{"id":{"repo_id":"tu-berlin","oai_identifier":"oai:depositonce.tu-berlin.de:11303/25232"},"canonical_url":"https://search.dev.ndltd.org/etd/tu-berlin/oai:depositonce.tu-berlin.de:11303/25232","repository":{"repo_id":"tu-berlin","name":"Technische Universität Berlin","base_url":"https://api-depositonce.tu-berlin.de/server/oai/request"},"display":{"title":"Ensuring reliable and secure deployment of emergent workloads on modern microprocessors","abstract":"Dependable systems aim to provide reliability and security guarantees, protecting against both random events and intentional threats. Physical phenomena, such as hardware faults, pose a challenge to dependable systems, as they can undermine both reliability and security. While these challenges have been extensively studied in the past, recent developments in fault models and cryptographic implementations introduce new challenges that call for new solutions. This thesis addresses challenges posed by these recent developments in two parts. First, it addresses new challenges to the reliability and fault resilience of modern microprocessors. A recent surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviors at scale suggests a change in the nature of faults in the wild. Recent publications suggest that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects. While microarchitectural mitigations to SDFs are known, placing them on the entire chip is prohibitively expensive. This thesis presents DelayAVF, a new metric to quantify the vulnerability of a processor design to small delay faults. DelayAVF provides key architectural insights that can be used to identify structures which are particularly vulnerable to SDFs, helping to guide targeted protections against these faults. We also present a case study on the OpenTitan hardware root of trust, exposing a real-world vulnerability in OpenTitan’s fault injection countermeasures. Our case study demonstrates the difficulty of correctly integrating fault injection countermeasures in pipelined processors. The second part of this thesis explores the resilience of post-quantum secure algorithms and implementations against physical attacks. The plausible advent of general-purpose quantum computing in the coming decades poses a mounting threat to contemporary public-key cryptography. This threat spurred the development of new cryptographic schemes that base their security on mathematical problems which remain hard even on a quantum computer. A now-finished NIST-led standardization process for post-quantum secure cryptographic algorithms has led to the standardization of three signature schemes. These schemes have thus far withstood cryptanalysis, lending credence to their security claims. However, as they are now slated for real-world deployment, their resilience against side-channel and fault injection attacks must be studied as well. This thesis conducts this investigation for Dilithium, a lattice-based signature scheme recently standardized as ML-DSA. We present two novel key recovery algorithms that elevate a minor, noisy leakage on Dilithium’s commitment vector, which is similar to the nonce in Schnorr signatures, into full secret key recovery. Both algorithms introduce methodologies that are novel to cryptanalysis, drawing on techniques from discrete optimization and outlier-resilient statistics. We use the efficacy of our key recovery algorithms to demonstrate three end-to-end side-channel and fault injection attacks that achieve sufficient leakage on Dilithium’s commitment vector and, consequently, secret-key recovery. We present the first end-to-end power-side channel attack on Dilithium’s reference implementation. We also present two attacks that subvert countermeasures presented by prior work: a fault injection attack against Dilithium implementations that implement multiple fault injection countermeasures, and a power side-channel attack against a masked Dilithium implementation. Our fault injection attack appears hard to protect against using only algorithm countermeasures, pointing to the need for more expensive countermeasures when deploying Dilithium. The attacks and key recovery algorithms presented in this thesis generalize to all lattice-based Fiat–Shamir with aborts signature schemes. The threat of physical attacks is not restricted to lattice-based cryptography, however. As a case in point, this thesis