VLDB 2026 Research / reviewers in the wild / expert
Jean-Max Dutertre
dblp:91/7973
· DBLP profile ↗
41ranked-venue papers
2as first author
17since 2021 · last 2026
0000-0002-2251-7815ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 27 · 1 first-author · 13 since 2021Software engineering, systems software and programming languages · 15 · 1 first-author · 7 since 2021Security and privacy · 12 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HEED: A Highly Efficient Electromagnetic Fault Detection SchemeabstractElectroMagnetic Fault Injection (EMFI) is a hard-ware attack technique that uses EM perturbations to deliberately induce faults in integrated circuits for attack purposes. In this paper, we propose to use a Digital Sensor (DS) based on a Time-to-Digital Converter (TDC) to detect such EMFI attacks. A TDC uses a delay line to sense variations in a device’s core voltage at the rate of its clock. Thus, it can detect EMFI attacks involving voltage and clock signal perturbations. The sensor output is expressed as a digital index, FN, which captures EMFI-induced delay variations. We evaluated the sensor’s effectiveness on real silicon using an FPGA test vehicle through extensive experiments. The results demonstrate that a single sensor can efficiently detect 100% of faults injected into an AES crypto-accelerator while ensuring wide circuit area coverage, with a highly negligible 1% false alarms rate thanks to the proposed differential fault detection methodology. To ascertain the sensor’s robustness, experiments were conducted under various thermal and noise conditions. Beyond fault detection, the sensor provides insight into the EMFI mechanism. The observed behavior is consistent with a timing constraint violation fault model. Roukoz Nabhan, Mohammad Ebrahimabadi, Jean-Luc Danger, Jean-Max Dutertre, Sylvain Guilley, Naghmeh Karimi, Raphael Viera 0001, Iyad Zaarour |
DATE | 4 |
| 2025 | Multi-Sensor Data Fusion for Enhanced Detection of Laser Fault Injection Attacks in Cryptographic Hardware: Practical ResultsabstractThough considered secure the cryptographic hardware can be compromised by fault injection attack, especially laser illumination due to its precision in targeting specific areas and its fine temporal control. To address this threat, this paper presents a low-cost detection scheme that utilizes Time-to-Digital Converters (TDCs) to sense the IR drops induced by laser illumination. To achieve a high detection rate while minimizing false alarms, the proposed approach incorporates multiple sensors, with as few as two sensors demonstrated in the study. The effectiveness of the scheme is validated using a real laser setup to illuminate a targeted AES module implemented on an AMD/Xilinx Artix-7 FPGA. Mohammad Ebrahimabadi, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi |
DATE | 5 |
| 2024 | EM Fault Injection-Induced Clock Glitches: From Mechanism Analysis to Novel Sensor DesignabstractThis paper introduces a novel sensor that is capable of detecting faults injected by electromagnetic disturbances. The sensor has been designed from an understanding of the physical mechanisms of ElectroMagnetic Fault Injection (EMFI). A recent study has identified an EMFI mechanism based on the timing violation fault model, which highlights the coexistence of two distinct mechanisms: electromagnetic disturbances that are coupled to the target’s power distribution network, which can cause timing faults by extending the propagation time of logic gates beyond the clock period, and disturbances that are coupled to the target’s clock distribution network, which can cause timing constraint violations due to EMFI-induced voltage glitches within the target’s clock tree. Building on this work, we have investigated the mechanism of EMFI-induced clock glitches, providing useful insights for designing a new sensor. The sensor incorporates two dummy clock paths that are maintained in a frozen state within the circuit. Both paths are respectively capable of detecting both positive and negative EMFI-induced glitches along these paths. The proposed sensor offers significant advantages, including full digitization, ease of implementation, low cost in terms of silicon area, low power consumption, and a high fault detection rate. Accurate design and experimental tests were performed on an FPGA board. Validation experiments were supported by spatial and temporal sensitivity maps covering the full-frequency spectrum of the target, which confirmed the effectiveness of the sensor. Roukoz Nabhan, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger, Laurent Sauvage |
IOLTS | 2 |
| 2024 | DELFINES: Detecting Laser Fault Injection Attacks via Digital SensorsabstractLaser Fault Injection Attacks (LFIA) are a major concern in physical security of electronic circuits as they allow an attacker to inject a fault with a very high spatial accuracy. They are also often considered by information technology security evaluation facilities (ITSEFs) to deliver security certification, as Common Criteria, of embedded systems. Time or spatial redundancy can be foreseen as protection methods but they are costly and do not ensure immunity against multiple laser injections. The detection would be efficient if the detecting sensors meet enough density and sensitivity to cover the functional blocks being protected. Most sensors rely on analog and specific technology. In this article, we propose a method to detect LFIAs via a fully digital sensor based on a time to digital converter (TDC) and show its efficacy in detecting such faults in various conditions related to the current induced by the laser, the characteristics of the power grid network (PGN) of the circuit and the environmental variables (voltage, temperature). The simulation results obtained using a 45nm Nangate technology confirms the high efficiency of the proposed scheme in detecting LFIAs in a large range of such conditions. Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2023 | Highlighting Two EM Fault Models While Analyzing a Digital Sensor LimitationsabstractFault injection attacks can be carried out against an operating circuit by exposing it to EM perturbations. These attacks can be detected using embedded digital sensors based on the EM fault injection mechanism, as the one introduced by El Baze et al. [1] which uses the sampling fault model [2], [3]. We tested on an experimental basis the efficiency of this sensor embedded in the AES accelerator of an FPGA. It proved effective when the target was clocked at moderate frequency (the injected faults were consistent with the sampling fault model). As the clock frequency was progressively increased, faults started to escape detection, which raises warnings about possible limitations of the sampling model. Further tests at frequencies close to the target maximal frequency revealed faults injected according to a timing fault model. Both series of experimental results ascertain that EM injection can follow at least two different fault models. Undetected faults and the existence of different fault injection mechanisms cast doubt upon the use of sensors based on a single model. Roukoz Nabhan, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger, Laurent Sauvage |
DATE | 2 |
| 2023 | Security Evaluation of a Hybrid CMOS/MRAM Ascon Hardware ImplementationabstractAs the number of IoT objects is growing fast, power consumption and security become a major concern in the design of integrated circuits. Lightweight Cryptography (LWC) algorithms aim to secure the communications of these connected objects at the lowest energy impact. To reduce the energy footprint of cryptographic primitives, several LWC hardware implementations embedding hybrid CMOS/MRAM-based cells have been investigated. These architectures use the non-volatile characteristic of MRAM to store data manipulated in the algorithm computation. We provide in this work a security evaluation of a hybrid CMOS/MRAM hardware implementation of the ASCON cipher, a finalist of the National Institute of Standards and Technology LWC contest. We focus on a simulation flow using the current EDA tools capable of carrying out power analysis for side-channel attacks, for the purpose of assessing potential weaknesses of MRAM hybridization. Differential Power Analysis (DPA) and Correlation Power Analysis (CPA) are conducted on the postroute and parasitic annoted netlist of the design. The results show that the hybrid implementation does not significantly lower the security feature compared to a reference CMOS implementation. Nathan Roussel, Olivier Potin, Jean-Max Dutertre, Jean-Baptiste Rigaud |
DATE | 3 |
| 2023 | Software-Only Control-Flow Integrity Against Fault Injection AttacksabstractIn this paper, we introduce a new Control-Flow Integrity (CFI) scheme for detecting Fault Injection Attacks (FIA). Our scheme is designed to be as generic as possible and to cover any microcontroller on the market, including non-secure ones. It is a full software approach, designed to detect CFI disruptions caused by FIA. The proposal is portable and designed for a high-level language implementation (C in our case). The main characteristic of our scheme is to link a predictable computed Chain of Trust (CoT) with the assets of a program. This approach classically allows the detection of fault injections leading to an illegitimate path of execution. In addition, this solution is designed to detect when a legitimate execution path is wrongly followed due to FIA. Simulations on several benchmarks finally validate the effectiveness of the method, using a multiple instruction skip faults model. François Bonnal, Vincent Dupaquis, Olivier Potin, Jean-Max Dutertre |
DSD | 4 |
| 2023 | Fault Injection on Embedded Neural Networks: Impact of a Single Instruction SkipabstractWith the large-scale integration and use of neural network models, especially in critical embedded systems, their security assessment to guarantee their reliability is becoming an urgent need. More particularly, models deployed in embed-ded platforms, such as 32-bit microcontrollers, are physically accessible by adversaries and therefore vulnerable to hardware disturbances. We present the first set of experiments on the use of two fault injection means, electromagnetic and laser injections, applied on neural networks models embedded on a Cortex M4 32-bit microcontroller platform. Contrary to most of state-of-the-art works dedicated to the alteration of the internal parameters or input values, our goal is to simulate and experimentally demonstrate the impact of a specific fault model that is instruction skip. For that purpose, we assessed several modification attacks on the control flow of a neural network inference. We reveal integrity threats by targeting several steps in the inference program of typical convolutional neural network models, which may be exploited by an attacker to alter the predictions of the target models with different adversarial goals. Clément Gaine, Pierre-Alain Moëllic, Olivier Potin, Jean-Max Dutertre |
