Stefan Mangard

dblp:91/4831 · DBLP profile ↗
← Back
107ranked-venue papers
7as first author
39since 2021 · last 2026
0000-0001-9650-8041ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 91 · 6 first-author · 35 since 2021Systems, architecture and hardware · 14 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 7 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CAGE-V: Confidential Computing Architecture supporting Guest Enclaves for RISC-V
abstract
Confidential VMs enable cloud service providers to operate a secure and trustworthy multi-tenant cloud infrastructure. The confidential computing architecture enforces strong isolation for mutually untrusted tenants, i.e., guest VMs, and protects tenants against an untrusted hypervisor. While confidential VMs ensure comprehensive protection for cloud workloads, such heavy-weight isolation is often omitted for serverless applications that co-locate thousands of cloud workers within the same process to optimize FaaS overheads through efficient context switches.
Moritz Waser, Paul Gollob, Martin Unterguggenberger, Stefan Mangard
AsiaCCS4
2025 FatPTE - Expanding Page Table Entries for Security
Lukas Lamster, Martin Unterguggenberger, Moritz Waser, David Schrammel, Stefan Mangard
ARES (2)5
2025 CHERI UNCHAINED: Generic Instruction and Register Control for CHERI Capabilities
Moritz Waser, Lukas Lamster, David Schrammel, Martin Unterguggenberger, Stefan Mangard
ARES (2)5
2025 FAULTLESS: Flexible and Transparent Fault Protection for Superscalar RISC-V Processors
Moritz Waser, David Schrammel, Robert Schilling, Stefan Mangard
DIMVA (2)4
2025 WaitWatcher and WaitGuard: Detecting Flush-Based Cache Side-Channels Through Spurious Wakeups
Lukas Lamster, Fabian Rauscher, Martin Unterguggenberger, Stefan Mangard
ESORICS (3)4
2025 Code Encryption with Intel TME-MK for Control-Flow Enforcement
Martin Unterguggenberger, Lukas Lamster, Mathias Oberhuber, Simon Scherer, Stefan Mangard
ESORICS (2)5
2025 KernelSnitch: Side Channel-Attacks on Kernel Data Structures
Lukas Maar, Jonas Juffinger, Thomas Steinbauer, Daniel Gruss, Stefan Mangard
NDSS5
2025 Power-Related Side-Channel Attacks using the Android Sensor Framework
Mathias Oberhuber, Martin Unterguggenberger, Lukas Maar, Andreas Kogler, Stefan Mangard
NDSS5
2025 TME-Box: Scalable In-Process Isolation through Intel TME-MK Memory Encryption
Martin Unterguggenberger, Lukas Lamster, David Schrammel, Martin Schwarzl, Stefan Mangard
NDSS5
2025 Efficient SPA Countermeasures Using Redundant Number Representation with Application to ML-KEM
Rishub Nagpal, Vedad Hadzic, Robert Primas, Stefan Mangard
SAC4
2025 ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago
Florian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan Mangard
USENIX Security Symposium4
2025 The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel Vulnerabilities
Lukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García, Stefan Mangard
USENIX Security Symposium5
2025 When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks
Lukas Maar, Lukas Giner, Daniel Gruss, Stefan Mangard
USENIX Security Symposium4
2025 Special Issue on Open Hardware for Embedded System Security and Cryptography
abstract
Sharing hardware designs, from descriptions to manufacturing files, is gaining momentum in academia and industry, with the first open silicon security chip becoming commercially available in 2025. Secure embedded open hardware aims to provide industry-level building blocks that meet high-quality standards for code, documentation, design, testing, and verification enabling final fabrication and security certification. Despite the increasing popularity and benefits of secure embedded open hardware, some challenges need to be addressed to achieve the goal of fabricating and certifying secure open hardware. These challenges include developing secure open hardware building blocks that meet high-quality standards, establishing automated and efficient security testing and verification methods, and ensuring the availability of tools and processes that support the secure integration of hardware building blocks into larger and more complex embedded systems.
Michael Tempelmeier, Fabrizio De Santis, Shivam Bhasin, Stefan Mangard
ACM Trans. Embed. Comput. Syst.4
2024 Beyond the Edges of Kernel Control-Flow Hijacking Protection with HEK-CFI
abstract
Over the past decade, vulnerabilities in the Linux kernel have more than doubled, allowing control-flow hijacking attacks that compromise the entire system. To thwart these attacks, Control-Flow Integrity (CFI) has emerged as state-of-the-art. However, existing kernel CFI schemes are still limited in providing protection against these attacks, e.g., during system events and for return addresses.
Lukas Maar, Pascal Nasahl, Stefan Mangard
AsiaCCS3
2024 Memory Tagging using Cryptographic Integrity on Commodity x86 CPUs
abstract
Memory tagging allows to establish memory safety for software developed in unsafe languages like C/C++. Since it is an effective mechanism with low architectural complexity, ISA extensions, like ARM MTE or SPARC ADI, already integrate memory tagging on the architectural level for commodity computer systems. However, despite being in high demand, memory tagging features are currently absent in modern x86 processors. This work presents IntegriTag, a hardware-enforced memory tagging solution for existing commodity x86 CPUs. We leverage the Intel® Total Memory Encryption-Multi-Key (Intel® TME-MK) hardware feature that was initially envisioned for virtual machine isolation to instead provide memory tagging capabilities on off-the-shelf x86 processors. Unlike ARM MTE and SPARC ADI, this does not require the integration of a separate tagged memory architecture, which would increase the overall system complexity. Instead, our solution allows us to implicitly enforce the desired security policies by incorporating them into the existing memory encryption integrity checks. In addition, our design addresses security issues that affect tagged memory architectures with small tag spaces. Intel® TME-MK allows for a greater number of key identifier bits, thus offering significantly stronger security compared to the 4-bit tags of ARM MTE and SPARC ADI. We implement a holistic open-source software framework based on Intel® TME-MK, supporting several software-controlled and hardware-enforced memory safety policies. Moreover, we evaluate our design's performance overhead and security properties, underlining the practicability and efficacy of our approach. Our design is binary-compatible with existing software and provides both temporal and spatial memory safety while imposing an overhead of 32–41%, which is significantly lower than the overheads of memory safety schemes in software on commodity hardware that provide comparable security properties.
