EDBT 2026 Demo / reviewers in the wild / expert
Jean-Pierre Seifert
dblp:98/117
· DBLP profile ↗
105ranked-venue papers
2as first author
28since 2021 · last 2026
0000-0002-5372-4825ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 76 · 2 first-author · 24 since 2021Systems, architecture and hardware · 13 · 4 since 2021Theory of computation · 7Software engineering, systems software and programming languages · 6 · 1 since 2021Computer networks · 3Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Photons are Perfect, Protocols are Not: Cracking QKD BBM92 via the Internet
Kashyap Thimmaraju, Max Henri Julian Hiort, Darshit Suratwala, Elham Amini, Jean-Pierre Seifert |
ACNS (3) | 5 |
| 2025 | Three Glitches to Rule One Car: Fault Injection Attacks on a Connected EV
Niclas Kühnapfel, Christian Werling, Hans Niklas Jacob, Jean-Pierre Seifert |
AsiaCCS | 4 |
| 2025 | Solving Concealed ILWE and Its Application for Breaking Masked Dilithium
Simon Damm, Asja Fischer, Alexander May 0001, Soundes Marzougui, Leander Schwarz, Henning Seidler, Jean-Pierre Seifert, Jonas Thietke, Vincent Ulitzsch |
ASIACRYPT (2) | 7 |
| 2025 | Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary Bridgingabstract5G networks are designed with a clear separation between control and user planes, interfaces, and core functions—each expected to operate within isolated trust boundaries. When these boundaries are not properly enforced, malicious traffic from user equipment can traverse unintended paths and reach sensitive components. This work demonstrates how an attacker-controlled UE can exploit such weaknesses using protocol tunneling and network boundary bridging to bypass isolation and interact with internal elements of the 5G core. Altaf Shaik, Robert Jaschek, Jean-Pierre Seifert |
CCS | 3 |
| 2025 | From NOP to ADD and Beyond: A Novel Fault-Model Comprising Variable-Length Instruction SetsabstractFault Injection Attacks (FIAs) pose significant security threats to embedded devices, compromising the security of critical systems. Although the implications of Fault Injection (FI) are well understood for embedded platforms exhibiting Reduced Instruction Set Computer (RISC) architectures, Complex Instruction Set Computer (CISC) platforms have received much less attention in security research. Modern x86 processors employ variable-length instructions spanning 1 to 15 bytes, creating unique vulnerability patterns that remain largely unexplored in existing FI research.We present the first systematic study of Electro-Magnetic Fault Injection (EMFI) attacks against variable-length Instruction Set Architectures (ISAs), highlighting misalignment effects. Our research introduces a novel fault model that demonstrates how strategically induced bit flips in instruction opcodes cause decoder misalignment, ultimately leading to the execution of completely different code sequences. We provide proof-of-concept evidence on Intel N100 hardware, showing how EMFI can transform a NOP instruction sequence into an equivalent-length ADD sequence, demonstrating novel misalignment vulnerabilities specific to variable-length ISAs. Xhani Marvin Sas, Thomas Martin Johannes Lehrach, Jean-Pierre Seifert |
FDTC | 3 |
| 2025 | Photonic Side-Channel Analyzer: Enabling Security-Aware Physical Design Methodologyabstract74 Meizhi Wang, S. S. Teja Nibhanupudi, Elham Amini, Antonio Saavedra, Daniel Wasserman, Jean-Pierre Seifert, Jaydeep P. Kulkarni |
ISPD | 8 |
| 2024 | What All the PHUZZ Is About: A Coverage-guided Fuzzer for Finding Vulnerabilities in PHP Web ApplicationsabstractCoverage-guided fuzz testing has received significant attention from the research community, with a strong focus on binary applications, greatly disregarding other targets, such as web applications. The importance of the World Wide Web in everyone's life cannot be overstated, and to this day, many web applications are developed in PHP. In this work, we address the challenges of applying coverage-guided fuzzing to PHP web applications and introduce Phuzz, a modular fuzzing framework for PHP web applications. Phuzz uses novel approaches to detect more client-side and server-side vulnerability classes than state-of-the-art related work, including SQL injections, remote command injections, insecure deserialization, path traversal, external entity injection, cross-site scripting, and open redirection. We evaluate Phuzz on a diverse set of artificial and real-world web applications with known and unknown vulnerabilities, and compare it against a variety of state-of-the-art fuzzers. In order to show Phuzz' effectiveness, we fuzz over 1,000 API endpoints of the 115 most popular WordPress plugins, resulting in over 20 security issues and 2 new CVE-IDs. Finally, we make the framework publicly available to motivate and encourage further research on web application fuzz testing. Sebastian Neef, Lorenz Kleissner, Jean-Pierre Seifert |
AsiaCCS | 3 |
| 2024 | Whispering Pixels: Exploiting Uninitialized Register Accesses in Modern GPUsabstractGraphic Processing Units (GPUs) have transcended their traditional use-case of rendering graphics and nowadays also serve as a powerful platform for accelerating ubiquitous, non-graphical rendering tasks. One prominent task is inference of neural networks, which process vast amounts of personal data, such as audio, text or images. Thus, GPUs became integral components for handling vast amounts of potentially confidential data, which has awakened the interest of security researchers. This lead to the discovery of various vulnerabilities in GPUs in recent years. In this paper, we uncover yet another vulnerability class in GPUs: We found that some GPU implementations lack proper register initialization routines before shader execution, leading to unintended register content leakage of previously executed shader kernels. We showcase the existence of the aforementioned vulnerability on products of 3 major vendors - Apple, NVIDIA and Qualcomm. The vulnerability poses unique challenges to an adversary due to opaque scheduling and register remapping algorithms present in the GPU firmware, complicating the reconstruction of leaked data. In order to illustrate the real-world impact of this flaw, we showcase how these challenges can be solved for attacking various workloads on the GPU. First, we showcase how uninitialized registers leak arbitrary pixel data processed by fragment shaders. We further implement information leakage attacks on intermediate data of Convolutional Neural Networks (CNNs) and present the attack's capability to leak and reconstruct the output of Large Language Models (LLMs). Frederik Dermot Pustelnik, Xhani Marvin Saß, Jean-Pierre Seifert |
EuroS&P | 3 |
| 2024 | MAYo or MAY-not: Exploring Implementation Security of the Post-Quantum Signature Scheme MAYO Against Physical AttacksabstractMAYO is a multivariate signature scheme notable for its efficiency and compact key size. Targeting NIST security level I, MAYO features a public key size of 1168 bytes and a signature size of 321 bytes, making it more compact than leading lattice-based signature schemes like Falcon and Dilithium, thereby easing integration into embedded systems. With the deployment of MAYO in embedded systems, studying the resilience of MAYO implementations against fault injection attacks is of increasing importance. In this paper, we investigate the security of MAYO against fault injection attacks, and present the first end-to-end fault injection attack on the multivariate scheme. The attack introduces a loop-abort fault in the sampling of the vinegar vector. We present two variants: A zero-ing attack, in which the skipped sampling results in an all-zero vinegar vector, and a differential fault attack. In both variants, the faulted signature reveals an oil vector, allowing for full key recovery through techniques borrowed from the reconciliation attack in a few seconds. Thomas Aulbach, Soundes Marzougui, Jean-Pierre Seifert, Vincent Ulitzsch |
FDTC | 3 |
| 2024 | Security Testing The O-RAN Near-Real Time RIC & A1 InterfaceabstractOpen-Radio Access Network (O-RAN) is the next evolutionary step in mobile network architecture and operations and the Near-Real Time RAN Intelligent Controller (Near-RT RIC) plays a central role in the O-RAN architecture as it interfaces between the orchestration layer and next generation eNodeBs. In this paper we highlight the architectural weakness of a centralized controller in O-RAN by first drawing parallels with the Software-Defined Networking (SDN) controller. We then present a two part security evaluation of two open-source Near-RT RICs (μONOS and OSC), focused on the newly introduced A1 interface of the Near-RT RIC. In the first part of our evaluation, we evaluate the supply-chain risks of μONOS and OSC using off-the-shelf open-source dependency analysis and configuration file analysis tools. In the second part, we present our run-time security testing of the A1 API implemented by μONOS and OSC using our custom O-RAN A1 Interface Testing Tool (OAITT). Our supply-chain risk analysis shows that both the open-source Near-RT RICs we evaluated have multiple dependency risks and weak or insecure configurations. We identified 211 and 285 known dependency vulnerabilities in μONOS and OSC respectively of which 82 and 190 dependencies were rated as high CVSS respectively. The A1 interface contributed to a majority of the dependency risks in both Near-RT RICs. From a security misconfiguration perspective, we identified issues concerning access control, lack of encryption and poor secret management. Our run-time testing of OSC and μONOS revealed the following. First, both Near-RT RICs lack TLS for the A1 interface. Second, malicious Non-Real Time RAN Intelligent Controller (Non-RT RIC)s or rApps that reside in the Non-RT RIC could tamper with policies installed in the Near-RT RIC which can impact the availability of the O-RAN. Third, the A1 protocol could be exploited by Non-RT RICs for covert communication via the Near-RT RIC. Fourth, the A1 implementation by μONOS was vulnerable to degradation of service attacks (10-60s response time for GET requests) and a denial of service attack, the latter has been ethically reported and a fix is underway. Kashyap Thimmaraju, Altaf Shaik, Sunniva Flück, Pere Joan Fullana Mora, Christian Werling, Jean-Pierre Seifert |
WISEC | 6 |
| 2023 | faulTPM: Exposing AMD fTPMs' Deepest SecretsabstractTrusted Platform Modules (TPMs) constitute an integral building block of modern security features. Moreover, as Windows 11 made a TPM 2.0 mandatory, they are subject to an ever-increasing academic challenge. While discrete TPMs (dTPMs) – as found in higher-end systems – have been susceptible to attacks on their exposed communication interface, more common firmware TPMs (fTPMs) are immune to this attack vector as they do not communicate with the CPU via an exposed bus.In this paper, we analyze a new class of attacks against fTPMs: Attacking their Trusted Execution Environment (TEE) can lead to a full TPM state compromise. We experimentally verify this attack by compromising the AMD Secure Processor (AMD-SP), which constitutes the TEE for AMD’s fTPMs. In contrast to previous dTPM sniffing attacks, this vulnerability exposes the complete internal TPM state of the fTPM. It allows us to extract any cryptographic material stored or sealed by the fTPM regardless of authentication mechanisms such as Platform Configuration Register (PCR) validation or passphrases with anti-hammering protection. First, we demonstrate the impact of our findings by – to the best of our knowledge – enabling the first attack against Full Disk Encryption (FDE) solutions backed by an fTPM. Furthermore, we lay out how any application relying solely on the security properties of the TPM – like Bitlocker’s TPM-only protector – can be defeated by an attacker with 2-3 hours of physical access to the target device. Lastly, we analyze the impact of our attack on FDE solutions protected by a TPM and PIN strategy. While a naive implementation also leaves the disk completely unprotected, we find that BitLocker’s FDE implementation withholds some protection depending on the complexity of the used PIN. Our results show that when an fTPM’s internal state is compromised, a TPM and PIN strategy for FDE is less secure than TPM-less protection with a reasonable passphrase. Hans Niklas Jacob, Christian Werling, Robert Buhren, Jean-Pierre Seifert |