DSD | 4 |
| 2023 | A Tale of Two Models: Discussing the Timing and Sampling EM Fault Injection ModelsabstractInvestigating the dynamics and mechanisms of Electromagnetic Fault Injection (EMFI) attacks, which expose an active circuit to electromagnetic disturbances, presents a persisting challenge due to the diverse and complex fault mechanisms involved. An improved understanding of EMFI modeling is paramount for developing proficient on-chip detection sensors, serving as countermeasures to these attacks. In light of this, our research evaluated the effectiveness of EMFI detection sensors, introduced by Elbaze et al., which rest on the premise that the sampling fault model accounts for EMFI. To assess the functionality of these sensors, we integrated them into an Advanced Encryption Standard (AES) accelerator of a Field-Programmable Gate Array (FPGA) and performed a series of experiments. The resulting evidence suggests that the explanation for EMFI is not a singular fault model but rather, two underlying mechanisms are implicated. At high frequencies, which corresponds to low slack, electromagnetic disturbances, in tandem with the target's Power Distribution Network (PDN), initiated timing constraint violations. This violation subsequently increased the logic propagation times, surpassing the clock period. Contrarily, at low to moderate frequencies, the induced faults generally aligned with the sampling fault model. However, certain deviations from the theoretical framework called into question the model's validity. Upon a deeper examination of the results, we determined that these faults, rather than being sampling faults, were tied to a different mechanism. Electromagnetic disturbances, when coupled with a target's Clock Distribution Network (CDN), can cause timing constraint violations due to EMFI-induced voltage glitches within the target's clock tree. By integrating the mechanisms of EMFI-induced clock glitches and timing faults into the timing violations fault model, we attain a holistic comprehension of EMFI mechanisms. It encapsulates both mechanisms induced by EMFI, spanning the full-frequency spectrum of the target. Roukoz Nabhan, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger, Laurent Sauvage |
FDTC | 2 |
| 2023 | Evaluation of Parameter-Based Attacks Against Embedded Neural Networks with Laser Injection
Mathieu Dumont, Kevin Hector, Pierre-Alain Moëllic, Jean-Max Dutertre, Simon Pontié |
SAFECOMP | 4 |
| 2022 | A CFI Verification System based on the RISC-V Instruction Trace EncoderabstractControl-Flow Integrity (CFI) is used to check a program execution flow and detect whether it is correctly executed and not altered by software or physical attacks. This paper presents a CFI verification system for programs executed on RISC- V cores. Our solution is based on the RISC- V instruction Trace Encoder (TE). The TE provides information about the execution path of the user program. Two approaches are proposed. One is consistent with the RISC- V TE standard. It permits to detect instruction skip attacks on function calls, on their returns and on branch instructions. The second implies an evolution of the RISC- V TE specifications to detect more complex fault models as the corruption of any discontinuity instruction. We implemented both approaches on a RISC-V core and simulated their efficiency against Fault Injection Attacks (FIA). Compared to existing CFI solutions, our methodology does not modify the user application code nor the RISC- V compiler. Anthony Zgheib, Olivier Potin, Jean-Baptiste Rigaud, Jean-Max Dutertre |
DSD | 4 |
| 2022 | An Experimentally Tuned Compact Electrical Model for Laser Fault Injection SimulationabstractThis work reports LFI experiments carried out on custom CMOS 65 nm digital test gates, aiming at tuning the parameters of a compact electrical model. Like in previous works, we observed a difference in behavior in the induced faults when using nanosecond and picosecond range laser pulse duration. However, our experimental results showed that the laser-sensitive areas were restricted to the PMOS transistors for ns laser pulses, contrary to what was previously stated in the literature. For ps pulse duration, these works outline the sensitivity of both the NMOS and PMOS of an SRAM cell following the theoretical model of LFI. These experiments help to calibrate the parameters of a compact electrical model, allowing the simulation of LFI attacks (using SPICE-like CAD tools). This compact model is built upon previous works, with simplifications to facilitate its use. Once tuned, simulations using the proposed compact model exhibit a good correlation with the experimental results. William Souza da Cruz, Raphael Viera 0001, Jean-Baptiste Rigaud, Guillaume Hubert, Jean-Max Dutertre |
IOLTS | 5 |