David Schrammel, Martin Unterguggenberger, Lukas Lamster, Salmin Sultana, Karanvir Grewal, Michael LeMay, David Durham, Stefan Mangard
EuroS&P8
2024 Exact Soft Analytical Side-Channel Attacks using Tractable Circuits
abstract
Detecting weaknesses in cryptographic algorithms is of utmost importance for designing secure information systems. The state-of-the-art *soft analytical side-channel attack* (SASCA) uses physical leakage information to make probabilistic predictions about intermediate computations and combines these "guesses" with the known algorithmic logic to compute the posterior distribution over the key. This attack is commonly performed via loopy belief propagation, which, however, lacks guarantees in terms of convergence and inference quality. In this paper, we develop a fast and exact inference method for SASCA, denoted as ExSASCA, by leveraging knowledge compilation and tractable probabilistic circuits. When attacking the *Advanced Encryption Standard* (AES), the most widely used encryption algorithm to date, ExSASCA outperforms SASCA by more than 31% top-1 success rate absolute. By leveraging sparse belief messages, this performance is achieved with little more computational cost than SASCA, and about 3 orders of magnitude less than exact inference via exhaustive enumeration. Even with dense belief messages, ExSASCA still uses 6 times less computations than exhaustive inference.
Thomas Wedenig, Rishub Nagpal, Gaëtan Cassiers, Stefan Mangard, Robert Peharz
ICML4
2024 Voodoo: Memory Tagging, Authenticated Encryption, and Error Correction through MAGIC
Lukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan Mangard
USENIX Security Symposium4
2024 Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android Kernels
Lukas Maar, Florian Draschbacher, Lukas Lamster, Stefan Mangard
USENIX Security Symposium4
2024 SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel
Lukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber, Stefan Mangard
USENIX Security Symposium5
2023 Formal Verification of Arithmetic Masking in Hardware and Software
Barbara Gigerl, Robert Primas, Stefan Mangard
ACNS (1)3
2023 DOPE: DOmain Protection Enforcement with PKS
abstract
The number of Linux kernel vulnerabilities discovered has increased drastically over the past years. In the kernel, even simple memory safety vulnerabilities can have devastating consequences, e.g., compromising the entire system. Efforts to mitigate these vulnerabilities have so far focused mainly on control-flow hijacking attacks in the kernel. Yet, data-oriented attacks remain largely unmitigated in practice as existing mitigations are limited in providing robust security guarantees at reasonable performance overhead for multiple sensitive data objects.
Lukas Maar, Martin Schwarzl, Fabian Rauscher, Daniel Gruss, Stefan Mangard
ACSAC5
2023 Secure Context Switching of Masked Software Implementations
abstract
Cryptographic software running on embedded devices requires protection against physical side-channel attacks such as power analysis. Masking is a widely deployed countermeasure against these attacks and is directly implemented on algorithmic level. Many works study the security of masked cryptographic software on CPUs, pointing out potential problems on algorithmic/microarchitecture-level, as well as corresponding solutions, and even show masked software can be implemented efficiently and with strong (formal) security guarantees. However, these works also make the implicit assumption that software is executed directly on the CPU without any abstraction layers in-between, i.e., they focus exclusively on the bare-metal case. Many practical applications, including IoT and automotive/industrial environments, require multitasking embedded OSs on which masked software runs as one out of many concurrent tasks. For such applications, the potential impact of events like context switches on the secure execution of masked software has not been studied so far at all.
Barbara Gigerl, Robert Primas, Stefan Mangard
AsiaCCS3
2023 SPEAR-V: Secure and Practical Enclave Architecture for RISC-V
abstract
Trusted Execution Environments (TEEs) and enclaves have become increasingly popular and are used from embedded devices to cloud servers. Today, many enclave architectures exist for different ISAs. However, some suffer from performance issues and controlled-channel attacks, while others only support constrained use cases for embedded devices or impose unrealistic constraints on the software. Modern cloud applications require a more flexible architecture that is both secure against such attacks and not constrained by, e.g., a limited number of physical memory ranges.
David Schrammel, Moritz Waser, Lukas Lamster, Martin Unterguggenberger, Stefan Mangard
AsiaCCS5
2023 Multi-Tag: A Hardware-Software Co-Design for Memory Safety based on Multi-Granular Memory Tagging
abstract
Memory safety vulnerabilities are a severe threat to modern computer systems allowing adversaries to leak or modify security-critical data. To protect systems from this attack vector, full memory safety is required. As software-based countermeasures tend to induce significant runtime overheads, which is not acceptable for production code, hardware assistance is needed. Tagged memory architectures, e.g., already offered by the ARM MTE and SPARC ADI extensions, assign meta-information to memory objects, thus allowing to implement memory safety policies. However, due to the high tag collision probability caused by the small tag sizes, the protection guarantees of these schemes are limited.
Martin Unterguggenberger, David Schrammel, Pascal Nasahl, Robert Schilling, Lukas Lamster, Stefan Mangard
AsiaCCS6
2023 Cryptographically Enforced Memory Safety
abstract
C/C++ memory safety issues, such as out-of-bounds errors, are still prevalent in today's applications. The presence of a single exploitable software bug allows an adversary to gain unauthorized memory access and ultimately compromise the entire system. Typically, memory safety schemes only achieve widespread adaption if they provide lightweight and practical security. Thus, hardware support is indispensable. However, countermeasures often restrict unauthorized access to data using heavy-weight protection mechanisms that extensively reshape the processor's microarchitecture and break legacy compatibility.
Martin Unterguggenberger, David Schrammel, Lukas Lamster, Pascal Nasahl, Stefan Mangard
CCS5
2023 SCFI: State Machine Control-Flow Hardening Against Fault Attacks
abstract
Fault injection (FI) is a powerful attack methodology allowing an adversary to entirely break the security of a target device. As finite-state machines (FSMs) are fundamental hardware building blocks responsible for controlling systems, inducing faults into these controllers enables an adversary to hijack the execution of the integrated circuit. A common defense strategy mitigating these attacks is to manually instantiate FSMs multiple times and detect faults using a majority voting logic. However, as each additional FSM instance only provides security against one additional induced fault, this approach scales poorly in a multi-fault attack scenario. In this paper, we present SCFI: a strong, probabilistic FSM protection mechanism ensuring that control-flow deviations from the intended control-flow are detected even in the presence of multiple faults. At its core, SCFI consists of a hardened next-state function absorbing the execution history as well as the FSM's control signals to derive the next state. When either the absorbed inputs, the state registers, or the function itself are affected by faults, SCFI triggers an error with no detection latency. We integrate SCFI into a synthesis tool capable of automatically hardening arbitrary unprotected FSMs without user interaction and open-source the tool. Our evaluation shows that SCFI provides strong protection guarantees with a better area-time product than FSMs protected using classical redundancy-based approaches. Finally, we formally verify the resilience of the protected state machines using a pre-silicon fault analysis tool.
Pascal Nasahl, Martin Unterguggenberger, Rishub Nagpal, Robert Schilling, David Schrammel, Stefan Mangard
DATE6
2023 SCRAMBLE-CFI: Mitigating Fault-Induced Control-Flow Attacks on OpenTitan
abstract
Secure elements physically exposed to adversaries are frequently targeted by fault attacks. These attacks can be utilized to hijack the control-flow of software allowing the attacker to bypass security measures, extract sensitive data, or gain full code execution.
