Constant-time foundations for the new spectre era
Sunjay Cauligi, Craig Disselkoen, Klaus v. Gleissenthall, Dean Michael Tullsen, Deian Stefan, Tamara Rezk, Gilles Barthe · 2020
The constant-time discipline is a software-based countermeasure used for protecting high assurance cryptographic implementations against timing side-channel attacks. Constant-time is effective (it protects against many known attacks), rigorous (it can be formalized using program semantics), and amenable to automated verification. Yet, the advent of micro-architectural attacks makes constant-time as it exists today far less useful.