| 2022 | A Closer Look at Evaluating the Bit-Flip Attack Against Deep Neural NetworksabstractDeep neural network models are massively deployed on a wide variety of hardware platforms. This results in the appearance of new attack vectors that significantly extend the standard attack surface, extensively studied by the adversarial machine learning community. One of the first attack that aims at drastically dropping the performance of a model by targeting its parameters stored in memory, is the Bit-Flip Attack (BFA). In this work, we point out several evaluation challenges related to the BFA. First, the lack of an adversary’s budget in the standard threat model is problematic, especially when dealing with physical attacks. Moreover, since the BFA presents critical variability, we discuss the influence of some training parameters and the importance of the model architecture. This work is the first to present the impact of the BFA against fully-connected architectures that present different behaviors compared to convolutional neural networks. These results highlight the importance of defining robust and sound evaluation methodologies to properly evaluate the dangers of parameter-based attacks as well as measure the real level of robustness offered by a defense. Kevin Hector, Pierre-Alain Moëllic, Mathieu Dumont, Jean-Max Dutertre |
IOLTS | 4 |
| 2021 | Further Analysis of Laser-induced IR-dropabstractStudies on laser induced IR-drop are recent and still not much covered. Since laser-induced IR-drop can amplify the well-known effects of induced photoelectric currents in ICs, this work aims to present important characteristics of such effect. Understanding the characteristics and effects of laser induced IR-drop in ICs allows the elaboration of more accurate simulation models, and consequently helps in the design of countermeasures that mitigate the effects of laser illumination. Simulations and experiments were performed in order to understand the relationship of the laser pulse width and the decoupling capacitance of the power supply network with the induced IR-drop. The results showed that the maximum variation of the supply voltage depends on the laser pulse duration, and on other circuit characteristics, such as RLC parameters of the supply network. It was possible to observe by simulations and experiments that, for the proposed circuit, the maximum variation of the supply voltage occurred for a laser pulse greater than or equal to 1 μs. Regarding the decoupling capacitance variation, the results showed that for a decoupling capacitor up to 100 pF, the IR-drop becomes even more relevant with a variation up to 97% of VDD. William Souza da Cruz, Raphael Viera 0001, Jean-Max Dutertre, Jean-Baptiste Rigaud, Guillaume Hubert |
ATS | 3 |
| 2021 | Analysis of a Laser-induced Instructions Replay Fault Model in a 32-bit MicrocontrollerabstractIn this paper, we present a method to obtain a new Laser Fault Injection (LFI)-induced fault model: replay of instructions on a 32-bit Microcontroller (MCU). This method allows a potential adversary to replay a block of two or four instructions with a fault rate up to 100%. These faults are induced by laser pulses and cause the instructions updating process of a Flash buffer to fail. As a result, the new instructions failing to be stored in the Flash buffer, the previous ones are replayed. We deeply studied the properties of this replay fault model by many experiments of laser fault injections. We have notably shown that the sensitivity window is proportional to the laser Pulse Width (PW), and that up to 20 instructions in a row were tested to be overwritten due to replaying five times the block of four instructions. The effects of the laser power and cache status (enabled or disabled) are also presented. Finally, we proposed and assessed a simple method to detect the LFI-induced replay faults using a hardware counter with different increments. Our results extend the ability of LFI on MCU, illustrating the accuracy and reproducibility of LFI. Vanthanh Khuat, Jean-Max Dutertre, Jean-Luc Danger |
DSD | 2 |
| 2021 | Laser Fault Injection in a 32-bit Microcontroller: from the Flash Interface to the Execution PipelineabstractIn this paper, we report on a method for obtaining faults using Laser Fault Injection (LFI) in a 32-bit Microcontroller (MCU) from the Flash interface to the execution pipeline via the AHB bus. Different fault behaviors were obtained at six positions along the instruction channel. Instruction(s) were observed to be faulted with a reproducibility of 100% at each position. By collecting the faults on all the positions together and analyzing their behaviors, the faults were identified and characterized. The faults on the Flash interface buffer are different depending on the cache operation modes. When the cache is disabled, the fault is related to a block of 32 bits, whereas when the cache is enabled, the fault is related to a block of 64 bits. Two fault models, namely, replay and skip of instructions block were obtained depending on the injection position. The fault happening at the AHB bus is with a block of two instructions in both cache operation modes. Depending on the injection position, two fault models of replay and skip of two instructions were also observed. The faults on the core pipeline are related to a single instruction. The fault behavior is such that both the fetch and execution stages were faulted. The skip of a single instruction was obtained by faulting either the fetch or the execution stage of the core pipeline. By increasing the Pulse Width (PW), tens to more than one hundred of instructions were faulted at each position. The impacts of LFI parameters such as the PW and the power on the faults were studied. In addition, we compared skip fault models achieved at different positions. Our results illustrate the spatial and temporal accuracy of the LFI, thus pointing out the vulnerable positions and unveiling information of the device architecture. Vanthanh Khuat, Jean-Luc Danger, Jean-Max Dutertre |
FDTC | 3 |