Pascal Nasahl, Stefan Mangard
ACM Great Lakes Symposium on VLSI2
2023 MEMES: Memory Encryption-Based Memory Safety on Commodity Hardware
David Schrammel, Salmin Sultana, Karanvir Grewal, Michael LeMay, David Durham, Martin Unterguggenberger, Pascal Nasahl, Stefan Mangard
SECRYPT8
2023 Scatter and Split Securely: Defeating Cache Contention and Occupancy Attacks
abstract
In this paper, we propose SassCache, a secure skewed associative cache with keyed index mapping. For this purpose, we design a new two-layered, low-latency cryptographic construction with configurable output coverage based on state-of-the-art cryptographic primitives. Based on this construction, SassCache is the first secure randomized cache with secure spacing. Victim cache lines automatically hide in locations the attacker cannot reach after less than 1 access on average. Consequently, attackers cannot evict the cache line, no matter which and how many memory accesses they perform. Our security analysis shows that all existing techniques for eviction set construction fail, and state-of-the-art attacks only apply to 1 in 3 million addresses, where SassCache is still as secure as ScatterCache. Compared to standard caches, Sass Cache has a single-threaded performance penalty of 1.75 % on the last-level cache hit rate in the SPEC2017 benchmark, and an average decrease of 11.7 p.p. in hit rate for MiBench, GAP and Scimark for our high-security settings.
Lukas Giner, Stefan Steinegger, Antoon Purnal, Maria Eichlseder, Thomas Unterluggauer, Stefan Mangard, Daniel Gruss
SP6
2023 Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels
Andreas Kogler, Jonas Juffinger, Lukas Giner, Lukas Gerlach 0001, Martin Schwarzl, Michael Schwarz 0001, Daniel Gruss, Stefan Mangard
USENIX Security Symposium8
2023 HashTag: Hash-based Integrity Protection for Tagged Architectures
Lukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan Mangard
USENIX Security Symposium4
2022 Power Contracts: Provably Complete Power Leakage Models for Processors
abstract
The protection of cryptographic software implementations against power-analysis attacks is critical for applications in embedded systems. A commonly used algorithmic countermeasure against these attacks is masking, a secret-sharing scheme that splits a sensitive computation into computations on multiple random shares. In practice, the security of masking schemes relies on several assumptions that are often violated by microarchitectural side-effects of CPUs. Many past works address this problem by studying these leakage effects and building corresponding leakage models that can then be integrated into a software verification workflow. However, these models have only been derived empirically, putting in question the otherwise rigorous security statements made with verification. We solve this problem in two steps. First, we introduce a contract layer between the (CPU) hardware and the software that allows the specification of microarchitectural side-effects on masked software in an intuitive language. Second, we present a method for proving the correspondence between contracts and CPU netlists to ensure the completeness of the specified leakage models. Then, any further security proofs only need to happen between software and contract, which brings benefits such as reduced verification runtime, improved user experience, and the possibility of working with vendor-supplied contracts of CPUs whose design is not available on netlist-level due to IP restrictions. We apply our approach to the popular RISC-V IBEX core, provide a corresponding formally verified contract, and describe how this contract could be used to verify masked software implementations.
Roderick Bloem, Barbara Gigerl, Marc Gourjon, Vedad Hadzic, Stefan Mangard, Robert Primas
CCS5
2022 Jenny: Securing Syscalls for PKU-based Memory Isolation Systems
David Schrammel, Samuel Weiser, Richard Sadek, Stefan Mangard
USENIX Security Symposium4
2021 CrypTag: Thwarting Physical and Logical Memory Vulnerabilities using Cryptographically Colored Memory
abstract
Memory vulnerabilities are a major threat to many computing systems. To effectively thwart spatial and temporal memory vulnerabilities, full logical memory safety is required. However, current mitigation techniques for memory safety are either too expensive or trade security against efficiency. One promising attempt to detect memory safety vulnerabilities in hardware is memory coloring, a security policy deployed on top of tagged memory architectures. However, due to the memory storage and bandwidth overhead of large tags, commodity tagged memory architectures usually only provide small tag sizes, thus limiting their use for security applications.
Pascal Nasahl, Robert Schilling, Mario Werner, Jan Hoogerbrugge, Marcel Medwed, Stefan Mangard
AsiaCCS6
2021 HECTOR-V: A Heterogeneous CPU Architecture for a Secure RISC-V Execution Environment
abstract
To ensure secure and trustworthy execution of applications in potentially insecure environments, vendors frequently embed trusted execution environments (TEE) into their systems. Applications executed in this safe, isolated space are protected from adversaries, including a malicious operating system. TEEs are usually build by integrating protection mechanisms directly into the processor or by using dedicated external secure elements. However, both of these approaches only cover a narrow threat model resulting in limited security guarantees. Enclaves nested into the application processor typically provide weak isolation between the secure and non-secure domain, especially when considering side-channel attacks. Although external secure elements do provide strong isolation, the slow communication interface to the application processor is exposed to adversaries and restricts the use cases. Independently of the used approach, TEEs often lack the possibility to establish secure communication to peripherals, and most operating systems executed inside TEEs do not provide state-of-the-art defense strategies, making them vulnerable to various attacks. We argue that TEEs, such as Intel SGX or ARM TrustZone, implemented on the main application processor, are insecure, especially when considering side-channel attacks. In this paper, we demonstrate how a heterogeneous multicore architecture can be utilized to realize a secure TEE design. We directly embed a secure processor into our HECTOR-V architecture to provide strong isolation between the secure and non-secure domain. The tight coupling of the TEE and the application processor enables HECTOR-V to provide mechanisms for establishing secure communication channels between different devices. We further introduce RISC-V Secure Co-Processor (RVSCP), a security-hardened processor tailored for TEEs. To secure applications executed inside the TEE, RVSCP provides hardware enforced control-flow integrity and rigorously restricts I/O accesses to certain execution states. RVSCP reduces the trusted computing base to a minimum by providing operating system services directly in hardware.
