VLDB 2026 Research / reviewers in the wild / expert
François-Xavier Standaert
dblp:38/2138
· DBLP profile ↗
161ranked-venue papers
19as first author
28since 2021 · last 2026
0000-0001-7444-0285ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 133 · 13 first-author · 21 since 2021Systems, architecture and hardware · 20 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Explaining Explanations: Interpretability Methods for Discourse Analysis of Transformer Attention Maps
Louis Escouflaire, Jérémie Bogaert, Antonin Descampe, Cédrick Fairon, François-Xavier Standaert |
LREC | 5 |
| 2026 | Learning with Errors with Output Dependencies: LWE, LWR, and Physical Learning Problems Under the Same Umbrella
Clément Hoffmann, Pierrick Méaux, Melissa Rossi, François-Xavier Standaert |
PQCrypto (1) | 4 |
| 2025 | IP Masking with Generic Security Guarantees Under Minimum Assumptions, and Applications
Sebastian Faust, Loïc Masure, Elena Michel, Hai Hoang Nguyen, Maximilian Orlt, François-Xavier Standaert |
ASIACRYPT (2) | 6 |
| 2024 | Leakage-Resilient Circuit GarblingabstractDue to the ubiquitous requirements and performance leap in the past decade, it has become feasible to execute garbling and secure computations in settings sensitive to side-channel attacks, including smartphones, IoTs and dedicated hardwares, and the possibilities have been demonstrated by recent works. To maintain security in the presence of a moderate amount of leaked information about internal secrets, we investigate leakage-resilient garbling. We augment the classical privacy, obliviousness and authenticity notions with leakages of the garbling function, and define their leakage-resilience analogues. We examine popular garbling schemes and unveil additional side-channel weaknesses due to wire label reuse and XOR leakages. We then incorporate the idea of label refreshing into the GLNP garbling scheme of Gueron et al. and propose a variant GLNPLR that provably satisfies our leakage-resilience definitions. Performance comparison indicates that GLNPLR is 60X (using AES-NI) or 5X (without AES-NI) faster than the HalfGates garbling with second order side-channel masking, for garbling AES circuit when the bandwidth is 2Gbps. Chun Guo 0002, François-Xavier Standaert, Weijia Wang 0003, Xiao Wang 0012 |
CCS | 4 |
| 2024 | Improved Reductions from Noisy to Bounded and Probing Leakages via Hockey-Stick Divergences
Maciej Obremski, João Ribeiro 0002, Lawrence Roy, François-Xavier Standaert, Daniele Venturi 0001 |
CRYPTO (6) | 4 |
| 2024 | Does a Reduced Fine-Tuning Surface Impact the Stability of the Explanations of LLMs?abstractExplainability is an increasingly demanded feature for the deployment of LLMs.In this context, it has been shown that the explanations of models that are equivalent from the accuracy viewpoint can differ due to their training randomness, leading to a need to characterize the explanations' distribution and to understand the origin of this sensitivity.In this paper, we investigate whether the fine-tuning surface, defined as the number of bits that are fine-tuned in a LLM, can serve as a good proxy for the stability of its explanations.We answer negatively and show that two different approaches for reducing the fine-tuning surface, namely quantizing and freezing (a part of) the models, lead to very different outcomes. Jérémie Bogaert, François-Xavier Standaert |
ESANN | 2 |
| 2024 | Connecting Leakage-Resilient Secret Sharing to Practice: Scaling Trends and Physical Dependencies of Prime Field Masking
Sebastian Faust, Loïc Masure, Elena Micheli, Maximilian Orlt, François-Xavier Standaert |
EUROCRYPT (4) | 5 |
| 2024 | Generalized Feistel Ciphers for Efficient Prime Field Masking
Lorenzo Grassi 0001, Loïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier Standaert |
EUROCRYPT (3) | 5 |
| 2023 | Forgery Attacks on Several Beyond-Birthday-Bound Secure MACs
Yaobin Shen, François-Xavier Standaert, Lei Wang 0031 |
ASIACRYPT (3) | 2 |
| 2023 | Leveraging Coprocessors as Noise Engines in Off-the-Shelf Microcontrollers
Balazs Udvarhelyi, François-Xavier Standaert |
CARDIS | 2 |
| 2023 | Combined Private Circuits - Combined Security RefurbishedabstractPhysical attacks are well-known threats to cryptographic implementations. While countermeasures against passive Side-Channel Analysis (SCA) and active Fault Injection Analysis (FIA) exist individually, protecting against their combination remains a significant challenge. A recent attempt at achieving joint security has been published at CCS 2022 under the name CINI-MINIS. The authors introduce relevant security notions and aim to construct arbitrary-order gadgets that remain trivially composable in the presence of a combined adversary. Yet, we show that all CINI-MINIS gadgets at any order are susceptible to a devastating attack with only a single fault and probe due to a lack of error correction modules in the compression. We explain the details of the attack, pinpoint the underlying problem in the constructions, propose an additional design principle, and provide new (fixed) provably secure and composable gadgets for arbitrary order. Luckily, the changes in the compression stage help us to save correction modules and registers elsewhere, making the resulting Combined Private Circuits (CPC) more secure and more efficient than the original ones. We also explain why the discovered flaws have been missed by the associated formal verification tool VERICA (TCHES 2022) and propose fixes to remove its blind spot. Finally, we explore alternative avenues to repair the compression stage without additional corrections based on non-completeness, i.e. constructing a compression that never recombines any secret. Yet, while this approach could have merit for low-order gadgets, it is, for now, hard to generalize and scales poorly to higher orders. We conclude that our refurbished arbitrary order CINI gadgets provide a solid foundation for further research. Jakob Feldtkeller, Tim Güneysu, Thorben Moos, Jan Richter-Brockmann, Sayandeep Saha, Pascal Sasdrich, François-Xavier Standaert |
CCS | 7 |
| 2023 | Learning with Physical Rounding for Linear and Quadratic Leakage Functions
Clément Hoffmann, Pierrick Méaux, Charles Momin, Yann Rotella, François-Xavier Standaert, Balazs Udvarhelyi |
CRYPTO (3) | 5 |
| 2023 | Prouff and Rivain's Formal Security Proof of Masking, Revisited - Tight Bounds in the Noisy Leakage Model
Loïc Masure, François-Xavier Standaert |
CRYPTO (3) | 2 |
| 2023 | Fine-tuning is not (always) overfitting artifactsabstractSince their release, transformers, and in particular fine-tuned transformers are widely used for text-related classification tasks.However, only a few studies try to understand how fine-tuning actually works and existing alternatives, such as feature-based transformers, are often overlooked.In this work, we study a French transformer model, Camem-BERT, to compare the fine-tuned and feature-based approaches in terms of their performances, interpretability and embedding space.We observe that while fine-tuning has a limited impact on performances in our case study, it significantly affects the intepretability (by better isolating words that are intuitively connected to the classification task) and embedding space (by summarizing the majority of the relevant information into a fewer dimensions) of the results.We conclude by highlighting open questions regarding the generalization potential of fine-tuned embeddings. Jérémie Bogaert, Emmanuel Jean, Cyril de Bodt, François-Xavier Standaert |
ESANN | 4 |
| 2023 | Effective and Efficient Masking with Low Noise Using Small-Mersenne-Prime Ciphers
Loïc Masure, Pierrick Méaux, Thorben Moos, François-Xavier Standaert |
EUROCRYPT (4) | 4 |
| 2023 | Improved Alpha-Information Bounds for Higher-Order Masked Cryptographic ImplementationsabstractEmbedded cryptographic devices are usually protected against side-channel attacks by masking strategies. In this paper, the security of protected cryptographic implementations is evaluated for any masking order, using alpha-information measures. Universal upper bounds on the probability of success of any type of side-channel attack are derived. These also provide lower bounds on the minimum number of queries required to achieve a given success rate. An important issue, solved in this paper, is to remove the loss factor due to the masking field size. Yi Liu 0066, Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Loïc Masure, Olivier Rioul, François-Xavier Standaert |
ITW | 7 |
