Ronan Lashermes

dblp:119/1192 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0002-0309-6533ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 On the Origins of Indirect Jumps in Embedded Software
abstract
Indirect control-flow transfers complicate control-flow graph (CFG) construction, thereby reducing the precision of static analyses and control-flow integrity mechanisms in embedded systems. While previous work has primarily focused on resolving indirect jump targets, comparatively little attention has been devoted to understanding the reasons behind their generation. This paper presents a systematic empirical study of the origins of indirect jumps in compiled binaries. We introduce a taxonomy that characterizes the programming constructs and compiler transformations responsible for their generation. Our analysis encompasses C, C++, Fortran, and Rust programs compiled with GCC and LLVM at multiple optimization levels, targeting the 32-bit RISC-V instruction set. We then quantify the prevalence of each identified category over representative benchmarks and analyze differences across programming languages and compilation configurations. By clarifying the origins of indirect control transfers, this work provides insight into their impact on CFG precision and the static analysis of embedded software.
Ariane Nicolas, Ronan Lashermes, Isabelle Puaut, Erven Rohou
LCTES2
2025 Exploring Speculation Barriers for RISC-V Selective Speculation
Herinomena Andrianatrehina, Ronan Lashermes, Joseph Paturel, Simon Rokicki, Thomas Rubiano
ARES (2)2
2021 Under the Dome: Preventing Hardware Timing Information Leakage
Mathieu Escouteloup, Ronan Lashermes, Jacques J. A. Fournier, Jean-Louis Lanet
CARDIS2
2018 Let's shock our IoT's heart: ARMv7-M under (fault) attacks
abstract
A fault attack is a well-known technique where the behaviour of a chip is voluntarily disturbed by hardware means in order to undermine the security of the information handled by the target. In this paper, we explore how Electromagnetic fault injection (EMFI) can be used to create vulnerabilities in sound software, targeting a Cortex-M3 microcontroller. Several use-cases are shown experimentally: control flow hijacking, buffer overflow (even with the presence of a canary), covert backdoor insertion and Return Oriented Programming can be achieved even if programs are not vulnerable in a software point of view. These results suggest that the protection of any software against vulnerabilities must take hardware into account as well.
Sébanjila Kevin Bukasa, Ronan Lashermes, Jean-Louis Lanet, Axel Legay
ARES2
2017 How TrustZone Could Be Bypassed: Side-Channel Attacks on a Modern System-on-Chip
Sébanjila Kevin Bukasa, Ronan Lashermes, Hélène Le Bouder, Jean-Louis Lanet, Axel Legay
WISTP2
2016 High-Performance Elliptic Curve Cryptography by Using the CIOS Method for Modular Multiplication
Amine Mrabet, Nadia El Mrabet, Ronan Lashermes, Jean-Baptiste Rigaud, Belgacem Bouallegue, Sihem Mesnager, Mohsen Machhout
CRiSIS3
2016 A Template Attack Against VERIFY PIN Algorithms
abstract
International audience
Hélène Le Bouder, Thierno Barry 0002, Damien Couroussé, Jean-Louis Lanet, Ronan Lashermes
SECRYPT5
2014 Practical Validation of Several Fault Attacks against the Miller Algorithm
abstract
Pairing based cryptography (PBC) is touted as an efficient approach to address usability and privacy issues in the cyberspace. Like most cryptographic algorithms, PBC must be robust not only against theoretical cryptanalysis but also against practical physical attacks such as fault injections. The computation of the Tate pairing can be divided into two parts, the Miller Algorithm and the Final Exponentiation. In this paper, we describe practical implementations of fault attacks against the Miller Algorithm validating common fault models used against pairings. In the light of the implemented fault attacks, we show that some blinding techniques proposed to protect the algorithm against Side-Channels Analyses cannot be used as countermeasures against the implemented fault attacks.
Ronan Lashermes, Marie Paindavoine, Nadia El Mrabet, Jacques J. A. Fournier, Louis Goubin
FDTC1
2013 Inverting the Final Exponentiation of Tate Pairings on Ordinary Elliptic Curves Using Faults
Ronan Lashermes, Jacques J. A. Fournier, Louis Goubin
CHES1
2012 A DFA on AES Based on the Entropy of Error Distributions
abstract
Differential fault analysis (DFA) techniques have been widely studied during the past decade. To our best knowledge, most DFA techniques on the Advanced Encryption Standard (AES) either impose strong constraints on the fault injection process or require numerous faults in order to recover the secret key. This article presents a simple methodology based on information theory which allows to adapt the number of required faults for the analysis to the fault injection process. With this technique, the constraints on the fault model to recover the last round key are considerably lowered. Additionally, entropy is proposed as a tool to apprehend the most complex fault models in DFA. A practical realization and simulations are presented to illustrate our methodology.
Ronan Lashermes, Guillaume Reymond, Jean-Max Dutertre, Jacques J. A. Fournier, Bruno Robisson, Assia Tria
FDTC1