Paper 2026/1242

SoK: The Constant Time Model

Billy Bob Brumley, Rochester Institute of Technology
Abstract

Constant time programming patterns is the primary defense against timing attacks on cryptographic implementations, yet what "constant time" means varies across academia and industry. This work systematizes constant time models and their evolution, identifies a recurring gap between what models protect and what specifications assume, and distills an offensive methodology for discovering timing vulnerabilities that originate outside the cryptographic primitive boundary. Applying this methodology, we locate a specification-level vulnerability related to private key loading, and confirm the leak in both OpenSSL and BoringSSL. Counterintuitively, BoringSSL's per-observation signal is several orders of magnitude stronger than OpenSSL's, despite an explicitly stricter threat model.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. WOOT 2026
Keywords
side channel analysistiming attacksleakage assessmentelliptic curve cryptographyOpenSSLBoringSSL
Contact author(s)
bbbics @ rit edu
History
2026-06-13: approved
2026-06-11: received
See all versions
Short URL
https://ia.cr/2026/1242
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2026/1242,
      author = {Billy Bob Brumley},
      title = {{SoK}: The Constant Time Model},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1242},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1242}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.