EuroS&P | 4 |
| 2023 | Breaking the Quadratic Barrier: Quantum Cryptanalysis of Milenage, Telecommunications' Cryptographic Backbone
Vincent Ulitzsch, Jean-Pierre Seifert |
PQCrypto | 2 |
| 2022 | Machine-Learning Side-Channel Attacks on the GALACTICS Constant-Time Implementation of BLISSabstractDue to the advancing development of quantum computers, practical attacks on conventional public-key cryptography may become feasible in the next few decades. To address this risk, post-quantum schemes that are assumed to be secure against quantum attacks are being developed. Lattice-based algorithms are promising replacements for conventional schemes, with BLISS being one of the earliest post-quantum signature schemes in this family. However, required subroutines such as Gaussian sampling have been demonstrated to be a risk for the security of BLISS, since implementing Gaussian sampling both efficient and secure with respect to physical attacks is challenging. Soundes Marzougui, Nils Wisiol, Patrick Gersch, Juliane Krämer, Jean-Pierre Seifert |
ARES | 5 |
| 2022 | Toward Optical Probing Resistant Circuits: A Comparison of Logic Styles and Circuit Design TechniquesabstractLaser-assisted side-channel analysis techniques, such as optical probing (OP), have been shown to pose a severe threat to secure hardware. While several countermeasures have been proposed in the literature, they can either be bypassed by an attacker or require a modification in the transistor's fabrication process, which is costly and complex. In this work, firstly, we propose a formulation for the caliber of reflected light from OP. Secondly, we propose circuit design techniques and logic styles to alleviate OP attacks based on our formulation. Finally, we compare several logic families and circuit design techniques in terms of performance and OP security merits. In this regard, we perform simulations to compare the optical beam interaction between the different logic gates. By utilizing our proposed circuit design techniques and dual-rail logic (DRL), the signal-to-noise ratio (SNR) of the reflected light from OP is reduced significantly. Sajjad Parvin, Thilo Krachenfels, Shahin Tajik, Jean-Pierre Seifert, Frank Sill, Rolf Drechsler |
ASP-DAC | 4 |
| 2022 | Cycle-Accurate Power Side-Channel Analysis Using the ChipWhisperer: A Case Study on Gaussian Sampling
Nils Wisiol, Patrick Gersch, Jean-Pierre Seifert |
CARDIS | 3 |
| 2022 | Profiling Side-Channel Attacks on Dilithium - A Small Bit-Fiddling Leak Breaks It All
Vincent Ulitzsch, Soundes Marzougui, Mehdi Tibouchi, Jean-Pierre Seifert |
SAC | 4 |
| 2022 | A Post-Quantum Secure Subscription Concealed Identifier for 6Gabstract5G saw the introduction of an encrypted user identifier, the Subscriber Concealed Identifier (SUCI), to provide confidentiality of the subscriber's whereabouts and identities. The SUCI protects the new generation of cellular networks against tracking devices, so-called IMSI-catchers, which have undermined users' confidentiality ever since the inception of cellular networks. However, the potential advent of large-scale quantum computers in the near future threatens to compromise the confidentiality provided by the SUCI yet again. The security of the public-key cryptography that underpins the SUCI relies on the hardness of the discrete logarithm problem. Using Shor's algorithm, a quantum adversary could break the SUCI's cryptography and once more gain the capability to track and identify users. Advancements in quantum computing are unpredictable, and a breakthrough might be only a decade away. Given the slow nature of standards and their implementation, it is thus necessary to already integrate now quantum-resistant cryptography into the current and also next-generation (6G) cellular networks. To contribute to this development, we propose a post-quantum secure scheme for the SUCI calculation, \textttKEMSUCI. To this end, we first analyze the weak points in the current SUCI calculation scheme when considering quantum attacks. We then describe an alternative SUCI calculation scheme based on post-quantum secure key-encapsulation mechanisms (KEMs). Our proposed scheme can use any of the KEMs submitted to the NIST call for standardization of post-quantum secure cryptography (PQC) schemes. For the usage in \textttKEMSUCI, the KEM should provide efficient execution on a SIM card and induce little network communication overhead. We evaluate all of the NIST PQC finalists under these aspects and identify Kyber and Saber as the best fit. Instantiated with these KEMs, \textttKEMSUCI can be integrated into 5G and 6G. Compared to the existing SUPI protection schemes, \textttKEMSUCI exhibits faster execution speed and only little communication overhead. Vincent Ulitzsch, Shinjo Park, Soundes Marzougui, Jean-Pierre Seifert |
WISEC | 4 |
| 2022 | Neural Network Modeling Attacks on Arbiter-PUF-Based DesignsabstractBy revisiting, improving, and extending recent neural-network based modeling attacks on XOR Arbiter PUFs from the literature, we show that XOR Arbiter PUFs, (XOR) Feed-Forward Arbiter PUFs, and Interpose PUFs can be attacked faster, up to larger security parameters, and with an order of magnitude fewer challenge-response pairs than previously known both in simulation and in silicon data. To support our claim, we discuss the differences and similarities of recently proposed modeling attacks and offer a fair comparison of the performance of these attacks by implementing all of them using the popular machine learning framework Keras and comparing their performance against the well-studied Logistic Regression attack. Our findings show that neural-network-based modeling attacks have the potential to outperform traditional modeling attacks on PUFs and must hence become part of the standard toolbox for PUF security analysis; the code and discussion in this paper can serve as a basis for the extension of our results to PUF designs beyond the scope of this work. Nils Wisiol, Bipana Thapaliya, Khalid T. Mursi, Jean-Pierre Seifert |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | VIA: Analyzing Device Interfaces of Protected Virtual MachinesabstractBoth AMD and Intel have presented technologies for confidential computing in cloud environments. The proposed solutions — AMD SEV (-ES, -SNP) and Intel TDX — protect VMs (VMs) against attacks from higher privileged layers through memory encryption and integrity protection. This model of computation draws a new trust boundary between virtual devices and the VM, which in so far lacks thorough examination. In this paper, we therefore present an analysis of the virtual device interface and discuss several attack vectors against a protected VM. Further, we develop and evaluate VIA, an automated analysis tool to detect cases of improper sanitization of input recieved via the virtual device interface. VIA improves upon existing approaches for the automated analysis of device interfaces in the following aspects: (i) support for virtualization relevant buses, (ii) efficient Direct Memory Access (DMA) support and (iii) performance. VIA builds upon the Linux Kernel Library and clang’s libfuzzer to fuzz the communication between the driver and the device via MMIO, PIO, and DMA. An evaluation of VIA shows that it performs 570 executions per second on average and improves performance compared to existing approaches by an average factor of 2706. Using VIA, we analyzed 22 drivers in Linux 5.10.0-rc6, thereby uncovering 50 bugs and initiating multiple patches to the virtual device driver interface of Linux. To prove our findings’ criticality under the threat model of AMD SEV and Intel TDX, we showcase three exemplary attacks based on the bugs found. The attacks enable a malicious hypervisor to corrupt the memory and gain code execution in protected VMs with SEV-ES and are theoretically applicable to SEV-SNP and TDX. Felicitas Hetzelt, Martin Radev, Robert Buhren, Mathias Morbitzer, Jean-Pierre Seifert |
ACSAC | 5 |
| 2021 | Free by Design: On the Feasibility of Free-Riding Attacks Against Zero-Rated Services
Julian Fietkau 0002, David Pascal Runge, Jean-Pierre Seifert |
CANS | 3 |
| 2021 | One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationabstractAMD Secure Encrypted Virtualization (SEV) offers protection mechanisms for virtual machines in untrusted environments through memory and register encryption. To separate security-sensitive operations from software executing on the main x86 cores, SEV leverages the AMD Secure Processor (AMD-SP). This paper introduces a new approach to attack SEV-protected virtual machines (VMs) by targeting the AMD-SP. We present a voltage glitching attack that allows an attacker to execute custom payloads on the AMD-SPs of all microarchitectures that support SEV currently on the market (Zen 1, Zen 2, and Zen 3). The presented methods allow us to deploy a custom SEV firmware on the AMD-SP, which enables an adversary to decrypt a VM's memory. Furthermore, using our approach, we can extract endorsement keys of SEV-enabled CPUs, which allows us to fake attestation reports or to pose as a valid target for VM migration without requiring physical access to the target host. Moreover, we reverse-engineered the Versioned Chip Endorsement Key (VCEK) mechanism introduced with SEV Secure Nested Paging (SEV-SNP). The VCEK binds the endorsement keys to the firmware version of TCB components relevant for SEV. Building on the ability to extract the endorsement keys, we show how to derive valid VCEKs for arbitrary firmware versions. With our findings, we prove that SEV cannot adequately protect confidential data in cloud environments from insider attackers, such as rogue administrators, on currently available CPUs. Robert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre Seifert |
CCS | 4 |
| 2021 | Predictive Cipher-Suite Negotiation for Boosting Deployment of New CiphersabstractDeployment of strong cryptographic ciphers for DNSSEC is essential for long term security of DNS. Unfortunately, due to the hurdles involved in adoption of new ciphers coupled with the limping deployment of DNSSEC, most domains use the weak RSA-1024 cipher. Elias Heftrig, Jean-Pierre Seifert, Haya Schulmann, Michael Waidner, Nils Wisiol |
CCS | 2 |
| 2021 | Nano Security: From Nano-Electronics to Secure SystemsabstractThe field of computer hardware stands at the verge of a revolution driven by recent breakthroughs in emerging nanodevices. “Nano Security” is a new Priority Program recently approved by DFG, the German Research Council. This initial-stage project initiative at the crossroads of nano-electronics and hardware-oriented security includes 11 projects with a total of 23 Principal Investigators from 18 German institutions. It considers the interplay between security and nano-electronics, focusing on a dichotomy which emerging nano-devices (and their architectural implications) have on system security. The projects within the Priority Program consider both: potential security threats and vulnerabilities stemming from novel nano-electronics, and innovative approaches to establishing and improving system security based on nano-electronics. This paper provides an overview of the Priority Program's overall philosophy and discusses the scientific objectives of its individual projects. Ilia Polian, Frank Altmann, Tolga Arul, Christian Boit, Ralf Brederlow, Lucas Davi, Rolf Drechsler, Nan Du 0004, Thomas Eisenbarth 0001, Tim Güneysu, Sascha Hermann, Matthias Hiller, Rainer Leupers, Farhad Merchant, Thomas Mussenbrock, Stefan Katzenbeisser 0001, Akash Kumar 0001, Wolfgang Kunz, Thomas Mikolajick, Vivek Pachauri, Jean-Pierre Seifert, Frank Sill, Jens Trommer |
