Christian Steger

dblp:50/4233 · DBLP profile ↗
← Back
110ranked-venue papers
0as first author
16since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 62 · 7 since 2021Software engineering, systems software and programming languages · 20 · 1 since 2021Security and privacy · 12 · 2 since 2021Artificial intelligence and machine learning · 6 · 2 since 2021Computer networks · 5Applied, interdisciplinary, general and emerging computing · 4Databases, data management, data science and information retrieval · 2 · 2 since 2021Theory of computation · 2
YearPublicationVenuePosition
2025 Exploring the Design Space and Research Directions for Digital Product Passport Systems
abstract
In this paper, we identify three major technical dimensions of a Digital Product Passport (DPP) system: data carrier, online storage for product information, and updating dynamic data. For each dimension, we first explore the design space in terms of architectural options and technical challenges, and then propose corresponding research directions. Specifically, this paper discusses key challenges such as counterfeiting, interoperability, and data sovereignty, and calls for research in areas such as decentralized identity and granular access management.
Stefan Kaser, Christian M. Lesjak, Rainer Matischek, Christian Steger
CNSM4
2025 SeaSentry: Maritime Real-Time Positioning in a Passive Radar-Detector Network
abstract
Maritime transport and vessel monitoring rely on multiple systems for positioning, such as the Automatic Identification System, electro-optical systems, and shore-based radar systems, to improve safety and efficiency in vessel tracking. However, each system has inherent limitations, including coverage gaps, reliance on vessel compliance, and limited real-time monitoring capabilities. As a complementary approach to existing methods and systems, this paper presents the SeaSentry system, a passive sensor network designed to detect, position, and track vessels in real time, thus eliminating the need for onboard installations. The sensors detect radar pulses emitted by the vessels' rotating radar antennas and compute time stamps as the radar beams pass over them. Geometric constraints can be derived from time differences of arrival to localize the vessels, with time error and synchronization demands in the millisecond range. Along with some initial results, this paper discusses the SeaSentry setup and data processing pipeline.
Taruna Tiwari, Christopher Funk, Benjamin Noack, Christian Steger, Hilko Wiards, Matthias Steidel, Florian Schiegg, Nhat M. Hoang, Mohit Mittal, Vesa Klumpp, Jörn Beschnidt
FUSION5
2025 Domain-Randomized Pointcloud Simulation and Label Filtering for Industrial 3D Object Detection
abstract
Recent advances in the generation of synthetic data for artificial intelligence have led to the development of simulators and the integration of physically accurate sensor behavior. Typically, machine learning models require large amounts of data, which are costly and time-consuming in collecting and labeling data. Thus, data aggregation is a challenging part of artificial intelligence. Most open-source simulators focus on autonomous driving, which limits their applicability for other use-cases. This work provides a new approach for an alternative simulator that is highly flexible, usable in any domain and, therefore, solves the problem described before. This simulator is based on the Isaac Sim framework and uses a new method to filter the bounding boxes using a clustering algorithm. A study on object detection for pallets and containers within a warehouse environment for autonomous robots shows that synthetic data is challenging realworld data by outperforming the baseline model by +7.24 in Average Precision utilizing the PointPillar architecture. Further, fine-tuning the weights with a small set of real-world data significantly improves the model, increasing its Average Precision by +24.79 relative to the baseline.
Christof Schützenhöfer, Sebastian Reicher, Thomas Ulz, Christian Steger
ICTAI4
2024 PAKA: Pseudonymous Authenticated Key Agreement without bilinear cryptography
abstract
Anonymity and pseudonymity are important concepts in the domain of the Internet of Things. The existing privacy-preserving key agreement schemes are only concerned with maintaining the privacy of the communicated data that appears on the channel established between two honest entities. However, privacy should also include anonymity or pseudonymity of the device identity. This means there should not exist any correlation handle to associate different communications done by the device.
Raphael Schermann, Simone Bussa, Rainer Urian, Ronald Toegl, Christian Steger
ARES5
2024 Utilizing 1D FMCW Radar Data for Distance Estimation to Port Infrastructure
abstract
Assistance systems play an important role in the proceeding transition of surface vessels towards highly automated operations. Particularly when navigating through congested areas like harbors, exact knowledge of distances to nearby obstacles is essential for collision avoidance. This paper applies a combined filtering and clustering approach in order to utilize 1D FMCW radar data for distance estimation to nearby obstacles in the harbor environment. The data processing aims at clearing the raw sensor data from unwanted signals caused by environmental influences like rain or waves and determines a reliable distance from the relevant signals. We evaluate our approach using sea trial data from a research vessel, comparing processed radar distances with a DGPS-based ground truth. The study assesses the performance of three density-based clustering algorithms-DBSCAN, HDBSCAN, and OPTICS-in this context. All of these algorithms show a good performance for processing the 1D FMCW data for our use case, enabling a reliable distance determination to a static obstacle. OPTICS performs slightly better in terms of eliminating disturbing signals than the remaining two algorithms. The processing times of all algorithms were found to be sufficient for online application of the proposed approach.
Mirjam Bogner, Fynn Pieper, Christian Steger, Matthias Steidel, Janusz A. Piotrowski, Sebastian Feuerstack
FUSION3
2023 Establishing Dynamic Secure Sessions for ECQV Implicit Certificates in Embedded Systems
abstract
Implicit certificates are gaining ever more prominence in constrained embedded devices, in both the internet of things (IoT) and automotive domains. They present a resource-efficient security solution against common threat concerns. The computational requirements are not the main issue anymore, with the focus now shifting to determining a good balance between the provided security level and the derived threat model. A security aspect that often gets overlooked is the establishment of secure communication sessions, as most design solutions are based only on the use of static key derivation, and therefore lack the perfect forward secrecy. This leaves the transmitted data open for potential future exposures as keys are tied to the certificates rather than the communication sessions. We aim to close this gap and present a design that utilizes the Station to Station (STS) protocol with implicit certificates. In addition, we propose potential protocol optimization implementation steps and run a comprehensive study on the performance and security level between the proposed design and the state-of-the-art key derivation protocols. In our comparative study, we show that we are able to mitigate many session-related security vulnerabilities that would otherwise remain open with only a slight computational increase of 20% compared to a static elliptic curve digital signature algorithm (ECDSA) key derivation.
Fikret Basic, Christian Steger, Robert Kofler
DATE2
2023 Secure Data Acquisition for Battery Management Systems
abstract
The growing awareness of environmental sustain-ability has led to new investments in the field of electric vehicles. One of the most expensive and important components of electric vehicles are their batteries, with battery management systems (BMS) being responsible for their control. New regulations, such as those of the European Union, aim to introduce battery passports as a way to track battery lifecycle from manufacturing, over second-life use, to recycling. Given the vast amount of data generated during the lifecycle of a battery, the current research is focused on combining BMS with cloud connectivity. However, not much research has yet been done in the area of BMS cloud security and secure data logging. To address this gap, we propose a novel solution for secure BMS data acquisition for on-premise and cloud environments. In this paper, we make two main contributions: a secure data structure for BMS logging and a secure architecture for transferring BMS data from its source to cloud and end systems. We demonstrate the feasibility of the design by developing a prototype with real components and evaluate it in terms of security and performance.
Fikret Basic, Christian Seifert, Christian Steger, Robert Kofler
DSD3
2023 Integration of the TPM in the AACKA Protocol
abstract
Anonymous credential schemes are commonly used to implement privacy-preserving cryptographic protocols. While Trusted Computing platforms are used to establish trust within a network. In this paper we show how a recently proposed Anonymous Authenticated Credential Key Agreement scheme (AACKA) can be used with a off-the-shelf TPM and what is necessary for it. We also introduce promising TPM-related use cases where the AACKA protocol can be applied. Finally, we evaluate the implementation with a hardware TPM and propose extensions for a standard TPM2.0 in order to enhance security.
Raphael Schermann, Rainer Urian, Christian Steger
DSD3
2022 Poster: Establishing Dynamic Secure Sessions for Intra-Vehicle Communication Using Implicit Certificates
Fikret Basic, Christian Steger, Robert Kofler
EWSN2
2022 Enabling Anonymous Authenticated Encryption with a Novel Anonymous Authenticated Credential Key Agreement (AACKA)
abstract
Anonymous credential schemes based on elliptic curve pairings are often used to implement privacy-friendly cryptographic protocols, with Direct Anonymous Attestation and Enhanced Privacy IDentification being the most prominent anonymous credential schemes. However, all those schemes are signature-based and do not immediately provide for agreement of (symmetric) encryption keys.In this paper we present a scheme for Anonymous Authenticated Credential Key Agreement, which can be used in anonymously authenticated encryption schemes. This novel building-block combines Camenisch-Lysyanskaya credentials with elliptic curve Diffie-Hellman key agreement.We show how the Authenticated Anonymous Key Agreement protocol can be used to design an anonymous credential based Elliptic Curve Integrated Encryption scheme and argue that it is more efficient than conventional hybrid approaches. We show the applicability of our scheme on performance-restricted Internet of Things devices in Cloud-, Fog-, or Edge-Computing scenarios. In particular, we provide an implementation and a performance evaluation for a standard-compliant Java Card 3.1 device.
Raphael Schermann, Rainer Urian, Ronald Toegl, Holger Bock, Christian Steger
TrustCom5
2021 An adaptive pixel accumulation algorithm for a 1D micro-scanning LiDAR
abstract
In advanced driver-assistance systems, LiDAR data are used for range detection and obstacle avoidance in combination with other sensors. The frame rate of a LiDAR sensor corresponds to the data availability that is crucial for efficient data fusion. In 1D micro-scanning LiDAR, pixel accumulation is introduced to increase data signal-to-noise ratio and typically performed a fixed number of times that directly affects pixel acquisition time and frame rate. In this paper, we present an adaptive pixel accumulation algorithm that not only reduces required on-chip memory array by compressing LiDAR raw data, but also increases data availability for occupancy grid computation by enabling an early peak detection and eliminating unnecessary accumulation cycles whenever possible. We implemented this concept on FPGA and compared its efficiency with a state-of-the-art approach. Presented simulation and measurement results show an improvement of data availability in short and mid-range scenarios or when detecting a highly reflective target.
Ievgeniia Maksymova, Christian Steger, Norbert Druml
DSD2
2021 Single-Frame Direct Reflectance Estimation With Indirect Time-of-Flight Cameras
abstract
Computer vision algorithms are influenced by variations in lighting conditions. Images, independent of lighting conditions have the potential to improve tasks such as material and object classification. For Time-of-Flight (ToF) cameras the largest variation in lighting condition is caused by the distance between the camera and the object. ToF cameras are intended for 3D distance measurement. However, the features which enable distance measurement can be used to realize methods to record distance normalised grey images.In this paper, we explore methods to extract direct reflectance estimates from ToF measurements. We propose two novel methods relying on coded modulation (CM) and compare them to a method that can convert data from the state-of-the-art continuous wave (CW) measurement method. With the invention of the CM based methods, we can realize the normalization in a single frame measurement, compared to the four frames recorded by the CW method.All three methods are evaluated based on simulation results and in-laboratory measurements. We are able to demonstrate that our novel methods, relying on CM, can achieve the desired measurement behaviour.
Caterina Nahler, Armin Schoenlieb, Sebastian Handel, Hannes Plank, Christian Steger, Norbert Druml
DSD5
2021 Towards a More Flexible IoT SAFE Implementation
abstract
The Internet of Things (IoT) is disseminating our daily life and gets ubiquitous not only in industry. With this growth, device and communications security is increasingly important. Hardware Security Modules (HSMs) are integrated into IoT devices to provide a "Root of Trust", and protect confidential key material. Due to lack of standardization, HSM manufacturers implement proprietary interfaces. To ease integration of hardware security, and enable interoperability, the GSMA proposes IoT SAFE, a standardized interface. In this work, IoT SAFE is evaluated and compared against the interfaces of proprietary HSMs. Improvements are proposed to reduce complexity, increase flexibility, and ease the integration into Transport Layer Security (TLS) libraries. The evaluation shows that the TLS handshake performance can be improved significantly for ECC and RSA certificate-based client authentication. The message count between HSM and hosting device is reduced by approximately 40% and 25%, respectively.
