VLDB 2026 Research / reviewers in the wild / expert
Alessandro Barenghi
dblp:25/2565
· DBLP profile ↗
70ranked-venue papers
27as first author
26since 2021 · last 2026
0000-0003-0840-6358ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 15 first-author · 11 since 2021Systems, architecture and hardware · 28 · 6 first-author · 10 since 2021Software engineering, systems software and programming languages · 4 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Theory of computation · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Quantum Oracle Synthesis from HDL Designs via Multi Level Intermediate RepresentationabstractQuantum computing is increasingly recognized as a promising approach for tackling computationally intractable problems. However, achieving the scalability necessary for real-world applications requires substantial advancements in the quantum software stack. In this work, we introduce a compiler toolchain based on a Multi-Level Intermediate Representation (MLIR) that automatically synthesizes quantum circuits from Hardware Description Language (HDL) specifications of classical functions into quantum assembly languages. Many quantum algorithms rely on combinatorial circuits as subroutines, which traditionally require extensive resources in terms of quantum gates and qubits and are often manually optimized. Our toolchain integrates a sequence of optimization passes that combine classical compiler techniques with quantum-specific improvements, resulting in an average qubit reduction of 30% and an average gate-count reduction of 20% in widely adopted benchmark circuits, including those used in cryptographic applications. Giacomo Lancellotti, Filippo Buda, Giacomo Carugati, Daniele Gazzola, Alessandro Barenghi, Giovanni Agosta, Gerardo Pelosi |
ASP-DAC | 5 |
| 2026 | Quantum Walks for Collision-Based Information Set DecodingabstractCode-based cryptography is central for post-quantum cryptography, with security grounded in the hardness of the Syndrome Decoding Problem (SDP). The most effective attacks are variants of Information Set Decoding (ISD), which remain exponential-time even in the quantum setting, where known techniques provide at most quadratic speedups via quantum amplitude amplification (QAA). In this work, we present the first gate-level realization of quantum walks (QW) for Stern-like collision-based ISD, and present a novel circuit for the update operator of the QW, correcting issues in prior proposals, while avoiding the use of exponential quantum random-access memory. Our construction enables a circuit-level complexity analysis under realistic cost models and allows a direct comparison between QW-based and QAA-based ISD. We evaluate our approach on the cryptographic schemes that reached the final stages of international standardization. Despite the richer algorithmic structure of QW, we show that they do not outperform plain QAA-based ISD for practical instances of the SDP, as the Gauss–Jordan elimination subroutine dominates the overall cost. More generally, we provide circuit-level evidence that QW offer an advantage over QAA only when the oracle cost is asymptotically smaller than the cost of the QW operations themselves. These results clarify the practical algorithmic limits of QW techniques and contribute to a more accurate assessment of quantum speedups for structured search problems in cryptanalysis. Simone Perriello, Alessandro Barenghi, Gerardo Pelosi |
CF | 2 |
| 2026 | Efficient QC-MDPC Cryptosystems with Bounded Decoding Failure Rate
Alessandro Annechini, Alessandro Barenghi, Gerardo Pelosi, Simone Perriello |
CRYPTO (4) | 2 |
| 2026 | ReFHE-NTT: Resource-Driven NTT FPGA Architecture for Fully Homomorphic EncryptionabstractFully Homomorphic Encryption (FHE) enables privacy-preserving computation on encrypted data at a high computational cost. Among the existing schemes, CKKS is gaining traction thanks to its support for approximate arithmetic over real numbers. In such a scheme, the Number Theoretic Transform (NTT) is dominant, involving intensive modular arithmetic, twiddle-factor handling, and nontrivial memory access patterns. As a result, NTT acceleration has gained significant interest, with many FPGA designs achieving high throughput by aggressively exploiting device resources. While effective for NTT-centric workloads, this approach is ill-suited to full FHE pipelines, where the NTT must coexist with other compute-intensive kernels. Thus, we propose ReFHE-NTT, a resource-efficient NTT accelerator tailored to such settings. Our design combines on-the-fly twiddle-factor fusion with specialized modular arithmetic for pseudo-Mersenne primes, reducing memory footprint and arithmetic cost without storing precomputed tables. We co-design and validate the accelerator on the KV260 MPSoC, supporting polynomial degrees log N ∈ 12…16 and CKKS parameter sets with moduli up to 64 bits per prime. To the best of our knowledge, ReFHE-NTT is the first solution targeting embedded platform to support full-scale CKKS parameter sets. Compared to prior FPGA designs, it achieves up to a 20.2× improvement in slice-equivalent efficiency over the fastest open-source accelerator and a 1.98× improvement over the most resource-efficient one. Integrated into HEAAN CKKS library, ReFHE-NTT delivers top end-to-end speedup of 15× for encoding and 7.9× for encryption, demonstrating how resource-driven NTT design can substantially improve FHE performance on embedded platforms. Valentino Guerrini, Giuseppe Sorrentino, Alessandro Barenghi, Davide Conficconi |
FCCM | 3 |
| 2026 | On the Hardness of Decoding Quasi-Cyclic Codes and the Security of Code-Based Public-Key CryptosystemsabstractPost-quantum public key encryption (PKE) schemes employing Quasi-Cyclic (QC) sparse parity-check matrix codes are enjoying significant success, thanks to their good performance profile and significant reduction in the keypair size. However, there is no formal proof that the hardness of decoding random QC codes is related to the decoding hardness of random codes, which is known to be NP-hard, nor that changing the (constant in the length) rate of the employed QC codes does not change the nature of the underlying hard problem. In this work, we address and solve these challenges, answering both of them in the affirmative. First, we prove computational equivalences among hard problems from coding theory and the corresponding problems for QC codes. Then, we provide a systematization of hard problems and security assumptions underlying QC-MDPC-based cryptosystems, proving that fixing the rate of the QC codes does not change the hardness of key recovery attacks. These results allow the design of Niederreiter-style QC-MDPC PKEs, with the additional flexibility granted by freely choosing the code rate, leading to code-based public key encryption schemes which are both secure and can be fit in very demanding scenarios, such as embedded systems. Alessandro Annechini, Alessandro Barenghi, Gerardo Pelosi |
ICISSP (2) | 2 |
| 2026 | On the Decoding Failure Rate of HQCabstractCryptography based on error correction codes has gained significant interest due to its ability to provide security against both classical and quantum adversaries. In 2025, the U.S. National Institute of Standards and Technology selected the Hamming Quasi-Cyclic (HQC) key encapsulation mechanism for standardization. A key aspect of HQC is the possibility of decryption failures, which reveal information about the private key. To address this issue, the HQC authors developed a probabilistic model for the decoding failure rate (DFR) of the underlying error-correcting code, and adjusted the cryptosystem parameters to thwart attacks based on decryption failures. However, the DFR model relies on the assumption of independence between coordinates of the error vector, which does not hold in HQC. This approximation yields conservative DFR estimates in regimes where failure probabilities can be simulated, and it is hypothesized to remains conservative for cryptographic-grade parameter sets. In this work, we eliminate the independence assumptions and derive a new closed-form DFR model for HQC. We demonstrate that the previous approximation remains conservative in the cryptographic regime and that HQC’s current decoding failure rates are lower than the required ones. We describe optimization techniques that enable our probabilistic model to serve as a parameter-tuning tool, and demonstrate how the size of HQC public keys and ciphertexts can be slightly reduced without compromising security. Alessandro Annechini, Alessandro Barenghi, Gerardo Pelosi |
