EDBT 2026 Demo / reviewers in the wild / expert
Amir Moradi 0001
dblp:38/3348
· DBLP profile ↗
79ranked-venue papers
21as first author
15since 2021 · last 2026
0000-0002-4032-7433ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 15 first-author · 5 since 2021Systems, architecture and hardware · 32 · 5 first-author · 10 since 2021Software engineering, systems software and programming languages · 8 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Postponing the Glitches is not Enough A Critical Analysis of the DATE 2024 E-ISW Masking Scheme
Amir Moradi 0001 |
DATE | 1 |
| 2026 | Impedance Side-Channel Analysis of ASICs: An investigation of measurement factorsabstractAbstract A substantial body of research has been conducted on the subject of physical side-channel analysis attacks and the measures that can be employed to counteract them. These attacks typically exploit the impact of computation or storage on current consumption or voltage drop on a chip, which is an unavoidable consequence of the underlying physical processes. This data-dependent influence can be exploited through analytical techniques such as power or electromagnetic analysis. Recently, a novel target for side-channel analysis adversaries has emerged, based on the data dependency between the chip’s power delivery network impedance and the temporarily stored content in registers. There are two principal reasons why information leakage through the Impedance Side Channel (IMSC) compromises the security of the implementations. First, this method can target the secret even outside the time window, provided that the sensitive data is stored somewhere in the circuit; and second, the simultaneous and independent probing of particular registers challenges the t-probing security model used in masking proofs, a primary side-channel countermeasure. It is crucial to highlight that the interdependence between the die impedance and the temporarily stored data in registers is revealed through scattering parameter analysis. Consequently, the precise measurement of data-dependent impedance, or equivalently, the Scattering (S)- parameter, is essential for its use as a side-channel, which is our focus in this study. In this study, we examine the impact of environmental factors on the IMSC, which are controlled by a classical side-channel adversary. Such factors include temperature and supply voltage. Due to the similarity between the measurement procedures of IMSC and Static Power Side- Channel Analysis (SPSCA), we further provide a fair comparison of these two side-channels in terms of their exploitability and ease of measurement. Most of the previously published studies on the IMSC have been conducted using Field Programmable Gate Arrays (FPGAs). This provides a high level of control over the placement of design components, which can, in turn, affect analysis results. In this work, we use a dedicated Application-Specific Integrated Circuit (ASIC) chip fabricated in 28nm Complementary Metal-Oxide-Semiconductor (CMOS) technology to conduct our study in a more realistic setting. We demonstrated the significant impact of the aforementioned environmental factors on the exploitability of such a side channel. In conclusion, an IMSC adversary can influence the device to leak more information by regulating its operational environment. Bijan Fadaeinia, Shahin Tajik, Amir Moradi 0001 |
J. Electron. Test. | 3 |
| 2025 | One More Motivation to Use Evaluation Tools This Time for Hardware Multiplicative Masking of AESabstractSafeguarding cryptographic implementations against the increasing threat of Side-Channel Analysis (SCA) attacks is essential. Masking, a countermeasure that randomizes intermediate values, is a cornerstone of such defenses. In particular, SCA-secure implementation of AES, the most-widely used encryption standard, can employ Boolean masking as well as multiplicative masking due to its underlying Galois field operations. However, multiplicative masking is susceptible to vulnerabilities, including the zero-value problem, which has been identified right after the introduction of multiplicative masking. At CHES 2018, De Meyer et al. proposed a hardware-based approach to manage these challenges and implemented multiplicative masking for AES, incorporating a Kronecker delta function and randomness optimization. In this work, we evaluate their design using the PROLEAD evaluation tool under the glitch-and transition-extended probing model. Our findings reveal a critical vulnerability in their first-order implementation of the Kronecker delta function, stemming from the employed randomness optimization. This leakage com-promises the security of their presented masked AES Sbox. After pinpointing the source of such a leakage, we propose an alternative randomness optimization to address this issue, and demonstrate its effectiveness through rigorous evaluations by means of PROLEAD. Hemin Rahimi, Amir Moradi 0001 |
DATE | 2 |
| 2023 | A Thorough Evaluation of RAMBAMabstractThe application of masking, widely regarded as the most robust and reliable countermeasure against Side-Channel Analysis~(SCA) attacks, has been the subject of extensive research across a range of cryptographic algorithms, especially AES. However, the implementation cost associated with applying such a countermeasure can be significant and even in some scenarios infeasible due to considerations such as area and latency overheads, as well as the need for fresh randomness to ensure the security properties of the resulting design. Most of these overheads originate from the ability to maintain security in the presence of physical defaults such as glitches and transitions. Among several schemes with a trade-off between such overheads, RAMBAM, presented at CHES~2022, offers an ultra-low latency in terms of the number of clock cycles. It is dedicated to the AES and utilizes redundant representations of the finite field elements to enhance protection against both passive and active physical attacks. Daniel Lammers, Amir Moradi 0001, Nicolai Müller, Aein Rezaei Shahmirzadi |
CCS | 2 |
| 2023 | Special Session: Mitigating Side-Channel Attacks Through Circuit to Application Layer ApproachesabstractSide-Channel Attacks (SCAs), which are always considered a severe threat to the security of the cryptographic circuits, today can also be employed to extract IP secrets and neural network models. Hence, developing novel security solutions at different design levels is crucial. In this paper, we explore recent countermeasures at the circuit, algorithmic, and microarchitecture levels. First, we explain how Reconfigurable Field-Effect Transistor (RFET), as a beyond CMOS technology, enables us to provide both IP and data protection against SCAs at the circuit level. Second, we investigate an automated method for generating masked circuits as an algorithmic solution, and then we review machine learning-based SCA detection mechanisms at the microarchitecture level. Finally, we discuss emerging threats of SCAs from the industrial point of view. Nima Kavand, Armin Darjani, Jens Trommer, Giulio Galderisi, Thomas Mikolajick, Nicolai Müller, Amir Moradi 0001, Chongzhou Fang, Ning Miao, Han Wang 0020, Sai Manoj Pudukotai Dinakarrao, Houman Homayoun, Benjamin Hettwer, Luca Parrini, Akash Kumar 0001 |
CODES+ISSS | 7 |
| 2023 | Automated Masking of FPGA-Mapped DesignsabstractDue to the importance of FPGAs for secure systems, dealing with private data, protection against side-channel analysis attacks is a must. Although masking is a widely-deployed countermeasure, its application - particularly in hardware - is costly and error-prone. Therefore, generating masked hardware automatically with publicly-available tools such as AGEMA is attractive. As AGEMA was introduced to generate ASIC designs, its direct application on FPGAs is inefficient. In this work, we present AGEMA_FPGA to automatically generate highly-efficient masked circuits for FPGAs. Compared to the original AGEMA designs, our masked FPGA-based circuits utilize up to 64% fewer LUTs and at most 22% fewer FFs while the power consumption is reduced by at most 59%. We further provide an experimental side-channel security analysis of our designs confirming their provable security nature. Nicolai Müller, Sergej Meschkov, Dennis Gnad, Mehdi Baradaran Tahoori, Amir Moradi 0001 |
FPL | 5 |
