Emmanuel Prouff

dblp:62/4866 · DBLP profile ↗
← Back
51ranked-venue papers
8as first author
1since 2021 · last 2021
0000-0002-3998-0478ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 47 · 7 first-authorSystems, architecture and hardware · 3 · 1 first-authorTheory of computation · 2 · 1 since 2021
YearPublicationVenuePosition
2021 Lower and Upper Bounds on the Randomness Complexity of Private Computations of AND
abstract
We consider multiparty information-theoretic private protocols, and specifically their randomness complexity. The randomness complexity of private protocols is of interest both because random bits are considered a scarce resource and because of the relation between that complexity measure and other complexity measures of boolean functions such as the circuit size or the sensitivity of the function being computed [Kushilevitz, Ostrovsky, and Rosén, J. Comput. Syst. Sci., 58 (1999), pp. 129--136] and [Gál and Rosén, SIAM J. Comput., 31 (2002), pp. 1424--1437]. More concretely, we consider the randomness complexity of the basic Boolean function \tt and, that serves as a building block in the design of many private protocols. We show that \tt and cannot be privately computed using a single random bit, thus giving the first nontrivial lower bound on the 1-private randomness complexity of an explicit Boolean function, $f: \{0,1\}^n \rightarrow \{0,1\}$. We further show that and, on any number of inputs $n$ (one input bit per player), can be privately computed using 8 random bits (and 7 random bits in the special case of $n=3$ players), improving the upper bound of 73 random bits implicit in [Kushilevitz, Ostrovsky, and Rosén, J. Comput. Syst. Sci., 58 (1999), pp. 129--136]. Together with our lower bound, we thus approach the exact determination of the randomness complexity of \tt and. To the best of our knowledge, the exact randomness complexity of private computation is not known for any explicit function (except for \tt xor, which is 1-random, and for several degenerate functions).
Eyal Kushilevitz, Rafail Ostrovsky, Emmanuel Prouff, Adi Rosén, Adrian Thillard, Damien Vergnaud
SIAM J. Discret. Math.3
2020 Random Probing Security: Verification, Composition, Expansion and New Constructions
Sonia Belaïd, Jean-Sébastien Coron, Emmanuel Prouff, Matthieu Rivain, Abdul Rahman Taleb
CRYPTO (1)3
2020 Table Recomputation-Based Higher-Order Masking Against Horizontal Attacks
abstract
Masking is a class of well-known countermeasure against side-channel analysis by employing the idea of secret sharing. The theoretical security proof model of higher-order masking was initiated by Ishai, Sahai, and Wagner, and Barthe et al. pushed forward it by proposing a more refine security definition named as t-SNI security. In CHES 2016, a new attack called horizontal side-channel attacks (HSCAs) came forward and successfully broke the Rivain-Prouff countermeasure, which has been proved to satisfy the t-SNI security. It presents a dilemma: instead of more secure, masking with higher-order may be more vulnerable due to the HSCA. Although there already exists an effective countermeasure for the Rivain-Prouff scheme, it is quite difficult to apply this method in the table recomputation-based higher-order masking schemes, such as the scheme introduced by Coron in EUROCRYPT 2014. To fill this gap, we propose a new table recomputation-based higher-order masking scheme, named as table compression masking (TCM) scheme. While meeting the t-SNI security, our new countermeasure is also secure against the HSCA. We give the formal security proof under the t-SNI security definition, as well as a heuristic security analysis considering the HSCA. Our analysis shows that, by dividing the full lookup table into many distinct parts and shifting them by refreshed shares, the same share will never be manipulated for more than twice in TCM scheme. This feature gives a heuristic security against HSCA. To our best knowledge, our countermeasure is the first solution for table recomputation-based higher-order masking to resist HSCA.