Pascal Nasahl, Robert Schilling, Mario Werner, Stefan Mangard
AsiaCCS4
2021 Secure and Efficient Software Masking on Superscalar Pipelined Processors
Barbara Gigerl, Robert Primas, Stefan Mangard
ASIACRYPT (2)3
2021 SERVAS! Secure Enclaves via RISC-V Authenticryption Shield
Stefan Steinegger, David Schrammel, Samuel Weiser, Pascal Nasahl, Stefan Mangard
ESORICS (2)5
2021 Coco: Co-Design and Co-Verification of Masked Software Implementations on CPUs
Barbara Gigerl, Vedad Hadzic, Robert Primas, Stefan Mangard, Roderick Bloem
USENIX Security Symposium4
2020 Donky: Domain Keys - Efficient In-Process Isolation for RISC-V and x86
David Schrammel, Samuel Weiser, Stefan Steinegger, Martin Schwarzl, Michael Schwarz 0001, Stefan Mangard, Daniel Gruss
USENIX Security Symposium6
2020 Malware Guard Extension: abusing Intel SGX to conceal cache attacks
abstract
Abstract In modern computer systems, user processes are isolated from each other by the operating system and the hardware. Additionally, in a cloud scenario it is crucial that the hypervisor isolates tenants from other tenants that are co-located on the same physical machine. However, the hypervisor does not protect tenants against the cloud provider and thus, the supplied operating system and hardware. Intel SGX provides a mechanism that addresses this scenario. It aims at protecting user-level software from attacks from other processes, the operating system, and even physical attackers.In this paper, we demonstrate fine-grained software-based side-channel attacks from a malicious SGX enclave targeting co-located enclaves. Our attack is the first malware running on real SGX hardware, abusing SGX protection features to conceal itself. Furthermore, we demonstrate our attack both in a native environment and across multiple Docker containers. We perform a Prime+Probe cache side-channel attack on a co-located SGX enclave running an up-to-date RSA implementation that uses a constant-time multiplication primitive. The attack works, although in SGX enclaves, there are no timers, no large pages, no physical addresses, and no shared memory. In a semi-synchronous attack, we extract 96 % of an RSA private key from a single trace. We extract the full RSA private key in an automated attack from 11 traces within 5 min.
Michael Schwarz 0001, Samuel Weiser, Daniel Gruss, Clémentine Maurice, Stefan Mangard
Cybersecur.5
2019 Protecting RISC-V Processors against Physical Attacks
abstract
RISC-V is an emerging instruction-set architecture suitable for a wide variety of applications, which ranges from simple microcontrollers to high-performance CPUs. As an increasing number of commercial vendors now plans to adopt the architecture in their products, its security aspects are becoming a significant concern. For microcontroller implementations of RISC-V, one of the main security risks are attackers with direct physical access to the microchip. These physical attackers can perform highly powerful attacks that span from memory probing to power analysis up to fault injection and analysis. In this paper, we give an overview of the capabilities of attackers with direct physical device access, common threat models and attack vectors, and possible countermeasures. Besides, we discuss in more detail current approaches to secure RISC-V processors against fault injection attacks on the microchip itself. First, we show how to protect the control-flow against fault attacks by using an encrypted instruction stream and decrypting it on-the-fly in a newly added pipeline stage between the processor's fetch and decode unit. Second, we show how to protect conditional branches against fault injection by adding redundancy to the comparison operation and entangling the comparison result with the encrypted instruction stream. Finally, we discuss an approach to protect all pointers and memory accesses from tampering.
Mario Werner, Robert Schilling, Thomas Unterluggauer, Stefan Mangard
DATE4
2019 TIMBER-V: Tag-Isolated Memory Bringing Fine-grained Enclaves to RISC-V
Samuel Weiser, Mario Werner, Ferdinand Brasser, Maja Malenko, Stefan Mangard, Ahmad-Reza Sadeghi
NDSS5
2019 Spectre Attacks: Exploiting Speculative Execution
abstract
Modern processors use branch prediction and speculative execution to maximize performance. For example, if the destination of a branch depends on a memory value that is in the process of being read, CPUs will try to guess the destination and attempt to execute ahead. When the memory value finally arrives, the CPU either discards or commits the speculative computation. Speculative logic is unfaithful in how it executes, can access the victim's memory and registers, and can perform operations with measurable side effects. Spectre attacks involve inducing a victim to speculatively perform operations that would not occur during correct program execution and which leak the victim's confidential information via a side channel to the adversary. This paper describes practical attacks that combine methodology from side channel attacks, fault attacks, and return-oriented programming that can read arbitrary memory from the victim's process. More broadly, the paper shows that speculative execution implementations violate the security assumptions underpinning numerous software security mechanisms, including operating system process separation, containerization, just-in-time (JIT) compilation, and countermeasures to cache timing and side-channel attacks. These attacks represent a serious threat to actual systems since vulnerable speculative execution capabilities are found in microprocessors from Intel, AMD, and ARM that are used in billions of devices. While makeshift processor-specific countermeasures are possible in some cases, sound solutions will require fixes to processor designs as well as updates to instruction set architectures (ISAs) to give hardware architects and software developers a common understanding as to what computation state CPU implementations are (and are not) permitted to leak.
Paul C. Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas 0004, Michael Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher 0002, Michael Schwarz 0001, Yuval Yarom
IEEE Symposium on Security and Privacy9
2019 ScatterCache: Thwarting Cache Attacks via Cache Set Randomization
Mario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz 0001, Daniel Gruss, Stefan Mangard
USENIX Security Symposium6
2019 Small Faults Grow Up - Verification of Error Masking Robustness in Arithmetically Encoded Programs
Anja F. Karl, Robert Schilling, Roderick Bloem, Stefan Mangard
VMCAI4
2018 Pointing in the Right Direction - Securing Memory Accesses in a Faulty World
abstract
Reading and writing memory are, besides computation, the most common operations a processor performs. The correctness of these operations is therefore essential for the proper execution of any program. However, as soon as fault attacks are considered, assuming that the hardware performs its memory operations as instructed is not valid anymore. In particular, attackers may induce faults with the goal of reading or writing incorrectly addressed memory, which can have various critical safety and security implications.
Robert Schilling, Mario Werner, Pascal Nasahl, Stefan Mangard
ACSAC4
2018 Statistical Ineffective Fault Attacks on Masked AES with Fault Countermeasures
Christoph Dobraunig, Maria Eichlseder, Hannes Groß, Stefan Mangard, Florian Mendel, Robert Primas
ASIACRYPT (2)4
2018 Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
abstract
Double-fetch bugs are a special type of race condition, where an unprivileged execution thread is able to change a memory location between the time-of-check and time-of-use of a privileged execution thread. If an unprivileged attacker changes the value at the right time, the privileged operation becomes inconsistent, leading to a change in control flow, and thus an escalation of privileges for the attacker. More severely, such double-fetch bugs can be introduced by the compiler, entirely invisible on the source-code level. We propose novel techniques to efficiently detect, exploit, and eliminate double-fetch bugs. We demonstrate the first combination of state-of-the-art cache attacks with kernel-fuzzing techniques to allow fully automated identification of double fetches. We demonstrate the first fully automated reliable detection and exploitation of double-fetch bugs, making manual analysis as in previous work superfluous. We show that cache-based triggers outperform state-of-the-art exploitation techniques significantly, leading to an exploitation success rate of up to 97%. Our modified fuzzer automatically detects double fetches and automatically narrows down this candidate set for double-fetch bugs to the exploitable ones. We present the first generic technique based on hardware transactional memory, to eliminate double-fetch bugs in a fully automated and transparent manner. We extend defensive programming techniques by retrofitting arbitrary code with automated double-fetch prevention, both in trusted execution environments as well as in syscalls, with a performance overhead below 1%.