ISIT | 2 |
| 2026 | CT-Monitor++: Improving the Certificate Transparency Ecosystem with Cryptographic and Security Checks
Simone Orlando, Alessandro Barenghi, Gerardo Pelosi |
SECRYPT (1) | 2 |
| 2026 | A high efficiency AVX2-optimized engineering of the post-quantum digital signature CROSSabstract• A complete engineering of the software optimization for the CROSS post quantum signature scheme tailored to Intel’s AVX2, including optimized scalar and vector modular arithmetics, and parallel SHAKE execution. The implementation is constant time. • A comparative benchmarking with full TLS communication establishment of post quantum signature schemes, taking into account different network latency scenarios, with both synthetic measurements and real world network latency validation. Post-quantum cryptosystems are currently attracting a significant amount of research efforts due to the continuous improvements in quantum computing technologies, and the inherent high inertia characterizing the replacement of cryptographic standards. This situation has pushed large standardization bodies, such as the USA National Institute of Standards and Technology (NIST), to open standardization competitions to foster proposals and public scrutiny of new quantum-resistant cryptosystems and digital signatures. Whilst NIST has chosen, after four selection rounds (November 2017 - June 2023), three digital signature algorithms, in July 2023 it started a new selection process as the chosen candidates either rely exclusively on lattice-based computationally hard problems, or have unsatisfactory performance figures. In this work, we tackle the performance engineering of the Codes and Restricted Objects Signature Scheme (CROSS), which has been admitted to the second round of selection by NIST in October 2024. We propose a set of techniques to optimize software realizations of CROSS, targeting the AVX2 ISA extension by Intel, as requested by NIST; exploiting fully our choices on the signature scheme parameters, as part of the design team. We note that these techniques are general enough to be ported to other vector ISA extensions (e.g., ARM Neon). We provide a complete performance validation of our realization both with dedicated microbenchmarks as well as full end-to-end TLS benchmarks with realistic network delays. Our results show that CROSS is competitive with each of the already standardized post-quantum signature schemes as well as with the other schemes still under evaluation in the second selection round. Alessandro Barenghi, Marco Gianvecchio, Gerardo Pelosi |
J. Inf. Secur. Appl. | 1 |
| 2026 | Solving the Subset Sum Problem via Quantum Walk SearchabstractQuantum walk-based search algorithms have demonstrated an asymptotic quadratic speedup compared to classical search methods. Formulating a generic search problem as a (quantum) search over a graph makes the efficiency of the algorithm to be closely dependent on the properties of the graph itself. In this work, we present a complete implementation of a quantum walk search procedure on Johnson graphs, speeding up the solution of the Subset Sum Problem, a well-known computational problem with applications in resource allocation, scheduling, and cryptanalysis. We provide a detailed design of each sub-circuit, quantifying their costs in terms of gate count, circuit depth, and qubit width, and exhibit all figures of merit as a function of the problem parameters. Our approach includes two distinct implementations: one that minimizes qubit usage and another focused on optimizing circuit depth. We compare our solutions against the unstructured Grover based quantum search algorithm, demonstrating a reduction of the cost on terms of T-count and T-depth, for practically solvable instances. The proposed design serves as a foundational building block for the development of efficient quantum search algorithms that can be modeled on Johnson graphs, bridging the gap with existing theoretical complexity analyses. Giacomo Lancellotti, Simone Perriello, Alessandro Barenghi, Gerardo Pelosi |
IEEE Trans. Computers | 3 |
| 2025 | Scrambling Compiler: Automated and Unified Countermeasure for Profiled and Non-profiled Side Channel Attacks
Gabriele Magnani, Isabella Piacentini, Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi |
ARES (1) | 4 |
| 2025 | Review of Policy-as-Code Approaches to Manage Security and Privacy Conditions in Edge and Cloud Computing Ecosystems
Beniamino Di Martino, Salvatore D'Angelo, Gennaro Junior Pezzullo, Dario Branco, Gerardo Pelosi, Alessandro Barenghi, Simone Orlando |
AINA (6) | 6 |
| 2025 | Threshold Selection for Iterative Decoding of $(v,\ w)$-Regular Binary Codes
Alessandro Annechini, Alessandro Barenghi, Gerardo Pelosi |
ISIT | 2 |
| 2025 | An Efficient and Unified RTL Accelerator Design for HQC-128, HQC-192, and HQC-256abstractIn the Post-Quantum Standardization (PQC) process held by the National Institute of Standards and Technology (NIST), the final round of evaluation of the asymmetric cryptographic schemes Classic McEliece, BIKE and HQC will elect the alternative Key Establishment Mechanism (KEM) to the FIPS203standard CRYSTALS-Kyber. In this work we present two configurations of a RTL hardware design of the HQC candidate, either optimized for devices exclusively working with client-server style protocols, or a unified accelerator compatible with all KEM operations, i.e. Key Generation, Encapsulation, and Decapsulation. Our designs are compatible with all the parameter sets defined by the HQC specification, providing security margins equivalent to the ones ofAES-128,AES-192, andAES-256based on a selection made at runtime. We are providing an extensive comparison with the current state-of-the-art RTL hardware designs for Artix-7 FPGAs of the schemes in the PQC process, introducing a new metric to evaluate the area utilization, historically a challenging task for such devices made of heterogeneous resources, and determining that HQC has by far the best figures among the code-based candidates in terms of latency, area occupied and efficiency, and even comparable with the lattice-based CRYSTALS-Kyber when using the parameters with lowest security margin. Francesco Antognazza, Alessandro Barenghi, Gerardo Pelosi |
IEEE Trans. Computers | 2 |
| 2024 | Design of a Quantum Walk Circuit to Solve the Subset-Sum ProblemabstractSearch algorithms based on quantum walks have emerged as a promising approach to solve computational problems across various domains, including combinatorial optimization, and cryptography. Stating a generic search problem in terms of a (quantum) search over a graph makes the efficiency of the algorithmic method depend on the structure of the graph itself. In this work, we propose a complete implementation of a quantum walk search on Johnson graphs, speeding up the solution of the subset-sum problem. We provide a detailed design of each sub-circuit, quantifying their cost in terms of gate number, depth, and width. We compare our solution against a Grover quantum search, showing a reduction of the T-count and T-depth for practically solvable problems. The proposed design provides a building block for the construction of efficient quantum search algorithms that can be modelled on Johnson graphs, filling the gap with the existing theoretical complexity analyses. Giacomo Lancellotti, Simone Perriello, Alessandro Barenghi, Gerardo Pelosi |
DAC | 3 |
