Kalle Ngo

dblp:216/2028 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0002-9842-2038ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2023 A Side-Channel Attack on a Hardware Implementation of CRYSTALS-Kyber
abstract
CRYSTALS-Kyber has been recently selected by the NIST as a new public-key encryption and key-establishment algorithm to be standardized. This makes it important to assess how well CRYSTALS-Kyber implementations withstand side-channel attacks. Software implementations of CRYSTALS-Kyber have already been analyzed and the discovered vulnerabilities were patched in the subsequently released versions. In this paper, we present a profiling side-channel attack on a hardware implementation of CRYSTALS-Kyber. Since hardware implementations carry out computations in parallel, they are typically more difficult to break than their software counterparts. We demonstrate a successful message (session key) recovery attack on a Xilinx Artix-7 FPGA implementation of CRYSTALS-Kyber by deep learning-based power analysis. Our results indicate that currently available hardware implementations of CRYSTALS-Kyber need better protection against side-channel attacks.
Yanning Ji, Kalle Ngo, Elena Dubrova, Linus Backlund
ETS3
2022 Side-Channel Analysis of Saber KEM Using Amplitude-Modulated EM Emanations
abstract
In the ongoing last round of NIST's post-quantum cryptography standardization competition, side-channel analysis of finalists is a main focus of attention. While their resistance to timing, power and near field electromagnetic (EM) side-channels has been thoroughly investigated, amplitude-modulated EM emanations has not been considered so far. The attacks based on amplitude-modulated EM emanations are more stealthy because they exploit side-channels intertwined into the signal transmitted by the on-board antenna. Thus, they can be mounted on a distance from the device under attack. In this paper, we present the first results of an amplitude-modulated EM side-channel analysis of one of the NIST PQ finalists, Saber key encapsulation mechanism (KEM), implemented on the nRF52832 (ARM Cortex-M4) system-on-chip supporting Bluetooth 5. By capturing amplitude-modulated EM emanations during decapsulation, we can recover each bit of the session key with 0.91 probability on average.
Kalle Ngo, Elena Dubrova
DSD2
2022 Side-Channel Analysis of the Random Number Generator in STM32 MCUs
abstract
The hardware random number generator (RNG) integrated in STM32 MCUs is intended to ensure that the numbers it generates cannot be guessed with a probability higher than a random guess. The RNG is based on several ring oscillators whose outputs are combined and post-processed to produce a 32-bit random number per round of computation. In this paper, we show that it is possible to train a neural network capable of recovering the Hamming weight of these random numbers from power traces with a higher than 60% probability. This is a 4-fold improvement over the 14% probability of the most likely Hamming weight.
Kalle Ngo, Elena Dubrova
ACM Great Lakes Symposium on VLSI1
2020 Attacking Trivium at the Bitstream Level
abstract
In this paper, we present a bitstream modification attack on the Trivium stream cipher, an international standard under ISO/IEC 29192-3. By changing the content of three LUTs in the bitstream, we reduce the non-linear state updating function of Trivium to a linear one. This makes it possible to recover the key from 288 keystream bits using at most 219.41operations. We also propose a countermeasure against bitstream modification attacks which obfuscates the bitstream using dummy and camouflaged LUTs which look legitimate to the attacker. We present an algorithm for injecting dummy LUTs directly into the bitstream without causing any performance or power penalty.
Kalle Ngo, Elena Dubrova, Michail Moraitis
ICCD1
2020 Breaking ACORN at Bitstream Level
abstract
Assuring the security of the Internet of Things (IoT) is much more challenging than assuring the security of centralized environments, like the cloud. A reason for this is that IoT devices are often deployed in domains that are remotely managed and monitored. Thus, they cannot be protected from physical attacks as reliably as data centers. Up till now, implementations of many established, standardized algorithms including AES and SNOW 3G have been broken by physical attacks. In this paper, we show that even the most recently designed algorithms are also vulnerable. We attack an SRAM-based FPGA implementation of ACORN v3 stream cipher, a finalist of CAESAR cryptographic competition for authenticated encryption. By modifying the content of several look-up tables directly in the bitstream, we inject faults which reduce the nonlinear feedback function of ACORN to a linear one. As a result, it becomes possible to extract the full key from 215.34bits of faulty keystream by an algebraic attack using 235.46operations. Our results, once again confirm the necessity to rethink the way cryptographic algorithms are implemented in FPGAs.
Michail Moraitis, Elena Dubrova, Kalle Ngo
VLSI-SOC3