EDBT 2026 Demo / reviewers in the wild / expert
John Preuß Mattsson
dblp:293/7246 · also John Preuss Mattsson
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2024
0009-0005-3807-7665ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Single-Trace Fault Injection Attack on Hedged Module Lattice Digital Signature Algorithm (ML-DSA)abstractModule Lattice Digital Signature Algorithm (MLDSA) is a post-quantum digital signature algorithm currently being standardised by the NIST. Devices making use of MLDSA are expected to soon become generally available in various environments. It is thus important to assess the resistance of ML-DSA implementations to physical attacks. This paper presents a fault injection attack on hedged ML-DSA in ARM Cortex-M4. First, voltage glitching is performed to skip computation of a seed during the generation of the signature. We identified settings that allowed us to consistently skip the necessary function without crashing the device. After the fault injection, the secret key vector $s_{1}$ is derived directly from the resulting faulty signature. The attack succeeds in recovering s1from a single trace with a probability of around $53 \%$. We also propose countermeasures against the presented attack. Sönke Jendral, John Preuß Mattsson, Elena Dubrova |
FDTC | 2 |
| 2023 | Hidden Stream Ciphers and TMTO Attacks on TLS 1.3, DTLS 1.3, QUIC, and Signal
John Preuß Mattsson |
CANS | 1 |
| 2021 | Nori: Concealing the Concealed Identifier in 5GabstractIMSI catchers have been a long standing and serious privacy problem in pre-5G mobile networks. To tackle this, 3GPP introduced the Subscription Concealed Identifier (SUCI) and other countermeasures in 5G. In this paper, we analyze the new SUCI mechanism and discover that it provides very poor anonymity when used with the variable length Network Specific Identifiers (NSI), which are part of the 5G standard. When applied to real-world name length data, we see that SUCI only provides 1-anonymity, meaning that individual subscribers can easily be identified and tracked. We strongly recommend 3GPP and GSMA to standardize and recommend the use of a padding mechanism for SUCI before variable length identifiers get more commonly used. We further show that the padding schemes, commonly used for network traffic, are not optimal for padding of identifiers based on real names. We propose a new improved padding scheme that achieves much less message expansion for a given k-anonymity. John Preuß Mattsson, Prajwol Kumar Nakarmi |
ARES | 1 |