Michael Schwarz 0001, Daniel Gruss, Moritz Lipp, Clémentine Maurice, Anders Fogh, Stefan Mangard
AsiaCCS7
2018 ProcHarvester: Fully Automated Analysis of Procfs Side-Channel Leaks on Android
abstract
The procfs has been identified as a viable source of side-channel information leaks on mobile devices. Starting with Android M (Android 6), access to the procfs has been continuously restricted in order to cope with these attacks. Yet, more recent papers demonstrated that even if access to process-specific information is restricted within the procfs, global statistics can still be exploited. However, with state-of-the-art techniques, the search for procfs information leaks requires a significant amount of manual work. This makes an exhaustive analysis of existing and newly introduced procfs resources in terms of information leaks impractical. We introduce ProcHarvester, a systematic and fully automated technique to assess procfs information leaks. ProcHarvester automatically triggers events of interest and later on applies machine learning techniques to identify procfs information leaks. We demonstrate the power of ProcHarvester by identifying information leaks to infer app starts from a set of 100 apps with an accuracy of 96% on Android N (Android 7). Thereby, we outperform the most accurate app inference attack by about 10 percentage points. We also demonstrate the ease of applicability of ProcHarvester by showing how to profile other events such as website launches as well as keyboard gestures, and we identify the first procfs side channels on Android O (Android 8). ProcHarvester advances investigations of procfs information leaks to the next level and will hopefully help to reduce the attack surface of side-channel attacks.
Raphael Spreitzer, Felix Kirchengast, Daniel Gruss, Stefan Mangard
AsiaCCS4
2018 High speed ASIC implementations of leakage-resilient cryptography
abstract
Embedded devices in the Internet-of-Things require encryption functionalities to secure their communication. However, side-channel attacks and in particular differential power analysis (DPA) attacks pose a serious threat to cryptographic implementations. While state-of-the-art countermeasures like masking slow down the performance and can only prevent DPA up to a certain order, leakage-resilient schemes are designed to stay secure even in the presence of side-channel leakage. Although several leakage-resilient schemes have been proposed, there are no hardware implementations to demonstrate their practicality and performance on measurable silicon. In this work, we present an ASIC implementation of a multi-core System-on-Chip extended with a software-programmable accelerator for leakage-resilient cryptography. The accelerator is deeply embedded in the shared memory architecture of the many-core system, supports different configurations, contains a high-throughput implementation of the 2PRG primitive based on AES-128, offers two side-channel protected re-keying functions, and is the first fabricated design of the side-channel secure authenticated encryption scheme ISAP. The accelerator reaches a maximum throughput of 7.49Gbit/s and a best-case energy efficiency of 137 Gbit/s/W making this accelerator suitable for high-speed secure IoT applications.
Robert Schilling, Thomas Unterluggauer, Stefan Mangard, Frank K. Gürkaynak, Michael Mühlberghuber, Luca Benini
DATE3
2018 Securing conditional branches in the presence of fault attacks
abstract
In typical software, many comparisons and subsequent branch operations are highly critical in terms of security. Examples include password checks, signature checks, secure boot, and user privilege checks. For embedded devices, these security-critical branches are a preferred target of fault attacks as a single bit flip or skipping a single instruction can lead to complete access to a system. In the past, numerous redundancy schemes have been proposed in order to provide control-flow-integrity (CFI) and to enable error detection on processed data. However, current countermeasures for general purpose software do not provide protection mechanisms for conditional branches. Hence, critical branches are in practice often simply duplicated. We present a generic approach to protect conditional branches, which links an encoding-based comparison result with the redundancy of CFI protection mechanisms. The presented approach can be used for all types of data encodings and CFI mechanisms and maintains their error-detection capabilities throughout all steps of a conditional branch. We demonstrate our approach by realizing an encoded comparison based on AN-codes, which is a frequently used encoding scheme to detect errors on data during arithmetic operations. We extended the LLVM compiler so that standard code and conditional branches can be protected automatically and analyze its security. Our design shows that the overhead in terms of size and runtime is lower than state-of-the-art duplication schemes.
Robert Schilling, Mario Werner, Stefan Mangard
DATE3
2018 Formal Verification of Masked Hardware Implementations in the Presence of Glitches
Roderick Bloem, Hannes Groß, Rinat Iusupov, Bettina Könighofer, Stefan Mangard, Johannes Winter
EUROCRYPT (2)5
2018 Sponge-Based Control-Flow Protection for IoT Devices
abstract
Embedded devices in the Internet of Things (IoT) face a wide variety of security challenges. For example, software attackers perform code injection and code-reuse attacks on their remote interfaces, and physical access to IoT devices allows to tamper with code in memory, steal confidential Intellectual Property (IP), or mount fault attacks to manipulate a CPU's control flow. In this work, we present Sponge-based Control Flow Protection (SCFP). SCFP is a stateful, sponge-based scheme to ensure the confidentiality of software IP and its authentic execution on IoT devices. At compile time, SCFP encrypts and authenticates software with instruction-level granularity. During execution, an SCFP hardware extension between the CPU's fetch and decode stage continuously decrypts and authenticates instructions. Sponge-based authenticated encryption in SCFP yields fine-grained control-flow integrity and thus prevents code-reuse, code-injection, and fault attacks on the code and the control flow. In addition, SCFP withstands any modification of software in memory. For evaluation, we extended a RISC-V core with SCFP and fabricated a real System on Chip (SoC). The average overhead in code size and execution time of SCFP on this design is 19.8% and 9.1 %, respectively, and thus meets the requirements of embedded IoT devices.
Mario Werner, Thomas Unterluggauer, David Schaffenrath, Stefan Mangard
EuroS&P4
2018 KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel Attacks
Michael Schwarz 0001, Moritz Lipp, Daniel Gruss, Samuel Weiser, Clémentine Maurice, Raphael Spreitzer, Stefan Mangard
NDSS7
2018 Fault Attacks on Nonce-Based Authenticated Encryption: Application to Keyak and Ketje
Christoph Dobraunig, Stefan Mangard, Florian Mendel, Robert Primas
SAC2
2018 Meltdown: Reading Kernel Memory from User Space
Moritz Lipp, Michael Schwarz 0001, Daniel Gruss, Thomas Prescher 0002, Werner Haas 0004, Anders Fogh, Jann Horn, Stefan Mangard, Paul C. Kocher, Daniel Genkin, Yuval Yarom, Michael Hamburg
USENIX Security Symposium8
2018 DATA - Differential Address Trace Analysis: Finding Address-based Side-Channels in Binaries
Samuel Weiser, Andreas Zankl, Raphael Spreitzer, Katja Miller, Stefan Mangard, Georg Sigl
USENIX Security Symposium5
2018 SCAnDroid: Automated Side-Channel Analysis of Android APIs
abstract
Although the Android system has been continuously hardened against side-channel attacks, there are still plenty of APIs available that can be exploited. However, most side-channel analyses in the literature consider specifically chosen APIs (or resources) in the Android framework, after a manual analysis of APIs for possible information leaks has been performed. Such a manual analysis is a tedious, time consuming, and error-prone task, meaning that information leaks tend to be overlooked.