| 2024 | Optimizing Quantum Circuit Synthesis with Dominator AnalysisabstractQuantum circuit synthesis translates a classical Boolean function into an equivalent quantum circuit. The syn-thesis is solvable by playing the reversible pebble game on the logic network of the function. However, optimal solutions are im-practical for large networks, affecting the number of qubits and gates of the final quantum circuit. In this work, we improve the solution of the reversible pebble game by leveraging dominance relations on the directed acyclic graph of the classical function, reducing qubits needed for syntheses. The proposed algorithm exposes a tunable tradeoff between the available number of qubits and the circuit size expressed as T-count and T-depth. We experimentally validate our methodology on cryptographic and arithmetic benchmarks, reporting reductions between 37% and 83 % in qubit number with respect to Bennet syntheses algorithms and complete the majority of our syntheses in less than a second, improving on the current running times of state of the art approaches. Giacomo Lancellotti, Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi |
ICCD | 3 |
| 2024 | A Quantum Method to Match Vector Boolean Functions using Simon's SolverabstractThe Boolean Matching Problem is a fundamental step in modern Electronic Design Automation toolchains, which allow the efficient design of large classical computers. In particular, the equivalence under negation-permutation-negation of two n-to-n vector Boolean functions requires the exploration of a super-exponential number of possible negations and permutations of input and output variables, and is widely regarded as a daunting challenge. Its classical complexity$(\mathcal{O}(n!2^{2n})$, where$n$is the number of input and output variables) is rarely tolerated by EDA tools, which are typically solving small instances of the Boolean Matching Problem for n-to-1 Boolean functions. In this work, we present a method to exploit the solver for Simon's problem to speedup the matching of n-to-n vector Boolean functions, as we show that, despite its higher complexity, it is friendlier to a quantum solver than matching single-output Boolean functions. Our solution allows saving a factor$2^{n}$in the overall worst-case computational effort, and is amenable to combined approaches such as the so-called Grover-meets-Simon, which have the potential of reducing it below the cost of classical n-to-1 matching. We provide a fully detailed quantum circuit implementing our proposal, and compute its cost, both counting the required amount of qubits and quantum gates. We conducted an experimental evaluation employing the ISCAS benchmark suite, a de-facto standard for classical EDA to derive our sample Boolean functions. Marco Venere, Alessandro Barenghi, Gerardo Pelosi |
ICCD | 2 |
| 2024 | Bit-Flipping Decoder Failure Rate Estimation for (v, w)-Regular CodesabstractProviding closed form estimates of the Decoding Failure Rates (DFR) of iterative decoder for low- and moderate-density parity check codes has attracted significant interest in the research community over the years. This interest has raised due to the use of iterative decoders in post-quantum cryptosystems, where the desired DFRs are impossible to estimate via Monte Carlo simulations. In this work, we propose a new technique to provide accurate estimates of the DFR of a two-iterations (parallel) bit-flipping decoder, which is also employable for cryptographic purposes. In doing so, we successfully tackle the estimation of the bit-flipping probabilities at the first and second decoder iteration, and provide a fitting estimate for the syndrome weight distribution. We numerically validate our results, providing comparisons of the modeled and simulated weight of the syndrome, incorrectly-guessed error bit distribution at the end of the first iteration, and two-iteration DFR, both in the floor and waterfall regime. Finally, we apply our method to estimate the DFR of LEDAcrypt, a post-quantum cryptosystem, improving by factors larger than$2^{70}$, with respect to the previous estimation techniques. Alessandro Annechini, Alessandro Barenghi, Gerardo Pelosi |
ISIT | 2 |
| 2023 | A Flexible ASIC-Oriented Design for a Full NTRU AcceleratorabstractPost-quantum cryptosystems are the subject of a significant research effort, witnessed by various international standardization competitions. Among them, the NTRU Key Encapsulation Mechanism has been recognized as a secure, patent-free, and efficient public key encryption scheme. In this work, we perform a design space exploration on an FPGA target, with the final goal of an efficient ASIC realization. Specifically, we focus on the possible choices for the design of polynomial multipliers with different memory bus widths to trade-off lower clock cycle counts with larger interconnections. Our design outperforms the best FPGA synthesis results at the state of the art, and we report the results of ASIC syntheses minimizing latency and area with a 40nm industrial grade technology library. Our speed-oriented design computes an encapsulation in 4.1 to 10.2μs and a decapsulation in 7.1 to 11.7μs, depending on the NTRU security level, while our most compact design only takes 20% more area than the underlying SHA-3 hash module. Francesco Antognazza, Alessandro Barenghi, Gerardo Pelosi, Ruggero Susella |
ASP-DAC | 2 |
| 2023 | A Non Profiled and Profiled Side Channel Attack Countermeasure through Computation InterleavingabstractSide channel attacks analyse devices to retrieve secret informations. These attacks can be performed using either a synthetic model or by profiling a specific instance of the targeted design. Our proposal is a novel countermeasure characterized by temporal interleaving of the computation. This approach improves upon existing methods by rendering the profiled models of a device non-portable and offering resistance against first-order non-profiled attacks. The assessment of the security of our proposed approach covers scenarios of profiled attacks with feature reduction techniques, both under a single-device and multi-device model, as well as first-order non-profiled attacks. Our design demonstrates improved results in terms of resource consumption and timing when compared to alternative solutions. Isabella Piacentini, Alessandro Barenghi, Gerardo Pelosi |
DSD | 2 |
| 2023 | Fault Attacks Friendliness of Post-quantum CryptosystemsabstractPost-quantum cryptosystems are often designed starting from a public key encryption algorithm and augmented with widely recognized cryptographic constructions, which in turn are shared among the majority of proposals and create common targets for fault attacks, but also opportunities for overarching countermeasures. In this talk, we survey the fault resilience of these recurring structures in both Key Encapsulation Methods (KEMs) and signature schemes, taking as case studies both the current KEMs selected for the fourth round in the US NIST standardization process, and its on-ramp for post-quantum signatures. Alessandro Barenghi, Gerardo Pelosi |
FDTC | 1 |
| 2023 | An Efficient Unified Architecture for Polynomial Multiplications in Lattice-Based CryptoschemesabstractThe significant effort in the research and design of large-scale quantum computers has spurred a transition to post-quantum cryptographic primitives worldwide. The post-quantum cryptographic primitive standardization effort led by the US NIST has recently selected the asymmetric encryption primitive Kyber as its candidate for standardization. It has also indicated NTRU, another lattice-based primitive, as a valid alternative if intellectual property issues are not solved. Finally, a more conservative alternative to NTRU, NTRUPrime was also considered as an alternate candidate, due to its design choices which remove the possibility for a large set of attacks preemptively. All the aforementioned asymmetric primitives provide good performances, and are prime choices provide IoT devices with post-quantum confidentiality services. In this work, we propose a unified design for a hardware accelerator able to speed up the computation of polynomial multiplications, the workhorse operation in all of the aforementioned cryptosystems, managing the differences in the polynomial rings of the cryptosystems. Our design is also able to outperform the state of the art designs tailored specifically for NTRU, and provide latencies similar to the symmetric cryptographic elements required by the scheme for Kyber and NTRUPrime. Francesco Antognazza, Alessandro Barenghi, Gerardo Pelosi, Ruggero Susella |
