Elisabeth Oswald

dblp:48/4127 · DBLP profile ↗
← Back
49ranked-venue papers
5as first author
7since 2021 · last 2024
0000-0001-7502-3184ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 45 · 5 first-author · 7 since 2021Systems, architecture and hardware · 3Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2024 Leakage Certification Made Simple
Aakash Chowdhury, Arnab Roy 0005, Carlo Brunetta, Elisabeth Oswald
CRYPTO (6)4
2024 A Novel Framework for Explainable Leakage Assessment
Elisabeth Oswald
EUROCRYPT (3)2
2022 Comparing Key Rank Estimation Methods
Rebecca Hay, Luke Mather, Elisabeth Oswald
CARDIS3
2022 A Novel Completeness Test for Leakage Models and Its Application to Side Channel Attacks and Responsibly Engineered Simulators
Elisabeth Oswald
EUROCRYPT (3)2
2022 Towards Micro-architectural Leakage Simulators: Reverse Engineering Micro-architectural Leakage Features Is Practical
Elisabeth Oswald, Dan Page
EUROCRYPT (3)2
2021 An Analytic Attack against ARX Addition Exploiting Standard Side-channel Leakage
abstract
In the last few years a new design paradigm, the so-called ARX (modular addition, rotation, exclusive-or) ciphers, have gained popularity in part because of their non-linear operation’s seemingly ‘inherent resilience’ against Differential Power Analysis (DPA) Attacks: the non-linear modular addition is not only known to be a poor target for DPA attacks, but also the computational complexity of DPA-style attacks grows exponentially with the operand size and thus DPA-style attacks quickly become practically infeasible. We however propose a novel DPA-style attack strategy that scales linearly with respect to the operand size in the chosen-message attack setting.
Yan Yan 0018, Elisabeth Oswald, Srinivas Vivek 0001
ICISSP2
2021 Neyman's Smoothness Test: A Trade-Off Between Moment-Based and Distribution-Based Leakage Detections
Elisabeth Oswald, Yan Yan 0018
IEEE Trans. Inf. Forensics Secur.2
2019 A Critical Analysis of ISO 17825 ('Testing Methods for the Mitigation of Non-invasive Attack Classes Against Cryptographic Modules')
Carolyn Whitnall, Elisabeth Oswald
ASIACRYPT (3)2
2019 Examining the practical side channel resilience of ARX-boxes
abstract
Implementations of ARX ciphers are hoped to have some intrinsic side channel resilience owing to the specific choice of cipher components: modular addition (A), rotation (R) and exclusive-or (X). Previous work has contributed to this understanding by developing theory regarding the side channel resilience of components (pioneered by the early works of Prouff) as well as some more recent practical investigations by Biryukov et al. that focused on lightweight cipher constructions. We add to this work by specifically studying ARX-boxes both mathematically as well as practically. Our results show that previous works' reliance on the simplistic assumption that intermediates independently leak (their Hamming weight) has led to the incorrect conclusion that the modular addition is necessarily the best target and that ARX constructions are therefore harder to attack in practice: we show that on an ARM M0, the best practical target is the exclusive or and attacks succeed with only tens of traces.
Yan Yan 0018, Elisabeth Oswald
CF2
2019 Constructing TI-Friendly Substitution Boxes Using Shift-Invariant Permutations
Arnab Roy 0005, Elisabeth Oswald
CT-RSA3
2019 Fault Attack Countermeasures for Error Samplers in Lattice-Based Cryptography
abstract
Lattice-based cryptography is one of the leading candidates for NIST's post-quantum standardisation effort, providing efficient key encapsulation and signature schemes. Most of these schemes base their hardness on variants of LWE, and thus rely heavily on error samplers to provide necessary uncertainty by obfuscating computations on secret information. Because of this it is a clear and obvious target for side-channel analysis, with numerous types of attacks targeting this component to gain secret-key information. In order to bring potential lattice-based cryptographic standards to practical realisation, it is important to protect these modules from past and future fault and side-channel attacks. This paper proposes countermeasures that exploit the distributions expected from these error samples, that is either Gaussian or binomial, by using statistical tests to verify the samplers are operating properly. The novel countermeasures are designed to protect against all previous fault attacks on error samplers. We optimize hardware implementation of the proposed tests to avoid division and square root calculations, however, the countermeasure we propose is sufficiently generic to be suitable also for software. We measure the impact of these countermeasures on performance and area consumption on a Xilinx Artix-7 FPGA. Our countermeasure achieve promising performance while resulting in a minimal overhead.
