Professor David Oswald

Professor David Oswald

School of Computer Science
Professor in Computer Security
Head of Research of Computer Science

Contact details

Address
School of Computer Science
University of Birmingham
Edgbaston
Birmingham
B15 2TT
UK

David Oswald is a Full Professor in the Centre for Cyber Security and Privacy at the University of Birmingham, UK. His main field of research is the security of embedded systems and trusted execution. On the one hand, the focus is on attack methods that exploit weaknesses in the physical implementation of mathematically secure cryptographic algorithms. Those techniques include both (passive) side-channel analysis and (active) fault injection, as well as reverse engineering.

On the other hand, David is working on the practical realization of security systems in embedded applications. His research on vulnerabilities of various wide-spread systems (e.g. DESFire RFID smartcards, VW/Hitag2 RKE systems, and Intel SGX) has created awareness for the crucial importance of security among developers of embedded devices.

For more information please visit David's Computer Science profile

Qualifications

  • PhD (“Dr.-Ing.”) in IT Security (Ruhr-University Bochum) 2013
  • Combined MSc/BSc in IT Security (“Dipl.-Ing.”) 2009

Postgraduate supervision

  • Murdock, main supervisor, since 2018: FaultFinder: From Faulty Output to Fault Model --- An Automated Approach

  • Pemberton, main supervisor, since 2018: BioLeak: Side-Channel Analysis of Fingerprint Matching Algorithms

  • Aldoseri, main supervisor since 2018: Security of TEEs

  • Zhang, main supervisor since 2019: Next-generation security protocols for medical devices

  • Spielman, main supervisor since 2021: SCAvenger - Attacking Machine Learning with Side Channel Attacks
  • Jacqueline, main supervisor since 2021: Capability architectures: attacks and defenses

Research

  • Embedded system security

  • IoT, RFID and wireless communication

  • Real-world implementation attacks

  • Side-channel analysis

  • Trusted Execution Environments

Publications

Recent publications

Article

Chen, Z & Oswald, D 2023, 'PMFault: Faulting and Bricking Server CPUs through Management Interfaces: Or: A Modern Example of Halt and Catch Fire', IACR Transactions on Cryptographic Hardware and Embedded Systems, vol. 2023, no. 2, pp. 1-23. https://doi.org/10.46586/tches.v2023.i2.1-23

Alder, F, Van Bulck, J, Spielman, J, Oswald, D & Piessens, F 2022, 'Faulty point unit: ABI poisoning attacks on trusted execution environments', Digital Threats: Research and Practice, vol. 3, no. 2, 13, pp. 1-26. https://doi.org/10.1145/3491264

Conference contribution

Murdock, K, Thompson, M & Oswald, D 2024, FaultFinder: lightning-fast, multi-architectural fault injection simulation. in ASHES '24: Proceedings of the 2024 Workshop on Attacks and Solutions in Hardware Security. Association for Computing Machinery (ACM), 8th Workshop on Attacks and Solutions in Hardware Security, Salt Lake City, Utah, United States, 18/10/24.

Zhang, M, Marin, E, Ryan, M, Kostakos, V, Murray, T, Tag, B & Oswald, D 2024, OOBKey: Key Exchange with Implantable Medical Devices Using Out-Of-Band Channels. in 2024 21st Annual International Conference on Privacy, Security and Trust (PST). Annual International Conference on Privacy, Security and Trust, IEEE.

Bowden, M, Chothia, T, Clee, A, Collins, S, Henes, J & Oswald, D 2024, Teaching Adversarial Thinking by Having Students Circumvent Exam Rules. in The 4th Annual Advances in Cyber Security Education: CSE-Connect . Springer Lecture Notes in Networks and Systems, The 4th Annual Advances in Cyber Security Education, Bristol, United Kingdom, 2/07/24.