Dominic Pirker, Christoph Reiter, Harald Witschnig, Christian Steger
DSD5
2021 Generating a PUF Fingerprint from an on-Chip Resistive Ladder DAC and ADC
abstract
This paper introduces an approach of extracting process variations inside System-on-Chips (SoCs) to derive a Physical Unclonable Function (PUF). The process variations are extracted from the architecture of a Digital-to-Analog Converter (DAC). The DAC consists of two independent resistive ladders to provide one single or two output voltages. The resistive ladder is characterized by the SoC with the on-chip Analog-to-Digital Converter (ADC) module. The developed PUF concept that exploits the process variations of the DAC is described and evaluated in this work. Due to the concept of not accepting an input challenge to the PUF, we designed a so-called weak-PUF. The final generated PUF response or also called fingerprint has a total length of 652 bits when using the maximum number of possible positions. In a typical operation condition, a worst-case intra-Hamming Distance (HD) of approximately 5% is achieved. Over a wide temperature range of -10°C to 70°C the intra-HD is increased to 13% in the worst-case. The inter-HD for all observed operating conditions is approximately 46%.
Christian Zajc, Markus Haberler, Gerald Holweg, Christian Steger
ISNCC4
2021 Towards Dynamic Master Determination in MEMS-based Micro-Scanning LiDAR Systems
abstract
Automated driving has been expected for decades. The first systems, which at least partially automate the vehicle, have been installed in higher priced vehicles for several years. In the near future, however, many more competencies are to be transferred to the systems and the vehicle will thus be fully automated. Such systems receive their data from various sensor systems such as Light Detection And Ranging (LiDAR). Therefore, it is essential that this information is transmitted correctly and reliably to the environmental perception system. In order to ensure this, redundancy of sensors is a key factor in addition to diversity. For example, multiple, independently controlled MEMS-based LiDAR systems can be operated synchronously. This requires the selection of a Master system which can be reliably followed by all Slave systems. In this publication, an architecture for MEMS-based Micro-Scanning LiDAR systems is proposed to determine the appropriate system as Master. The architecture has been implemented in an FPGA prototyping platform to demonstrate its feasibility and evaluate its performance.
Philipp Stelzer, Andreas Strasser, Christian Steger, Norbert Druml
IV3
2021 Design Space Exploration for Secure IoT Devices and Cyber-Physical Systems
abstract
With the advent of the Internet of Things (IoT) and Cyber-Physical Systems (CPS), embedded devices have been gaining importance in our daily lives, as well as industrial processes. Independent of their usage, be it within an IoT system or a CPS, embedded devices are always an attractive target for security attacks, mainly due to their continuous network availability and the importance of the data they handle. Thus, the design of such systems requires a thorough consideration of the various security constraints they are liable to. Introducing these security constraints, next to other requirements, such as power consumption, and performance increases the number of design choices a system designer must consider. As the various constraints are often conflicting with each other, designers face the complex task of balancing them. System designers facilitate Design Space Exploration (DSE) tools to support a system designer in this job. However, available DSE tools only offer a limited way of considering security constraints during the design process. In this article, we introduce a novel DSE framework, which allows the consideration of security constraints, in the form of attack scenarios, and attack mitigations in the form of security tasks. Based on the descriptions of the system’s functionality and architecture, possible attacks, and known mitigation techniques, the framework finds the optimal design for a secure IoT device or CPS. Our framework’s functionality and its benefits are shown based on the design of a secure sensor system.
Lukas Gressl, Christian Steger, Ulrich Neffe
ACM Trans. Embed. Comput. Syst.2
2020 Adaptive MEMS Mirror Control for Reliable Automotive Driving Assistance Applications
abstract
A continuously growing interest towards autonomous vehicles highlights the need of robust sensors that will reliably operate under harsh environmental conditions. In this paper, we analyze environmental disturbances that influence the optical sensing accuracy of a MEMS-based LiDAR (Light Detection and Ranging) sensor, and propose an adaptive control scheme of the MEMS mirror that lower the impact of disturbances on the sensing accuracy. This scheme exploits data from various internal and external monitors and adapts MEMS mirror control parameters such that the angular RMS jitter does not exceed 15m° when environmental conditions change. Measurement results show that this approach not only introduces robustness in the MEMS mirror control loop but also improves overall reliability of ADAS applications.
Ievgeniia Maksymova, Philipp Greiner, Christian Steger, Leonhard Christian Niedermueller, Norbert Druml
DSD3
2020 Quantitative and Qualitative Evaluation Methods of Automotive Time of Flight Based Sensors
abstract
Time of Flight (ToF) based three-dimensional (3D) imaging sensors, such as Light Detection and Ranging (LiDAR) sensors or ToF cameras, can be used to depict their surroundings in form of a point cloud. The ToF method measures the time an emitted light signal takes to be reflected by a point in space and derives the distance from the known travel time of light. More and more ToF based 3D sensors are developed for automotive use as their target application. Automotive sensors are part of a safety critical application. Therefore, it is important to ensure that the provided sensor data is accurate with a known probability. In this paper, we describe and evaluate test procedures for quantitative and qualitative performance evaluation of ToF/LiDAR sensors with focus on automotive use. We propose a LiDAR error and influence model from which we derived eight test areas. We described and conducted tests for six of the eight test areas. The described test cases were evaluated on three LiDAR sensors and one ToF camera. The results show that targets and test procedures need to be adapted to the specific tested ToF/LiDAR sensor. Especially noticeable where influences on test procedures due sparse sensor resolution. Furthermore, the test results show that target application specific tests can provide additional information on the behaviour of the sensor.
Caterina Nahler, Christian Steger, Norbert Druml
DSD2
2020 A Hybrid Timestamping Approach for Multi-Sensor Perception Systems
abstract
Synchronized and precisely timestamped data from perception sensors is highly advantageous for the low-level fusion of multiple sensor data. Many open-available, low-cost perception sensors do neither provide hardware support for precise clock synchronization, nor provide timestamps with their measurement data. In this work, we present an approach to enable synchronization and accurate timestamping of hardware-triggerable sensors in multi-sensor perception systems.We utilize a hybrid timestamping approach, taking into account the timestamp of a hardware trigger and the software timestamp. The presented timestamping approach utilizes the trigger time to assign precise timestamps to the data streams of the perception sensors. Precise timestamps are mandatory in order to achieve a high perception performance in dynamic applications which utilize low-level data streams.Additionally, we present an implementation of the approach on a multi-sensor perception platform, archiving a timestamp precision in the range of 2 ms. An existing Robot Operating System (ROS) architecture of the platform is extended to assign hybrid timestamps to the data streams. Additionally, we present a pedestrian detection implementation which fuses the timestamped data into a representation.
Josef Steinbaeck, Christian Steger, Eugen Brenner, Norbert Druml
DSD2
2020 Enabling Fail-Operational Behavior and Degradation for Safety-Critical Automotive 3D Flash LiDAR Systems
abstract
Advancing the current Advanced Driver Assistance Systems (ADAS) is coupled with introducing novel technologies into the automotive domain such as Light Detection and Ranging (LiDAR). LiDAR is attributed as a key-technology that will be one of the key enablers for safe and reliable automated driving. Considering the fact that vehicles nowadays rely on the driver in safety-critical situations leads to the problem that in a fully-automated driving scenario the vehicle needs to control every possible situation on its own. This increases the requirements and the overall safety level of the system but also for each component and needs a gradual transition from fail-safe to fail-operational behavior at least as long as the occupants and other road participants could be endangered.This publication introduces a novel system architecture of a fail-operational 3D Flash LiDAR System that enables dynamic system degradation during run-time as well as internal built-in self-test (BIST) for automated failure injection tests. The novel fail-operational system architecture is able to handle critical temperature ranges as well as long-term memory faults.
Andreas Strasser, Philipp Stelzer, Felix Warmer, Christian Steger, Norbert Druml
DSD4
2020 Optimizing Picnic for Limited Memory Resources
abstract
Picnic is a post-quantum digital signature scheme, where the security is based on the difficulty of inverting a symmetric block cipher and zero-knowledge proofs. However, generating a Picnic signature to a specific message requires up to 300 kB content depending RAM. As the memory of an IoT device is limited this can lead to issues at the implementation. Our target is bringing post-quantum cryptography to IoT systems. We propose three structural adjustments of the Picnic algorithm to reduce the memory usage. Two adjustments are compatible with the reference implementation, one of them breaks backward compatibility. We show analytically that the content depending memory for generating a signature can be decreased to under 10 kB.With these adjustments, Picnic becomes suitable for IoT devices with little RAM. Since our approach also aims at easier parallelization, a speed-up depending on the number of instances is possible.
Johannes Winkler, Andrea Höller, Christian Steger
DSD3
2020 System Architecture and Security Issues of Smartphone-based Point-Of-Care Devices
abstract
In recent years, personalized healthcare has become increasingly popular in our society. Wearable devices started a trend for monitoring physical health parameters. The next evolution after wearable devices are Point-Of-Care (POC) devices, which provide more vital parameter analyses for everyone. The electrification of POC devices is required to simplify the process and to increase the accuracy of measurement results. In this work, we focus on POC devices in combination with smartphones. Of Ten, these devices are measuring and processing very sensitive data, which underlie a high privacy restriction. Therefore, it is required to provide an architecture and security issue analysis of POC devices. The outcome of this research contribution provides a sensitization for the requirement of enhanced security features. Especially, to fulfill the need for a power-aware security concept for a POC system architecture, which underlies limited resources like power consumption.
Christian Zajc, Gerald Holweg, Christian Steger
DSD3
2020 Multi-Layered IoT System Design Towards End-to-End Secure Communication
abstract
An increasing amount of sensory data, often of confidential nature, is exchanged day by day: from the sensor and actuator layers over smart gateways to the business logic and analytics level. Robust yet efficient security measures play an essential role in this interaction. However, the complexity of securely connecting different building blocks of a distributed, multi-layered systems is considerable. Security methodologies are often applied at a late stage of system development, posing problems such as inappropriate security levels, performance issues, and longer time-to-market cycles. Addressing possible security properties already in the design phase of a security-critical system helps to mitigate these problems. In this paper, we discuss a distributed, multi-layered IoT data collection system that enables data aggregation and exchange from the embedded level up to different cloud instances while supporting end-to-end secured communication. The system was designed in the course of a case study where we used a design-space-exploration tool for identifying secure processes in regard to key management and distribution. Based on our analysis results, a distributed proof of concept was developed. Subsequently, the most critical processes of the individual layers were evaluated regarding security and execution speed.
Alexander Rech, Lukas Gressl, Fikret Basic, Christian Seifert, Christian Steger, Andreas Daniel Sinnhofer
IECON5
2020 Multi-Depth Sensing for Applications With Indirect Solid-State LiDAR
abstract
In recent years, topics like autonomous driving increased the demand on robust environmental sensors. Depth sensors are most commonly used. Solid state Light Detection And Ranging (LiDAR) sensors are well suited for these applications. The measurement principle is based on measuring the phase and consequently the delay of emitted and reflected light. Problems arise if strong reflectors, like street-signs, impair the measurement. In this paper, we present a novel algorithm for depth calculation, based on indirect Time-of-Flight (ToF) data. With this approach it is possible to separate multiple reflectors in the scenery. This allows the generation of multiple depth images. In our approach an arbitrary number of different code sequences are applied as modulation signal. With these code sequences we generate a so called ToF-matrix. With this ToFmatrix, the measured environmental response can be mapped to a distance. As our evaluation shows, our method is able to achieve results with more information compared to conventional ToF-imaging. We demonstrate the separation of the reflection of a street-sign, from a target. This algorithm enables the usage of indirect ToF in automotive areas. We believe that this versatile calculation approach can increase the benefit of indirect LiDAR application for autonomous driving.