| 2023 | Red Team vs. Blue Team: A Real-World Hardware Trojan Detection Case Study Across Four Modern CMOS Technology GenerationsabstractVerifying the absence of maliciously inserted Trojans in Integrated Circuits (ICs) is a crucial task – especially for security-enabled products. Depending on the concrete threat model, different techniques can be applied for this purpose. Assuming that the original IC layout is benign and free of backdoors, the primary security threats are usually identified as the outsourced manufacturing and transportation. To ensure the absence of Trojans in commissioned chips, one straightforward solution is to compare the received semiconductor devices to the design files that were initially submitted to the foundry. Clearly, conducting such a comparison requires advanced laboratory equipment and qualified experts. Nevertheless, the fundamental techniques to detect Trojans which require evident changes to the silicon layout are nowadays well-understood. Despite this, there is a glaring lack of public case studies describing the process in its entirety while making the underlying datasets publicly available. In this work, we aim to improve upon this state of the art by presenting a public and open hardware Trojan detection case study based on four different digital ICs using a Red Team vs. Blue Team approach. Hereby, the Red Team creates small changes acting as surrogates for inserted Trojans in the layouts of 90 nm, 65 nm, 40 nm, and 28 nm ICs. The quest of the Blue Team is to detect all differences between digital layout and manufactured device by means of a GDSII–vs–SEM-image comparison. Can the Blue Team perform this task efficiently? Our results spark optimism for the Trojan seekers and answer common questions about the efficiency of such techniques for relevant IC sizes. Further, they allow to draw conclusions about the impact of technology scaling on the detection performance. Endres Puschner, Thorben Moos, Steffen Becker 0003, Christian Kison, Amir Moradi 0001, Christof Paar |
SP | 5 |
| 2022 | Second-Order Low-Randomness d + 1 Hardware Sharing of the AESabstractIn this paper, we introduce a second-order masking of the AES using the minimal number of shares and a total of 1268 bits of randomness including the sharing of the plaintext and key. The masking of the S-box is based on the tower field decomposition of the inversion over bytes where the changing of the guards technique is used in order to re-mask the middle branch of the decomposition. The sharing of the S-box is carefully crafted such that it achieves first-order probing security without the use of randomness and such that the sharing of its output is uniform. Multi-round security is achieved by re-masking the state where we use a theoretical analysis based on the propagation of probed information to reduce the demand for fresh randomness per round. The result is a second-order masked AES which competes with the state-of-the-art in terms of latency and area, but reduces the randomness complexity over eight times over the previous known works. In addition to the corresponding theoretical analysis and proofs for the security of our masked design, it has been implemented on FPGA and evaluated via lab analysis. Siemen Dhooghe, Aein Rezaei Shahmirzadi, Amir Moradi 0001 |
CCS | 3 |
| 2022 | Low-Latency Hardware Private CircuitsabstractOver the last years, the rise of the IoT, and the connection of mobile - and hence physically accessible - devices, immensely enhanced the demand for fast and secure hardware implementations of cryptographic algorithms which offer thorough protection against SCA attacks. Among a variety of proposed countermeasures against SCA, masking has transpired to be a promising candidate, attracting significant attention in both, academia and industry. Here, abstract adversary models have been derived, aiming to accurately model real-world attack scenarios, while being sufficiently simple to enable formally proving the SCA resilience of masked implementations on an algorithmic level. In the context of hardware implementations, the robust probing model has become highly relevant for proving SCA resilience due to its capability to model physical defaults like glitches and data transitions. As constructing a correct and secure masked variant of large and complex circuits is a challenging task, a new line of research has recently emerged, aiming to design small, masked subcircuits - realizing for instance a simple AND gate - which still guarantee security when composed to a larger circuit. Although several designs realizing such composable subcircuits - commonly referred to as gadgets - have been proposed, negligible research was conducted in order to find trade-offs between different overhead metrics, like randomness requirement, latency, and area consumption. David Knichel, Amir Moradi 0001 |
CCS | 2 |
| 2022 | A Cautionary Note on Protecting Xilinx' UltraScale(+) Bitstream Encryption and Authentication EngineabstractFPGA bitstream protection schemes are often the first line of defense for secure hardware designs. In general, breaking the bitstream encryption would enable attackers to subvert the confidentiality and infringe on the IP. Or breaking the authenticity enables manipulating the design, e.g., inserting hardware Trojans. Since FPGAs see widespread use in our interconnected world, such attacks can lead to severe damages, including physical harm. Recently we [1] presented a surprising attack — Starbleed — on Xilinx 7-Series FPGAs, tricking an FPGA into acting as a decryption oracle. For their UltraScale(+) series, Xilinx independently upgraded the security features to AES-GCM, RSA signatures, and a periodic GHASH-based checksum to validate the bitstream during decryption. Hence, UltraScale(+) devices were considered not affected by Starbleed-like attacks [2], [1].We identified novel security weaknesses in Xilinx UltraScale(+) FPGAs if configured outside recommended settings. In particular, we present four attacks in this situation: two attacks on the AES encryption and novel GHASH-based checksum and two authentication downgrade attacks. As a major contribution, we show that the Starbleed attack is still possible within the UltraScale(+) series by developing an attack against the GHASH-based checksum. After describing and analyzing the attacks, we list the subtle configuration changes which can lead to security vulnerabilities and secure configurations not affected by our attacks. As Xilinx only recommends configurations not affected by our attacks, users should be largely secure. However, it is not unlikely that users employ settings outside the recommendations, given the rather large number of configuration options and the fact that Security Misconfiguration is among the leading top 10 OWASP security issues. We note that these security weaknesses shown in this paper had been unknown before. Maik Ender, Gregor Leander, Amir Moradi 0001, Christof Paar |
FCCM | 3 |
| 2021 | On the Impact of Aging on Power Analysis Attacks Targeting Power-Equalized Cryptographic CircuitsabstractSide-channel analysis attacks exploit the physical characteristics of cryptographic chip implementations to extract their embedded secret keys. In particular, Power Analysis (PA) attacks make use of the dependency of the power consumption on the data being processed by the cryptographic devices. To tackle the vulnerability of cryptographic circuits against PA attack, various countermeasures have been proposed in literature and adapted by industries, among which a branch of hiding schemes opt to equalize the power consumption of the chip regardless of the processed data. Although these countermeasures are supposed to reduce the information leakage of cryptographic chips, they fail to consider the impact of aging occurs during the device lifetime. Due to aging, the specifications of transistors, and in particular their threshold-voltage, deviate from their fabrication-time specification, leading to a change of circuit's delay and power consumption over time. In this paper, we show that the aging-induced impacts result in imbalances in the equalized power consumption achieved by hiding countermeasures. This makes such protected cryptographic chips vulnerable to PA attacks when aged. The experimental results extracted through the aging simulation of the PRESENT cipher protected by Sense Amplifier Based Logic (SABL), one of the well-known hiding countermeasures, show that the achieved protection may not last during the circuit lifetime. Md Toufiq Hasan Anik, Bijan Fadaeinia, Amir Moradi 0001, Naghmeh Karimi |
