EDBT 2026 Demo / reviewers in the wild / expert
Marc Stöttinger
dblp:66/7913
· DBLP profile ↗
16ranked-venue papers
1as first author
6since 2021 · last 2025
0000-0001-7970-3945ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 2 since 2021Security and privacy · 5 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Credential-Based Pseudonym Generation for Programming Process Data CollectionabstractTools for collecting fine-grained programming process data may use pseudonyms when linking the data to students to increase privacy. However, some of these tools allow researchers or instructors to access the pseudonym mapping. Others do not sufficiently consider the students' device usage, which may introduce bias when multiple devices are used, or when devices are reset or replaced. We propose a novel technique that addresses these limitations by generating pseudonyms using login credentials to university accounts. In addition, we provide results on a survey about device usage in introductory programming courses. These suggest that the vast majority of our students use more than one device and that the majority reset or replace their device at least once. We conclude that our technique is of considerable interest, particularly in contexts where compliance with legal or ethical regulations is required. Björn Fischer, Marc Stöttinger, Berit Barthelmes, Sven Eric Panitz, Ralf Dörner 0001 |
ITiCSE (1) | 2 |
| 2024 | Evaluating an Open-Source Hardware Approach from HDL to GDS for a Security Chip Design - a Review of the Final Stage of Project HEPabstractThe project “Hardening the value chain through open-source, trustworthy EDA tools and processors (HEP)” uses open-source, free components and tools for the production of a prototypical security chip. A design flow using only free and open tools from the abstract description in SpinalHDL via OpenROAD down to the GDS-file for tape-out has been established, and first ASICs produced at IHP. The prototypical hardware security module (HSM) produced in this way provides, among other things, a processor based on VexRiscv, a cryptographic accelerator and masking of cryptographic keys. The open development tools used in the process were integrated into a common environment and expanded to include missing functionality. Subsequently, the whole tool chain and its peripherals are wrapped into a new Nyx container. The easy accessibility of the used process significantly reduces the learning curve for chip design. Additionally, we provide tools for formal verification and masking against side-channel attacks in our design flow. Interest in the results of project HEP has been shown in publications in which industrial partners participated, such as Elektrobit, Hensoldt Cyber, IAV, Secure-IC and Swissbit Germany. Tim Henkes, Steffen Reith, Marc Stöttinger, Norbert Herfurth, Goran Panic, Julian Wälde, Fabian Buschkowski, Pascal Sasdrich, Christoph Lüth, Milan Funck, Tuba Kiyan, Arnd Weber, Detlef Boeck, René Rathfelder, Torsten Grawunder |
DATE | 3 |
| 2023 | Voronoi Based Multidimensional Parameter Optimization for Fault Injection AttacksabstractFault injection attacks are used to overcome security mechanisms of embedded devices. While this can be done with low-cost equipment for simple targets and attack types, more sophisticated targets require a higher precision and better equipment. Precise parameters can also help to increase reliability and thus minimize the probability of damage, which is essential for forensic data extraction. In this work, we present a novel iterative method for finding suitable parameter combinations for fault injection attacks based on Voronoi tessellation, an algorithm for partitioning a space into cells based on the given input points. This method can reduce the number of parameter combinations to be tested before finding a successful combination, while preserving optimal candidate solutions. We show that the method can work with an arbitrary number of parameters and arbitrary result shapes. In addition, we show some algorithmic refinements that can help reduce computation time for high-dimensional parameter spaces. This allows not only the optimization of parameter-intensive attack types, but also the inclusion of non-essential parameters to further improve the reliability of the results. Simulation results show the potential of the proposed method, especially when it comes to minimizing the number of resets performed. Likewise, we discuss the problems encountered when applying this method to sensitive real devices and propose solutions to overcome them. Marius Eggert, Marc Stöttinger |
FDTC | 2 |
| 2022 | Patient Zero & Patient Six: Zero-Value and Correlation Attacks on CSIDH and SIKE
Fabio Campos, Michael Meyer 0001, Krijn Reijnders, Marc Stöttinger |
SAC | 4 |