Armin Schoenlieb, David Lugitsch, Christian Steger, Gerald Holweg, Norbert Druml
IV3
2020 Towards Synchronisation of Multiple Independent MEMS-based Micro-Scanning LiDAR Systems
abstract
In intelligent vehicles, it is indispensable to have reliable Advanced Driver-Assistance Systems (ADAS) on board. These ADAS require various types of sensors, like Light Detection and Ranging (LiDAR). Nowadays, drivers delegate some responsibilities to their highly automated vehicles; however, it is not legally secured. Nevertheless, the legislator will, in the future, deal with automated vehicles. The fundamentals will be laid to ensure that the transfer of responsibilities will be permitted under certain conditions. Car manufacturers, on the other hand, must ensure that components are safe and reliable. With LiDAR, this could be achieved with Micro-Electro-Mechanical System (MEMS) technology. As with humans as drivers, it is also advantageous for intelligent systems if obstacles in the environment are detected promptly. Especially when the obstacles are moving, it helps to initiate appropriate measures, such as braking. Therefore, it is attempted to extend the Field-of-View (FoV) of the various sensors. By synchronising multiple MEMS mirrors, it is able to extend the FoV of the LiDAR part in an environmental perception system. In this publication, an architecture is proposed for MEMS-based Micro-Scanning LiDAR Systems to achieve synchronisation of multiple independently controlled MEMS mirrors. The architecture was implemented in an FPGA prototyping platform to show its feasibility and evaluate its performance.
Philipp Stelzer, Andreas Strasser, Christian Steger, Hannes Plank, Norbert Druml
IV3
2020 Trigger Alarm: A Smart NFC Sniffer for High-Precision Measurements
Martin Erb, Christian Steger, Martin Troyer, Josef Preishuber-Pflügl
ICTSS2
2020 Towards an Automated Exploration of Secure IoT/CPS Design-Variants
Lukas Gressl, Michael Krisper, Christian Steger, Ulrich Neffe
SAFECOMP3
2019 Hybrid Sensing Approach For Coded Modulation Time-of-Flight Cameras
abstract
In recent years, application fields such as industrial automation and indoor robot navigation increased the demand on reliable localization systems. Simultaneous mapping and localization systems often depend on depth imaging in order to reconstruct the scene. Time-of-Flight sensors prove to be well suited for these applications, however are impaired by different error sources. The measurement principle is based on measuring the phase and consequently the delay of emitted and reflected light. Specular surfaces can cause pixel saturation, while the periodicity of the measured phase leads to ambiguous distances. In this paper, we aim to solve these problems by proposing a new Time-of-Flight depth sensing approach. By combining the emerging coded modulation method with traditional depth sensing, we are able to unify the advantages of both methods. Images captured with coded modulation show a pixel response only within selected distance limits. In contrast traditional continuous wave Time-of-Flight imaging exhibits a superior signal-to-noise ratio. This method enables to mask erroneous distance measurements, allowing Time-of-Flight sensors to produce more reliable depth measurements and gain traction in the industrial environment. As our evaluation shows, our method is able to remove the influence of specular surfaces, and is capable of masking ambiguous distance measurements. Furthermore, our approach improves the system behavior by enabling more robust exposure time control.
Armin Schoenlieb, Hannes Plank, Christian Steger, Gerald Holweg, Norbert Druml
DATE3
2019 Consideration of Security Attacks in the Design Space Exploration of Embedded Systems
abstract
Designing secure systems is a complex task, particularly for designers who are no security experts. Cyber security plays a key role in embedded systems, especially for the domain of the Internet of Things (IoT). IoT systems of this kind are becoming increasingly important in daily life as they simplify various tasks. They are usually small, either embedded into bigger systems or battery driven, and perform monitoring or one shot tasks. Thus, they are subject to manifold constraints in terms of performance, power consumption, chip area, etc. As they are continuously connected to the internet and utilize our private data to perform their tasks, they are interesting for potential attackers. Cyber security thus plays an important role for the design of an IoT system. As the usage of security measures usually increases both computation time, as well as power consumption, a conflict between these constraints must be solved. For the designers of such systems, balancing these constraints constitutes a highly complex task. In this paper we propose a novel approach for considering possible security attacks on embedded systems, simplifying the consideration of security requirements immediately at the start of the design process. We introduce a security aware design space exploration framework which based on an architectural, behavioral and security attack description, finds the optimal design for IoT systems. We also demonstrate the feasibility and the benefits of our framework based on a door access system use case.
Lukas Gressl, Christian Steger, Ulrich Neffe
DSD2
2019 Coded Modulation Simulation Framework for Time-of-Flight Cameras
abstract
In recent years, application fields such as secure face recognition or autonomous driving increased the demand on efficient depth sensing systems. Time-of-Flight (ToF) sensors are well suited for these applications. The measurement principle is based on measuring the phase and consequently the delay of emitted and reflected light. For this delay measurement a continuous wave signal is emitted. Coded modulation replaces this continuous wave signal with code sequences. This enables new possibilities as the measurement range of the camera is adjustable with coded modulation. A well suited way for the characterization of this modulation method is a simulation framework. In this paper, we present a simulation framework for coded modulation ToF imagers. We present a detailed description of our PMD technology. From this theoretical description, we adapt an existing simulation model for coded modulation ToF cameras. The model of the camera considers various different noise sources. Furthermore depth calculation principles of coded modulation are introduced. As our evaluation shows, our framework is able to simulate real life behavior of coded modulation. Furthermore we are able to model the correlation form, and consequently the depth and intensity measurement behavior. In the end we evaluate our simulation results with real live measurement data. With this framework easy to use evaluation of coded modulation will enable new applications for this technique.
Armin Schoenlieb, Matthias Almer, David Lugitsch, Christian Steger, Gerald Holweg, Norbert Druml
DSD4
2019 Occupancy Grid Fusion of Low-Level Radar and Time-of-Flight Sensor Data
abstract
We present an approach to fuse radar and time-of-flight (ToF) range sensor data into an occupancy grid. Fusing the low-level data at sensor level prevents the loss of precious information during compression and pre-processing. Constructing the low-level occupancy grid from raw sensor data enables the detection of occupied cells which are not clearly visible by any of the single sensors. Fusion of the heterogeneous sensor data enhances the perception quality since single sensors fail in certain conditions. Thus, the fusion at low-level holds a high potential to enhance the perception quality for automotive/robotic applications. We demonstrate our approach with real-world data from a mobile sensor platform with three ToF cameras and a 77 GHz high-resolution radar sensor. An occupancy grid is created whenever synchronized sensor data from all sensors is available. The proposed method performed successful detection of multiple pedestrians in different test scenarios. Our approach to build an occupancy grid from radar and optical range sensors can be used as a base in various short-range perception applications (e.g., in robotics or mobile devices).
Josef Steinbaeck, Christian Steger, Eugen Brenner, Gerald Holweg, Norbert Druml
DSD2
2019 Live State-of-Health Safety Monitoring for Safety-Critical Automotive Systems
abstract
Autonomously driving vehicles require higher safety and reliability standards than traditional human-driven vehicles as they need to be able to handle safety-critical situations on their own. Therefore, these systems needs to demonstrate fail-operational behavior to ensure safety of the passengers by basic car controls. Especially silent failures of semiconductor devices can be critical from a safety point of view. Semiconductor devices fail abruptly and cannot be detected in advance. This paper presents a novel sensor approach to detect those kind of silent failures ahead of time and to ensure safety for future advanced driver-assistance systems (ADAS) such as LiDAR (Light Detection and Ranging). We have evaluated the design of our novel sensor concept in SystemC which will be implemented in a LiDAR system to mitigate silent failures as well as enable dynamic safety contracts.
Andreas Strasser, Philipp Stelzer, Christian Steger, Norbert Druml
DSD3
2019 A Distributed Framework Towards Local and Online Service Access
abstract
Seamless integration of smart devices into our daily lives is becoming increasingly ubiquitous. In fact, different methods for accessing infrastructure and mobility services as well as connected information systems are part of today's smart cities. The problem is, however, that due to environmental and use case restrictions, no standard authentication and authorization scheme for accessing heterogeneous services (car access, charging, obtaining sensory data) can be applied. In this paper we present a distributed service management framework that provides different means for authentication and authorization to services, infrastructure, and datasets. The platform acts as a scalable trusted cloud layer that enables applications to access online and locally available smart city services. It issues and manages digital tokens for authenticating and entitling connected devices to access these services. Our developed proof of concept is a hybrid system consisting of a multi-layered cloud environment as well as mobile devices acting as clients (service-holders) and kiosks (service-redemption units) for redeeming services online (e.g. access data) or locally (e.g. access area). Even though we use a multi-layer approach, we achieve short waiting times for the user underlining the usability aspect of the developed prototype.
Alexander Rech, Maximilian Kammerer, Markus Pistauer, Christian Steger
ETFA4
2019 Security Driven Design Space Exploration for Embedded Systems
abstract
With the advent of the Internet of Things (IoT) and Cyber Physical Systems (CPS), embedded devices have been gaining importance in our daily lives, as well as industrial processes. Independent of their usage, be it within an IoT system or a CPS, embedded devices are always an attractive target for security attacks, largely due to their continuous network availability and the importance of the data they handle. Thus, the design of such systems requires a thorough consideration of the various security constraints they are liable to. Introducing these security constraints, next to other requirements (e.g. power consumption, performance, etc.), increases the number of design choices that must be taken. As the various constraints are often conflicting each other, designers are faced with the complex task of balancing them. To support a system designer in this job, Design Space Exploration (DSE) tools can be facilitated. However, available DSE tools only offer a limited way of considering security constraints during the design process. In this paper we introduce a novel DSE framework, which allows the consideration of security constraints, in the form of attack scenarios, and attack mitigations, in the form of security tasks. Based on the descriptions of the system's functionality and architecture, possible attacks, and known mitigation techniques, the framework finds the optimal design for an secure IoT device or CPS. Our framework's functionality and its benefits are shown based on the design of a secure sensor system.
Lukas Gressl, Christian Steger, Ulrich Neffe
FDL2
2019 Sensing Danger: Exploiting Sensors to Build Covert Channels
abstract
Recent incidents have shown that sensor-equipped devices can be used by adversaries to perform malicious activities, such as spying on end-users or for industrial espionage. In this paper, we present a novel attack scenario that uses unsecured embedded sensors to build covert channels that can be used to bypass security mechanisms and transfer information between isolated processes. We present covert channels that require read- and write-access for sensor registers as well as a covert channel that transfers data by just triggering sensor readings so that malicious behavior cannot be distinguished from normal sensor usage. For each presented covert channel we discuss the trade-off between data rate and the likelihood of being detected as well as potential countermeasures. The fastest covert channel we implemented achieves a data rate of 4844 bit/s while the stealthiest but slower covert channel cannot be distinguished from normal user behavior. To highlight the significance of these security issues, we used popular platforms, such as Linux and Android, to evaluate the presented covert channels. However, we do not make any assumption regarding the device’s platform, and thus we believe that the presented exploits pose a significant security risk for any sensor-equipped device.
Thomas Ulz, Markus Feldbacher, Thomas Pieber 0002, Christian Steger
ICISSP4
2019 A Novel Embedded Platform for Secure and Privacy-Concerned Cross-Domain Service Access
abstract
Connected driving is a hot topic in the automotive industry and a leverage to push new Mobility as a Service (MaaS) methodologies, making vehicles an essential part of the Internet of Things (IoT). However, these new technologies often lead to security risks and privacy concerns, especially due to the increasing number of datasets exchanged between vehicles, drivers, and local infrastructure. Furthermore, the possibilities for vehicles to access heterogeneous services offered by different service providers are often limited due to rigid system boundaries. In this paper we present a novel federated service management concept for increased interoperability across distinct services in the field of Smart Mobility and Smart Cities. Our approach provides secure authentication and authorization between cars, their drivers, and other information systems, while retraining the level of privacy according to the users' preferences. The scalability and dynamic configurability of the solution and the elaborated proof-of-concept will set it apart from application-centered gateways to an embedded generic platform by virtue of its modular software design.
Alexander Rech, Markus Pistauer, Christian Steger
IV3
2018 PRYSTINE - PRogrammable sYSTems for INtelligence in AutomobilEs
abstract
Among the actual trends that will affect society in the coming years, autonomous driving stands out as having the potential to disruptively change the automotive industry as we know it today. As a consequence, this will also highly impact the semiconductor industry and open new market opportunities, since semiconductors play an indispensable role as enablers for automated vehicles. Fully automated driving has been identified as one major enabler to master the Grand Societal Challenges of safe, clean, and efficient mobility. For this, fail-operational behavior is essential in the sense, plan, and act stages of the automation chain in order to handle safety-critical situations by its own, which currently is not reached with state-of-the-art approaches also due to missing reliable environment perception and sensor fusion. PRYSTINE, which was the highest ranked ECSEL project proposal in 2017, will realize Fail-operational Urban Surround perceptION (FUSION) which is based on robust Radar and LiDAR sensor fusion and control functions in order to enable safe automated driving in urban and rural environments. Furthermore, PRYSTINE will strengthen and extend traditional core competencies of the European industry, research organizations, and universities in smart mobility and in particular in the electronic component and systems and cyber-physical systems domain.
