Hadi Soleimany

dblp:120/2977 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-3961-4988ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 5 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Algebraic Linked Fault Analysis on PHOTON-Beetle AEAD
abstract
PHOTON-Beetle is an authenticated encryption scheme, which was a finalist in the NIST’s call for standardization in the area of lightweight cryptography (LWC). There are certain difficulties while executing known fault attacks on PHOTON-Beetle in the real world. One of the attacks is in the random fault model, but it requires 237.15faults, which makes it difficult to implement in practice. Other attacks require fewer faults (29.32and 211.5) but rely on the bit-fault models, which necessitates expensive tools and detailed information about the implementation. In this paper, we bridge this gap by presenting an attack that is based on a realistic fault model that requires only 29. We employ a new fault attack technique called linked ineffective fault attack (LIFA). Our attack does not require knowing the plaintext or the corresponding ciphertext. Compared to conventional key-recovery techniques, we provide a highly efficient algebraic method for obtaining the secret key. Furthermore, we introduce linked effective fault analysis (LEFA) and show that, in a noisy environment, LEFA performs significantly better than LIFA in attacking the PHOTON-Beetle while maintaining the basic assumptions of LIFA. We verify our attack using several simulations, as well as conducting practical experiments in the ATmega328P against the publicly available PHOTON-Beetle implementation made available by the designers.
Mohammadsadeq Borjiyan-Borujeni, Hadi Soleimany, Ali Asghar Beigizad
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2024 Linked Fault Analysis
abstract
Numerous fault models with distinct characteristics and effects have been developed. The costs, repeatability, and practicability of these models should be assessed. Moreover, there must be effective ways to use the injected fault to retrieve the secret key, particularly if the implementation includes any countermeasures. In this paper, we introduce a new fault analysis called “linked fault analysis” (LFA), a more powerful technique than other well-known fault attacks against implementations of symmetric primitives, especially in software implementations. For known fault analysis, the basis for the fault model is either the bias over the faulty value or the relationship between the correct value and the faulty one. In the LFA, however, a single fault involves two intermediate values. The faulty target variable,$u'$, is linked to a second variable,$v$, such that a particular relation holds:$u'=l(v)$. LFA lets the attacker perform fault attacks without the input control, using far fewer data than previously introduced fault attacks in the same class. We show the utilization of LFA in the presence or absence of typical redundancy-based countermeasures by introducing “Linked Differential Fault Analysis” (LDFA) and “Linked Ineffective Fault Analysis” (LIFA). We also demonstrate that, under specific circumstances, LFA is still effective even when masking protections are in place. We have performed our attacks against the public implementation of AES and PRESENT in ATMEGA328p to show the feasibility of LFA in the real world. The practical results and simulations validate our theoretical models as well.
Ali Asghar Beigizad, Hadi Soleimany, Sara Zarei 0001, Hamed Ramzanipour
IEEE Trans. Inf. Forensics Secur.2
2023 Exploiting statistical effective fault attack in a blind setting
abstract
Abstract In order to obtain the secret key, the majority of physical attacks require knowledge of the plaintext or ciphertext, which may be unavailable or cannot be exploited. Blind attacks are introduced to do key recovery in circumstances where the adversary has no direct access to plaintext and ciphertext. A combination of fault and power attacks can circumvent typical countermeasures in this setting, for example, Fault Template Attack (FTA). However, FTA relies on bit fault injection, which is difficult to implement in practice. The SIFA‐blind, a framework for executing the Statistical Ineffective Fault Attack, is more flexible, but sensitivity to setup noise and missed faults is its main drawback. To address this deficiency, we suggest two ways to use Statistical Effective Fault Attack in a blind setting that are much less affected by missed faults and noise when measuring power traces, even though they do not use fault injection at the bit level. In order to demonstrate the viability and adaptability of our proposed attacks, we injected a fault via glitch frequency onto the ChipWhisperer board. While SEFA‐blind does not need a bit‐level fault, our results demonstrate that it is better than SIFA‐blind when the number of missed faults increases.
Navid Vafaei, Hadi Soleimany, Nasour Bagheri
IET Inf. Secur.2
2022 Flush+Reload Attacks on SEED
abstract
Abstract Flush+Reload is a powerful access-driven cache attack in which the attacker leverages a security weakness in the X86 processor architecture to extract the private data of the victim. This attack can be mounted in a cross-core setting, where the memory deduplication is enabled and several users are sharing the same physical machine. In this paper, for the first time, we demonstrate that SEED implementation of OpenSSL 1.1.0 running inside the victim VM is vulnerable against the Flush+Reload attacks and the attacker can recover the keys of this encryption. SEED is a standard encryption algorithm that was developed by the Korea Information Security Agency (KISA) and has been used for confidential services in the Republic of Korea. Our work demonstrates that the attacker can retrieve the secret keys of SEED in 3 min in the native setup and 4 min in the cross-VM setup by performing the Flush+Reload technique. Our experimental results show that common implementation of this standard cipher is vulnerable to Flush+Reload attack in both native and cross-VM settings. To the best of our knowledge, this paper presents the first cache-based attack on a SEED block cipher.