also presents the first end-to-end fault injection attack against MAYO, a multivariate signature scheme. MAYO is a promising candidate for the NIST call for alternative signature schemes, a standardization call that aims to standardize signature schemes that are not based on structured lattices. Our fault injection attack allows for secret key recovery within seconds from only one faulted signature, and underscores the need for protective measures for MAYO implementations.","abstract_html":"Dependable systems aim to provide reliability and security guarantees, protecting against both random events and intentional threats. Physical phenomena, such as hardware faults, pose a challenge to dependable systems, as they can undermine both reliability and security. While these challenges have been extensively studied in the past, recent developments in fault models and cryptographic implementations introduce new challenges that call for new solutions. This thesis addresses challenges posed by these recent developments in two parts. First, it addresses new challenges to the reliability and fault resilience of modern microprocessors. A recent surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviors at scale suggests a change in the nature of faults in the wild. Recent publications suggest that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects. While microarchitectural mitigations to SDFs are known, placing them on the entire chip is prohibitively expensive. This thesis presents DelayAVF, a new metric to quantify the vulnerability of a processor design to small delay faults. DelayAVF provides key architectural insights that can be used to identify structures which are particularly vulnerable to SDFs, helping to guide targeted protections against these faults. We also present a case study on the OpenTitan hardware root of trust, exposing a real-world vulnerability in OpenTitan’s fault injection countermeasures. Our case study demonstrates the difficulty of correctly integrating fault injection countermeasures in pipelined processors. The second part of this thesis explores the resilience of post-quantum secure algorithms and implementations against physical attacks. The plausible advent of general-purpose quantum computing in the coming decades poses a mounting threat to contemporary public-key cryptography. This threat spurred the development of new cryptographic schemes that base their security on mathematical problems which remain hard even on a quantum computer. A now-finished NIST-led standardization process for post-quantum secure cryptographic algorithms has led to the standardization of three signature schemes. These schemes have thus far withstood cryptanalysis, lending credence to their security claims. However, as they are now slated for real-world deployment, their resilience against side-channel and fault injection attacks must be studied as well. This thesis conducts this investigation for Dilithium, a lattice-based signature scheme recently standardized as ML-DSA. We present two novel key recovery algorithms that elevate a minor, noisy leakage on Dilithium’s commitment vector, which is similar to the nonce in Schnorr signatures, into full secret key recovery. Both algorithms introduce methodologies that are novel to cryptanalysis, drawing on techniques from discrete optimization and outlier-resilient statistics. We use the efficacy of our key recovery algorithms to demonstrate three end-to-end side-channel and fault injection attacks that achieve sufficient leakage on Dilithium’s commitment vector and, consequently, secret-key recovery. We present the first end-to-end power-side channel attack on Dilithium’s reference implementation. We also present two attacks that subvert countermeasures presented by prior work: a fault injection attack against Dilithium implementations that implement multiple fault injection countermeasures, and a power side-channel attack against a masked Dilithium implementation. Our fault injection attack appears hard to protect against using only algorithm countermeasures, pointing to the need for more expensive countermeasures when deploying Dilithium. The attacks and key recovery algorithms presented in this thesis generalize to all lattice-based Fiat–Shamir with aborts signature schemes. The threat of physical attacks is not restricted to lattice-based cryptography, however. As