Zhipeng Guo 0002, Ming Tang 0002, Emmanuel Prouff, Maixing Luo, Fei Yan 0008
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2019 Lower and Upper Bounds on the Randomness Complexity of Private Computations of AND
Eyal Kushilevitz, Rafail Ostrovsky, Emmanuel Prouff, Adi Rosén, Adrian Thillard, Damien Vergnaud
TCC (2)3
2019 Monomial Evaluation of Polynomial Functions Protected by Threshold Implementations
Simon Landry, Yanis Linge, Emmanuel Prouff
WISTP3
2018 Outsourcing Signatures of Confidential Documents
Hervé Chabanne, Julien Keuffer, Emmanuel Prouff
CRiSIS3
2017 Convolutional Neural Networks with Data Augmentation Against Jitter-Based Countermeasures - Profiling Attacks Without Pre-processing
Eleonora Cagli, Cécile Canovas, Emmanuel Prouff
CHES3
2017 Private Multiplication over Finite Fields
Sonia Belaïd, Fabrice Benhamouda, Alain Passelègue, Emmanuel Prouff, Adrian Thillard, Damien Vergnaud
CRYPTO (3)4
2017 Redefining the transparency order
Kaushik Chakraborty 0001, Sumanta Sarkar, Subhamoy Maitra, Bodhisatwa Mazumdar, Debdeep Mukhopadhyay, Emmanuel Prouff
Des. Codes Cryptogr.6
2017 Stochastic Collision Attack
abstract
On the one hand, collision attacks have been introduced in the context of side-channel analysis for attackers who exploit repeated code with the same data without having any knowledge of the leakage model. On the other hand, stochastic attacks have been introduced to recover leakage models of internally processed intermediate secret variables. Both techniques have shown advantages and intrinsic limitations. Most collision attacks, for instance, fail in exploiting all the leakages (e.g., only a subset of matching samples are analyzed), whereas stochastic attacks cannot involve linear regression with the full basis (while the latter basis is the most informative one). In this paper, we present an innovative attacking approach, which combines the flavors of stochastic and collision attacks. Importantly, our attack is derived from the optimal distinguisher, which maximizes the success rate when the model is known. Notably, we develop an original closed-form expression, which shows many benefits by using the full algebraic description of the leakage model. Using simulated data, we show in the unprotected case that, for low noise, the stochastic collision attack is superior to the state of the art, whereas asymptotically and thus, for higher noise, it becomes equivalent to the correlation-enhanced collision attack. Our so-called stochastic collision attack is extended to the scenario where the implementation is protected by masking. In this case, our new stochastic collision attack is more efficient in all scenarios and, remarkably, tends to the optimal distinguisher. We confirm the practicability of the stochastic collision attack thanks to experiments against a public data set (DPA contest v4). Furthermore, we derive the stochastic collision attack in case of zero-offset leakage that occurs in protected hardware implementations and use simulated data for comparison. Eventually, we underline the capability of the new distinguisher to improve its efficiency when the attack multiplicity increases.
Nicolas Bruneau, Claude Carlet, Sylvain Guilley, Annelie Heuser, Emmanuel Prouff, Olivier Rioul
IEEE Trans. Inf. Forensics Secur.5
2016 Kernel Discriminant Analysis for Information Extraction in the Presence of Masking
Eleonora Cagli, Cécile Canovas, Emmanuel Prouff
CARDIS3
2016 Horizontal Side-Channel Attacks and Countermeasures on the ISW Masking Scheme
Alberto Battistello, Jean-Sébastien Coron, Emmanuel Prouff, Rina Zeitoun
CHES3
2016 Faster Evaluation of SBoxes via Common Shares
Jean-Sébastien Coron, Aurélien Greuet, Emmanuel Prouff, Rina Zeitoun
CHES3
2016 Randomness Complexity of Private Circuits for Multiplication
