to be highly leaky, lacking any inherent side-channel countermeasures. Following established literature, the attack employed a 20-millisecond wait time after halting the clock before measurements began, with a 20-millisecond window length for averaging the power consumption.
The results of this baseline attack were stark: a full key recovery was achievable with approximately 1500 MTD (measurements to disclosure). The speaker presented a diagram illustrating the recovery of a single subkey (one byte), where the correct key candidate emerged with very high correlation after about a thousand traces, clearly distinguishing itself from 255 incorrect guesses. This confirmed the severe vulnerability of unprotected designs to static CPA.
A critical question for designing effective countermeasures was to determine precisely how long sensitive data persisted and remained vulnerable after the last active clock edge. To investigate this, the researchers progressively reduced both the offset (time before measurement starts) and the window length of their static attack. They found that even at an offset of 200 microseconds, with over a million traces, absolutely no leakage could be observed. This 200-microsecond threshold, which is three orders of magnitude greater than the 1-microsecond target clearance time, became a crucial cutoff point. It demonstrated that while the leakage window is finite, it is significantly longer than typical clock cycle periods, providing a substantial window for attackers to exploit.
These findings motivated the core principle of the "Borrowed Time" countermeasure: all successful static attacks rely on two simultaneous conditions:
- The clock supplied to the target circuit must be stopped.
- Sensitive content must remain in registers and be unchanged.
The fundamental insight and key finding for the countermeasure's design was that by preventing these two conditions from co-existing, static side-channel attacks could be effectively nullified. The countermeasure's goal, therefore, was to detect a stopped clock and, upon detection, immediately overwrite sensitive registers with random values, thereby removing the sensitive content before an attacker could perform a meaningful static measurement within the identified vulnerable window.
Technical Deep Dive
▶ Watch: Proposed countermeasure: preventing static state conditions (5:30)
The "Borrowed Time" countermeasure is an innovative in-chip solution designed to prevent static side-channel analysis by actively responding to a halted clock. The primary objective is to detect a stopped clock and, upon detection, clear sensitive registers by overwriting their contents with randomness. The researchers developed two variants: one based on a phase-lock loop (PLL), which leverages existing clock management circuitry, and another based on custom asynchronous circuitry, specifically tailored for lightweight systems demanding low power and minimal circuit area. For this discussion, we will focus on the more universally applicable and lightweight asynchronous design.
The design for the asynchronous "Borrowed Time" countermeasure integrates several key components:
- Clock Sense Circuit:
- This circuit is responsible for continuously monitoring the external clock signal provided to the target.
- It operates by passing the clock signal through a chain of delay elements. Each element introduces a fixed, small delay, creating multiple time-shifted "taps" of the original clock signal.
- These taps are then fed into a combinatorial logic element.
- When the clock is actively ticking, the combinatorial element observes variation across these time-shifted taps (i.e., at any given instant, some taps will be high while others are low, reflecting the clock's transitions). In this state, the circuit allows normal operation.
- However, if the clock signal stops, all taps will eventually settle to a single, consistent state (either all high or all low, depending on where the clock halted). The absence of variation across the taps signals a halted clock.
- Upon detecting this static state, the clock sense circuit asserts an alarm signal, referred to as
stop_detect.
- State Reset Circuitry:
- This component intervenes directly with the inputs of the sensitive registers within the target circuit.
- It employs a multiplexer at the input of each sensitive register.
- Under normal operation (when
stop_detectis low), the multiplexer passes the original, sensitive data from the target circuit directly to the register input. - When the
stop_detectalarm goes high, the multiplexer switches its input. Instead of the sensitive data, it now feeds random values generated by an on-chip random number generator (RNG) into the register inputs. - A crucial detail is that the RNG is designed to operate even with the potentially stopped clock, ensuring it can generate enough fresh randomness to clear all sensitive registers within a very short timeframe. The speaker confirmed the RNG can work with the same clock that gets stopped, producing sufficient randomness.