| 2021 | Luring Transferable Adversarial Perturbations for Deep Neural NetworksabstractThe growing interest for adversarial examples, i.e. maliciously modified examples which fool a classifier, has resulted in many defenses intended to detect them, render them inoffensive or make the model more robust against them. In this paper, we pave the way towards a new approach to improve the robustness of a model against black-box transfer attacks. A removable additional neural network is included in the target model, and is designed to induce the luring effect, which tricks the adversary into choosing false directions to fool the target model. Training the additional model is achieved thanks to a loss function acting on the logits sequence order. Our deception-based method only needs to have access to the predictions of the target model and does not require a labeled data set. We explain the luring effect thanks to the notion of robust and non-robust useful features and perform experiments on MNIST, SVHN and CIFAR10 to characterize and evaluate this phenomenon. Additionally, we scale the luring effect to ImageNet, experiment practical use of it and discuss its complementarity with other defense schemes. Rémi Bernhard, Pierre-Alain Moëllic, Jean-Max Dutertre |
IJCNN | 3 |
| 2020 | Single-bit Laser Fault Model in NOR Flash Memories: Analysis and ExploitationabstractLaser injection is a powerful fault injection technique with a high spatial accuracy which allows an adversary to efficiently extract the secret information from an electronic device. The control and the repeatability of faults requires the attacker to understand the relation of the fault model to the setup (notably the laser spot size) and the process node of the target device. Most studies on laser fault injection report fault models resulting from a photo-electric current in CMOS transistors. This study provides a black-box analysis of the effect of a photo-electric current in floating-gate transistors of two embedded NOR Flash memories from two different manufacturers. Experimental results demonstrate that single-bit bit-set faults can be injected in code and data without corrupting the Flash memory, even with a laser spot of more than 20 μm in diameter, which is several orders of magnitude larger than the process node of the floating-gate transistors in the experiments. This article also presents the specifics of performing a "safe-error" attack on AES, leveraging the previously detailed single-bit bit-set fault model. Alexandre Menu, Jean-Max Dutertre, Jean-Baptiste Rigaud, Brice Colombier, Pierre-Alain Moëllic, Jean-Luc Danger |
FDTC | 2 |
| 2020 | Simulation and Experimental Demonstration of the Importance of IR-Drops During Laser Fault InjectionabstractLaser fault injections induce transient faults into ICs by locally generating transient currents that temporarily flip the outputs of the illuminated gates. Laser fault injection can be anticipated or studied by using simulation tools at different abstraction levels: physical, electrical, or logical. At the electrical level, the classical laser fault injection model is based on the addition of current sources to the various sensitive nodes of CMOS transistors. However, this model does not take into account the large transient current components also induced between the VDD and GND of ICs designed with advanced CMOS technologies. These short-circuit currents provoke a significant IR-drop that contribute to the fault injection process. This paper describes our research on the assessment of this contribution. It shows through simulation and experiments that during laser fault injection campaigns, laser-induced IR-drop is always present when considering circuits designed with deep submicron technologies. It introduces an enhanced electrical fault model taking the laser-induced IR-drop into account. It also proposes a methodology that allows the use of the model to simulate laser-induced faults at the electrical level in large-scale circuits. On the basis of further simulations and experimental results, we found that, depending on the laser pulse characteristics, the number of injected faults may be underestimated by a factor of up to 2.4 if the laser-induced IR-drop is ignored. This could lead to incorrect estimations of the fault injection threshold, which is especially relevant to the design of countermeasure techniques for secure integrated systems. Raphael Viera 0001, Philippe Maurine, Jean-Max Dutertre, Rodrigo Possamai Bastos |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2019 | Remote Side-Channel Attacks on Heterogeneous SoC
Joseph Gravellier, Jean-Max Dutertre, Yannick Teglia, Philippe Loubet-Moundi, Francis Olivier |
CARDIS | 2 |
| 2019 | Impact of Low-Bitwidth Quantization on the Adversarial Robustness for Embedded Neural NetworksabstractAs the will to deploy neural network models on embedded systems grows, and considering the related memory footprint and energy consumption requirements, finding lighter solutions to store neural networks such as parameter quantization and more efficient inference methods becomes major research topics. Parallel to that, adversarial machine learning has risen recently, unveiling some critical flaws of machine learning models, especially neural networks. In particular, perturbed inputs called adversarial examples have been shown to fool a model into making incorrect predictions. In this paper, we investigate the adversarial robustness of quantized neural networks under different attacks. We show that quantization is not a robust protection when considering advanced threats and may result in severe form of gradient masking which leads to a false impression of security. However, and interestingly, we experimentally observe poor transferability capacities between full-precision and quantized models and between models with different quantization levels which we explain by the quantization value shift phenomenon and gradient misalignment. Rémi Bernhard, Pierre-Alain Moëllic, Jean-Max Dutertre |
