Konrad Hohentanner

dblp:313/4316 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0003-2283-6071ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Memory Tagging with Intra-Object Detection: Bridging the Gap in Fine-Grained Memory Safety
abstract
1000
Konrad Hohentanner, Lukas Hertel, Minu Föger, Lukas Auer, Julian Horsch
AsiaCCS1
2026 Multi-Partner Project: Advancing European Semiconductor and Chiplet Innovation Through the Bavarian Chip Design Center
abstract
Europe’s semiconductor industry relies heavily on Asian and US manufacturers. The EU Chips Act seeks to strengthen Europe’s capabilities across the semiconductor value chain. Aligned with this goal, the Bavarian Chip Design Center (BCDC) supports local chip design, manufacturing, and talent development, with a focus on RISC-V computing and heterogeneous integration. Within BCDC, the Technical University of Munich and Fraunhofer are developing a chiplet-based architecture optimized for low-power edge AI. The system integrates two chiplets, combining a security-enhanced RISC-V core and AI accelerators, connected via a chiplet-optimized serial interface that supports encrypted data. The chiplets are mounted on a custom interposer with low-capacitance wires for efficient data transmission. System-and component-level development is currently ongoing, with a tapeout in 22 nm FD-SOI planned for 2027. The overall goal is to deliver a proof of concept for a small-scale energy-efficient chiplet system that demonstrates Bavaria’s and Europe’s capability to drive innovation in novel chip design fields.
Hussam Amrouch, Jehaan Joseph, Michael Schirmer, Johannes Geier, Ulf Schlichtmann, Michael Meidinger, Thomas Wild, Andreas Herkersdorf, Jens Nöpel, Georg Sigl, Carsten Trinitis, Aswathy Nedumpalli Sankaranarayanan, Martin Schulz 0001, Andreas Korb, Konrad Hohentanner
DATE16
2025 Unveiling Privacy Risks in WebGPU through Hardware-based Device Fingerprinting
abstract
Privacy is a fundamental right concerned with the protection and control of personal and sensitive information. A common threat to user privacy is the monitoring and tracking of individuals during web browsing without their consent. A common technique used for this purpose is browser fingerprinting, which exploits characteristics of a user's device to create a unique identifier. Traditionally, software-based fingerprints have been used for this purpose. Recently, hardware-based fingerprinting has gained attention due to its resilience to privacy-enhancing technologies. WebGPU is a modern JavaScript API that enables webpages to efficiently utilize a device's Graphics Processing Unit (GPU) for general-purpose computation. This paper focuses on the impact of WebGPU on hardware-based fingerprinting. We show that by using this web API, the execution behaviour of a device's GPU can be characterized to reidentify the device while evading privacy mechanisms. We introduce AtomicIncrement, a novel fingerprinting approach based on the scheduling behaviour of compute shaders which is usable within WebGPU with both high accuracy and low computational impact. In our evaluation, a classifier can reidentify a device with an accuracy of 70% from a pool of 500 devices using AtomicIncrement fingerprints, highlighting the privacy threat of WebGPU-based fingerprinting for modern web browsing. A robustness analysis with over 2 million fingerprints shows that the accuracy remains stable under various device conditions.
Konrad Hohentanner, Nils Kemmerzell, Steffen Florschütz
WISEC1
2024 DMTI: Accelerating Memory Error Detection in Precompiled C/C++ Binaries with ARM Memory Tagging Extension
abstract
Memory safety bugs in C/C++ persist as significant security issues despite extensive research and attempted mitigations. Current detection frameworks use complex runtime metadata structures which greatly impact the overall performance by increasing execution runtime and memory consumption. This work introduces Dynamic Memory Tagging Instrumentation (DMTI), utilizing the ARM Memory Tagging Extension (MTE) to efficiently detect memory errors in precompiled binaries with no check instrumentation during runtime. Our method, implemented through the Ghidra and DynamoRIO frameworks uses a two-step approach to improve both effectiveness and efficiency. In an analysis step, an object layout for each function inside a binary is generated. Then, during runtime, dynamic instrumentation is used to enable MTE and insert instructions to manage the necessary object metadata, which allows automatic detection of memory violations. Compared to previous approaches, the removal of the check logic leads to substantial performance gains, which we demonstrate in our prototype evaluation. DMTI exhibits superior efficiency with an average runtime overhead of only 2× compared to 10× for state-of-the-art memory checking frameworks.
Andreas Hager-Clukas, Konrad Hohentanner
AsiaCCS2
2022 Enhancing the Security of FPGA-SoCs via the Usage of ARM TrustZone and a Hybrid-TPM
abstract
Isolated execution is a concept commonly used for increasing the security of a computer system. In the embedded world, ARM TrustZone technology enables this goal and is currently used on mobile devices for applications such as secure payment or biometric authentication. In this work, we investigate the security benefits achievable through the usage of ARM TrustZone on FPGA-SoCs. We first adapt Microsoft’s implementation of a firmware Trusted Platform Module (fTPM) running inside ARM TrustZone for the Zynq UltraScale+ platform. This adaptation consists in integrating hardware accelerators available on the device to fTPM’s implementation and to enhance fTPM with an entropy source derived from on-chip SRAM start-up patterns. With our approach, we transform a software implementation of a TPM into a hybrid hardware/software design that could address some of the security drawbacks of the original implementation while keeping its flexibility. To demonstrate the security gains obtained via the usage of ARM TrustZone and our hybrid-TPM on FPGA-SoCs, we propose a framework that combines them for enabling a secure remote bitstream loading. The approach consists in preventing the insecure usages of a bitstream reconfiguration interface that are made possible by the manufacturer and to integrate the interface inside a Trusted Execution Environment.
Mathieu Gross, Konrad Hohentanner, Stefan Wiehler, Georg Sigl
ACM Trans. Reconfigurable Technol. Syst.2