Martin Novotný

dblp:70/1524 · DBLP profile ↗
← Back
26ranked-venue papers
3as first author
5since 2021 · last 2024
0000-0001-6446-7257ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 25 · 3 first-author · 5 since 2021Security and privacy · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2024 How Primitive but How Effective: Fault-Injection Attack on Cryptographic Accelerator of Microchip CEC 1702 Microcontroller
abstract
Fault injection attacks pose a substantial threat to the security of digital systems, compromising integrity and exposing vulnerabilities. This article explores fault injection techniques, specifically voltage glitching, within the context of Lenstra's attack, which is an extension of the Bellcore attack, on RSA-CRT, which has existed for decades. The focus is on the cryptographic accelerator of the Microchip CEC 1702 microcontroller. The study employs the Chip Whisperer toolkit to perform fault injection attacks on both software and hardware implementations of RSA-CRT. Results reveal vulnerabilities in the commercially produced Microchip CEC 1702 microcontroller, highlighting potential security risks associated with fault injection attacks.
Lukás Danêk, Martin Novotný
DSD2
2022 Versatile Hardware Framework for Elliptic Curve Cryptography
abstract
We propose versatile hardware framework for ECC. The framework supports arithmetic operations over P-256, Ed25519 and Curve25519 curves, enabling easy implementation of various ECC algorithms. Framework finds its application area e.g. in FIDO2 attestation or in nowadays rapidly expanding field of hardware wallets. As the design is intended to be ASIC-ready, we designed it to be area efficient. Hardware units are reused for calculations in several finite fields, and some of them are superior to previously designed circuits in terms of time-area product. The framework implements several attack countermeasures. It enables implementation of certain countermeasures even in later stages of design. The design was validated on SoC FPGA.
Vít Masek, Martin Novotný
DDECS2
2022 Implementation of the Rainbow signature scheme on SoC FPGA
abstract
Thanks to the research progress, quantum computers are slowly becoming a reality and some companies already have their working prototypes. While this is great news for some, it also means that some of the encryption algorithms used today will be rendered unsafe and obsolete. Due to this fact, NIST (US National Institute of Standards and Technology) has been running a standardization process for quantum-resistant key exchange algorithms and digital signatures. One of these is Rainbow—a signature scheme based on the fact that solving a set of random multivariate quadratic system is an NP-hard problem. This work aims to develop an AXI-connected accelerator for the Rainbow signature scheme, specifically the Ia variant. The accelerator is highly parameterizable, allowing to choose the data bus width, directly affecting the FPGA area used. It is also possible to swap components to use the design for other variants of Rainbow. This allows for a comprehensive experimental evaluation of our design. The developed accelerator provides significant speedup compared to CPU-based computation. This paper includes detailed documentation of the design as well as performance and resource utilisation evaluation.
Tomás Preucil, Petr Socha, Martin Novotný
DSD3
2021 Side-channel attack on Rainbow post-quantum signature
abstract
Rainbow, a layered multivariate quadratic digital signature, is a candidate for standardization in a competition-like process organized by NIST. In this paper, we present a CPA side-channel attack on the submitted 32-bit reference implementation. We evaluate the attack on an STM32F3 ARM microcontroller, successfully revealing the full private key. Furthermore, we propose a simple masking scheme with minimum overhead.
David Pokorný, Petr Socha, Martin Novotný
DATE3
2021 Secure and dependable: Area-efficient masked and fault-tolerant architectures
abstract
Masking is a powerful instrument for protecting cryptographic devices against side-channel analysis. Multiple masking schemes were introduced providing provable security against attacks of arbitrary order even in the presence of glitches. When a device is a part of some safety-critical system, it needs to meet dependability requirements; therefore, it should be protected against spontaneously occurring faults. Existing commonly used fault-tolerance architectures involve high area overhead as so as the masking schemes do. In this paper, we propose architectures meeting dependability properties of simple modular-redundancy schemes and SCA resistance of masking schemes, but decreasing the area overhead utilizing the randomness involved in the masking schemes.We compare our Masked Duplex architecture with Triple Modular Redundancy. While using one less redundant module, our architecture saves around 20% of the area in comparison with TMR in the case of Threshold Implementation of PRESENT cipher, promising more savings for more complex cryptographic schemes.