Raphael Spreitzer, Gerald Palfinger, Stefan Mangard
WISEC3
2017 Leakage Bounds for Gaussian Side Channels
Thomas Unterluggauer, Thomas Korak, Stefan Mangard, Robert Schilling, Luca Benini, Frank K. Gürkaynak, Michael Mühlberghuber
CARDIS3
2017 Securing Memory Encryption and Authentication Against Side-Channel Attacks Using Unprotected Primitives
abstract
Memory encryption is used in many devices to protect memory content from attackers with physical access to a device. However, many current memory encryption schemes can be broken using Differential Power Analysis (DPA). In this work, we present MEAS---the first Memory Encryption and Authentication Scheme providing security against DPA attacks. The scheme combines ideas from fresh re-keying and authentication trees by storing encryption keys in a tree structure to thwart first-order DPA without the need for DPA-protected cryptographic primitives. Therefore, the design strictly limits the use of every key to encrypt at most two different plaintext values. MEAS prevents higher-order DPA without changes to the cipher implementation by using masking of the plaintext values. MEAS is applicable to all kinds of memory, e.g., NVM and RAM, and has memory overhead comparable to existing memory authentication techniques without DPA protection, e.g., 7.3% for a block size fitting standard disk sectors.
Thomas Unterluggauer, Mario Werner, Stefan Mangard
AsiaCCS3
2017 Reconciling d+1 Masking in Hardware and Software
Hannes Groß, Stefan Mangard
CHES2
2017 Single-Trace Side-Channel Attacks on Masked Lattice-Based Encryption
Robert Primas, Peter Pessl, Stefan Mangard
CHES3
2017 An Efficient Side-Channel Protected AES Implementation with Arbitrary Protection Order
Hannes Groß, Stefan Mangard, Thomas Korak
CT-RSA2
2017 Side-channel plaintext-recovery attacks on leakage-resilient encryption
abstract
Differential power analysis (DPA) is a powerful tool to extract the key of a cryptographic implementation from observing its power consumption during the en-/decryption of many different inputs. Therefore, cryptographic schemes based on frequent re-keying such as leakage-resilient encryption aim to inherently prevent DPA on the secret key by limiting the amount of data being processed under one key. However, the original asset of encryption, namely the plaintext, is disregarded. This paper builds on this observation and shows that the re-keying countermeasure does not only protect the secret key, but also induces another DPA vulnerability that allows for plaintext recovery. Namely, the frequent re-keying in leakage-resilient streaming modes causes constant plaintexts to be attackable through first-order DPA. Similarly, constant plaintexts can be revealed from re-keyed block ciphers using templates in a second-order DPA. Such plaintext recovery is particularly critical whenever long-term key material is encrypted and thus leaked. Besides leakage-resilient encryption, the presented attacks are also relevant for a wide range of other applications in practice that implicitly use re-keying, such as multi-party communication and memory encryption with random initialization for the key. Practical evaluations on both an FPGA and a microcontroller support the feasibility of the attacks and thus suggest the use of cryptographic implementations protected by mechanisms like masking in scenarios that require data encryption with multiple keys.
Thomas Unterluggauer, Mario Werner, Stefan Mangard
DATE3
2017 Malware Guard Extension: Using SGX to Conceal Cache Attacks
Michael Schwarz 0001, Samuel Weiser, Daniel Gruss, Clémentine Maurice, Stefan Mangard
DIMVA5
2017 Higher-Order Side-Channel Protected Implementations of KECCAK
abstract
The efficient protection of security critical devices against side-channel analysis attacks is a fundamental need in the age of Internet of Things and ubiquitous computing. In this work, we introduce a configurable hardware design of KECCAK (SHA-3) which can be tailored to fulfill the needs of a wide range of different applications. Our KECCAK design is therefore equipped with generic side-channel protection capabilities. The design can thus be synthesized for any desired protection level by just changing one design parameter.Regardless of its generic appearance, the introduced KECCAK design yields the smallest (15.7 kGE) first-order protected KECCAK implementation published to this date. Furthermore, it is to the best of our knowledge the first higher-order side-channel resistant implementation of KECCAK. In total, we state results for four different KECCAK variants up to the ninth protection order.
Hannes Groß, David Schaffenrath, Stefan Mangard
DSD3
2017 Practical Keystroke Timing Attacks in Sandboxed JavaScript
Moritz Lipp, Daniel Gruss, Michael Schwarz 0001, David Bidner, Clémentine Maurice, Stefan Mangard
ESORICS (2)6
2017 Transparent memory encryption and authentication
abstract
Security features of modern (SoC) FPGAs permit to protect the confidentiality of hard- and software IP when the devices are powered off as well as to validate the authenticity of IP when being loaded at startup. However, these approaches are insufficient since attackers with physical access can also perform attacks during runtime, demanding for additional security measures. In particular, RAM used by modern (SoC) FPGAs is under threat since RAM stores software IP as well as all kinds of other sensitive information during runtime. To solve this issue, we present an open-source framework for building transparent RAM encryption and authentication pipelines, suitable for both FPGAs and ASICs. The framework supports various ciphers and modes of operation as shown by our comprehensive evaluation on a Xilinx Zynq-7020 SoC. For encryption, the ciphers Prince and AES are used in the ECB, CBC and XTS mode. Additionally, the authenticated encryption cipher Ascon is used both standalone and within a TEC tree. Our results show that the data processing of our encryption pipeline is highly efficient with up to 94 % utilization of the read bandwidth that is provided by the FPGA interface. Moreover, the use of a cryptographically strong primitive like Ascon yields highly practical results with 54 % bandwidth utilization.