| 2023 | Compositional Verification of Efficient Masking Countermeasures against Side-Channel AttacksabstractMasking is one of the most effective countermeasures for securely implementing cryptographic algorithms against power side-channel attacks, the design of which however turns out to be intricate and error-prone. While techniques have been proposed to rigorously verify implementations of cryptographic algorithms, currently they are limited in scalability. To address this issue, compositional approaches have been investigated, but insofar they fail to prove the security of recent efficient implementations. To fill this gap, we propose a novel compositional verification approach. In particular, we introduce two new language-level security notions based on which we propose composition strategies and verification algorithms. Our approach is able to prove efficient implementations, which cannot be done by prior compositional approaches. We implement our approach as a tool CONVINCE and conduct extensive experiments to confirm its efficacy. We also use CONVINCE to further explore the design space of the AES Sbox with least refreshing by replacing its implementation for finite-field multiplication with more efficient counterparts. We automatically prove leakage-freeness of these new versions. As a result, we can effectively reduce 1,600 randomness and 3,200 XOR-operations of the state-of-the-art AES implementation. Yedi Zhang, Fu Song, Taolue Chen 0001, François-Xavier Standaert |
Proc. ACM Program. Lang. | 5 |
| 2023 | An In-Depth Evaluation of Externally Amplified Coupling (EAC) Attacks - A Concrete Threat for Masked Cryptographic ImplementationsabstractMasking is a systematic countermeasure to achieve side-channel security for cryptographic algorithms. However, its secure implementation relies on an independence assumption that can be violated by signal coupling. It has been established that coupling induced within a device can be detrimental. It was demonstrated on a$1^{st}$-order secure design (i.e., with two shares) that an adversary who can manipulate the design’s power-measurement setup can externally induce significant coupling. It can thus concretely reduce the “effective-security-order”, i.e., make$1^{st}$-order leakages as significant as$2^{nd}$-order ones with fewer measurements. This paper explores the impact of such external amplification phenomena on fabricated hardware test cases for the first time. We designed a dedicated ASIC to extend the empirical results for demonstrating impact up to the$4^{th}$order. We have systematically evaluate d factors related to adversarial control, e.g., the external measurement resistance. We also investigate d their relative influence compared to intra-design ones, i.e., internal power-grid resistance and transistors’ inherent resistance. Our study demonstrates that externally amplified coupling scale s up to concrete masked hardware designs with various amounts of shares and is not very sensitive to intra-design parameters. Therefore, providing experimental evidence that such coupling should be considered during masking validation. Ofek Gur, Tomer Gross, Davide Bellizia, François-Xavier Standaert, Itamar Levi |
IEEE Trans. Circuits Syst. I Regul. Pap. | 4 |
| 2022 | Towards Case-Optimized Hybrid Homomorphic Encryption - Featuring the Elisabeth Stream Cipher
Orel Cosseron, Clément Hoffmann, Pierrick Méaux, François-Xavier Standaert |
ASIACRYPT (3) | 4 |
| 2022 | A Third is All You Need: Extended Partial Key Exposure Attack on CRT-RSA with Additive Exponent Blinding
Yuanyuan Zhou 0006, Joop van de Pol, Yu Yu 0001, François-Xavier Standaert |
ASIACRYPT (4) | 4 |
| 2022 | A Nearly Tight Proof of Duc et al.'s Conjectured Security Bound for Masked Implementations
Loïc Masure, Olivier Rioul, François-Xavier Standaert |
CARDIS | 3 |
| 2022 | Analyzing the Leakage Resistance of the NIST's Lightweight Crypto Competition's Finalists
Corentin Verhamme, Gaëtan Cassiers, François-Xavier Standaert |
CARDIS | 3 |
| 2022 | Efficient Profiled Side-Channel Analysis of Masked Implementations, ExtendedabstractWe extend the study of efficient profiled attacks on masking schemes initiated by Lerman and Markowitch (TIFS, 2019) in different directions. First, we study both the profiling complexity and the online attack complexity of different profiled distinguishers. Second, we extend the range of the noise levels of their experiments, in order to cover (higher-noise) contexts where masking is effective. Third, we further contextualize the investigated distinguishers (e.g., in terms of adversarial capabilities and a priori assumptions on the leakage probability density function). Finally, we complete the list of distinguishers considered in this previous work and add expectation-maximization, soft analytical side-channel attacks and multi-layer perceptrons in our comparisons. Our results allow shedding an interesting new light on the respective strengths and weaknesses of these different statistical tools, both in the context of a side-channel security evaluation and for concrete attacks. In particular, they confirm the experimental relevance of evaluation shortcuts leveraging the masking randomness during profiling, in order to speed up the evaluation process. Olivier Bronchain, François Durvaux, Loïc Masure, François-Xavier Standaert |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Efficient Leakage-Resilient MACs Without Idealized Assumptions
Francesco Berti, Chun Guo 0002, Thomas Peters, François-Xavier Standaert |
ASIACRYPT (2) | 4 |
| 2021 | Towards a Better Understanding of Side-Channel Analysis Measurements Setups
Davide Bellizia, Balazs Udvarhelyi, François-Xavier Standaert |
CARDIS | 3 |
| 2021 | Towards Tight Random Probing Security
Gaëtan Cassiers, Sebastian Faust, Maximilian Orlt, François-Xavier Standaert |
CRYPTO (3) | 4 |
| 2021 | Evaluating and Designing against Side-Channel Leakage: White Box or Black Box?abstractSide-channel analysis is an important concern for the security of cryptographic implementations, and may lead to powerful key recovery attacks if no countermeasures are deployed. Therefore, various types of protection mechanisms have been proposed over the last 20 years. In view of the cost and performance overheads caused by these protections, their fair evaluation and scarce use are a primary concern for hardware and software designers. Yet, the physical nature of side-channel analysis also renders the security evaluation of cryptographic implementations very different from the one of cryptographic algorithms against mathematical cryptanalysis. That is, while the latter can be quantified based on (well-defined) time, data and memory complexities, the evaluation of side-channel security additionally requires to quantify the informativeness and exploitability of the physical leakages. This implies that a part of these security evaluations is inherently heuristic and dependent on engineering expertise. It also raises the question of the capabilities given to the adversary/evaluator. For example, should she get full (unrestricted) access to the implementation to gain a precise understanding of its functioning (which I will denote as the white box approach) or should she be more restricted? In this talk, I will argue that a white box approach is not only desirable in order to avoid designing and evaluating implementations with a "false sense of security" but also that such designs become feasible in view of the research progresses made over the last two decades. François-Xavier Standaert |
IH&MMSec | 1 |
| 2021 | Hardware Private Circuits: From Trivial Composition to Full VerificationabstractThe design of glitch-resistant higher-order masking schemes is an important challenge in cryptographic engineering. A recent work by Mooset al.(CHES 2019) showed that most published schemes (and all efficient ones) exhibit local or composability flaws at high security orders, leaving a critical gap in the literature on hardware masking. In this article, we first extend the simulatability framework of Belaïdet al.(EUROCRYPT 2016) and prove that a compositional strategy that is correct without glitches remains valid with glitches. We then use this extended framework to prove the first masked gadgets that enable trivial composition with glitches at arbitrary orders. We show that the resulting “Hardware Private Circuits” approach the implementation efficiency of previous (flawed) schemes. We finally investigate how trivial composition can serve as a basis for a tool that allows verifying full masked hardware implementations (e.g., of complete block ciphers) at any security order from their HDL code. As side products, we improve the randomness complexity of the best published refreshing gadgets, show that some S-box representations allow latency reductions and confirm practical claims based on implementation results. Gaëtan Cassiers, Benjamin Grégoire, Itamar Levi, François-Xavier Standaert |
IEEE Trans. Computers | 4 |
| 2020 | Packed Multiplication: How to Amortize the Cost of Side-Channel Masking?