Pemberton, O & Oswald, D 2023, BioLeak: Exploiting Cache Timing to Recover Fingerprint Minutiae Coordinates. in ASHES '23: Proceedings of the 2023 Workshop on Attacks and Solutions in Hardware Security. CCS: Computer and Communications Security, Association for Computing Machinery (ACM), pp. 61–72, 2023 Workshop on Attacks and Solutions in Hardware Security (ASHES ’23), Copenhagen, Denmark, 30/11/23. https://doi.org/10.1145/3605769.3623994

Van Strydonck , T, Noorman , J, Jackson, J, Dias, L, Vanderstraeten , R, Oswald, D, Piessens, F & Devriese , D 2023, CHERI-TrEE: Flexible enclaves on capability machines. in EuroS&P - 8th IEEE European Symposium on Security and Privacy. IEEE European Symposium on Security and Privacy, IEEE, pp. 1143-1159, 8th IEEE European Symposium on Security and Privacy, Delft, Netherlands, 3/07/23. https://doi.org/10.1109/EuroSP57164.2023.00070.

Alder, F, Daniel, L-A, Oswald, D, Piessens, F & Van Bulck, J 2023, Pandora: Principled Symbolic Validation of Intel SGX Enclave Runtimes. in 2024 IEEE Symposium on Security and Privacy (SP). Proceedings of the IEEE Symposium on Security and Privacy , IEEE, 45th IEEE Symposium on Security and Privacy, San Francisco, California, United States, 20/05/24.

Xu, Z, Pemberton, O, Oswald, D & Zheng, Z 2023, Reveal the invisible secret: chosen-ciphertext side-channel attacks on NTRU. in International Conference on Smart Card Research and Advanced Applications: CARDIS 2022: Smart Card Research and Advanced Applications. Lecture Notes in Computer Science, vol. 13820, Springer, pp. 227–247, 21st Smart Card Research and Advanced Application Conference, Birmingham, United Kingdom, 7/11/22. https://doi.org/10.1007/978-3-031-25319-5_12

Aldoseri, A, Chothia, T, Moreira-Sanchez, J & Oswald, D 2023, Symbolic Modelling of Remote Attestation Protocols for Device and App Integrity on Android. in J Liu, Y Xiang, S Nepal & G Tsudik (eds), ASIA CCS '23: Proceedings of the 2023 ACM on Asia Conference on Computer and Communications Security. Association for Computing Machinery (ACM), pp. 218–231, 18th ACM ASIA Conference on Computer and Communications Security , Melbourne, Victoria, Australia, 10/07/23. https://doi.org/10.1145/3579856.3582812

Aldoseri, A, Oswald, D & Chiper, R 2022, A tale of four gates: privilege escalation and permission bypasses on android through app components. in V Atluri, R Di Pietro, CD Jensen & W Meng (eds), Computer Security – ESORICS 2022: 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26–30, 2022, Proceedings, Part II. 1 edn, Lecture Notes in Computer Science, vol. 13555, Springer, pp. 233–251. https://doi.org/10.1007/978-3-031-17146-8_12

Zhang, M, Marin, E, Oswald, D & Singelée, D 2022, FuzzyKey: comparing fuzzy cryptographic primitives on resource-constrained devices. in V Grosso & T Pöppelmann (eds), Smart Card Research and Advanced Applications - 20th International Conference, CARDIS 2021, Revised Selected Papers: 20th International Conference, CARDIS 2021, Lübeck, Germany, November 11–12, 2021, Revised Selected Papers. Lecture Notes in Computer Science, vol. 13173, Springer Verlag, pp. 289-309, 20th Smart Card Research and Advanced Application Conference, Lübeck, Germany, 11/11/21. https://doi.org/10.1007/978-3-030-97348-3_16

Aldoseri, A & Oswald, D 2022, insecure://: Vulnerability analysis of URI scheme handling in Android mobile browsers. in Proceedings of MADWeb 2022: Workshop on Measurements, Attacks, and Defenses for the Web. Proceedings of the Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb), The Internet Society, Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb) 2022
, 28/04/22. https://doi.org/10.14722/madweb.2022.23003

Preprint

Wang, Q & Oswald, D 2024 'Confidential Computing on Heterogeneous CPU-GPU Systems: Survey and Future Directions' arXiv. https://doi.org/10.48550/arXiv.2408.11601

Zhang, C, Yang, X, Oswald, D, Ryan, M & Jovanovic, P 2024 'Eva: Efficient IVC-Based Authentication of Lossy-Encoded Videos' Cryptology ePrint Archive. <https://eprint.iacr.org/2024/1436>

View all publications in research portal