CW | 3 |
| 2019 | Precise Spatio-Temporal Electromagnetic Fault Injections on Data TransfersabstractFault injection techniques allow an attacker to alter the behavior of an electronic device in order to extract confidential information or be granted unauthorized privileges. To this end, local electromagnetic fault injections (EMFI) are commonly used to corrupt or prevent the execution of instructions. However, little attention is devoted to practical data corruption. This article investigates the local effects of EMFI on data transfer from the Flash memory to the 128-bit data buffer of a cortex-M microcontroller. We demonstrate that the corrupted bits are closely related to the location of the injection probe, allowing us to set or reset from 0 to 128 bits with a byte-level precision. Moreover, the spatial and temporal accuracy of the injection technique allowed us to target the data prefetch mechanism without corrupting the code execution. We highlight the efficiency of the derived fault model with three practical case studies. Firstly, we demonstrate precise key-zeroing and key-setting capability, with further extension to a DFA on the secret key of a cipher from Biham and Shamir, that was never implemented practically. Next, we report practical persistent faults on ARM microcontroller, which allows an attacker to retrieve the secret key of a cipher with a single successful injection. Alexandre Menu, Shivam Bhasin, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger |
FDTC | 3 |
| 2019 | Dual Detection of Heating and Photocurrent attacks (DDHP) Sensor using Hybrid CMOS/STT-MRAMabstractIntegrated Circuits (ICs) have to be protected against threatening environmental radiations and malicious perturbations. A large panel of countermeasures has been developed to answer the needs of this challenging field. The Bulk Built-In Current Sensor (BBICS) is a highly reliable solution for the detection of these abnormal transient radiations that could induce a transient current in the Front-End of Line (FEoL). This paper proposes an innovative sensor based on the BBICS associated to the power-efficient emerging non-volatile memory Spin Transfer Torque Magnetic Random Access Memory (STTMRAM). The goal of this security solution is to detect both possible photoelectrical laser injections and thermal perturbations. Thus, the proposed architecture designated by Dual Detection of Heating and Photocurrent attacks (DDHP) highlights a dual detection efficiency, on the CMOS circuitry and on the Back-End of Line (BEoL) STT-MRAM technology. Mounia Kharbouche-Harrari, Romain Wacquez, Gregory di Pendina, Jean-Max Dutertre, Jérémy Postel-Pellerin, Driss Aboulkassimi, Jean-Michel Portal |
IOLTS | 4 |
| 2018 | Laser Fault Injection at the CMOS 28 nm Technology Node: an Analysis of the Fault ModelabstractS. Skorobogatov and R. Anderson identified laser illumination as an effective technique to conduct fault attacks in 2002. In these early days of laser-induced fault injection, it was proven to be possible to inject single-bit faults into integrated circuits. This corresponds to the more restrictive fault model found in the fault attack bibliography. The target area under laser illumination (a few micrometers, down to ~1 µm) broadly matched that of a single transistor. It was consistent with a single-bit fault model. However, since then the technology of secure devices has evolved. In current circuits even the smallest laser spots may illuminate several logic cells. This raises the question of the validity of the single-bit fault model: does it still hold? In this work, we report an assessment of its validity through experimental results obtained from circuits designed at the 28 nm CMOS technology node. We also describe the main properties of the corresponding fault model obtained from both static and dynamic experiments. Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Stephan De Castro, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre |
FDTC | 1 |
| 2018 | The case of using CMOS FD-SOI rather than CMOS bulk to harden ICs against laser attacksabstractAt first used to emulate the effects of radioactive ionizing particules passing through integrated circuits (ICs), laser illumination is also used to inject faults into the computations of secure ICs for the purpose of retrieving secret data. The CMOS FD-SOI technology is expected to be less sensitive to laser faults injection than the more usual CMOS bulk technology. We report in this work an experimental assessment of the interest of using FD-SOI rather than CMOS bulk to decrease laser sensitivity. Our experiments were conducted on test chips at the 28nm node for both technologies with laser pulse durations in the picosecond and nanosecond ranges. Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre |
IOLTS | 1 |
