In this paper, we analyse the results and claims presented in the paper \emph{`Are Randomized Caches Truly Random? Formal Analysis of Randomized Partitioned Caches'}, presented at HPCA conference 2023. In addition, we also analyse the applicability of `Bucket and Ball' analytical model presented in MIRAGE (Usenix Security 2021) for its security estimation. We put forth the fallacies in the original bucket and ball model and discuss its implications. Finally, we demonstrate a cache occupancy attack on MIRAGE with just $10\%$ of total cache capacity and extend the framework to establish a covert channel and a template-based fingerprinting attack.
翻译:本文分析了发表于HPCA 2023会议的论文《随机缓存真的随机吗?——随机分区缓存的形式化分析》中的结果与论断。此外,我们还评估了MIRAGE(Usenix Security 2021)中提出的“桶与球”分析模型在安全评估中的适用性。我们指出了原始桶与球模型中的谬误,并讨论了其影响。最后,我们仅利用总缓存容量的10%演示了对MIRAGE的缓存占用攻击,并将该框架扩展为建立隐蔽信道与基于模板的指纹攻击。