Zoya Dyka

dblp:14/4673 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0002-6819-0467ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 11 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorSecurity and privacy · 1
YearPublicationVenuePosition
2023 Non-Profiled Semi-Supervised Horizontal Attack Against Elliptic Curve Scalar Multiplication Using Support Vector Machines
abstract
There are different ways to leverage Side Channel information into a successful attack against cryptographic hardware. The most constraint attack scenario assumes no knowledge about the internal states of the hardware during secret key processing and therefore provides no labels for power hungry deep learning algorithms, which are the state of the art in profiling attacks. In our non-profiled single-trace attack we used a statistical method the comparison to the mean to retrieve the initial key candidates and trained a highly regularized Support Vector Machine (SVM) using those candidates. We achieved an improvement in attack correctness of about 10%between the initial and final key candidates. We attacked two implementations of Elliptic Curve Scalar Multiplication. One is an ASIC produced in the IHP 250nm technology, where the hardware description was compiled using the compile_ultra option, which has been proven to increase the resistance against SCA attacks. Another one is an FPGA implementation, using the sequential addressing countermeasure, which minimizes the number of clock cycles with bus addressing leakage.
Marcin Aftowicz, Ievgen Kabin, Zoya Dyka, Peter Langendörfer
DSD3
2021 Optical Fault Injection Attacks against Radiation-Hard Shift Registers
abstract
If devices are physically accessible optical fault injection attacks pose a great threat since the data processed as well as the operation flow can be manipulated. Successful physical attacks may lead not only to leakage of secret information such as cryptographic private keys, but can also cause economic damage especially if as a result of such a manipulation a critical infrastructure is successfully attacked. It can be expected that radiation-hard designs, specially crafted for space applications, are more robust not only against high-energy particles and short electromagnetic waves but also against optical fault injection attacks. In this work we investigated the sensitivity of radiation-hard JICG shift registers to optical fault injection attacks. In our experiments, we were able to trigger bit-set and bit-reset repeatedly changing the data stored in single JICG flip-flops despite their high-radiation fault tolerance.
Dmytro Petryk, Zoya Dyka, Roland Sorge, Jan Schäffner, Peter Langendörfer
DSD2
2021 Resistance of the Montgomery Ladder Against Simple SCA: Theory and Practice
abstract
Abstract The Montgomery kP algorithm i.e. the Montgomery ladder is reported in literature as resistant against simple SCA due to the fact that the processing of each key bit value of the scalar k is done using the same sequence of operations. We implemented the Montgomery kP algorithm using Lopez-Dahab projective coordinates for the NIST elliptic curve B-233. We instantiated the same VHDL code for a wide range of clock frequencies for the same target FPGA and using the same compiler options. We measured electromagnetic traces of the kP executions using the same input data, i.e. scalar k and elliptic curve point P, and measurement setup. Additionally, we synthesized the same VHDL code for two IHP CMOS technologies, for a broad spectrum of frequencies. We simulated the power consumption of each synthesized design during an execution of the kP operation, always using the same scalar k and elliptic curve point P as inputs. Our experiments clearly show that the success of simple electromagnetic analysis attacks against FPGA implementations as well as the one of simple power analysis attacks against synthesized ASIC designs depends on the target frequency for which the design was implemented and at which it is executed significantly. In our experiments the scalar k was successfully revealed via simple visual inspection of the electromagnetic traces of the FPGA for frequencies from 40 to 100 MHz when standard compile options were used as well as from 50 MHz up to 240 MHz when performance optimizing compile options were used. We obtained similar results attacking the power traces simulated for the ASIC. Despite the significant differences of the here investigated technologies the designs’ resistance against the attacks performed is similar: only a few points in the traces represent strong leakage sources allowing to reveal the key at very low and very high frequencies. For the “middle” frequencies the number of points which allow to successfully reveal the key increases when increasing the frequency.