ASP-DAC | 3 |
| 2021 | Automated Masking of Software Implementations on Industrial MicrocontrollersabstractPhysical side-channel attacks threaten the security of exposed embedded devices, such as microcontrollers. Dedicated countermeasures, like masking, are necessary to prevent these powerful attacks. However, a gap between well-studied leakage models and observed leakage on real devices makes the application of these countermeasures non-trivial. This work provides a gadget-based concept to automated masking covering practically relevant leakage models to achieve security on real-world devices. We realize this concept with a fully automated compiler that transforms unprotected microcontroller-implementations of cryptographic primitives into masked executables, capable of being executed on the target device. In a case study, we apply our approach to a bitsliced LED implementation and perform a TVLA-based security evaluation of its core component: the PRESENT s-box. Arnold Abromeit, Florian Bache, Leon A. Becker, Marc Gourjon, Tim Güneysu, Sabrina Jorn, Amir Moradi 0001, Maximilian Orlt, Falk Schellenberg |
DATE | 7 |
| 2021 | Stealthy Logic Misuse for Power Analysis Attacks in Multi-Tenant FPGAsabstractFPGAs have been used in the cloud since several years, for workloads such as machine learning, database processes and security tasks. As for other cloud services, a highly desired feature is virtualization in which multiple tenants share a single FPGA to increase utilization and by that efficiency. By solely using standard FPGA logic in the untrusted tenant, on-chip logic sensors have recently been proposed, allowing remote power analysis side-channel and covert channel attacks on the victim tenant. However, such sensors are implemented by unusual circuit constructions, such as ring oscillators or delay lines, which might be easily detected by bitstream and/or netlist checking. In this paper we show that such structural checking methods are not universal solutions as the attacks can make use of “benign-looking” circuits. We demonstrate this by showing a successful Correlation Power Analysis attack on the Advanced Encryption Standard. Dennis Gnad, Vincent Meyers, Nguyen Minh Dang, Falk Schellenberg, Amir Moradi 0001, Mehdi Baradaran Tahoori |
DATE | 5 |
| 2021 | Impeccable Circuits IIIabstractAs a recent fault-injection attack, SIFA defeats most of the known countermeasures. Although error-correcting codes have been shown effective against SIFA, they mainly require a large redundancy to correct a few bits. In this work, we propose a hybrid construction with the ability to detect and correct injected faults at the same time. We provide a general implementation methodology which guarantees the correction of up to tc-bit faults and the detection of at most tdfaulty bits. Exhaustive evaluation of our constructions, by the open-source fault diagnostic tool VerFI, indicate the success of our designs in achieving the desired goals. Shahram Rasoolzadeh, Aein Rezaei Shahmirzadi, Amir Moradi 0001 |
ITC | 3 |
| 2021 | Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelabstractDue to its sound theoretical basis and practical efficiency, masking has become the most prominent countermeasure to protect cryptographic implementations against physical side-channel attacks (SCAs). The core idea of masking is to randomly split every sensitive intermediate variable during computation into at least t+1 shares, where t denotes the maximum number of shares that are allowed to be observed by an adversary without learning any sensitive information. In other words, it is assumed that the adversary is bounded either by the possessed number of probes (e.g., microprobe needles) or by the order of statistical analyses while conducting higher-order SCA attacks (e.g., differential power analysis). Such bounded models are employed to prove the SCA security of the corresponding implementations. Consequently, it is believed that given a sufficiently large number of shares, the vast majority of known SCA attacks are mitigated.In this work, we present a novel laser-assisted SCA technique, called Laser Logic State Imaging (LLSI), which offers an unlimited number of contactless probes, and therefore, violates the probing security model assumption. This technique enables us to take snapshots of hardware implementations, i.e., extract the logical state of all registers at any arbitrary clock cycle with a single measurement. To validate this, we mount our attack on masked AES hardware implementations and practically demonstrate the extraction of the full-length key in two different scenarios. First, we assume that the location of the registers (key and/or state) is known, and hence, their content can be directly read by a single snapshot. Second, we consider an implementation with unknown register locations, where we make use of multiple snapshots and a SAT solver to reveal the secrets. Thilo Krachenfels, Fatemeh Ganji, Amir Moradi 0001, Shahin Tajik, Jean-Pierre Seifert |
SP | 3 |
| 2020 | SILVER - Statistical Independence and Leakage Verification
David Knichel, Pascal Sasdrich, Amir Moradi 0001 |
ASIACRYPT (1) | 3 |
| 2020 | Impeccable Circuits IIabstractProtection against active physical attacks is of serious concerns of cryptographic hardware designers. Introduction of SIFA invalidating several previously-thought-effective counter-measures, made this challenge even harder. Here in this work we deal with error correction, and introduce a methodology which shows, depending on the selected adversary model, how to correctly embed error-correcting codes in a cryptographic implementation. Our construction guarantees the correction of faults, in any location of the circuit and at any clock cycle, as long as they fit into the underlying adversary model. Based on case studies evaluated by open-source fault diagnostic tools, we claim protection against SIFA. Aein Rezaei Shahmirzadi, Shahram Rasoolzadeh, Amir Moradi 0001 |
DAC | 3 |
| 2020 | The Risk of Outsourcing: Hidden SCA Trojans in Third-Party IP-Cores Threaten Cryptographic ICsabstractSide-channel analysis (SCA) attacks - especially power analysis - are powerful ways to extract the secrets stored in and processed by cryptographic devices. In recent years, researchers have shown interest in utilizing on-chip measurement facilities to perform such SCA attacks remotely. It was shown that simple voltage-monitoring sensors can be constructed from digital elements and put on multi-tenant FPGAs to perform remote attacks on neighbouring cryptographic co-processors. A similar threat is the unsuspecting integration of third-party IP-Cores into an IC design. Even if the function of an acquired IP-Core is not security critical by itself, it may contain an on-chip sensor as a Trojan that can eavesdrop on cryptographic operations across the whole device. In contrast to all FPGA-based investigations reported in the literature so far, we examine the efficiency of such on-chip sensors as a source of information leakage in an ASIC-based case study for the first time. To this end, in addition to a cryptographic core (lightweight block cipher PRESENT) we designed and implemented a voltage-monitoring sensor on an ASIC fabricated by a 40 nm commercial standard cell library. Despite the physical distance between the sensor and the PRESENT core, we show the possibility of fully recovering the secret key of the PRESENT core by processing the sensor's output. Our results imply that the hidden insertion of such a sensor - for example by a malicious third party IP-Core vendor - can endanger the security of embedded systems which deal with sensitive information, even if the device cannot be physically accessed by the adversary. David Knichel, Thorben Moos, Amir Moradi 0001 |
ETS | 3 |
| 2020 | The Unpatchable Silicon: A Full Break of the Bitstream Encryption of Xilinx 7-Series FPGAs
Maik Ender, Amir Moradi 0001, Christof Paar |
USENIX Security Symposium | 2 |