ICISSP | 2 |
| 2023 | Improving the Efficiency of Quantum Circuits for Information Set DecodingabstractCode-based cryptosystems are a promising option for Post-Quantum Cryptography, as neither classical nor quantum algorithms provide polynomial time solvers for their underlying hard problem. Indeed, to provide sound alternatives to lattice-based cryptosystems, U.S. National Institute of Standards and Technology (NIST) advanced all round 3 code-based cryptosystems to round 4 of its Post-Quantum standardization initiative. We present a complete implementation of a quantum circuit based on the Information Set Decoding (ISD) strategy, the best known one against code-based cryptosystems, providing quantitative measures for the security margin achieved with respect to the quantum-accelerated key recovery on AES, targeting both the current state-of-the-art approach and the NIST estimates. Our work improves the state-of-the-art, reducing the circuit depth by 2 19 to 2 30 for all the parameters of the NIST selected cryptosystems, mainly due to an improved quantum Gauss–Jordan elimination circuit with respect to previous proposals. We show how our Prange’s-based quantum ISD circuit reduces the security margin with respect to its classical counterpart. Finally, we address the concern brought forward in the latest NIST report on the parameters choice for the McEliece cryptosystem, showing that its parameter choice yields a computational effort slightly below the required target level. Simone Perriello, Alessandro Barenghi, Gerardo Pelosi |
ACM Trans. Quantum Comput. | 2 |
| 2022 | Profiled side channel attacks against the RSA cryptosystem using neural networks
Alessandro Barenghi, Diego Carrera, Silvia Mella, Andrea Pace, Gerardo Pelosi, Ruggero Susella |
J. Inf. Secur. Appl. | 1 |
| 2021 | Profiled Attacks Against the Elliptic Curve Scalar Point Multiplication Using Neural Networks
Alessandro Barenghi, Diego Carrera, Silvia Mella, Andrea Pace, Gerardo Pelosi, Ruggero Susella |
NSS | 1 |
| 2021 | LESS-FM: Fine-Tuning Signatures from the Code Equivalence Problem
Alessandro Barenghi, Jean-François Biasse, Edoardo Persichetti, Paolo Santini |
PQCrypto | 1 |
| 2021 | A Quantum Circuit to Speed-Up the Cryptanalysis of Code-Based Cryptosystems
Simone Perriello, Alessandro Barenghi, Gerardo Pelosi |
SecureComm (2) | 2 |
| 2020 | Efficient Oblivious Substring Search via Architectural SupportabstractPerforming private and efficient searches over encrypted outsourced data enables a flourishing growth of cloud based services managing sensitive data as the genomic, medical and financial ones. We tackle the problem of building an efficient indexing data structure, enabling the secure and private execution of substring search queries over an outsourced document collection. Our solution combines the efficiency of an index-based substring search algorithm with the secure-execution features provided by the SGX technology and the access pattern indistinguishability guarantees provided by an Oblivious RAM. To prevent the information leakage from the access pattern side-channel vulnerabilities affecting SGX based applications, we redesign three ORAM algorithms, and perform a comparative evaluation to find the best engineering trade-offs for a privacy-preserving index-based substring search protocol. The practicality of our solution is supported by a response time of about 1 second to retrieve all the positions of a protein in the 3 GB string of the human genome. Nicholas Mainardi, Davide Sampietro, Alessandro Barenghi, Gerardo Pelosi |
ACSAC | 3 |
| 2020 | Constant weight strings in constant time: a building block for code-based post-quantum cryptosystemsabstractCode based cryptosystems often need to encode either a message or a random bitstring into one of fixed length and fixed (Hamming) weight. The lack of an efficient and reliable bijective map presents a problem in building constructions around the said cryptosystems to attain security against active attackers. We present an efficiently computable, bijective function which yields the desired mapping. Furthermore, we delineate how the said function can be computed in constant time. We experimentally validate the effectiveness and efficiency of our approach, comparing it against the current state of the art solutions, achieving three to four orders of magnitude improvements in computation time, and validate its constant runtime. Alessandro Barenghi, Gerardo Pelosi |
CF | 1 |
| 2020 | A comprehensive analysis of constant-time polynomial inversion for post-quantum cryptosystemsabstractPost-quantum cryptosystems have currently seen a surge in interest thanks to the current standardization initiative by the U.S.A. National Institute of Standards and Technology (NIST). A common primitive in post-quantum cryptosystems, in particular in code-based ones, is the computation of the inverse of a binary polynomial in a binary polynomial ring. In this work, we analyze, realize in software, and benchmark a broad spectrum of binary polynomial inversion algorithms, targeting operand sizes which are relevant for the current second round candidates in the NIST standardization process. We evaluate advantages and shortcomings of the different inversion algorithms, including their capability to run in constant-time, thus preventing timing side-channel attacks. Alessandro Barenghi, Gerardo Pelosi |
CF | 1 |
| 2020 | Compiler-Based Techniques to Secure Cryptographic Embedded Software Against Side-Channel AttacksabstractSide-channel attacks are a concrete and practical threat to the security of computing systems, ranging from high performance platforms to embedded devices. In this paper, we will provide a brief systematization of the current existing approaches to analyze the side-channel vulnerability of an implementation, or automatically implement countermeasures, relying on methodologies typical of compiler systems. We will dedicate a spotlight to a significant progress in the countermeasures techniques which is represented by the application of dynamic compilation techniques to prevent a side-channel attacker from devising a model of the attacked application. We conclude the work highlighting promising research directions in this field. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2020 | Scramble Suit: A Profile Differentiation Countermeasure to Prevent Template AttacksabstractEnsuring protection against side channel attacks (SCAs) is a crucial requirement in the design of modern secure embedded systems. Profiled SCAs, the class to which template attacks and machine learning attacks belong, derive a model of the side channel behavior of a device identical to the target one, and exploit the said model to extract the key from the target, under the hypothesis that the side channel behaviors of the two devices match. We propose an architectural countermeasure against cross-device profiled attacks which differentiates the side channel behavior of different instances of the same hardware design, preventing the reuse of a model derived on a device other than the target one. In particular, we describe an instance of our solution providing a protected hardware implementation of the advanced encryption standard (AES) block cipher and experimentally validate its resistance against both Bayesian templates and machine learning approaches based on support vector machines also considering different state-of-the-art feature reduction techniques to increase the effectiveness of the profiled attacks. Results show that our countermeasure foils the key retrieval attempts via profiled attacks ensuring a key derivation accuracy equivalent to a random guess. Alessandro Barenghi, William Fornaciari, Gerardo Pelosi, Davide Zoni |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2019 | Privacy preserving