Mario Werner, Thomas Unterluggauer, Robert Schilling, David Schaffenrath, Stefan Mangard
FPL5
2017 Hello from the Other Side: SSH over Robust Cache Covert Channels in the Cloud
Clémentine Maurice, Manuel Weber, Michael Schwarz 0001, Lukas Giner, Daniel Gruss, Carlo Alberto Boano, Stefan Mangard, Kay Römer
NDSS7
2016 Concealing Secrets in Embedded Processors Designs
Hannes Groß, Manuel Jelinek, Stefan Mangard, Thomas Unterluggauer, Mario Werner
CARDIS3
2016 Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLR
abstract
Modern operating systems use hardware support to protect against control-flow hijacking attacks such as code-injection attacks. Typically, write access to executable pages is prevented and kernel mode execution is restricted to kernel code pages only. However, current CPUs provide no protection against code-reuse attacks like ROP. ASLR is used to prevent these attacks by making all addresses unpredictable for an attacker. Hence, the kernel security relies fundamentally on preventing access to address information. We introduce Prefetch Side-Channel Attacks, a new class of generic attacks exploiting major weaknesses in prefetch instructions. This allows unprivileged attackers to obtain address information and thus compromise the entire system by defeating SMAP, SMEP, and kernel ASLR. Prefetch can fetch inaccessible privileged memory into various caches on Intel x86. It also leaks the translation-level for virtual addresses on both Intel x86 and ARMv8-A. We build three attacks exploiting these properties. Our first attack retrieves an exact image of the full paging hierarchy of a process, defeating both user space and kernel space ASLR. Our second attack resolves virtual to physical addresses to bypass SMAP on 64-bit Linux systems, enabling ret2dir attacks. We demonstrate this from unprivileged user programs on Linux and inside Amazon EC2 virtual machines. Finally, we demonstrate how to defeat kernel ASLR on Windows 10, enabling ROP attacks on kernel and driver binary code. We propose a new form of strong kernel isolation to protect commodity systems incuring an overhead of only 0.06-5.09%.
Daniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp, Stefan Mangard
CCS5
2016 Enhancing Side-Channel Analysis of Binary-Field Multiplication with Bit Reliability
Peter Pessl, Stefan Mangard
CT-RSA2
2016 Rowhammer.js: A Remote Software-Induced Fault Attack in JavaScript
Daniel Gruss, Clémentine Maurice, Stefan Mangard
DIMVA3
2016 Flush+Flush: A Fast and Stealthy Cache Attack
Daniel Gruss, Clémentine Maurice, Klaus Wagner 0001, Stefan Mangard
DIMVA4
2016 ARMageddon: Cache Attacks on Mobile Devices
Moritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice, Stefan Mangard
USENIX Security Symposium5
2016 DRAMA: Exploiting DRAM Addressing for Cross-CPU Attacks
Peter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 0001, Stefan Mangard
USENIX Security Symposium5
2016 Exploiting Data-Usage Statistics for Website Fingerprinting Attacks on Android
abstract
The browsing behavior of a user allows to infer personal details, such as health status, political interests, sexual orientation, etc. In order to protect this sensitive information and to cope with possible privacy threats, defense mechanisms like SSH tunnels and anonymity networks (e.g., Tor) have been established. A known shortcoming of these defenses is that website fingerprinting attacks allow to infer a user's browsing behavior based on traffic analysis techniques. However, website fingerprinting typically assumes access to the client's network or to a router near the client, which restricts the applicability of these attacks.
Raphael Spreitzer, Simone Griesmayr, Thomas Korak, Stefan Mangard
WISEC4
2015 Towards Fresh and Hybrid Re-Keying Schemes with Beyond Birthday Security
Christoph Dobraunig, François Koeune, Stefan Mangard, Florian Mendel, François-Xavier Standaert
CARDIS3
2015 Protecting the Control Flow of Embedded Processors against Fault Attacks
Mario Werner, Erich Wenger, Stefan Mangard
CARDIS3
2015 Practical Memory Deduplication Attacks in Sandboxed Javascript
abstract
Page deduplication is a mechanism to reduce the memory footprint of a system. Identical physical pages are identified across borders of virtual machines and programs and merged by the operating system or the hypervisor. However, this enables side-channel information leakage through cache or memory access time. Therefore, it is considered harmful in public clouds today, but it is still considered safe to use in a private environment, i.e., private clouds, personal computers, and smartphones. We present the first memory-disclosure attack in sandboxed Javascript which exploits page deduplication. Unlike previous attacks, our attack does not require the victim to execute an adversary’s program, but simply to open a website which contains the adversary’s Javascript code. We are not only able to determine which applications are running, but also specific user activities, for instance, whether the user has specific websites currently opened. The attack works on servers, personal computers and smartphones, and across the borders of virtual machines.
Daniel Gruss, David Bidner, Stefan Mangard
ESORICS (1)3
2015 Fault Attacks at the System Level - The Challenge of Securing Application Software
abstract
Summary form only given. During the last two decades, fault attacks on cryptographic algorithms have received significantly more attention in the academic community than fault attacks on application software. However, fault attacks on application software pose a serious threat in practice. Faults can for example be induced to bypass cryptographic functions or to obtain root access to a device. Such faults can be induced by physical means or as the recent publication of the Rowhammer attack has shown, faults can even be induced remotely. This talk provides an overview of attack techniques as well as of countermeasures to secure not only cryptography, but entire systems, against fault attacks.
Stefan Mangard
FDTC1
2015 Cache Template Attacks: Automating Attacks on Inclusive Last-Level Caches
Daniel Gruss, Raphael Spreitzer, Stefan Mangard
USENIX Security Symposium3
2014 On the Security of Fresh Re-keying to Counteract Side-Channel and Fault Attacks
Christoph Dobraunig, Maria Eichlseder, Stefan Mangard, Florian Mendel
CARDIS3
2013 Clustering Algorithms for Non-profiled Single-Execution Attacks on Exponentiations
Johann Heyszl, Andreas Ibing, Stefan Mangard, Fabrizio De Santis, Georg Sigl
CARDIS3
2012 Localized Electromagnetic Analysis of Cryptographic Implementations
Johann Heyszl, Stefan Mangard, Benedikt Heinz, Frederic Stumpf, Georg Sigl
CT-RSA2
2011 Arithmetic logic units with high error detection rates to counteract fault attacks
abstract
Modern security-aware embedded systems need protection against fault attacks. These attacks rely on intentionally induced faults. Such intentional faults have not only a different origin, but also a different nature than errors that fault-tolerant systems usually have to face. For instance an adversary who attacks the circuit with two lasers can potentially induce two errors at different positions. Such errors can not only defeat simple double modular redundancy schemes, but as we show, also naive schemes based on any linear code over GF(2). In this article, we describe arithmetic logic units (ALUs) which provide high error detection rates even in the presence of such errors. The contribution in this article is threefold. First, we show that the minimum weight of an undetected error is no longer defined by the code distance when certain arithmetic and logic operations are applied to the codewords. As a result, additional hardware is needed to preserve the minimum error weight for a given code. Second, we show that for multi-residue codes, these delicate operations are rare in typical smart card applications. This allows for an efficient time-area trade-off for checking the codewords and thus to significantly reduce the hardware costs for such a protected ALU. Third, we implement the proposed architectures and study the influence of the register file and a multiplier on the area and on the critical path.