| 2018 | Standard CAD Tool-Based Method for Simulation of Laser-Induced Faults in Large-Scale CircuitsabstractDesigning secure integrated systems requires methods and tools dedicated to simulating that early design stages' the effects of laser-induced transient faults maliciously injected by attackers. Existing methods for simulation of laser-induced transient faults do not take into account IR drop effects that are able to cause timing failures, abnormal reset, and SRAM flipping. This paper proposes a novel standard CAD tool-based method allowing to simulate laser-induced faults in large-scale circuits. Thanks to a power-grid network modeled by a commercial IR drop CAD tool, an additional transient current component causing laser-induced IR drop is taken into consideration. This current component flows from Vdd to Gnd and may have a significant effect on the fault injection process. The method provides fault sensitivity maps that enable a quick assessment of laser-induced fault effects on the circuit under analysis. As shown in the results, the number of induced faults is underestimated by a factor as large as 3.1 if laser-induced IR drop is ignored. This may lead to incorrect estimations of the fault injection threshold, which is especially relevant for the design of countermeasure techniques for secure integrated systems. Simulation times regarding four different circuits are also presented in the results section. Raphael Viera 0001, Jean-Max Dutertre, Philippe Maurine, Rodrigo Possamai Bastos |
ISPD | 2 |
| 2017 | Role of Laser-Induced IR Drops in the Occurrence of Faults: Assessment and SimulationabstractLaser fault injection attacks induce transient faults into ICs by locally generating transient currents capable of temporarily flipping the outputs of logic gates. Laser fault injection may be anticipated or studied by using simulation tools at different abstraction levels: physical, electrical or logical. At the electrical level, the general laser-fault injection model is based on the addition of current sources to the various sensitive nodes of CMOS transistors. This type of electrical model does not take into account the large transient current components also induced between VDD and GND as a result of laser illumination. Such current components have no direct effect on the logic gate output nodes. Still, they provoke a significant IR-drop that may, in turn, contribute to the fault injection process. This paper describes our research on the assessment of this contribution. It introduces an upgraded electrical model taking the laser-induced IR-drop into account. It also proposes a methodology that allows the model's use to simulate laser-induced faults at electrical level in large-scale circuits. On the basis of simulations with a case-study circuit, we found that, depending on the parameters of the laser pulse, the number of injected faults may be underestimated by a factor as large as 48 if the laser-induced IR-drop is ignored. This may lead to incorrect estimations of the fault injection threshold, which is especially relevant for the design of countermeasure techniques for secure integrated systems. Raphael Viera 0001, Jean-Max Dutertre, Rodrigo Possamai Bastos, Philippe Maurine |
DSD | 2 |
| 2016 | On the use of Forward Body Biasing to decrease the repeatability of laser-induced faults
Marc Lacruche, Noemie Beringuier-Boher, Jean-Max Dutertre, Jean-Baptiste Rigaud, Edith Kussener |
DATE | 3 |
| 2016 | Frontside Versus Backside Laser Injection: A Comparative StudyabstractThe development of cryptographic devices was followed by the development of so-called implementation attacks, which are intended to retrieve secret information exploiting the hardware itself. Among these attacks, fault attacks can be used to disturb the circuit while performing a computation to retrieve the secret. Among possible means of injecting a fault, laser beams have proven to be accurate and powerful. The laser can be used to illuminate the circuit either from its frontside (i.e., where metal interconnections are first encountered) or from the backside (i.e., through the substrate). Historically, frontside injection was preferred because it does not require the die to be thinned. Nevertheless, due to the increasing integration of metal layers in modern technologies, frontside injections do not allow targeting of any desired location. Indeed, metal lines act as mirrors, and they reflect and refract most of the energy provided by the laser beam. Conversely, backside injections, although more difficult to set up, allow an increase of the resolution of the target location and remove the drawbacks of the frontside technique. This article compares experimental results from frontside and backside fault injections. The effectiveness of the two techniques is measured in terms of exploitable errors on an AES circuit (i.e., errors that can be used to extract the value of the secret key used during the encryption process). We will show, conversely to what is generally assumed, that frontside injection can provide even better results compared to backside injection, especially for low-cost beams with a large laser spot. Stephan De Castro, Jean-Max Dutertre, Bruno Rouzeyre, Giorgio Di Natale, Marie-Lise Flottes |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2015 | Experimental validation of a Bulk Built-In Current Sensor for detecting laser-induced currentsabstractBulk Built-In Current Sensors (BBICS) were developed to detect the transient bulk currents induced in the bulk of integrated circuits when hit by ionizing particles or pulsed laser. This paper reports the experimental evaluation of a complete BBICS architecture, designed to simultaneously monitor PMOS and NMOS transistors, under Photoelectric Laser Stimulation (PLS). The obtained results are the first experimental proof of the efficiency of BBICS in laser fault injection detection attempts. Furthermore, this paper highlights the importance of BBICS tapping in a sensitive area (logical gates) for improved laser detection. It studies the performances of this BBICS architecture and suggests modifications for its future implementation. Clement Champeix, Nicolas Borrel, Jean-Max Dutertre, Bruno Robisson, Mathieu Lisart, Alexandre Sarafianos |
