VLDB 2026 Research / reviewers in the wild / expert
Philippe Roche
dblp:17/3699
· DBLP profile ↗
19ranked-venue papers
1as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 17 · 1 first-author · 10 since 2021Software engineering, systems software and programming languages · 10 · 1 first-author · 6 since 2021Theory of computation · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Framework for Chiplet Authentication During Post-Stacking TestabstractThe semiconductor industry is adopting chiplets as an alternative to integrated circuit design. With adoption of off-the-shelf chiplets, supply chain attacks are likely to increase, making chiplet authentication essential. This work identifies post-stacking testing as the best phase for authentication and proposes a framework using existing industry standards. The framework includes a flexible authentication IP integrated into the chiplet design, compatible with various authentication methods; an IP insertion flow compatible with commercial DFT insertion tools; a secure module for the test environment; and the corresponding test procedure. Results show that chiplet authentication can be implemented without disrupting industry practices, with multiple authentication methods available based on the context. Juan Suzano, Anthony Philippe, Fady Abouzeid, Philippe Roche, Giorgio Di Natale |
DDECS | 4 |
| 2026 | Fault Model-Driven Formal Verification of Cryptographic Hardware Against Fault Attacks
Daniel Thirion, George-Cristian Sercaianu, Valentin Egloff, Jean-Marc Daveau, Vincent Beroulle, David Hély, Philippe Roche |
ETS | 7 |
| 2026 | Reducing Safety False-Positives in Parity-Based Security AES Using a Hardware Fault ClassifierabstractInternational audience Daniel Thirion, Jean-Marc Daveau, Valentin Egloff, Vincent Beroulle, Philippe Roche, David Hély |
IOLTS | 5 |
| 2025 | Comparative Study of Safety and Security-Protected AES DesignsabstractWith the increase in cybersecurity requirements and the growing connectivity of critical systems like vehicles and satellites, implementing both functional safety and hardware security is crucial. Although safety and security methods are well studied, combined analysis at the RTL or Netlist level remains under-explored. This paper provides an initial analysis of multiple AES designs—one unprotected, one with a safety-oriented countermeasure (Lockstep), and one with security-oriented countermeasures (Parity-Predictor)—using both simulation and formal methods. We identify the challenges and opportunities for enhancing combined safety and security assessments. Additionally, we evaluate the AES designs against ISO 26262 safety metrics and analyze their resilience to laser attacks, offering insight into their security robustness. Daniel Thirion, Jean-Marc Daveau, Valentin Egloff, David Hély, Vincent Beroulle, Philippe Roche |
DDECS | 6 |
| 2025 | Dose Effects and Mitigation in 28nm FD-SOI Advanced Interface Bus Chiplet InterconnectabstractChiplet technology for 2.5-D/3-D integration is being rapidly adopted, including for System-on-Chips used in mission critical applications. We present a Total Ionizing Dose Effect study of a prototype Advanced Interface Bus (AIB) die-to-die interface in 28nm FD-SOI technology using pulsed x-rays and in-situ monitoring of the dose. Degradation of the maximum working frequency of the interface was observed due to the deposited dose. Using either the core voltage or the body bias voltage, we demonstrate that it is possible to partially recover this frequency loss. In space applications, this compensation, combined with in-situ dose monitoring, can be used to extend the life of 2.5-D/3-D circuits using high-speed die-to-die interfaces. Antoine Rouget, Fady Abouzeid, Adrian Evans, Victor Malherbe, Aleksandra Chumakova, Philippe Roche, Fabien Clermidy |
IOLTS | 6 |