Ievgen Kabin, Zoya Dyka, Dan Klann, Marcin Aftowicz, Peter Langendörfer
J. Electron. Test.2
2020 RESCUE: Interdependent Challenges of Reliability, Security and Quality in Nanoelectronic Systems
abstract
The recent trends for nanoelectronic computing systems include machine-to-machine communication in the era of Internet-of-Things (IoT) and autonomous systems, complex safety-critical applications, extreme miniaturization of implementation technologies and intensive interaction with the physical world. These set tough requirements on mutually dependent extra-functional design aspects. The H2020 MSCAITN project RESCUE is focused on key challenges for reliability, security and quality, as well as related electronic design automation tools and methodologies. The objectives include both research advancements and cross-sectoral training of a new generation of interdisciplinary researchers. Notable interdisciplinary collaborative research results for the first halfperiod include novel approaches for test generation, soft-error and transient faults vulnerability analysis, cross-layer fault-tolerance and error-resilience, functional safety validation, reliability assessment and run-time management, HW security enhancement and initial implementation of these into holistic EDA tools.
Maksim Jenihhin, Said Hamdioui, Matteo Sonza Reorda, Milos Krstic, Peter Langendörfer, Christian Sauer 0001, Anton Klotz, Michael Hübner 0001, Jörg Nolte, Heinrich Theodor Vierhaus, Georgios N. Selimis, Dan Alexandrescu, Mottaqiallah Taouil, Geert Jan Schrijen, Jaan Raik, Luca Sterpone, Giovanni Squillero, Zoya Dyka
DATE18
2020 Breaking a fully Balanced ASIC Coprocessor Implementing Complete Addition Formulas on Weierstrass Elliptic Curves
abstract
In this paper we report on the results of selected horizontal SCA attacks against two open-source designs that implement hardware accelerators for elliptic curve cryptography. Both designs use the complete addition formula to make the point addition and point doubling operations indistinguishable. One of the designs uses in addition means to randomize the operation sequence as a countermeasure. We used the comparison to the mean and an automated SPA to attack both designs. Despite all these countermeasures, we were able to extract the keys processed with a correctness of 100%.
Ievgen Kabin, Zoya Dyka, Dan Klann, Nele Mentens, Lejla Batina, Peter Langendörfer
DSD2
2020 Challenges of Return-Oriented-Programming on the Xtensa Hardware Architecture
abstract
This paper shows how the Xtensa architecture can be attacked with Return-Oriented-Programming (ROP). The presented techniques include possibilities for both supported Application Binary Interfaces (ABIs). Especially for the windowed ABI a powerful mechanism is presented that not only allows to jump to gadgets but also to manipulate registers without relying on specific gadgets. This paper purely focuses on how the properties of the architecture itself can be exploited to chain gadgets and not on specific attacks or a gadget catalog.
Kai Lehniger, Marcin Aftowicz, Peter Langendörfer, Zoya Dyka
DSD4
2020 Evaluation of the Sensitivity of RRAM Cells to Optical Fault Injection Attacks
abstract
Resistive Random Access Memory (RRAM) is a type of Non-Volatile Memory (NVM). In this paper we investigate the sensitivity of the TiN/Ti/Al:HfO2/TiN-based 1T-1R RRAM cells implemented in a 250 nm CMOS IHP technology to the laser irradiation in detail. Experimental results show the feasibility to influence the state of the cells under laser irradiation, i.e. successful optical Fault Injection. We focus on the selection of the parameters of the laser station and their influence on the success of optical Fault Injections.