Weijia Wang 0003, Chun Guo 0002, François-Xavier Standaert, Yu Yu 0001, Gaëtan Cassiers |
ASIACRYPT (1) | 3 |
| 2020 | On the Security of Off-the-Shelf Microcontrollers: Hardware Is Not Enough
Balazs Udvarhelyi, Antoine van Wassenhove, Olivier Bronchain, François-Xavier Standaert |
CARDIS | 4 |
| 2020 | Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance Jungle
Davide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso, Chun Guo 0002, Charles Momin, Olivier Pereira, Thomas Peters, François-Xavier Standaert |
CRYPTO (1) | 9 |
| 2020 | Learning with Physical Noise or ErrorsabstractHard learning problems have recently attracted significant attention within the cryptographic community, both as a versatile assumption on which to build various protocols, and as a potentially sound basis for lightweight (possibly side-channel and fault resistant) implementations. Yet, in this second case, a recurrent drawback of primitives based on the Learning Parity with Noise and Learning With Errors problems is their additional randomness requirements to generate noise or errors. In parallel, the move towards nanoscale devices renders modern implementations increasingly prone to various types of errors. As a result, inexact computing has emerged as a new paradigm to efficiently deal with the challenges raised by such erroneous computations, and mitigate the cost and power consumption overheads they cause. In this paper, we show that these cryptographic and electronic challenges can actually be turned into new opportunities, and provide an elegant solution one to the other. That is, we show that inexact implementations of inner product computations lead to a natural way to define new Learning with Physical Noise or Error assumptions, paving the way to more efficient and physically secure implementations, with potential interest for securing emerging Internet of Things applications. Dina Kamel, François-Xavier Standaert, Alexandre Duc, Denis Flandre, Francesco Berti |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Trivially and Efficiently Composing Masked Gadgets With Probe Isolating Non-InterferenceabstractWe revisit the analysis and design of masked cryptographic implementations to prevent side-channel attacks. Our starting point is the (known) observation that proving the security of a higher-order masked block cipher exhaustively requires unrealistic computing power. As a result, a natural strategy is to split algorithms in smaller parts (or gadgets), with as main objectives to enable both simple composition (as initiated by Barthe et al. at CCS 2016) and efficient implementations. We argue that existing composition strategies allow either trivial composition with significant overheads or optimized composition with more analysis efforts. As a result, we first introduce a new definition of Probe Isolating Non-Interference (PINI) that allows both trivial composition and efficient implementations. We next prove general composition theorems for PINI gadgets that considerably simplify the analysis of complex masked implementations. We finally design efficient multiplication gadgets that satisfy this definition. As additional results, we exhibit a limitation of existing compositional strategies for the analysis of Multiple-Inputs / Multiple-Outputs (MIMO) gadgets, extend Barthe et al. definition of Strong Non-Interference (SNI) to deal with this context, and describe an optimization method to design efficient MIMO-SNI (sub)circuits. Our results allow proving the security of a recent masked AES implementation by Goudarzi and Rivain (EUROCRYPT 2017). From the implementation viewpoint, PINI implementations reach the level of performance of the best composable masking schemes for the AES Rijndael, and outperform them by significant factors for lightweight ciphers. Gaëtan Cassiers, François-Xavier Standaert |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Key Enumeration from the Adversarial Viewpoint
Melissa Azouaoui, Romain Poussier, François-Xavier Standaert, Vincent Verneuil |
CARDIS | 3 |
| 2019 | Strong Authenticity with Leakage Under Weak and Falsifiable Physical Assumptions
Francesco Berti, Chun Guo 0002, Olivier Pereira, Thomas Peters, François-Xavier Standaert |
Inscrypt | 5 |
| 2019 | Leakage Certification Revisited: Bounding Model Errors in Side-Channel Security Evaluations
Olivier Bronchain, Julien M. Hendrickx, Clément Massart, Alexander Olshevsky, François-Xavier Standaert |
CRYPTO (1) | 5 |
| 2019 | maskVerif: Automated Verification of Higher-Order Masking in Presence of Physical Defaults
Gilles Barthe, Sonia Belaïd, Gaëtan Cassiers, Pierre-Alain Fouque, Benjamin Grégoire, François-Xavier Standaert |
ESORICS (1) | 6 |
| 2019 | A security oriented transient-noise simulation methodology: Evaluation of intrinsic physical noise of cryptographic designs
Kashif Nawaz, Léopold Van Brandt, Itamar Levi, François-Xavier Standaert, Denis Flandre |
Integr. | 4 |
| 2019 | Making Masking Security Proofs Concrete (Or How to Evaluate the Security of Any Leaking Device), Extended Version
Alexandre Duc, Sebastian Faust, François-Xavier Standaert |
J. Cryptol. | 3 |
| 2019 | Provable Order Amplification for Code-Based Masking: How to Avoid Non-Linear Leakages Due to Masked OperationsabstractCode-based masking schemes have been shown to provide higher theoretical security guarantees than Boolean masking. In particular, one interesting feature put forward at CARDIS 2016 and then analyzed at CARDIS 2017 was the socalled security order amplification: under the assumption that the leakage function is linear, it guarantees that an implementation performing only linear operations will have a security order in the bounded moment leakage model larger than d - 1, where d is the number of shares. The main question regarding this feature is its practical relevance. First of all, concrete block ciphers do not only perform linear operations. Second, it may be that actual leakage functions are not perfectly linear (raising questions regarding what happens when one deviates from such assumptions). In this paper, we show that the issue of only linear operations can be provably avoided and that it is possible to obtain security order amplification for any functionality to implement. We then show that (not so) slightly non-linear leakage functions do not annihilate the nice properties (i.e., that the code-based schemes we consider remain interesting compared to the Boolean masking). We conclude with a performance evaluation of the proposals, showing that the performance overheads are moderate for a reasonable number of shares (we studied when the number of the shares d = 2,3,4). In additional, our results could be specified to the case of provable security for low entropy masking, which can be considered as a side bonus of our contributions. We give some preliminary results on how to construct the low entropy masking schemes with provable high security order against linear leakage. Weijia Wang 0003, Yu Yu 0001, François-Xavier Standaert |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | How (Not) to Use Welch's T-Test in Side-Channel Security Evaluations
François-Xavier Standaert |
CARDIS | 1 |
| 2018 | Ciphertext Integrity with Misuse and Leakage: Definition and Efficient Constructions with Symmetric PrimitivesabstractLeakage resilience (LR) and misuse resistance (MR) are two important properties for the deployment of authenticated encryption (AE) schemes. They aim at mitigating the impact of implementation flaws due to side-channel leakages and misused randomness. In this paper, we discuss the interactions and incompatibilities between these two properties. Francesco Berti, François Koeune, Olivier Pereira, Thomas Peters, François-Xavier Standaert |
AsiaCCS | 5 |
| 2018 | Masking Proofs Are Tight and How to Exploit it in Security Evaluations
Vincent Grosso, François-Xavier Standaert |
EUROCRYPT (2) | 2 |
| 2018 | Start Simple and then Refine: Bias-Variance Decomposition as a Diagnosis Tool for Leakage ProfilingabstractEvaluating the resistance of cryptosystems to side-channel attacks is an important research challenge. Profiled attacks reveal the degree of resilience of a cryptographic device when an adversary examines its physical characteristics. So far, evaluation laboratories launch several physical attacks (based on engineering intuitions) in order to find one strategy that eventually extracts secret information (such as a secret cryptographic key). The certification step represents a complex task because in practice the evaluators have tight memory and time constraints. In this paper, we propose a principled way of guiding the design of the most successful evaluation strategies thanks to the (bias-variance) decomposition of a security metric of profiled attacks. Our results show that we can successfully apply our framework on unprotected and protected algorithms implemented in software and hardware. Liran Lerman, Nikita Veshchikov, Olivier Markowitch, François-Xavier Standaert |
IEEE Trans. Computers | 4 |
| 2018 | Ridge-Based DPA: Improvement of Differential Power Analysis For Nanoscale ChipsabstractDifferential power analysis (DPA), as a very practical type of side-channel attacks, has been widely studied and used for the security analysis of cryptographic implementations. However, as the development of the chip industry leads to smaller technologies, the leakage of cryptographic implementations in nanoscale devices tends to be nonlinear (i.e., leakages of intermediate bits are no longer independent) and unpredictable. These phenomena make some existing side-channel attacks not perfectly suitable, i.e., decreasing their performance and making some common used prior power models (e.g., Hamming weight) to be much less respected in practice. To solve the above issues, we introduce the regularization process from statistical learning to the area of side-channel attack and propose the ridge-based DPA. We also apply the cross-validation technique to search for the most suitable value of the parameter for our new attack methods. In addition, we present theoretical analyses to deeply investigate the properties of ridge-based DPA for nonlinear leakages. We evaluate the performance of ridge-based DPA in both simulation-based and practical experiments, comparing to the state-to-the-art DPAs. The results confirm the theoretical analysis. Further, our experiments show the robustness of ridge-based DPA to cope with the difference between the leakages of profiling and exploitation power traces. Therefore, by showing a good adaptability to the leakage of the nanoscale chips, the ridge-based DPA is a good alternative to the state-to-the-art ones. Weijia Wang 0003, Yu Yu 0001, François-Xavier Standaert, Zheng Guo 0001, Dawu Gu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Consolidating Inner Product Masking