substring search protocol with polylogarithmic communication costabstractThe problem of efficiently searching into outsourced encrypted data, while providing strong privacy guarantees, is a challenging problem arising from the separation of data ownership and data management typical of cloud-based applications. Several cryptographic solutions allowing a client to look-up occurrences of a substring of choice in an outsourced document collection have been publicly presented. Nonetheless, practical application requirements in terms of privacy, security and efficiency actively push for new and improved solutions. We present a privacy-preserving substring search protocol exhibiting a sub-linear communication cost, with a limited computational effort on the server side. The proposed protocol provides search pattern and access pattern privacy, while its extension to a multi-user setting shows significant savings in terms of outsourced storage w.r.t. a baseline solution where the whole dataset is replicated. The performance figures of an optimized implementation of our protocol, searching into a remotely stored genomic dataset, validate the practicality of the approach exhibiting a data transfer of less than 200 kiB to execute a query over a document of 40 MiB, with execution times on client and server in the range of a few seconds and a few minutes, respectively. Nicholas Mainardi, Alessandro Barenghi, Gerardo Pelosi |
ACSAC | 2 |
| 2019 | A secure and authenticated host-to-memory communication interfaceabstractEmerging non-volatile memories (NVMs) have the potential to change the memory-storage hierarchy in computing devices, and even to replace DRAM as main memories. In fact NVMs, beside offering byte-addressability and data persistence, promise better scalability and higher capacity than DRAM. However, from a security point of view, the persistent nature of emerging memories provides a larger time window to exfiltrate data from a device with respect to current DRAM-based main memories, and NVMs have in general lower write endurance than DRAM, thus requiring wear-out conscious encryption schemes. In this work we propose an architectural solution to secure non-volatile emerging memories, providing confidentiality, integrity and authenticity to the entire set of data, addresses and commands. Our solution relies on securing and authenticating the entire information transport between the host controller and the memory, enabling the storage of cleartext data inside the NVM. Such an approach allows to retain the advantage of differential write strategies without forsaking security. We validate our proposed architecture through the simulation of a set of software benchmarks on an embedded architecture, employing the gem5 trace-based architectural simulator. Niccolò Izzo, Alessandro Barenghi, Luca Breveglieri, Gerardo Pelosi, Paolo Amato |
CF | 2 |
| 2019 | Plaintext recovery attacks against linearly decryptable fully homomorphic encryption schemes
Nicholas Mainardi, Alessandro Barenghi, Gerardo Pelosi |
Comput. Secur. | 2 |
| 2018 | Side-channel security of superscalar CPUs: evaluating the impact of micro-architectural featuresabstractSide-channel attacks are performed on increasingly complex targets, starting to threaten superscalar CPUs supporting a complete operating system. The difficulty of both assessing the vulnerability of a device to them, and validating the effectiveness of countermeasures is increasing as a consequence. In this work we prove that assessing the side-channel vulnerability of a software implementation running on a CPU should take into account the microarchitectural features of the CPU itself. We characterize the impact of microarchitectural features and prove the effectiveness of such an approach attacking a dual-core superscalar CPU. Alessandro Barenghi, Gerardo Pelosi |
DAC | 1 |
| 2018 | Comparison-Based Attacks Against Noise-Free Fully Homomorphic Encryption Schemes
Alessandro Barenghi, Nicholas Mainardi, Gerardo Pelosi |
ICICS | 1 |
| 2018 | LEDAkem: A Post-quantum Key Encapsulation Mechanism Based on QC-LDPC Codes
Marco Baldi, Alessandro Barenghi, Franco Chiaraluce, Gerardo Pelosi, Paolo Santini |
PQCrypto | 2 |
| 2018 | Systematic parsing of X.509: Eradicating security issues with a parse treeabstractX.509 certificate parsing and validation is a critical task which has shown consistent lack of effectiveness, with practical attacks being reported with a steady rate during the last 10 years. In this work we analyze the X.509 standard and provide a grammar description of it amenable to the automated generation of a parser with strong termination guarantees, providing unambiguous input parsing. We report the results of analyzing a 11M X.509 certificate dump of the HTTPS servers running on the entire IPv4 space, showing that 21.5% of the certificates in use are syntactically invalid. We compare the results of our parsing against 7 widely used TLS libraries showing that 631k to 1,156k syntactically incorrect certificates are deemed valid by them (5.7%–10.5%), including instances with security critical mis-parsings. We prove the criticality of such mis-parsing exploiting one of the syntactic flaws found in existing certificates to perform an impersonation attack. Alessandro Barenghi, Nicholas Mainardi, Gerardo Pelosi |
J. Comput. Secur. | 1 |
| 2018 | A Comprehensive Side-Channel Information Leakage Analysis of an In-Order RISC CPU MicroarchitectureabstractSide-channel attacks are a prominent threat to the security of embedded systems. To perform them, an adversary evaluates the goodness of fit of a set of key-dependent power consumption models to a collection of side-channel measurements taken from an actual device, identifying the secret key value as the one yielding the best-fitting model. In this work, we analyze for the first time the microarchitectural components of a 32-bit in-order RISC CPU, showing which one of them is accountable for unexpected side-channel information leakage. We classify the leakage sources, identifying the data serialization points in the microarchitecture and providing a set of hints that can be fruitfully exploited to generate implementations resistant against side-channel attacks, either writing or generating proper assembly code. Davide Zoni, Alessandro Barenghi, Gerardo Pelosi, William Fornaciari |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2016 | ShieldFS: a self-healing, ransomware-aware filesystem
Andrea Continella, Alessandro Guagnelli, Giovanni Zingaro, Giulio De Pasquale, Alessandro Barenghi, Stefano Zanero, Federico Maggi 0001 |
ACSAC | 5 |
| 2016 | V2I Cooperation for Traffic Management with SafeCopabstractThe Safe Cooperating Cyber-Physical Systems using Wireless Communication (SafeCop) project addresses safety-related issues in cooperating cyber-physical systems. These systems, characterised by wireless communications, multiple stakeholders, and variable operating environments, are called Cooperative Open Cyber-Physical Systems (CO-CPS). CO-CPSs can successfully address several societal challenges -- cooperative vehicles have been shown to reduce fuel consumption as well as the number of accidents. A vehicle-to-infrastructure (V2I) cooperation for the traffic management scenario is therefore considered as a key use cases of SafeCop. In this paper, we outline the V2I traffic management scenario, assess the research goals that arise from it, and provide an overview of the architecture of the demonstrator, as well as a roadmap for its development and evaluation. Giovanni Agosta, Alessandro Barenghi, Carlo Brandolese, William Fornaciari, Gerardo Pelosi, Stefano Delucchi, Massimo Massa, Maurizio Mongelli, Enrico Ferrari, Leonardo Napoletani, Luciano Bozzi, Carlo Tieri, Dajana Cassioli, Luigi Pomante |
DSD | 2 |