DATE | 21 |
| 2021 | The Forgotten Threat of Voltage Glitching: A Case Study on Nvidia Tegra X2 SoCsabstractVoltage fault injection (FI) is a well-known attack technique that can be used to force faulty behavior in processors during their operation. Glitching the supply voltage can cause data value corruption, skip security checks, or enable protected code paths. At the same time, modern systems on a chip (SoCs) are used in security-critical applications, such as self-driving cars and autonomous machines. Since these embedded devices are often physically accessible by attackers, vendors must consider device tampering in their threat models. However, while the threat of voltage FI is known since the early 2000s, it seems as if vendors still forget to integrate countermeasures. This work shows how the entire boot security of an Nvidia SoC, used in Tesla’s autopilot and Mercedes-Benz’s infotainment system, can be circumvented using voltage FI. We uncover a hidden bootloader that is only available to the manufacturer for testing purposes and disabled by fuses in shipped products. We demonstrate how to re-enable this bootloader using FI to gain code execution with the highest privileges, enabling us to extract the bootloader’s firmware and decryption keys used in later boot stages. Using a hardware implant, an adversary might misuse the hidden bootloader to bypass trusted code execution even during the system’s regular operation. Otto Bittner, Thilo Krachenfels, Andreas Galauner, Jean-Pierre Seifert |
FDTC | 4 |
| 2021 | Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelabstractDue to its sound theoretical basis and practical efficiency, masking has become the most prominent countermeasure to protect cryptographic implementations against physical side-channel attacks (SCAs). The core idea of masking is to randomly split every sensitive intermediate variable during computation into at least t+1 shares, where t denotes the maximum number of shares that are allowed to be observed by an adversary without learning any sensitive information. In other words, it is assumed that the adversary is bounded either by the possessed number of probes (e.g., microprobe needles) or by the order of statistical analyses while conducting higher-order SCA attacks (e.g., differential power analysis). Such bounded models are employed to prove the SCA security of the corresponding implementations. Consequently, it is believed that given a sufficiently large number of shares, the vast majority of known SCA attacks are mitigated.In this work, we present a novel laser-assisted SCA technique, called Laser Logic State Imaging (LLSI), which offers an unlimited number of contactless probes, and therefore, violates the probing security model assumption. This technique enables us to take snapshots of hardware implementations, i.e., extract the logical state of all registers at any arbitrary clock cycle with a single measurement. To validate this, we mount our attack on masked AES hardware implementations and practically demonstrate the extraction of the full-length key in two different scenarios. First, we assume that the location of the registers (key and/or state) is known, and hence, their content can be directly read by a single snapshot. Second, we consider an implementation with unknown register locations, where we make use of multiple snapshots and a SAT solver to reveal the secrets. Thilo Krachenfels, Fatemeh Ganji, Amir Moradi 0001, Shahin Tajik, Jean-Pierre Seifert |
SP | 5 |
| 2021 | Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel Attacks
Thilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre Seifert |
USENIX Security Symposium | 4 |
| 2021 | Special Session: Physical Attacks through the Chip Backside: Threats, Challenges, and OpportunitiesabstractThis paper reviews the evolution of a powerful class of physical attacks against integrated circuits (ICs), developed initially for performing failure analysis (FA) from the IC backside. Over the last two decades, several publications have demonstrated the effectiveness of these techniques in bypassing the IC protection schemes and extracting the stored assets inside secure ICs. In this work, we take a fresh look at such hardware attacks from three different perspectives. First, we will discuss the potential threat of the attacks against modern technologies and demystify a set of wrong beliefs about the attacks' complexity. Second, we review some technical challenges of such attacks from a law enforcement agency's perspective for unraveling crimes and preventing further crimes by criminals involved. Finally, we give an insight into the future development of FA tools and the opportunities for designing effective countermeasures against attacks through the chip backside. Elham Amini, Kai Bartels, Christian Boit, Marius Eggert, Norbert Herfurth, Tuba Kiyan, Thilo Krachenfels, Jean-Pierre Seifert, Shahin Tajik |
VTS | 8 |
| 2021 | RNNIDS: Enhancing network intrusion detection systems through deep learning
Soroush M. Sohi, Jean-Pierre Seifert, Fatemeh Ganji |
Comput. Secur. | 2 |
| 2020 | Pitfalls in Machine Learning-based Adversary Modeling for Hardware SystemsabstractThe concept of the adversary model has been widely applied in the context of cryptography. When designing a cryptographic scheme or protocol, the adversary model plays a crucial role in the formalization of the capabilities and limitations of potential attackers. These models further enable the designer to verify the security of the scheme or protocol under investigation. Although being well established for conventional cryptanalysis attacks, adversary models associated with attackers enjoying the advantages of machine learning techniques have not yet been developed thoroughly. In particular, when it comes to composed hardware, often being security-critical, the lack of such models has become increasingly noticeable in the face of advanced, machine learning-enabled attacks. This paper aims at exploring the adversary models from the machine learning perspective. In this regard, we provide examples of machine learning-based attacks against hardware primitives, e.g., obfuscation schemes and hardware root-of-trust, claimed to be infeasible. We demonstrate that this assumption becomes however invalid as inaccurate adversary models have been considered in the literature. Fatemeh Ganji, Sarah Amir, Shahin Tajik, Domenic Forte, Jean-Pierre Seifert |
DATE | 5 |
| 2020 | Agamotto: Accelerating Kernel Driver Fuzzing with Lightweight Virtual Machine Checkpoints
Dokyung Song, Felicitas Hetzelt, Jonghwan Kim, Brent ByungHoon Kang, Jean-Pierre Seifert, Michael Franz |
USENIX Security Symposium | 5 |
| 2019 | Insecure Until Proven Updated: Analyzing AMD SEV's Remote AttestationabstractCloud computing is one of the most prominent technologies to host Internet services that unfortunately leads to an increased risk of data theft. Customers of cloud services have to trust the cloud providers, as they control the building blocks that form the cloud. This includes the hypervisor enabling the sharing of a single hardware platform among multiple tenants. Executing in a higher-privileged CPU mode, the hypervisor has direct access to the memory of virtual machines. While data at rest can be protected using well-known disk encryption methods, data residing in main memory is still threatened by a potentially malicious cloud provider. AMD Secure Encrypted Virtualization (SEV) claims a new level of protection in such cloud scenarios. AMD SEV encrypts the main memory of virtual machines with VM-specific keys, thereby denying the higher-privileged hypervisor access to a guest's memory. To enable the cloud customer to verify the correct deployment of his virtual machine, SEV additionally introduces a remote attestation protocol. This protocol is a crucial component of the SEV technology that can prove that SEV protection is in place and that the virtual machine was not subject to manipulation. This paper analyzes the firmware components that implement the SEV remote attestation protocol on the current AMD Epyc Naples CPU series. We demonstrate that it is possible to extract critical</> CPU-specific keys that are fundamental for the security of the remote attestation protocol. Building on the extracted keys, we propose attacks that allow a malicious cloud provider a complete circumvention of the SEV protection mechanisms. Although the underlying firmware issues were already fixed by AMD, we show that the current series of AMD Epyc CPUs, i.e., the Naples series, does not prevent the installation of previous firmware versions. We show that the severity of our proposed attacks is very high as no purely software-based mitigations are possible. This effectively renders the SEV technology on current AMD Epyc CPUs useless when confronted with an untrusted cloud provider. To overcome these issues, we also propose robust changes to the SEV design that allow future generations of the SEV technology to mitigate the proposed attacks. Robert Buhren, Christian Werling, Jean-Pierre Seifert |
CCS | 3 |
| 2019 | PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary
Dokyung Song, Felicitas Hetzelt, Dipanjan Das 0002, Chad Spensky, Yeoul Na, Stijn Volckaert, Giovanni Vigna, Christopher Krügel, Jean-Pierre Seifert, Michael Franz |
NDSS | 9 |
| 2019 | New vulnerabilities in 4G and 5G cellular access network protocols: exposing device capabilitiesabstractCellular devices support various technical features and services for 2G, 3G, 4G and upcoming 5G networks. For example, these technical features contain physical layer throughput categories, radio protocol information, security algorithm, carrier aggregation bands and type of services such as GSM-R, Voice over LTE etc. In the cellular security standardisation context, these technical features and network services termed as device capabilities and exchanged with the network during the device registration phase. In this paper, we study device capabilities information specified for 4G and 5G devices and their role in establishing security association between the device and network. Our research results reveal that device capabilities are exchanged with the network before the authentication stage without any protection and not verified by the network. Consequently, we present three novel classes of attacks exploiting unprotected device capabilities information in 4G and upcoming 5G networks - identification attacks, bidding down attacks, and battery drain attacks against cellular devices. We implement proof-of-concept attacks using low-cost hardware and software setup to evaluate their impact against commercially available 4G devices and networks. We reported identified vulnerabilities to the relevant standardisation bodies and provide countermeasure to mitigate device capabilities attacks in 4G and upcoming 5G networks. Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, Jean-Pierre Seifert |
WiSec | 4 |
| 2018 | Anomaly Detection Approaches for Secure Cloud Reference Architectures in Legal Metrology
Alexander Oppermann, Federico Grasso Toro, Florian Thiel, Jean-Pierre Seifert |
CLOSER | 4 |
