EDBT 2026 Demo / reviewers in the wild / expert
Patrick Koeberl
dblp:17/9767
· DBLP profile ↗
8ranked-venue papers
3as first author
0since 2021 · last 2020
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 3 first-authorSecurity and privacy · 1Software engineering, systems software and programming languages · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
7 papers |
Hardware security and side channels · 68% Systems and software security · 21% Cyber-physical and IoT security · 12% | |
| Computer architecture, parallel and distributed computing, and storage systems
7 papers |
Reconfigurable computing and FPGAs · 58% Embedded and real-time systems · 26% Cloud and datacenter computing · 8% |
Topics — the 17 heaviest of 19, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels
trusted execution environments |
0.8 | 4 | 2015 | HAFIX: hardware-assisted flow integrity extension · DAC 2015 TyTAN: tiny trust anchor for tiny devices · DAC 2015 TrustLite: a security architecture for tiny embedded devices · EuroSys 2014 |
Reconfigurable computing and FPGAs
FPGA security |
0.4 | 1 | 2020 | Multi-tenant FPGA Security: Challenges and Opportunities · FPGA 2020 |
Reconfigurable computing and FPGAs › FPGA virtualization
multi-tenant FPGA |
0.4 | 1 | 2020 | Multi-tenant FPGA Security: Challenges and Opportunities · FPGA 2020 |
Systems and software security › memory safety
control-flow integrity |
0.4 | 2 | 2015 | HAFIX: hardware-assisted flow integrity extension · DAC 2015 Hardware-Assisted Fine-Grained Control-Flow Integrity: Towards Efficient Protection of Embedded Systems Against Software Exploitation · DAC 2014 |
Embedded and real-time systems
embedded system security |
0.3 | 3 | 2017 | TrustLite: a security architecture for tiny embedded devices · EuroSys 2014 LO-FAT: Low-Overhead Control Flow ATtestation in Hardware · DAC 2017 Hardware-Assisted Fine-Grained Control-Flow Integrity: Towards Efficient Protection of Embedded Systems Against Software Exploitation · DAC 2014 |
Cyber-physical and IoT security › embedded device attestation
control-flow attestation |
0.3 | 1 | 2017 | LO-FAT: Low-Overhead Control Flow ATtestation in Hardware · DAC 2017 |
Hardware security and side channels › hardware security primitives
hardware root of trust |
0.3 | 1 | 2017 | LO-FAT: Low-Overhead Control Flow ATtestation in Hardware · DAC 2017 |
Hardware security and side channels › trusted execution environments
remote attestation |
0.3 | 1 | 2017 | LO-FAT: Low-Overhead Control Flow ATtestation in Hardware · DAC 2017 |
Hardware security and side channels › hardware security primitives
physical unclonable function |
0.2 | 1 | 2016 | Remanence Decay Side-Channel: The PUF Case · IEEE Trans. Inf. Forensics Secur. 2016 |
Hardware security and side channels
side-channel attack |
0.2 | 1 | 2016 | Remanence Decay Side-Channel: The PUF Case · IEEE Trans. Inf. Forensics Secur. 2016 |
Systems and software security › return-oriented programming defense
code reuse attack defense |
0.2 | 1 | 2015 | HAFIX: hardware-assisted flow integrity extension · DAC 2015 |
Reconfigurable computing and FPGAs › cloud FPGA
FPGA-as-a-service |
0.1 | 1 | 2020 | Multi-tenant FPGA Security: Challenges and Opportunities · FPGA 2020 |
Cloud and datacenter computing
resource allocation |
0.1 | 1 | 2020 | Multi-tenant FPGA Security: Challenges and Opportunities · FPGA 2020 |
Memory systems › random-access memory
SRAM |
0.1 | 1 | 2016 | Remanence Decay Side-Channel: The PUF Case · IEEE Trans. Inf. Forensics Secur. 2016 |
Processor architecture and microarchitecture
instruction set architecture |
0.1 | 1 | 2015 | HAFIX: hardware-assisted flow integrity extension · DAC 2015 |
Cyber-physical and IoT security
embedded system security |
0.1 | 1 | 2014 | TrustLite: a security architecture for tiny embedded devices · EuroSys 2014 |
Embedded and real-time systems
cyber-physical system platforms |
0.1 | 1 | 2014 | Hardware-Assisted Fine-Grained Control-Flow Integrity: Towards Efficient Protection of Embedded Systems Against Software Exploitation · DAC 2014 |
Methods — techniques the papers use, named apart from their topics