Josep Balasch, Sebastian Faust, Benedikt Gierlichs, Clara Paglialonga, François-Xavier Standaert |
ASIACRYPT (1) | 5 |
| 2017 | Towards Sound and Optimal Leakage Detection Procedure
A. Adam Ding, François Durvaux, François-Xavier Standaert, Yunsi Fei |
CARDIS | 4 |
| 2017 | Connecting and Improving Direct Sum Masking and Inner Product Masking
Romain Poussier, Qian Guo 0001, François-Xavier Standaert, Claude Carlet, Sylvain Guilley |
CARDIS | 3 |
| 2017 | Gimli : A Cross-Platform Permutation
Daniel J. Bernstein, Stefan Kölbl, Stefan Lucks, Pedro Maat Costa Massolino, Florian Mendel, Kashif Nawaz, Tobias Schneider 0002, Peter Schwabe, François-Xavier Standaert, Yosuke Todo, Benoît Viguier |
CHES | 9 |
| 2017 | Very High Order Masking: Efficient Implementation and Security Evaluation
Anthony Journault, François-Xavier Standaert |
CHES | 2 |
| 2017 | A Systematic Approach to the Side-Channel Analysis of ECC Implementations with Worst-Case Horizontal Attacks
Romain Poussier, Yuanyuan Zhou 0006, François-Xavier Standaert |
CHES | 3 |
| 2017 | Ridge-Based Profiled Differential Power Analysis
Weijia Wang 0003, Yu Yu 0001, François-Xavier Standaert, Dawu Gu, Chi Zhang 0061 |
CT-RSA | 3 |
| 2017 | Parallel Implementations of Masking Schemes and the Bounded Moment Leakage Model
Gilles Barthe, François Dupressoir, Sebastian Faust, Benjamin Grégoire, François-Xavier Standaert, Pierre-Yves Strub |
EUROCRYPT (1) | 5 |
| 2017 | Improving the security and efficiency of block ciphers based on LS-designs
Anthony Journault, François-Xavier Standaert, Kerem Varici |
Des. Codes Cryptogr. | 2 |
| 2016 | Taylor Expansion of Maximum Likelihood Attacks for Masked and Shuffled Implementations
Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Olivier Rioul, François-Xavier Standaert, Yannick Teglia |
ASIACRYPT (1) | 5 |
| 2016 | Unknown-Input Attacks in the Parallel Setting: Improving the Security of the CHES 2012 Leakage-Resilient PRF
Marcel Medwed, François-Xavier Standaert, Ventzislav Nikov, Martin Feldhofer |
ASIACRYPT (1) | 2 |
| 2016 | An Analysis of the Learning Parity with Noise Assumption Against Fault Attacks
Francesco Berti, François-Xavier Standaert |
CARDIS | 2 |
| 2016 | Inner Product Masking for Bitslice Ciphers and Security Order Amplification for Linear Leakages
Weijia Wang 0003, François-Xavier Standaert, Yu Yu 0001, Sihang Pu, Zheng Guo 0001, Dawu Gu |
CARDIS | 2 |
| 2016 | Private Circuits III: Hardware Trojan-Resilience via Testing AmplificationabstractSecurity against hardware trojans is currently becoming an essential ingredient to ensure trust in information systems. A variety of solutions have been introduced to reach this goal, ranging from reactive (i.e., detection-based) to preventive (i.e., trying to make the insertion of a trojan more difficult for the adversary). In this paper, we show how testing (which is a typical detection tool) can be used to state concrete security guarantees for preventive approaches to trojan-resilience. For this purpose, we build on and formalize two important previous works which introduced ``input scrambling" and ``split manufacturing" as countermeasures to hardware trojans. Using these ingredients, we present a generic compiler that can transform any circuit into a trojan-resilient one, for which we can state quantitative security guarantees on the number of correct executions of the circuit thanks to a new tool denoted as ``testing amplification". Compared to previous works, our threat model covers an extended range of hardware trojans while we stick with the goal of minimizing the number of honest elements in our transformed circuits. Since transformed circuits essentially correspond to redundant multiparty computations of the target functionality, they also allow reasonably efficient implementations, which can be further optimized if specialized to certain cryptographic primitives and security goals. Stefan Dziembowski, Sebastian Faust, François-Xavier Standaert |
CCS | 3 |
| 2016 | Towards Easy Leakage Certification
François Durvaux, François-Xavier Standaert, Santos Merino Del Pozo |
CHES | 2 |
| 2016 | Simple Key Enumeration (and Rank Estimation) Using Histograms: An Integrated Approach
Romain Poussier, François-Xavier Standaert, Vincent Grosso |
CHES | 2 |
| 2016 | Towards Sound Fresh Re-keying with Hard (Physical) Learning Problems
Stefan Dziembowski, Sebastian Faust, Gottfried Herold, Anthony Journault, Daniel Masny, François-Xavier Standaert |
CRYPTO (2) | 6 |
| 2016 | Leverage Emerging Technologies For DPA-Resilient Block Cipher Design
Yu Bi, Kaveh Shamsi, Jiann-Shiun Yuan, François-Xavier Standaert, Yier Jin |
DATE | 4 |
| 2016 | From Improved Leakage Detection to the Detection of Points of Interests in Leakage Traces
François Durvaux, François-Xavier Standaert |
EUROCRYPT (1) | 2 |
| 2016 | Towards Stream Ciphers for Efficient FHE with Low-Noise Ciphertexts
Pierrick Méaux, Anthony Journault, François-Xavier Standaert, Claude Carlet |
EUROCRYPT (1) | 3 |
| 2016 | Bridging the Gap: Advanced Tools for Side-Channel Leakage Estimation Beyond Gaussian Templates and Histograms
Tobias Schneider 0002, Amir Moradi 0001, François-Xavier Standaert, Tim Güneysu |
SAC | 3 |
| 2016 | A Framework for the Analysis and Evaluation of Algebraic Fault Attacks on Lightweight Block CiphersabstractAlgebraic fault analysis (AFA), which combines algebraic cryptanalysis with fault attacks, has represented serious threats to the security of lightweight block ciphers. Inspired by an earlier framework for the analysis of side-channel attacks presented at EUROCRYPT 2009, a new generic framework is proposed to analyze and evaluate algebraic fault attacks on lightweight block ciphers. We interpret AFA at three levels: 1) the target; 2) the adversary; and 3) the evaluator. We describe the capability of an adversary in four parts: 1) the fault injector; 2) the fault model describer; 3) the cipher describer; and 4) the machine solver. A formal fault model is provided to cover most of current fault attacks. Different strategies of building optimal equation set are also provided to accelerate the solving process. At the evaluator level, we consider the approximate information metric and the actual security metric. These metrics can be used to guide adversaries, cipher designers, and industrial engineers. To verify the feasibility of the proposed framework, we make a comprehensive study of AFA on an ultra-lightweight block cipher called LBlock. Three scenarios are exploited, which include injecting a fault to encryption, to key scheduling, or modifying the round number or counter. Our best results show that a single fault injection is enough to recover the master key of LBlock within the affordable complexity in each scenario. To verify the generic feature of the proposed framework, we apply AFA to three other block ciphers, i.e., Data Encryption Standard, PRESENT, and Twofish. The results demonstrate that our framework can be used for different ciphers with different structures. Fan Zhang 0010, Shize Guo, Xinjie Zhao 0001, Tao Wang 0008, Jian Yang 0018, François-Xavier Standaert, Dawu Gu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2015 | ASCA, SASCA and DPA with Enumeration: Which One Beats the Other and When?
Vincent Grosso, François-Xavier Standaert |
ASIACRYPT (2) | 2 |
| 2015 | Towards Fresh and Hybrid Re-Keying Schemes with Beyond Birthday Security
Christoph Dobraunig, François Koeune, Stefan Mangard, Florian Mendel, François-Xavier Standaert |
CARDIS | 5 |
| 2015 | Comparing Approaches to Rank Estimation for Side-Channel Security Evaluations
Romain Poussier, Vincent Grosso, François-Xavier Standaert |
CARDIS | 3 |
| 2015 | Leakage-Resilient Authentication and Encryption from Symmetric Cryptographic PrimitivesabstractLeakage-resilient cryptosystems aim to maintain security in situations where their implementation leaks physical information about their internal secrets. Because of their efficiency and usability on a wide range of platforms, solutions based on symmetric primitives (such as block ciphers) are particularly attractive in this context. So far, the literature has mostly focused on the design of leakage-resilient pseudorandom objects (e.g. PRGs, PRFs, PRPs). In this paper, we consider the complementary and practically important problem of designing secure authentication and encryption schemes. For this purpose, we follow a pragmatic approach based on the advantages and limitations of existing leakage-resilient pseudorandom objects, and rely on the (arguably necessary, yet minimal) use of a leak-free component. The latter can typically be instantiated with a block cipher implementation protected by traditional countermeasures, and we investigate how to combine it with the more intensive use of a much more efficient (less protected) block cipher implementation. Based on these premises, we propose and analyse new constructions of leakage-resilient MAC and encryption schemes, which allow fixing security and efficiency drawbacks of previous proposals in this direction. For encryption, we additionally provide a detailed discussion of why previously proposed (indistinguishability based) security definitions cannot capture actual side-channel attacks, and suggest a relaxed and more realistic way to quantify leakage-resilience in this case, by reducing the security of many iterations of the primitive to the security of a single iteration, independent of the security notion guaranteed by this single iteration (that remains hard to define). Olivier Pereira, François-Xavier Standaert, Srinivas Vivek 0001 |
CCS | 2 |
| 2015 | Blind Source Separation from Single Measurements Using Singular Spectrum Analysis
Santos Merino Del Pozo, François-Xavier Standaert |
CHES | 2 |
| 2015 | Evaluation and Improvement of Generic-Emulating DPA Attacks
Weijia Wang 0003, Yu Yu 0001, Zheng Guo 0001, François-Xavier Standaert, Dawu Gu |
CHES | 5 |
| 2015 | Side-channel attacks from static power: when should we care?
