EDBT 2026 Demo / reviewers in the wild / expert
Elisabeth Oswald
dblp:48/4127
· DBLP profile ↗
49ranked-venue papers
5as first author
7since 2021 · last 2024
0000-0001-7502-3184ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 45 · 5 first-author · 7 since 2021Systems, architecture and hardware · 3Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Leakage Certification Made Simple
Aakash Chowdhury, Arnab Roy 0005, Carlo Brunetta, Elisabeth Oswald |
CRYPTO (6) | 4 |
| 2024 | A Novel Framework for Explainable Leakage Assessment
Elisabeth Oswald |
EUROCRYPT (3) | 2 |
| 2022 | Comparing Key Rank Estimation Methods
Rebecca Hay, Luke Mather, Elisabeth Oswald |
CARDIS | 3 |
| 2022 | A Novel Completeness Test for Leakage Models and Its Application to Side Channel Attacks and Responsibly Engineered Simulators
Elisabeth Oswald |
EUROCRYPT (3) | 2 |
| 2022 | Towards Micro-architectural Leakage Simulators: Reverse Engineering Micro-architectural Leakage Features Is Practical
Elisabeth Oswald, Dan Page |
EUROCRYPT (3) | 2 |
| 2021 | An Analytic Attack against ARX Addition Exploiting Standard Side-channel LeakageabstractIn the last few years a new design paradigm, the so-called ARX (modular addition, rotation, exclusive-or) ciphers, have gained popularity in part because of their non-linear operation’s seemingly ‘inherent resilience’ against Differential Power Analysis (DPA) Attacks: the non-linear modular addition is not only known to be a poor target for DPA attacks, but also the computational complexity of DPA-style attacks grows exponentially with the operand size and thus DPA-style attacks quickly become practically infeasible. We however propose a novel DPA-style attack strategy that scales linearly with respect to the operand size in the chosen-message attack setting. Yan Yan 0018, Elisabeth Oswald, Srinivas Vivek 0001 |
ICISSP | 2 |
| 2021 | Neyman's Smoothness Test: A Trade-Off Between Moment-Based and Distribution-Based Leakage Detections
Elisabeth Oswald, Yan Yan 0018 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | A Critical Analysis of ISO 17825 ('Testing Methods for the Mitigation of Non-invasive Attack Classes Against Cryptographic Modules')
Carolyn Whitnall, Elisabeth Oswald |
ASIACRYPT (3) | 2 |
| 2019 | Examining the practical side channel resilience of ARX-boxesabstractImplementations of ARX ciphers are hoped to have some intrinsic side channel resilience owing to the specific choice of cipher components: modular addition (A), rotation (R) and exclusive-or (X). Previous work has contributed to this understanding by developing theory regarding the side channel resilience of components (pioneered by the early works of Prouff) as well as some more recent practical investigations by Biryukov et al. that focused on lightweight cipher constructions. We add to this work by specifically studying ARX-boxes both mathematically as well as practically. Our results show that previous works' reliance on the simplistic assumption that intermediates independently leak (their Hamming weight) has led to the incorrect conclusion that the modular addition is necessarily the best target and that ARX constructions are therefore harder to attack in practice: we show that on an ARM M0, the best practical target is the exclusive or and attacks succeed with only tens of traces. Yan Yan 0018, Elisabeth Oswald |
CF | 2 |
| 2019 | Constructing TI-Friendly Substitution Boxes Using Shift-Invariant Permutations
Arnab Roy 0005, Elisabeth Oswald |
CT-RSA | 3 |
| 2019 | Fault Attack Countermeasures for Error Samplers in Lattice-Based CryptographyabstractLattice-based cryptography is one of the leading candidates for NIST's post-quantum standardisation effort, providing efficient key encapsulation and signature schemes. Most of these schemes base their hardness on variants of LWE, and thus rely heavily on error samplers to provide necessary uncertainty by obfuscating computations on secret information. Because of this it is a clear and obvious target for side-channel analysis, with numerous types of attacks targeting this component to gain secret-key information. In order to bring potential lattice-based cryptographic