Unit content
Side channels and observable implementation effects
A system can leak secret information even when its explicit outputs follow the intended rules.
A side channel arises when secret-dependent computation changes some observable implementation effect, such as
- execution time;
- cache behavior;
- memory-access patterns;
- power consumption;
- electromagnetic emissions.
An adversary can correlate those observations with candidate secret values without directly reading the protected memory.
For example, a comparison routine that exits at the first mismatching byte can take longer when more prefix bytes are correct. Repeated timing measurements may therefore reveal information about the expected value.
Side-channel resistance often requires making observable behavior independent of secrets, reducing measurement quality, or isolating shared implementation state.
Side channels show that a security model must account for more than deliberately returned values. Physical and microarchitectural effects can become information outputs when an adversary is able to observe them.