Santos Merino Del Pozo, François-Xavier Standaert, Dina Kamel, Amir Moradi 0001 |
DATE | 2 |
| 2015 | Small Tweaks Do Not Help: Differential Power Analysis of MILENAGE Implementations in 3G/4G USIM CardsabstractSide-channel attacks are an increasingly important concern for the security of cryptographic embedded devices, such as the SIM cards used in mobile phones. Previous works have exhibited such attacks against implementations of the 2G GSM algorithms (COMP-128, A5). In this paper, we show that they remain an important issue for USIM cards implementing the AES-based MILENAGE algorithm used in 3G/4G communications. In particular, we analyze instances of cards from a variety of operators and manufacturers, and describe successful Differential Power Analysis attacks that recover encryption keys and other secrets (needed to clone the USIM cards) within a few minutes. Further, we discuss the impact of the operator-defined secret parameters in MILENAGE on the difficulty to perform Differential Power Analysis, and show that they do not improve implementation security. Our results back up the observation that physical security issues raise long-term challenges that should be solved early in the development of cryptographic implementations, with adequate countermeasures. Yu Yu 0001, François-Xavier Standaert, Zheng Guo 0001, Dawu Gu, Yijie Ge, Xinjun Xie |
ESORICS (1) | 3 |
| 2015 | Making Masking Security Proofs Concrete - Or How to Evaluate the Security of Any Leaking Device
Alexandre Duc, Sebastian Faust, François-Xavier Standaert |
EUROCRYPT (1) | 3 |
| 2015 | Simpler and More Efficient Rank Estimation for Side-Channel Security Assessment
Cezary Glowacz, Vincent Grosso, Romain Poussier, Joachim Schüth, François-Xavier Standaert |
FSE | 5 |
| 2015 | On the Impacts of Mathematical Realization over Practical Security of Leakage Resilient Cryptographic Schemes
Guangjun Fan, Yongbin Zhou, François-Xavier Standaert, Dengguo Feng |
ISPEC | 3 |
| 2015 | Automatic Application of Power Analysis CountermeasuresabstractWe introduce a compiler that automatically inserts software countermeasures to protect cryptographic algorithms against power-based side-channel attacks. The compiler first estimates which instruction instances leak the most information through side-channels. This information is obtained either by dynamic analysis, evaluating an information theoretic metric over the power traces acquired during the execution of the input program, or by static analysis. As information leakage implies a loss of security, the compiler then identifies (groups of) instruction instances to protect with a software countermeasure such as random precharging or Boolean masking. As software protection incurs significant overhead in terms of cryptosystem runtime and memory usage, the compiler protects the minimum number of instruction instances to achieve a desired level of security. The compiler is evaluated on two block ciphers, AES and Clefia; our experiments demonstrate that the compiler can automatically identify and protect the most important instruction instances. To date, these software countermeasures have been inserted manually by security experts, who are not necessarily the main cryptosystem developers. Our compiler offers significant productivity gains for cryptosystem developers who wish to protect their implementations from side-channel attacks. Ali Galip Bayrak, Francesco Regazzoni 0001, David Novo, Philip Brisk, François-Xavier Standaert, Paolo Ienne |
IEEE Trans. Computers | 5 |
| 2014 | Soft Analytical Side-Channel Attacks
Nicolas Veyrat-Charvillon, Benoît Gérard, François-Xavier Standaert |
ASIACRYPT (1) | 3 |
| 2014 | On the Cost of Lazy Engineering for Masked Software Implementations
Josep Balasch, Benedikt Gierlichs, Vincent Grosso, Oscar Reparaz, François-Xavier Standaert |
CARDIS | 5 |
| 2014 | Combining Leakage-Resilient PRFs and Shuffling - Towards Bounded Security for Small Embedded Devices
Vincent Grosso, Romain Poussier, François-Xavier Standaert, Lubos Gaspar |
CARDIS | 3 |
| 2014 | FPGA Implementations of SPRING - And Their Countermeasures against Side-Channel Attacks
Hai Brenner, Lubos Gaspar, Gaëtan Leurent, Alon Rosen, François-Xavier Standaert |
CHES | 5 |
| 2014 | Hardware Implementation and Side-Channel Analysis of Lapin
Lubos Gaspar, Gaëtan Leurent, François-Xavier Standaert |
CT-RSA | 3 |
| 2014 | The Myth of Generic DPA...and the Magic of Learning
Carolyn Whitnall, Elisabeth Oswald, François-Xavier Standaert |
CT-RSA | 3 |
| 2014 | How to Certify the Leakage of a Chip?
François Durvaux, François-Xavier Standaert, Nicolas Veyrat-Charvillon |
EUROCRYPT | 2 |
| 2014 | LS-Designs: Bitslice Encryption for Efficient Masked Software Implementations
Vincent Grosso, Gaëtan Leurent, François-Xavier Standaert, Kerem Varici |
FSE | 3 |
| 2014 | Exploiting the Incomplete Diffusion Feature: A Specialized Analytical Side-Channel Attack Against the AES and Its Application to Microcontroller ImplementationsabstractAlgebraic side-channel attack (ASCA) is a typical technique that relies on a general solver to solve the equations of a cipher and its side-channel leaks. It falls under analytical side-channel attack and can recover the entire key at once. Many ASCAs are proposed against the AES, and they utilize the Gröbner basis-based, SAT-based, or optimizer-based solver. The advantage of the general solver approach is its generic feature, which can be easily applied to different cryptographic algorithms. The disadvantage is that it is difficult to take into account the specialized properties of the targeted cryptographic algorithms. The results vary depending on what type of solver is used, and the time complexity is quite high when considering the error-tolerant attack scenarios. Thus, we were motivated to find a new approach that would lessen the influence of the general solver and reduce the time complexity of ASCA. This paper proposes a new analytical side-channel attack on AES by exploiting the incomplete diffusion feature in one AES round. We named our technique incomplete diffusion analytical side-channel analysis (IDASCA). Different from previous ASCAs, IDASCA adopts a specialized approach to recover the secret key of AES instead of the general solver. Extensive attacks are performed against the software implementation of AES on an 8-bit microcontroller. Experimental results show that: 1) IDASCA can exploit the side-channel leaks in all AES rounds using a single power trace; 2) it has less time complexity and more robustness than previous ASCAs, especially when considering the error-tolerant attack scenarios; and 3) it can calculate the reduced key search space of AES for the given amount of side-channel leaks. IDASCA can also interpret the mechanism behind previous ASCAs on AES from a quantitative perspective, such as why ASCA can work under unknown plaintext/ciphertext scenarios and what are the extreme cases in ASCAs. Shize Guo, Xinjie Zhao 0001, Fan Zhang 0010, Tao Wang 0008, Zhijie Jerry Shi, François-Xavier Standaert, Chujiao Ma |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2013 | Low Entropy Masking Schemes, Revisited
Vincent Grosso, François-Xavier Standaert, Emmanuel Prouff |
CARDIS | 2 |
| 2013 | From New Technologies to New Solutions - Exploiting FRAM Memories to Enhance Physical Security
Stéphanie Kerckhof, François-Xavier Standaert, Eric Peeters |
CARDIS | 2 |
| 2013 | Block Ciphers That Are Easier to Mask: How Far Can We Go?
Benoît Gérard, Vincent Grosso, María Naya-Plasencia, François-Xavier Standaert |
CHES | 4 |
| 2013 | Masking vs. Multiparty Computation: How Large Is the Gap for AES?