| 2021 | A Fault Resistant AES via Input-Output Differential Tables with DPA AwarenessabstractNowadays, hardware-based AES faces more than one type of Side-Channel-Attacks (SCA), such as the Differential Power Analysis (DPA) attack and the Differential Fault Analysis (DFA) attack. However, most of the current DFA-resistant implementations of AES only focus on resisting the DFA attack but with minimal concurrent considerations on their DPA resistance capability. In this paper, we propose a fault resistant AES with DPA awareness. First, we evaluate the DPA resistance for different implementation architectures of AES before the implementation with S-Box over GF(24)2is selected. Second, we evaluate the DPA resistance for different fault detection architectures before the concurrent fault detection method is selected. Third, we propose a novel fault resistant technique for AES using input-output differential tables over GF(24)2. We have performed tests based on Partial Guessing Entropy (PGE) to evaluate the DPA resistance for the existing DFA-resistant designs and our proposed design. Experimental results prove that our design has a slower convergence speed (around 33%) with a 100% fault coverage rate and less area than the existing countermeasure designs for fault injection. Results also show that the fault detection designs weaken their DPA resistance, which indicates the importance of co-design of DFA and DPA to achieve less power information leakage. Yi Estelle Wang, Marc Stöttinger, Yajun Ha |
ISCAS | 2 |
| 2021 | Verifying Post-Quantum Signatures in 8 kB of RAM
Andreas Hülsing, Matthias J. Kannwischer, Juliane Krämer, Tanja Lange 0001, Marc Stöttinger, Elisabeth Waitz, Thom Wiggers, Bo-Yin Yang |
PQCrypto | 6 |
| 2020 | Trouble at the CSIDH: Protecting CSIDH with Dummy-Operations Against Fault Injection AttacksabstractThe isogeny-based scheme CSIDH is a promising candidate for quantum-resistant static-static key exchanges with very small public keys, but is inherently difficult to implement in constant time. In the current literature, there are two directions for constant-time implementations: algorithms containing dummy computations and dummy-free algorithms. While the dummy-free implementations come with a 2x slowdown, they offer by design more resistance against fault attacks. In this work, we evaluate how practical fault injection attacks are on the constant-time implementations containing dummy calculations. We present three different fault attacker models. We evaluate our fault models both in simulations and in practical attacks. We then present novel countermeasures to protect the dummy isogeny computations against fault injections. The implemented countermeasures result in an overhead of 7% on the Cortex-M4 target, falling well short of the 2x slowdown for dummy-less variants. Fabio Campos, Matthias J. Kannwischer, Michael Meyer 0001, Hiroshi Onuki, Marc Stöttinger |
FDTC | 5 |
| 2019 | Security in Autonomous SystemsabstractAutonomous systems promise solutions to a wide range of technical and societal problems, and their use appears especially attractive in safety-critical domains, like transportation or factory automation. This paper focuses on an underestimated aspect of autonomous systems: their security implications. Many approaches to design traditional secure systems do not readily transfer to autonomous systems, due to their high complexity and exposure to a broad spectrum of threats. Moreover, autonomous systems are often designed to be extremely long-living, and any security solutions should anticipate future threats to some extent. This paper starts with an overview of security threats applicable to autonomous systems and today's countermeasures to address these threats. Then, two representative techniques are elucidated in more detail: the use of post-quantum cryptography to achieve secure communication, and remote attestation as one essential building block for platform security. Stefan Katzenbeisser 0001, Ilia Polian, Francesco Regazzoni 0001, Marc Stöttinger |
ETS | 4 |
| 2013 | TROJANUS: An ultra-lightweight side-channel leakage generator for FPGAsabstractIn this article we present a new side-channel building block for FPGAs, which, akin to the old Roman god of Janus, has two contradictory faces: as a watermarking tool, it allows to uniquely identify IP cores by adding a single slice to the design; as a Trojan Side-Channel (TSC) it can potentially leak an entire encryption key within only one trace and without the knowledge of either the plaintext or the ciphertext. We practically verify TROJANUS' feasibility by embedding it as a TSC into a lightweight FPGA implementation of PRESENT. Besides, we investigate the leakage behavior of FPGAs in more detail and present a new pre-processing technique, which can potentially increase the correlation coefficient of DPA attacks. Sebastian Kutzner, Axel Poschmann, Marc Stöttinger |
FPT | 3 |
| 2012 | A New Difference Method for Side-Channel Analysis with High-Dimensional Leakage Models
Annelie Heuser, Michael Kasper, Werner Schindler, Marc Stöttinger |
CT-RSA | 4 |
| 2012 | Revealing side-channel issues of complex circuits by enhanced leakage modelsabstractIn the light of implementation attacks a better understanding of complex circuits of security sensitive applications is an important issue. Appropriate evaluation tools and metrics are required to understand the origin of implementation flaws within the design process. The selected leakage model has significant influence on the reliability of evaluation results concerning the side-channel resistance of a cryptographic implementation. In this contribution we introduce methods, which determine the accuracy of the leakage characterization and allow to quantify the signal-to-noise ratio. This allows a quantitative assessment of the side-channel resistance of an implementation without launching an attack. We validate the conclusions drawn from our new methods by real attacks and obtain similar results. Compared to the commonly used Hamming Distance model in our experiments enhanced leakage models increased the attack efficiency by up to 500%. Annelie Heuser, Werner Schindler, Marc Stöttinger |