| 2025 | Formal Analysis of Fault Propagation in Complex Digital SystemsabstractWith the increasing availability of computational resources and the progress in research concerning automated formal methods, the characterization of safety features for hardware requires improved precision in functional vulnerability detection. In the context of formal fault injection, the model checking algorithm can be used to detect vulnerabilities in digital systems by violating the nominal temporal properties. We present a general methodology to reduce the state space that is computed and traversed during these fault campaigns. The chosen criteria preserves the nominal behavior and the failure modes, expressed by the fault-violated properties. This process is crucial to provide a manipulable object for subsequent Failure Mode and Effects Analysis. Finally, we propose an assumption-based guarantee technique to model how a fault may propagate through different hardware units, for a scalable methodology of formal fault injection and vulnerability detection in complex SoCs. Damiano Zuccalà, Samuel Hon, Mohammad Reza Heidari Iman, Jean-Marc Daveau, Philippe Roche, Katell Morin-Allory |
MEMOCODE | 5 |
| 2024 | IEEE 1838 compliant scan encryption and integrity for 2.5/3D ICsabstract2.5D and 3D integrated circuits (IC) are the natural evolution of traditional 2D SoCs. 2.5D and 3D integration is the process of assembling pre-manufactured chiplets in an interposer or in a stack. This process can damage the chiplets or lead to faulty connections. Thus, the importance of post-bond test of chiplets. The IEEE Std 1838(TM)-2019 (IEEE 1838) design-for-testability (DFT) standard defines mandatory and optional structures for accessing DFT functions on the chiplet. Compliant chiplets form a DFT network that can be exploited by attackers to violate the confidentiality or integrity of the message transmitted over the serial path. In this work, we combine a message integrity verification system with a scan encryption mechanism to protect the scan chain of an IEEE 1838-compliant DFT implementation. The scan encryption prevents unauthorized actors from writing meaningful data into the scan chain. Message integrity verification makes messages from untrustworthy sources detectable. In conjunction, both security primitives protect the scan chain from malicious chiplets on the stack, scan-based attacks, and brute force attacks. The proposed solution causes less than 1% area overhead on designs composed of more than 5 million gates and less than 1% test time overhead for typical DFT implementations. Juan Suzano, Antoine Chastand, Emanuele Valea, Giorgio Di Natale, Anthony Philippe, Fady Abouzeid, Philippe Roche |
ETS | 7 |
| 2024 | Formal Resilience Metric Characterization in Complex Digital SystemsabstractAs digital systems are continuously becoming more complex, new methods are required to ensure their resilience. Research and industry are working together to develop automated formal methods, and, recently, great progress has been made to overcome this challenge. This work describes a general procedure to quantitatively determine, by Model Checking, the resilience level of a digital block whose flip-flops are perturbed by bit-flips. The flow relies on the formal proof, and provides a rich variety of results with much improved performance and accuracy (boost of ~ 300x and ~ 30x in the two test cases). The resilience metric is the number of distinct counterexamples provided by the formal engine, for each fault target. Failure traces are differentiated in two ways, showing on the test cases the great enhancement over simulation. Damiano Zuccalà, Jean-Marc Daveau, Philippe Roche, Katell Morin-Allory |
ETS | 3 |
| 2024 | Formal Fault Injection in Digital Blocks with Mined AssertionsabstractAs digital systems keep miniaturizing and becoming more complex, new methods are required to ensure their fault tolerance. Research and industry are working together to automatize such task, and, recently, great progress has been made to overcome this challenge. Starting from an exhaustive reference simulation, we have a general procedure to determine, by Model Checking, the fault tolerance of flip-flops that are perturbed by bit-flip events. Assuming that the design is correctly implemented, the temporal properties are used as fault detectors, automatically generated through a re-adapted version of the open source software Goldmine. By this, we can also address circuits without explicit specification (blind blocks), using automatic assertions induced from the reference golden waveform. Properties are mainly mined inside the design, allowing to calculate by Model Checking the fault masking capacity of the addressed modules. We consider two medium sized blocks, showing results with much-improved performance and accuracy over classical simulated fault injection. Damiano Zuccalà, Paul Breuil, Jean-Marc Daveau, Philippe Roche, Katell Morin-Allory |
MEMOCODE | 4 |