| 2018 | Secure Cloud Computing: Risk Analysis for Secure Cloud Reference Architecture in Legal MetrologyabstractIn the field of Legal Metrology, a risk assessment is demanded by European directives for certain measuring instruments.In this paper, a previously published reference cloud architecture will be subjected to such an assessment to demonstrate its suitability for providing adequate software protection.A specially tailored and standardized method is used to identify essential threats and common attack vectors for the reference architecture.With the help of calculated probability score and risk factors, the fulfillment of the essential requirements of the applicable European directives are shown.Furthermore, Attack Probability Trees are applied to more complex scenarios to identify suitable countermeasures to increase the resilience level where necessary. Alexander Oppermann, Marko Esche, Florian Thiel, Jean-Pierre Seifert |
FedCSIS | 4 |
| 2018 | On the Impact of Rogue Base Stations in 4G/LTE Self Organizing NetworksabstractMobile network operators choose Self Organizing Network (SON) concept as a cost-effective method to deploy LTE/4G networks and meet user expectations for high quality of service and bandwidth. The main objective of SON is to introduce automation into network management activities and reduce human intervention. SON enabled LTE networks heavily rely on the information acquired from mobile phones to provide self-configuration, self-optimization, and self-healing features. However, mobile phones can be attacked over-the-air using rogue base stations. In this paper, we carefully study SON related LTE/4G security specifications and reveal several vulnerabilities. Our key idea is to introduce a rogue eNodeB that uses legitimate mobile devices as a covert channel to launch attacks against SON enabled LTE networks. Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, Jean-Pierre Seifert |
WISEC | 4 |
| 2018 | Peeking Over the Cellular Walled Gardens - A Method for Closed Network Diagnosis -abstractA cellular network is a closed system, and each network operator has built a unique “walled garden” for their network by combining different operation policies, network configurations, and implementation optimizations. Unfortunately, some of these combinations can induce performance degradation due to misconfiguration or unnecessary procedures. To detect such degradation, a thorough understanding of even the minor details of the standards and operator-specific implementations is important. However, it is difficult to detect such problems, as the control plane is complicated by numerous procedures. This paper introduces a simple yet powerful method that diagnoses these problems by exploiting the operator-specific implementations of cellular networks. We develop a signaling collection and analysis tool that collects control plane messages from operators and finds problems through comparative analysis. The analysis process consists of three different control plane comparison procedures that can find such problems effectively. These individual procedures use a time threshold, control flow sequence, and signaling failure as the basis for comparison. To this end, we collect approximately 3.1 million control-plane messages from 13 major cellular operators worldwide. As a case study, we analyze the circuit-switched fallback technology that triggers generation crossover between third generation and long-term evolution technologies. Byeongdo Hong, Shinjo Park, Dongkwan Kim 0001, Hyunwook Hong, Hyunwoo Choi, Jean-Pierre Seifert, Sung-Ju Lee 0001, Yongdae Kim |
IEEE Trans. Mob. Comput. | 7 |
| 2017 | On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAsabstractModern Integrated Circuits (ICs) employ several classes of countermeasures to mitigate physical attacks. Recently, a powerful semi-invasive attack relying on optical contactless probing has been introduced, which can assist the attacker in circumventing the integrated countermeasures and probe the secret data on a chip. This attack can be mounted using IC debug tools from the backside of the chip. The first published attack based on this technique was conducted against a proof-of-concept hardware implementation on a Field Programmable Gate Array (FPGA). Therefore, the success of optical probing techniques against a real commercial device without any knowledge of the hardware implementation is still questionable. The aim of this work is to assess the threat of optical contactless probing in a real attack scenario. To this end, we conduct an optical probing attack against the bitstream encryption feature of a common FPGA. We demonstrate that the adversary is able to extract the plaintext data containing sensitive design information and intellectual property (IP). In contrast to previous optical attacks from the IC backside, our attack does not require any device preparation or silicon polishing, which makes it a non-invasive attack. Additionally, we debunk the myth that small technology sizes are unsusceptible to optical attacks, as we use an optical resolution of about 1 um to successfully attack a 28 nm device. Based on our time measurements, an attacker needs less than 10 working days to conduct the optical analysis and reverse-engineer the security-related parts of the hardware. Finally, we propose and discuss potential countermeasures, which could make the attack more challenging. Shahin Tajik, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit |
CCS | 3 |
| 2017 | Fault Attacks on Encrypted General Purpose Compute PlatformsabstractAdversaries with physical access to a target platform can perform cold boot or DMA attacks to extract sensitive data from the RAM. To prevent such attacks, hardware vendors announced respective processor extensions. AMD's extension SME will provide means to encrypt the RAM to protect security-relevant assets that reside there. The encryption will protect the user's content against passive eavesdropping. However, the level of protection it provides in scenarios that involve an adversary who cannot only read from RAM but also change content in RAM is less clear. This paper addresses the open research question whether encryption alone is a dependable protection mechanism in practice when considering an active adversary. To this end, we first build a software based memory encryption solution on a desktop system which mimics AMD's SME. Subsequently, we demonstrate a proof-of-concept fault attack on this system, by which we are able to extract the private RSA key of a GnuPG user. Our work suggests that transparent memory encryption is not enough to prevent active attacks. Robert Buhren, Shay Gueron, Jan Nordholz, Jean-Pierre Seifert, Julian Vetter |
CODASPY | 4 |
| 2017 | PUFMon: Security monitoring of FPGAs using physically unclonable functionsabstractMainstream FPGAs and programmable SoCs employ different countermeasures during configuration and runtime to mitigate physical attacks. However, it has been demonstrated that sophisticated active attack techniques, such as laser voltage probing, can still bypass the bitstream protections during the configuration phase. On the other hand, although the security monitoring IP cores provided by FPGA vendors can ensure the physical security during the runtime of applications, they are unable to detect such attacks during configuration. In this work, we propose a novel approach to using PUFs as physical sensors to monitor the integrity of FPGAs against active attacks. Small modifications in existing PUF architectures enable us to design a PUF-based security scheme, which can be deployed for integrity monitoring and authentication/key generation at the same time. We evaluate the effectiveness of our framework against a range of powerful attacks, such as optical probing and fault attacks. We further discuss how this scheme can be deployed during bitstream configuration in FPGAs with partial reconfiguration capability. Shahin Tajik, Julian Fietkau 0002, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit |
IOLTS | 4 |
| 2017 | Static Program Analysis as a Fuzzing Aid
Bhargava Shastry, Markus Leutner, Tobias Fiebig, Kashyap Thimmaraju, Fabian Yamaguchi, Konrad Rieck, Stefan Schmid 0001, Jean-Pierre Seifert, Anja Feldmann |
RAID | 8 |
| 2017 | Photonic Side-Channel Analysis of Arbiter PUFs
Shahin Tajik, Enrico Dietz, Sven Frohmann, Helmar Dittrich, Dmitry Nedospasov, Clemens Helfmeier, Jean-Pierre Seifert, Christian Boit, Heinz-Wilhelm Hübers |
J. Cryptol. | 7 |
| 2016 | Strong Machine Learning Attack Against PUFs with No Mathematical Model
Fatemeh Ganji, Shahin Tajik, Fabian Fäßler, Jean-Pierre Seifert |
CHES | 4 |
| 2016 | No Place to Hide: Contactless Probing of Secret Data on FPGAs
Heiko Lohrke, Shahin Tajik, Christian Boit, Jean-Pierre Seifert |
CHES | 4 |
| 2016 | Secure Cloud Reference Architectures for Measuring Instruments under Legal ControlabstractCloud Computing has been a trending topic for years now and it seems it has finally become mature enough
for widespread commercial application. In this paper, the authors describe their approach to establish a secure
cloud architecture which conforms to the Measuring Instruments Directive of the European Union while keeping
the flexibility and benefits that cloud computing promises for companies and customers alike. The authors
introduce a modular concept of a secure cloud system architecture which will ensure cross-virtual machine
collaboration and a legitimate, secure and protected flow of measurement data. Alexander Oppermann, Jean-Pierre Seifert, Florian Thiel |
CLOSER (1) | 2 |
| 2016 | Towards Vulnerability Discovery Using Staged Program Analysis
Bhargava Shastry, Fabian Yamaguchi, Konrad Rieck, Jean-Pierre Seifert |
DIMVA | 4 |
| 2016 | Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems
Altaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan, Valtteri Niemi |
NDSS | 2 |
| 2015 | Lattice Basis Reduction Attack against Physically Unclonable FunctionsabstractDue to successful modeling attacks against arbiter PUFs (Physically Unclonable Functions), the trend towards consideration of XOR arbiter PUFs has emerged. Nevertheless, it has already been demonstrated that even this new non-linear structure, with a restricted number of parallel arbiter chains, is still vulnerable to more advanced modeling attacks and side channel analyses. However, so far the security of XOR arbiter PUFs with a large number of parallel arbiter chains has not been appropriately assessed. Furthermore, as another countermeasure against modeling and physical attacks, the concept of controlled PUFs, i.e., with a limited access to challenges and responses, has also been developed. Towards a better understanding of the security of XOR arbiter PUFs, the present paper simultaneously addresses all above mentioned countermeasures by introducing a novel attack, which is a combination of a lattice basis reduction attack and a photonic side channel analysis. We present how our new attack can be successfully launched against XOR arbiter PUFs with an arbitrarily large number of parallel arbiter chains. Most interestingly, our attack does not require any access to challenges or responses. Finally, by conducting an exhaustive discussion on our experimental results, the practical feasibility of our attack scenario is proved as well. Fatemeh Ganji, Juliane Krämer, Jean-Pierre Seifert, Shahin Tajik |
CCS | 3 |