| 2020 | Spin Me Right Round Rotational Symmetry for FPGA-Specific AES: Extended VersionabstractAbstract The effort in reducing the area of AES implementations has largely been focused on application-specific integrated circuits (ASICs) in which a tower field construction leads to a small design of the AES S-box. In contrast, a naive implementation of the AES S-box has been the status-quo on field-programmable gate arrays (FPGAs). A similar discrepancy holds for masking schemes—a well-known side-channel analysis countermeasure—which are commonly optimized to achieve minimal area in ASICs. In this paper, we demonstrate a representation of the AES S-box exploiting rotational symmetry which leads to a 50% reduction in the area footprint on FPGA devices. We present new AES implementations which improve on the state-of-the-art and explore various trade-offs between area and latency. For instance, at the cost of increasing 4.5 times the latency, one of our design variants requires 25% less look-up tables (LUTs) than the smallest known AES on Xilinx FPGAs by Sasdrich and Güneysu at ASAP 2016. We further explore the protection of such implementations against side-channel attacks. We introduce a generic methodology for masking anyn-bit Boolean functions of degreetwith protection orderd. The methodology is exact for first-order and heuristic for higher orders. Its application to our new construction of the AES S-box allows us to improve previous results and introduce the smallest first-order masked AES implementation on Xilinx FPGAs, to date. Felix Wegener, Lauren De Meyer, Amir Moradi 0001 |
J. Cryptol. | 3 |
| 2020 | Impeccable CircuitsabstractBy injecting faults, active physical attacks pose serious threats to cryptographic hardware where Concurrent Error Detection (CED) schemes are promising countermeasures. They are usually based on an Error-Detecting Code (EDC) which enables detecting certain injected faults depending on the specification of the underlying code. Here, we propose a methodology to enable correct, practical, and robust implementation of code-based CEDs. We show that straightforward hardware implementations of given code-based CEDs can suffer from severe vulnerabilities, not providing the desired protection level. In particular, propagation of faults into combinatorial logic is often ignored in security evaluation of these schemes. First, we formally define this detrimental effect and demonstrate its destructive impact. Second, we introduce an implementation strategy to limit the fault propagation effect. Third, in contrast to many other works where the fault coverage is the main focus, we present a detailed implementation strategy which can guarantee the detection of any fault covered by the underlying EDC. This holds for any time of the computation and any location in the circuit, both in data processing and control unit. In short, we provide practical guidelines how to construct efficient CED schemes with arbitrary EDCs to achieve the desired protection level. We practically evaluate the efficiency of our methodology by case studies covering different symmetric block ciphers and various linear EDCs. Anita Aghaie, Amir Moradi 0001, Shahram Rasoolzadeh, Aein Rezaei Shahmirzadi, Falk Schellenberg, Tobias Schneider 0002 |
IEEE Trans. Computers | 2 |
| 2020 | TI-PUF: Toward Side-Channel Resistant Physical Unclonable FunctionsabstractOne of the main motivations behind introducing PUFs was their ability to resist physical attacks. Among them, cloning was the major concern of related scientific literature. Several primitive PUF designs have been introduced to the community, and several machine learning attacks have been shown capable of modeling such constructions. Although a few works have expressed how to make use of Side-Channel Analysis (SCA) leakage of PUF constructions to significantly improve the modeling attacks, little attention has been paid to provide corresponding countermeasures. In this paper, we present a generic technique to operate any PUF primitive in an SCA-secure fashion. We, for the first time, make it possible to apply a provably-secure masking countermeasure - Threshold Implementation (TI) - on a strong PUF design. As a case study, we concentrate on the Interpose PUF and based on practical experiments on an FPGA prototype, we demonstrate the ability of our construction to prevent the recovery of intermediate values through SCA measurements. Anita Aghaie, Amir Moradi 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | Side-Channel Hardware Trojan for Provably-Secure SCA-Protected ImplementationsabstractHardware Trojans have drawn the attention of academia, industry, and government agencies. Effective detection mechanisms and countermeasures against such malicious designs can only be developed when there is a deep understanding of how hardware Trojans can be built in practice, in particular, Trojans specifically designed to avoid detection. In this article, we present a mechanism to introduce an extremely stealthy hardware Trojan into cryptographic primitives equipped with provably-secure first-order side-channel countermeasures. Once the Trojan is triggered, the malicious design exhibits exploitable side-channel leakage, leading to successful key recovery attacks. Generally, such a Trojan requires neither addition nor removal of any logic which makes it extremely hard to detect. On ASICs, it can be inserted by subtle manipulations at the subtransistor level and on FPGAs by changing the routing of particular signals, leading to zero logic overhead. The underlying concept is based on modifying a securely masked hardware implementation in such a way that running the device at a particular clock frequency violates one of its essential properties, leading to exploitable leakage. We apply our technique to a threshold implementation of the PRESENT block cipher realized in two different CMOS technologies and show that triggering the Trojan makes the ASIC prototypes vulnerable. Samaneh Ghandali, Thorben Moos, Amir Moradi 0001, Christof Paar |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2020 | Static Power Side-Channel Analysis - An Investigation of Measurement FactorsabstractThe static power consumption of modern CMOS devices has become a substantial concern in the context of the side-channel security of cryptographic hardware. Its continuous growth in nanometer-scaled technologies is not only inconvenient for effective low-power designs but does also create a new target for power analysis adversaries. Additionally, it has to be noted that several of the numerous sources of static power dissipation in CMOS circuits exhibit an exponential dependence on environmental factors which a classical power analysis adversary is in control of. These factors include the operating conditions' temperature and supply voltage. Furthermore, in the case of clock control, the measurement interval can be adjusted arbitrarily. Our experiments on a 150-nm CMOS ASIC reveal that with respect to the signal-to-noise ratio in static power side-channel analyses, stretching the measurement interval decreases the noise exponentially and even more importantly that raising the working temperature increases the signal exponentially. Control over the supply voltage has a far smaller, but still noticeable, positive impact as well. In summary, a static power analysis adversary can physically force a device to leak more information by controlling its operating environment and furthermore measure these leakages with arbitrary precision by modifying the interval length. Thorben Moos, Amir Moradi 0001, Bastian Richter 0001 |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2019 | A Comparison of χ 2-Test and Mutual Information as Distinguisher for Side-Channel Analysis
Bastian Richter 0001, David Knichel, Amir Moradi 0001 |
CARDIS | 3 |