Norbert Druml, Georg Macher, Michael Stolz, Eric Armengaud, Daniel Watzenig, Christian Steger, Thomas Herndl, Andreas Eckel, Anna Ryabokon, Alfred Hoess, Sumeet S. Kumar, George Dimitrakopoulos 0001, Herbert Roedig
DSD6
2018 Virtual White Cane Featuring Time-of-Flight 3D Imaging Supporting Visually Impaired Users
abstract
Supporting visually impaired people in their everyday's life is of crucial importance. Thanks to the technological advancements in semiconductors and cyber-physical systems, novel powerful tools and capabilities emerged recently. The integration of miniaturized Time-of-Flight 3D imaging modules combined with vast CPU and GPU power into commercially available smart phones, is a major enabler for a future virtual white cane aiding visually impaired people. This work presents a virtual white cane prototype which in particular targets visually impaired persons and vulnerable road users in general. It exploits the unique 3D environment perception features of a commercially available smart phone in order to perceive the environment in a three dimensional way based on the Time-of-Flight 3D imaging technology. This work not only introduces new concepts, such as a combined v disparity / RANSAC ground plane detection and the so-called Conservative Polar Histogram, it also considerably outperforms the object detection performance compared to state-of-the-art approaches.
Norbert Druml, Thomas Pietsch, Markus Dielacher, Christian Steger, Marcus Baumgart, Cristina Consani, Thomas Herndl, Gerald Holweg
DSD4
2018 Design and Implementation of an HCI Based Peer to Peer APDU Protocol
abstract
An ever increasing number of System on Chips need secure storage of key material or confidential data, therefore relying on the usage of Secure Elements (SEs). In traditional systems, the SE is a passive device, communicating with the other system's components via a master-slave topology. As applications running on SEs tend to become more involved in the interaction with other components by actively sending out data, the present communication setup poses a hindrance. In this paper we propose a method, which allows the bidirectional exchange of command-response messages of the Application Protocol Data Unit (APDU) protocol, by encapsulating the APDU messages in packets defined by the Host Controller Interface (HCI). Thus, the master-slave based APDU protocol can be used in a peer to peer communication, without changing the APDU protocol, and minimally extending the HCI. In this paper, the HCI extensions of the new approach are explained. The HCI based approach is compared to a method, which only uses the APDU protocol, by evaluating a simulation based implementation, and comparing the expected performance of both approaches.
Lukas Gressl, Ulrich Neffe, Christian Steger
DSD3
2018 Design of a Low-Level Radar and Time-of-Flight Sensor Fusion Framework
abstract
We present an open hardware and software platform to efficiently fuse heterogeneous sensor data in an automotive/robotic context. The framework presented in this paper provides researchers a base platform in order to develop and evaluate sensor fusion strategies. In contrast to similar approaches, this framework exploits in particular the raw radar data and enables the fusion at low-level. The proposed system utilizes low-level data from radar sensors as well as indirect (e.g. 3D imaging) and direct (e.g. LIDAR) Time-of-Flight (ToF) sensors. After a configurable amount of pre-processing at sensor-level, the sensor data is transferred to a centralized platform and aligned temporally and spatially. We demonstrate the transformation of radar data into the 3D coordinate system in order to fuse it with point cloud data from ToF sensors. Due to the modular structure of the framework, it also enables the exploration of various system partitioning concepts.
Josef Steinbaeck, Christian Steger, Gerald Holweg, Norbert Druml
DSD2
2018 Inter-device Sensor-Fusion for Action Authorization on Industrial Mobile Robots
Sarah Haas, Andrea Höller, Thomas Ulz, Christian Steger
SAFECOMP4
2017 Hardware-Secured Configuration and Two-Layer Attestation Architecture for Smart Sensors
abstract
The necessity to (re-)configure Internet of Things devices such as smart sensors during their entire lifecycle is becoming more important due to recent attacks targeting these devices. Allowing configuration parameters to be changed in any phase of a smart sensor's lifecycle allows security updates or new key material to be applied. Also, the functionality of a smart sensor can be altered by changing its configuration. The challenges that need to be considered when enabling the configuration of arbitrary parameters are the security and usability of the configuration interface, the secured storage of confidential configuration data, and the attestation of successfully applied configuration updates. Therefore, we present an NFC-based configuration approach that relies on dedicated secured hardware to solve these challenges. In addition to a hardware extension for smart sensors, we also present a secured configuration protocol as well as a two-layer configuration attestation process to verify the correct utilization of all transmitted configuration parameters.
Thomas Ulz, Thomas Pieber 0002, Christian Steger, Sarah Haas, Rainer Matischek, Holger Bock
DSD3
2017 Security for building automation with hardware-based node authentication
abstract
Providing reasonable security is a fundamental requirement in building and home automation. The authenticity of devices must be protected to prevent cloned or corrupted devices from joining a private network. State-of-the-art systems already provide secured communication links either by a security layer in the interface protocol stack (e.g. the Security Manager Protocol in Bluetooth Low Energy) or by using the Transport Layer Security (TLS) protocol on top of the interface protocol. These solutions have in common that they only protect the communication links. Thus the system is still vulnerable to active and passive physical attacks that aim to clone the device or to extract the used keys. We show an approach with off-the-shelf security trust anchors that allows securing a device against such attacks. The proposed solution allows product authentication with low-cost ready-to-use components which can be easily integrated in an architecture similar to existing proposals. We demonstrate the feasibility of the approach by presenting a prototype implementation and discuss performance and security implications. The results indicate that the proposed architecture provides reasonable security at acceptable costs and can serve as template for many applications in the Internet of Things (IoT) context.
Christian H. Lesjak, Andrea Höller, Christian Steger
ETFA4
2017 Towards trustworthy data in networked control systems: A hardware-based approach
abstract
The importance of Networked Control Systems (NCS) is steadily increasing due to recent trends such as smart factories. Correct functionality of such NCS needs to be protected as malfunctioning systems could have severe consequences for the controlled process or even threaten human lives. However, with the increase in NCS, also attacks targeting these systems are becoming more frequent. To mitigate attacks that utilize captured sensor data in an NCS, transferred data needs to be protected. While using well-known methods such as Transport Layer Security (TLS) might be suitable to protect the data, resource constraint devices such as sensors often are not powerful enough to perform the necessary cryptographic operations. Also, as we will show in this paper, applying simple encryption in an NCS may enable easy Denial-of-Service (DoS) attacks by attacking single bits of the encrypted data. Therefore, in this paper, we present a hardware-based approach that enables sensors to perform the necessary encryption while being robust against (injected) bit failures.
Thomas Ulz, Thomas Pieber 0002, Christian Steger, Rainer Matischek, Holger Bock
ETFA3
2017 Synchronization of time-of-flight 3D sensors for optical communication
abstract
Time-of-Flight 3D imaging systems are promising transceivers for image sensor based optical communication. 3D sensing based on Time-of-Flight is the most miniaturized depth imaging technology available and is currently being integrated into consumer electronics such as smart phones. Optical line-of-sight communication with a depth imaging system offers complete location-awareness of the communication partner. This enables new opportunities in fields like secure authentication, augmented reality or vehicle to vehicle communication. We show how Time-of-Flight systems are capable of using phase shift keying of pulsed light (PLPSK) to transmit data over a line-of-sight connection. PLPSK is still unexplored in the domain of image sensors and enables Time-of-Flight sensors to transmit multiple bits per frame at rates of over 7 kHz. A serious problem however are asynchronous modulation signals, causing frequent transmission errors and impairing proper communication. In this work, we formulate and discuss the severity of the problem and propose a synchronization procedure. We evaluate our solution with a prototype system, and show that it is possible to reach a synchronization success rate of nearly 100% over a distance of 9 meter.
Hannes Plank, Armin Schoenlieb, Christoph Ehrenhöfer, Christian Steger, Gerald Holweg, Norbert Druml
ICC4
2017 High-performance indoor positioning and pose estimation with time-of-flight 3D imaging
abstract
In recent years, fields such as industrial automation, virtual and augmented reality and autonomous robotics increased the demand for location-awareness of electronic devices. Image sensor based inside-out localization and tracking systems are sufficiently accurate to determine the position and orientation of electronic devices. Without additional sensors however, these systems are impaired in reaching high update-rates, handling fast motions, and tend to be unable to provide localization with low latency. We present a new localization approach in our work, using Time-of-Flight 3D sensors in combination with small reflective markers. This allows to establish high-performance optical localization systems, delivering the position and orientation of a device at a rate of several hundred Hz. A novel Time-of-Flight 3D sensing procedure is introduced, enabling to measure the 3D positions of fast moving targets at unprecedented frame-rates. With this work, we aim to close the gap between indoor positioning and motion tracking, enabling a new class of location-aware devices.
Hannes Plank, Theresa Egger, Christoph Steffan, Christian Steger, Gerald Holweg, Norbert Druml
IPIN4
2017 Hardware Secured, Password-based Authentication for Smart Sensors for the Industrial Internet of Things
Thomas Pieber 0002, Thomas Ulz, Christian Steger, Rainer Matischek
NSS3
2017 Secured Offline Authentication on Industrial Mobile Robots Using Biometric Data
Sarah Haas, Thomas Ulz, Christian Steger
RoboCup3
2017 SystemC Test Case Generation with the Gazebo Simulator
abstract
The current approach of hardware simulators are testbeds that supply the Device under Test (DUT) with inputs.These sequences of inputs are the result of engineers reverse engineering the use cases extracting the inputs from them and adding some extreme cases.This paper describes an approach where the input sequences are generated directly from the use case itself.The use case is therefore simulated in an environmental simulator such as Gazebo.This generates the stimuli for the DUT.To facilitate the compatibility between the different simulation environments we present an easy-to-use and easy-to-implement communication strategy.
Thomas Pieber 0002, Thomas Ulz, Christian Steger
SIMULTECH3
2016 OptiSec3D - A new Paradigm in Secure Communication and Authentication featuring Time-of-Flight
Hannes Plank, Matthias Almer, Robert Lobnik, Christian Steger, Thomas Ruprechter, Holger Bock, Josef Haid, Gerald Holweg, Norbert Druml
EWSN4
2015 Where does all this waste come from?
abstract
Abstract Agile development processes are more flexible than conventional ones. They emphasize iterative development and learning over feedback loops. Nevertheless, we experienced some pitfalls in the application of agile processes in dependable software systems. We present here the experiences we gathered in the construction of high‐quality industrial software. Moreover, we will digest our experiences into a conceptual model of waste creation. This model will be refined to a case study where we take appropriate measurements in order to provide empirical evidence for it. Finally, we discuss the implications of the developed model, which helps to estimate the trade‐off between agile and traditional software processes. Copyright © 2015 John Wiley & Sons, Ltd.
Wolfgang Raschke, Massimiliano Zilli, Johannes Loinig, Reinhold Weiss, Christian Steger, Christian Kreiner
J. Softw. Evol. Process.5
2014 Hardware/Software Co-Design of Elliptic-Curve Cryptography for Resource-Constrained Applications
abstract
ECC is an asymmetric encryption providing a comparably high cryptographic strength in relation to the key sizes employed. This makes ECC attractive for resource-constrained systems. While pure hardware solutions usually offer a good performance and a low power consumption, they are inflexible and typically lead to a high area.
