Alejandro Cabrera Aldaya

dblp:180/3056 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0002-1544-6772ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2025 External Entropy Supply for IoT Devices Employing a RISC-V Trusted Execution Environment
Arttu Paju, Juha Nurmi, Alejandro Cabrera Aldaya, Nicola Tuveri, Juha Savimäki, Marko Kivikangas, Brian McGillion
CRiSIS3
2025 The Sound of Reduction: Minimal Inputs, Maximal Coverage
abstract
Guaranteeing the security of cryptographic constructions requires not only theoretically sound designs but also correct and robust implementations. Among the various software testing techniques, fuzz testing is a technique commonly used to automatically verify computer programs that accept user input, by observing its behavior upon receiving diverse inputs. While fuzz testing has proven effective in identifying implementation issues, the structural complexity and input constraints of cryptographic software is one of the big hurdles that existing fuzzers are wrestling with. In this work, we introduce The Sound of Reduction (SoR), a novel fuzzing framework that combines complexity reduction with coverage guidance to improve the effectiveness of fuzzers when applied in cryptographic software. At the core of SoR is an enhanced version of Proptest testing library, that can perform efficient input minimization while leveraging runtime coverage feedback to explore deeper execution paths. We evaluate our approach across a broad range of Post-Quantum Cryptography implementations, including lattice, code, and multivariate-based schemes. Our results demonstrate significant improvements in code coverage and input corpus quality compared to state-of-the-art coverage-guided fuzzers.
Iaroslav Gridin, Antonis Michalas, Alejandro Cabrera Aldaya
TrustCom3
2022 HyperDegrade: From GHz to MHz Effective CPU Frequencies
Alejandro Cabrera Aldaya, Billy Bob Brumley
USENIX Security Symposium1
2020 Déjà Vu: Side-Channel Analysis of Mozilla's NSS
abstract
Recent work on Side Channel Analysis (SCA) targets old, well-known vulnerabilities, even previously exploited, reported, and patched in high-profile cryptography libraries. Nevertheless, researchers continue to find and exploit the same vulnerabilities in old and new products, highlighting a big issue among vendors: effectively tracking and fixing security vulnerabilities when disclosure is not done directly to them. In this work, we present another instance of this issue by performing the first library-wide SCA security evaluation of Mozilla's NSS security library. We use a combination of two independently-developed SCA security frameworks to identify and test security vulnerabilities. Our evaluation uncovers several new vulnerabilities in NSS affecting DSA, ECDSA, and RSA cryptosystems. We exploit said vulnerabilities and implement key recovery attacks using signals---extracted through different techniques such as timing, microarchitecture, and EM---and improved lattice methods.
Sohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García, Jesús-Javier Chi-Domínguez, Alejandro Cabrera Aldaya, Billy Bob Brumley
CCS6
2020 Certified Side Channels
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, Billy Bob Brumley
USENIX Security Symposium5
2019 Port Contention for Fun and Profit
abstract
Simultaneous Multithreading (SMT) architectures are attractive targets for side-channel enabled attackers, with their inherently broader attack surface that exposes more per physical core microarchitecture components than cross-core attacks. In this work, we explore SMT execution engine sharing as a side-channel leakage source. We target ports to stacks of execution units to create a high-resolution timing side-channel due to port contention, inherently stealthy since it does not depend on the memory subsystem like other cache or TLB based attacks. Implementing our channel on Intel Skylake and Kaby Lake architectures featuring Hyper-Threading, we mount an end-to-end attack that recovers a P-384 private key from an OpenSSL-powered TLS server using a small number of repeated TLS handshake attempts. Furthermore, we show that traces targeting shared libraries, static builds, and SGX enclaves are essentially identical, hence our channel has wide target application.
Alejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García, Nicola Tuveri
IEEE Symposium on Security and Privacy1