EDBT 2026 Demo / reviewers in the wild / expert
Jan Pelzl
dblp:34/1982
· DBLP profile ↗
12ranked-venue papers
1as first author
1since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8Security and privacy · 4 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Cryptographic primitives and cryptanalysis · 95% Hardware security and side channels · 5% | |
| Computer architecture, parallel and distributed computing, and storage systems
4 papers |
Reconfigurable computing and FPGAs · 50% Integrated circuit design · 30% Parallel and multicore computing · 10% |
Topics — the 8 heaviest of 12, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic primitives and cryptanalysis › public-key cryptography › elliptic curve cryptography
hyperelliptic curve cryptography |
0.1 | 2 | 2005 | Cantor versus Harley: Optimization and Analysis of Explicit Formulae for Hyperelliptic Curve Cryptosystems · IEEE Trans. Computers 2005 Hyperelliptic Curve Cryptosystems: Closing the Performance Gap to Elliptic Curves · CHES 2003 |
Cryptographic primitives and cryptanalysis
public-key cryptography |
0.1 | 2 | 2005 | Cantor versus Harley: Optimization and Analysis of Explicit Formulae for Hyperelliptic Curve Cryptosystems · IEEE Trans. Computers 2005 Hyperelliptic Curve Cryptosystems: Closing the Performance Gap to Elliptic Curves · CHES 2003 |
Cryptographic primitives and cryptanalysis › public-key cryptography › public-key cryptanalysis
elliptic curve cryptanalysis |
0.1 | 1 | 2007 | Attacking elliptic curve cryptosystems with special-purpose hardware · FPGA 2007 |
Cryptographic primitives and cryptanalysis › generic attacks
exhaustive key search |
0.1 | 1 | 2006 | Breaking Ciphers with COPACOBANA - A Cost-Optimized Parallel Code Breaker · CHES 2006 |
Cryptographic primitives and cryptanalysis
integer factorization |
0.1 | 1 | 2005 | SHARK: A Realizable Special Hardware Sieving Device for Factoring 1024-Bit Integers · CHES 2005 |
Integrated circuit design › digital circuit design
cryptographic hardware |
0.1 | 1 | 2005 | SHARK: A Realizable Special Hardware Sieving Device for Factoring 1024-Bit Integers · CHES 2005 |
Hardware security and side channels
hardware attacks |
0.0 | 1 | 2007 | Attacking elliptic curve cryptosystems with special-purpose hardware · FPGA 2007 |
Processor architecture and microarchitecture › microprocessor design
microprocessor implementation |
0.0 | 1 | 2005 | Cantor versus Harley: Optimization and Analysis of Explicit Formulae for Hyperelliptic Curve Cryptosystems · IEEE Trans. Computers 2005 |
Methods — techniques the papers use, named apart from their topics
pollard-rho method · 0.1multi-processing hardware architecture · 0.1special number field sieve · 0.1karatsuba reduction · 0.1harley's algorithm · 0.1cantor's algorithm · 0.1hyperelliptic curve cryptosystems · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Enhancing Long-Term Storage Security in Critical Infrastructures Under NIS2 Directive: Addressing Post-quantum Cryptography Challenges
Nino Ricchizzi, Andrea Langner, Jan Pelzl |
CRITIS | 3 |
| 2008 | Special-Purpose Hardware for Solving the Elliptic Curve Discrete Logarithm ProblemabstractThe resistance against powerful index-calculus attacks makes Elliptic Curve Cryptosystems (ECC) an interesting alternative to conventional asymmetric cryptosystems, like RSA. Operands in ECC require significantly less bits at the same level of security, resulting in a higher computational efficiency compared to RSA. With growing computational capabilities and continuous technological improvements over the years, however, the question of the security of ECC against attacks based on special-purpose hardware arises. In this context, recently emerged low-cost FPGAs demand for attention in the domain of hardware-based cryptanalysis: the extraordinary efficiency of modern programmable hardware devices allow for a low-budget implementation of hardware-based ECC attacks---without the requirement of the expensive development of ASICs. With focus on the aspect of cost-efficiency, this contribution presents and analyzes an FPGA-based architecture of an attack against ECC over prime fields. A multi-processing hardware architecture for Pollard's Rho method is described. We provide results on actually used key lengths of ECC (128 bits and above) and estimate the expected runtime for a successful attack. As a first result, currently used elliptic curve cryptosystems with a security of 160 bit and above turn out to be infeasible to break with available computational and financial resources. However, some of the security standards proposed by the Standards for Efficient Cryptography Group (SECG) become subject to attacks based on low-cost FPGAs. Tim Güneysu, Christof Paar, Jan Pelzl |
ACM Trans. Reconfigurable Technol. Syst. | 3 |