Andrea Höller, Norbert Druml, Christian Kreiner, Christian Steger, Tomaz Felicijan
DAC4
2014 A Flexible and Lightweight ECC-Based Authentication Solution for Resource Constrained Systems
abstract
RFID-based and NFC-based applications can be found, apart from others, in security critical application fields, such as payment or access control. For this purpose, Elliptic-Curve Cryptography (ECC) is commonly used hardware integrated in resource constrained applications in order to provide authenticity and data integrity. On the one hand, specialized crypto hardware approaches provide good performance and consume low power. On the other hand, they often lack flexibility, caused, for example, by hardware integrated protocols and cryptographic parameters. Here we present a flexible and lightweight ECC-based authentication solution that takes into account resource constrained systems. This technique permits to shift parts of the computational intense ECC calculations from the resource constrained device to the authentication terminal. By employing a security controller with a small multi-purpose hardware acceleration core, high computation speed is achieved and a maximum level of flexibility is maintained at the same time. We demonstrate the feasible implementation of the proposed technique by means of an Android-based reader / smart card system, which represent a prime example of contemporary power-constrained and performance-constrained embedded systems. An ECC-based authentication can be carried out on average within 25 ms and checked against a back-end server within 66 ms in a secured manner. Thus, a secured and flexible one-way authentication system is given that shows high performance. This solution can be utilized in a wide variety of application fields, such as anti-counterfeiting, where flexibility and low chip prices are essential.
Norbert Druml, Manuel Menghin, Adnan Kuleta, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
DSD4
2014 A Fault Attack Emulation Environment to Evaluate Java Card Virtual-Machine Security
abstract
Java-enabled smart cards are used in different fields of application, such as access control, electronic banking, and passports. On these cards, a standardized virtual machine runs, which protects the security-critical code and data using a sandbox model. Unfortunately, this sandbox can be circumvented by fault attacks, which corrupt the data on which the virtual machine operates. The fault emulation environment of this work enables the user to configure faults at definable Java applet code locations. The user specifies which Java code she wants to attack but does not need to provide any information on where these data are placed in the memory and when the memory is accessed. To enable this approach, our environment monitors the virtual machine during the applet execution to receive the information which Java code is currently executed and which security-critical memory regions are in use. Then, the faults are injected using a bus saboteur at the correct clock cycle and memory location. This generic high-level approach provides the environment user an abstraction of the internal states of the virtual machine and the emulated hardware. Therefore, our environment enables the recreation of currently known attacks and allows us to study the effects of fault attacks on the virtual-machine behavior. The concept was successfully evaluated by a Java wallet case study. This case study shows a speedup of 6,600 compared to a simulation.
Michael Lackner, Reinhard Berlach, Michael Hraschan, Reinhold Weiss, Christian Steger
DSD5
2014 Development Framework for Model Driven Architecture to Accomplish Power-Aware Embedded Systems
abstract
Developing an embedded system today means integrating a bundle of features into a constrained and complex system. Examples are Near Field Communication (NFC) handsets like smart phones, which will hit the 1.2billion mark in 2017. Model Driven Architecture (MDA) is an approach to handle this complexity. Challenges in MDA are the verification of power-requirements across the development phases and to find the suitable abstraction for the power models for higher abstraction levels. Therefore, we propose a framework for MDA to support cross-verification of these requirements. We implemented this framework and made a case study of developing a power-aware NFC-System. The case study shows that the framework allows a power-verification with an accuracy of 10%.
Manuel Menghin, Norbert Druml, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
DSD3
2014 Instruction Folding Compression for Java Card Runtime Environment
abstract
Java Card is a secure Java running environment targeted for smart cards. In such low-end embedded systems, ROM size and execution time play very important, usually opposing roles. Dictionary compression can be applied to the Java Card software architecture, but pays for the reduced ROM size of the applications with a higher execution time. On the other hand, acceleration mechanisms to speed up the execution need additional information or additional software complexity, with the effect of increasing ROM size. In this paper, we propose a dictionary compression system based on an instruction folding mechanism that permits a reduction in the ROM size of Java Card applications, and at the same time, a speed-up of their execution.
Massimiliano Zilli, Wolfgang Raschke, Reinhold Weiss, Johannes Loinig, Christian Steger
DSD5
2014 A High Performance Java Card Virtual Machine Interpreter Based on an Application Specific Instruction-Set Processor
abstract
Java Card is a Java running environment specific for smart cards. In such low-end embedded systems, the execution time of the applications is an issue of first order. One of the components of the Java Card Virtual Machine (JCVM) playing an important role in the execution speed is the bytecode interpreter. In Java systems the main technique for speeding-up the interpreter execution is the Just-In-Time compilation (JIT), but this resource consuming technique is inapplicable in systems with as restricted resources available as in smart cards. This paper presents a hardware/software co-design solution for the performance improvement of the interpreter. In the software domain, we adopted a pseudo-threaded code interpreter that allows a better run-time performance with a small amount of additional code. In the hardware domain, we proceeded moving parts of the interpreter into hardware, giving origin to a Java Card interpreter based on an application specific instruction set processor.
Massimiliano Zilli, Wolfgang Raschke, Reinhold Weiss, Johannes Loinig, Christian Steger
DSD5
2013 A defensive Java Card virtual machine to thwart fault attacks by microarchitectural support
abstract
Java Cards, which are primarily used to store security-sensitive data, are employed in a wide range of applications, such as authentication and banking. Because these data must be protected against logical and fault attacks, static and runtime verification must be performed to assure the security of Java applets. Currently, this verification is performed in the software. Runtime verification for counteracting fault attacks is costly due to additional execution time and memory consumption. To circumvent the drawbacks of software verification, we propose incorporating a microarchitectural support of runtime verification directly into smart card hardware. These new hardware features enable a defensive virtual machine to counteract buffer overflow attacks, type confusion attacks, control flow attacks, and data integrity attacks. To measure the additional overhead of hardware and performance, the new microarchitectural security features are integrated into a smart card prototype on a field programmable gate array board.
Michael Lackner, Reinhard Berlach, Michael Hraschan, Reinhold Weiss, Christian Steger
CRiSIS5
2013 Emulation-Based Fault Effect Analysis for Resource Constrained, Secure, and Dependable Systems
abstract
Testing hardware and software components regarding their fault detection and fault handling capabilities is of vital importance. However, considering the fact that security systems are built using several distributed hardware components (e.g., reader/smart card authentication system), testing each component individually is insufficient. Because novel system-wide multi-fault attack campaigns can be conducted, fault propagation as well as fault handling of the entire system must be regarded. State-of-the-art emulation-based fault analysis approaches neglect this system aspect as well as the fault impact on power dissipation and power supply. Here, we present a novel analysis methodology that characterizes the behavior of complete systems during the design phase, in terms of fault handling, power dissipation, and power supply. Emulation-based techniques are applied to provide cycle accurate analysis information of the system-under-test in real time. The presented approach is of importance when it comes to test resource constrained, dependable, and high secure system designs. We demonstrate the application of this approach by means of a reader/smart card authentication system. Furthermore, we show how system level-based multi-fault attacks can be emulated and how the resulting system behavior (e.g., power consumption, power supply, information leakage) can be exploited to extract security relevant information.
Norbert Druml, Manuel Menghin, Daniel Kroisleitner, Christian Steger, Reinhold Weiss, Armin Krieg, Holger Bock, Josef Haid
DSD4
2013 Power and Thermal Fault Effect Exploration Framework for Reader/Smart Card Designs
abstract
Power consumption and thermal behavior are important characteristics that need to be explored and evaluated during a product's development cycle. If not handled properly, the consequences are, for example, increased mean-time-to-failure and fatal timing variations of the critical path. In the field of contactlessly powered reader/smart card systems, a magnetic field strength exceeding the allowed maximum threshold may harm the smart card's hardware. Thus, secure smart cards must be designed to cope with faults provoked by power oversupply and thermal stress. Proper fault detection and fault handling are imperative tasks to protect internal secrets. However, state-of-the-art design exploration tools cover these smart card specific power and thermal stress issues only to some extent. Here we present an innovative high level simulation approach used for exploring and simulating secure reader/smart card systems, focusing on magnetic field oversupply and thermal stress evaluations. Gate-level-based power models are used besides RF-channel models, thermal models, and thermal effect models. Furthermore, fault injection techniques are featured to evaluate the fault resistance of a smart card system's software implementation. This framework grants software and hardware designers a novel opportunity to detect functional, power, thermal, and security issues during the design time. We demonstrate the usage of our exploration framework and show an innovative hardware design approach to prolong the lifetime of smart card electronics, which are exposed to high magnetic field strengths.
Norbert Druml, Manuel Menghin, Tobias Rauter, Christian Steger, Reinhold Weiss, Christian Bachmann, Holger Bock, Josef Haid
DSD4
2013 PtNBridge - A Power-Aware and Trustworthy Near Field Communication Bridge to Embedded Systems
abstract
More than 500 million Near Field Communication (NFC) devices will be delivered in 2014. This technology enables a lot of application fields like using it for bridges to embedded systems (e.g., smart meters). With this wireless bridge the user can interact with the embedded system using an off-the-shelf NFC-enabled smart phone. The user of such a bridge also trusts in the system's security. Furthermore, this security should not lead to an excessive battery drain of the smart phone nor the embedded system. This publication deals with these concerns and shows a method called PtNBridge. The method secures the whole communication path from the smart phone application to the accessed module in the embedded system (e.g., power sensor of the smart meter). To take account of the energy consumption, the PtNBridge has been analyzed and optimized to avoid an excessive battery drain. Two variants of the PtNBridge have been implemented, which aim for two different goals of power-aware security.
Manuel Menghin, Norbert Druml, Manuel Trebo Fioriello, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
DSD4
2013 Emulation-Based Test and Verification of a Design's Functional, Performance, Power, and Supply Voltage Behavior
abstract
Test and verification are essential parts during a product's development cycle. Simulation and emulation are well known techniques to test and verify the functionality of a design-under-test (DUT) before its tape-out. However, there are additional issues like peak power consumption and supply voltage drops, which can compromise a hardware's functionality. These issues are only partly covered by nowadays functional hardware emulation test and verification approaches. This paper presents a comprehensive emulation methodology. It combines functional hardware emulation with model-based performance, power, and supply voltage analysis techniques. The DUT, which has to be available in a hardware description language, is integrated into a FPGA along with designated analysis units. These analysis units implement models of the DUT's performance, power consumption, and supply voltage behavior. The presented emulation methodology allows a designer to test designs in such a way that the cycle accurate results are taken online, in real-time, and verify both functional and performance behavior, as well as power consumption and supply voltage levels. The proposed comprehensive emulation methodology is used, as an example of application, to verify the design of a LEON3 multi-core processor system as well as a RF-powered contacatless smart card. The depicted results demonstrate that this emulation approach is suitable to detect functional misbehavior caused by power and supply voltage hazards and how they influence the performance of the system.
Norbert Druml, Manuel Menghin, Christian Steger, Reinhold Weiss, Andreas Genser, Holger Bock, Josef Haid
PDP3
2013 Emulation-based design evaluation of reader/smart card systems
abstract
Design exploration and evaluation are essential tasks during a product's development cycle. Simulation and hardware emulation are common techniques to explore and evaluate the functionality of hardware/software designs. However, when it comes to distributed secure applications, like contactless reader/smart card systems, non-functional design properties and system aspects (e.g., conctactless power transfer, power consumption) have to be regarded too. State-of-the-art simulation-based and emulation-based design exploration tools cover these design issues and system aspects only to some extent. Here we present a design exploration framework for complete reader/smart card systems using state-of-the-art model-based emulation and estimation techniques. This novel system-based approach is of high importance because of the high availability of battery powered mobile readers (i.e. smart phones) and novel mobile application fields. Contactless power transfer and power consumption analyses of reader and smart cards can be performed for each clock cycle and in real time. Thus, novel system-level power and security optimization techniques can be evaluated considering the reader/smart card system as a whole. We demonstrate the application of our exploration framework by means of a typical Diffie-Hellman key exchange between reader and smart card and highlight power optimization possibilities.