DATE | 3 |
| 2012 | Side channel analysis of the SHA-3 finalistsabstractAt the cutting edge of today's security research and development, the SHA-3 competition evaluates a new secure hashing standard in succession to SHA-2. The five remaining candidates of the SHA-3 competition are BLAKE, Grøstl, JH, Keccak, and Skein. While the main focus was on the algorithmic security of the candidates, a side channel analysis has only been performed for BLAKE and Grøstl [1]. In order to equally evaluate all candidates, we identify side channel attacks on JH-MAC, Keccak-MAC, and Skein-MAC and demonstrate the applicability of the attacks by attacking their respective reference implementation. Additionally, we revisit the side channel analysis of Grøstl and introduce a profiling based side channel attack, which emphasizes the importance of side channel resistant hash functions by recovering the input to the hash function using only the measured power consumption. Michael Zohner, Michael Kasper, Marc Stöttinger, Sorin A. Huss |
DATE | 3 |
| 2012 | Side-channel resistant AES architecture utilizing randomized composite field representationsabstractIn the recent decade methods and applications of side-channel analysis gain more and more attention for industry applications as well as in academia. The research on counter-measures against power analysis attacks on embedded devices with security-sensitive applications turned out to be a challenging area. Very often the proposed countermeasures consume to much resources in order to increase the barrier to hinder a successful attack. The presented scheme uses randomized isomorphisms of the algebraic construction of the S-box and thus increases the resistance at a very low cost in terms of hardware resources. The resource utilization of the proposed masking scheme is smaller than a standard Boolean masking scheme for FPGAs. Our conducted experiments on the FPGA evaluation platform SASEBO GII demonstrates that we improved the resistance against the common DPA attack about 100 times compared to the non-hardened AES-128 version. Bernhard Jungk, Marc Stöttinger, Jan Gampe, Steffen Reith, Sorin A. Huss |
FPT | 2 |
| 2011 | How a Symmetry Metric Assists Side-Channel Evaluation - A Novel Model Verification Method for Power AnalysisabstractSide-channel analysis has become an important field of research for the semiconductor industry and for the academic sector as well. Of particular interest is constructive side-channel analysis as it supports a target-oriented associated design process. The main goal is to increase the side-channel resistance of cryptographic implementations within the design phase by a combination of advanced stochastic methods with design methods, tools, and countermeasures. In this contribution we present a new enhanced tool that utilizes symmetry properties to assist the side-channel evaluation of cryptographic implementations. This technique applies a symmetry metric, which is introduced as an engineering tool to verify the suitability of the leakage model in the evaluation phase of security-sensitive designs. Additionally, this approach also supports the designer in the selection of appropriate time instants. Annelie Heuser, Michael Kasper, Werner Schindler, Marc Stöttinger |
DSD | 4 |
| 2010 | Side-Channel Resistance Evaluation of a Neural Network Based Lightweight Cryptography SchemeabstractSide-channel attacks have changed the design of secure cryptographic systems dramatically. Several published attacks on implementations of well known algorithms such as, e.g., AES, show the need to consider these aspects to build more resistant cryptographic systems. On the other hand, with the increasing use of cryptography in embedded systems a significant demand exists for cryptographic algorithms that are both resource-and power-efficient. These can be either modified existing or completely new ones. One of the candidates for such a new algorithm is the Tree Parity Machine Public Key Exchange, an algorithm based on artificial neural networks. While it has been evaluated in a number of practical applications in the past, its side-channel resistance has not been examined yet. We would like to close this gap and present a side-channel attack strategy as well as results gathered from measurements made on a real implementation. Marc Stöttinger, Sorin A. Huss, Sascha Mühlbach, Andreas Koch 0001 |
EUC | 1 |
| 2010 | A stochastic method for security evaluation of cryptographic FPGA implementationsabstractWe introduce a stochastic method for the security evaluation and dynamic power consumption analysis in the context of side-channel analysis. This method allows to estimate data-dependent power consumption induced by secret parameters, e.g. a cryptographic key, which may be exploited in power attacks. In particular, IP-cores for security applications on FPGAs have to be made secure against these attacks. We show that the same stochastic methods provide FPGA designers constructive feedback on the information leakage of the design. Applied as a constructive tool these stochastic methods allow the designer to quantify the side-channel resistance and weaknesses of the IP-core design, a feature which supports the design of secure and side-channel resistant implementations, especially on FPGAs. Michael Kasper, Werner Schindler, Marc Stöttinger |
FPT | 3 |