| 2007 | Attacking elliptic curve cryptosystems with special-purpose hardwareabstractSince their invention in the mid 1980s, Elliptic Curve Cryptosystems (ECC) have become an alternative to common Public-Key (PK) cryptosystems such as, e.g., RSA. The utilization of Elliptic Curves (EC) in cryptography is very promising because of their resistance against powerful index-calculus attacks. Providing a similar level of security as RSA, ECC allows for efficient implementation due to a significantly smaller bit size of the operands. It is widely accepted that the only feasible way to attack actual cryptosystems, if at all, is the application of dedicated hardware. In times of continuous technological improvements and increasing computing power, the question of the security of ECC against attacks based on special-purpose hardware and, in particular based on recently emerged low-cost FPGAs, arises.This work presents the first architecture with a corresponding FPGA implementation of an attack against ECC over prime fields. We describe an FPGA-based multi-processing hardware architecture for the Pollard-Rho method which is, to our knowledge, currently the most efficient attack against ECC. The implementation is running on a contemporary low-cost FPGA which allows for a much better cost-performance ratio than conventional CPUs. With the implementation at hand, a fairly accurate estimate about the cost of an FPGA-based attack can be given. We will extrapolate the results on actual ECC key lengths (128 bits and above) and estimate the expected runtimes for a successful attack. Since FPGA-based attacks are out of reach for key lengths exceeding 128 bits, we provide estimates for an ASIC design.Based on our results, currently used elliptic curve cryptosystems (160 bit and above) are infeasible to break with available computational and financial resources. However, some of the security standards proposed by the SECG in [2, 3] become subject to attacks based on low-cost FPGAs. Tim Güneysu, Christof Paar, Jan Pelzl |
FPGA | 3 |
| 2006 | Breaking Ciphers with COPACOBANA - A Cost-Optimized Parallel Code BreakerabstractCryptanalysis of symmetric and asymmetric ciphers is computationally extremely demanding. Since the security parameters (in particular the key length) of almost all practical crypto algorithms are chosen such that attacks with conventional computers are computationally infeasible, the only promising way to tackle existing ciphers (assuming no mathematical breakthrough) is to build special-purpose hardware. Dedicating those machines to the task of cryptanalysis holds the promise of a dramatically improved cost-performance ratio so that breaking of commercial ciphers comes within reach. This contribution presents the design and realization of the COPACOBANA (Cost-Optimized Parallel Code Breaker) machine, which is optimized for running cryptanalytical algorithms and can be realized for less than US$ 10,000. It will be shown that, depending on the actual algorithm, the architecture can outperform conventional computers by several orders in magnitude. COPACOBANA hosts 120 low-cost FPGAs and is able to, e.g., perform an exhaustive key search of the Data Encryption Standard (DES) in less than nine days on average. As a real-world application, our architecture can be used to attack machine readable travel documents (ePass). COPACOBANA is intended, but not necessarily restricted to solving problems related to cryptanalysis. The hardware architecture is suitable for computational problems which are parallelizable and have low communication requirements. The hardware can be used, e.g., to attack elliptic curve cryptosystems and to factor numbers. Even though breaking full-size RSA (1024 bit or more) or elliptic curves (ECC with 160 bit or more) is out of reach with COPACOBANA, it can be used to analyze cryptosystems with a (deliberately chosen) small bitlength to provide reliable security estimates of RSA and ECC by extrapolation. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Sandeep S. Kumar, Christof Paar, Jan Pelzl, Gerd Pfeiffer, Manfred Schimmler |
CHES | 3 |
| 2006 | A Parallel Hardware Architecture for fast Gaussian Elimination over GF(2)abstractThis paper presents a hardware-optimized variant of the well-known Gaussian elimination over GF(2) and its highly efficient implementation. The proposed hardware architecture can solve any regular and (uniquely solvable) overdetermined linear system of equations (LSE) and is not limited to matrices of a certain structure. Besides solving LSEs, the architecture at hand can also accomplish the related problem of matrix inversion extremely fast. Its average running time for n times n binary matrices with uniformly distributed entries equals 2n (clock cycles) as opposed to about frac14n3in software. The average running time remains very close to 2n for matrices with densities much greater or lower than 0.5. The architecture has a worst-case time complexity of O(n2) and also a space complexity of O(n2). With these characteristics the architecture is particularly suited to efficiently solve medium-sized LSEs as they for example appear in the cryptanalysis of certain stream cipher classes. Moreover, we propose a hardware-optimized algorithm for matrix-by-matrix multiplication over GF(2) which runs in linear time and quadratic space on a similar architecture. This opens up the possibility of building a more complex architecture for efficiently solving larger LSEs by means of Strassen's algorithm which could significantly improve the time complexity of algebraic attacks on various ciphers. As proof-of-concept we realized our architecture on a contemporary low-cost FPGA. The implementation for a 50 times 50 LSE can be clocked with a frequency of up to 300 MHz and computes the solution in 0.33 mus on average Andrey Bogdanov, M. C. Mertens, Christof Paar, Jan Pelzl, Andy Rupp |
FCCM | 4 |
| 2006 | COPACOBANA A Cost-Optimized Special-Purpose Hardware for Code-BreakingabstractCryptanalysis of symmetric and asymmetric ciphers is computationally extremely demanding. Since the security parameters of almost all practical crypto algorithms are chosen such that attacks with conventional computers are computationally infeasible, the only promising way to tackle existing ciphers (assuming no mathematical breakthrough) is to build special-purpose hardware. This contribution presents a special-purpose hardware labeled COPACOBANA (cost-optimized parallel code breaker), which is optimized for running crypt-analytical algorithms with low communication overhead. The price-performance ratio as primary and a cost margin of less than US$ 10,000 as secondary design goal led to a reconfigurable computer built as cluster of programmable logic devices Sandeep S. Kumar, Christof Paar, Jan Pelzl, Gerd Pfeiffer, Manfred Schimmler |
