1,720,964 research outputs found
Sicherstellung der zuverlässigen und sicheren Ausführung neuartiger Progamme auf modernen Mikroprozessoren
Dependable systems aim to provide reliability and security guarantees, protecting against both random events and intentional threats. Physical phenomena, such as hardware faults, pose a challenge to dependable systems, as they can undermine both reliability and security. While these challenges have been extensively studied in the past, recent developments in fault models and cryptographic implementations introduce new challenges that call for new solutions.
This thesis addresses challenges posed by these recent developments in two parts. First, it addresses new challenges to the reliability and fault resilience of modern microprocessors. A recent surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviors at scale suggests a change in the nature of faults in the wild. Recent publications suggest that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects. While microarchitectural mitigations to SDFs are known, placing them on the entire chip is prohibitively expensive. This thesis presents DelayAVF, a new metric to quantify the vulnerability of a processor design to small delay faults. DelayAVF provides key architectural insights that can be used to identify structures which are particularly vulnerable to SDFs, helping to guide targeted protections against these faults. We also present a case study on the OpenTitan hardware root of trust, exposing a real-world vulnerability in OpenTitan’s fault injection countermeasures. Our case study demonstrates the difficulty of correctly integrating fault injection countermeasures in pipelined processors.
The second part of this thesis explores the resilience of post-quantum secure algorithms and implementations against physical attacks. The plausible advent of general-purpose quantum computing in the coming decades poses a mounting threat to contemporary public-key cryptography. This threat spurred the development of new cryptographic schemes that base their security on mathematical problems which remain hard even on a quantum computer. A now-finished NIST-led standardization process for post-quantum secure cryptographic algorithms has led to the standardization of three signature schemes. These schemes have thus far withstood cryptanalysis, lending credence to their security claims. However, as they are now slated for real-world deployment, their resilience against side-channel and fault injection attacks must be studied as well.
This thesis conducts this investigation for Dilithium, a lattice-based signature scheme recently standardized as ML-DSA. We present two novel key recovery algorithms that elevate a minor, noisy leakage on Dilithium’s commitment vector, which is similar to the nonce in Schnorr signatures, into full secret key recovery. Both algorithms introduce methodologies that are novel to cryptanalysis, drawing on techniques from discrete optimization and outlier-resilient statistics.
We use the efficacy of our key recovery algorithms to demonstrate three end-to-end side-channel and fault injection attacks that achieve sufficient leakage on Dilithium’s commitment vector and, consequently, secret-key recovery. We present the first end-to-end power-side channel attack on Dilithium’s reference implementation. We also present two attacks that subvert countermeasures presented by prior work: a fault injection attack against Dilithium implementations that implement multiple fault injection countermeasures, and a power side-channel attack against a masked Dilithium implementation. Our fault injection attack appears hard to protect against using only algorithm countermeasures, pointing to the need for more expensive countermeasures when deploying Dilithium. The attacks and key recovery algorithms presented in this thesis generalize to all lattice-based Fiat–Shamir with aborts signature schemes.
The threat of physical attacks is not restricted to lattice-based cryptography, however. As a case in point, this thesis also presents the first end-to-end fault injection attack against MAYO, a multivariate signature scheme. MAYO is a promising candidate for the NIST call for alternative signature schemes, a standardization call that aims to standardize signature schemes that are not based on structured lattices. Our fault injection attack allows for secret key recovery within seconds from only one faulted signature, and underscores the need for protective measures for MAYO implementations.„Dependable Systems“ müssen sowohl Zuverlässigkeits- als auch Sicherheitsgarantien bieten, um sich gegen zufällige Ereignisse und gezielte Bedrohungen zu schützen. Physikalische Phänomene wie Hardwarefehler stellen eine Herausforderung für solche Systeme dar, da sie sowohl die Zuverlässigkeit als auch die Sicherheit beeinträchtigen können. Obwohl diese Herausforderungen in der Vergangenheit umfassend untersucht wurden, führen neue Entwicklungen in Fehlermodellen und kryptografischen Implementierungen zu zusätzlichen Problemen, die neue Lösungen erfordern.
Diese Dissertation behandelt die durch diese neuen Entwicklungen entstandenen Herausforderungen in zwei Teilen.