- Clock Edge Generator:
- Even if randomness is applied to the register inputs, the registers themselves cannot update without an active clock edge to latch the new values. Since the external clock has been stopped, a dedicated mechanism is needed to provide this crucial edge.
- This is achieved using another clock multiplexer, which generates the
system_clockthat actually drives the sensitive registers. - Under normal circumstances, the
system_clockis simply the original, external clock signal. - However, when
stop_detectis asserted, the clock multiplexer switches. It then uses a delayed version of thestop_detectsignal itself as the activesystem_clockedge. - The
stop_detectsignal, by definition, transitions from low to high when the clock stops. This guaranteed low-to-high transition, once appropriately delayed, serves as the single, active clock edge needed to latch the random data into the sensitive registers. This effectively clears their sensitive contents.
The combined effect of these components is a robust, self-contained mechanism. The clock sense circuit detects a halt, the state reset circuitry prepares random data, and the clock edge generator provides the necessary pulse to securely overwrite the sensitive registers. The system is engineered to detect a stopped clock within one clock cycle period. For targets operating in the megahertz (MHz) range, "Borrowed Time" can clear registers within, at worst, 1 microsecond. This is critically important because it is well before the 200-microsecond window identified in the key findings as the minimum time required for an attacker to observe static leakage.
Furthermore, "Borrowed Time" offers additional benefits: it can be tuned to operate across a given frequency range, making it adaptable to dynamic target systems. It is also resilient to clock glitching attacks, which attempt to manipulate clock signals. Importantly, it enables safe operation within clock-gated systems. Clock gating is a common design practice for power saving, where parts of the circuit are temporarily deprived of a clock signal. "Borrowed Time" ensures that even in such scenarios, sensitive registers are properly handled if the clock is stopped for malicious intent, allowing designers to reap the benefits of power savings without compromising security.
Demo / Proof of Concept
▶ Watch: Two countermeasure variants: PLL and asynchronous (6:35)
While the presentation did not feature a live, interactive "demo" in the traditional sense, the effectiveness of the "Borrowed Time" countermeasure was rigorously validated through a comprehensive experimental evaluation, serving as a powerful proof of concept. The researchers reiterated their initial attack methodology, attempting to mount static side-channel attacks against the same FPGA-based AES implementation, but this time with the "Borrowed Time" countermeasure integrated.
The experimental setup mirrored the baseline leakage scenario: static CPA was performed with varying time windows and offsets, attempting to recover the AES key. However, with "Borrowed Time" activated, the results were dramatically different. The speaker emphatically stated that there was "no emergence of the correct key candidates for millions of traces." This outcome stands in stark contrast to the 1500 MTD required to fully recover the key in the unprotected baseline scenario.
This experimental validation unequivocally demonstrated the efficacy of "Borrowed Time." By detecting the halted clock within one clock cycle and clearing sensitive registers within approximately 1 microsecond, the countermeasure successfully eliminated the window of opportunity for static side-channel attacks. The absence of any key correlation, even with an extremely high number of attack traces, confirms that the sensitive data was effectively removed from the registers before an attacker could obtain a stable, exploitable static power measurement. This validation is critical for asserting that "Borrowed Time" is a viable and robust hardware-level defense against this specific class of physical attacks.
Defensive Implications
▶ Watch: Detailed design of asynchronous clock sensor (7:00)
The "On Borrowed Time" countermeasure provides crucial insights and practical strategies for hardware designers and security architects aiming to fortify their systems against advanced physical attacks. The primary implication is the undeniable need for active, hardware-level defenses against static side-channel analysis, a threat often overlooked in favor of dynamic attack countermeasures.
Defenders should recognize that relying solely on software-level obfuscation or traditional dynamic side-channel protections is insufficient. If a device handles sensitive data, especially cryptographic keys or intermediate values, in registers, and if an attacker can halt its clock, then static leakage is a real and present danger. Integrating mechanisms like "Borrowed Time" directly into the silicon design is therefore essential for robust security.