| 2016 | Encasing block ciphers to foil key recovery attempts via side channelabstractProviding efficient protection against energy consumption based side channel attacks (SCAs) for block ciphers is a relevant topic for the research community, as current overheads are in the 100× range. Unprofiled SCAs exploit information leakage from the outmost rounds of a cipher; we propose a solution encasing it between keyed transformations amenable to an efficient SCA protection. Our solution can be employed as a drop in replacement for an unprotected implementation, or be retrofit to an existing one, while retaining communication capabilities with legacy insecure endpoints. Experiments on a Cortex-M4 µC, show performance improvements in the range of 60×, compared with available solutions. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
ICCAD | 2 |
| 2016 | A privacy-preserving encrypted OSN with stateless server interaction: The Snake design
Alessandro Barenghi, Michele Beretta 0002, Alessandro Di Federico, Gerardo Pelosi |
Comput. Secur. | 1 |
| 2016 | A Fault-Based Secret Key Retrieval Method for ECDSA: Analysis and CountermeasureabstractElliptic curve cryptosystems proved to be well suited for securing systems with constrained resources like embedded and portable devices. In a fault-based attack, errors are induced during the computation of a cryptographic primitive, and the results are collected to derive information about the secret key safely stored in the device. We introduce a novel attack methodology to recover the secret key employed in implementations of the Elliptic Curve Digital Signature Algorithm. Our attack exploits the information leakage induced when altering the execution of the modular arithmetic operations used in the signature primitive and does not rely on the underlying elliptic curve mathematical structure, thus being applicable to all standardized curves. We provide both a validation of the feasibility of the attack, even employing common off-the-shelf hardware to perform the required computations, and a low-cost countermeasure to counteract it. Alessandro Barenghi, Guido Bertoni, Luca Breveglieri, Gerardo Pelosi, Stefano Sanfilippo, Ruggero Susella |
ACM J. Emerg. Technol. Comput. Syst. | 1 |
| 2015 | Information leakage chaff: feeding red herrings to side channel attackersabstractA prominent threat to embedded systems security is represented by side-channel attacks: they have proven effective in breaching confidentiality, violating trust guarantees and IP protection schemes. State-of-the-art countermeasures reduce the leaked information to prevent the attacker from retrieving the secret key of the cipher. We propose an alternate defense strategy augmenting the regular information leakage with false targets, quite like chaff countermeasures against radars, hiding the correct secret key among a volley of chaff targets. This in turn feeds the attacker with a large amount of invalid keys, which can be used to trigger an alarm whenever the attack attempts a content forgery using them, thus providing a reactive security measure. We realized a LLVM compiler pass able to automatically apply the proposed countermeasure to software implementations of block ciphers. We provide effectiveness and efficiency results on an AES implementation running on an ARM Cortex-M4 showing performance overheads comparable with state-of-the-art countermeasures. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
DAC | 2 |
| 2015 | Challenging the Trustworthiness of PGP: Is the Web-of-Trust Tear-Proof?abstractThe OpenPGP protocol provides a long time adopted and widespread tool for secure and authenticated asynchronous communications, as well as supplies data integrity and authenticity validation for software distribution. In this work, we analyze the Web-of-Trust on which the OpenPGP public key authentication mechanism is based, and evaluate a threat model where its functionality can be jeopardized. Since the threat model is based on the viability of compromising an OpenPGP keypair, we performed an analysis of the state of health of the global OpenPGP key repository. Despite the detected amount of weak keypairs is rather low, our results show how, under reasonable assumptions, approximately 70 % of the Web-of-Trust strong set is potentially affected by the described threat. Finally, we propose viable mitigation strategies to cope with the highlighted threat. Alessandro Barenghi, Alessandro Di Federico, Gerardo Pelosi, Stefano Sanfilippo |
ESORICS (1) | 1 |
| 2015 | OpenCL performance portability for general-purpose computation on graphics processor units: an exploration on cryptographic primitivesabstractSummary The modern trend toward heterogeneous many‐core architectures has led to high architectural diversity in both high performance and high‐end embedded systems. To effectively exploit the computational resources of such a wide range of architectures, programming languages and APIs such as OpenCL have become increasingly popular. Although OpenCL provides functional code portability and the ability to fine tune the application to the target hardware, providing performance portability is still an open problem. Thus, many research works have investigated the optimization of specific combinations of application and target platform. In this paper, we aim at leveraging the experience obtained in the implementation of algorithms from the cryptography domain to provide a set of guidelines for modern many‐core heterogeneous architecture performance portability and to establish a base on which domain‐specific languages and compiler transformations could be built in the near future. We study algorithmic choices and the effect of compiler transformations on three representative applications in the chosen domain on a set of seven target platforms. To estimate how well the application fits the architecture, we define a metric of computational intensity both for the architecture and the application implementation. Besides being useful to compare either different implementation or algorithmic choices and their fitness to a specific architecture, it can also be useful to the compiler to guide the code optimization process. Copyright © 2014 John Wiley & Sons, Ltd. Giovanni Agosta, Alessandro Barenghi, Alessandro Di Federico, Gerardo Pelosi |
Concurr. Comput. Pract. Exp. | 2 |
| 2015 | Trace-based schedulability analysis to enhance passive side-channel attack resilience of embedded software
Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
Inf. Process. Lett. | 2 |
| 2015 | Parallel parsing made practical
Alessandro Barenghi, Stefano Crespi-Reghizzi, Dino Mandrioli, Federica Panella, Matteo Pradella |
Sci. Comput. Program. | 1 |
| 2015 | The MEET Approach: Securing Cryptographic Embedded Software Against Side Channel AttacksabstractWe propose an efficient and effective methods to secure software implementations of cryptographic primitives on low-end embedded systems, against passive side channel attacks relying on the observation of power consumption or electro-magnetic emissions. The proposed approach exploits a modified LLVM compiler toolchain to automatically generate a secure binary characterized by a randomized execution flow. We improve the current state-of-the-art in dynamic executable code countermeasures removing the requirement of a writable code segment, and reducing the countermeasure overhead. Also, we provide a new method to refresh the random values employed in the share splitting approaches to lookup table protection. Finally, we devise an automated approach to protect spill actions onto the main memory, which are inserted by the compiler backend register allocator when there is a lack of available registers, thus, removing the need for manual assembly inspection. We report a validation of the performances of our approach on all the current ISO-standard block ciphers, employing an ARM Cortex-M4 based microcontroller as the validation platform. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2014 | The PAPAGENO Parallel-Parser Generator
Alessandro Barenghi, Stefano Crespi-Reghizzi, Dino Mandrioli, Federica Panella, Matteo Pradella |
CC | 1 |