Norbert Druml, Manuel Menghin, Daniel Kroisleitner, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
RSP4
2013 A Defensive Virtual Machine Layer to Counteract Fault Attacks on Java Cards
Michael Lackner, Reinhard Berlach, Wolfgang Raschke, Reinhold Weiss, Christian Steger
WISTP5
2013 Hardware accelerated smart-card software evaluation supported by information leakage and activity sensors
Armin Krieg, Johannes Grinschgl, Christian Steger, Reinhold Weiss, Holger Bock, Andreas Genser, Josef Haid
J. Inf. Secur. Appl.3
2013 Power And Fault Emulation for Software Verification and System Stability Testing in Safety Critical Environments
abstract
In recent years the complexity of digital control systems in safety critical environments increased steadily from simple discrete control units to complex embedded systems. A wide industrial consensus about the necessity of a set of safety definitions lead to the introduction of several functional safety standards like IEC61508. To achieve that novel embedded systems comply with these requirements, thorough testing is needed during early design stages of the integrated device. Currently only fault injection testing using manufactured products and netlists of system-on-chips are used to determine the fault resistance of the embedded system. This late testing could result in expensive redesigns and hide implementation errors because of the black-box approach. This approach is also not practicable if software and hardware providers are separate entities. This paper presents a flexible fault injection and power estimation platform to enable thorough examinations of novel complex system-on-chips for automotive or similar critical environments. The microprocessor evaluation approach is extended with smart bus fault emulation units for common buses like Ethernet. The combined power and fault emulation techniques allow for the instant exploration of eventual power supply peaks and implementation weaknesses.
Armin Krieg, Christopher Preschern, Johannes Grinschgl, Christian Steger, Christian Kreiner, Reinhold Weiss, Holger Bock, Josef Haid
IEEE Trans. Ind. Informatics4
2012 Hardware-Accelerated Workload Characterization for Power Modeling and Fault Injection
abstract
During recent years the increasing introduction of system functionality into integrated devices resulted into several new problems for chip designers. First, high system-on-chip complexity combined with increased clock frequencies leads to power budget and thermal issues. Second, small semiconductor process structures are more sensitive to faults resulting from logic degradation and external radiation sources. Early testing and evaluation of hardware and software implementations have been enabled in the last years using hardware-accelerated emulation techniques. Such implementations rely on functional models of the target system, generated using specialized benchmark suites. These have been designed to accurately resemble typical application scenarios of the target implementation. Unfortunately, power and fault injection emulation accuracy is depending on a good coverage of the system's logic, which is not guaranteed by typical benchmarks. Therefore, this paper proposes an exhaustive hardware accelerated methodology for the evaluation of such applications and generation of accurate emulation models. The behavior of standard benchmarks are investigated using an open available system-on-chip platform based case study.
Armin Krieg, Johannes Grinschgl, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
Asian Test Symposium3
2012 Towards the Hardware Accelerated Defensive Virtual Machine - Type and Bound Protection
Michael Lackner, Reinhard Berlach, Johannes Loinig, Reinhold Weiss, Christian Steger
CARDIS5
2012 Estimation based power and supply voltage management for future RF-powered multi-core smart cards
abstract
RF-powered smart cards are constrained in their operation by their power consumption. Smart card application designers must pay attention to power consumption peaks, high average power consumption and supply voltage drops. If these hazards are not handled properly, the smart card's operational stability is compromised. Here we present a novel multi-core smart card design, which improves the operational stability of nowadays used smart cards. Estimation based techniques are applied to provide cycle accurate power and supply voltage information of the smart card in real time. A supply voltage management unit monitors the provided power and supply voltage information, flattens the smart card's power consumption and prevents supply voltage drops by means of a dynamic voltage and frequency scaling (DVFS) policy. The presented multi-core smart card design is evaluated on a hardware emulation platform to prove its proper functionality. Experimental tests show that harmful power variations can be reduced by up to 75% and predefined supply voltage levels are maintained properly. The presented analysis and management functionalities are integrated at a minimal area overhead of 10.1%.
Norbert Druml, Christian Steger, Reinhold Weiss, Andreas Genser, Josef Haid
DATE2
2012 System side-channel leakage emulation for HW/SW security coverification of MPSoCs
abstract
During recent years a tremendous number of embedded systems has been introduced into every person's house-hold. Such systems cannot only be found inside non-critical applications like entertainment devices but also in safety or security critical implementations like smart-cards. The increasing complexity leads to the introduction of several different co-design techniques to enable the parallel design of the system's hardware and software. Especially concerning security evaluation procedures this may raise a problem of trust between the manufacturer of the hardware and the software if both are different entities. To enable a bridge between these two worlds, simulation and emulation-based approaches have been shown in literature and industry to provide abstracted information about fault-attack effects to the software developer. However, no fast and cost-effective approach is available to provide a metric about how much of a given secret is leaking from the device to its environment. Therefore, this paper proposes such a metric and an emulation-based methodology to enable an early estimation of side-channel leakage to a possible adversary. The effectiveness of our approach is shown using a common available system-on-chip implementation using an open-source standard-cell library for characterization and a FPGA-based emulation platform for demonstration.
Armin Krieg, Johannes Grinschgl, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
DDECS3
2012 Adaptive Field Strength ScalingL: A Power Optimization Technique for Contactless Reader / Smart Card Systems
abstract
Many near field communication (NFC)-based reader / smart card applications are operated at a maximum magnetic field strength to increase the smart card's operational stability. However, a maximum magnetic field strength is worthwhile only in situations of high smart card power requirements (e.g., performing cryptographic operations) or long distance communications. As a result, electrical power is wasted, which limits the run-time of mobile battery-operated reader devices. Here we present an adaptive field strength scaling (AFSS) methodology. The strength of the reader's emitted magnetic field is modified depending on the instantaneous power consumption requirements of the smart card. When the smart card consumes less power, the magnetic field strength is reduced. Whereas when it consumes more power, the magnetic field strength is increased. Thus, the power consumption of the reader / smart card system as a whole is optimized while preserving the smart card's operational stability. In this work, we present the design and implementation of two different AFSS approaches. A reader / smart card hardware emulation platform is used to prove the AFSS technique's feasibility and proper functionality. Experimental tests demonstrate that the energy consumption of the AFSS enhanced reader / smart card system can be reduced by up to 54% compared to current commonly used approaches. Furthermore, we show that the smart card's stability is preserved if the AFSS technique is applied.
Norbert Druml, Manuel Menghin, Christian Steger, Reinhold Weiss, Andreas Genser, Holger Bock, Josef Haid
DSD3
2012 PROCOMON: An Automatically Generated Predictive Control Signal Monitor
abstract
Today security and safety applications are often a large conglomerate of complex different components. Because of a strong trend to high system integration to fulfill financial and production cost constraints, as much of these components as possible are combined to form large-scale system-on-chips. Risks of dependability and security problems caused by device degradation and adversaries lead to a wide range of research concerning fault detection and recovery techniques in recent years. Especially in safety systems the concurrent use of different checking techniques, to protect the integrity of the operation, is preferred. Standard duplication or triplication methods for such critical devices are not completely fulfilling this property and raising a need for new on-line testing and recovery methodologies. Furthermore, the smart-card sector produces a strong need for new checking techniques with a low resource footprint. Therefore, this paper presents a novel automatized hardware generation flow to create a predictive control signal monitor unit in an automatized way. Depending on the instruction loaded by the processor pipeline this unit will predict the signature of following control signal changes. Hence, a new way of fault detection, weak checking, is implemented without introducing any large additional hardware blocks. A case study using an open-source processor is also presented to show the applicability of our approach.
Armin Krieg, Johannes Grinschgl, Norbert Druml, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
DSD4
2012 Characterization and handling of low-cost micro-architectural signatures in MPSoCs
abstract
In recent years the wide spread introduction of small embedded systems into every corner of everyday life lead to the strong need for highly reliable and secure computing machines. These machines now affect the safety of humans as well as the security of personal data and consequently money transactions. To ensure the integrity of these systems' operating state, several fault detection mechanisms have been developed to safely correct or stop unforeseen execution behavior. Because of the rise of battery or even field-supplied systems these mechanisms often heavily decrease available power budgets or lead to significantly increased production costs. Therefore, this paper introduces novel micro-architectural execution signature characterization and handling techniques for system-on-chip designs providing power estimation hardware. Existing power sensor infrastructure is reused to enable efficient system-state monitoring using micro-architectural hashes to cover a wide range of implemented system functionality. Reduced hashing implementations are characterized for their fault detection efficiency. This hardware-based approach provides a completely transparent solution to counteract faults resulting from emerging wearout defects or intentional attacks on the execution integrity.
Armin Krieg, Johannes Grinschgl, Christian Steger, Reinhold Weiss, Andreas Genser, Holger Bock, Josef Haid
ETS3
2012 NIZE - a Near Field Communication interface enabling zero energy standby for everyday electronic devices
abstract
Standby power consumption of electric devices is a growing waste of energy. Between 5% and 14% of the residential electrical power consumption is caused by devices being in standby mode. Depending on the device type, more than 50% of standby power consumption could be saved by applying state-of-the-art power management techniques. By implementing a zero energy standby design and outsourcing power consuming user interfaces, even more electrical power can be saved. Here we present a novel Near Field Communication (NFC) interfacing method for everyday electronic devices. By implementing this interface, the target device can be shut down during idle times. Thus, standby power consumption is eliminated completely. If user interaction is requested, NFC provides the electrical energy to switch on the target device's power supply and to start the device. Furthermore, any control, status, and maintenance information can be transmitted over NFC. By outsourcing high power dissipating and unoptimized user interfaces (touch screens, WiFi, etc.) to the power optimized NFC reader, further energy savings are possible also during running state. This paper demonstrates the implementation and integration of this novel interfacing technique into common consumer electronics. Two implementation approaches are presented. A simple, energy harvesting-based approach illustrates the basic working principle. The second, more sophisticated approach, enables also authentication, encrypted data transfer, user interface outsourcing, configuration and control tasks, etc. A proof of concept is demonstrated by means of an access control terminal.
Norbert Druml, Manuel Menghin, Rejhan Basagic, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
WiMob4
2012 POWER-MODES: POWer-EmulatoR- and MOdel-Based DEpendability and Security Evaluations
abstract
Innovation cycles have been shortening significantly during the last years. This process puts tremendous pressure on designers of embedded systems for security-or reliability-critical applications. Eventual design problems not detected during design time can lead to lost money, confidentiality, or even loss of life in extreme cases. Therefore it is of vital importance to evaluate a new system for its robustness against intentionally and random induced operational faults. Currently this is generally done using extensive simulation runs using gate-level models or direct measurements on the finished silicon product. These approaches either need a significant amount of time and computational power for these simulations or rely on existing product samples. This article presents a novel system evaluation platform using power emulation and fault injection techniques to provide an additional tool for developers of embedded systems in security-and reliability-critical fields. Faults are emulated using state-of-the-art fault injection methods and a flexible pattern representation approach. The resulting effects of these faults on the power consumption profile are estimated using state-of-the-art power emulation hardware. A modular system augmentation approach provides emulation flexibility similar to fault simulation implementations. The platform enables the efficient evaluation of new hardware or software implementations of critical security or reliability solutions at an early development phase.
Armin Krieg, Johannes Grinschgl, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
ACM Trans. Reconfigurable Technol. Syst.3
2011 Modular Fault Injector for Multiple Fault Dependability and Security Evaluations
abstract
The increasing level of integration and decreasing size of circuit elements leads to greater probabilities of operational faults. More sensible electronic devices are also more prone to external influences by energizing radiation. Additionally not only natural causes of faults are a concern of today's chip designers. Especially smart cards are exposed to complex attacks through which an adversary tries to extract knowledge from a secured system by putting it into an undefined state. These problems make it increasingly necessary to test a new design for its fault robustness. Several previous publications propose the usage of single bit injection platforms, but the limited impact of these campaigns might not be the right choice to provide a wide fault attack coverage. This paper first introduces a new in-system fault injection strategy for automatic test pattern injection. Secondly, an approach is presented that provides an abstraction of the internal fault injection structures to a more generic high level view. Through this abstraction it is possible to support the task separation of design and test-engineers and to enable the emulation of physical attacks on circuit level. The controller's generalized interface provides the ability to use the developed controller on different systems using the same bus system. The high level of abstraction is combinable with the advantage of high performance autonomous emulations on high end FPGA-platforms.