standards to practical realisation, it is important to protect these modules from past and future fault and side-channel attacks. This paper proposes countermeasures that exploit the distributions expected from these error samples, that is either Gaussian or binomial, by using statistical tests to verify the samplers are operating properly. The novel countermeasures are designed to protect against all previous fault attacks on error samplers. We optimize hardware implementation of the proposed tests to avoid division and square root calculations, however, the countermeasure we propose is sufficiently generic to be suitable also for software. We measure the impact of these countermeasures on performance and area consumption on a Xilinx Artix-7 FPGA. Our countermeasure achieve promising performance while resulting in a minimal overhead. James Howe, Ayesha Khalid, Marco Martinoli, Francesco Regazzoni 0001, Elisabeth Oswald |
ISCAS | 5 |
| 2018 | Non-profiled Mask Recovery: The Impact of Independent Component Analysis
Elisabeth Oswald, Hua Chen 0011 |
CARDIS | 2 |
| 2018 | A Systematic Study of the Impact of Graphical Models on Inference-Based Attacks on AES
Joey Green, Arnab Roy 0005, Elisabeth Oswald |
CARDIS | 3 |
| 2018 | Two Sides of the Same Coin: Counting and Enumerating Keys Post Side-Channel Attacks Revisited
Daniel P. Martin 0001, Luke Mather, Elisabeth Oswald |
CT-RSA | 3 |
| 2018 | Exploring Potential 6LoWPAN Traffic Side Channels
Yan Yan 0018, Elisabeth Oswald, Theodore Tryfonas |
EWSN | 2 |
| 2018 | Assessing the Feasibility of Single Trace Power Analysis of Frodo
Joppe W. Bos, Simon Friedberger, Marco Martinoli, Elisabeth Oswald, Martijn Stam |
SAC | 4 |
| 2017 | Authenticated Encryption in the Face of Protocol and Side Channel Leakage
Guy Barwell, Daniel P. Martin 0001, Elisabeth Oswald, Martijn Stam |
ASIACRYPT (1) | 3 |
| 2017 | A Novel Use of Kernel Discriminant Analysis as a Higher-Order Side-Channel Distinguisher
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005 |
CARDIS | 3 |
| 2017 | Quantum Key Search with Side Channel Advice
Daniel P. Martin 0001, Ashley Montanaro, Elisabeth Oswald, Daniel James Shepherd |
SAC | 3 |
| 2017 | Categorising and Comparing Cluster-Based DPA Distinguishers
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005 |
SAC | 3 |
| 2017 | Towards Practical Tools for Side Channel Aware Software Engineering: 'Grey Box' Modelling for Instruction Leakages
David McCann, Elisabeth Oswald, Carolyn Whitnall |
USENIX Security Symposium | 2 |
| 2016 | Characterisation and Estimation of the Key Rank Distribution in the Context of Side Channel Evaluations
Daniel P. Martin 0001, Luke Mather, Elisabeth Oswald, Martijn Stam |
ASIACRYPT (1) | 3 |
| 2015 | Counting Keys in Parallel After a Side Channel Attack
Daniel P. Martin 0001, Jonathan F. O'Connell 0001, Elisabeth Oswald, Martijn Stam |
ASIACRYPT (2) | 3 |
| 2015 | Robust Profiling for DPA-Style Attacks
Carolyn Whitnall, Elisabeth Oswald |
CHES | 2 |
| 2015 | Reliable information extraction for single trace attacks
Valentina Banciu, Elisabeth Oswald, Carolyn Whitnall |
DATE | 2 |
| 2015 | A Leakage Resilient MAC
Daniel P. Martin 0001, Elisabeth Oswald, Martijn Stam, Marcin Wójcik |
IMACC | 2 |
| 2014 | Simulatable Leakage: Analysis, Pitfalls, and New Constructions
Jake Longo, Daniel P. Martin 0001, Elisabeth Oswald, Dan Page, Martijn Stam, Michael Tunstall |
ASIACRYPT (1) | 3 |
| 2014 | Multi-target DPA Attacks: Pushing DPA Beyond the Limits of a Desktop Computer
Luke Mather, Elisabeth Oswald, Carolyn Whitnall |
ASIACRYPT (1) | 2 |
| 2014 | The Myth of Generic DPA...and the Magic of Learning
Carolyn Whitnall, Elisabeth Oswald, François-Xavier Standaert |
CT-RSA | 2 |
| 2013 | Does My Device Leak Information? An a priori Statistical Power Analysis of Leakage Detection Tests
Luke Mather, Elisabeth Oswald, Joe Bandenburg, Marcin Wójcik |
ASIACRYPT (1) | 2 |
| 2013 | Profiling DPA: Efficacy and Efficiency Trade-Offs
Carolyn Whitnall, Elisabeth Oswald |
CHES | 2 |
| 2013 | Masking Tables - An Underestimated Security Risk
Michael Tunstall, Carolyn Whitnall, Elisabeth Oswald |
FSE | 3 |
| 2012 | Compiler Assisted Masking
