Ruggero Susella

dblp:07/8151 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-5700-2811ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 since 2021
YearPublicationVenuePosition
2023 A Flexible ASIC-Oriented Design for a Full NTRU Accelerator
abstract
Post-quantum cryptosystems are the subject of a significant research effort, witnessed by various international standardization competitions. Among them, the NTRU Key Encapsulation Mechanism has been recognized as a secure, patent-free, and efficient public key encryption scheme. In this work, we perform a design space exploration on an FPGA target, with the final goal of an efficient ASIC realization. Specifically, we focus on the possible choices for the design of polynomial multipliers with different memory bus widths to trade-off lower clock cycle counts with larger interconnections. Our design outperforms the best FPGA synthesis results at the state of the art, and we report the results of ASIC syntheses minimizing latency and area with a 40nm industrial grade technology library. Our speed-oriented design computes an encapsulation in 4.1 to 10.2μs and a decapsulation in 7.1 to 11.7μs, depending on the NTRU security level, while our most compact design only takes 20% more area than the underlying SHA-3 hash module.
Francesco Antognazza, Alessandro Barenghi, Gerardo Pelosi, Ruggero Susella
ASP-DAC4
2023 An Efficient Unified Architecture for Polynomial Multiplications in Lattice-Based Cryptoschemes
abstract
The significant effort in the research and design of large-scale quantum computers has spurred a transition to post-quantum cryptographic primitives worldwide. The post-quantum cryptographic primitive standardization effort led by the US NIST has recently selected the asymmetric encryption primitive Kyber as its candidate for standardization. It has also indicated NTRU, another lattice-based primitive, as a valid alternative if intellectual property issues are not solved. Finally, a more conservative alternative to NTRU, NTRUPrime was also considered as an alternate candidate, due to its design choices which remove the possibility for a large set of attacks preemptively. All the aforementioned asymmetric primitives provide good performances, and are prime choices provide IoT devices with post-quantum confidentiality services. In this work, we propose a unified design for a hardware accelerator able to speed up the computation of polynomial multiplications, the workhorse operation in all of the aforementioned cryptosystems, managing the differences in the polynomial rings of the cryptosystems. Our design is also able to outperform the state of the art designs tailored specifically for NTRU, and provide latencies similar to the symmetric cryptographic elements required by the scheme for Kyber and NTRUPrime.
Francesco Antognazza, Alessandro Barenghi, Gerardo Pelosi, Ruggero Susella
ICISSP4
2022 Profiled side channel attacks against the RSA cryptosystem using neural networks
Alessandro Barenghi, Diego Carrera, Silvia Mella, Andrea Pace, Gerardo Pelosi, Ruggero Susella
J. Inf. Secur. Appl.6
2021 Profiled Attacks Against the Elliptic Curve Scalar Point Multiplication Using Neural Networks
Alessandro Barenghi, Diego Carrera, Silvia Mella, Andrea Pace, Gerardo Pelosi, Ruggero Susella
NSS6
2018 Breaking Ed25519 in WolfSSL
Niels Samwel, Lejla Batina, Guido Bertoni, Joan Daemen, Ruggero Susella
CT-RSA5
2018 CASCA: A Design Automation Approach for Designing Hardware Countermeasures Against Side-Channel Attacks
abstract
Implementing a cryptographic circuit poses challenges not always acknowledged in the backing mathematical theory. One of them is the vulnerability against side-channel attacks . A side-channel attack is a procedure that uses information leaked by the circuit through, for example, its own power consumption or electromagnetic emissions, to derive sensitive data (e.g, the secret key used for encryption). Nowadays, we design circuitry to keep this sensitive information from leaking (i.e., a countermeasure ), but the path from specification down to implementation is far from being fully automatic. As we know, manual refinement steps can be error prone and the sheer potential of these errors can be devastating in a scenario such as the one we are dealing with. In this article, we investigate whether a single embedded domain specific language (EDSL) can, at the same time, help us in specifying and enforcing the functionality of the circuit as well as its protection against side-channel attacks. The EDSL is a fundamental block of an original design flow (named Countermeasure Against Side-Channel Attacks, i.e., CASCA) whose aim is to complement an existing industrial scenario and to provide the necessary guarantee that a secure primitive is not vulnerable up to a first-order attack. As a practical case study, we will show how we applied the proposed tools to ensure both functional and extra-functional correctness of a composite-field Advanced Encryption Standard (AES) S-Box. To ensure the reproducibility of this research, this article is accompanied by an open source release of the EDSL 1 that contains the presented S-Box implementation and an additional 3-Shares threshold implementation of the Keccak χ function [7].
Lorenzo Delledonne, Vittorio Zaccaria, Ruggero Susella, Guido Bertoni, Filippo Melzani
ACM Trans. Design Autom. Electr. Syst.3
2016 A Compact and Exception-Free Ladder for All Short Weierstrass Elliptic Curves
Ruggero Susella, Sofia Montrasio
CARDIS1
2016 A Fault-Based Secret Key Retrieval Method for ECDSA: Analysis and Countermeasure
abstract
Elliptic curve cryptosystems proved to be well suited for securing systems with constrained resources like embedded and portable devices. In a fault-based attack, errors are induced during the computation of a cryptographic primitive, and the results are collected to derive information about the secret key safely stored in the device. We introduce a novel attack methodology to recover the secret key employed in implementations of the Elliptic Curve Digital Signature Algorithm. Our attack exploits the information leakage induced when altering the execution of the modular arithmetic operations used in the signature primitive and does not rely on the underlying elliptic curve mathematical structure, thus being applicable to all standardized curves. We provide both a validation of the feasibility of the attack, even employing common off-the-shelf hardware to perform the required computations, and a low-cost countermeasure to counteract it.
Alessandro Barenghi, Guido Bertoni, Luca Breveglieri, Gerardo Pelosi, Stefano Sanfilippo, Ruggero Susella
ACM J. Emerg. Technol. Comput. Syst.6
2015 New Results for Partial Key Exposure on RSA with Exponent Blinding
abstract
In 1998, Boneh, Durfee and Frankel introduced partial key exposure attacks, a novel application of Coppersmith's method, to retrieve an RSA private key given only a fraction of its bits.This type of attacks is of particular interest in the context of side-channel attacks.By applying the exponent blinding technique as a countermeasure for side-channel attacks, the private exponent becomes randomized at each execution.Thus the attacker has to rely only on a single trace, significantly incrementing the noise, making the exponent bits recovery less effective.This countermeasure has also the side-effect of modifying the RSA equation used by partial key exposure attacks, in a way studied by Joye and Lepoint in 2012.We improve their results by providing a simpler technique in the case of known least significant bits and a better bound for the known most significant bits case.Additionally, we apply partial key exposure attacks to CRT-RSA when exponent blinding is used, a case not yet analyzed in literature.Our findings, for which we provide theoretical and experimental results, aim to reduce the number of bits to be recovered through side-channel attacks in order to factor an RSA modulus when the implementation is protected by exponent blinding.
Stelvio Cimato, Silvia Mella, Ruggero Susella
SECRYPT3
2013 On the Homomorphic Computation of Symmetric Cryptographic Primitives
Silvia Mella, Ruggero Susella
IMACC2