| 2015 | Laser Fault Attack on Physically Unclonable FunctionsabstractPhysically Unclonable Functions (PUFs) are introduced to remedy the shortcomings of traditional methods of secure key storage and random key generation on Integrated Circuits (ICs). Due to their effective and low-cost implementations, intrinsic PUFs are popular PUF instances employed to improve the security of different applications on reconfigurable hardware. In this work we introduce a novel laser fault injection attack on intrinsic PUFs by manipulating the configuration of logic cells in a programable logic device. We present two fault attack scenarios, where not only the effectiveness of modeling attacks can be dramatically increased, but also the entropy of the targeted PUF responses are drastically decreased. In both cases, we conduct detailed theoretical analyses by considering XOR arbiter PUFs and RO PUFs as the examples of PUF-based authenticators and PUF-based random key generators, respectively. Finally we present our experimental results based on conducting laser fault injection on real PUFs, implemented on a common complex programmable logic device manufactured in 180 nm technology. Shahin Tajik, Heiko Lohrke, Fatemeh Ganji, Jean-Pierre Seifert, Christian Boit |
FDTC | 4 |
| 2014 | The role of photons in cryptanalysisabstractPhotons can be exploited to reveal secrets of security ICs like smartcards, secure microcontrollers, and cryptographic coprocessors. One such secret is the secret key of cryptographic algorithms. This work gives an overview about current research on revealing these secret keys by exploiting the photonic side channel. Different analysis methods are presented. It is shown that the analysis of photonic emissions also helps to gain knowledge about the attacked device and thus poses a threat to modern security ICs. The presented results illustrate the differences between the photonic and other side channels, which do not provide fine-grained spatial information. It is shown that the photonic side channel has to be addressed by software engineers and during chip design. Juliane Krämer, Michael Kasper, Jean-Pierre Seifert |
ASP-DAC | 3 |
| 2014 | Paradigm shift in IPTV service generation: Comparison between locally- and Cloud-rendered IPTV UIabstractThis paper introduces a novel and fundamental change in the creation and delivery of media services like IP Television (IPTV) through the idea of the so-called virtual SetTop Box (vSTB). By shifting most of the service execution environment - e.g. the Web browser - to a Cloud infrastructure, the vSTB concept addresses certain limitations of current IPTV deployments. Nevertheless, routing UI delivery out of the Cloud causes a significant impact on the network infrastructure, which might have some implications for IPTV system response and can therefore result in a lower Quality of Experience overall. This paper describes this approach and its current implementation, as well as identifying and addressing network challenges that emerged in a corresponding project in the Telekom Innovation Laboratories. Furthermore, this paper provides a comparison between IPTV service executed locally on an end-user device (locally-rendered IPTV UI), and that delivered to an end-user after it was executed within the cloud (Cloud-rendered IPTV UI) and empirically shows the feasibility of the presented vSTB Approach. Alexandra Mikityuk, Jean-Pierre Seifert, Oliver Friedrich |
CCNC | 2 |
| 2014 | Physical Characterization of Arbiter PUFs
Shahin Tajik, Enrico Dietz, Sven Frohmann, Jean-Pierre Seifert, Dmitry Nedospasov, Clemens Helfmeier, Christian Boit, Helmar Dittrich |
CHES | 4 |
| 2014 | Physical vulnerabilities of Physically Unclonable FunctionsabstractIn recent years one of the most popular areas of research in hardware security has been Physically Unclonable Functions (PUF). PUFs provide primitives for implementing tamper detection, encryption and device fingerprinting. One particularly common application is replacing Non-volatile Memory (NVM) as key storage in embedded devices like smart cards and secure microcontrollers. Though a wide array of PUF have been demonstrated in the academic literature, vendors have only begun to roll out PUFs in their end-user products. Moreover, the improvement to overall system security provided by PUFs is still the subject of much debate. This work reviews the state of the art of PUFs in general, and as a replacement for key storage in particular. We review also techniques and methodologies which make the physical response characterization and physical/digital cloning of PUFs possible. Clemens Helfmeier, Christian Boit, Dmitry Nedospasov, Shahin Tajik, Jean-Pierre Seifert |
DATE | 5 |
| 2014 | Emission Analysis of Hardware ImplementationsabstractToday, hardware implementations are the basis for many security applications, such as cryptographic ciphers. Such applications are realized using complex combinatorial logic circuits of substantial size. Therefore, understanding the gate-level implementation can be crucial for the attacker. However, Hardware Description Language (HDL) behavioral models and gate-level net list are seldom available for a particular design. Executing software directly on the device to assist in understanding the implementation is one potential solution. However, this may either be infeasible or completely impossible in practice as target devices may be incapable of executing code. Currently, few works have proposed forms of dynamic gate-level analysis of the actual hardware implementations. Moreover, current reverse-engineering techniques based on physical delayering and optical imaging cannot be applied to programmable logic. In this work we present the first dynamic emission analysis of a hardware implementation. This technique does not require any prior knowledge about the target device. Furthermore, it does not require code to be executed by the target. Hardware implementations consist of basic primitives that form the building blocks of complex hardware functions. By individually analyzing each primitive and correlating the corresponding optical images, the emission fingerprint of each primitive can be identified. As a result the hardware implementation of the device can be reconstructed. We present practical results for a common Complex Programmable Logic Device (CPLD). However, the same approach can be applied to hardware implementations in general. Shahin Tajik, Dmitry Nedospasov, Clemens Helfmeier, Jean-Pierre Seifert, Christian Boit |
DSD | 4 |
| 2014 | A Practical Second-Order Fault Attack against a Real-World Pairing ImplementationabstractSeveral fault attacks against pairing-based cryptography have been described theoretically in recent years. Interestingly, none of these has been practically evaluated. We accomplish this task and prove that fault attacks against pairing-based cryptography are indeed possible and even practical - thus posing a serious threat. Moreover, we successfully conduct a second-order fault attack against an open source implementation of the eta pairing on an AVR XMEGA A1. We inject the first fault into the computation of the Miller Algorithm and apply the second fault to completely skip the final exponentiation. We introduce a low-cost setup that allows us to generate multiple independent faults in one computation. The setup implements these faults by clock glitches which induce instruction skips. With this setup we conducted the first practical fault attack against a complete pairing computation. Johannes Blömer, Ricardo Gomes da Silva, Peter Günther 0001, Juliane Krämer, Jean-Pierre Seifert |
FDTC | 5 |
| 2014 | Design and Implementation of Efficient Integrity Protection for Open Mobile PlatformsabstractThe security of mobile devices such as cellular phones and smartphones has gained extensive attention due to their increasing usage in people's daily life. The problem is challenging as the computing environments of these devices have become more open and general-purpose while at the same time they have the constraints of performance and user experience. We propose and implement SEIP, a simple and efficient but yet effective solution for the integrity protection of real-world cellular phone platforms, which is motivated by the disadvantages of applying traditional integrity models on these performance and user experience constrained devices. The major security objective of SEIP is to protect trusted services and resources (e.g., those belonging to cellular service providers and device manufacturers) from third-party code. We propose a set of simple integrity protection rules based upon open mobile operating system environments and application behaviors. Our design leverages the unique features of mobile devices, such as service convergence and limited permissions of user installed applications, and easily identifies the borderline between trusted and untrusted domains on mobile platforms. Our approach, thus, significantly simplifies policy specifications while still achieves a high assurance of platform integrity. SEIP is deployed within a commercially available Linux-based smartphone and demonstrates that it can effectively prevent certain malware. The security policy of our implementation is less than 20 kB, and a performance study shows that it is lightweight. Xinwen Zhang, Jean-Pierre Seifert, Onur Aciiçmez |
IEEE Trans. Mob. Comput. | 2 |
| 2013 | Third international workshop on trustworthy embedded devices (TrustED 2013)abstractCyber physical systems (CPS) feature a tight combination of and coordination between the system's computational and physical elements. A current NIST report estimates that "by the end of the decade, embedded networking and computing components are projected to account for more than half of the value share in diverse sectors, including automotive, consumer electronics, avionics and aerospace, manufacturing, telecommunications, intelligent buildings, and health and medical equipment" and further conjectures that "future applications of CPS are more transformative than the IT revolution of the past three decades". While the increasing proliferation of embedded systems in general and CPS in particular provide a variety of new possibilities, new risks and challenges emerge. Due to the strong interdisciplinary character, advancement in CPS requires a new systems science that encompasses both physical and computational aspects. Frederik Armknecht, Jean-Pierre Seifert |
CCS | 2 |
| 2013 | Breaking and entering through the siliconabstractAs the surplus market of failure analysis equipment continues to grow, the cost of performing invasive IC analysis continues to diminish. Hardware vendors in high-security applications utilize security by obscurity to implement layers of protection on their devices. High-security applications must assume that the attacker is skillful, well-equipped and well-funded. Modern security ICs are designed to make readout of decrypted data and changes to security configuration of the device impossible. Countermeasures such as meshes and attack sensors thwart many state of the art attacks. Because of the perceived difficulty and lack of publicly known attacks, the IC backside has largely been ignored by the security community. However, the backside is currently the weakest link in modern ICs because no devices currently on the market are protected against fully-invasive attacks through the IC backside. Fully-invasive backside attacks circumvent all known countermeasures utilized by modern implementations. In this work, we demonstrate the first two practical fully-invasive attacks against the IC backside. Our first attack is fully-invasive backside microprobing. Using this attack we were able to capture decrypted data directly from the data bus of the target IC's CPU core. We also present a fully invasive backside circuit edit. With this attack we were able to set security and configuration fuses of the device to arbitrary values. Clemens Helfmeier, Dmitry Nedospasov, Christopher Tarnovsky, Starbug, Christian Boit, Jean-Pierre Seifert |
CCS | 6 |
| 2013 | SMS-Based One-Time Passwords: Attacks and Defense - (Short Paper)
Collin Mulliner, Ravishankar Borgaonkar, Patrick Stewin, Jean-Pierre Seifert |
DIMVA | 4 |
