Johannes Obermaier

dblp:153/0959 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
2since 2021 · last 2021
0000-0001-8021-6132ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 1 first-authorSecurity and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2021 ARCHIE: A QEMU-Based Framework for Architecture-Independent Evaluation of Faults
abstract
Fault injection is a major threat to embedded system security since it can lead to modified control flows and leakage of critical security parameters, such as secret keys. However, injecting physical faults into devices is cumbersome and difficult since it requires a lot of preparation and manual inspection of the assembly instructions. Furthermore, a single fault injection method cannot cover all possible fault types. Simulating fault injection in comparison, is, in general, less costly, more time-efficient, and can cover a large amount of possible fault combinations. Hence, many different fault injection tools have been developed for this purpose. However, previous tools have several drawbacks since they target only individual architectures or cover merely a limited amount of the possible fault types for only specific memory types. In this paper, we present ARCHIE, a QEMU-based architecture-independent fault evaluation tool, that is able to simulate transient and permanent instruction and data faults in RAM, flash, and processor registers. ARCHIE supports dynamic code analysis and parallelized execution. It makes use of the Tiny Code Generator (TCG) plugin, which we extended with our fault plugin to enable read and write operations from and to guest memory. We demonstrate ARCHIE’s capabilities through automatic binary analysis of two exemplary applications, TinyAES and a secure bootloader, and validate our tool’s results in a laser fault injection experiment. We show that ARCHIE can be run both on a server with extensive resources and on a common laptop. ARCHIE can be applied to a wide range of use cases for analyzing and enhancing open source and proprietary firmware in white, grey, or black box tests.
Florian Hauschild, Kathrin Garb, Lukas Auer, Bodo Selmke, Johannes Obermaier
FDTC5
2021 FORTRESS: FORtified Tamper-Resistant Envelope with Embedded Security Sensor
abstract
Protecting security modules from attacks on the hardware level presents a very challenging endeavor since the attacker can manipulate the device directly through physical access. To address this issue, different physical security enclosures have been developed with the goal to cover entire hardware modules and, hence, protect them from external manipulation.Novel concepts are battery-less and based on Physical Unclonable Functions (PUFs), aiming at overcoming the most severe drawbacks of past devices; the need for active monitoring and, thus, limited battery life-time. Although some progress has already been made for certain aspects of PUF-based enclosures, the combination and integration of all required components and the creation of a corresponding architecture for Hardware Security Modules (HSMs) is still an open issue. In this paper, we present FORTRESS, a PUF-based HSM that integrates the tamper-sensitive capacitive PUF-based envelope and its embedded security sensor IC into a secure architecture. Our concept proposes a secure life cycle concept including shipment aspects, a full key generation scheme with re-enrollment capabilities, and ourthe next generation Embedded Key Management System. With FORTRESS, we take the next step towards the productive operation of PUF-based HSMs.
Kathrin Garb, Johannes Obermaier, Elischa Ferres, Martin Künig
PST2
2020 Temporary Laser Fault Injection into Flash Memory: Calibration, Enhanced Attacks, and Countermeasures
abstract
There exist different attacks on microcontroller and embedded system security. One of them is laser fault injection (LFI). Laser fault injection into flash memory that has only temporary effects has been observed by several research groups. However, up to this date, the experiments have been conducted under specific conditions which differ from realistic applications and the search for the respective laser position was described as being cumbersome. We present several temporary LFI experiments on flash memory that produce reliable results in real-life conditions and discuss a simple method to calibrate the laser to obtain the desired faults and reproduce them reliably. Furthermore, we discuss countermeasures to the described attack, considering flash-aware error detection that is able to detect the injected faults and data degradation.
Kathrin Garb, Johannes Obermaier
IOLTS2
2018 A measurement system for capacitive PUF-based security enclosures
abstract
Battery-backed security enclosures that are permanently monitored for penetration and tampering are common solutions for providing physical integrity to multi-chip embedded systems. This paper presents a well-tailored measurement system for a batteryless PUF-based capacitive enclosure. The key is derived from the PUF and encrypts the underlying system. We present a system concept for combined enclosure integrity verification and PUF evaluation. The system performs differential capacitive measurements inside the enclosure by applying stimulus signals with a 180° phase shift that isolate the local variation in the femtofarad range. The analog circuitry and corresponding digital signal processing chain perform precise PUF digitization, using a microcontroller-based digital lock-in amplifier. The system's measurement range is approximately ±73 fF, the conversion time per PUF node is less than 0.6 ms, and the raw data shows a measurement noise of 0.3 fF. This is the base for a high-entropy key generation while enabling a short system startup time. The system is scalable to the enclosure size and has been experimentally verified to extract information from 128 PUF nodes, using a system prototype. The results show that our concept forms a cornerstone of a novel batteryless PUF-based security enclosure.
Johannes Obermaier, Vincent Immler, Matthias Hiller, Georg Sigl
DAC1