Vojtech Miskovský, Hana Kubátová, Martin Novotný
DSD3
2020 Novel Dummy Rounds Schemes as a DPA Countermeasure in PRESENT Cipher
abstract
The Dummy Rounds Side-Channel Attacks countermeasure scheme for digital design has been proposed in earlier work. Its experimental evaluation and analysis revealed weaknesses that resulted in the proposal of an enhanced Dummy Rounds scheme. In this paper, we present the implementation of the proposed enhancement of Dummy Rounds scheme in PRESENT cipher and provide its experimental evaluation using Welch's t-test. We further propose several novel modifications of Dummy Rounds scheme as a solution to other security problems we have encountered. Novel Dummy Rounds scheme, namely its modifications proposed in this paper, are superior to earlier proposed schemes in terms of side-channel leakage prevention.
Petr Moucha, Stanislav Jerabek, Martin Novotný
DDECS3
2020 Novel Controller for Dummy Rounds Scheme DPA Countermeasure
abstract
In our previous work, we developed the Dummy Rounds countermeasure to protect the hardware design against side-channel attacks. The scheme employs hiding in time and hiding in consumption. After several improvements of the data path, the leakage has been minimized significantly. In this paper, we present the enhancement of the Dummy Rounds controller. This enhancement enables further reduction of the leakage. We tested the method on PRESENT cipher implemented in the Sakura-G board. The design was evaluated using Welch's t-test.
Petr Moucha, Stanislav Jerabek, Martin Novotný
DSD3
2020 Towards High-Level Synthesis of Polymorphic Side-Channel Countermeasures
abstract
Side-channel attacks pose a severe threat to both software and hardware cryptographic implementations. Current literature presents various countermeasures against these kinds of attacks, based on approaches such as hiding or masking, implemented either in software, or on register-transfer or gate-level in hardware. However, emerging trends in hardware design lean towards a system-level approach, allowing for faster, less errorprone, design process, an efficient hardware/software co-design, or sophisticated validation, verification, and (co)simulation strategies. In this paper, we propose a Boolean masking scheme suitable for high-level synthesis. We implement a protected PRESENT encryption in C language, utilizing the concept of dynamic logic reconfiguration, synthesize it for Xilinx Artix 7 FPGA, and we compare our results regarding clock cycle latency and area utilization. We evaluate the effectiveness of proposed countermeasures using specific t-test leakage assessment methodology. We show that our high-level synthesis implementation successfully conceals the side-channel leakage while maintaining reasonable area and latency overhead.
Petr Socha, Martin Novotný
DSD2
2019 Dynamic Logic Reconfiguration Based Side-Channel Protection of AES and Serpent
abstract
Dynamic logic reconfiguration is a concept which allows for efficient on-the-fly modifications of combinational circuit behaviour in both ASIC and FPGA devices. The reconfiguration of Boolean functions is achieved by modification of their generators (e.g. shift register-based look-up tables) and it can be controlled from within the chip, without the necessity of any external intervention. This hardware polymorphism can be utilized for the implementation of side-channel attack countermeasures, as demonstrated by Sasdrich et al. for the lightweight cipher PRESENT. In this work we adopt these countermeasures to two of the AES finalists, namely Rijndael and Serpent. Just like PRESENT, both Rijndael and Serpent are block ciphers based on a substitution-permutation network. We describe the countermeasures and adjustments necessary to protect these ciphers using the resources available in modern Xilinx FPGAs. We describe our VHDL implementations and evaluate the side-channel leakage and effectiveness of different countermeasure combinations using a methodology based on Welch's t-test. We did not detect any significant leakage from the fully protected versions of our implementations. We show that the countermeasures proposed by Sasdrich et al. are, with some modifications compared to the protected PRESENT implementation, successfully applicable to AES and Serpent.
Petr Socha, Jan Brejník, Stanislav Jerabek, Martin Novotný, Nele Mentens
DSD4
2018 Dummy Rounds as a DPA Countermeasure in Hardware
abstract
This paper describes the technique of Dummy Rounds as a countermeasure against DPA in hardware implementation of round-based ciphers. Its principle is inspired by several well-known countermeasures used in hardware as Hiding and Dynamic Reconfiguration as well as countermeasures used in software implementations as Dummy cycles, Random order execution or Hiding in time. Being inspired by countermeasures based on dynamic reconfiguration, this method combines hiding of power consumption with hiding in time. In this work we also discuss the amount of randomness available for the control of the computation.
Stanislav Jerabek, Jan Schmidt, Martin Novotný, Vojtech Miskovský
DSD3
2018 Correlation Power Analysis Distinguisher Based on the Correlation Trace Derivative
abstract
Correlation power analysis (CPA) is one of the most common side channel attacks today, posing a threat to many modern ciphers, including AES. The simplest method to extract the correct key guess is selecting the guess with the maximum Pearson correlation coefficient. We propose another distinguisher based on a significant change in the correlation trace rather than on the absolute value of the coefficient. Our approach performs better than the standard CPA, especially in the noisy environment.