Vincent Grosso, François-Xavier Standaert, Sebastian Faust |
CHES | 2 |
| 2013 | Leakage-Resilient Symmetric Cryptography under Empirically Verifiable Assumptions
François-Xavier Standaert, Olivier Pereira, Yu Yu 0001 |
CRYPTO (1) | 1 |
| 2013 | Practical Leakage-Resilient Pseudorandom Objects with Minimum Public Randomness
Yu Yu 0001, François-Xavier Standaert |
CT-RSA | 2 |
| 2013 | Security Evaluations beyond Computing Power
Nicolas Veyrat-Charvillon, Benoît Gérard, François-Xavier Standaert |
EUROCRYPT | 3 |
| 2013 | Systematic Construction and Comprehensive Evaluation of Kolmogorov-Smirnov Test Based Side-Channel Distinguishers
Yongbin Zhou, François-Xavier Standaert, Hailong Zhang 0001 |
ISPEC | 3 |
| 2012 | Shuffling against Side-Channel Attacks: A Comprehensive Study with Cautionary Note
Nicolas Veyrat-Charvillon, Marcel Medwed, Stéphanie Kerckhof, François-Xavier Standaert |
ASIACRYPT | 4 |
| 2012 | Compact Implementation and Performance Evaluation of Hash Functions in ATtiny Devices
Josep Balasch, Baris Ege, Thomas Eisenbarth 0001, Benoît Gérard, Tim Güneysu, Stefan Heyse, Stéphanie Kerckhof, François Koeune, Thomas Plos, Thomas Pöppelmann, Francesco Regazzoni 0001, François-Xavier Standaert, Gilles Van Assche, Ronny Van Keer, Loïc van Oldeneel tot Oldenzeel, Ingo von Maurich |
CARDIS | 13 |
| 2012 | Efficient Removal of Random Delays from Embedded Software Implementations Using Hidden Markov Models
François Durvaux, Mathieu Renauld, François-Xavier Standaert, Loïc van Oldeneel tot Oldenzeel, Nicolas Veyrat-Charvillon |
CARDIS | 3 |
| 2012 | Unified and Optimized Linear Collision Attacks and Their Application in a Non-profiled Setting
Benoît Gérard, François-Xavier Standaert |
CHES | 2 |
| 2012 | Towards Green Cryptography: A Comparison of Lightweight Ciphers from the Energy Viewpoint
Stéphanie Kerckhof, François Durvaux, Cédric Hocquet, David Bol, François-Xavier Standaert |
CHES | 5 |
| 2012 | Towards Super-Exponential Side-Channel Security with Efficient Leakage-Resilient PRFs
Marcel Medwed, François-Xavier Standaert, Antoine Joux |
CHES | 2 |
| 2012 | Algebraic Side-Channel Attacks Beyond the Hamming Weight Leakage Model
Yossef Oren, Mathieu Renauld, François-Xavier Standaert, Avishai Wool |
CHES | 3 |
| 2012 | Key-Alternating Ciphers in a Provable Setting: Encryption Using a Small Number of Public Permutations - (Extended Abstract)
Andrey Bogdanov, Lars R. Knudsen, Gregor Leander, François-Xavier Standaert, John P. Steinberger, Elmar Tischhauser |
EUROCRYPT | 4 |
| 2012 | An Optimal Key Enumeration Algorithm and Its Application to Side-Channel Attacks
Nicolas Veyrat-Charvillon, Benoît Gérard, Mathieu Renauld, François-Xavier Standaert |
Selected Areas in Cryptography | 4 |
| 2011 | Compact FPGA Implementations of the Five SHA-3 Finalists
Stéphanie Kerckhof, François Durvaux, Nicolas Veyrat-Charvillon, Francesco Regazzoni 0001, Guerric Meurice de Dormale, François-Xavier Standaert |
CARDIS | 6 |
| 2011 | Fresh Re-keying II: Securing Multiple Parties against Side-Channel and Fault Attacks
Marcel Medwed, Christophe Petit 0001, Francesco Regazzoni 0001, Mathieu Renauld, François-Xavier Standaert |
CARDIS | 5 |
| 2011 | Extractors against Side-Channel Attacks: Weak or Strong?
Marcel Medwed, François-Xavier Standaert |
CHES | 2 |
| 2011 | Information Theoretic and Security Analysis of a 65-Nanometer DDSLL AES S-Box
Mathieu Renauld, Dina Kamel, François-Xavier Standaert, Denis Flandre |
CHES | 3 |
| 2011 | Leftover Hash Lemma, Revisited
Boaz Barak, Yevgeniy Dodis, Hugo Krawczyk, Olivier Pereira, Krzysztof Pietrzak, François-Xavier Standaert, Yu Yu 0001 |
CRYPTO | 6 |
| 2011 | Generic Side-Channel Distinguishers: Improvements and Limitations
Nicolas Veyrat-Charvillon, François-Xavier Standaert |
CRYPTO | 2 |
| 2011 | A first step towards automatic application of power analysis countermeasuresabstractIn cryptography, side channel attacks, such as power analysis, attempt to uncover secret information from the physical implementation of cryptosystems rather than exploiting weaknesses in the cryptographic algorithms themselves. The design and implementation of physically secure cryptosystems is a challenge for both hardware and software designers. Measuring and evaluating the security of a system is manual and empirical, which is costly and time consuming; this work demonstrates that it is possible to automate these processes. We introduce a systematic methodology for automatic application of software countermeasures and demonstrate its effectiveness on an AES software implementation running on an 8-bit AVR microcontroller. The framework identifies the most vulnerable instructions of the implementation to power analysis attacks, and then transforms the software using a chosen countermeasure to protect the vulnerable instructions. Lastly, it evaluates the security of the system using an information-theoretic metric and a direct attack. Ali Galip Bayrak, Francesco Regazzoni 0001, Philip Brisk, François-Xavier Standaert, Paolo Ienne |
DAC | 4 |
| 2011 | A Formal Study of Power Variability Issues and Side-Channel Attacks for Nanoscale Devices
Mathieu Renauld, François-Xavier Standaert, Nicolas Veyrat-Charvillon, Dina Kamel, Denis Flandre |
EUROCRYPT | 2 |
| 2011 | A Formalization of the Security Features of Physical FunctionsabstractPhysical attacks against cryptographic devices typically take advantage of information leakage (e.g., side-channels attacks) or erroneous computations (e.g., fault injection attacks). Preventing or detecting these attacks has become a challenging task in modern cryptographic research. In this context intrinsic physical properties of integrated circuits, such as Physical(ly) Unclonable Functions (PUFs), can be used to complement classical cryptographic constructions, and to enhance the security of cryptographic devices. PUFs have recently been proposed for various applications, including anti-counterfeiting schemes, key generation algorithms, and in the design of block ciphers. However, currently only rudimentary security models for PUFs exist, limiting the confidence in the security claims of PUF-based security primitives. A useful model should at the same time (i) define the security properties of PUFs abstractly and naturally, allowing to design and formally analyze P UF-based security solutions, and (ii) provide practical quantification tools allowing engineers to evaluate PUF instantiations. In this paper, we present a formal foundation for security primitives based on PUFs. Our approach requires as little as possible from the physics and focuses more on the main properties at the heart of most published works on PUFs: robustness (generation of stable answers), unclonability (not provided by algorithmic solutions), and unpredictability. We first formally define these properties and then show that they can be achieved by previously introduced PUF instantiations. We stress that such a consolidating work allows for a meaningful security analysis of security primitives taking advantage of physical properties, becoming increasingly important in the development of the next generation secure information systems. Frederik Armknecht, Roel Maes, Ahmad-Reza Sadeghi, François-Xavier Standaert, Christian Wachsmann |
IEEE Symposium on Security and Privacy | 4 |
| 2011 | One for all - all for one: unifying standard differential power analysis attacksabstractIn this study, the authors examine the relationship between and the efficiency of different approaches to standard (univariate) differential power analysis (DPA) attacks. The authors first show that, when fed with the same assumptions about the target device (i.e. with the same leakage model), the most popular approaches such as using a distance-of-means test, correlation analysis and Bayes attacks are essentially equivalent in this setting. Differences observed in practice are not because of differences in the statistical tests but because of statistical artefacts. Then, the authors establish a link between the correlation coefficient and the conditional entropy in side-channel attacks. In a first-order attack scenario, this relationship allows linking currently used metrics to evaluate standard DPA attacks (such as the number of power traces needed to perform a key recovery) with an information theoretic metric (the mutual information). The authors results show that in the practical scenario defined formally in this study, both measures are equally suitable to compare devices with respect to their susceptibility to DPA attacks. Together with observations regarding key and algorithm independence the authors consequently extend theoretical strategies for the sound evaluation of leaking devices towards the practice of side-channel attacks. Stefan Mangard, Elisabeth Oswald, François-Xavier Standaert |
IET Inf. Secur. | 3 |
| 2011 | Mutual Information Analysis: a Comprehensive Study
Lejla Batina, Benedikt Gierlichs, Emmanuel Prouff, Matthieu Rivain, François-Xavier Standaert, Nicolas Veyrat-Charvillon |
J. Cryptol. | 5 |
| 2010 | Multi-trail Statistical Saturation Attacks
Baudoin Collard, François-Xavier Standaert |
ACNS | 2 |
| 2010 | Adaptive Chosen-Message Side-Channel Attacks
Nicolas Veyrat-Charvillon, François-Xavier Standaert |
ACNS | 2 |
| 2010 | The World Is Not Enough: Another Look on Second-Order DPA
François-Xavier Standaert, Nicolas Veyrat-Charvillon, Elisabeth Oswald, Benedikt Gierlichs, Marcel Medwed, Markus Kasper, Stefan Mangard |
ASIACRYPT | 1 |
| 2010 | Practical leakage-resilient pseudorandom generatorsabstractCryptographic systems and protocols are the core of many Internet security procedures (such as SSL, SSH, IPSEC, DNSSEC, secure mail, etc.). At the heart of all cryptographic functions is a good source of randomness, and for efficiency, the primitive of pseudorandom generator (PRG). PRG can also be used in the design of stream ciphers, for secure communications. The Internet is nowadays composed of many types of devices with very different hardware and software characteristics. Hence, one of the concerns in such open environments is the information "leakage" and its exploitation via the so-called "side channel attacks". Yu Yu 0001, François-Xavier Standaert, Olivier Pereira, Moti Yung |
CCS | 2 |
| 2010 | Randomly driven fuzzy key extraction of unclonable imagesabstractIn this paper, we develop an adjustable Fuzzy Extractor using the Physical Unclonable Functions (PUF) obtained by a common laser engraving method to sign physical objects. In particular, a string (or helper data) is generated by XORing a binary reduction of the PUF observation with the encoding of a randomly generated key, or identifier. Since the binary reduction (or hash) relies on keeping the sign of few random projections of the observation, a measure concentration property bounds, with a controlled accuracy, the distance between two different hashes in function of this of the original images. The error correcting code used to encode the identifier stabilizes therefore both the observation noise and the hashing distortion. In a verification stage, reobserving the PUF with the helper data in hand allows one to authenticate the object if the identifier can be exactly recovered. We conclude this work by calibrating and challenging the system on a database of laser-written PUFs, balancing helper data size, that is, hashing dimensions, and system security. Saloomeh Shariati, Laurent Jacques, François-Xavier Standaert, Benoît Macq, Mohamed Amin Salhi, Philippe Antoine |
ICIP | 3 |
| 2010 | How to strongly link data and its medium: the paper caseabstractEstablishing a strong link between the paper medium and the data represented on it is an interesting alternative to defeat unauthorised copy and content modification attempts. Many applications would benefit from it, such as show tickets, contracts, banknotes or medical prescripts. In this study, the authors present a low-cost solution that establishes such a link by combining digital signatures, physically unclonable functions and fuzzy extractors. The proposed protocol provides two levels of security that can be used according to the time available for verifying the signature and the trust in the paper holder. In practice, this solution uses ultra-violet fibres that are poured into the paper mixture. Fuzzy extractors are then used to build identifiers for each sheet of paper and a digital signature is applied to the combination of these identifiers and the data to be protected from copy and modification. The authors additionally provide a careful statistical analysis of the robustness and amount of randomness reached by the extractors. The authors conclude that identifiers of 72 bits can be derived, which is assumed to be sufficient for the proposed application. However, more randomness, robustness and unclonability could be obtained at the cost of a more expensive process, keeping exactly the same methodology. Philippe Bulens, François-Xavier Standaert, Jean-Jacques Quisquater |
IET Inf. Secur. | 2 |
| 2009 | How to Compare Profiled Side-Channel Attacks?