| 2013 | Invasive PUF AnalysisabstractIn this work we consider the suitability of Phyiscaly Unclonable Functions (PUFs) for high-security applications. For PUFs to be considered secure in such scenarios they must be resilient to both semi-invasive and fully-invasive attacks. We introduce a new failure analysis technique for semi-invasive, single-trace, backside readout of logic states. We apply this technique to characterize the unique physical response of a memory-based PUF. With these results we identify several weakness in current PUF schemes. We extend current PUF definitions to be resilient against such attacks by requiring that PUFs be implemented in a serialized manner. Finally, we improve already existing PUF architectures to include these concepts. Dmitry Nedospasov, Jean-Pierre Seifert, Clemens Helfmeier, Christian Boit |
FDTC | 2 |
| 2013 | Let Me Answer That for You: Exploiting Broadcast Information in Cellular Networks
Nico Golde, Kevin Redon, Jean-Pierre Seifert |
USENIX Security Symposium | 3 |
| 2013 | Architecting against Software Cache-Based Side-Channel AttacksabstractUsing cache-like architectural components including data caches, instruction caches, or branch target buffers as a side channel, software cache-based side-channel attacks are able to derive secret keys used in cryptographic operations through legitimate software activities. Existing software solutions are typically application specific and incur substantial performance overhead. Recent hardware proposals against attacks on data caches, although effective in reducing performance overhead, may still be vulnerable to advanced attacks. Furthermore, efficient defenses against attacks on other cache structures, including instruction caches and branch target buffers, are missing. In this paper, we propose hardware-software integrated approaches to defend against software cache-based attacks comprehensively. For attacks on data caches, we propose to use preloading, informing loads, and informing loads with software random permutation to secure the partition-locked cache (PLcache), the random permutation (RPcache) and regular caches, respectively. These approaches present different tradeoffs between hardware complexity and performance overhead. To defend against attacks on instruction caches, we show that the PLcache with preloading and the RPcache provide good protection. To defend against attacks based on branch target buffers, we propose to adopt a new update policy to eliminate potential information leaking. Our experiments show that the proposed schemes not only provide strong security protection but also incur small performance overhead. Jingfei Kong, Onur Aciiçmez, Jean-Pierre Seifert, Huiyang Zhou |
IEEE Trans. Computers | 3 |
| 2012 | Simple Photonic Emission Analysis of AES - Photonic Side Channel Analysis for the Rest of Us
Alexander Schlösser, Dmitry Nedospasov, Juliane Krämer, Susanna Orlic, Jean-Pierre Seifert |
CHES | 5 |
| 2012 | Taming Mr Hayes: Mitigating signaling based attacks on smartphonesabstractMalicious injection of cellular signaling traffic from mobile phones is an emerging security issue. The respective attacks can be performed by hijacked smartphones and by malware resident on mobile phones. Until today there are no protection mechanisms in place to prevent signaling based attacks other than implementing expensive additions to the cellular core network. In this work we present a protection system that resides on the mobile phone. Our solution works by partitioning the phone software stack into the application operating system and the communication partition. The application system is a standard fully featured Android system. On the other side, communication to the cellular network is mediated by a flexible monitoring and enforcement system running on the communication partition. We implemented and evaluated our protection system on a real smartphone. Our evaluation shows that it can mitigate all currently known signaling based attacks and in addition can protect users from cellular Trojans. Collin Mulliner, Steffen Liebergeld, Jean-Pierre Seifert |
DSN | 4 |
| 2012 | Structure-Based RSA Fault Attacks
Benjamin Michéle, Juliane Krämer, Jean-Pierre Seifert |
ISPEC | 3 |
| 2012 | Remote Attestation with Domain-Based Integrity Model and Policy AnalysisabstractWe propose and implement an innovative remote attestation framework called DR@FT for efficiently measuring a target system based on an information flow-based integrity model. With this model, the high integrity processes of a system are first measured and verified, and these processes are then protected from accesses initiated by low integrity processes. Toward dynamic systems with frequently changed system states, our framework verifies the latest state changes of a target system instead of considering the entire system information. Our attestation evaluation adopts a graph-based method to represent integrity violations, and the graph-based policy analysis is further augmented with a ranked violation graph to support high semantic reasoning of attestation results. As a result, DR@FT provides efficient and effective attestation of a system's integrity status, and offers intuitive reasoning of attestation results for security administrators. Our experimental results demonstrate the feasibility and practicality of DR@FT. Wenjuan Xu, Xinwen Zhang, Hongxin Hu, Gail-Joon Ahn, Jean-Pierre Seifert |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2011 | Poster: Towards detecting DMA malware
Patrick Stewin, Jean-Pierre Seifert, Collin Mulliner |
CCS | 2 |
| 2011 | Security analysis of a femtocell deviceabstractMobile network operators are adapting femtocells in order to simplify their network architecture for increased coverage, performance, and greater revenue opportunities. While emerging as a new low-cost technology which assures best connectivity, it has also introduced a range of new potential security risks for the mobile network operators. In this paper, we analyze these security issues and demonstrate the weaknesses of femtocell security. We demonstrate several security flaws that allowing attackers to gain root access and to install malicious applications on the femtocell. Furthermore, we experimentally evaluate and show a wide range of possible threats to femtocell; including compromise of femtocell credentials; physical, configuration, and protocol attacks; user data and identity privacy attacks. The vulnerabilities we found suggest that commercial-available femtocells fail to fulfill 3GPP security requirements and could expose operator network elements to the attacker. Our findings and successful attacks exhibit the need for further research to bridge the gap between theoretical and practical security of femtocell devices. Ravishankar Borgaonkar, Kevin Redon, Jean-Pierre Seifert |
SIN | 3 |
| 2011 | SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale
Collin Mulliner, Nico Golde, Jean-Pierre Seifert |
USENIX Security Symposium | 3 |
| 2011 | Dependable multimedia communications: Systems, services, and applications
Han-Chieh Chao, Jean-Pierre Seifert, Shiguo Lian, Liang Zhou 0002 |
J. Netw. Comput. Appl. | 2 |
| 2010 | In God we trust all others we monitorabstractModern x86 platforms offer stealth capabilities, that are exploited by rootkits to hide malicious code as shown by the rootkit evolution. Recently, security researchers discovered a very powerful execution environment for rootkits that is isolated from the actual x86 host platform. According to the capabilities of the isolated environment the researches called it "ring -3". Security mechanisms, such as antivirus software, cannot reveal "ring -3" rootkits, since they are executed in the operating system which makes them unable to access "ring -3". Patrick Stewin, Jean-Pierre Seifert |
CCS | 2 |
| 2010 | DR@FT: Efficient Remote Attestation Framework for Dynamic Systems
Wenjuan Xu, Gail-Joon Ahn, Hongxin Hu, Xinwen Zhang, Jean-Pierre Seifert |
ESORICS | 5 |
| 2010 | SEIP: Simple and Efficient Integrity Protection for Open Mobile Platforms
Xinwen Zhang, Jean-Pierre Seifert, Onur Aciiçmez |
ICICS | 2 |
| 2010 | pBMDS: a behavior-based malware detection system for cellphone devicesabstractComputing environments on cellphones, especially smartphones, are becoming more open and general-purpose, thus they also become attractive targets of malware. Cellphone malware not only causes privacy leakage, extra charges, and depletion of battery power, but also generates malicious traffic and drains down mobile network and service capacity. In this work we devise a novel behavior-based malware detection system named pBMDS, which adopts a probabilistic approach through correlating user inputs with system calls to detect anomalous activities in cellphones. pBMDS observes unique behaviors of the mobile phone applications and the operating users on input and output constrained devices, and leverages a Hidden Markov Model (HMM) to learn application and user behaviors from two major aspects: process state transitions and user operational patterns. Built on these, pBDMS identifies behavioral differences between malware and human users. Through extensive experiments on major smartphone platforms, we show that pBMDS can be easily deployed to existing smartphone hardware and it achieves high detection accuracy and low false positive rates in protecting major applications in smartphones. Liang Xie 0002, Xinwen Zhang, Jean-Pierre Seifert, Sencun Zhu |
WISEC | 3 |
| 2009 | A Secure DVB Set-Top Box via Trusting Computing TechnologiesabstractrdquoThis paper presents a very natural "killer applcation" of modern Commercially Off The Shelf (COTS) available Trusted Computing technologies. The application which we propose is a secure and cost optimized DVB Set-top Box. Our respective reference architecture is exclusively build upon such COTS Trusted Computing technologies and completely avoids the use of any proprietary and thus expensive hardware. Particularly, we will use an orchestration of the following TC concepts from the PC field and standardized by the Trusted Computing Group: Secure Boot, Remote Attestation, Trusted Channels, Virtualization for Domain Isolation, and the Trusted Platform Module (TPM). The Trusted Domain Isolation concept (as realized through Trusted Virtualization) allows the simple subscription to different Service Providers (SP) without the need of any SP-specific hardware requirements. The vast computing power of modern CPU architectures allows for the pure software virtualization of any SP-proprietary hardware. In addition to that isolation concept, the novel hardware assisted security ingredients of modern CPUs allow in combination with the TPM for a verifiable evidence of a tamper-free execution environment for the different SP's. I.e., at all times during the execution of a SP's "virtual set-top box", the respective SP is able to remotely request an attestation of the whole execution platform and ensure its fundamental system integrity. This attestation proves either that no "malicous platform tampering" or "unintended platform use" is happening, or in case that it fails, it gives the SP the possibility to deny further services by simply cutting the content delivery channel. Thus, at all times we can guarantee the various SP's strong security assurances. Moreover, the nowadays very well understood and very efficient (even real-time capable!) virtualization concept allows a simple and efficient migration of different SP architectures to such a universal DVB Set-top Box. In some cases a simple binary migration with only little modifications might be possible. Also, our architecture inherently supports the easy integration of an open but strongly isolated user partition, thus allowing the user for a kind of his own PC within his home TV and Set-top Box combination. Moreover, this also allows for an elegant realization of very recent initiatives aiming to merge the home TV experience with the full Web experience (e.g. See'N'Search [27]). In addition to being a very natural killer application of such Trusted Computing. Onur Aciiçmez, Jean-Pierre Seifert, Xinwen Zhang |