Im ersten Teil geht es um neue Herausforderungen für die Zuverlässigkeit moderner Mikroprozessoren und deren Widerstandsfähigkeit gegenüber Fehlerinjektionsangriffen.
Eine jüngste Häufung von Berichten großer Cloud-Anbieter über neue Arten von sogenannten Silent Data Corruption (SDC) deutet auf eine Veränderung der Natur von Fehlern in realen Systemen hin. Neue Veröffentlichungen legen nahe, dass eine mögliche Ursache dieser SDCs sogenannte Small Delay Faults (SDFs) sind, die durch marginale Defekte ausgelöst werden.
Zwar sind mikroarchitekturelle Schutzmaßnahmen gegen SDFs bekannt, deren flächendeckende Anwendung auf einem Chip ist jedoch mit hohen Kosten verbunden.
Die vorliegende Doktorarbeit führt DelayAVF ein, eine neue Metrik zur Quantifizierung der Anfälligkeit eines Prozessordesigns gegenüber kleinen Verzögerungsfehlern.
DelayAVF liefert wichtige Erkenntnisse für die Identifizierung besonders anfälliger Strukturen und somit gezielte Schutzmaßnahmen gegen diese Fehler zu ermöglichen.
Außerdem präsentiert diese Arbeit eine Fallstudie zum Hardware-Root-of-Trust OpenTitan, in der eine reale Schwachstelle in den Fehlerinjektions-Gegenmaßnahmen des Prozessordesigns aufgedeckt wird.
Die Fallstudie verdeutlicht die Schwierigkeit, Fehlerinjektions-Gegenmaßnahmen korrekt in Pipeline-Prozessoren zu integrieren.
Der zweite Teil dieser Dissertation untersucht die Resilienz post-quanten-sicherer Algorithmen und Implementierungen gegenüber physikalischen Angriffen.
Die potenzielle Verfügbarkeit universeller Quantencomputer in den kommenden Jahrzehnten stellt eine zunehmende Bedrohung für die heutige Public-Key-Kryptographie dar.
Diese Bedrohung hat zur Entwicklung neuer kryptografischer Verfahren geführt, deren Sicherheit auf mathematischen Problemen basiert, die auch für Quantencomputer schwer lösbar bleiben.
Ein mittlerweile abgeschlossener, von NIST geleiteter Standardisierungsprozess für post-quanten-sichere kryptografische Algorithmen führte zur Standardisierung von drei Signatursystemen.
Diese Verfahren haben bisher sämtlichen kryptografischen Angriffen standgehalten, was ihre Sicherheitsversprechen stützt.
Da sie nun jedoch für reale Anwendungen vorgesehen sind, muss auch ihre Widerstandsfähigkeit gegenüber Seitenkanal- und Fehlerinjektionsangriffen untersucht werden.
Diese Arbeit führt eine solche Untersuchung für Dilithium durch, ein gitterbasiertes Signaturschema, das kürzlich als ML-DSA standardisiert wurde.
Wir präsentieren zwei neuartige Algorithmen zur Schlüsselrekonstruktion, die den Schlüssel aus einer geringen, verrauschte Leakage im sogenannten Commitment-Vektor von Dilithium --- vergleichbar mit der Nonce in Schnorr-Signaturen --- wiederherstellen. Beide Algorithmen bringen neue Methoden in die Kryptanalyse ein, übertragen aus den Feldern der diskreten Optimierung und der robusten Statistik.
Wir nutzen die Effektivität dieser Algorithmen, um drei ende-zu-ende Seitenkanal- und Fehlerinjektionsangriffe zu demonstrieren, die eine ausreichende Leakage des Commitment-Vektors erzeugen und damit die Wiederherstellung des geheimen Schlüssels ermöglichen.
Dabei präsentiert diese Arbeit den ersten vollständigen Stromseitenkanalangriff auf die Referenzimplementierung von Dilithium.
Zudem präsentieren wir zwei Angriffe, die vorhandene Gegenmaßnahmen umgehen: einen Fehlerinjektionsangriff auf Implementierungen von Dilithium mit mehreren Schutzmechanismen sowie einen Stromseitenkanalangriff auf eine maskierte Implementierung von Dilithium.