a case in point, this thesis also presents the first end-to-end fault injection attack against MAYO, a multivariate signature scheme. MAYO is a promising candidate for the NIST call for alternative signature schemes, a standardization call that aims to standardize signature schemes that are not based on structured lattices. Our fault injection attack allows for secret key recovery within seconds from only one faulted signature, and underscores the need for protective measures for MAYO implementations.","abstract_has_math":false,"creators":["Ulitzsch, Vincent Quentin"],"institution":null,"degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Seifert, Jean-Pierre"],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025","date_published":"2025","updated_at":"2026-07-27T21:28:52Z","subjects":[],"languages":["en"],"rights":[],"rights_urls":["https://creativecommons.org/licenses/by/4.0/"],"identifier_entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://doi.org/10.14279/depositonce-24054"],"render_values":[{"text":"https://doi.org/10.14279/depositonce-24054","href":"https://doi.org/10.14279/depositonce-24054","code":true}]}]},"links":{"outbound_url":"https://depositonce.tu-berlin.de/handle/11303/25232","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Seifert, Jean-Pierre"]},{"key":"dc:creator","label":"Author","values":["Ulitzsch, Vincent Quentin"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-08-05T08:46:29Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-08-05T08:46:29Z"]},{"key":"dc:date.issued","label":"Date","values":["2025"]},{"key":"dc:type","label":"Dc Type","values":["Doctoral Thesis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights.uri","label":"Rights URI","values":["https://creativecommons.org/licenses/by/4.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://depositonce.tu-berlin.de/handle/11303/25232","https://doi.org/10.14279/depositonce-24054"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Dependable systems aim to provide reliability and security guarantees, protecting against both random events and intentional threats. Physical phenomena, such as hardware faults, pose a challenge to dependable systems, as they can undermine both reliability and security. While these challenges have been extensively studied in the past, recent developments in fault models and cryptographic implementations introduce new challenges that call for new solutions. This thesis addresses challenges posed by these recent developments in two parts. First, it addresses new challenges to the reliability and fault resilience of modern microprocessors. A recent surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviors at scale suggests a change in the nature of faults in the wild. Recent publications suggest that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects. While microarchitectural mitigations to SDFs are known, placing them on the entire chip is prohibitively expensive. This thesis presents DelayAVF, a new metric to quantify the vulnerability of a processor design to small delay faults. DelayAVF provides key architectural insights that can be used to identify structures which are particularly vulnerable to SDFs, helping to guide targeted protections against these faults. We also present a case study on the OpenTitan hardware root of trust, exposing a real-world vulnerability in OpenTitan’s fault injection countermeasures. Our case study demonstrates the difficulty of correctly integrating fault injection countermeasures in pipelined processors. The second part of this thesis explores the resilience of post-quantum secure algorithms and implementations against physical attacks. The plausible advent of general-purpose quantum computing in the coming decades poses a mounting threat to contemporary public-key cryptography. This threat spurred the development of new cryptographic schemes that base their security on mathematical problems which remain hard even on a quantum computer. A now-finished NIST-led standardization process for post-quantum secure cryptographic algorithms has led to the standardization of three signature schemes. These schemes have thus far withstood cryptanalysis, lending credence to their security claims. However, as they are now slated for real-world deployment, their resilience against side-channel and fault injection attacks must be studied as