Johannes Grinschgl, Armin Krieg, Christian Steger, Reinhold Weiss, Holger Bock, Josef Haid
DSD3
2011 A side channel attack countermeasure using system-on-chip power profile scrambling
abstract
Since the discovery that hardware used for cryptographic applications could leak secret information through its power or radiation profile a wide range of possible attack methods has been published. The rapid evolution of these side-channel attacks made it increasingly important to minimize this possible information leakage. Additionally timing information also derived from this power profile is used to control fault-attack campaigns to drive the system into an unintended state. Therefore a wide range of leakage countermeasures has been developed for dedicated cryptographic hardware. Contrariwise only little work is available concerning power profile scrambling techniques for cryptographic software implementations running on general purpose architectures. Such implementations often include power management hardware to cope with several power budget constraints which could be used to influence the system's power consumption during run-time. This paper proposes a novel side channel attack countermeasure technique using such power management methods in combination with techniques for power profile manipulation. State-of-the-art power estimation hardware using a reduced power model allows for the efficient on-line monitoring and manipulation of the power consumption and radiation profile.
Armin Krieg, Johannes Grinschgl, Christian Steger, Reinhold Weiss, Josef Haid
IOLTS3
2011 Supply voltage emulation platform for DVFS voltage drop compensation explorations
abstract
The supply voltage level has emerged as an important metric alongside power consumption information to investigate system stability and reliability issues. In this paper, we propose a supply voltage emulation platform based on a power emulation approach to derive real-time power and supply voltage information from a system. Moreover, we present a dynamic voltage and frequency scaling (DVFS) based voltage drop compensation scheme to maintain stable system operation. The early design phase applicability of our emulation-based approach enables the investigation of the effectiveness of voltage drop compensation schemes before the final chip is available.
Andreas Genser, Christian Bachmann, Christian Steger, Reinhold Weiss, Josef Haid
ISPASS3
2011 Measuring the state-of-charge - Analysis and impact on wireless sensor networks
abstract
Wireless sensor networks (WSNs) are typically used in application areas without wired infrastructure or mobility. Therefore, each sensor node needs its own energy supply unit. Sustainable WSNs are powered by energy harvesting systems (EHSs). These systems harvest and buffer the energy from the environment into rechargeable batteries or double layer capacitors. Due to the fact that the connectivity of the WSN depends on every single sensor node, it is important to know the state-of-charge (SoC) of the buffer to determine the remaining operating time. Therefore, each node has to measure its SoC, calculate the remaining operating time and populate this information through the network. The measurement is usually done by an integrated analog-to-digital converter (ADC) of the microcontroller. Each ADC has a specified error that has to be taken into account at the calculations of the remaining operating time. This work presents the error analysis of the SoC measurement using different energy storage components.
Leander B. Hörmann, Philipp M. Glatz, Christian Steger, Reinhold Weiss
LCN3
2011 Computer-Aided PHA, FTA and FMEA for Automotive Embedded Systems
Roland Mader, Eric Armengaud, Andrea Leitner, Christian Kreiner, Quentin Bourrouilh, Gerhard Grießnig, Christian Steger, Reinhold Weiss
SAFECOMP7
2011 Designing sustainable Wireless sensor networks with efficient energy harvesting systems
abstract
Wireless sensor networks (WSNs) are resource-constrained devices. Especially energy is scarce. Recent advances with energy harvesting system (EHS) technology now offer new opportunities for long-lived WSNs. Several prototypes of EHS-enhanced WSN platforms have recently been designed in a low-power and power-efficient way. While the field starts to mature there are still a few lessons to be learned for building low-cost and robust systems. Especially, perpetual systems pose new constraints that have not yet been formalized in well-established metrics. Several studies exist, that try to tune systems and algorithms offline for being able to cope with different situations that might occur. The prediction of solar traces is a well-known example for EHS-enhanced WSNs. However, it is a cumbersome task trying to be prepared for all possible extreme conditions especially when prediction is needed. Therefore, we introduce RiverMote which is a low-cost highly efficient design with extended black-out sustainability (BOS) capabilities. We suggest to put special focus on BOS as a mechanism that can even react to hard-to-model events in a general way without the need to rely on error-prone prediction mechanisms. RiverMote is a low-cost WSN platform with integrated EHS. It outperforms state-of-the-art EHS technology efficiency for WSNs and supports BOS of more than three weeks.
Philipp M. Glatz, Leander B. Hörmann, Christian Steger, Reinhold Weiss
WCNC3
2011 Evaluation of component-aware dynamic voltage scaling for mobile devices and wireless sensor networks
abstract
Energy efficiency is very important for mobile devices and wireless sensor networks (WSNs), because the consumable energy is limited. Therefore, the operating time of such devices depends mainly on the capacity of the energy storage component and on the average power consumption of the device. The power consumption depends on the supply voltage and on the activated components of the hardware. This work presents the evaluation of component-aware dynamic voltage scaling (CADVS). This low power technique combines the power-down of unused components and the minimization of the supply voltage. Typically, each component of the hardware (microcontroller, transceiver, sensors) has its own supply voltage range. Therefore, the minimum allowed supply voltage depends on the activated components. However, the activated components and consequently the minimum allowed supply voltage varies over time. CADVS uses voltage converter to adjusts the supply voltage of the hardware to save as much energy as possible. This work presents the evaluation of six different voltage converters. It has been shown that CADVS can be used to save up to 38.7% of the energy compared to a constant voltage supply using the introduced scenario while achieving the same end-user performance.
Leander B. Hörmann, Philipp M. Glatz, Christian Steger, Reinhold Weiss
WOWMOM3
2010 Holistic simulation of FlexRay networks by using run-time model switching
abstract
Automotive network technologies such as FlexRay present a cost-optimized structure in order to tailor the system to the required functionalities and to the environment. The space exploration for optimization of single components (cable, transceiver, communication controller, middleware, application) as well as the integration of these components (e.g. selection of the topology) are complex activities that can be efficiently supported by means of simulation. The main challenge while simulating communication architectures is to efficiently integrate the heterogeneous models in order to obtain accurate results for a relevant operation time of the system. In this work, a run-time model switching method is introduced for the holistic simulation of FlexRay networks. Based on a complete modeling of the main network components, the simulation performance increase is analyzed and the new test and diagnosis possibilities resulting from this holistic approach are discussed.
Michael Karner, Eric Armengaud, Christian Steger, Reinhold Weiss
DATE3
2010 Exploration of the FlexRay signal integrity using a combined prototyping and simulation approach
abstract
Ensuring a correct signal integrity within the entire FlexRay network and for all the possible environmental situations is mandatory for reliable operation of the distributed application. However, this is a goal difficult to reach due to the large number of parameters that influence the signal integrity. The use of simulation is a natural answer to efficiently support space exploration. We discuss in this work how the TEODACS test approach supports the validation process of the simulation models for FlexRay topologies and provides trustfulness for the simulation results even if hardware reference is not available. Further, we introduce a new method for the advanced analysis and evaluation of signal integrity in FlexRay networks.
Martin Krammer, Federico Clazzer, Eric Armengaud, Michael Karner, Christian Steger, Reinhold Weiss
DDECS5
2010 Automated simulation-based verification of power requirements for Systems-on-Chips
abstract
Today power dissipation is the most important constraint for Systems-on-Chips (SoCs). Consequently, it is necessary to consider power in the requirements of mobile, battery-powered devices in which SoCs are often used. These power requirements describe battery lifetime, power constraints and low-power states. Verification ensures that the system fulfills the power requirements. However, verifying all requirements of the complex SoC design needs considerable effort. We introduce a methodology to reduce the verification effort through a high degree of automation. Our novel approach to verify battery lifetime, power constraints and the power aware design comprises three parts. First, a semi-formal use case format unifies specification of power and system requirements. Second, these specifications are used to automatically derive test cases and to generate a verification environment. Third, fast simulation and power estimation are employed to verify battery lifetime, power constraints and the power aware design against the requirements.
Christoph Trummer, Christoph M. Kirchsteiger, Christian Steger, Reinhold Weiss, Markus Pistauer, Damian Dalton
DDECS3
2010 Automated Power Characterization for Run-Time Power Emulation of SoC Designs
abstract
With the advent of increasingly complex systems, the use of traditional power estimation approaches is rendered infeasible due to extensive simulation times. Hardware accelerated power emulation techniques, performing power estimation as a by-product of functional emulation, are a promising solution to this problem. However, only little attention has been awarded so far to the problem of devising a generic methodology capable of automatically enabling the power emulation of a given system-under-test. In this paper, we propose an automated power characterization and modeling methodology for high level power emulation. Our methodology automatically extracts relevant model parameters from training set data and generates an according power model. Furthermore, we investigate the automation of the power model hardware implementation and the automated integration into the overall system's HDL description. For a smart card controller test-system the automatically created power model reduces the average estimation error from 11.78% to 4.71% as compared to a manually optimized one.
Christian Bachmann, Andreas Genser, Christian Steger, Reinhold Weiss, Josef Haid
DSD3
2010 Fast simulation based testing of anti-tearing mechanisms for small embedded systems
abstract
Small embedded systems are often powered by unreliable power supplies like energy harvesting systems or external power supplies. For secure embedded systems a sudden loss of power can violate data integrity. The power has just to drop when data is written to non-volatile memory. In order to guarantee data integrity, a secure embedded system has to provide an anti-tearing mechanism. In this work we summarize a fast simulation based test method for such mechanisms.
Johannes Loinig, Christian Steger, Reinhold Weiss, Ernst Haselsteiner
ETS2
2010 TOSPIE2: tiny operating system plug-in for energy estimation
abstract
TinyOS2 (TOS2) is the state of the art operating system for wireless sensor network (WSN) programming. There are a number of testbeds and simulation tools for checking functional correctness and a few integrated development environments (IDEs) that support graphical user interface (GUI) and power profiling of WSN simulation as well. All these systems and environments are tailored towards design optimization of WSNs subject to functional correctness and energy conservation. Unfortunately, all these approaches lack self-contained support for energy harvesting systems (EHSs) which is the state of the art technique for tackling the energy conservation problem. Here, we present the design and implementation of a self-contained X-in-the-loop approach. TOSPIE2 is an Eclipse plug-in that integrates TOS2 installation and compilation support, power profiles and EHS efficiency in simulation and measurement.
Philipp M. Glatz, Christian Steger, Reinhold Weiss
IPSN2
2010 Power emulation: Methodology and applications for HW/SW power optimization
abstract
Power profiling methods are indispensible in the power-aware design of HW/SW systems. By extending functional emulators with power estimation hardware, high-level power information can be derived during run-time, yielding a considerable speed-up as compared to simulation based approaches. A key enabler for the widespread use of the power emulation methodology is the automation of both power model creation and HDL adaptation. In this paper, we outline our system-level power emulation technique as well as its automatic power modeling and hardware adaptation. Furthermore, applications in the field of HW/SW power management are illustrated.
Josef Haid, Christian Bachmann, Andreas Genser, Christian Steger, Reinhold Weiss
MEMOCODE4
2010 Identification and Verification of Security Relevant Functions in Embedded Systems Based on Source Code Annotations and Assertions
Johannes Loinig, Christian Steger, Reinhold Weiss, Ernst Haselsteiner
WISTP2
2009 Low-Power ASIP Architecture Exploration and Optimization for Reed-Solomon Processing
abstract
The advent of the mobile age has heavily changed the requirements of today's communication devices. Data transmission over interference-prone wireless channels requires additional steps of data processing, such as forward error correction, to ensure reliable communication. In this work we present RS(63,55) Reed-Solomon encoding and decoding algorithms according to the IEEE 802.15.4a standard executed on dedicated application-specific processor architectures. Algorithmic as well as architectural modifications to speed up execution and well-known low-power techniques to reduce the power consumption are discussed. The speed-up for our proposed designs compared to a general purpose baseline architecture is up to two orders of magnitude. Power reduction due to clock-gating and guarded evaluation results in a 40% power drop and the energy consumption is decreased up to 60x.
Andreas Genser, Christian Bachmann, Christian Steger, Jos Hulzink, Mladen Berekovic
ASAP3
2009 A low-power ASIP for IEEE 802.15.4a ultra-wideband impulse radio baseband processing
abstract
The IEEE 802.15.4a amendment has introduced ultra-wideband impulse radio (UWB IR) as a promising physical layer for energy-efficient, low data rate communications. A critical part of the UWB IR receiver design is the low-power implementation of the digital baseband processing required for synchronization and data decoding. In this paper we present the development of an application-specific instruction-set processor (ASIP) that is tailored to the requirements defined by the baseband algorithms. We report a number of optimizations applied to the algorithms as well as to the hardware architecture. This enables performance increases up to a factor of 122x and energy consumption decreases up to 90x as compared to a 16-bit baseline architecture. Furthermore, this ASIP offers greater flexibility due to programmability as compared to an ASIC implementation.