James Howe, Ayesha Khalid, Marco Martinoli, Francesco Regazzoni 0001, Elisabeth Oswald
ISCAS5
2018 Non-profiled Mask Recovery: The Impact of Independent Component Analysis
Elisabeth Oswald, Hua Chen 0011
CARDIS2
2018 A Systematic Study of the Impact of Graphical Models on Inference-Based Attacks on AES
Joey Green, Arnab Roy 0005, Elisabeth Oswald
CARDIS3
2018 Two Sides of the Same Coin: Counting and Enumerating Keys Post Side-Channel Attacks Revisited
Daniel P. Martin 0001, Luke Mather, Elisabeth Oswald
CT-RSA3
2018 Exploring Potential 6LoWPAN Traffic Side Channels
Yan Yan 0018, Elisabeth Oswald, Theodore Tryfonas
EWSN2
2018 Assessing the Feasibility of Single Trace Power Analysis of Frodo
Joppe W. Bos, Simon Friedberger, Marco Martinoli, Elisabeth Oswald, Martijn Stam
SAC4
2017 Authenticated Encryption in the Face of Protocol and Side Channel Leakage
Guy Barwell, Daniel P. Martin 0001, Elisabeth Oswald, Martijn Stam
ASIACRYPT (1)3
2017 A Novel Use of Kernel Discriminant Analysis as a Higher-Order Side-Channel Distinguisher
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005
CARDIS3
2017 Quantum Key Search with Side Channel Advice
Daniel P. Martin 0001, Ashley Montanaro, Elisabeth Oswald, Daniel James Shepherd
SAC3
2017 Categorising and Comparing Cluster-Based DPA Distinguishers
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005
SAC3
2017 Towards Practical Tools for Side Channel Aware Software Engineering: 'Grey Box' Modelling for Instruction Leakages
David McCann, Elisabeth Oswald, Carolyn Whitnall
USENIX Security Symposium2
2016 Characterisation and Estimation of the Key Rank Distribution in the Context of Side Channel Evaluations
Daniel P. Martin 0001, Luke Mather, Elisabeth Oswald, Martijn Stam
ASIACRYPT (1)3
2015 Counting Keys in Parallel After a Side Channel Attack
Daniel P. Martin 0001, Jonathan F. O'Connell 0001, Elisabeth Oswald, Martijn Stam
ASIACRYPT (2)3
2015 Robust Profiling for DPA-Style Attacks
Carolyn Whitnall, Elisabeth Oswald
CHES2
2015 Reliable information extraction for single trace attacks
Valentina Banciu, Elisabeth Oswald, Carolyn Whitnall
DATE2
2015 A Leakage Resilient MAC
Daniel P. Martin 0001, Elisabeth Oswald, Martijn Stam, Marcin Wójcik
IMACC2
2014 Simulatable Leakage: Analysis, Pitfalls, and New Constructions
Jake Longo, Daniel P. Martin 0001, Elisabeth Oswald, Dan Page, Martijn Stam, Michael Tunstall
ASIACRYPT (1)3
2014 Multi-target DPA Attacks: Pushing DPA Beyond the Limits of a Desktop Computer
Luke Mather, Elisabeth Oswald, Carolyn Whitnall
ASIACRYPT (1)2
2014 The Myth of Generic DPA...and the Magic of Learning
Carolyn Whitnall, Elisabeth Oswald, François-Xavier Standaert
CT-RSA2
2013 Does My Device Leak Information? An a priori Statistical Power Analysis of Leakage Detection Tests
Luke Mather, Elisabeth Oswald, Joe Bandenburg, Marcin Wójcik
ASIACRYPT (1)2
2013 Profiling DPA: Efficacy and Efficiency Trade-Offs
Carolyn Whitnall, Elisabeth Oswald
CHES2
2013 Masking Tables - An Underestimated Security Risk
Michael Tunstall, Carolyn Whitnall, Elisabeth Oswald
FSE3
2012 Compiler Assisted Masking
Andrew Moss, Elisabeth Oswald, Dan Page, Michael Tunstall
CHES2
2011 An Exploration of the Kolmogorov-Smirnov Test as a Competitor to Mutual Information Analysis
Carolyn Whitnall, Elisabeth Oswald, Luke Mather
CARDIS2
2011 A Comprehensive Evaluation of Mutual Information Analysis Using a Fair Evaluation Framework
Carolyn Whitnall, Elisabeth Oswald
CRYPTO2
2011 One for all - all for one: unifying standard differential power analysis attacks
abstract