well. This thesis conducts this investigation for Dilithium, a lattice-based signature scheme recently standardized as ML-DSA. We present two novel key recovery algorithms that elevate a minor, noisy leakage on Dilithium’s commitment vector, which is similar to the nonce in Schnorr signatures, into full secret key recovery. Both algorithms introduce methodologies that are novel to cryptanalysis, drawing on techniques from discrete optimization and outlier-resilient statistics. We use the efficacy of our key recovery algorithms to demonstrate three end-to-end side-channel and fault injection attacks that achieve sufficient leakage on Dilithium’s commitment vector and, consequently, secret-key recovery. We present the first end-to-end power-side channel attack on Dilithium’s reference implementation. We also present two attacks that subvert countermeasures presented by prior work: a fault injection attack against Dilithium implementations that implement multiple fault injection countermeasures, and a power side-channel attack against a masked Dilithium implementation. Our fault injection attack appears hard to protect against using only algorithm countermeasures, pointing to the need for more expensive countermeasures when deploying Dilithium. The attacks and key recovery algorithms presented in this thesis generalize to all lattice-based Fiat–Shamir with aborts signature schemes. The threat of physical attacks is not restricted to lattice-based cryptography, however. As a case in point, this thesis also presents the first end-to-end fault injection attack against MAYO, a multivariate signature scheme. MAYO is a promising candidate for the NIST call for alternative signature schemes, a standardization call that aims to standardize signature schemes that are not based on structured lattices. Our fault injection attack allows for secret key recovery within seconds from only one faulted signature, and underscores the need for protective measures for MAYO implementations.","„Dependable Systems“ müssen sowohl Zuverlässigkeits- als auch Sicherheitsgarantien bieten, um sich gegen zufällige Ereignisse und gezielte Bedrohungen zu schützen. Physikalische Phänomene wie Hardwarefehler stellen eine Herausforderung für solche Systeme dar, da sie sowohl die Zuverlässigkeit als auch die Sicherheit beeinträchtigen können. Obwohl diese Herausforderungen in der Vergangenheit umfassend untersucht wurden, führen neue Entwicklungen in Fehlermodellen und kryptografischen Implementierungen zu zusätzlichen Problemen, die neue Lösungen erfordern. Diese Dissertation behandelt die durch diese neuen Entwicklungen entstandenen Herausforderungen in zwei Teilen. Im ersten Teil geht es um neue Herausforderungen für die Zuverlässigkeit moderner Mikroprozessoren und deren Widerstandsfähigkeit gegenüber Fehlerinjektionsangriffen. Eine jüngste Häufung von Berichten großer Cloud-Anbieter über neue Arten von sogenannten Silent Data Corruption (SDC) deutet auf eine Veränderung der Natur von Fehlern in realen Systemen hin. Neue Veröffentlichungen legen nahe, dass eine mögliche Ursache dieser SDCs sogenannte Small Delay Faults (SDFs) sind, die durch marginale Defekte ausgelöst werden. Zwar sind mikroarchitekturelle Schutzmaßnahmen gegen SDFs bekannt, deren flächendeckende Anwendung auf einem Chip ist jedoch mit hohen Kosten verbunden. Die vorliegende Doktorarbeit führt DelayAVF ein, eine neue Metrik zur Quantifizierung der Anfälligkeit eines Prozessordesigns gegenüber kleinen Verzögerungsfehlern. DelayAVF liefert wichtige Erkenntnisse für die Identifizierung besonders anfälliger Strukturen und somit gezielte Schutzmaßnahmen gegen diese Fehler zu ermöglichen. Außerdem präsentiert diese Arbeit eine Fallstudie zum Hardware-Root-of-Trust OpenTitan, in der eine reale Schwachstelle in den Fehlerinjektions-Gegenmaßnahmen des Prozessordesigns aufgedeckt wird. Die Fallstudie verdeutlicht die Schwierigkeit, Fehlerinjektions-Gegenmaßnahmen korrekt in Pipeline-Prozessoren zu integrieren. Der zweite Teil dieser Dissertation untersucht die Resilienz post-quanten-sicherer Algorithmen und Implementierungen gegenüber physikalischen Angriffen. Die potenzielle Verfügbarkeit universeller Quantencomputer in den kommenden Jahrzehnten stellt eine zunehmende Bedrohung für die heutige Public-Key-Kryptographie dar. Diese Bedrohung hat zur Entwicklung neuer kryptografischer Verfahren