Privilege, isolation & side channels
Enforce access rules, and understand what timing can still reveal.
Architectural permission checks and microarchitectural observation are different layers.
Restricts sensitive operations.
Make a cache miss
A cache fetches a whole line. Locality reuses it; conflicting mappings can evict useful data even before total capacity is exhausted.
What this model includes
One read-only cache, 64-byte lines, LRU replacement, eight total lines, eight-byte elements, 32 accesses. No prefetching or multilevel effects.
What happens inside
Create protection boundaries
Privilege levels restrict instructions and resource access. Page permissions protect address spaces; IOMMUs restrict device accesses. Virtualization adds guest execution and address translation under a hypervisor. Trusted execution mechanisms protect particular boundaries under specific threat models, not every part of a system.
Consider observable behavior
Caches, predictors, and shared resources can reveal information through timing or contention. Speculative execution may leave effects even when architectural results are discarded. Mitigations depend on hardware, firmware, OS, and code. Constant-time algorithms aim to avoid secret-dependent behavior but require careful validation on the target.
What this means for your code
Low-level engineer
State a threat model and follow platform mitigation guidance. Correct privilege checks alone do not address every side channel.
Software developer
Use maintained cryptographic libraries and current platform patches. Avoid building secret-dependent code from unverified “branchless” tricks.
Read the actual specifications
These references supply the underlying contracts and implementation details. The diagrams here are simplified teaching models.