| 2024 | Analysis of Combinational Circuit Failure Rate based on Graph Partitioning and Probabilistic Binomial Approach
Esther Goudet, Fabio Sureau, Paul Breuil, Luis Peña Treviño, Lirida A. B. Naviner, Jean-Marc Daveau, Philippe Roche |
J. Electron. Test. | 7 |
| 2022 | Software Product Reliability Based on Basic Block Metrics RecompositionabstractIn the context of functional verification, the focus has always been on hardware and its ability to be both resilient to errors and to recover from them autonomously. In order to evaluate these characteristics, an extensive use of Fault Injection tools is made to achieve clear and granular results. These testing campaigns are carried out on the entire DUT and require a consistent amount of time and computational resources. The possibility of reducing these costs applying modern techniques as the study of the Dysfunctional State Machine or the proof of concept regarding the composability of single block fault injection campaigns to obtain a library of component of which the reliability metrics are well known, as already been extensively discussed and proven on hardware. In this work instead the application of this methodologies to software is presented for the first time. In order to do so, the software has been divided into basic block, atomic chunks of code having precise carachteristics that will ensure the possibility to study them singularly and then recompose them into a software product which reliability metrics are known, without the need for complete Fault injection campaign. Tiziano Fiorucci, Giorgio Di Natale, Jean-Marc Daveau, Philippe Roche |
IOLTS | 4 |
| 2021 | Automated Dysfunctional Model Extraction for Model Based Safety Assessment of Digital SystemsabstractIn the field of automatic quality or safety assurance level evaluation, this paper proposes the first approach towards the automation of the extraction processes of both the valid and faulty state machines within a System-on-a-Chip. The data automatically extracted by this method is a relevant input for behavioural modelization and FMEA analysis. The method is based on a semi-automated approach for the systematic extraction of failure modes of a digital design in the hypothesis of a single-event upset (SEU) or stuck-at in flip-flops. This procedure aims to enhance human driven failure analysis and provide inputs for RAMS frameworks in the process of quality assurance of complex devices. The main objective is to transport and apply RAMS methods and tools in the area of SoCs design. Experimental results have been conducted on an I2C - AHB system, laying the base for a complete and more complex analysis on an entire SoC. Tiziano Fiorucci, Jean-Marc Daveau, Giorgio Di Natale, Philippe Roche |
IOLTS | 4 |
| 2018 | Q-Learning-based Adaptive Power Management for IoT System-on-Chips with Embedded Power StatesabstractThis paper introduces an Adaptive Power Management (APM) hardware module based on reinforcement learning techniques. The APM provides power consumption optimization during the suspend state of an Internet-of-Things (IoT) System-on-Chip (SoC) with 8 embedded power states. A Q-Learning algorithm with a counter-based exploration policy has been chosen and implemented. A complete analysis has been performed to properly define the parameters of the algorithm and characterize the proposed solution. A hardware implementation is also shown and introduces the APM design and simplification made for an Ultra Low Power hardware. This solution gives a long term average gain of 17% of power consumption during the system suspend time. Yvan Debizet, Guenole Lallement, Fady Abouzeid, Philippe Roche, Jean-Luc Autran |
ISCAS | 4 |
| 2016 | A 28nm FD-SOI standard cell 0.6-1.2V open-loop frequency multiplier for low power SoC clockingabstractThis paper presents a new design for SoC clocking based on open-loop frequency multiplication. The architecture, fully implemented in 28nm FD-SOI standard cells, achieves frequency tracking within one input reference period making it a promising candidate for Dynamic Voltage and Frequency Scaling (DVFS) schemes. A calibration scheme is implemented for wide voltage range (0.6-1.2V) operation and to offset P&R and variability induced mismatch. Measurements at 0.6V (0.8/0.4V FBB) show a Fmax of 93MHz with a power of 2.91mW/MHz and a jitter of 2.7 % UI. Martin Cochet, Sylvain Clerc, Mehdi Naceur, Pierre Schamberger, Damien Croain, Jean-Luc Autran, Philippe Roche |