geführt, deren Sicherheit auf mathematischen Problemen basiert, die auch für Quantencomputer schwer lösbar bleiben. Ein mittlerweile abgeschlossener, von NIST geleiteter Standardisierungsprozess für post-quanten-sichere kryptografische Algorithmen führte zur Standardisierung von drei Signatursystemen. Diese Verfahren haben bisher sämtlichen kryptografischen Angriffen standgehalten, was ihre Sicherheitsversprechen stützt. Da sie nun jedoch für reale Anwendungen vorgesehen sind, muss auch ihre Widerstandsfähigkeit gegenüber Seitenkanal- und Fehlerinjektionsangriffen untersucht werden. Diese Arbeit führt eine solche Untersuchung für Dilithium durch, ein gitterbasiertes Signaturschema, das kürzlich als ML-DSA standardisiert wurde. Wir präsentieren zwei neuartige Algorithmen zur Schlüsselrekonstruktion, die den Schlüssel aus einer geringen, verrauschte Leakage im sogenannten Commitment-Vektor von Dilithium --- vergleichbar mit der Nonce in Schnorr-Signaturen --- wiederherstellen. Beide Algorithmen bringen neue Methoden in die Kryptanalyse ein, übertragen aus den Feldern der diskreten Optimierung und der robusten Statistik. Wir nutzen die Effektivität dieser Algorithmen, um drei ende-zu-ende Seitenkanal- und Fehlerinjektionsangriffe zu demonstrieren, die eine ausreichende Leakage des Commitment-Vektors erzeugen und damit die Wiederherstellung des geheimen Schlüssels ermöglichen. Dabei präsentiert diese Arbeit den ersten vollständigen Stromseitenkanalangriff auf die Referenzimplementierung von Dilithium. Zudem präsentieren wir zwei Angriffe, die vorhandene Gegenmaßnahmen umgehen: einen Fehlerinjektionsangriff auf Implementierungen von Dilithium mit mehreren Schutzmechanismen sowie einen Stromseitenkanalangriff auf eine maskierte Implementierung von Dilithium. Es scheint schwierig, unseren Fehlerinjektionsangriff allein durch algorithmische Gegenmaßnahmen abzuwehren, was auf die Notwendigkeit teurerer Schutzmaßnahmen beim Einsatz von Dilithium hinweist. Die vorgestellten Angriffe und Schlüsselrekonstruktionsalgorithmen lassen sich auf alle gitterbasierten Fiat---Shamir-with-Aborts-Signaturschemata verallgemeinern. Die Bedrohung durch physikalische Angriffe beschränkt sich jedoch nicht auf gitterbasierte Kryptographie. Als Beispiel präsentiert diese Dissertation auch den ersten vollständigen Fehlerinjektionsangriff auf MAYO, ein multivariates Signaturschema. MAYO ist ein vielversprechender Kandidat im Rahmen des NIST-Standardisierungsprozess für alternative, nicht auf strukturierten Gittern basierende, Signaturschemata. Unser Fehlerinjektionsangriff ermöglicht die Wiederherstellung des geheimen Schlüssels innerhalb weniger Sekunden aus nur einer manipulierten Signatur und unterstreicht die Notwendigkeit von Schutzmaßnahmen für MAYO-Implementierungen."]},{"key":"dc:title","label":"Title","values":["Ensuring reliable and secure deployment of emergent workloads on modern microprocessors"]}]}],"canonical_facts":{"dc:contributor.advisor":["Seifert, Jean-Pierre"],"dc:creator":["Ulitzsch, Vincent Quentin"],"dc:date.accessioned":["2025-08-05T08:46:29Z"],"dc:date.available":["2025-08-05T08:46:29Z"],"dc:date.issued":["2025"],"dc:description.abstract":["Dependable systems aim to provide reliability and security guarantees, protecting against both random events and intentional threats. Physical phenomena, such as hardware faults, pose a challenge to dependable systems, as they can undermine both reliability and security. While these challenges have been extensively studied in the past, recent developments in fault models and cryptographic implementations introduce new challenges that call for new solutions. This thesis addresses challenges posed by these recent developments in two parts. First, it addresses new challenges to the reliability and fault resilience of modern microprocessors. A recent surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviors at scale suggests a change in the nature of faults in the wild. Recent publications suggest that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects. While microarchitectural mitigations to SDFs are known, placing them on the entire chip is prohibitively expensive. This thesis presents DelayAVF, a new metric to quantify the vulnerability of a processor design to small delay faults. DelayAVF provides key architectural insights that can be used to identify structures which