CCNC | 2 |
| 2009 | Hardware-software integrated approaches to defend against software cache-based side channel attacksabstractSoftware cache-based side channel attacks present serious threats to modern computer systems. Using caches as a side channel, these attacks are able to derive secret keys used in cryptographic operations through legitimate activities. Among existing countermeasures, software solutions are typically application specific and incur substantial performance overhead. Recent hardware proposals including the partition-locked cache (PLcache) and random-permutation cache (RPcache) (Wang and Lee, 2007), although very effective in reducing performance overhead while enhancing the security level, may still be vulnerable to advanced cache attacks. In this paper, we propose three hardware-software approaches to defend against software cache-based attacks - they present different tradeoffs between hardware complexity and performance overhead. First, we propose to use preloading to secure the PLcache. Second, we leverage informing loads, which is a lightweight architectural support originally proposed to improve memory performance, to protect the RPcache. Third, we propose novel software permutation to replace the random permutation hardware in the RPcache. This way, regular caches can be protected with hardware support for informing loads. In our experiments, we analyze various processor models for their vulnerability to cache attacks and demonstrate that even to the processor model that is most vulnerable to cache attacks, our proposed software-hardware integrated schemes provide strong security protection. Jingfei Kong, Onur Aciiçmez, Jean-Pierre Seifert, Huiyang Zhou |
HPCA | 3 |
| 2009 | On the Impossibility of Detecting Virtual Machine Monitors
Shay Gueron, Jean-Pierre Seifert |
SEC | 2 |
| 2008 | A Trusted Mobile Phone PrototypeabstractDue to the increasing security demands in mobile devices, the Trusted Computing Group (TCG) formed a dedicated Mobile Phone Working Group (MPWG) to address these security needs. MPWG recently released a Trusted Mobile Phone Reference Architecture (TCG-MPRA) specification that integrates well-known security concepts (TPM, isolation, Integrity Measurement and Verification (IMV), etc.) from the trusted" PC universe, tailored for mobile phones. The business needs of the mobile phone industry mandate 4 different stakeholders (platform owners): device "manufacturer, cellular service provider, general service provider, and the end-user. The specification requires separate trusted and isolated operational domains (Trusted Engines) for each stakeholder. Although the TCG MPWG does not explicitly prescribe a specific technical realization of these trusted engines, a general consensus is use of established (Trusted) Virtualization concepts from corresponding PC architectures. However, we will demo another isolation technique specifically crafted for mobile platforms that respects their resource limitations. We achieve this goal by realizing the MPWG specification by leveraging SELinux which provides a generic domain isolation concept at the kernel level. In addition to utilizing SELinux to realize mobile phone specific (isolated) operational domains, we are also able to seamlessly integrate the important IMV concept into our SELinux-based Trusted Mobile Phone architecture. In our demo we will present a hardware prototvpe, representing a generic mobile phone, implementing the TCG MPWG specification. First, we will "Securely Boot" our TC-aware SELinux kernel out of a hardware Mobile Trusted Module (MTM). Next, we will show how easy and efficient we can realize the 4 isolated Trusted Engines. The value of the Trusted Engines and the fundamental IMV principle will be demonstrated through successful mitigation of two automatic Linux cell-phone worms. The prototype in this demo is in effect, the world's first novel, efficient and inherently secure implementation of MPWG specification. Onur Aciiçmez, Afshin Latifi, Jean-Pierre Seifert, Xinwen Zhang |
CCNC | 3 |
| 2008 | Usage control platformization via trustworthy SELinuxabstractContinuous access control after an object is released into a distributed environment has been regarded as the usage control problem and has been investigated by different researchers in various papers. However, the enabling technology for usage control is a challenging problem and the space has not been fully explored yet. In this paper we identify the general requirements of a trusted usage control enforcement in heterogeneous computing environments, and also propose a general platform architecture to meet these requirements. Masoom Alam, Jean-Pierre Seifert, Qi Li 0002, Xinwen Zhang |
AsiaCCS | 2 |
| 2008 | Model-based behavioral attestationabstractRemote attestation is an important characteristic of trusted computing technology which provides reliable evidence that a trusted environment actually exists. Existing approaches for the realization of remote attestation measure the trustworthiness of a target platform from its binaries, configurations, properties or security policies. All these approaches are low-level attestation techniques only, and none of them define what a trusted behavior actually is and how to specify it. In this paper, we present a novel approach where the trustworthiness of a platform is associated with the behavior of a policy model. In our approach, the behavior of a policy model is attested rather than a software or hardware platform. Thus, the attestation feature is not tied to a specific software or hardware platform, or to a particular remote attestation technique, or to an individual type of security policy. We select usage control (UCON) as our target policy model as it is a comprehensive and exible model. We propose a framework to identify, specify, and attest different behaviors of UCON. Masoom Alam, Xinwen Zhang, Mohammad Nauman, Tamleek Ali, Jean-Pierre Seifert |
SACMAT | 5 |
| 2008 | A general obligation model and continuity: enhanced policy enforcement engine for usage controlabstractThe usage control model (UCON) has been proposed to augment traditional access control models by integrating authorizations, obligations, and conditions and providing the properties of decision continuity and attribute mutability. Several recent work have applied UCON to support security requirements in different computing environments such as resource sharing in collaborative computing systems and data control in remote platforms. In this paper we identify two individual but interrelated problems of the original UCON model and recent implementations: oversimplifying the concept of usage session of the model, and the lack of comprehensive ongoing enforcement mechanism of implementations. We extend the core UCON model with continuous usage sessions thus extensively augment the expressiveness of obligations in UCON, and then propose a general, continuity-enhanced and configurable usage control enforcement engine. Finally we explain how our approach can satisfy flexible security requirements with an implemented prototype for a healthcare information system. Basel Katt, Xinwen Zhang, Ruth Breu, Michael Hafner, Jean-Pierre Seifert |
SACMAT | 5 |
| 2007 | Predicting Secret Keys Via Branch Prediction
Onur Aciiçmez, Çetin Kaya Koç, Jean-Pierre Seifert |
CT-RSA | 3 |
| 2007 | A Model-Driven Framework for Trusted Computing Based SystemsabstractExisting approaches for Trust Management through software alone - by their very principle - are uncompromising and have inherent weaknesses. Once the information leaves the service provider platform, there is no way to guarantee the integrity of the information on the client (or service requestor) platform. The Trusted Computing Group proposed a quantum leap in security, a hardware based "root of trust" by which the integrity of a platform - be a client or service provider can be verified. However, there is no approach for the integration of this novel but essentially straight forward concept into the distributed application development. We believe that the complexity of Trusted Computing (TC) is one of the key factors that will hinder its successful integration within the web services based distributed application realm. Model-driven techniques offer a promising approach to alleviate the complexity of platforms. This contribution has three objectives. First, we detail SECTET - a model-driven framework for leveraging TC concepts at a higher level of abstraction. We secondly elaborate the integration of platform-independent XACML policies with the platform-specific SELinux policies. Thirdly, we share our experiences regarding the implementation results of the SECTET on TC based systems. Masoom Alam, Jean-Pierre Seifert, Xinwen Zhang |
EDOC | 2 |
| 2007 | Cheap Hardware Parallelism Implies Cheap SecurityabstractThe paper presents a new aspect within that PC oriented side-channel attack arena. Specifically, we present a novel square vs. multiplication oriented side-channel attack which is very unique to certain simultaneous multi threading CPU architectures and it seems that it cannot be carried out on CPU architectures without SMT hardware assistance. The simple reason for this uniqueness of our novel attack is the fact that it doesn't rest - as all other previous MicroArchitectural side-channel attacks - upon a shared resource with the persistent state property between context/process switches, for e.g., caches, BTBs, etc. Instead, it is based upon the fact that Intel's hyper-threading technology shares the ALU's large parallel integer (floating-point) multiplier between its two hardware threads, where it is noteworthy that the multiplier obviously doesn't preserve its state during context switches. As the latest OpenSSL changes, i.e., protections against side-channels attacks are already in place, cf. (Brickell et al., 2006), our paper doesn't introduce a new vulnerability into the OpenSSL library at all. Nevertheless, our attack has the following unintuitive property. Longer key sizes just make our attack scenario easier and not more difficult as one could assume at first sight. Thus, the present paper teaches that the sole presence of particular multi threading implementations requires a very deep understanding of the interplay between the underlying hardware and software, in order to appropriately judge the implied security consequences. Onur Aciiçmez, Jean-Pierre Seifert |
FDTC | 2 |
| 2007 | New Branch Prediction Vulnerabilities in OpenSSL and Necessary Software Countermeasures
Onur Aciiçmez, Shay Gueron, Jean-Pierre Seifert |
IMACC | 3 |
| 2006 | A refined look at Bernstein's AES side-channel analysisabstractIn a recent manuscript Dan Bernstein claims the successful extraction of an AES key from a network server through another client computer. His side-channel attack was actually the simplest conceivable timing analysis of AES. Although Bernstein gave no thorough analysis of his methodology or the underlying technique the paper contained the full C-source code. This was actually very useful to repeat, analyze and extend his experiments and technique. Our paper improves upon the work done by Bernstein in the following ways: Michael Neve, Jean-Pierre Seifert, Zhenghong Wang |
AsiaCCS | 2 |
| 2006 | Sign Change Fault Attacks on Elliptic Curve Cryptosystems
Johannes Blömer, Martin Otto 0002, Jean-Pierre Seifert |
FDTC | 3 |
| 2006 | Is It Wise to Publish Your Public RSA Keys?