| 2019 | Active Fences against Voltage-based Side Channels in Multi-Tenant FPGAsabstractDynamic and partial reconfiguration together with hardware parallelism make FPGAs attractive as virtualized accelerators. However, recently it has been shown that multi-tenant FPGAs are vulnerable to remote side-channel attacks (SCA) from malicious users, allowing them to extract secret keys without a logical connection to the victim core. Typical mitigations against such attacks are hiding and masking schemes, to increase attackers' efforts in terms of side-channel measurements. However, they require significant efforts and tailoring for a specific algorithm, hardware implementation and mapping. In this paper, we show a hiding countermeasure against voltage-based SCA that can be integrated into any implementation, without requiring modifications or tailoring to the protected module. We place a properly mapped Active Fence of ring oscillators between victim and attacker circuit, enabled as a feedback of an FPGA-based sensor, leading to reduced side-channel leakage. Our experimental results based on a Lattice ECP5 FPGA and an AES-128 module show that two orders of magnitude more traces are needed for a successful key recovery, while no modifications to the underlying cryptographic module are necessary. Jonas Krautter, Dennis Gnad, Falk Schellenberg, Amir Moradi 0001, Mehdi Baradaran Tahoori |
ICCAD | 4 |
| 2019 | Automated Probe Repositioning for On-Die EM MeasurementsabstractIn side-channel analysis attacks, on-die localized EM monitoring enable high bandwidth measurements of only a relevant part of the Integrated Circuit (IC). This can lead to improved attacks compared to cases where only power consumption is measured. Combined with profiled attacks which utilize a training phase to create precise models of the information leakage, the attacks can become even more powerful. In contrast, localized EM measurements can cause difficulties in applying the learned models as the probe should be identically positioned for both the training and the attack even when the setup was used otherwise in between. Even small differences in the probe position can lead to significant differences in the recorded signals. In this paper we present an automated system to precisely and efficiently reposition the probe when performing repeated measurements. Based on the training IC, we train a machine learning system to return the position of the probe for a given measurement. By taking a small number of measurements on the IC under attack, we can then obtain the coordinates of the measurements and map it to correct the coordinate system. As the target for our practical analyses, we use an STM32L0 ARM-M0+ microcontroller with integrated hardware AES. Bastian Richter 0001, Alexander Wild, Amir Moradi 0001 |
ICCAD | 3 |
| 2018 | Yet Another Size Record for AES: A First-Order SCA Secure AES S-Box Based on \(\mathrm {GF}(2^8)\) Multiplication
Felix Wegener, Amir Moradi 0001 |
CARDIS | 2 |
| 2018 | An inside job: Remote power analysis attacks on FPGAsabstractHardware Trojans have gained increasing interest during the past few years. Undeniably, the detection of such malicious designs needs a deep understanding of how they can practically be built and developed. In this work we present a design methodology dedicated to FPGAs which allows measuring a fraction of the dynamic power consumption. More precisely, we develop internal sensors which are based on FPGA primitives, and transfer the internally-measured side-channel leakages outside. These are distributed and calibrated delay sensors which can indirectly measure voltage fluctuations due to power consumption. By means of a cryptographic core as a case study, we present different settings and parameters for our employed sensors. Using their side-channel measurements, we further exhibit practical key-recovery attacks confirming the applicability of the underlying measurement methodology. This opens a new door to integrate hardware Trojans in a) applications where the FPGA is remotely accessible and b) FPGA-based multi-user platforms where the reconfigurable resources are shared among different users. This type of Trojan is highly difficult to detect since there is no signal connection between targeted (cryptographic) core and the internally-deployed sensors. Falk Schellenberg, Dennis Gnad, Amir Moradi 0001, Mehdi Baradaran Tahoori |
DATE | 3 |
| 2018 | Remote inter-chip power analysis side-channel attacks at board-levelabstractThe current practice in board-level integration is to incorporate chips and components from numerous vendors. A fully trusted supply chain for all used components and chipsets is an important, yet extremely difficult to achieve, prerequisite to validate a complete board-level system for safe and secure operation. An increasing risk is that most chips nowadays run software or firmware, typically updated throughout the system lifetime, making it practically impossible to validate the full system at every given point in the manufacturing, integration and operational life cycle. This risk is elevated in devices that run 3rd party firmware. In this paper we show that an FPGA used as a common accelerator in various boards can be reprogrammed by software to introduce a sensor, suitable as a remote power analysis side-channel attack vector at the board-level. We show successful power analysis attacks from one FPGA on the board to another chip implementing RSA and AES cryptographic modules. Since the sensor is only mapped through firmware, this threat is very hard to detect, because data can be exfiltrated without requiring inter-chip communication between victim and attacker. Our results also prove the potential vulnerability in which any untrusted chip on the board can launch such attacks on the remaining system. Falk Schellenberg, Dennis Gnad, Amir Moradi 0001, Mehdi Baradaran Tahoori |
ICCAD | 3 |
| 2018 | Bitstream Fault Injections (BiFI)-Automated Fault Attacks Against SRAM-Based FPGAsabstractThis contribution is concerned with the question whether an adversary can automatically manipulate an unknown FPGA bitstream realizing a cryptographic primitive such that the underlying secret key is revealed. In general, if an attacker has full knowledge about the bitstream structure and can make changes to the target FPGA design, she can alter the bitstream leading to key recovery. However, this requires challenging reverse-engineering steps in practice. We argue that this is a major reason why bitstream fault injection attacks have been largely neglected in the past. In this paper, we show that malicious bitstream modifications are i) much easier to conduct than commonly assumed and ii) surprisingly powerful. We introduce a novel class of bitstream fault injection (BiFI) attacks which does not require any reverse-engineering. Our attacks can be automatically mounted without any detailed knowledge about either the bitstream format or the design of the crypto primitive which is being attacked. Bitstream encryption features do not necessarily prevent our attack if the integrity of the encrypted bitstream is not carefully checked. We have successfully verified the feasibility of our attacks in practice by considering several publicly available AES designs. As target platforms, we have conducted our experiments on Spartan-6 and Virtex-5 Xilinx FPGAs. Pawel Swierczynski, Georg T. Becker, Amir Moradi 0001, Christof Paar |
IEEE Trans. Computers | 3 |
| 2018 | GliFreD: Glitch-Free Duplication Towards Power-Equalized Circuits on FPGAsabstractDesigners of secure hardware are required to harden their implementations against physical threats, such as power analysis attacks. In particular, cryptographic hardware circuits need to decorrelate their current consumption from the information inferred by processing (secret) data. A common technique to achieve this goal is the use of special logic styles that aim at equalizing the current consumption at each single processing step. However, since all hiding techniques like Dual-Rail Precharge (DRP) were originally developed for ASICs, the deployment of such countermeasures on FPGA devices with fixed and predefined logic structure poses a particular challenge. In this work, we propose and practically evaluate a new DRP scheme (GliFreD) that has been exclusively designed for FPGA platforms. GliFreD overcomes the well-known early propagation issue, prevents glitches, uses an isolated dual-rail concept, and mitigates imbalanced routings. With all these features, GliFreD significantly exceeds the level of physical security achieved by any previously reported, related countermeasures for FPGAs. Alexander Wild, Amir Moradi 0001, Tim Güneysu |
IEEE Trans. Computers | 2 |
| 2017 | The First Thorough Side-Channel Hardware Trojan
Maik Ender, Samaneh Ghandali, Amir Moradi 0001, Christof Paar |
ASIACRYPT (1) | 3 |
| 2017 | Bit-Sliding: A Generic Technique for Bit-Serial Implementations of SPN-based Primitives - Applications to AES, PRESENT and SKINNY
