Paper 2026/1632

Counters and Nonces for Mitigating Ciphertext Side Channels

Moritz Peters, Ruhr University Bochum
Jens Alich, Ruhr University Bochum
Ashwin Jha, Ruhr University Bochum
Gregor Leander, Ruhr University Bochum
Yuval Yarom, Ruhr University Bochum
Tim Güneysu, Ruhr University Bochum, German Research Centre for Artificial Intelligence
Abstract

Recent works have highlighted the risk of deterministic memory encryption, as used for example in AMD SEV. In the so-called ciphertext side-channel attack, an adversary leaks sensitive information, such as cryptographic keys, from an encrypted VM by observing changes in the encrypted contents of the memory. To date, countermeasures have been quite restricted in scope and have not addressed the root cause. Alternatively, some studies suggest adding freshness to memory encryption. However, this approach is considered impractical due to the performance overhead introduced by fetching such freshness values for every single memory access. In this work, we propose an efficient approach for eliminating most of the overhead of fetching the aforementioned freshness. Our core idea is to repurpose the ECC memory area to efficiently store random nonces or counters. We propose a range of implementations with varying trade-offs between security guarantees and performance overhead, and demonstrate that we can achieve a solid baseline security even with small random nonces. By leaving a portion of ECC memory unused, we show that it is possible to efficiently integrate protection mechanisms such as memory integrity and memory tagging, while limiting the overall performance overhead to approximately 2%.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Ciphertext Side ChannelMemory EncryptionCountermeasureAMD SEV-SNPIntel SGX/TDX
Contact author(s)
moritz peters-v41 @ rub de
jens alich @ rub de
ashwin jha @ rub de
gregor leander @ rub de
yuval yarom @ rub de
tim gueneysu @ rub de
History
2026-08-12: approved
2026-08-07: received
See all versions
Short URL
https://ia.cr/2026/1632
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1632,
      author = {Moritz Peters and Jens Alich and Ashwin Jha and Gregor Leander and Yuval Yarom and Tim Güneysu},
      title = {Counters and Nonces for Mitigating Ciphertext Side Channels},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1632},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1632}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.