Guillaume Barbu

dblp:56/7975 · DBLP profile ↗
← Back
12ranked-venue papers
11as first author
3since 2021 · last 2023
0000-0001-9740-8966ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 11 first-author · 3 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2023 All Shall FA-LLL: Breaking CT-RSA 2022 and CHES 2022 Infective Countermeasures with Lattice-Based Fault Attacks
Guillaume Barbu, Christophe Giraud 0001
CT-RSA1
2022 FA-LLLing for RSA: Lattice-based Fault Attacks against RSA Encryption and Signature
abstract
At CT-RSA 2022, it was shown that combining the power of lattice reduction algorithms with that of fault injection allows not only to carve new attack paths, as previously known, but also to pave existing ones, so to speak. Indeed, using faulty results to build an instance of the Hidden Number Problem, and eventually solving it, can allow an attacker to consider less restrictive fault models than before. In this article, we introduce two new fault attacks on both RSA encryption and signature using this approach. Our lattice-based attack can require as few as 2 faulty ciphertexts and signatures respectively to reveal the hidden secrets with a 32-bit random fault model. At the other end of the fault model spectrum, our attack is still successful considering a very permissive fault model where the attacker can randomly alter up to 98% of the targeted value.
Guillaume Barbu
FDTC1
2021 A High-Order Infective Countermeasure Framework
abstract
Either based on voltage, LASER or electro-magnetic disturbances, fault attacks represent an ever growing threat to cryptographic implementations, all the more when multiple-fault scenarios are considered. The state-of-the-art of fault countermeasures is essentially divided into two paradigms: Detection-based and infection-based countermeasures. The simple concept of detection-based countermeasures has been proven efficient to counteract fault attacks and easily extendable to handle high-order fault models. On the other hand, the design of infective countermeasures is much more challenging since most proposals have been broken in a single-fault setting. In this paper we present a new infective countermeasure framework fit for any symmetric cryptosystem. This framework takes into account the fatal flaws of previous infective proposals. Our framework can be instantiated in various flavours depending on the context of use and the available software or hardware components. In addition, we describe how our framework can be set-up to handle high-order fault attacks. As far as we know, this is the first time an infective countermeasure proposes such a feature.
Guillaume Barbu, Luk Bettale, Laurent Castelnovi, Thomas Chabrier, Nicolas Debande, Christophe Giraud 0001, Nathan Reboud
FDTC1
2019 Toward a Hardware Man-in-the-Middle Attack on PCIe Bus for Smart Data Replay
abstract
The growing need for speed of recent embedded systems leads to the adoption of the high speed communication PCIe protocol (Peripheral Component Interconnect Express) as an internal data bus. This technology is used in some recent smartphones, and will be probably adopted by the others in the next few years. The communication between the SoC and its memory through the PCIe bus represent an important source of information for criminal investigations. In this paper, we present a new reliable attack vector on PCIe. We chose to perform a hardware Man-in-the-Middle attack, allowing real-time data analysis, data-replay and a copy technique inspired by the shadow-copy principle. Through this attack, we will be able to locate, duplicate and replay sensitive data. The main challenge of this article is to develop an architecture compliant with PCIe protocol constraints such as response time, frequency and throughput, in order to be invisible to the communication parts. We designed a proof of concept of an emulator based on a computer with PCIe 3.0 bus and a Stratix 5 FPGA with an endpoint PCIe port as development target.
Mohamed Amine Khelif, Jordane Lorandel, Olivier Romain, Matthieu Regnery, Denis Baheux, Guillaume Barbu
DSD6
2016 Analysis of a Code-Based Countermeasure Against Side-Channel and Fault Attacks
Guillaume Barbu, Alberto Battistello
WISTP1
2014 New Countermeasures against Fault and Software Type Confusion Attacks on Java Cards
Guillaume Barbu, Christophe Giraud 0001
WISTP1
2012 Dynamic Fault Injection Countermeasure - A New Conception of Java Card Security
Guillaume Barbu, Philippe Andouard, Christophe Giraud 0001
CARDIS1
2012 Embedded Eavesdropping on Java Card
Guillaume Barbu, Christophe Giraud 0001, Vincent Guerin
SEC1
2012 Tampering with Java Card Exceptions - The Exception Proves the Rule
Guillaume Barbu, Philippe Hoogvorst, Guillaume Duc
SECRYPT1
2011 Java Card Operand Stack: Fault Attacks, Combined Attacks and Countermeasures
Guillaume Barbu, Guillaume Duc, Philippe Hoogvorst
CARDIS1
2011 Synchronized Attacks on Multithreaded Systems - Application to Java Card 3.0 -
Guillaume Barbu, Hugues Thiebeauld
CARDIS1
2010 Attacks on Java Card 3.0 Combining Fault and Logical Attacks
Guillaume Barbu, Hugues Thiebeauld, Vincent Guerin
CARDIS1