Trepo - Selaus tekijän mukaan "Brumley, Billy Bob"

    • Attestation Waves: Platform Trust via Remote Power Analysis 

      Delgado-Lozano, Ignacio M.; Martínez-Rodríguez, Macarena C.; Bakas, Alexandros; Brumley, Billy Bob; Michalas, Antonis
      Lecture Notes in Computer Science (2021)
      conference
      <p>Attestation is a strong tool to verify the integrity of an untrusted system. However, in recent years, different attacks have appeared that are able to mislead the attestation process with treacherous practices ...
    • Cache storage attacks 

      Brumley, Billy Bob
      Lecture Notes in Computer Science (2015)
      conference
      <p>Covert channels are a fundamental concept for cryptanalytic side-channel attacks. Covert timing channels use latency to carry data, and are the foundation for timing and cache-timing attacks. Covert storage channels ...
    • Cache-Timing Attacks on RSA Key Generation 

      Aldaya, Alejandro Cabrera; Pereida García, Cesar; Alvarez Tapia, Luis Manuel; Brumley, Billy Bob (2019)
      article
      During the last decade, constant-time cryptographic software has quickly transitioned from an academic construct to a concrete security requirement for real-world libraries. Most of OpenSSL’s constant-time code paths are ...
    • Constant-Time Callees with Variable-Time Callers 

      Pereida Garcia, Cesar; Brumley, Billy Bob (2017)
      conference
      Side-channel attacks are a serious threat to security critical software. To mitigate remote timing and cache-timing attacks, many ubiquitous cryptography software libraries feature constant-time implementations of cryptographic ...
    • Déjà Vu: Side-Channel Analysis of Mozilla's NSS 

      Hassan, Sohaib Ul; Gridin, Iaroslav; Delgado-Lozano, Ignacio M.; García, Cesar Pereida; Chi-Domínguez, Jesús Javier; Aldaya, Alejandro Cabrera; Brumley, Billy Bob
      Proceedings of the ACM Conference on Computer and Communications Security (30.10.2020)
      conference
      <p>Recent work on Side Channel Analysis (SCA) targets old, well-known vulnerabilities, even previously exploited, reported, and patched in high-profile cryptography libraries. Nevertheless, researchers continue to ...
    • Faster Binary Curve Software: A Case Study 

      Brumley, Billy Bob
      Lecture Notes in Computer Science (2015)
      conference
    • A Formula for Disaster: A Unified Approach to Elliptic Curve Special-Point-Based Attacks 

      Sedlacek, Vladimir; Chi-Domínguez, Jesús Javier; Jancar, Jan; Brumley, Billy Bob
      Lecture Notes in Computer Science (2021)
      conference
      The Refined Power Analysis, Zero-Value Point, and Exceptional Procedure attacks introduced side-channel techniques against specific cases of elliptic curve cryptography. The three attacks recover bits of a static ECDH key ...
    • From A to Z - Projective coordinates leakage in the wild 

      Cabrera Aldaya, Alejandro; Pereida García, Cesar; Brumley, Billy Bob (06 / 2020)
      article
    • Investigating child sexual abuse material availability, searches, and users on the anonymous Tor network for a public health intervention strategy 

      Nurmi, Juha; Paju, Arttu; Brumley, Billy Bob; Insoll, Tegan; Ovaska, Anna K.; Soloveva, Valeriia; Vaaranen-Valkonen, Nina; Aaltonen, Mikko; Arroyo, David (2024)
      article
      Tor is widely used for staying anonymous online and accessing onion websites; unfortunately, Tor is popular for distributing and viewing illicit child sexual abuse material (CSAM). From 2018 to 2023, we analyse 176,683 ...
    • "Make Sure DSA Signing Exponentiations Really are Constant-Time" 

      García, Cesar Pereida; Brumley, Billy Bob; Yarom, Yuval (2016)
      conference
      TLS and SSH are two of the most commonly used protocols for securing Internet traffic. Many of the implementations of these protocols rely on the cryptographic primitives provided in the OpenSSL library. In this work we ...
    • Malware Finances and Operations: a Data-Driven Study of the Value Chain for Infections and Compromised Access 

      Nurmi, Juha; Niemelä, Mikko; Brumley, Billy Bob (29.08.2023)
      conference
    • Memory Tampering Attack on Binary GCD Based Inversion Algorithms 

      Aldaya, Alejandro Cabrera; Brumley, Billy Bob; Sarmiento, Alejandro J.Cabrera; Sánchez-Solano, Santiago (2018)
      article
      <p>In the field of cryptography engineering, implementation-based attacks are a major concern due to their proven feasibility. Fault injection is one attack vector, nowadays a major research line. In this paper, we ...
    • OpenSSLNTRU: Faster post-quantum TLS key exchange 

      Bernstein, Daniel J.; Brumley, Billy Bob; Chen, Ming-Shing; Tuveri, Nicola (10.08.2022)
      conference
      Google's CECPQ1 experiment in 2016 integrated a post-quantum key-exchange algorithm, newhope1024, into TLS 1.2. The Google-Cloudflare CECPQ2 experiment in 2019 integrated a more efficient key-exchange algorithm, ntruhrss701, ...
    • Set It and Forget It! Turnkey ECC for Instant Integration 

      Belyavsky, Dmitry; Brumley, Billy Bob; Chi-Domínguez, Jesús-Javier; Rivera-Zamarripa, Luis; Ustinov, Igor (2020)
      conference
      Historically, Elliptic Curve Cryptography (ECC) is an active field of applied cryptography where recent focus is on high speed, constant time, and formally verified implementations. While there are a handful of outliers ...
    • SoK: A Systematic Review of TEE Usage for Developing Trusted Applications 

      Paju, Arttu; Javed, Muhammad Owais; Nurmi, Juha; Savimäki, Juha; McGillion, Brian; Brumley, Billy Bob (29.08.2023)
      conference
      Trusted Execution Environments (TEEs) are a feature of modern central processing units (CPUs) that aim to provide a high assurance, isolated environment in which to run workloads that demand both confidentiality and ...
    • SoK: Remote Power Analysis 

      Martínez-Rodríguez, MacArena C.; Delgado-Lozano, Ignacio M.; Brumley, Billy Bob
      ACM International Conference Proceeding Series (17.08.2021)
      conference
      In recent years, numerous attacks have appeared that aim to steal secret information from their victim using the power side-channel vector, yet without direct physical access. These attacks are called Remote Power Attacks ...
    • When one vulnerable primitive turns viral - Novel single-trace attacks on ECDSA and RSA 

      Cabrera Aldaya, Alejandro; Brumley, Billy Bob (2020)
      article