Shay Gueron, Jean-Pierre Seifert |
FDTC | 2 |
| 2005 | On authenticated computing and RSA-based authenticationabstractThis paper presents a novel hardware attack against RSA-based authentication of programs. Like the seminal paper from [10] it exploits the attacker's ability to arbitrarily tamper with a computational device during its data processing. But, contrary to [10] our method targets the RSA signature verification which processes only public data. Surprisingly, we prove how to let the RSA verification process accept signatures (with high probability and assuming the Riemann Hypothesis) of arbitrary code --- signed with our own self-created private key. While our attack is so far only theoretical, its practical feasibility has been already implicitly confirmed, cf. [6]. In fact, through real experiments with tamper-resistant devices [4] discovered the following caveat being at the heart of our vulnerability: the most often observed fault during RSA-computations exposed to glitch attacks is the erroneous modification of the moduli. Moreover, our attack relies only upon the simplest and most easiest practically implementable fault induction method described by [8]. Our idea is somehow inspired by practiced methods circumventing the FLASH Boot ROM authentication mechanism of the Xbox due to F. Lehner, cf[17]. Our attack can be interpreted as the extrapolation of the mathematical foundation underlying those Xbox vulnerabilities. Jean-Pierre Seifert |
CCS | 1 |
| 2005 | On-Line Testing for Secure Implementations: Design and ValidationabstractOn-line testing approaches can today be useful when designing circuits with severe security constraints. The reasons are summarized in the introduction to the special session on secure implementations (in these proceedings). The presentations in this special session aimed at introducing the specific concerns related to security as well as some approaches used to protect the circuits and to validate their robustness for certification. This panel aims at discussing in more details how on-line testing techniques can help in improving security and how the achieved level of security can be evaluated at different stages in the design flow. Various aspects are covered by the participants, including: counter-measures for fault attacks in hardware cryptographic primitives, design for test versus design for security, use of fault injection tools in evaluating the robustness against attacks and validation of security at the system level. Régis Leveugle, Yervant Zorian, Luca Breveglieri, André K. Nieuwland, Klaus Rothbart, Jean-Pierre Seifert |
IOLTS | 6 |
| 2004 | High-Speed Modular Multiplication
Wieland Fischer, Jean-Pierre Seifert |
CT-RSA | 2 |
| 2003 | A new CRT-RSA algorithm secure against bellcore attacksabstractIn this paper we describe a new algorithm to prevent fault attacks on RSA signature algorithms using the Chinese Remainder Theorem (CRT-RSA). This variant of the RSA signature algorithm is widely used on smartcards. Smartcards on the other hand are particularly susceptible to fault attacks like the one described in [7]. Recent results have shown that fault attacks are practical and easy to accomplish ([21], [17]).Therefore, they establish a practical need for fault attack protected CRT-RSA schemes. Starting from a careful derivation and classification of fault models, we describe a new variant of the CRT-RSA algorithm. For the most realistic fault model described, we rigorously analyze the success probability of an adversary against our new CRT-RSA algorithm. Thereby, we prove that our new algorithm is secure against the Bellcore attack. Johannes Blömer, Martin Otto 0002, Jean-Pierre Seifert |
CCS | 3 |
| 2003 | Unfolded Modular Multiplication
Wieland Fischer, Jean-Pierre Seifert |
ISAAC | 2 |
| 2002 | Note on Fast Computation of Secret RSA Exponents
Wieland Fischer, Jean-Pierre Seifert |
ACISP | 2 |
| 2002 | On the Implementation of the Advanced Encryption Standard on a Public-key Crypto-Coprocessor
Antonio Valverde Garcia, Jean-Pierre Seifert |
CARDIS | 2 |
| 2002 | Fault Attacks on RSA with CRT: Concrete Results and Practical Countermeasures
Christian Aumüller, Peter Bier, Wieland Fischer, Peter Hofreiter, Jean-Pierre Seifert |
CHES | 5 |
| 2002 | Increasing the Bitlength of a Crypto-Coprocessor
Wieland Fischer, Jean-Pierre Seifert |
CHES | 2 |
| 2001 | Using Fewer Qubits in Shor's Factorization Algorithm Via Simultaneous Diophantine Approximation
Jean-Pierre Seifert |
CT-RSA | 1 |
| 1999 | On Routing in Circulant Graphs
Jin-Yi Cai, George Havas, Bernard Mans, Ajay Nerurkar, Jean-Pierre Seifert, Igor E. Shparlinski |
COCOON | 5 |
| 1999 | Tensor-Based Trapdoors for CVP and Their Application to Public Key Cryptographyabstract. We propose two trapdoors for the Closest-Vector-Problem in lattices (CVP) related to the lattice tensor product. Using these trapdoors we set up a lattice-based cryptosystem which resembles to the McEliece scheme. 1 Keywords. Public Key Cryptosystem, Closest Vector Problem, Lattice Reduction, Trapdoor, McEliece 1 Introduction Since the invention of public key cryptography in 1976 by Di#e and Hellman [DH76] security of most cryptosystems is based on the (assumed) hardness of factoring or computing discrete logarithms. Only a few schemes based on other problems remain unbroken. Among which there is the McEliece scheme [St95] based on the computational di#culty of decoding a random code. It is still a challenge to develop new public key cryptosystem originating from the hardness of non number-theoretic problems. In a pioneer work Ajtai [A96] constructed an e#ciently computable function which is hard to invert on the average if the underlying lattice problem is intractable in th... Roger Fischlin, Jean-Pierre Seifert |
IMACC | 2 |
| 1999 | The Complexity of the Extended GCD Problem
George Havas, Jean-Pierre Seifert |
MFCS | 2 |
| 1999 | On the Complexity of Computing Short Linearly Independent Vectors and Short Bases in a LatticeabstractMotivated by Ajtai's worst-case to average-case reduction for lattice problems, we study the complexity of computing short linearly independent vectors (short basis) in a lattice.We show that approximating the length of a shortest set of linearly independent vectors (shortest basis) within any constant factor is NP-hard.Under the assumption that problems in NP cannot be solved in DTIME(n p"'y'og(n)) we show that no polynomial time algorithm can approximate the length of a shortest set of linearly independent vectors (shortest basis) within a factor of 2'"g'-'("), E > 0 arbitrary, but fixed.Finally, we obtain results on the limits of non-approximability for computing short linearly independent vectors (short basis).Our strongest result in this direction states that under reasonable complexity-theoretic assumptions, approximating the length of a shortest set of linearly independent vectors (shortest basis) within a factor of n/a is not NP-hard. Johannes Blömer, Jean-Pierre Seifert |
STOC | 2 |
| 1999 | Approximating Shortest Lattice Vectors is not Harder than Approximating Closest Lattice Vectors
Oded Goldreich 0001, Daniele Micciancio, Shmuel Safra, Jean-Pierre Seifert |
Inf. Process. Lett. | 4 |
| 1998 | On the Hardness of Approximating Shortest Integer Relations among Rational Numbers
Carsten Rössner, Jean-Pierre Seifert |
Theor. Comput. Sci. | 2 |
| 1996 | Approximating Good Simultaneous Diophantine Approximations Is Almost NP-Hard
Carsten Rössner, Jean-Pierre Seifert |
MFCS | 2 |