remanence decay analysis · 0.5cloning attack · 0.5return address protection · 0.4backward-edge CFI · 0.4state model · 0.4per-function CFI label · 0.4hardware protection mechanisms · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | Multi-tenant FPGA Security: Challenges and OpportunitiesabstractAn emerging trend in the data center is the at-scale deployment of Field-Programmable Gate Arrays (FPGAs) which combine multi-gigabit and ultra-low latency workload acceleration with hardware-level reconfigurability. In particular, for applications such as Deep Learning where techniques and algorithms are rapidly changing, the inherent flexibility of FPGAs grants them an edge over hardened data processing units such as ASICs or GPUs. Inevitably, Cloud Service Providers (CSPs) will seek to maximize resource utilization for their FPGA investments as they currently do for general-purpose computing resources. Current FPGA deployments in the data center tend to be single-tenant or support multiple tenants through time multiplexing (temporal multi-tenancy) which can result in resource underutilization. This approach does not scale and presents challenges for elastic workloads whose properties are not fully known ahead of time. Instead, we expect that closing the resource utilization gap will require efficient spatial allocation of FPGA resources across multiple tenants while maintaining security and QoS guarantees. In particular, new usage models such as FPGA-as-a-Service, where resources are exposed directly to the cloud tenant, present unique challenges on the security and QoS side. In this talk we review the threat landscape and trust models associated with FPGA multi-tenancy, highlight future research challenges and examine the unique opportunities that FPGA multi-tenancy enables given adequate guarantees on security and QoS. Patrick Koeberl |
FPGA | 1 |
| 2017 | LO-FAT: Low-Overhead Control Flow ATtestation in HardwareabstractAttacks targeting software on embedded systems are becoming increasingly prevalent. Remote attestation is a mechanism that allows establishing trust in embedded devices. However, existing attestation schemes are either static and cannot detect control-flow attacks, or require instrumentation of software incurring high performance overheads. To overcome these limitations, we present LO-FAT, the first practical hardware-based approach to control-flow attestation. By leveraging existing processor hardware features and commonly-used IP blocks, our approach enables efficient control-flow attestation without requiring software instrumentation. We show that our proof-of-concept implementation based on a RISC-V SoC incurs no processor stalls and requires reasonable area overhead. Ghada Dessouky, Shaza Zeitouni, Thomas Nyman, Andrew Paverd, Lucas Davi, Patrick Koeberl, N. Asokan, Ahmad-Reza Sadeghi |
DAC | 6 |
| 2016 | Remanence Decay Side-Channel: The PUF CaseabstractWe present a side-channel attack based on remanence decay in volatile memory and show how it can be exploited effectively to launch a noninvasive cloning attack against SRAM physically unclonable functions (PUFs) - an important class of PUFs typically proposed as lightweight security primitives, which use existing memory on the underlying device. We validate our approach using SRAM PUFs instantiated on two 65-nm CMOS devices. We discuss countermeasures against our attack and propose the constructive use of remanence decay to improve the cloning resistance of SRAM PUFs. Moreover, as a further contribution of independent interest, we show how to use our evaluation results to significantly improve the performance of the recently proposed TARDIS scheme, which is based on remanence decay in SRAM memory and used as a time-keeping mechanism for low-power clockless devices. Shaza Zeitouni, Yossef Oren, Christian Wachsmann, Patrick Koeberl, Ahmad-Reza Sadeghi |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | TyTAN: tiny trust anchor for tiny devicesabstractEmbedded systems are at the core of many security-sensitive and safety-critical applications, including automotive, industrial control systems, and critical infrastructures. Existing protection mechanisms against (software-based) malware are inflexible, too complex, expensive, or do not meet real-time requirements. Ferdinand Brasser, Brahim El Mahjoub, Ahmad-Reza Sadeghi, Christian Wachsmann, Patrick Koeberl |