Jérémy Jean, Amir Moradi 0001, Thomas Peyrin, Pascal Sasdrich |
CHES | 2 |
| 2017 | Hiding Higher-Order Side-Channel Leakage - Randomizing Cryptographic Implementations in Reconfigurable Hardware
Pascal Sasdrich, Amir Moradi 0001, Tim Güneysu |
CT-RSA | 2 |
| 2017 | SPARX - A side-channel protected processor for ARX-based cryptographyabstractARX-based cryptographic algorithms are composed of only three elemental operations — addition, rotation and exclusive or — which are mixed to ensure adequate confusion and diffusion properties. While ARX-ciphers can easily be protected against timing attacks, special measures like masking have to be taken in order to prevent power and electromagnetic analysis. In this paper we present a processor architecture for ARX-based cryptography, that intrinsically guarantees first-order SCA resistance of any implemented algorithm. This is achieved by protecting the complete data path using a Boolean masking scheme with three shares. We evaluate our security claims by mapping an ARX-algorithm to the proposed architecture and using the common leakage detection methodology based on Student's i-test to certify the side-channel resistance of our processor. Florian Bache, Tobias Schneider 0002, Amir Moradi 0001, Tim Güneysu |
DATE | 3 |
| 2017 | Static power side-channel analysis of a threshold implementation prototype chipabstractThe static power consumption of modern CMOS devices has become a substantial concern in the context of the side-channel security of cryptographic hardware. The continuous growth of the leakage power dissipation in nanometer-scaled CMOS technologies is not only inconvenient for effective low power designs, but does also create a new target for power analysis adversaries. In this paper, we present the first experimental results of a static power side-channel analysis targeting an ASIC implementation of a provably first-order secure hardware masking scheme. The investigated 150 nm CMOS prototype chip realizes the PRESENT-80 lightweight block cipher as a threshold implementation and allows us to draw a comparison between the information leakage through its dynamic and static power consumption. By employing a sophisticated measurement setup dedicated to static power analysis, including a very low-noise DC amplifier as well as a climate chamber, we are able to recover the key of our target implementation with significantly less traces compared to the corresponding dynamic power analysis attack. In particular, for a successful third-order attack exploiting the static currents, less than 200 thousand traces are needed. Whereas for the same attack in the dynamic power domain around 5 million measurements are required. Furthermore, we are able to show that only-first-order resistant approaches like the investigated threshold implementation do not significantly increase the complexity of a static power analysis. Therefore, we firmly believe that this side channel can actually become the target of choice for real-world adversaries against masking countermeasures implemented in advanced CMOS technologies. Thorben Moos, Amir Moradi 0001, Bastian Richter 0001 |
DATE | 2 |
| 2016 | Side-Channel Analysis Protection and Low-Latency in Action - - Case Study of PRINCE and Midori -
Amir Moradi 0001, Tobias Schneider 0002 |
ASIACRYPT (1) | 1 |
| 2016 | Strong 8-bit Sboxes with Efficient Masking in Hardware
Erik Boss, Vincent Grosso, Tim Güneysu, Gregor Leander, Amir Moradi 0001, Tobias Schneider 0002 |
CHES | 5 |
| 2016 | The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS
Christof Beierle, Jérémy Jean, Stefan Kölbl, Gregor Leander, Amir Moradi 0001, Thomas Peyrin, Yu Sasaki 0001, Pascal Sasdrich, Siang Meng Sim |
CRYPTO (2) | 5 |
| 2016 | ParTI - Towards Combined Hardware Countermeasures Against Side-Channel and Fault-Injection Attacks
Tobias Schneider 0002, Amir Moradi 0001, Tim Güneysu |
CRYPTO (2) | 2 |
| 2016 | White-Box Cryptography in the Gray Box - - A Hardware Implementation and its Side Channels -
Pascal Sasdrich, Amir Moradi 0001, Tim Güneysu |
FSE | 2 |
| 2016 | Bridging the Gap: Advanced Tools for Side-Channel Leakage Estimation Beyond Gaussian Templates and Histograms
Tobias Schneider 0002, Amir Moradi 0001, François-Xavier Standaert, Tim Güneysu |
SAC | 2 |
| 2015 | Arithmetic Addition over Boolean Masking - Towards First- and Second-Order Resistance in Hardware
Tobias Schneider 0002, Amir Moradi 0001, Tim Güneysu |
ACNS | 2 |
| 2015 | Assessment of Hiding the Higher-Order Leakages in Hardware - What Are the Achievements Versus Overheads?
Amir Moradi 0001, Alexander Wild |
CHES | 1 |
| 2015 | Leakage Assessment Methodology - A Clear Roadmap for Side-Channel Evaluations
Tobias Schneider 0002, Amir Moradi 0001 |
CHES | 2 |
| 2015 | Side-channel attacks from static power: when should we care?
Santos Merino Del Pozo, François-Xavier Standaert, Dina Kamel, Amir Moradi 0001 |
DATE | 4 |
| 2015 | Affine Equivalence and Its Application to Tightening Threshold Implementations
Pascal Sasdrich, Amir Moradi 0001, Tim Güneysu |
SAC | 2 |
| 2015 | A Hardware-Based Countermeasure to Reduce Side-Channel Leakage: Design, Implementation, and EvaluationabstractSide-channel attacks are one of the major concerns for security-enabled applications as they make use of information leaked by the physical implementation of the underlying cryptographic algorithm. Hence, reducing the side-channel leakage of the circuits realizing the cryptographic primitives is amongst the main goals of circuit designers. In this paper, we present a novel circuit concept, which decouples the main power supply from an internal power supply that is used to drive a single logic gate. The decoupling is done with the help of buffering capacitances integrated into semiconductor. We also introduce-compared to the previously known schemes-an improved decoupling circuit which reduces the crosstalk from the internal to the external power supply. The result of practical side-channel evaluation on a prototype chip fabricated in a 150nm CMOS technology shows a high potential of our proposed technique to reduce the side-channel leakages. Andreas Gornik, Amir Moradi 0001, Jürgen Oehm, Christof Paar |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2015 | Physical Security Evaluation of the Bitstream Encryption Mechanism of Altera Stratix II and Stratix III FPGAsabstractTo protect Field-Programmable Gate Array (FPGA) designs against Intellectual Property (IP) theft and related issues such as product cloning, all major FPGA manufacturers offer a mechanism to encrypt the bitstream that is used to configure the FPGA. From a mathematical point of view, the employed encryption algorithms (e.g., Advanced Encryption Standard (AES) or 3DES) are highly secure. However, it has been shown that the bitstream encryption feature of several FPGA families is susceptible to side-channel attacks based on measuring the power consumption of the cryptographic module. In this article, we present the first successful attack on the bitstream encryption of the Altera Stratix II and Stratix III FPGA families. To this end, we analyzed the Quartus II software and reverse engineered the details of the proprietary and unpublished schemes used for bitstream encryption on Stratix II and Stratix III. Using this knowledge, we demonstrate that the full 128-bit AES key of a Stratix II as well as the full 256-bit AES key of a Stratix III can be recovered by means of side-channel attacks. In both cases, the attack can be conducted in a few hours. The complete bitstream of these FPGAs that are (seemingly) protected by the bitstream encryption feature can hence fall into the hands of a competitor or criminal—possibly implying system-wide damage if confidential information such as proprietary encryption schemes or secret keys programmed into the FPGA are extracted. In addition to lost IP, reprogramming the attacked FPGA with modified code, for instance, to secretly plant a hardware Trojan, is a particularly dangerous scenario for many security-critical applications. Pawel Swierczynski, Amir Moradi 0001, David F. Oswald, Christof Paar |
ACM Trans. Reconfigurable Technol. Syst. | 2 |
| 2014 | Detecting Hidden Leakages
Amir Moradi 0001, Sylvain Guilley, Annelie Heuser |
ACNS | 1 |
| 2014 | Side-Channel Leakage through Static Power - Should We Care about in Practice?