In this study, the authors examine the relationship between and the efficiency of different approaches to standard (univariate) differential power analysis (DPA) attacks. The authors first show that, when fed with the same assumptions about the target device (i.e. with the same leakage model), the most popular approaches such as using a distance-of-means test, correlation analysis and Bayes attacks are essentially equivalent in this setting. Differences observed in practice are not because of differences in the statistical tests but because of statistical artefacts. Then, the authors establish a link between the correlation coefficient and the conditional entropy in side-channel attacks. In a first-order attack scenario, this relationship allows linking currently used metrics to evaluate standard DPA attacks (such as the number of power traces needed to perform a key recovery) with an information theoretic metric (the mutual information). The authors results show that in the practical scenario defined formally in this study, both measures are equally suitable to compare devices with respect to their susceptibility to DPA attacks. Together with observations regarding key and algorithm independence the authors consequently extend theoretical strategies for the sound evaluation of leaking devices towards the practice of side-channel attacks.
Stefan Mangard, Elisabeth Oswald, François-Xavier Standaert
IET Inf. Secur.2
2010 The World Is Not Enough: Another Look on Second-Order DPA
François-Xavier Standaert, Nicolas Veyrat-Charvillon, Elisabeth Oswald, Benedikt Gierlichs, Marcel Medwed, Markus Kasper, Stefan Mangard
ASIACRYPT3
2008 Randomised representations
abstract
The authors show that a number of existing methods for side-channel defence are essentially the same techniques presented in different contexts. By abstracting this technique, they present necessary conditions which need to be satisfied for it to be successful in preventing side-channel analysis. They also show that concrete application of the technique via randomised field representation produces more efficient implementations than application of the technique via randomised projective coordinates.
Nigel P. Smart, Elisabeth Oswald, Dan Page
IET Inf. Secur.2
2007 Template Attacks on Masking - Resistance Is Futile
Elisabeth Oswald, Stefan Mangard
CT-RSA1
2006 An AES Smart Card Implementation Resistant to Power Analysis Attacks
Christoph Herbst, Elisabeth Oswald, Stefan Mangard
ACNS2
2006 Practical Second-Order DPA Attacks for Masked Smart Card Implementations of Block Ciphers
Elisabeth Oswald, Stefan Mangard, Christoph Herbst, Stefan Tillich
CT-RSA1
2006 Searching for Differential Paths in MD4
Martin Schläffer, Elisabeth Oswald
FSE2
2005 Successfully Attacking Masked AES Hardware Implementations
Stefan Mangard, Norbert Pramstaller, Elisabeth Oswald
CHES3
2005 Update on SHA-1
Vincent Rijmen, Elisabeth Oswald
CT-RSA2
2005 A Side-Channel Analysis Resistant Description of the AES S-Box
Elisabeth Oswald, Stefan Mangard, Norbert Pramstaller, Vincent Rijmen
FSE1
2003 Power-Analysis Attacks on an FPGA - First Experimental Results
Siddika Berna Örs Yalçin, Elisabeth Oswald, Bart Preneel
CHES2
2002 Enhancing Simple Power-Analysis Attacks on Elliptic Curve Cryptosystems
Elisabeth Oswald
CHES1
2002 An ASIC Implementation of the AES SBoxes
Johannes Wolkerstorfer, Elisabeth Oswald, Mario Lamberger
CT-RSA2
2001 Randomized Addition-Subtraction Chains as a Countermeasure against Power Attacks
Elisabeth Oswald, Manfred Josef Aigner
CHES1