Sonia Belaïd, Fabrice Benhamouda, Alain Passelègue, Emmanuel Prouff, Adrian Thillard, Damien Vergnaud
EUROCRYPT (2)4
2015 Enhancing Dimensionality Reduction Methods for Side-Channel Attacks
Eleonora Cagli, Cécile Canovas, Emmanuel Prouff
CARDIS3
2015 Improved Side-Channel Analysis of Finite-Field Multiplication
Sonia Belaïd, Jean-Sébastien Coron, Pierre-Alain Fouque, Benoît Gérard, Jean-Gabriel Kammerer, Emmanuel Prouff
CHES6
2015 Algebraic Decomposition for Probing Security
Claude Carlet, Emmanuel Prouff, Matthieu Rivain, Thomas Roche
CRYPTO (1)2
2014 Side-Channel Attack against RSA Key Generation Algorithms
Aurélie Bauer, Éliane Jaulmes, Victor Lomné, Emmanuel Prouff, Thomas Roche
CHES4
2014 How to Estimate the Success Rate of Higher-Order Side-Channel Attacks
Victor Lomné, Emmanuel Prouff, Matthieu Rivain, Thomas Roche, Adrian Thillard
CHES2
2014 On the Practical Security of a Leakage Resilient Masking Scheme
Emmanuel Prouff, Matthieu Rivain, Thomas Roche
CT-RSA1
2014 Side-Channel Analysis of Montgomery's Representation Randomization
Éliane Jaulmes, Emmanuel Prouff, Justine Wild
Selected Areas in Cryptography2
2013 Behind the Scene of Side Channel Attacks
Victor Lomné, Emmanuel Prouff, Thomas Roche
ASIACRYPT (1)2
2013 Low Entropy Masking Schemes, Revisited
Vincent Grosso, François-Xavier Standaert, Emmanuel Prouff
CARDIS3
2013 Success through Confidence: Evaluating the Effectiveness of a Side-Channel Attack
Adrian Thillard, Emmanuel Prouff, Thomas Roche
CHES2
2013 Horizontal and Vertical Side-Channel Attacks against Secure RSA Implementations
Aurélie Bauer, Éliane Jaulmes, Emmanuel Prouff, Justine Wild
CT-RSA3
2013 Masking against Side-Channel Attacks: A Formal Security Proof
Emmanuel Prouff, Matthieu Rivain
EUROCRYPT1
2013 Higher-Order Side Channel Security and Mask Refreshing
Jean-Sébastien Coron, Emmanuel Prouff, Matthieu Rivain, Thomas Roche
FSE2
2013 Horizontal Collision Correlation Attack on Elliptic Curves
Aurélie Bauer, Éliane Jaulmes, Emmanuel Prouff, Justine Wild
Selected Areas in Cryptography3
2013 A New Second-Order Side Channel Attack Based on Linear Regression
abstract
Since the preliminary works of Kocher et al. in the nineties, studying and enforcing the resistance of cryptographic implementations against side channel analysis (SCA) is became a dynamic and prolific area of embedded security. Stochastic attacks, introduced by Schindler et al., form one of the main families of SCA and they offer a valuable alternative to template attacks which are known to be among the most efficient ones. However, stochastic attacks, as long as template attacks, have been initially designed for adversaries with a perfect copy of the target device in hand. Such a prerequisite makes them a pertinent tool when studying the implementations resistance against the most powerful adversaries, but it limits their pertinence as a cryptanalytic technique. Indeed, getting open access to a copy of the device under attack is difficult in practice and, even when possible, it remains difficult to exploit templates acquired on one device to attack another one. In light of this observation, several papers have been published to adapt stochastic attacks for contexts where the above prerequisite is no longer needed. They succeeded in defining practical attacks against unprotected implementations but no work was published until now to explain how stochastic attacks can be applied against secure implementations. In this paper, we deal with this issue. We first extend the previous analyses of stochastic attacks to highlight their core foundations. Then, we explain how they can be generalized to defeat first-order masking techniques, which are the main SCA countermeasures. Eventually, we illustrate the interest of the new attack by a series of experiments on simulated and real curves.