François-Xavier Standaert, François Koeune, Werner Schindler |
ACNS | 1 |
| 2009 | A Design Flow and Evaluation Framework for DPA-Resistant Instruction Set Extensions
Francesco Regazzoni 0001, Alessandro Cevrero, François-Xavier Standaert, Stéphane Badel, Theo Kluter, Philip Brisk, Yusuf Leblebici, Paolo Ienne |
CHES | 3 |
| 2009 | Algebraic Side-Channel Attacks on the AES: Why Time also Matters in DPA
Mathieu Renauld, François-Xavier Standaert, Nicolas Veyrat-Charvillon |
CHES | 2 |
| 2009 | Mutual Information Analysis: How, When and Why?
Nicolas Veyrat-Charvillon, François-Xavier Standaert |
CHES | 2 |
| 2009 | Algebraic Side-Channel Attacks
Mathieu Renauld, François-Xavier Standaert |
Inscrypt | 2 |
| 2009 | A Statistical Saturation Attack against the Block Cipher PRESENT
Baudoin Collard, François-Xavier Standaert |
CT-RSA | 2 |
| 2009 | A Unified Framework for the Analysis of Side-Channel Key Recovery Attacks
François-Xavier Standaert, Tal Malkin, Moti Yung |
EUROCRYPT | 1 |
| 2009 | Scaling Trends of the AES S-box Low Power Consumption in 130 and 65 nm CMOS Technology NodesabstractIn the recent years, the power consumption of the AES (advanced encryption standard) S-box has been a target for intensive optimization as the power budget of security enhanced RFID (radio frequency identification devices) tags is limited to a few muW. In this paper, 0.13 mum and 65 nm CMOS technology nodes are thoroughly investigated in order to select the most appropriate one in terms of power consumption and computation delay. Schematic simulation results of full custom S-boxes show that the optimum choice in our context is the LP (low power) flavor of the 65 nm node with standard Vt(SVT) devices. This leads to a power consumption below 100 nW at 100 kHz using nominal 1.2 V supply voltage, which is an order of magnitude lower than what was previously published in the open literature. The reported delay is 2.35 ns. Our study then extends the reduction of the power consumption further by reducing the supply voltage. The power consumption at 100 kHz decreases by 60 % as the supply voltage is reduced to 0.8 V. Dina Kamel, François-Xavier Standaert, Denis Flandre |
ISCAS | 2 |
| 2009 | Provable security of block ciphers against linear cryptanalysis: a mission impossible?
Gilles Piret, François-Xavier Standaert |
Des. Codes Cryptogr. | 2 |
| 2008 | A block cipher based pseudo random number generator secure against side-channel key recoveryabstractWe study the security of a block cipher-based pseudorandom number generator (PRNG), both in the black box world and in the physical world, separately. We first show that the construction is a secure PRNG in the ideal cipher model. Then, we demonstrate its security against a Bayesian side-channel key recovery adversary. As a main result, we show that our construction guarantees that the success rate of the adversary does not increase with the number of physical observations, but in a limited and controlled way. Besides, we observe that, under common assumptions on side-channel attack strategies, increasing the security parameter (typically the block cipher key size) by a polynomial factor involves an increase of a side-channel attack complexity by an exponential factor, making the probability of a successful attack negligible. We believe this work provides a first interesting example of the way the algorithmic design of a cryptographic scheme influences its side-channel resistance. Christophe Petit 0001, François-Xavier Standaert, Olivier Pereira, Tal Malkin, Moti Yung |
AsiaCCS | 2 |
| 2008 | Using Subspace-Based Template Attacks to Compare and Combine Power and Electromagnetic Information Leakages
François-Xavier Standaert, Cédric Archambeau |
CHES | 1 |
| 2008 | Experiments on the Multiple Linear Cryptanalysis of Reduced Round Serpent
Baudoin Collard, François-Xavier Standaert, Jean-Jacques Quisquater |
FSE | 2 |
| 2008 | On the Energy Cost of Communication and Cryptography in Wireless Sensor NetworksabstractEnergy is a central concern in the deployment of wireless sensor networks. In this paper, we investigate the energy cost of cryptographic protocols, both from a communication and a computation point of view, based on practical measurements on the MICAz and TelosB sensors. We focus on the cost of two key agreement protocols: Kerberos and the elliptic curve Diffie-Hellman key exchange with authentication provided by the elliptic curve digital signature algorithm (ECDH-ECDSA). We find that, in our context, Kerberos is around one order of magnitude less costly than the ECDH-ECDSA key exchange and confirm that it should be preferred in situations where a trusted third party is available. We also observe that the power dedicated to communications can become a central concern when the nodes need to stay in listen mode, e.g. between the protocol rounds, even when reduced using a low power listening (LPL) protocol. Therefore, listening should be considered when assessing the cost of cryptographic protocols on sensor nodes. Giacomo de Meulenaer, François Gosset, François-Xavier Standaert, Olivier Pereira |
WiMob | 3 |
| 2008 | Security analysis of higher-order Boolean masking schemes for block ciphers (with conditions of perfect masking)abstractSide-channel attacks are an important class of cryptanalytic techniques against cryptographic implementations and masking is a frequently considered solution to improve the resistance of a cryptographic implementation against side-channel attacks. The security of higher-order Boolean masking schemes in various contexts is analysed. The results presented are 2-fold. First, the definitions of higher-order side-channel attacks with the related security notions are formalised and certain security weaknesses in recently proposed masking schemes are put forward. Second, the conditions upon which a substitution box in a block cipher can be perfectly masked by Boolean values in order to counteract side-channel attacks are investigated. That is, can the leakages' statistical distributions at a masked S-box output (over all possible masks) be independent of the secret key targeted in the attacks? The consequences of this requirement are studied in two commonly considered leakage models, namely the Hamming weight and distance models, and conditions on the substitution boxes are derived. As a result of the analysis, it appears that these conditions are not achievable as they lead to evident cryptanalytic weaknesses. Thus, it is formally confirmed that masking cannot be used as a stand-alone countermeasure and cannot offer provable security against side-channel attacks. Gilles Piret, François-Xavier Standaert |
IET Inf. Secur. | 2 |
| 2007 | Information Theoretic Evaluation of Side-Channel Resistant Logic Styles
François Macé, François-Xavier Standaert, Jean-Jacques Quisquater |
CHES | 2 |
| 2007 | Improved and Multiple Linear Cryptanalysis of Reduced Round Serpent
Baudoin Collard, François-Xavier Standaert, Jean-Jacques Quisquater |
Inscrypt | 2 |
| 2007 | Power and electromagnetic analysis: Improved model, consequences and comparisons
Eric Peeters, François-Xavier Standaert, Jean-Jacques Quisquater |
Integr. | 2 |
| 2007 | FPGA implementations of the ICEBERG block cipher
François-Xavier Standaert, Gilles Piret, Gaël Rouvroy, Jean-Jacques Quisquater |
Integr. | 1 |
| 2006 | SEA: A Scalable Encryption Algorithm for Small Embedded Applications
François-Xavier Standaert, Gilles Piret, Neil Gershenfeld, Jean-Jacques Quisquater |
CARDIS | 1 |
| 2006 | Template Attacks in Principal Subspaces
Cédric Archambeau, Eric Peeters, François-Xavier Standaert, Jean-Jacques Quisquater |
CHES | 3 |
| 2006 | Towards Security Limits in Side-Channel Attacks
François-Xavier Standaert, Eric Peeters, Cédric Archambeau, Jean-Jacques Quisquater |
CHES | 1 |
| 2006 | A Comparative Cost/Security Analysis of Fault Attack Countermeasures
Tal Malkin, François-Xavier Standaert, Moti Yung |
FDTC | 2 |
| 2006 | FPGA Implementations of the DES and Triple-DES Masked Against Power Analysis AttacksabstractThis paper presents FPGA implementations of the DES and Triple-DES with improved security against power analysis attacks. The proposed designs use Boolean masking, a previously introduced technique to protect smart card implementations from these attacks. We demonstrate that recent reconfigurable devices offer excellent opportunities to implement a masked DES. In particular, we use the large embedded memories available in the Xilinx Virtex-II proreg FPGAs to store precomputed and masked substitution tables. Compared to an unprotected DES design, our proposal only requires 45% more logic resources and 128 Kbit of memory and yields a throughput of about 1 Gbit/sec François-Xavier Standaert, Gaël Rouvroy, Jean-Jacques Quisquater |
FPL | 1 |
| 2006 | An Overview of Power Analysis Attacks Against Field Programmable Gate ArraysabstractSince their introduction by Kocher in 1998, power analysis attacks have attracted significant attention within the cryptographic community. While early works in the field mainly threatened the security of smart cards and simple processors, several recent publications have shown the vulnerability of hardware implementations as well. In particular, field programmable gate arrays are attractive options for hardware implementation of encryption algorithms,but their security against power analysis is a serious concern, as we discuss in this paper. For this purpose, we present recent results of attacks attempted against standard encryption algorithms, provide a theoretical estimation of these attacks based on simple statistical parameters and evaluate the cost and security of different possible countermeasures. François-Xavier Standaert, Eric Peeters, Gaël Rouvroy, Jean-Jacques Quisquater |
Proc. IEEE | 1 |
| 2005 | Improved Higher-Order Side-Channel Attacks with FPGA Experiments
Eric Peeters, François-Xavier Standaert, Nicolas Donckers, Jean-Jacques Quisquater |
CHES | 2 |
| 2004 | On the Security of the DeKaRT Primitive
Gilles Piret, François-Xavier Standaert, Gaël Rouvroy, Jean-Jacques Quisquater |
CARDIS | 2 |
| 2004 | Power Analysis of an FPGA: Implementation of Rijndael: Is Pipelining a DPA Countermeasure?