are particularly vulnerable to SDFs, helping to guide targeted protections against these faults. We also present a case study on the OpenTitan hardware root of trust, exposing a real-world vulnerability in OpenTitan’s fault injection countermeasures. Our case study demonstrates the difficulty of correctly integrating fault injection countermeasures in pipelined processors. The second part of this thesis explores the resilience of post-quantum secure algorithms and implementations against physical attacks. The plausible advent of general-purpose quantum computing in the coming decades poses a mounting threat to contemporary public-key cryptography. This threat spurred the development of new cryptographic schemes that base their security on mathematical problems which remain hard even on a quantum computer. A now-finished NIST-led standardization process for post-quantum secure cryptographic algorithms has led to the standardization of three signature schemes. These schemes have thus far withstood cryptanalysis, lending credence to their security claims. However, as they are now slated for real-world deployment, their resilience against side-channel and fault injection attacks must be studied as well. This thesis conducts this investigation for Dilithium, a lattice-based signature scheme recently standardized as ML-DSA. We present two novel key recovery algorithms that elevate a minor, noisy leakage on Dilithium’s commitment vector, which is similar to the nonce in Schnorr signatures, into full secret key recovery. Both algorithms introduce methodologies that are novel to cryptanalysis, drawing on techniques from discrete optimization and outlier-resilient statistics. We use the efficacy of our key recovery algorithms to demonstrate three end-to-end side-channel and fault injection attacks that achieve sufficient leakage on Dilithium’s commitment vector and, consequently, secret-key recovery. We present the first end-to-end power-side channel attack on Dilithium’s reference implementation. We also present two attacks that subvert countermeasures presented by prior work: a fault injection attack against Dilithium implementations that implement multiple fault injection countermeasures, and a power side-channel attack against a masked Dilithium implementation. Our fault injection attack appears hard to protect against using only algorithm countermeasures, pointing to the need for more expensive countermeasures when deploying Dilithium. The attacks and key recovery algorithms presented in this thesis generalize to all lattice-based Fiat–Shamir with aborts signature schemes. The threat of physical attacks is not restricted to lattice-based cryptography, however. As a case in point, this thesis also presents the first end-to-end fault injection attack against MAYO, a multivariate signature scheme. MAYO is a promising candidate for the NIST call for alternative signature schemes, a standardization call that aims to standardize signature schemes that are not based on structured lattices. Our fault injection attack allows for secret key recovery within seconds from only one faulted signature, and underscores the need for protective measures for MAYO implementations.","„Dependable Systems“ müssen sowohl Zuverlässigkeits- als auch Sicherheitsgarantien bieten, um sich gegen zufällige Ereignisse und gezielte Bedrohungen zu schützen. Physikalische Phänomene wie Hardwarefehler stellen eine Herausforderung für solche Systeme dar, da sie sowohl die Zuverlässigkeit als auch die Sicherheit beeinträchtigen können. Obwohl diese Herausforderungen in der Vergangenheit umfassend untersucht wurden, führen neue Entwicklungen in Fehlermodellen und kryptografischen Implementierungen zu zusätzlichen Problemen, die neue Lösungen erfordern. Diese Dissertation behandelt die durch diese neuen Entwicklungen entstandenen Herausforderungen in zwei Teilen. Im ersten Teil geht es um neue Herausforderungen für die Zuverlässigkeit moderner Mikroprozessoren und deren Widerstandsfähigkeit gegenüber Fehlerinjektionsangriffen. Eine jüngste Häufung von Berichten großer Cloud-Anbieter über neue Arten von sogenannten Silent Data Corruption (SDC) deutet auf eine Veränderung der Natur von Fehlern in realen Systemen hin. Neue Veröffentlichungen legen nahe, dass eine mögliche Ursache dieser SDCs sogenannte Small Delay Faults (SDFs) sind, die durch marginale Defekte