ISCAS | 7 |
| 2013 | Ultra-wide voltage range designs in fully-depleted silicon-on-insulator FETsabstractTodays' MPSoC applications are requiring a convergence between very high speed and ultra low power. Ultra Wide Voltage Range (UWVR) capability appears as a solution for high energy efficiency with the objective to improve the speed at very low voltage and decrease the power at high speed. Using Fully Depleted Silicon-On-Insulator (FDSOI) devices significantly improves the trade-off between leakage, variability and speed even at low-voltage. A full design framework is presented for UWVR operation using FDSOI Ultra Thin Body and Box technology considering power management, multi-VT enablement, standard cells design and SRAM bitcells. Technology performances are demonstrated on a ARM A9 critical path showing a speed increase from 40% to 200% without added energy cost. In opposite, when performance is not required, FDSOI enables to reduce leakage power up to 10X using Reverse Body Biasing. Edith Beigné, Alexandre Valentian, Bastien Giraud, Olivier Thomas, Thomas Benoist, Yvain Thonnart, Serge Bernard, Guillaume Moritz, Olivier Billoint, Y. Maneglia, Philippe Flatresse, Jean-Philippe Noël, Fady Abouzeid, Bertrand Pelloux-Prayer, Anuj Grover, Sylvain Clerc, Philippe Roche, Julien Le Coz, Sylvain Engels, Robin Wilson |
DATE | 17 |
| 2011 | An approach to reduce computational cost in combinatorial logic netlist reliability analysis using circuit clustering and conditional probabilitiesabstractWe propose a novel approach relying on signal state conditional probabilities and circuit clustering to perform a probabilistic analytical estimation of the reliability of combinatorial logic circuits. This approach uses clustering and joint conditional probabilities to reduce the execution time and matrix size needed. Its effectiveness is demonstrated on a 8 bit Brent Kung adder. Josep Torras Flaquer, Jean-Marc Daveau, Lirida A. B. Naviner, Philippe Roche |
IOLTS | 4 |
| 2008 | Growing Interest of Advanced Commercial CMOS Technologies for Space and Medical Applications. Illustration with a New Nano-Power and Radiation-Hardened SRAM in 130nm CMOSabstractThis paper reviews recent experimental confirmations that the intrinsic radiation robustness of commercial CMOS technologies naturally improves with the down-scaling. When additionally using innovative design techniques, it becomes now possible to assure that performance and radiation-hardness are both met. An illustration is given with an original nano-power and radiation-hardened 8 Mb SRAM designed in 130 nm CMOS. Philippe Roche, Mark Lysinger, Gilles Gasiot, Jean-Marc Daveau, Mehdi Zamanian, Pierre Dautriche |
IOLTS | 1 |
| 2006 | Factors That Impact the Critical Charge of Memory ElementsabstractIn the current paper we investigate the factors that affect the critical charge (Qcrit) for a soft error in a memory cell. Also the spread of Qcritdue to variations in the transistor model parameters is studied. The role of the current waveform that is applied in the simulation, the current pulse width, and the inclusion of back-end parasitics are discussed. Furthermore, we treat the impact on Qcritof supply voltage, temperature, and process variant. Also, the paper deals with the effects of parameter variations through the node capacitance and the PMOS ON-current. Finally, we show the importance of the spread in Qcritand demonstrate that detailed knowledge about the current-pulse width is necessary for accurate SER estimation Tino Heijmen, Damien Giot, Philippe Roche |
IOLTS | 3 |
| 2006 | Reduced Instrumentation and Optimized Fault Injection Control for Dependability AnalysisabstractFault-injection based dependability analysis has proved to be an efficient mean to predict the behavior of a circuit in presence of faults. Instrumentation-based techniques are in general used to perform the injection during simulation or emulation. The weak point of these techniques remains the characteristics obtained after modification of either the high-level description or the circuit netlist, especially when emulation is used. This paper proposes an instrumentation technique reducing the extra hardware and accelerating the fault injection campaigns thanks to optimized fault location addressing and parallel injection Pierre Vanhauwaert, Régis Leveugle, Philippe Roche |
VLSI-SoC | 3 |