Technische Universität Berlin
Ensuring reliable and secure deployment of emergent workloads on modern microprocessors
Abstract
dc:description.abstractDependable systems aim to provide reliability and security guarantees, protecting against both random events and intentional threats. Physical phenomena, such as hardware faults, pose a challenge to dependable systems, as they can undermine both reliability and security. While these challenges have been extensively studied in the past, recent developments in fault models and cryptographic implementations introduce new challenges that call for new solutions. This thesis addresses challenges posed by these recent developments in two parts. First, it addresses new challenges to the reliability and fault resilience of modern microprocessors. A recent surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviors at scale suggests a change in the nature of faults in the wild. Recent publications suggest that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects. While microarchitectural mitigations to SDFs are known, placing them on the entire chip is prohibitively expensive. This thesis presents DelayAVF, a new metric to quantify the vulnerability of a processor design to small delay faults. DelayAVF provides key architectural insights that can be used to identify structures which are particularly vulnerable to SDFs, helping to guide targeted protections against these faults. We also present a case study on the OpenTitan hardware root of trust, exposing a real-world vulnerability in OpenTitan’s fault injection countermeasures. Our case study demonstrates the difficulty of correctly integrating fault injection countermeasures in pipelined processors. The second part of this thesis explores the resilience of post-quantum secure algorithms and implementations against physical attacks. The plausible advent of general-purpose quantum computing in the coming decades poses a mounting threat to contemporary public-key cryptography. This threat spurred the development of new cryptographic schemes that base their security on mathematical problems which remain hard even on a quantum computer. A now-finished NIST-led standardization process for post-quantum secure cryptographic algorithms has led to the standardization of three signature schemes. These schemes have thus far withstood cryptanalysis, lending credence to their security claims. However, as they are now slated for real-world deployment, their resilience against side-channel and fault injection attacks must be studied as well. This thesis conducts this investigation for Dilithium, a lattice-based signature scheme recently standardized as ML-DSA. We present two novel key recovery algorithms that elevate a minor, noisy leakage on Dilithium’s commitment vector, which is similar to the nonce in Schnorr signatures, into full secret key recovery. Both algorithms introduce methodologies that are novel to cryptanalysis, drawing on techniques from discrete optimization and outlier-resilient statistics. We use the efficacy of our key recovery algorithms to demonstrate three end-to-end side-channel and fault injection attacks that achieve sufficient leakage on Dilithium’s commitment vector and, consequently, secret-key recovery. We present the first end-to-end power-side channel attack on Dilithium’s reference implementation. We also present two attacks that subvert countermeasures presented by prior work: a fault injection attack against Dilithium implementations that implement multiple fault injection countermeasures, and a power side-channel attack against a masked Dilithium implementation. Our fault injection attack appears hard to protect against using only algorithm countermeasures, pointing to the need for more expensive countermeasures when deploying Dilithium. The attacks and key recovery algorithms presented in this thesis generalize to all lattice-based Fiat–Shamir with aborts signature schemes. The threat of physical attacks is not restricted to lattice-based cryptography, however. As a case in point, this thesis also presents the first end-to-end fault injection attack against MAYO, a multivariate signature scheme. MAYO is a promising candidate for the NIST call for alternative signature schemes, a standardization call that aims to standardize signature schemes that are not based on structured lattices. Our fault injection attack allows for secret key recovery within seconds from only one faulted signature, and underscores the need for protective measures for MAYO implementations.
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Ulitzsch, Vincent Quentin
- Advisor dc:contributor.advisor
-
- Seifert, Jean-Pierre
Rights
- Licence dc:rights.uri
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- Identifier URI
- https://doi.org/10.14279/depositonce-24054
- OAI identifier oai:identifier
- oai:depositonce.tu-berlin.de:11303/25232