Marcel Medwed, Stefan Mangard
DATE2
2011 One for all - all for one: unifying standard differential power analysis attacks
abstract
In this study, the authors examine the relationship between and the efficiency of different approaches to standard (univariate) differential power analysis (DPA) attacks. The authors first show that, when fed with the same assumptions about the target device (i.e. with the same leakage model), the most popular approaches such as using a distance-of-means test, correlation analysis and Bayes attacks are essentially equivalent in this setting. Differences observed in practice are not because of differences in the statistical tests but because of statistical artefacts. Then, the authors establish a link between the correlation coefficient and the conditional entropy in side-channel attacks. In a first-order attack scenario, this relationship allows linking currently used metrics to evaluate standard DPA attacks (such as the number of power traces needed to perform a key recovery) with an information theoretic metric (the mutual information). The authors results show that in the practical scenario defined formally in this study, both measures are equally suitable to compare devices with respect to their susceptibility to DPA attacks. Together with observations regarding key and algorithm independence the authors consequently extend theoretical strategies for the sound evaluation of leaking devices towards the practice of side-channel attacks.
Stefan Mangard, Elisabeth Oswald, François-Xavier Standaert
IET Inf. Secur.1
2010 The World Is Not Enough: Another Look on Second-Order DPA
François-Xavier Standaert, Nicolas Veyrat-Charvillon, Elisabeth Oswald, Benedikt Gierlichs, Marcel Medwed, Markus Kasper, Stefan Mangard
ASIACRYPT7
2010 On the Duality of Probing and Fault Attacks
Berndt M. Gammel, Stefan Mangard
J. Electron. Test.2
2009 Practical Attacks on Masked Hardware
Thomas Popp, Mario Kirschbaum, Stefan Mangard
CT-RSA3
2007 Protecting AES Software Implementations on 32-Bit Processors Against Power Analysis
Stefan Tillich, Christoph Herbst, Stefan Mangard
ACNS3
2007 Power and EM Attacks on Passive 13.56 MHz RFID Devices
Michael Hutter, Stefan Mangard, Martin Feldhofer
CHES2
2007 Evaluation of the Masked Logic Style MDPL on a Prototype Chip
Thomas Popp, Mario Kirschbaum, Thomas Zefferer, Stefan Mangard
CHES4
2007 Template Attacks on Masking - Resistance Is Futile
Elisabeth Oswald, Stefan Mangard
CT-RSA2
2006 An AES Smart Card Implementation Resistant to Power Analysis Attacks
Christoph Herbst, Elisabeth Oswald, Stefan Mangard
ACNS3
2006 Pinpointing the Side-Channel Leakage of Masked AES Hardware Implementations
Stefan Mangard, Kai Schramm
CHES1
2006 Practical Second-Order DPA Attacks for Masked Smart Card Implementations of Block Ciphers
Elisabeth Oswald, Stefan Mangard, Christoph Herbst, Stefan Tillich
CT-RSA2
2006 Side channel analysis resistant design flow
abstract
The threat of side-channel attacks (SCA) is of crucial importance when designing systems with cryptographic hardware or software. The FP6-funded project SCARD enhances the typical micro-chip design flow in order to provide a means for designing side-channel resistant circuits and systems. Appropriate SCA-simulation tools and SCA analysis for the designer of secure systems are part of the project goals. We consider these enhancements for traditional design flows of micro-chips as necessary in order to enable the design for the next generation of secure and dependable devices. SCARD is in its final phase, the final result a SCARD chip designed by using the developed design flow is currently implemented
Manfred Josef Aigner, Stefan Mangard, Francesco Menichelli, Renato Menicocci, Mauro Olivieri, Thomas Popp, Giuseppe Scotti, Alessandro Trifiletti
ISCAS2
2006 Implementation aspects of the DPA-resistant logic style MDPL
abstract
An important task when implementing cryptographic algorithms in hardware is to provide adequate protection against differential power analysis (DPA) attacks. During the last years, several countermeasures against these attacks have been proposed. One of them is a logic style called masked dual-rail pre-charged logic (MDPL). This article discusses several implementation aspects of this logic style. First, it is shown how MDPL circuits can be built using a semi-custom design flow. Subsequently, the area requirements, the speed, the power consumption and the DPA resistance of MDPL circuits are analyzed based on a case study. This case study shows that the power consumption of MDPL circuits is significantly higher than the one of corresponding CMOS circuits. Motivated by this observation, new low-power techniques for MDPL circuits are proposed. During the time when MDPL circuits do not perform operations that are critical for DPA attacks, the proposed low-power techniques reduce the power consumption of MDPL circuits by about a factor of four
Thomas Popp, Stefan Mangard
ISCAS2
2005 Successfully Attacking Masked AES Hardware Implementations
Stefan Mangard, Norbert Pramstaller, Elisabeth Oswald
CHES1
2005 Masked Dual-Rail Pre-charge Logic: DPA-Resistance Without Routing Constraints
Thomas Popp, Stefan Mangard
CHES2
2005 Side-Channel Leakage of Masked CMOS Gates
Stefan Mangard, Thomas Popp, Berndt M. Gammel
CT-RSA1
2005 A Side-Channel Analysis Resistant Description of the AES S-Box
Elisabeth Oswald, Stefan Mangard, Norbert Pramstaller, Vincent Rijmen
FSE2
2004 Hardware Countermeasures against DPA ? A Statistical Analysis of Their Effectiveness
Stefan Mangard
CT-RSA1
2003 A Highly Regular and Scalable AES Hardware Architecture
abstract
This article presents a highly regular and scalable AES hardware architecture, suited for full-custom as well as for semicustom design flows. Contrary to other publications, a complete architecture (even including CBC mode) that is scalable in terms of throughput and in terms of the used key size is described. Similarities of encryption and decryption are utilized to provide a high level of performance using only a relatively small area (10,799 gate equivalents for the standard configuration). This performance is reached by balancing the combinational paths of the design. No other published AES hardware architecture provides similar balancing or a comparable regularity. Implementations of the fastest configuration of the architecture provide a throughput of 241 Mbits/sec on a 0.6 /spl mu/m CMOS process using standard cells.
Stefan Mangard, Manfred Josef Aigner, Sandra Dominikus
IEEE Trans. Computers1
2001 A new approach to DNS security (DNSSEC)
abstract
The Domain Name System (DNS) is a distributed database that allows convenient storing and retrieving of resource records. DNS has been extended to provide security services (DNSSEC) mainly through public-key cryptography. We propose a new approach to DNSSEC that may result in a signicantly more ecient protocol. We introduce a new strategy to build chains of trust from root servers to authoritative servers. The techniques we employ are based on symmetric-key cryptography. Keywords Domain Name System Security (DNSSEC), Authentication Protocols, Digital Signatures, Symmetric Encryption 1.
Giuseppe Ateniese, Stefan Mangard
CCS2