FCCM | 3 |
| 2005 | SHARK: A Realizable Special Hardware Sieving Device for Factoring 1024-Bit Integers
Jens Franke, Thorsten Kleinjung, Christof Paar, Jan Pelzl, Christine Priplata, Colin Stahlke |
CHES | 4 |
| 2005 | Hardware Factorization Based on Elliptic Curve MethodabstractThe security of the most popular asymmetric cryptographic scheme RSA depends on the hardness of factoring large numbers. The best known method for factorization large integers is the general number field sieve (GNFS). Recently, architectures for special purpose hardware for the GNFS have been proposed. One important step within the GNFS is the factorization of mid-size numbers for smoothness testing, an efficient algorithm for which is the elliptic curve method (ECM). Since the smoothness testing is also suitable for parallelization, it is promising to improve ECM via special-purpose hardware. We show that massive parallel and cost efficient ECM hardware engines can improve the cost-time product of the RSA moduli factorization via the GNFS considerably. The computation of ECM is a classical example for an algorithm that can be significantly accelerated through special-purpose hardware. In this work, we present an efficient hardware implementation of ECM to factor numbers up to 200 bits, which is also scalable to other bit lengths. For proof-of-concept purposes, ECM is realized as a software-hardware co-design on an FPGA and an embedded microcontroller. This appears to be the first publication of a realized hardware implementation of ECM, and the first description of GNFS acceleration through hardware-based ECM. Martin Simka, Jan Pelzl, Thorsten Kleinjung, Jens Franke, Christine Priplata, Colin Stahlke, Milos Drutarovský, Viktor Fischer |
FCCM | 2 |
| 2005 | Efficient Hardware Architectures for Modular Multiplication on FPGAsabstractThe computational fundament of most public-key cryptosystems is the modular multiplication. Improving the efficiency of the modular multiplication is directly associated with the efficiency of the whole cryptosystem. This paper presents an implementation and comparison of three recently proposed, highly efficient architectures for modular multiplication on FPGAs: interleaved modular multiplication and two variants of the Montgomery modular multiplication. This (first) hardware implementation of these designs shows their relative performance regarding area and speed. One of the main findings is that the interleaved multiplication has the least area time product of all investigated architectures. As a typical cryptographic application, we show that a 1024-bit RSA exponentiation can be performed in less than 6.1ms at a clock rate of 69MHz on a Xilinx Virtex FPGA. David Narh Amanor, Viktor Bunimov, Christof Paar, Jan Pelzl, Manfred Schimmler |
FPL | 4 |
| 2005 | Cantor versus Harley: Optimization and Analysis of Explicit Formulae for Hyperelliptic Curve CryptosystemsabstractHyperelliptic curves (HEC) look promising for cryptographic applications, because of their short operand size compared to other public-key schemes. The operand sizes seem well suited for small processor architectures, where memory and speed are constrained. However, the group operation has been believed to be too complex and, thus, HEC have not been used in this context so far. In recent years, a lot of effort has been made to speed up group operation of genus-2 HEC. In this paper, we increase the efficiency of the genus-2 and genus-3 hyperelliptic curve cryptosystems (HECC). For certain genus-3 curves, we can gain almost 80 percent performance for a group doubling. This work not only improves Gaudry and Harley's algorithm, but also improves the original algorithm introduced by Cantor [1987]. Contrary to common belief, we show that it is also practical for certain curves to use Cantor's algorithm to obtain the highest efficiency for the group operation. In addition, we introduce a general reduction method for polynomials according to Karatsuba. We implemented our most efficient group operations on Pentium and ARM microprocessors. Thomas J. Wollinger, Jan Pelzl, Christof Paar |
IEEE Trans. Computers | 2 |
| 2004 | Elliptic and hyperelliptic curves on embedded µPabstractIt is widely recognized that data security will play a central role in future IT systems. Providing public-key cryptographic primitives, which are the core tools for security, is often difficult on embedded processor due to computational, memory, and power constraints. This contribution appears to be the first thorough comparison of two public-key families, namely elliptic curve (ECC) and hyperelliptic curve cryptosystems on a wide range of embedded processor types (ARM, ColdFire, PowerPC). We investigated the influence of the processor type, resources, and architecture regarding throughput. Further, we improved previously known HECC algorithms resulting in a more efficient arithmetic. Thomas J. Wollinger, Jan Pelzl, Volker Wittelsberger, Christof Paar, Gökay Saldamli, Çetin Kaya Koç |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2003 | Hyperelliptic Curve Cryptosystems: Closing the Performance Gap to Elliptic Curves
Jan Pelzl, Thomas J. Wollinger, Jorge Guajardo, Christof Paar |
CHES | 1 |