DAC | 5 |
| 2015 | HAFIX: hardware-assisted flow integrity extensionabstractCode-reuse attacks like return-oriented programming (ROP) pose a severe threat to modern software on diverse processor architectures. Designing practical and secure defenses against code-reuse attacks is highly challenging and currently subject to intense research. However, no secure and practical system-level solutions exist so far, since a large number of proposed defenses have been successfully bypassed. To tackle this attack, we present HAFIX (Hardware-Assisted Flow Integrity eXtension), a defense against code-reuse attacks exploiting backward edges (returns). HAFIX provides fine-grained and practical protection, and serves as an enabling technology for future control-flow integrity instantiations. This paper presents the implementation and evaluation of HAFIX for the Intel® Siskiyou Peak and SPARC embedded system architectures, and demonstrates its security and efficiency in code-reuse protection while incurring only 2% performance overhead. Lucas Davi, Matthias Hanreich, Debayan Paul, Ahmad-Reza Sadeghi, Patrick Koeberl, Dean Sullivan, Orlando Arias, Yier Jin |
DAC | 5 |
| 2014 | Hardware-Assisted Fine-Grained Control-Flow Integrity: Towards Efficient Protection of Embedded Systems Against Software ExploitationabstractEmbedded systems have become pervasive and are built into a vast number of devices such as sensors, vehicles, mobile and wearable devices. However, due to resource constraints, they fail to provide sufficient security, and are particularly vulnerable to runtime attacks (code injection and ROP). Previous works have proposed the enforcement of control-flow integrity (CFI) as a general defense against runtime attacks. However, existing solutions either suffer from performance overhead or only enforce coarse-grain CFI policies that a sophisticated adversary can undermine. In this paper, we tackle these limitations and present the design of novel security hardware mechanisms to enable fine-grained CFI checks. Our CFI proposal is based on a state model and a per-function CFI label approach. In particular, our CFI policies ensure that function returns can only transfer control to active call sides (i.e., return landing pads of functions currently executing). Further, we restrict indirect calls to target the beginning of a function, and lastly, deploy behavioral heuristics for indirect jumps. Lucas Davi, Patrick Koeberl, Ahmad-Reza Sadeghi |
DAC | 2 |
| 2014 | TrustLite: a security architecture for tiny embedded devicesabstractEmbedded systems are increasingly pervasive, interdependent and in many cases critical to our every day life and safety. Tiny devices that cannot afford sophisticated hardware security mechanisms are embedded in complex control infrastructures, medical support systems and entertainment products [51]. As such devices are increasingly subject to attacks, new hardware protection mechanisms are needed to provide the required resilience and dependency at low cost. Patrick Koeberl, Steffen Schulz 0001, Ahmad-Reza Sadeghi, Vijay Varadharajan |
EuroSys | 1 |
| 2013 | Memristor PUFs: a new generation of memory-based physically unclonable functionsabstractMemristors are emerging as a potential candidate for next-generation memory technologies, promising to deliver non-volatility at performance and density targets which were previously the domain of SRAM and DRAM. Silicon Physically Unclonable Functions (PUFs) have been introduced as a relatively new security primitive which exploit manufacturing variation resulting from the IC fabrication process to uniquely fingerprint a device instance or generate device-specific cryptographic key material. While silicon PUFs have been proposed which build on traditional memory structures, in particular SRAM, in this paper we present a memristor-based PUF which utilizes a weak-write mechanism to obtain cell behaviour which is influenced by process variation and hence usable as a PUF response. Using a model-based approach we evaluate memristor PUFs under random process variations and present results on the performance of this new PUF variant. Patrick Koeberl, Ünal Koçabas, Ahmad-Reza Sadeghi |
DATE | 1 |