Petr Socha, Vojtech Miskovský, Hana Kubátová, Martin Novotný
DSD4
2017 Optimization of Pearson correlation coefficient calculation for DPA and comparison of different approaches
abstract
Differential power analysis (DPA) is one of the most common side channel attacks. To perform this attack we need to calculate a large amount of correlation coefficients. This amount is even higher when attacking FPGAs or ASICs, for higher order attacks and especially for attacking DPA protected devices. This article explains different approaches to the calculation of correlations, describes our implementation of these approaches and presents a detailed comparison considering their performance and their properties for a practical usage.
Petr Socha, Vojtech Miskovský, Hana Kubátová, Martin Novotný
DDECS4
2017 Influence of Fault-Tolerance Techniques on Power-Analysis Resistance of Cryptographic Design
abstract
As the security is becoming more and more important these days, we still should not forget about reliability. When designing a cryptographic device for some mission-critical or another reliability demanding system, we need to make the device not only attack-resistant, but also fault-tolerant. There are many common fault-tolerant digital design techniques, however, it is questionable, how these techniques affect the attack-resistance. Do they make the device more vulnerable e.g. to side-channel attacks?In our work we focused on finding the answer to this question. We experimentally evaluated the influence of information redundancy, space redundancy and time redundancy techniques on resistance against power analysis attack. In this paper we present our observations.
Jan Riha, Vojtech Miskovský, Hana Kubátová, Martin Novotný
DSD4
2013 Differential Power Analysis under Constrained Budget: Low Cost Education of Hackers
abstract
The differential power analysis is popular technique in exploiting weaknesses of the embedded systems - mostly of the smart cards. This approach is understandable as the DPA does not require expensive equipment or strong theoretical background on the device under attack. Therefore it is ideal for education of beginners or students in the field of computer security. The aim of this paper is to describe the economy of obtaining the basic equipment for the education of the differential power analysis and to share the experience with its teaching.
Filip Stepánek, Jirí Bucek, Martin Novotný
DSD3
2013 On measurement of synchronous phasors in electrical grids
abstract
Precise estimation of frequency and phasor has become important in electrical power grids. Knowledge of phasor enables localization of faults, calculation of active and reactive power flows, determination of electrical parameters of system components (lines, transformers), etc. In this paper we present a new method for frequency and phasor assessment. Frequency assessment is done by applying statistical methods such as minimizing standard deviation of moving averages for the window length corresponding to possible frequency. Phasor assessment is done using numerical quadrature. The algorithm has been developed using Wolfram Mathematica®and implemented in development board equipped with a microcontroller.
Jan Kyncl, Adithya Hariram, Martin Novotný
ISCAS3
2012 Lightweight cipher resistivity against brute-force attack: Analysis of PRESENT
abstract
The PRESENT cipher is symmetric block cipher with 64 bits of data block and 80 (or 128) bits of key. It is based on Substitution-permutation network and consists of 31 rounds. PRESENT is intended to be implemented in small embedded and contactless systems, thus its design needs only small amount of chip area and consumes low power. In this work we evaluate the resistance of PRESENT against brute-force attack. We determine the computational demand of this type of attack conducted on special parallel hardware COPACOBANA consisting of array of FPGA chips with custom design.
Jan Pospisil 0002, Martin Novotný
DDECS2
2012 Evaluating Cryptanalytical Strength of Lightweight Cipher PRESENT on Reconfigurable Hardware
abstract
The PRESENT cipher is a symmetric block cipher with 64 bits of data block and 80 (or 128) bits of key. It is based on Substitution-permutation network and consists of 31 rounds. PRESENT is intended to be implemented in small embedded and contactless systems, thus its design needs only small amount of chip area and consumes low power. In this work we evaluate the resistance of PRESENT against time-memory trade-off attack. Specifically Rainbow Tables method is used. We determine the computational demand of this type of attack conducted on special parallel reconfigurable hardware COPACOBANA consisting of array of FPGA chips with custom design.
Jan Pospisil 0002, Martin Novotný
DSD2
2011 Breaking Hitag2 with Reconfigurable Hardware
abstract
The Hitag2 stream cipher is used in many real world applications, such as car immobilizers and door opening systems, as well as for the access control of buildings. The short length of the 48-bit secret key employed makes the cipher vulnerable to a brute-force attack, i.e., exhaustive key search. In this paper we develop the first hardware architecture for the cryptanalysis of Hitag2 by means of exhaustive key search. Our implementation on the Cost-Optimized Parallel Code-Breaker COPACOBANA is able to reveal the secret key of a Hitag2 transponder in less than 2 hours (103.5 minutes) in the worst case. The speed of our approach outperforms all previously proposed attacks and requires only 2 sniffed communications between a car and a tag. Our findings thus define a new lower limit for the cloning of car keys in practice. Moreover, the attack is arbitrarily parallelizable and could thus be run on multiple COPACOBANAs to decrease the time to find the secret key.
