EDBT 2026 Demo / reviewers in the wild / expert
Anna Pätschke
dblp:327/9148
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0001-7828-2333ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Zebrafix: Mitigating Memory-Centric Side-Channel Leakage via InterleavingabstractConstant-time code has become the de-facto standard for secure cryptographic implementations. However, some memory-based leakage classes such as ciphertext side-channels and silent stores remain unaddressed. Prior work proposed three different methods for ciphertext side-channel mitigation, for which one, the practicality of interleaving data with counter values, remains to be explored. To close this gap, we define design choices and requirements to leverage interleaving for a generic ciphertext side-channel mitigation. Based on these results, we implement Zebrafix, a compiler-based tool to ensure freshness of memory stores. We evaluate Zebrafix and find that interleaving can perform much better than other ciphertext sidechannel mitigations, at the cost of a high practical complexity. We further observe that ciphertext side-channels and silent stores belong to a broader attack category: memory-centric sidechannels. Under this unified view, we show that interleavingbased ciphertext side-channel mitigations can be used to prevent silent stores as well. Anna Pätschke, Jan Wichelmann, Thomas Eisenbarth 0001 |
RAID | 1 |
| 2024 | Obelix: Mitigating Side-Channels Through Dynamic ObfuscationabstractTrusted execution environments (TEEs) offer hardware-assisted means to protect code and data. However, as shown in numerous results over the years, attackers can use side-channels to leak data access patterns and even single-step the code. While the vendors are slowly introducing hardware-based countermeasures for some attacks, others will stay unaddressed. This makes a software-level countermeasure desirable, but current available solutions only address very specific attack vectors or have a narrow leakage model.In this work, we take a holistic view at the vulnerabilities of TEEs and design a tool named Obelix, which is the first to protect both code and data against a wide range of TEE attacks, from cache attacks over single-stepping to ciphertext side-channels. We analyze the practically achievable precision of state-of-the-art single-stepping tools, and present an algorithm which uses that knowledge to divide a program into uniform code blocks, that are indistinguishable for a strong attacker. By storing these blocks and the program data in oblivious RAM, the attacker cannot follow execution, effectively protecting both secret code and data. We describe how we automate our approach to make it available for developers who are unfamiliar with side-channels. As an obfuscation tool, Obelix comes with a considerable performance overhead, but compensates this with strong security guarantees and easy applicability without requiring any expert knowledge. Jan Wichelmann, Anja Rabich, Anna Pätschke, Thomas Eisenbarth 0001 |
SP | 3 |
| 2023 | MAMBO-V: Dynamic Side-Channel Leakage Analysis on RISC-V
Jan Wichelmann, Christopher Peredy, Florian Sieck, Anna Pätschke, Thomas Eisenbarth 0001 |
DIMVA | 4 |
| 2023 | Cipherfix: Mitigating Ciphertext Side-Channel Attacks in Software
Jan Wichelmann, Anna Pätschke, Luca Wilke, Thomas Eisenbarth 0001 |
USENIX Security Symposium | 2 |
| 2022 | Microwalk-CI: Practical Side-Channel Analysis for JavaScript ApplicationsabstractSecret-dependent timing behavior in cryptographic implementations has resulted in exploitable vulnerabilities, undermining their security. Over the years, numerous tools to automatically detect timing leakage or even to prove their absence have been proposed. However, a recent study at IEEE S&P 2022 showed that, while many developers are aware of one or more analysis tools, they have major difficulties integrating these into their workflow, as existing tools are tedious to use and mapping discovered leakages to their originating code segments requires expert knowledge. In addition, existing tools focus on compiled languages like C, or analyze binaries, while the industry and open-source community moved to interpreted languages, most notably JavaScript. Jan Wichelmann, Florian Sieck, Anna Pätschke, Thomas Eisenbarth 0001 |
CCS | 3 |