Milad Seddigh, Hadi Soleimany
Comput. J.2
2022 Statistical Effective Fault Attacks: The Other Side of the Coin
abstract
The introduction of Statistical Ineffective Fault Attacks (SIFA) has led to a renewed interest in fault attacks. SIFA requires minimal knowledge of the concrete implementation and is effective even in the presence of common fault or power analysis countermeasures. However, further investigations reveal that undesired and frequent ineffective events, which we refer to as the noise phenomenon, are the bottleneck of SIFA that can considerably diminish its strength. This includes noise associated with the attack’s setup and caused by the countermeasures utilized in the implementation. This research aims to address this significant drawback. We present two novel statistical fault attack variants that are far more successful in dealing with these noisy conditions. The first variant is the Statistical Effective Fault Attack (SEFA), which exploits the non-uniform distribution of intermediate variables in circumstances when the induced faults are effective. The idea behind the second proposed method, dubbed Statistical Hybrid Fault Attacks (SHFA), is to take advantage of the biased distributions of both effective and ineffective cases simultaneously. Our experimental results in various case studies, including noise-free and noisy setups, back up our reasoning that SEFA surpasses SIFA in several instances and that SHFA outperforms both or is at least as efficient as the best of them. For example, in the case of a 4-bits random-AND fault injected into the AES with a 35% missed fault rate, utilizing SEFA reduces the number of needed ciphertexts by 50%. In the same case study, SHFA can yield 10% and 55% reductions compared to SEFA and SIFA.
Navid Vafaei, Sara Zarei 0001, Nasour Bagheri, Maria Eichlseder, Robert Primas, Hadi Soleimany
IEEE Trans. Inf. Forensics Secur.6
2021 Enhanced cache attack on AES applicable on ARM-based devices with new operating systems
Mahdi Esfahani, Hadi Soleimany, Mohammad Reza Aref
Comput. Networks2
2020 Framework for faster key search using related-key higher-order differential properties: applications to Agrasta
abstract
The relevance of the related‐key model is usually controversial. However, in some cases, related‐key properties have already been used to reduce the effective key length of the cipher in the single‐key model. Hence, research into this direction can be helpful to bridge the gap between theory and practice aspects of the related‐key model. Motivated by this challenge, the authors develop a new framework to provide further evidence that deterministic related‐key characteristics can be utilised in the single‐key model. The authors describe a sound framework for utilising related‐key higher‐order differential distinguishers that can beat the boundaries given by exhaustive key search. The data required is only one known as plaintext–ciphertext pair if the number of ciphertext bits matches the key length. From a theoretical point of view, the connection between related‐key higher‐order differential properties and the security of cryptographic primitives in the single‐key model are precised. From a practical point of view, the proposed framework is used to evaluate the security of Agrasta cipher which is a variant of Rasta cipher presented at CRYPTO 2018. The proposed method is the first analysis of Agrasta reduced to three rounds that performs better than exhaustive key search and is independent of the used linear layers.
Christoph Dobraunig, Farokhlagha Moazami, Christian Rechberger, Hadi Soleimany
IET Inf. Secur.4
2020 New single-trace side-channel attacks on a specific class of Elgamal cryptosystem
abstract
The so‐called attack is one of the most important order‐2 element attacks, as it requires a non‐adaptive chosen ciphertext which is considered as a more realistic attack model compared to adaptive chosen ciphertext scenario. To protect the implementation against attack, several literatures propose the simplest solution, i.e. ‘block the special message ’. In this study, the authors conduct an in‐depth research on the attack based on the SMA and Montgomery ladder (ML) algorithms. They show that despite the unaccepted ciphertext countermeasure, other types of attacks are applicable to specific classes of Elgamal cryptosystems. They propose new chosen‐message power‐analysis attacks with order‐4 elements which utilise a chosen ciphertext c such that where p is the prime number used as a modulus in Elgamal. Such a ciphertext can be found simply when . They demonstrate that ML and SMA algorithms are subjected to the new ‐type attack by utilising a different ciphertext. They implement the proposed attacks on the TARGET Board of the ChipWhisperer CW1173 and the proposed experiments validate the feasibility and effectiveness of the attacks by using only a single power trace.
Parinaz Mahdion, Hadi Soleimany, Pouya Habibi, Farokhlagha Moazami
IET Inf. Secur.2
2016 Key Recovery Attack Against 2.5-Round \pi -Cipher
Christina Boura, Avik Chakraborti, Gaëtan Leurent, Goutam Paul 0001, Dhiman Saha, Hadi Soleimany, Valentin Suder
FSE6
2015 Self-similarity cryptanalysis of the block cipher ITUbee
abstract
Recent developments in the resource constrained devices have led to a renewed interest in designing light‐weight primitives with inventive and unconventional structures. Using round‐dependent constants instead of a strong key schedule is one of the most widely used trick against the self‐similarity cryptanalysis in recent cipher proposals. So far there has been little discussion about the effect of the round constants on the security of the ciphers. In this study, the authors identify several weaknesses in round‐reduced versions of the block cipher ITUbee, which was presented recently at LightSec 2013. These weaknesses allow to build relations between the round constants. The author's technique leads to several cryptanalysis in the weak‐key, related‐key and single‐key models and shows that the resistance of ITUbee against self‐similarity cryptanalysis is not independent of the values of round constants. They show that the round‐reduced cipher under a fraction of the keys is distinguishable from an ideal random permutation. Then they utilise a similar technique to show there exists a deterministic related‐key differential distinguisher for up to eight rounds of the cipher. This observation leads to the decrease of the security of 8‐round ITUbee in the single‐key model by one bit.
Hadi Soleimany
IET Inf. Secur.1
2015 Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012
J. Cryptol.1
2014 Probabilistic Slide Cryptanalysis and Its Applications to LED-64 and Zorro
Hadi Soleimany
FSE1
2014 Zero-correlation linear cryptanalysis of reduced-round LBlock
Hadi Soleimany, Kaisa Nyberg
Des. Codes Cryptogr.1
2013 Reflection Cryptanalysis of PRINCE-Like Ciphers
Hadi Soleimany, Céline Blondeau, Xiaoli Yu, Wenling Wu, Kaisa Nyberg, Lei Zhang 0012
FSE1