Dmytro Petryk, Zoya Dyka, Mamathamba Kalishettyhalli Mahadevaiaha, Ievgen Kabin, Christian Wenger, Peter Langendörfer
DSD2
2020 Methods increasing inherent resistance of ECC designs against horizontal attacks
abstract
Due to the nature of applications such as critical infrastructure and the Internet of Things etc. side channel analysis attacks are becoming a serious threat. Side channel analysis attacks take advantage from the fact that the behaviour of crypto implementations can be observed and provides hints that simplify revealing keys. A new type of SCA is the so called horizontal differential SCA. In this paper we investigate two different approaches to increase the inherent resistance of our hardware accelerator for the kP operation. The first approach aims at reducing the impact of the addressing in our design by realizing a regular schedule of the addressing. In the second approach, we investigated how the formula used to implement the multiplication of GF(2n)-elements influences the results of horizontal DPA attacks against a Montgomery kP-implementation. We implemented 5 designs with different partial multipliers, i.e. based on different multiplication formulae. We used two different technologies, i.e. a 130 and a 250 nm technology, to simulate power traces for our analysis. We show that the implemented multiplication formula influences the success of horizontal attacks significantly. The combination of these two approaches leads to the most resistant design. For the 250 nm technology only 2 key candidates could be revealed with a correctness of about 70% which is a huge improvement given the fact that for the original design 7 key candidates achieved a correctness of more than 90%. For our 130 nm technology no key candidate was revealed with a correctness of more than 60%.
Ievgen Kabin, Zoya Dyka, Dan Klann, Peter Langendörfer
Integr.2
2017 Methods for Increasing the Resistance of Cryptographic Designs Against Horizontal DPA Attacks
Ievgen Kabin, Zoya Dyka, Dan Kreiser, Peter Langendörfer
ICICS2
2015 Clockwise Randomization of the Observable Behaviour of Crypto ASICs to Counter Side Channel Attacks
abstract
Side channel attacks take advantage from the fact that the behavior of crypto implementations can be observed and provides hints that allow revealing keys. In this paper we present a novel approach to prevent SCA or at least to increase the effort to reveal keys significantly. Our approach is based on the fact that there are some functions used in cryptographic operations that can be implemented using different formulae or algorithms. These algorithms come with their individual complexity that results in individual circuits with individual power consumption. So, if the crypto implementation uses these different algorithms whenever it is executed or if the sequence in which the different algorithms are used is randomized, extracting the key gets extremely challenging if not impossible. Applying our idea is extremely challenging when it comes to ASIC implementations. The point here is that the functionality is fixed and cannot be altered after production. But we discuss that a runtime permutation of the relation between operands and algorithms used for their processing that alters the observable behavior in the same way as executing different algorithms.
Zoya Dyka, Christian Wittke, Peter Langendörfer
DSD1
2012 Side channel attacks and the non volatile memory of the future
abstract
In this paper, we describe a new non-volatile memory, based on metal-insulator-metal that provides performance benefits compared to standard Flash memory. In addition and more importantly, it comes with some advantages with respect to side channel attacks, i.e., its structure prevents by default optical analysis.
Zoya Dyka, Christian Walczyk, Damian Walczyk, Christian Wenger, Peter Langendörfer
CASES1
2005 Area Efficient Hardware Implementation of Elliptic Curve Cryptography by Iteratively Applying Karatsuba's Method
abstract
Securing communication channels is especially needed in wireless environments, but applying cipher mechanisms in software is limited by the calculation and energy resources of mobile devices. If hardware is applied to realize cryptographic operations, cost becomes an issue. We describe an approach which tackles all three of these points. We implemented a hardware accelerator for polynomial multiplication in extended Galois fields (GF) applying Karatsuba's method iteratively. With this approach, the area required is reduced to 2.1 mm/sup 2/ in comparison to 6.2 mm/sup 2/ for the standard application of Karatsuba's method, i.e., for its recursive application. Our approach also reduces the energy consumption to 60 per cent of the original approach. The price we have to pay for this achievement is an increased execution time. In our implementation, a polynomial multiplication takes 3 clock cycles, whereas the recursive Karatsuba approach needs only one clock cycle. However, considering area, energy and calculation speed, we are convinced that the benefits of our approach outweigh its drawback.
Zoya Dyka, Peter Langendörfer
DATE1