Specifically, hardware designers should:
- Proactively incorporate clock-stop detection: Implement circuitry capable of reliably identifying when the primary clock signal to sensitive modules has been halted or significantly disrupted.
- Ensure immediate register sanitization: Upon detecting a stopped clock, sensitive registers must be cleared and overwritten with random, non-data-dependent values. This action must occur within a timeframe significantly shorter than the window an attacker would need to perform a successful static measurement (e.g., within microseconds, well below the 200-microsecond leakage window identified in the research).
- Consider the overheads and deployment scenarios: While "Borrowed Time" demonstrates modest overheads (e.g., 20% power overhead for lightweight AES compared to 200-300% for masking), designers must weigh these costs against the security benefits. The availability of both PLL-based and asynchronous variants allows for flexibility, with the latter being particularly suitable for resource-constrained, low-power, or low-area applications.
- Maintain compatibility with power-saving features: The countermeasure's compatibility with clock gating is a significant advantage. This means designers do not have to sacrifice power efficiency—a critical concern for embedded and mobile devices—to implement this security feature. They can still utilize clock gating for power savings while ensuring security against malicious clock stoppage.
- Embrace open-source artifacts: The researchers made their code artifacts open source, which provides a valuable resource for designers to study, adapt, and integrate similar protections into their own designs. This fosters a collaborative approach to enhancing hardware security.
Ultimately, "Borrowed Time" underscores a paradigm shift: security against physical attacks must extend beyond dynamic analysis to encompass the static state of a circuit. For any system where the integrity of sensitive data is paramount, designers must assume sophisticated adversaries who can manipulate clock signals and be prepared with on-chip countermeasures that actively defend against such manipulations.
Key Takeaways
- Static side-channel analysis is a potent and growing threat: Unlike dynamic attacks, it exploits a circuit's quiescent state when the clock is halted, providing clean, noise-free measurements of sensitive register contents.
- "Borrowed Time" is an effective on-chip countermeasure: It actively defends against static side-channel attacks by detecting a halted clock and preemptively clearing sensitive registers.
- The countermeasure operates in three key stages: A clock sense circuit detects clock stoppage, state reset circuitry applies random data to register inputs, and a clock edge generator provides a one-shot pulse to latch this randomness.
- "Borrowed Time" is fast and efficient: It can detect a stopped clock within one cycle and clear registers within approximately 1 microsecond, well before static leakage can be observed (e.g., the 200-microsecond window found in experiments).
- Modest overhead and flexible deployment: The asynchronous variant offers low power and area overhead (e.g., 20% power overhead for lightweight AES) and is compatible with power-saving techniques like clock gating.
- Experimentally validated effectiveness: Rigorous testing demonstrated that with "Borrowed Time" enabled, no key leakage was observed, even after millions of attack traces, effectively neutralizing static CPA.
About the Speaker(s)
Robert Dumitru presented the paper "On Borrowed Time – Preventing Static Side-Channel Analysis." This work was a collaborative effort involving researchers from the University of Adelaide, Rural University Boom, UC Luang, and the Australian Department of Defense. Robert Dumitru's presentation at the NDSS Symposium highlights his expertise in hardware security and countermeasures against side-channel attacks, demonstrating a deep understanding of both the attack methodologies and the intricate hardware design required for robust defenses.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid, original hardware security research with a clean threat model, a novel countermeasure architecture, and rigorous experimental validation. The work fills a genuine gap — static side-channel analysis has been underserved compared to dynamic CPA, and Borrowed Time addresses it with an elegant, low-overhead hardware primitive rather than yet another masking scheme.
Heather Calloway (CISO) — WEAK
Technically credible and experimentally rigorous work on a real and underappreciated hardware attack surface. But this is a chip design paper delivered to a research audience — there is no bridge to the people who procure, certify, or govern the systems this vulnerability lives in.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025