Amir Moradi 0001 |
CHES | 1 |
| 2014 | Early Propagation and Imbalanced Routing, How to Diminish in FPGAs
Amir Moradi 0001, Vincent Immler |
CHES | 1 |
| 2014 | Fault Sensitivity Analysis Meets Zero-Value AttackabstractPrevious works have shown that the combinatorial path delay of a cryptographic function, e.g., The AES S-box, depends on its input value. Since the relation between critical path delay and input value seems to be relatively random and highly dependent on the routing of the circuit, up to now only template or some collision attacks could reliably extract the used secret key of implementations not protected against fault attacks. Here we present a new attack which is based on the fact that, because of the zero-to-zero mapping of the AES Sbox inversion circuit, the critical path when processing the zero input is notably shorter than for all other inputs. Applying the attack to an AES design protected by an state-of-the-art fault detection scheme, we are able to fully recover the secret key in less than eight hours. Note that we neither require a known key measurement step (template case) nor a high similarity between different S-box instances (collision case). The only information gathered from the device is whether a fault occurred when processing a chosen plaintext. Oliver Mischke, Amir Moradi 0001, Tim Güneysu |
FDTC | 2 |
| 2013 | Attacking Atmel's CryptoMemory EEPROM with Special-Purpose Hardware
Alexander Wild, Tim Güneysu, Amir Moradi 0001 |
ACNS | 3 |
| 2013 | On the Simplicity of Converting Leakages from Multivariate to Univariate - (Case Study of a Glitch-Resistant Masking Scheme)
Amir Moradi 0001, Oliver Mischke |
CHES | 1 |
| 2013 | Side-channel attacks on the bitstream encryption mechanism of Altera Stratix II: facilitating black-box analysis using software reverse-engineeringabstractIn order to protect FPGA designs against IP theft and related issues such as product cloning, all major FPGA manufacturers offer a mechanism to encrypt the bitstream used to configure the FPGA. From a mathematical point of view, the employed encryption algorithms, e.g., AES or 3DES, are highly secure. However, recently it has been shown that the bitstream encryption feature of several FPGA product lines is susceptible to side-channel attacks that monitor the power consumption of the cryptographic module. In this paper, we present the first successful attack on the bitstream encryption of the Altera Stratix II FPGA. To this end, we reverse-engineered the details of the proprietary and unpublished Stratix II bitstream encryption scheme from the Quartus II software. Using this knowledge, we demonstrate that the full 128-bit AES key of a Stratix II can be recovered by means of side-channel analysis with 30,000 measurements, which can be acquired in less than three hours. The complete bitstream of a Stratix II that is (seemingly) protected by the bitstream encryption feature can hence fall into the hands of a competitor or criminal - possibly implying system-wide damage if confidential information such as proprietary encryption schemes or keys programmed into the FPGA are extracted. In addition to lost IP, reprogramming the attacked FPGA with modified code, for instance, to secretly plant a hardware trojan, is a particularly dangerous scenario for many security-critical applications. Amir Moradi 0001, David F. Oswald, Christof Paar, Pawel Swierczynski |
FPGA | 1 |
| 2013 | Comprehensive Evaluation of AES Dual Ciphers as a Side-Channel Countermeasure
Amir Moradi 0001, Oliver Mischke |
ICICS | 1 |
| 2013 | Introducing proxy zero-knowledge proof and utilization in anonymous credential systemsabstractABSTRACT In pseudonym systems, users by means of pseudonyms anonymously interact with organizations to obtain credentials. The credential scheme constructed by Lysyanskaya and Camenisch is among the most complete credential systems, in which “all‐or‐nothing” sharing scheme is used to prevent users sharing their credentials. If a user cannot directly show a credential issued by an organization, she or he has to give her or his own secret key to someone else as a proxy; afterward, the proxy can show the credential on behalf of the user. Thus, according to the all‐or‐nothing property of the system, having the user's secret key, the proxy can use all credentials of the user for itself. To solve this problem, in this paper, we present proxy zero‐knowledge proof and utilize it in Lysyanskaya and Camenisch anonymous credential system. In our proposed system, instead of giving the secret key to the proxy, the user generates a proxy key based on the desired credential particularly for the proxy. Therefore, the proxy neither is the owner of the user's credential nor uses his or her other credentials. Copyright © 2012 John Wiley & Sons, Ltd. Hoda Jannati, Mahmoud Salmasizadeh, Javad Mohajeri, Amir Moradi 0001 |
Secur. Commun. Networks | 4 |
| 2013 | One Attack to Rule Them All: Collision Timing Attack versus 42 AES ASIC CoresabstractWhen complex functions, for example, substitution boxes of block ciphers, are realized in hardware, timing attributes of the underlying combinational circuit depend on the input/output changes of the function. These characteristics can be exploited by the help of a relatively new scheme called fault sensitivity analysis. A collision timing attack which exploits the data-dependent timing characteristics of combinational circuits is demonstrated in this paper. The attack is based on an also recently published correlation collision attack, which avoids the need for a hypothetical timing model for the underlying combinational circuit to recover the secret materials. The target platforms of our proposed attack are 14 AES ASIC cores of the SASEBO LSI chips in three different process technologies, 13 nm, 90 nm, and 65 nm. Successfully breaking all cores including the DPA-protected and fault attack protected cores indicates the strength of the attack. Amir Moradi 0001, Oliver Mischke, Christof Paar |
IEEE Trans. Computers | 1 |
| 2012 | How Far Should Theory Be from Practice? - Evaluation of a Countermeasure
Amir Moradi 0001, Oliver Mischke |
CHES | 1 |
| 2012 | Black-Box Side-Channel Attacks Highlight the Importance of Countermeasures - An Analysis of the Xilinx Virtex-4 and Virtex-5 Bitstream Encryption Mechanism
Amir Moradi 0001, Markus Kasper, Christof Paar |
CT-RSA | 1 |
| 2012 | Statistical Tools Flavor Side-Channel Collision Attacks
Amir Moradi 0001 |
EUROCRYPT | 1 |
