Thilo Krachenfels

dblp:170/0453 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2022
0000-0002-8569-2020ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021
YearPublicationVenuePosition
2022 Toward Optical Probing Resistant Circuits: A Comparison of Logic Styles and Circuit Design Techniques
abstract
Laser-assisted side-channel analysis techniques, such as optical probing (OP), have been shown to pose a severe threat to secure hardware. While several countermeasures have been proposed in the literature, they can either be bypassed by an attacker or require a modification in the transistor's fabrication process, which is costly and complex. In this work, firstly, we propose a formulation for the caliber of reflected light from OP. Secondly, we propose circuit design techniques and logic styles to alleviate OP attacks based on our formulation. Finally, we compare several logic families and circuit design techniques in terms of performance and OP security merits. In this regard, we perform simulations to compare the optical beam interaction between the different logic gates. By utilizing our proposed circuit design techniques and dual-rail logic (DRL), the signal-to-noise ratio (SNR) of the reflected light from OP is reduced significantly.
Sajjad Parvin, Thilo Krachenfels, Shahin Tajik, Jean-Pierre Seifert, Frank Sill, Rolf Drechsler
ASP-DAC2
2021 One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted Virtualization
abstract
AMD Secure Encrypted Virtualization (SEV) offers protection mechanisms for virtual machines in untrusted environments through memory and register encryption. To separate security-sensitive operations from software executing on the main x86 cores, SEV leverages the AMD Secure Processor (AMD-SP). This paper introduces a new approach to attack SEV-protected virtual machines (VMs) by targeting the AMD-SP. We present a voltage glitching attack that allows an attacker to execute custom payloads on the AMD-SPs of all microarchitectures that support SEV currently on the market (Zen 1, Zen 2, and Zen 3). The presented methods allow us to deploy a custom SEV firmware on the AMD-SP, which enables an adversary to decrypt a VM's memory. Furthermore, using our approach, we can extract endorsement keys of SEV-enabled CPUs, which allows us to fake attestation reports or to pose as a valid target for VM migration without requiring physical access to the target host. Moreover, we reverse-engineered the Versioned Chip Endorsement Key (VCEK) mechanism introduced with SEV Secure Nested Paging (SEV-SNP). The VCEK binds the endorsement keys to the firmware version of TCB components relevant for SEV. Building on the ability to extract the endorsement keys, we show how to derive valid VCEKs for arbitrary firmware versions. With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rogue administrators, on currently available CPUs.
Robert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre Seifert
CCS3
2021 The Forgotten Threat of Voltage Glitching: A Case Study on Nvidia Tegra X2 SoCs
abstract
Voltage fault injection (FI) is a well-known attack technique that can be used to force faulty behavior in processors during their operation. Glitching the supply voltage can cause data value corruption, skip security checks, or enable protected code paths. At the same time, modern systems on a chip (SoCs) are used in security-critical applications, such as self-driving cars and autonomous machines. Since these embedded devices are often physically accessible by attackers, vendors must consider device tampering in their threat models. However, while the threat of voltage FI is known since the early 2000s, it seems as if vendors still forget to integrate countermeasures. This work shows how the entire boot security of an Nvidia SoC, used in Tesla’s autopilot and Mercedes-Benz’s infotainment system, can be circumvented using voltage FI. We uncover a hidden bootloader that is only available to the manufacturer for testing purposes and disabled by fuses in shipped products. We demonstrate how to re-enable this bootloader using FI to gain code execution with the highest privileges, enabling us to extract the bootloader’s firmware and decryption keys used in later boot stages. Using a hardware implant, an adversary might misuse the hidden bootloader to bypass trusted code execution even during the system’s regular operation.
Otto Bittner, Thilo Krachenfels, Andreas Galauner, Jean-Pierre Seifert
FDTC2
2021 Real-World Snapshots vs. Theory: Questioning the t-Probing Security Model
abstract
Due to its sound theoretical basis and practical efficiency, masking has become the most prominent countermeasure to protect cryptographic implementations against physical side-channel attacks (SCAs). The core idea of masking is to randomly split every sensitive intermediate variable during computation into at least t+1 shares, where t denotes the maximum number of shares that are allowed to be observed by an adversary without learning any sensitive information. In other words, it is assumed that the adversary is bounded either by the possessed number of probes (e.g., microprobe needles) or by the order of statistical analyses while conducting higher-order SCA attacks (e.g., differential power analysis). Such bounded models are employed to prove the SCA security of the corresponding implementations. Consequently, it is believed that given a sufficiently large number of shares, the vast majority of known SCA attacks are mitigated.In this work, we present a novel laser-assisted SCA technique, called Laser Logic State Imaging (LLSI), which offers an unlimited number of contactless probes, and therefore, violates the probing security model assumption. This technique enables us to take snapshots of hardware implementations, i.e., extract the logical state of all registers at any arbitrary clock cycle with a single measurement. To validate this, we mount our attack on masked AES hardware implementations and practically demonstrate the extraction of the full-length key in two different scenarios. First, we assume that the location of the registers (key and/or state) is known, and hence, their content can be directly read by a single snapshot. Second, we consider an implementation with unknown register locations, where we make use of multiple snapshots and a SAT solver to reveal the secrets.
Thilo Krachenfels, Fatemeh Ganji, Amir Moradi 0001, Shahin Tajik, Jean-Pierre Seifert
SP1
2021 Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel Attacks
Thilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre Seifert
USENIX Security Symposium1
2021 Special Session: Physical Attacks through the Chip Backside: Threats, Challenges, and Opportunities
abstract
This paper reviews the evolution of a powerful class of physical attacks against integrated circuits (ICs), developed initially for performing failure analysis (FA) from the IC backside. Over the last two decades, several publications have demonstrated the effectiveness of these techniques in bypassing the IC protection schemes and extracting the stored assets inside secure ICs. In this work, we take a fresh look at such hardware attacks from three different perspectives. First, we will discuss the potential threat of the attacks against modern technologies and demystify a set of wrong beliefs about the attacks' complexity. Second, we review some technical challenges of such attacks from a law enforcement agency's perspective for unraveling crimes and preventing further crimes by criminals involved. Finally, we give an insight into the future development of FA tools and the opportunities for designing effective countermeasures against attacks through the chip backside.
Elham Amini, Kai Bartels, Christian Boit, Marius Eggert, Norbert Herfurth, Tuba Kiyan, Thilo Krachenfels, Jean-Pierre Seifert, Shahin Tajik
VTS7
2015 Near field communication interface for a packet-based serial data transmission using a dual interface EEPROM
abstract
A new application for a wireless packet-based serial data transmission using an EEPROM with an I2C and a NFC interface will be presented in this paper. Our system allows the secure exchange of a large amount of data compared to classical NFC appliances. A protocol handles the fragmentation, encryption, error handling, session handling and authentication. A brief description of the used ST M24SR64-Y EEPROM including the memory layout and the used special hardware features will be discussed. In addition, a new kind of antenna for such an application with respect to a reduced footprint is presented. Our target is an implementation for industrial or medical applications to write a configuration or firmware or to read parameters from the device with no direct electro-mechanical connection.
Jacob Maxa, Thilo Krachenfels, Helmut Beikirch
ETFA2