Hardware security laboratory
Microarchitectural & Power Side-Channel Analyzer
A deterministic, local simulation of RSA Simple Power Analysis, AES Differential Power Analysis, and Flush+Reload cache leakage. Nothing is measured from real hardware or sent over the network.
3. Flush+Reload β cache-line eviction heatmap
Red cells are cache flushes, yellow cells are victim accesses, and reload timing distinguishes cached lines from uncached lines.
L1 line
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
00
01
02
03
04
05
06
07
08
09
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
FlushVictim accessReload: fast / cachedReload: slow / evictedObserved lines: 3, 7, 11, 18, 23
Why the leak appears
- SPA: square-and-multiply implementations make secret-dependent operation sequences visible in power traces.
- DPA: averaging is replaced by correlation across many traces; the correct hypothesis aligns with the measured leakage.
- Flush+Reload: cache eviction followed by reload timing can reveal which lookup table lines a victim touched.
Defenses
- Use constant-time, constant-memory-access implementations for secret-dependent operations.
- Prefer hardware-accelerated AES-NI or other audited primitives over software lookup tables where available.
- Use bitsliced or masked designs when the physical threat model requires stronger leakage resistance.
- For physical devices, add shielding, noise countermeasures, randomization, and fault/side-channel evaluation during certification.
Safety boundary: all values, traces, correlations, and cache timings above are deterministic teaching data. The lab does not access a microphone, oscilloscope, CPU performance counters, browser cache, network, or external target.