Paper 2026/1632
Counters and Nonces for Mitigating Ciphertext Side Channels
Abstract
Recent works have highlighted the risk of deterministic memory encryption, as used for example in AMD SEV. In the so-called ciphertext side-channel attack, an adversary leaks sensitive information, such as cryptographic keys, from an encrypted VM by observing changes in the encrypted contents of the memory. To date, countermeasures have been quite restricted in scope and have not addressed the root cause. Alternatively, some studies suggest adding freshness to memory encryption. However, this approach is considered impractical due to the performance overhead introduced by fetching such freshness values for every single memory access. In this work, we propose an efficient approach for eliminating most of the overhead of fetching the aforementioned freshness. Our core idea is to repurpose the ECC memory area to efficiently store random nonces or counters. We propose a range of implementations with varying trade-offs between security guarantees and performance overhead, and demonstrate that we can achieve a solid baseline security even with small random nonces. By leaving a portion of ECC memory unused, we show that it is possible to efficiently integrate protection mechanisms such as memory integrity and memory tagging, while limiting the overall performance overhead to approximately 2%.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Ciphertext Side ChannelMemory EncryptionCountermeasureAMD SEV-SNPIntel SGX/TDX
- Contact author(s)
-
moritz peters-v41 @ rub de
jens alich @ rub de
ashwin jha @ rub de
gregor leander @ rub de
yuval yarom @ rub de
tim gueneysu @ rub de - History
- 2026-08-12: approved
- 2026-08-07: received
- See all versions
- Short URL
- https://ia.cr/2026/1632
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1632,
author = {Moritz Peters and Jens Alich and Ashwin Jha and Gregor Leander and Yuval Yarom and Tim Güneysu},
title = {Counters and Nonces for Mitigating Ciphertext Side Channels},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1632},
year = {2026},
url = {https://eprint.iacr.org/2026/1632}
}