﻿<?xml version="1.0" encoding="UTF-8"?>
<b:Sources SelectedStyle="" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography"  xmlns="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" >
<b:Source>
<b:Tag>shrestha.ea:secure-cache-evaluation:2026</b:Tag>
<b:SourceType>BookSection</b:SourceType>
<b:Publisher>IEEE</b:Publisher>
<b:Year>2026</b:Year>
<b:Month>April</b:Month>
<b:ConferenceName>Design, Automation &amp; Test in Europe Conference (DATE)</b:ConferenceName>
<b:Author>
<b:Author><b:NameList>
<b:Person><b:Last>Shrestha</b:Last><b:First>Pratik</b:First></b:Person>
<b:Person><b:Last>Brucker</b:Last><b:First>Achim</b:First><b:Middle>D</b:Middle></b:Person>
<b:Person><b:Last>Bhatti</b:Last><b:First>M</b:First><b:Middle>Khurram</b:Middle></b:Person>
</b:NameList></b:Author>
</b:Author>
<b:Title>From Entropy to Leakage: A Unified Methodology for Security Evaluation of Caches</b:Title>
<b:Comments>Cache Side-Channel Attacks (CSCAs) can leak sensitive information by exploiting shared cache resources. Although many secure cache designs like CEASER, Scatter-Cache, PhantomCache, MIRAGE, and IECache have been proposed, the security evaluation methods being used by these designs remain diverse, often inconsistent, and scattered. This inconsistency makes it challenging to compare the security strengths of the state-of-the-art cache designs for security-critical applications. To address this challenge, we propose a novel consistent security evaluation methodology, called the UniSEC (Unified methodology for Security Evaluation of Caches), which estimates Worst-Case Leakage (WCL) and provides a consistent, comprehensive, and realistic measure of potential information leakage that various cache designs exhibit. UniSEC empirically shows that WCL estimation maximizes the revelation of potential information leakage that Relative Eviction Entropy (REE) based method fails to capture. UniSEC introduces an Effective Security Score (ESS) that takes into account Active Attackers Cache Lines (AACLs) within an attackers eviction set and the uniformity of the eviction distribution across the AACLs to measure the worst-case leakage. Our results show that well-distributed eviction probabilities across attackers eviction set lead to higher ESS and overall entropy. We carry out experiments to measure WCL, REE, and ESS in six state-of-the-art secure cache designs and vary associativity and cache sizes to measure the impact on information leakage. Our experiments reveal that security-critical applications cannot rely on the security guarantees being provided by REE alone. Therefore, WCL is a more realistic metric for measuring the actual amount of information leakage in caches.</b:Comments>
</b:Source>
</b:Sources>