Christian Bachmann, Andreas Genser, Jos Hulzink, Mladen Berekovic, Christian Steger
DATE5
2009 Fault insertion testing of a novel CPLD-based fail-safe system
abstract
According to the standard IEC 61508 fault insertion testing is required for the verification of fail-safe systems. Usually these systems are realized with microcontrollers. Fail-safe systems based on a novel CPLD-based architecture require a different method to perform fault insertion testing than microcontroller-based systems. This paper describes a method to accomplish fault insertion testing of a system based on the novel CPLD-based architecture using the original system hardware. The goal is to verify the realized safety integrity measures of the system by inserting faults and observing the behavior of the system. The described method exploits the fact, that the system contains two channels, where both channels contain a CPLD. During a test one CPLD is configured using a modified programming file. This file is available after the compilation of a VHDL-description, which was modified using saboteurs or mutants. This allows injecting a fault into this CPLD. The other CPLD is configured as fault-free device. The entire system has to detect the injected fault using its safety integrity measures. Consequently it has to enter and/or maintain a safe state.
Gerhard Grießnig, Roland Mader, Christian Steger, Reinhold Weiss
DATE3
2009 Moving Beyond the Component Boundaries for Efficient Test and Diagnosis of Automotive Communication Architectures
abstract
Integration work at system level has been made easier with the introduction of the time-triggered concept and technologies such as FlexRay. Paradoxically, the ongoing integration efforts at component level have led to complex local interactions between the subsystems that are difficult to analyze globally. We present in this work a test environment for automotive networks that goes beyond the component boundaries and enables the concurrent analysis of the entire communication architecture. This supports the investigation of data- and fault propagation within the system as well as the analysis of the interactions between the components. Supported by an industrial use case, we discuss how this environment improves fault detection and diagnosis of the system.
Eric Armengaud, Allan Tengg, Michael Karner, Christian Steger, Reinhold Weiss, Martin Kohl
ETFA4
2009 Optimizing HW/SW Co-simulation based on run-time model switching
Michael Karner, Christian Steger, Reinhold Weiss, Eric Armengaud
FDL2
2008 Verification and analysis of dependable automotive communication systems based on HW/SW co-simulation
abstract
The introduction of FlexRay in the automotive industry as well as the standardization efforts for the hardware and software architecture rise different challenges: How to efficiently integrate the new services in the system, how to validate the communication architecture with respect to the effects influencing the network? The research project TEODACS aims at answering these questions. We present in this document a new validation approach for the communication architecture based on the simulation of the entire FlexRay network within a co-simulation framework. This environment largely reduces the processing resources required for simulation and thus makes the analysis of such complex system possible.
Michael Karner, Christian Steger, Reinhold Weiss, Eric Armengaud, Daniel Watzenig, Gernot Knoll
ETFA2
2007 Automated Software Power Optimization for Smart Card Systems with Focus on Peak Reduction
abstract
The complexity of embedded systems is continuously growing due to the increasing requirements on performance. In portable systems such as smart cards, not only performance is an important attribute, but also the power and energy consumed by a given application. Sources of energy used in smart card systems like batteries and electromagnetic fields are not such ideal elements, as their effectiveness depends heavily on the energy consumed over time. Optimization strategies proposed so far are implemented statically. Often a manual measurement of the current profile followed by manual optimizations is carried out. This procedure is very time consuming. We present a method for reducing automatically the power of an application based on a compiler optimization.
Matthias Grumer, Manuel Wendt, Christian Steger, Reinhold Weiss, Ulrich Neffe, Andreas Mühlberger
AICCSA3
2007 Simulation platform for UHF RFID
abstract
Developing modern integrated and embedded systems require well-designed processes to ensure flexibility and independency. These features are related to exchangeability of hardware targets and to the ability of choosing the target at a very late stage in the implementation process. Especially in the field of ultra high frequency radio frequency identification (UHF RFID) the model-based design approach leads to expected results. Beside a clear design process, which is applied in this work to build the required system architecture, the scope for UHF RFID simulations is defined and an extendable platform based on the MathWorks Matlab Simulinkreg is developed. This simulation platform, based on a multi-processor hardware target, using a Texas Instruments TMS320C6416 digital signal processor is able to run UHF RFID tag simulations of very high complexity. The highest effort is made to ensure flexibility to handle future simulation models on the same hardware target, realized by the continuous design and implementation flow of this platform based on model-based design
Vojtech Derbek, Christian Steger, Reinhold Weiss, Daniel Wischounig, Josef Preishuber-Pflügl, Markus Pistauer
DATE2
2007 Simulation Based Verification of Energy Storage Architectures for Higher Class Tags supported by Energy Harvesting Devices
abstract
Enhanced RFID tag technology especially in the UHF frequency range provides extended functionality like high operating range and sensing and monitoring capabilities. Such functionality requiring extended system structures including data acquisition units, real time clocks and active transmitters causes a high energy consumption of the tag and requires an on board energy store (battery). As a key parameter of the reliability of an RFID system is the lifetime, the energy budget of the higher class tag has to be as balanced as possible. This can be achieved by using energy harvesting devices as additional power supply. The PowerTag1project and thus this paper proposes special energy storage structures interfacing energy harvesting devices and dealing with their special requirements for the use with battery-driven higher class UHF RFID tags. Different implementation variants of such structures are compared by using accurate simulation models of the various parts of the system. The results of the simulations are compared to manufacturer given and guaranteed system performance parameters of a state-of-the-art higher class UHF RFID system.
Alex Janek, Christoph Trummer, Christian Steger, Reinhold Weiss, Josef Preishuber-Pflügl, Markus Pistauer
DSD3
2005 Power consumption profile analysis for security attack simulation in smart cards at high abstraction level
abstract
Smart cards are embedded systems which are used in an increasing number of secure applications. As they store and deal with confidential and secret data many attacks are performed on these cards to reveal this private information. Consequently, the security demands on smart cards are very high. It is mandatory to evaluate the security of the design but this is performed often very late in the design process or when the chip has already been manufactured. This paper presents a hierarchical security attack simulation flow for smart card designs where security attacks can be simulated in the processor specific model at transaction layer 1 in SystemC. Therefore, the power consumption profile is analyzed at this level. Preliminary results show that this analysis at high abstraction level can be used to determine vulnerabilities of the system to security attacks. Moreover, points to insert software countermeasures can easily be identified.
Klaus Rothbart, Ulrich Neffe, Christian Steger, Reinhold Weiss, Edgar Rieger, Andreas Mühlberger
EMSOFT3
2005 Automatic Generation of a Verification Platform
Suad Katjazovic, Christian Steger, Andreas Schuhai, Markus Pistauer
FDL2
2005 Extended abstract: an environment for design verification of smart card systems using attack simulation in SystemC
abstract
In this paper an environment for design verification of smart cards using security attack simulation in SystemC is presented. The method for automatic instrumentation of the SystemC code is described, also depicted is the process by which design robustness against attacks is verified. This process involves the system behavior analysis using an extended control flow graph. The results discuss the system behavior analysis of a Java Card/spl trade/ Virtual Machine.
Klaus Rothbart, Ulrich Neffe, Christian Steger, Reinhold Weiss, Edgar Rieger, Andreas Mühlberger
MEMOCODE3
2004 High Level Fault Injection for Attack Simulation in Smart Cards
abstract
Smart cards are one of the smallest computing platforms in use today. They are used in an increasing number of security applications. To gain sensitive data, a lot of security attacks are performed on smart cards. Therefore it is mandatory to test smart cards for robustness in matters of security. Tests are very time consuming and are performed often very late in the design process. This paper presents a methodology for high-level fault injection for security attack simulation in smart cards. The fault injection technique into SystemC designs is described and the fault injection tool is presented. Moreover, the system behaviour analysis is depicted. Preliminary results show that this methodology can assist in finding system components vulnerable to security attacks.
Klaus Rothbart, Ulrich Neffe, Christian Steger, Reinhold Weiss, Edgar Rieger, Andreas Mühlberger
Asian Test Symposium3
2004 Energy Estimation Based on Hierarchical Bus Models for Power-Aware Smart Cards
abstract
Smart cards are one of the smallest computing platforms in use today. Due to their limited resources applications are often simple and less complex. High performance 32-bit smart cards, which were introduced by several vendors in the last years, allow the implementation of complex applications on smart cards. Additional to the high performance processor cores these smart cards contain coprocessors to reach the performance and power consumption goals. The interface between the processor and the coprocessor influences the performance and power consumption and should be evaluated early in the design process. We propose a hierarchical bus model for system-level smart card design which supports accurate energy dissipation estimation. The bus models have been implemented in systemC 2.0 at transaction level layer one (cycle accurate) and layer two (timing estimation). We evaluate accuracy and simulation performance of the models and show their usage as bus functional models for a smart card application.
Ulrich Neffe, Klaus Rothbart, Christian Steger, Reinhold Weiss, Edgar Rieger, Andreas Mühlberger
DATE3
2004 SystemC Based Design Space Exploration for Power Aware Smart Cards
Ulrich Neffe, Christian Steger, Reinhold Weiss, Andreas Mühlberger, Edgar Rieger, Klaus Rothbart
FDL2
2004 A Generic Simulation Framework for Multiprocessor Architectures
Mario Polaschegg, Christian Steger, Damian Dalton, Abhay Vadher
FDL2
2003 Run-time energy estimation in system-on-a-chip designs
abstract
In this paper, a co-processor for run-time energy estimation in system-on-a-chip designs is proposed. The estimation process is done by using power macro-models, thus making analogue measurement equipment obsolete to the software engineer once the system-on-a-chip (SOC) design is characterized. Compared to sampling-based profiling systems [17], the performance overhead of energy profiling is less, because the energy estimation is done completely parallel to the functional units residing on the SOC. The proposed methodology can be used for run-time power optimization and in-system energy profiling. The co-processor was evaluated on a SOC for MPEG layer III audio decoding and the experimental results show a maximum relative error of <5%.
Josef Haid, Gerald Kaefer, Christian Steger, Reinhold Weiss
ASP-DAC3
2001 A HW/SW Codesign Framework Based on Distributed DSP Virtual Machines
abstract
In recent years the interest on the problem of designing mixed hardware/software systems has increased due to growing system complexities. This paper describes a hardware/software codesign framework for the design of embedded systems based on digital signal processors and FPGAs. Our approach is based on distributed DSP virtual machines for simulation and verification of the application on a Linux cluster and for running the application on different target architectures (DSPs, FPGAs) as well. The DSP virtual machines were designed to make DSP applications portable across different platforms while maintaining optimal code.
Christian Kreiner, Christian Steger, Egon Teiniker, Reinhold Weiss
DSD2
1999 Autonomous Agents for Online Diagnosis of a Safety-critical System based on Probabilistic Causal Reasoning
abstract
The goal of decentralization in failure detection, identification, and recovery of high-assurance systems is to focus diagnosis on safety-critical components. The goal of probabilistic causal reasoning in diagnosis is to improve performance of fault isolation, However, this reasoning method is dependent on prior reliability knowledge. Our approach aims at focusing the overall diagnostic cycle in two independent ways: first, autonomous agents diagnose high-consequence appliances of a modular manufacturing system and second prior reliability data needed is derived from a quality assurance program. Therefore we present a hybrid technique in combining quality assurance data, failure mode and effects analysis and probabilistic causal reasoning. We develop a dynamic Bayesian network which, given evidence from sensor observations, is able to learn and reason over time. We successfully apply autonomous diagnosis agents in concert with reliability assessment to improve online diagnosis of a pneumatic-mechanical device.
Johannes Lauber, Christian Steger, Reinhold Weiss
ISADS2
1991 Design and implementation of a distributed real-time expert-system for fault diagnosis in modular manufacturing systems
Eugen Brenner, J. Grabner, M. Moosburger, G. Otschko, K. Schlögl, P. Seifter, Christian Steger, Reinhold Weiss
Microprocessing and Microprogramming8