| 2014 | A Multiple Equivalent Execution Trace Approach to Secure Cryptographic Embedded SoftwareabstractWe propose an efficient and effective method to secure software implementations of cryptographic primitives on low-end embedded systems, against passive side-channel attacks relying on the observation of power consumption or electro-magnetic emissions. The proposed approach exploits a modified llvm compiler toolchain to automatically generate a secure binary characterized by a randomized execution flow. Also, we provide a new method to refresh the random values employed in the share splitting approaches to lookup table protection, addressing a currently open issue. We improve the current state-of-the-art in dynamic executable code countermeasures removing the requirement of a writeable code segment, and reducing the countermeasure overhead. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
DAC | 2 |
| 2014 | On the Security of Partially Masked Software ImplementationsabstractProviding sound countermeasures against passive side channel attacks has received large interest in open literature. The scheme proposed in (Ishai et al., 2003) secures a computation against a d-probing adversary splitting it into d+1 shares, albeit with a significant performance overhead (5× to 20×). We maintain that it is possible to apply such countermeasures only to a portion of the cipher implementation, retaining the same computational security, backing a widespread intuition present among practitioners. We provide the sketch of a computationally bound attacker model, adapted as an extension of the one in (Ishai et al., 2003), and detail the resistance metric employed to estimate the computational effort of such an attacker, under sensible assumptions on the characteristic of the device leakage (which is, to the current state of the art, still lacking a complete formalization). Alessandro Barenghi, Gerardo Pelosi |
SECRYPT | 1 |
| 2014 | Differential Fault Analysis for Block Ciphers: an Automated Conservative AnalysisabstractDifferential Fault Analysis (DFA) exploits the differences between a correct and a faulty output of a cipher implementation to derive the secret parameters. All the current DFA techniques are tailored to the cipher being attacked and do not provide a general framework. We propose an automated general framework to assess the vulnerability of block ciphers against DFAs, providing a conservative analysis on the attacker capabilities and a practical lower bound on the attacker effort required to extract the secret-key. The proposed technique is based on dataflow analysis of software cipher implementations and has been implemented as a pass of the llvm compiler infrastructure. This work shows how the automated tool we developed is able to detect which and how many faults an attacker can exploit to recover the values of portions of the secret-key material employed by a standard block cipher, validating the effectiveness of our approach. The precise analysis provided by our tool allows to apply the computationally demanding fault attack countermeasures only to the vulnerable portions of the cipher. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
SIN | 2 |
| 2013 | Compiler-based side channel vulnerability analysis and optimized countermeasures applicationabstractModern embedded systems manage sensitive data increasingly often through cryptographic primitives. In this context, side-channel attacks, such as power analysis, represent a concrete threat, regardless of the mathematical strength of a cipher. Evaluating the resistance against power analysis of cryptographic implementations and preventing it, are tasks usually ascribed to the expertise of the system designer. This paper introduces a new security-oriented data-flow analysis assessing the vulnerability level of a cipher with bit-level accuracy. A general and extensible compiler-based tool was implemented to assess the instruction resistance against power-based side-channels. The tool automatically instantiates the essential masking countermeasures, yielding a x2.5 performance speedup w.r.t. protecting the entire code. Giovanni Agosta, Alessandro Barenghi, Massimo Maggi, Gerardo Pelosi |
DAC | 2 |
| 2013 | Enhancing Passive Side-Channel Attack Resilience through Schedulability Analysis of Data-Dependency Graphs
Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi, Michele Scandale |
NSS | 2 |
| 2013 | Parallel parsing of operator precedence grammars
Alessandro Barenghi, Stefano Crespi-Reghizzi, Dino Mandrioli, Matteo Pradella |
Inf. Process. Lett. | 1 |
| 2013 | A fault induction technique based on voltage underfeeding with application to attacks against AES and RSA
Alessandro Barenghi, Guido Bertoni, Luca Breveglieri, Gerardo Pelosi |
J. Syst. Softw. | 1 |
| 2012 | A code morphing methodology to automate power analysis countermeasuresabstractWe introduce a general framework to automate the application of countermeasures against Differential Power Attacks aimed at software implementations of cryptographic primitives. The approach enables the generation of multiple versions of the code, to prevent an attacker from recognizing the exact point in time where the observed operation is executed and how such operation is performed. The strategy increases the effort needed to retrieve the secret key through hindering the formulation of a correct hypothetical consumption to be correlated with the power measurements. The experimental evaluation shows how a DPA attack against OpenSSL AES implementation on an industrial grade ARM-based SoC is hindered with limited performance overhead. Giovanni Agosta, Alessandro Barenghi, Gerardo Pelosi |
DAC | 2 |
| 2012 | PAPAGENO: A Parallel Parser Generator for Operator Precedence Grammars
Alessandro Barenghi, Ermes Viviani, Stefano Crespi-Reghizzi, Dino Mandrioli, Matteo Pradella |
SLE | 1 |
| 2012 | Fault Injection Attacks on Cryptographic Devices: Theory, Practice, and CountermeasuresabstractImplementations of cryptographic algorithms continue to proliferate in consumer products due to the increasing demand for secure transmission of confidential information. Although the current standard cryptographic algorithms proved to withstand exhaustive attacks, their hardware and software implementations have exhibited vulnerabilities to side channel attacks, e.g., power analysis and fault injection attacks. This paper focuses on fault injection attacks that have been shown to require inexpensive equipment and a short amount of time. The paper provides a comprehensive description of these attacks on cryptographic devices and the countermeasures that have been developed against them. After a brief review of the widely used cryptographic algorithms, we classify the currently known fault injection attacks into low-cost ones (which a single attacker with a modest budget can mount) and high-cost ones (requiring highly skilled attackers with a large budget). We then list the attacks that have been developed for the important and commonly used ciphers and indicate which ones have been successfully used in practice. The known countermeasures against the previously described fault injection attacks are then presented, including intrusion detection and fault detection. We conclude the survey with a discussion on the interaction between fault injection attacks (and the corresponding countermeasures) and power analysis attacks. Alessandro Barenghi, Luca Breveglieri, Israel Koren, David Naccache |
Proc. IEEE | 1 |
| 2011 | On the vulnerability of FPGA bitstream encryption against power analysis attacks: extracting keys from xilinx Virtex-II FPGAsabstractOver the last two decades FPGAs have become central components for many advanced digital systems, e.g., video signal processing, network routers, data acquisition and military systems. In order to protect the intellectual property and to prevent fraud, e.g., by cloning a design embedded into an FPGA or manipulating its content, many current FPGAs employ a bitstream encryption feature. We develop a successful attack on the bitstream encryption engine integrated in the widespread Virtex-II Pro FPGAs from Xilinx, using side-channel analysis. After measuring the power consumption of a single power-up of the device and a modest amount of off-line computation, we are able to recover all three different keys used by its triple DES module. Our method allows extracting secret keys from any real-world device where the bitstream encryption feature of Virtex-II Pro is enabled. As a consequence, the target product can be cloned and manipulated at the will of the attacker since no side-channel protection was included into the design of the decryption module. Also, more advanced attacks such as reverse engineering or the introduction of hardware Trojans become potential threats. While performing the side-channel attack, we were able to deduce a hypothetical architecture of the hardware encryption engine. To our knowledge, this is the first attack against the bitstream encryption of a commercial FPGA reported in the open literature. Amir Moradi 0001, Alessandro Barenghi, Timo Kasper, Christof Paar |