Petr Stembera, Martin Novotný
DSD2
2011 Education of Digital and Analog Circuits supported by computer algebra system
abstract
We describe our approach in education of the course Digital and Analog Circuits, which belongs to curricula of the Informatics study program. For analysis of analog and simple digital circuits we use computer algebra system Mathematica, which minimizes the amount of routine, handy calculations. This fact enables focusing on the problem and solving more examples, which in turn provides better comprehension of the topic. As Mathematica is later used in subsequent courses, its knowledge is utilized in these courses. Last, but not least, Mathematica provides several programming paradigms, which can be easy demonstrated to students of Informatics study program.
Jan Kyncl, Martin Novotný
ISCAS2
2008 A Real-World Attack Breaking A5/1 within Hours
Timo Gendrullis, Martin Novotný, Andy Rupp
CHES2
2008 Cryptanalysis with COPACOBANA
abstract
Cryptanalysis of ciphers usually involves massive computations. The security parameters of cryptographic algorithms are commonly chosen so that attacks are infeasible with available computing resources. This contribution presents a variety of cryptanalytical applications utilizing the COPACOBANA (Cost-Optimized Parallel Code Breaker) machine which is a high-performance, low-cost cluster consisting of 120 Field Programmable Gate Arrays (FPGA). COPACOBANA appears to be the only such reconfigurable parallel FPGA machine optimized for code breaking tasks reported in the open literature. Depending on the actual algorithm, the parallel hardware architecture can outperform conventional computers by several orders of magnitude. In this work, we will focus on novel implementations of cryptanalytical algorithms, utilizing the impressive computational power of COPACOBANA. We describe various exhaustive key search attacks on symmetric ciphers and demonstrate an attack on a security mechanism employed in the electronic passport. Furthermore, we describe time-memory tradeoff techniques which can, e.g., be used for attacking the popular A5/1 algorithm used in GSM voice encryption. In addition, we introduce efficient implementations of more complex cryptanalysis on asymmetric cryptosystems, e.g., Elliptic Curve Cryptosystems (ECC) and number co-factorization for RSA.
Tim Güneysu, Timo Kasper, Martin Novotný, Christof Paar, Andy Rupp
IEEE Trans. Computers3
2007 General Digit-Serial Normal Basis Multiplier with Distributed Overlap
abstract
We present the architecture of digit-serial normal basis multiplier over GF(2m). The multiplier was derived from the multiplier of Agnew et al. Proposed multiplier is scalable by the digit width of general value in difference of the multiplier of Agnew et al. that may be scaled only by digit width that divides the degree m. This helps designers to trade area for speed e.g. in public-key cryptographic systems based on elliptic-curves, where m should be a prime number. Functionality of multiplier has been tested by simulation and implemented in Xilinx Virtex 4 FPGA.
Martin Novotný, Jan Schmidt
DSD1
2006 Two Architectures of a General Digit-Serial Normal Basis Multiplier
abstract
We present two architectures of digit-serial normal basis multiplier over GF(2m). Proposed multipliers are scalable by the digit width of general value in difference of the multiplier of Agnew et al., that may be scaled only by digit width that divides the degree m. This helps designers to trade area for speed e.g. in cryptographic systems, where m should be a prime number. Functionality of multipliers has been tested by simulation and implemented in Xilinx Virtex 4 FPGA
Martin Novotný, Jan Schmidt
DSD1
2006 General Digit Width Normal Basis Multipliers with Circular and Linear Structure
abstract
Normal basis multipliers over GF(2m) with circular and linear structure are presented here. Proposed multipliers are scalable by the digit width of general value in difference of the multiplier of Agnew et al. that may be scaled only by digit width that divides the degree m. This capability enables designers to accelerate e.g. public-key cryptographic systems based on elliptic-curves, where m should be a prime number.
Martin Novotný, Jan Schmidt
FPL1
2004 Design and Implementation of the Memory Scheduler for the PC-Based Router
Tomás Marek, Martin Novotný, Ludek Crha
FPL2
2002 Exploration of Design Space in ECDSA
Jan Schmidt, Martin Novotný, Martin Jäger, Milos Becvár, Michal Jáchim
FPL2