Es scheint schwierig, unseren Fehlerinjektionsangriff allein durch algorithmische Gegenmaßnahmen abzuwehren, was auf die Notwendigkeit teurerer Schutzmaßnahmen beim Einsatz von Dilithium hinweist.
Die vorgestellten Angriffe und Schlüsselrekonstruktionsalgorithmen lassen sich auf alle gitterbasierten Fiat---Shamir-with-Aborts-Signaturschemata verallgemeinern.
Die Bedrohung durch physikalische Angriffe beschränkt sich jedoch nicht auf gitterbasierte Kryptographie.
Als Beispiel präsentiert diese Dissertation auch den ersten vollständigen Fehlerinjektionsangriff auf MAYO, ein multivariates Signaturschema.
MAYO ist ein vielversprechender Kandidat im Rahmen des NIST-Standardisierungsprozess für alternative, nicht auf strukturierten Gittern basierende, Signaturschemata.
Unser Fehlerinjektionsangriff ermöglicht die Wiederherstellung des geheimen Schlüssels innerhalb weniger Sekunden aus nur einer manipulierten Signatur und unterstreicht die Notwendigkeit von Schutzmaßnahmen für MAYO-Implementierungen.BMBF, 16KISK030, 6G Research and Innovation Cluster (6G-RIC), Souverän. Digital. Vernetzt
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
Breaking the Quadratic Barrier: Quantum Cryptanalysis of Milenage, Telecommunications’ Cryptographic Backbone
476504The potential advent of large-scale quantum computers in the near future poses a threat to contemporary cryptography. One ubiquitous usage of cryptography is currently present in the vibrant field of cellular networks. The cryptography of cellular networks is centered around seven secret-key algorithms f1, . . . , f5, f ∗1 , f ∗5 , aggregated into an authentication and key agreement algorithm set. Still, to the best of our knowledge, these secret key algorithms have not yet been subject to quantum cryptanalysis. Instead, many quantum security considerations for telecommunication networks argue that the threat posed by quantum computers is restricted to public-key cryptography. However, various recent works have presented quantum attacks on secret key cryptography that exploit quantum period finding to achieve more than a quadratic speedup compared to the best known classical attacks. Motivated by this quantum threat to symmetric cryptography, this paper presents a quantum cryptanalysis for the Milenage algorithm set, the prevalent instantiation of the seven secret-key f1, . . . , f5, f∗ 1 , f∗ 5 algorithms that underpin cellular security. Building upon recent quantum cryptanalytic results, we show attacks that go beyond a quadratic speedup. Concretely, we provide quantum attack scenarios for all Milenage algorithms, including exponential speedups distinguishable by different quantum attack models. Our results do not constitute an immediate quantum break of the Milenage algorithms, but they do show that Milenage suffers from structural weaknesses making it susceptible to quantum attacks
Variations on the Author
“Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
Appropriate Similarity Measures for Author Cocitation Analysis
We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
Dispelling the Myths Behind First-author Citation Counts
We conducted a full-scale evaluative citation analysis study of scholars in the XML research field to explore just how different from each other author rankings resulting from different citation counting methods actually are, and to demonstrate the capability of emerging data and tools on the Web in supporting more realistic citation counting methods. Our results contest some common arguments for the continued
use of first-author citation counts in the evaluation of scholars, such as high correlations between author rankings by first-author citation counts and other citation
counting methods, and high costs of using more realistic citation counting methods that are not well-supported by the ISI databases. It is argued that increasingly available digital full text research papers make it possible for citation analysis studies to go beyond what the ISI databases have directly supported and to employ more
sophisticated methods
koamabayili/VECTRON-author-checklist: VECTRON author checklist
We have done our best to complete the author checklist relating to the use of animals in the hut study. Note that the objective for the hut study was to evaluate the IRS treatment applications for residual efficacy against Anopheles mosquitoes, including the local An. coluzzii mosquito population. Cows were only used to attract mosquitoes into the huts and no tests were carried out directly on the cows. The author checklist is intended for use with studies where experiments are carried out on animals, which is why we have had such difficulty in completing this for the hut study, as many of the questions do not relate to how the cows were used
Author-wise bibliometric analysis based on entropy.
Author-wise bibliometric analysis based on entropy.</p
- …