| 2012 | Masked Dual-Rail Precharge Logic Encounters State-of-the-Art Power Analysis MethodsabstractLatest evaluation of the state-of-the-art iMDPL logic style has shown small information leakage compared to its predecessor version MDPL. Concurrently, new advanced power analysis attacks specifically targeting iMDPL have been proposed. Up to now, these attacks are purely theoretic and have not been applied to an implementation. We present a comprehensive analysis of iMDPL, backed by real measurements collected from a 180 nm iMDPL prototype chip. We thoroughly study the extent of remaining information leakage of iMDPL by applying all relevant attacks. Our investigation shows the vulnerability of the target device, a standalone AES core, to several of the advanced attack methods. In comparison to conventional power analysis attacks, the advanced attacks need less power measurements to obtain meaningful results. With the help of logic level simulations routing imbalances between complementary mask trees are identified as a major source of leakage. Amir Moradi 0001, Mario Kirschbaum, Thomas Eisenbarth 0001, Christof Paar |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2011 | On the vulnerability of FPGA bitstream encryption against power analysis attacks: extracting keys from xilinx Virtex-II FPGAsabstractOver the last two decades FPGAs have become central components for many advanced digital systems, e.g., video signal processing, network routers, data acquisition and military systems. In order to protect the intellectual property and to prevent fraud, e.g., by cloning a design embedded into an FPGA or manipulating its content, many current FPGAs employ a bitstream encryption feature. We develop a successful attack on the bitstream encryption engine integrated in the widespread Virtex-II Pro FPGAs from Xilinx, using side-channel analysis. After measuring the power consumption of a single power-up of the device and a modest amount of off-line computation, we are able to recover all three different keys used by its triple DES module. Our method allows extracting secret keys from any real-world device where the bitstream encryption feature of Virtex-II Pro is enabled. As a consequence, the target product can be cloned and manipulated at the will of the attacker since no side-channel protection was included into the design of the decryption module. Also, more advanced attacks such as reverse engineering or the introduction of hardware Trojans become potential threats. While performing the side-channel attack, we were able to deduce a hypothetical architecture of the hardware encryption engine. To our knowledge, this is the first attack against the bitstream encryption of a commercial FPGA reported in the open literature. Amir Moradi 0001, Alessandro Barenghi, Timo Kasper, Christof Paar |
CCS | 1 |
| 2011 | Generic Side-Channel Countermeasures for Reconfigurable Devices
Tim Güneysu, Amir Moradi 0001 |
CHES | 2 |
| 2011 | On the Power of Fault Sensitivity Analysis and Collision Side-Channel Attacks in a Combined Setting
Amir Moradi 0001, Oliver Mischke, Christof Paar, Yang Li 0001, Kazuo Ohta, Kazuo Sakiyama |
CHES | 1 |
| 2011 | Pushing the Limits: A Very Compact and a Threshold Implementation of AES
Amir Moradi 0001, Axel Poschmann, San Ling, Christof Paar, Huaxiong Wang |
EUROCRYPT | 1 |
| 2011 | Improving the energy efficiency of reversible logic circuits by the combined use of adiabatic styles
Mehrdad Khatir, Alireza Ejlali, Amir Moradi 0001 |
Integr. | 3 |
| 2011 | Side-Channel Resistant Crypto for Less than 2, 300 GE
Axel Poschmann, Amir Moradi 0001, Khoongming Khoo, Chu-Wee Lim, Huaxiong Wang, San Ling |
J. Cryptol. | 2 |
| 2010 | Correlation-Enhanced Power Analysis Collision Attack
Amir Moradi 0001, Oliver Mischke, Thomas Eisenbarth 0001 |
CHES | 1 |
| 2010 | Practical Power Analysis Attacks on Software Implementations of McEliece
Stefan Heyse, Amir Moradi 0001, Christof Paar |
PQCrypto | 2 |
| 2009 | KeeLoq and Side-Channel Analysis-Evolution of an AttackabstractLast year we were able to break KeeLoq, which is a 64 bit block cipher that is popular for remote keyless entry (RKE) systems. KeeLoq RKEs are widely used for access control purposes such as garage openers or car door systems. Even though the attack seems almost straightforward in hindsight, there where many practical and theoretical problems to overcome. In this talk I want to describe the evolution of the attack over about two years. Also, some possible future improvements using fault-injection will be mentioned. During the first phase of breaking KeeLoq, a surprisingly long time was spent on analyzing the target hardware, taking measurements and wondering why we did not succeed. In the second phase, we were able to use differential power analysis attacks successfully on numerous commercially available products employing KeeLoq code hopping. Our techniques allow for efficiently revealing both the secret key of a remote transmitter and the manufacturer key stored in a receiver. As a result, a remote control can be cloned from only ten power traces, allowing for a practical key recovery in a few minutes. With similar techniques but with considerably more measurements (typically on the order of 10,000) we can extract the manufacturer key which is stored in every receiver device, e.g., a garage door opener unit. In the third phase, and most recent phase, we were able to come up with several improvements. Most notably, we found that an SPA (simple power analysis) attack allows to recover the manufacturer key with one measurement. In the talk, we will also speculate about extensions to fault-injection and timing attacks. It is important to note that most of our findings are not specific to KeeLoq but are - in principle - applicable to any symmetric cipher with an implementation that is not sidechannel resistant. Christof Paar, Thomas Eisenbarth 0001, Markus Kasper, Timo Kasper, Amir Moradi 0001 |
FDTC | 5 |
| 2009 | Vulnerability modeling of cryptographic hardware to power analysis attacks
Amir Moradi 0001, Mahmoud Salmasizadeh, Mohammad T. Manzuri Shalmani, Thomas Eisenbarth 0001 |
Integr. | 1 |
| 2008 | On the Power of Power Analysis in the Real World: A Complete Break of the KeeLoqCode Hopping Scheme
Thomas Eisenbarth 0001, Timo Kasper, Amir Moradi 0001, Christof Paar, Mahmoud Salmasizadeh, Mohammad T. Manzuri Shalmani |
CRYPTO | 3 |
| 2008 | A secure and low-energy logic style using charge recovery approachabstractThe charge recovery logic families have been designed several years ago not in order to eliminate the side-channel leakage but to reduce the power consumption. However, in this article we present a new charge recovery logic style not only to gain high energy efficiency but also to achieve the resistance against side-channel attacks especially against differential power analysis attacks. Our approach is a modified version of a classical charge recovery logic style namely 2N-2N2P. Simulation results show a significant improvement in DPA-resistance level as well as in power consumption reduction in comparison with 2N-2N2P and other DPA-resistant logic styles. Mehrdad Khatir, Amir Moradi 0001, Alireza Ejlali, Mohammad T. Manzuri Shalmani, Mahmoud Salmasizadeh |
ISLPED | 2 |
| 2007 | Compact and Secure Design of Masked AES S-Box
Babak Zakeri, Mahmoud Salmasizadeh, Amir Moradi 0001, Mahmoud Tabandeh, Mohammad T. Manzuri Shalmani |
ICICS | 3 |
| 2006 | A Generalized Method of Differential Fault Attack Against AES Cryptosystem
Amir Moradi 0001, Mohammad T. Manzuri Shalmani, Mahmoud Salmasizadeh |
CHES | 1 |
| 2005 | Enhanced cross-diamond-hexagonal search algorithms for fast block motion estimationabstractThis paper proposes two enhanced cross-diamond-hexagonal search algorithms to solve the motion-estimation problem in video coding. These algorithms differ from each other by their second step search only, and both of them employ cross-shaped pattern in first step. Proposed method is an improvement over CDHS, which eliminates some checking points of CDHS algorithm. Experimental results show that the proposed methods perform faster than the diamond search (DS) and CDHS, whereas similar quality is preserved. Amir Moradi 0001, Rouhollah Dianat, Shohreh Kasaei, Mohammad T. Manzuri Shalmani |
AVSS | 1 |