ausgelöst werden. Zwar sind mikroarchitekturelle Schutzmaßnahmen gegen SDFs bekannt, deren flächendeckende Anwendung auf einem Chip ist jedoch mit hohen Kosten verbunden. Die vorliegende Doktorarbeit führt DelayAVF ein, eine neue Metrik zur Quantifizierung der Anfälligkeit eines Prozessordesigns gegenüber kleinen Verzögerungsfehlern. DelayAVF liefert wichtige Erkenntnisse für die Identifizierung besonders anfälliger Strukturen und somit gezielte Schutzmaßnahmen gegen diese Fehler zu ermöglichen. Außerdem präsentiert diese Arbeit eine Fallstudie zum Hardware-Root-of-Trust OpenTitan, in der eine reale Schwachstelle in den Fehlerinjektions-Gegenmaßnahmen des Prozessordesigns aufgedeckt wird. Die Fallstudie verdeutlicht die Schwierigkeit, Fehlerinjektions-Gegenmaßnahmen korrekt in Pipeline-Prozessoren zu integrieren. Der zweite Teil dieser Dissertation untersucht die Resilienz post-quanten-sicherer Algorithmen und Implementierungen gegenüber physikalischen Angriffen. Die potenzielle Verfügbarkeit universeller Quantencomputer in den kommenden Jahrzehnten stellt eine zunehmende Bedrohung für die heutige Public-Key-Kryptographie dar. Diese Bedrohung hat zur Entwicklung neuer kryptografischer Verfahren geführt, deren Sicherheit auf mathematischen Problemen basiert, die auch für Quantencomputer schwer lösbar bleiben. Ein mittlerweile abgeschlossener, von NIST geleiteter Standardisierungsprozess für post-quanten-sichere kryptografische Algorithmen führte zur Standardisierung von drei Signatursystemen. Diese Verfahren haben bisher sämtlichen kryptografischen Angriffen standgehalten, was ihre Sicherheitsversprechen stützt. Da sie nun jedoch für reale Anwendungen vorgesehen sind, muss auch ihre Widerstandsfähigkeit gegenüber Seitenkanal- und Fehlerinjektionsangriffen untersucht werden. Diese Arbeit führt eine solche Untersuchung für Dilithium durch, ein gitterbasiertes Signaturschema, das kürzlich als ML-DSA standardisiert wurde. Wir präsentieren zwei neuartige Algorithmen zur Schlüsselrekonstruktion, die den Schlüssel aus einer geringen, verrauschte Leakage im sogenannten Commitment-Vektor von Dilithium --- vergleichbar mit der Nonce in Schnorr-Signaturen --- wiederherstellen. Beide Algorithmen bringen neue Methoden in die Kryptanalyse ein, übertragen aus den Feldern der diskreten Optimierung und der robusten Statistik. Wir nutzen die Effektivität dieser Algorithmen, um drei ende-zu-ende Seitenkanal- und Fehlerinjektionsangriffe zu demonstrieren, die eine ausreichende Leakage des Commitment-Vektors erzeugen und damit die Wiederherstellung des geheimen Schlüssels ermöglichen. Dabei präsentiert diese Arbeit den ersten vollständigen Stromseitenkanalangriff auf die Referenzimplementierung von Dilithium. Zudem präsentieren wir zwei Angriffe, die vorhandene Gegenmaßnahmen umgehen: einen Fehlerinjektionsangriff auf Implementierungen von Dilithium mit mehreren Schutzmechanismen sowie einen Stromseitenkanalangriff auf eine maskierte Implementierung von Dilithium. Es scheint schwierig, unseren Fehlerinjektionsangriff allein durch algorithmische Gegenmaßnahmen abzuwehren, was auf die Notwendigkeit teurerer Schutzmaßnahmen beim Einsatz von Dilithium hinweist. Die vorgestellten Angriffe und Schlüsselrekonstruktionsalgorithmen lassen sich auf alle gitterbasierten Fiat---Shamir-with-Aborts-Signaturschemata verallgemeinern. Die Bedrohung durch physikalische Angriffe beschränkt sich jedoch nicht auf gitterbasierte Kryptographie. Als Beispiel präsentiert diese Dissertation auch den ersten vollständigen Fehlerinjektionsangriff auf MAYO, ein multivariates Signaturschema. MAYO ist ein vielversprechender Kandidat im Rahmen des NIST-Standardisierungsprozess für alternative, nicht auf strukturierten Gittern basierende, Signaturschemata. Unser Fehlerinjektionsangriff ermöglicht die Wiederherstellung des geheimen Schlüssels innerhalb weniger Sekunden aus nur einer manipulierten Signatur und unterstreicht die Notwendigkeit von Schutzmaßnahmen für MAYO-Implementierungen."],"dc:identifier.uri":["https://depositonce.tu-berlin.de/handle/11303/25232","https://doi.org/10.14279/depositonce-24054"],"dc:language.iso":["en"],"dc:rights.uri":["https://creativecommons.org/licenses/by/4.0/"],"dc:title":["Ensuring reliable and secure deployment of emergent workloads on modern microprocessors"],"dc:type":["Doctoral Thesis"]},"updated_at":"2026-07-27T21:28:52Z"}