Tensions in Practice: Data-dependent speed in tension with hiding a work trace¶
Record lookup · selected observable
A toy lookup searches three positions for one matching record. It returns only “Found,” but an observer can also count comparisons. Stopping at the match reveals its position through the amount of work. Checking all three positions keeps that count fixed. The public answer is identical; the selected trace is not.
Avoid unnecessary comparisons
Stop when the required answer has been established.
Hide the matching position
Keep the selected comparison-count trace independent of where the record sits.
Why these aims pull against each other
Skipping work produces a useful speed difference and a revealing trace. Flattening that trace adds work when the match is early.
Choose an arrangement to see what changes and what remains difficult.
Finite illustrative comparisons. Text states carry the meaning; color is not a measured score or universal preference.
What this choice protects
What it costs
When it fits
Compare the arrangements
Stop at match
The record occurs exactly once. Check positions in order and stop at the first match.
| Checks | Answer | Position shown? | |
|---|---|---|---|
| Match at 1 | 1 | Found | Yes |
| Match at 2 | 2 | Found | Yes |
| Match at 3 | 3 | Found | Yes |
- What it protects
- An early match requires only one or two comparisons.
- What it costs
- Anyone who can count comparisons learns the matching position.
- When it fits
- The position is public, or this selected observable is outside the application’s confidentiality requirement and the saved work matters.
Illustration note: The finite setting and values are editorial assumptions, not measured effects or recommended operating settings. The observer is stipulated to see the exact count; no attack on a real implementation is demonstrated.
Check all three
Check every position and combine the match results into the same “Found” answer.
| Checks | Answer | Position shown? | |
|---|---|---|---|
| Match at 1 | 3 | Found | No |
| Match at 2 | 3 | Found | No |
| Match at 3 | 3 | Found | No |
- What it protects
- The count is three for every possible matching position in this model.
- What it costs
- An early match still pays for the remaining comparisons: two extra at position one and one extra at position two.
- When it fits
- The position must remain hidden from this observer, and the implementation can enforce the stated fixed-work behavior.
Illustration note: The finite setting and values are editorial assumptions, not measured effects or recommended operating settings. Fixed comparison count does not prove constant execution time or eliminate memory, power, traffic or other channels.
What this illustration does—and does not—establish
Side Channel Attack: Coupling: Function Requires the Variation That Leaks supplies the function/variation conflict. The finite lookup and count-visible observer are editorial assumptions.
- Every row contains one match; missing-record behavior is outside the example.
- The labels concern comparison count alone, not a complete confidentiality guarantee.
- An observable matters as a side channel only when it carries protected information that the observer can measure.
Source entries
Side Channel Attack
Side Channel Attack: Coupling: Function Requires the Variation That Leaks supplies the conflict examined here.
Coupling: Function Requires the Variation That Leaks
Confidentiality wants behavior invariant to secrets; usefulness requires behavior that varies with inputs — and inputs are often correlated with secrets.
Structural Tensions
Diagnostic: ask what observable would falsify the proof, and whether anyone budgeted to measure it.