CCS | 2 |
| 2011 | On the Efficiency of Design Time Evaluation of the Resistance to Power AttacksabstractSide-channel attacks are a realistic threat to the security of real world implementations of cryptographic algorithms. In order to evaluate the resistance of designs against power analysis attacks, power values obtained from circuit simulations in early design phases offer two distinct advantages: First, they offer fast feedback loops to designers, second the number of redesigns can be reduced. This work investigates the accuracy of design time power estimation tools in assessing the security level of a device against differential power attacks. Alessandro Barenghi, Guido Bertoni, Fabrizio De Santis, Filippo Melzani |
DSD | 1 |
| 2011 | Fault attack to the elliptic curve digital signature algorithm with multiple bit faultsabstractElliptic curve cryptosystems proved to be well suited for securing systems with constrained resources like embedded and portable devices. In a fault attack, errors are induced during the computation of a cryptographic primitive, and the faulty results are collected to derive information about the secret key stored into the device in a non-readable way. Scenarios where the secure devices are seized by an opponent are quite common. Consequently, it is possible for an attacker to induce changes in the working environment of the device to cause alterations in the computation of the cryptographic primitive. We introduce a new fault model and attack methodology to recover the secret key employed in implementations of the Elliptic Curve Digital Signature Algorithm. Our attack exploits the information leakage induced when altering the execution of the modular arithmetic operations used in the signature primitive and does not rely on the properties of the underlying elliptic curve mathematical structure, thus being applicable to curves defined on both prime fields and binary fields. The attack is easily reproducible with low cost fault injection technologies relying on transient errors placed within a single datapath width of the target architecture. Alessandro Barenghi, Guido Bertoni, Luca Breveglieri, Gerardo Pelosi, Andrea Palomba |
SIN | 1 |
| 2011 | Information Leakage Discovery Techniques to Enhance Secure Chip Design
Alessandro Barenghi, Gerardo Pelosi, Yannick Teglia |
WISTP | 1 |
| 2010 | Fault attack on AES with single-bit induced faultsabstractThis work presents a differential fault attack against AES employin any key size, regardless of the key scheduling strategy. The presented attack relies on the injection of a single bit flip, and is able to check for the correctness of the injection of the fault a posteriori. This fault model nicely fits the one obtained through underfeeding a computing device employing a low cost tunable power supply unit. This fault injection technique, which has been successfully applied to hardware implementations of AES, receives a further validation in this paper where the target computing device is a system-on-chip based on the widely adopted ARM926EJ-S CPU core. The attack is successfully carried out against two different devices, etched in two different technologies (a generic 130 nm and a low-power oriented 90 nm library) running a software implementation of AES-192 and AES-256 and has been reproduced on multiple instances of the same chip. Alessandro Barenghi, Guido Bertoni, Luca Breveglieri, Mauro Pellicioli, Gerardo Pelosi |
IAS | 1 |
| 2010 | Improving first order differential power attacks through digital signal processingabstractSide-channel attacks pose a critical threat to the deployment of secure embedded systems. Differential-power analysis is a technique relying on measuring the power consumption of device while it computes a cryptographic primitive, and extracting the secret information from it exploiting the knowledge of the operations involving the key. There is no open literature describing how to properly employ Digital Signal Processing (DSP) techniques in order to improve the effectiveness of the attacks. This paper presents a pre-processing technique based on DSP, reducing the number of traces needed to perform an attack by an order of magnitude with respect to the results obtained with raw datasets, and puts it into practical use attacking a commercial 32-bit software implementation of AES running on a Cortex-M3 CPU. The main contribution of this paper is proposing a leakage model for software implemented cryptographic primitives and an effective framework to extract it. Alessandro Barenghi, Gerardo Pelosi, Yannick Teglia |
SIN | 1 |
| 2009 | Low Voltage Fault Attacks on the RSA CryptosystemabstractFault injection attacks are a powerful tool to exploit implementative weaknesses of robust cryptographic algorithms. The faults induced during the computation of the cryptographic primitives allow to extract pieces of information about the secret parameters stored into the device using the erroneous results. Various fault induction techniques have been researched, both to make practical several theoretical fault models proposed in open literature and to outline new kinds of vulnerabilities. In this paper we describe a non-invasive fault model based on the effects of underfeeding the power supply of an ARM general purpose CPU. We describe the methodology followed to characterize the fault model on an ARM9 microprocessor and propose and mount attacks on implementations of the RSA primitives. Alessandro Barenghi, Guido Bertoni, Emanuele Parrinello, Gerardo Pelosi |
FDTC | 1 |
| 2009 | Design of a parallel AES for graphics hardware using the CUDA frameworkabstractWeb servers often need to manage encrypted transfers of data. The encryption activity is computationally intensive, and exposes a significant degree of parallelism. At the same time, cheap multicore processors are readily available on graphics hardware, and toolchains for development of general purpose programs are being released by the vendors. In this paper, we propose an effective implementation of the AES-CTR symmetric cryptographic primitive using the CUDA framework. We provide quantitative data for different implementation choices and compare them with the common CPU-based OpenSSL implementation on a performance-cost basis. With respect to previous works, we focus on optimizing the implementation for practical application scenarios, and we provide a throughput improvement of over 14 times. We also provide insights on the programming knowledge required to efficiently exploit the hardware resources by exposing the different kinds of parallelism built in the AES-CTR cryptographic primitive. Andrea Di Biagio, Alessandro Barenghi, Giovanni Agosta, Gerardo Pelosi |
IPDPS | 2 |
| 2009 | Fast Disk Encryption through GPGPU AccelerationabstractWe present the design and performance analysis of a GPU-optimized implementation of a disk encryption application employing the XTS mode of operation applied together with the Twofish algorithm within the well-known TrueCrypt suite. We show how to correctly tune the design parameters, including data allocation, thread packing, and parallelization strategy. Overall, our implementation of TrueCrypt running on a NVidia GTX260 GPU outperforms by 67% the baseline implementation running on a four core CPU. Giovanni Agosta, Alessandro Barenghi, Fabrizio De Santis, Andrea Di Biagio, Gerardo Pelosi |
PDCAT | 2 |