Andrew Moss, Elisabeth Oswald, Dan Page, Michael Tunstall |
CHES | 2 |
| 2011 | An Exploration of the Kolmogorov-Smirnov Test as a Competitor to Mutual Information Analysis
Carolyn Whitnall, Elisabeth Oswald, Luke Mather |
CARDIS | 2 |
| 2011 | A Comprehensive Evaluation of Mutual Information Analysis Using a Fair Evaluation Framework
Carolyn Whitnall, Elisabeth Oswald |
CRYPTO | 2 |
| 2011 | One for all - all for one: unifying standard differential power analysis attacksabstractIn this study, the authors examine the relationship between and the efficiency of different approaches to standard (univariate) differential power analysis (DPA) attacks. The authors first show that, when fed with the same assumptions about the target device (i.e. with the same leakage model), the most popular approaches such as using a distance-of-means test, correlation analysis and Bayes attacks are essentially equivalent in this setting. Differences observed in practice are not because of differences in the statistical tests but because of statistical artefacts. Then, the authors establish a link between the correlation coefficient and the conditional entropy in side-channel attacks. In a first-order attack scenario, this relationship allows linking currently used metrics to evaluate standard DPA attacks (such as the number of power traces needed to perform a key recovery) with an information theoretic metric (the mutual information). The authors results show that in the practical scenario defined formally in this study, both measures are equally suitable to compare devices with respect to their susceptibility to DPA attacks. Together with observations regarding key and algorithm independence the authors consequently extend theoretical strategies for the sound evaluation of leaking devices towards the practice of side-channel attacks. Stefan Mangard, Elisabeth Oswald, François-Xavier Standaert |
IET Inf. Secur. | 2 |
| 2010 | The World Is Not Enough: Another Look on Second-Order DPA
François-Xavier Standaert, Nicolas Veyrat-Charvillon, Elisabeth Oswald, Benedikt Gierlichs, Marcel Medwed, Markus Kasper, Stefan Mangard |
ASIACRYPT | 3 |
| 2008 | Randomised representationsabstractThe authors show that a number of existing methods for side-channel defence are essentially the same techniques presented in different contexts. By abstracting this technique, they present necessary conditions which need to be satisfied for it to be successful in preventing side-channel analysis. They also show that concrete application of the technique via randomised field representation produces more efficient implementations than application of the technique via randomised projective coordinates. Nigel P. Smart, Elisabeth Oswald, Dan Page |
IET Inf. Secur. | 2 |
| 2007 | Template Attacks on Masking - Resistance Is Futile
Elisabeth Oswald, Stefan Mangard |
CT-RSA | 1 |
| 2006 | An AES Smart Card Implementation Resistant to Power Analysis Attacks
Christoph Herbst, Elisabeth Oswald, Stefan Mangard |
ACNS | 2 |
| 2006 | Practical Second-Order DPA Attacks for Masked Smart Card Implementations of Block Ciphers
Elisabeth Oswald, Stefan Mangard, Christoph Herbst, Stefan Tillich |
CT-RSA | 1 |
| 2006 | Searching for Differential Paths in MD4
Martin Schläffer, Elisabeth Oswald |
FSE | 2 |
| 2005 | Successfully Attacking Masked AES Hardware Implementations
Stefan Mangard, Norbert Pramstaller, Elisabeth Oswald |
CHES | 3 |
| 2005 | Update on SHA-1
Vincent Rijmen, Elisabeth Oswald |
CT-RSA | 2 |
| 2005 | A Side-Channel Analysis Resistant Description of the AES S-Box
Elisabeth Oswald, Stefan Mangard, Norbert Pramstaller, Vincent Rijmen |
FSE | 1 |
| 2003 | Power-Analysis Attacks on an FPGA - First Experimental Results
Siddika Berna Örs Yalçin, Elisabeth Oswald, Bart Preneel |
CHES | 2 |
| 2002 | Enhancing Simple Power-Analysis Attacks on Elliptic Curve Cryptosystems
Elisabeth Oswald |
CHES | 1 |
| 2002 | An ASIC Implementation of the AES SBoxes
Johannes Wolkerstorfer, Elisabeth Oswald, Mario Lamberger |
CT-RSA | 2 |
| 2001 | Randomized Addition-Subtraction Chains as a Countermeasure against Power Attacks
Elisabeth Oswald, Manfred Josef Aigner |
CHES | 1 |