Guillaume Dabosville, Julien Doget, Emmanuel Prouff
IEEE Trans. Computers3
2012 On the Use of Shamir's Secret Sharing against Side-Channel Analysis
Jean-Sébastien Coron, Emmanuel Prouff, Thomas Roche
CARDIS2
2012 A First-Order Leak-Free Masking Countermeasure
Houssem Maghrebi, Emmanuel Prouff, Sylvain Guilley, Jean-Luc Danger
CT-RSA2
2012 Higher-Order Masking Schemes for S-Boxes
Claude Carlet, Louis Goubin, Emmanuel Prouff, Michaël Quisquater, Matthieu Rivain
FSE3
2011 Thwarting Higher-Order Side Channel Analysis with Additive and Multiplicative Maskings
Laurie Genelle, Emmanuel Prouff, Michaël Quisquater
CHES2
2011 Higher-Order Glitches Free Implementation of the AES Using Secure Multi-party Computation Protocols
Emmanuel Prouff, Thomas Roche
CHES1
2011 Mutual Information Analysis: a Comprehensive Study
Lejla Batina, Benedikt Gierlichs, Emmanuel Prouff, Matthieu Rivain, François-Xavier Standaert, Nicolas Veyrat-Charvillon
J. Cryptol.3
2010 Secure Multiplicative Masking of Power Functions
Laurie Genelle, Emmanuel Prouff, Michaël Quisquater
ACNS2
2010 Provably Secure Higher-Order Masking of AES
Matthieu Rivain, Emmanuel Prouff
CHES2
2009 Theoretical and Practical Aspects of Mutual Information Based Side Channel Analysis
Emmanuel Prouff, Matthieu Rivain
ACNS1
2009 First-Order Side-Channel Attacks on the Permutation Tables Countermeasure
Emmanuel Prouff, Robert P. McEvoy
CHES1
2009 Higher-Order Masking and Shuffling for Software Implementations of Block Ciphers
Matthieu Rivain, Emmanuel Prouff, Julien Doget
CHES2
2009 Securing AES Implementation against Fault Attacks
abstract
On smart card environment, speed and memory optimization of cryptographic algorithms are an ongoing preoccupation. In addition, there is the necessity to protect the device against various attacks. In this paper we present a fault attack detection scheme for the AES using digest values. They are deduced from the mathematical description of each AES individual transformation. The security of our countermeasure is proved in a realistic fault model. Moreover we show that it can be combined with data masking to thwart efficiently both FA and DPA. Eventually, implementations of our method are presented, showing that it can be an interesting alternative to the traditional doubling countermeasure method.
Laurie Genelle, Christophe Giraud 0001, Emmanuel Prouff
FDTC3
2009 Statistical Analysis of Second Order Differential Power Analysis
abstract
Second order Differential Power Analysis (2O-DPA) is a powerful side-channel attack that allows an attacker to bypass the widely used masking countermeasure. To thwart 2O-DPA, higher order masking may be employed but it implies a nonnegligible overhead. In this context, there is a need to know how efficient a 2O-DPA can be, in order to evaluate the resistance of an implementation that uses first order masking and, possibly, some hardware countermeasures. Different methods of mounting a practical 2O-DPA attack have been proposed in the literature. However, it is not yet clear which of these methods is the most efficient. In this paper, we give a formal description of the higher order DPA that are mounted against software implementations. We then introduce a framework in which the attack efficiencies may be compared. The attacks we focus on involve the combining of several leakage signals and the computation of correlation coefficients to discriminate the wrong key hypotheses. In the second part of this paper, we pay particular attention to 2O-DPA that involves the product combining or the absolute difference combining. We study them under the assumption that the device leaks the Hamming weight of the processed data together with an independent Gaussian noise. After showing a way to improve the product combining, we argue that in this model, the product combining is more efficient not only than absolute difference combining, but also than all the other combining techniques proposed in the literature.
Emmanuel Prouff, Matthieu Rivain, Régis Bevan
IEEE Trans. Computers1
2008 Secure Implementation of the Stern Authentication and Signature Schemes for Low-Resource Devices
Pierre-Louis Cayrel, Philippe Gaborit, Emmanuel Prouff
CARDIS3
2008 Attack and Improvement of a Secure S-Box Calculation Based on the Fourier Transform
Jean-Sébastien Coron, Christophe Giraud 0001, Emmanuel Prouff, Matthieu Rivain
CHES3
2008 Block Ciphers Implementations Provably Secure Against Second Order Side Channel Analysis
Matthieu Rivain, Emmanuelle Dottax, Emmanuel Prouff
FSE3
2007 Side Channel Cryptanalysis of a Higher Order Masking Scheme
Jean-Sébastien Coron, Emmanuel Prouff, Matthieu Rivain
CHES2
2007 CRT RSA Algorithm Protected Against Fault Attacks
Arnaud Boscher, Robert Naciri, Emmanuel Prouff
WISTP3
2006 Off-Line Group Signatures with Smart Cards
Jean-Bernard Fischer, Emmanuel Prouff
CARDIS2
2006 Provably Secure S-Box Implementation Based on Fourier Transform
Emmanuel Prouff, Christophe Giraud 0001, Sébastien Aumônier
CHES1
2005 DPA Attacks and S-Boxes
Emmanuel Prouff
FSE1
2003 On Plateaued Functions and Their Constructions
Claude Carlet, Emmanuel Prouff
FSE2