Wait a Cycle: Eroding Cryptographic Trust in Low-End Tees via Timing Side Channels
Ruben Van Dijck, Márton Bognár, Jo Van Bulck · 2025
The growing interconnectivity of low-end embedded devices has spurred research into lightweight trusted execution environments (TEEs), which are designed to meet strict power, cost, and real-time constraints. A key focus has been on the development of dedicated frameworks and libraries to ensure message integrity and authenticity through strong, sometimes formally verified cryptography. However, existing security analyses commonly dismiss side channels, assuming that small microcontrollers are less susceptible to timing variations than high-end CPUs and that these variations are easily avoided by good programming practices. This paper systematically examines timing side channels in open-source low-end TEEs. We identify subtle vulnerabilities at different levels of the hardware-software stack: (1) the use of non-constant-time$\mathrm{C} / \mathrm{C}++$standard library functions such as memcmp; (2) compiler-induced timing leaks for comparing primitive data values; and (3) a hardware-level timing flaw in the cryptographic core of the Sancus TEE. We experimentally validate these timing side channels and build practical exploits to break TEE security guarantees and inject forged messages. Our findings demonstrate that timing side channels pose a critical, yet often overlooked threat to low-end TEEs, underscoring the need for future security models to account for them.