Microarchitectural optimizations are crucial for performance but open the door to attacks that can undermine software-enforced security policies. The current gold standard for defending against such attacks is the constant-time programming discipline, widely adopted to secure cryptographic implementations. However, constan-time fails to provide protection against certain
classes of attacks, such as Spectre.
This talk will introduce the threats posed by recent microarchitectural side-channel attacks and present recent mitigation strategies based on hardware-software co-design. It will also discuss how to formalize security at the hardware-software interface in order to provably achieve end-to-end security against microarchitectural attacks.