François-Xavier Standaert, Siddika Berna Örs Yalçin, Bart Preneel |
CHES | 1 |
| 2004 | Reconfigurable hardware solutions for the digital rights management of digital cinemaabstractThis paper presents a hardware implementation of a decoder for Digital Cinema images. This decoder enables us to deal with image size of 2K with 24 frames per second and 36 bits per pixels. It is the first implementation known nowadays that perfectly fits in one single Virtex-II® FPGA and includes AES decryption, JPEG 2000 decompression and fingerprinting blocks. This hardware offers therefore high-quality image processing as well as robust security. Gaël Rouvroy, François-Xavier Standaert, Frédéric Lefèbvre, Jean-Jacques Quisquater, Benoît Macq, Jean-Didier Legat |
Digital Rights Management Workshop | 2 |
| 2004 | Power Analysis Attacks Against FPGA Implementations of the DES
François-Xavier Standaert, Siddika Berna Örs Yalçin, Jean-Jacques Quisquater, Bart Preneel |
FPL | 1 |
| 2004 | ICEBERG : An Involutional Cipher Efficient for Block Encryption in Reconfigurable Hardware
François-Xavier Standaert, Gilles Piret, Gaël Rouvroy, Jean-Jacques Quisquater, Jean-Didier Legat |
FSE | 1 |
| 2003 | Efficient Implementation of Rijndael Encryption in Reconfigurable Hardware: Improvements and Design Tradeoffs
François-Xavier Standaert, Gaël Rouvroy, Jean-Jacques Quisquater, Jean-Didier Legat |
CHES | 1 |
| 2003 | Design strategies and modified descriptions to optimize cipher FPGA implementations: fast and compact results for DES and triple-DESabstractWe propose a new mathematical DES description that allows optimized implementations. It also provides the best DES and triple-DES FPGA implementations known in term of ratio throughput/area, where area means the number of FPGA slices used. First, we get a less resource consuming unrolled DES implementation that works at data rates of 21.3 Gbps (333 MHz), using VIRTEX II technology. In this design, the plaintext, the key and the mode (encryption/decrytion) can be changed on a cycle-by-cycle basis with no dead cycles. In addition, we also propose sequential DES and triple-DES designs that are currently the most efficient ones in term of resources used as well as in term of throughput. Based on our DES and triple-DES results, we also set up conclusions for optimized FPGA design choices and possible improvement of cipher implementations with a modified structure description. Gaël Rouvroy, François-Xavier Standaert, Jean-Jacques Quisquater, Jean-Didier Legat |
FPGA | 2 |
| 2003 | A methodology to implement block ciphers in reconfigurable hardware and its application to fast and compact AES RIJNDAELabstractReprogrammable devices such as Field Programmable Gate Arrays (FPGA's) are highly attractive options for hardware implementations of encryption algorithms and this report investigates a methodology to efficiently implement block ciphers in CLB-based FPGA's. Our methodology is applied to the new Advanced Encryption Standard RIJNDAEL and the resulting designs offer better performances than previously published in literature. We propose designs that unroll the 10 AES rounds and pipeline them in order to optimize the frequency and throughput results. In addition, we implemented solutions that allow to change the plaintext and the key on a cycle-by-cycle basis with no dead cycles. Another strong focus is placed on low area circuits and we propose sequential designs with very low area requirements. Finally we demonstrate that RAM-based implementations implies different constraints but our methodology still holds. François-Xavier Standaert, Gaël Rouvroy, Jean-Jacques Quisquater, Jean-Didier Legat |
FPGA | 1 |
| 2003 | Design Strategies and Modified Descriptions to Optimize Cipher FPGA Implementations: Fast and Compact Results for DES and Triple-DES
Gaël Rouvroy, François-Xavier Standaert, Jean-Jacques Quisquater, Jean-Didier Legat |
FPL | 2 |
| 2003 | Power Analysis of FPGAs: How Practical is the Attack?
François-Xavier Standaert, Loïc van Oldeneel tot Oldenzeel, David Samyde, Jean-Jacques Quisquater |
FPL | 1 |
| 2003 | Efficient Uses of FPGAs for Implementations of DES and Its Experimental Linear CryptanalysisabstractIn its basic version, linear cryptanalysis is a known-plaintext attack that uses a linear relation between input-bits, output-bits, and key-bits of an encryption algorithm that holds with a certain probability. If enough plaintext-ciphertext pairs are provided, this approximation can be used to assign probabilities to the possible keys and to locate the most probable one. Matsui (1993) applied it to DES, becoming the best known attack against DES. Knudsen (2000) proposed three chosen-plaintext linear attacks, the third one becoming the best chosen-plaintext attack. This paper presents two original FPGA implementations of a DES encryption/decryption core that work at data rates up to 21.3 Gbps (333 MHz). We believe that our implementations are the fastest ones known nowadays. In our design, the plaintext, the key, and the mode (encryption/decryption) can be changed with no dead cycles. Based on one of our fast DES implementations, we present an FPGA implementation of the known-plaintext linear cryptanalysis of DES. The resulting design is deployed on eight FPGAs and allows us to find 12+1 key bits in about 2.3 hours. As a comparison, the fastest software implementation known so far (in 2000) used the idle time of 18 Intel Pentium III MMX and broke a DES key in 4.32 days. Our fast linear cryptanalysis implementation made the performing of practical tests possible, allowing a comparison with Matsui's theoretical estimations. Gaël Rouvroy, François-Xavier Standaert, Jean-Jacques Quisquater, Jean-Didier Legat |
IEEE Trans. Computers | 2 |
| 2002 | A Time-Memory Tradeoff Using Distinguished Points: New Analysis & FPGA Results
François-Xavier Standaert, Gaël Rouvroy, Jean-Jacques Quisquater, Jean-Didier Legat |
CHES | 1 |
| 2002 | An FPGA Implementation of the Linear Cryptanalysis
François Koeune, Gaël Rouvroy, François-Xavier Standaert, Jean-Jacques Quisquater, Jean-Pierre David, Jean-Didier Legat |
FPL | 3 |
| 2002 | A Cryptanalytic Time-Memory Tradeoff: First FPGA Implementation
Jean-Jacques Quisquater, François-Xavier Standaert, Gaël Rouvroy, Jean-Pierre David, Jean-Didier Legat |
FPL | 2 |