IOLTS | 3 |
| 2015 | Laser fault injection into SRAM cells: Picosecond versus nanosecond pulsesabstractLaser fault injection into SRAM cells is a widely used technique to perform fault attacks. In previous works, Roscian and Sarafianos studied the relations between the layout of the cell, its different laser-sensitive areas and their associated fault model using 50 ns duration laser pulses. In this paper, we report similar experiments carried out using shorter laser pulses (30 ps duration instead of 50 ns). Laser-sensitive areas that did not appear at 50 ns were observed. Additionally, these experiments confirmed the validity of the bit-set/bit-reset fault model over the bit-flip one. We also propose an upgrade of the simulation model they used to take into account laser pulses in the picosecond range. Finally, we performed additional laser fault injection experiments on the RAM memory of a microcontroller to validate the previous results. Marc Lacruche, Nicolas Borrel, Clement Champeix, Cyril Roscian, Alexandre Sarafianos, Jean-Baptiste Rigaud, Jean-Max Dutertre, Edith Kussener |
IOLTS | 7 |
| 2014 | Evidence of a Larger EM-Induced Fault Model
Sébastien Ordas, Ludovic Guillaume-Sage, Karim Tobich, Jean-Max Dutertre, Philippe Maurine |
CARDIS | 4 |
| 2014 | Efficiency of a glitch detector against electromagnetic fault injectionabstractThe use of electromagnetic glitches has recently emerged as an effective fault injection technique for the purpose of conducting physical attacks against integrated circuits. First research works have shown that electromagnetic faults are induced by timing constraint violations and that they are also located in the vicinity of the injection probe. This paper reports the study of the efficiency of a glitch detector against EM injection. This detector was originally designed to detect any attempt of inducing timing violations by means of clock or power glitches. Because electromagnetic disturbances are more local than global, the use of a single detector proved to be inefficient. Our subsequent investigation of the use of several detectors to obtain a full fault detection coverage is reported, it also provides further insights into the properties of electromagnetic injection and into the key role played by the injection probe. Loïc Zussa, Amine Dehbaoui, Karim Tobich, Jean-Max Dutertre, Philippe Maurine, Ludovic Guillaume-Sage, Jessy Clédière, Assia Tria |
DATE | 4 |
| 2014 | Laser-induced fault effects in security-dedicated circuitsabstractLasers have become one of the most efficient means to attack secure integrated systems. Actual faults or errors induced in the system depend on many parameters, including the circuit technology and the laser characteristics. Understanding the physical effects is mandatory to correctly evaluate during the design flow the potential consequences of a laser-based attack and implement efficient counter-measures. This paper presents results obtained within the LIESSE project, aiming at defining a comprehensive approach for designers. Outcomes include the definition of fault/error models at several levels of abstraction, specific CAD tools using these models and new counter-measures well-suited to thwart laser-based attacks. Actual measures on components manufactured in the new 28 nm FDSOI technology are also presented. Régis Leveugle, Paolo Maistri, Pierre Vanhauwaert, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Guillaume Hubert, Stephan De Castro, Jean-Max Dutertre, Alexandre Sarafianos, Noemie Beringuier-Boher, Mathieu Lisart, Joel Damiens, Philippe Candelier, Clément Tavernier |
VLSI-SoC | 13 |
| 2014 | Electromagnetic analysis and fault injection onto secure circuitsabstractImplementation attacks are a major threat to hardware cryptographic implementations. These attacks exploit the correlation existing between the computed data and variables such as computation time, consumed power, and electromagnetic (EM) emissions. Recently, the EM channel has been proven as an effective passive and active attack technique against secure implementations. In this paper, we resume the recent results obtained on this subject, with a particular focus on EM as a fault injection tool. Paolo Maistri, Régis Leveugle, Lilian Bossuet, Alain Aubert, Viktor Fischer, Bruno Robisson, Nicolas Moro, Philippe Maurine, Jean-Max Dutertre, Mathieu Lisart |
VLSI-SoC | 9 |
| 2013 | Fault Model Analysis of Laser-Induced Faults in SRAM Memory CellsabstractThe use of a laser to inject faults into SRAM memory cells is well known. However, the corresponding fault model is often unknown or misunderstood: the induced faults may be described as bit-flip or bit-set/reset faults. We have investigated in this paper whether the bit-set/reset fault model or bit-flip fault model may be encountered in SRAMs. First, the fault model of a standalone SRAM was considered. Experiments revealed that the relevant fault model was the bit-set/reset. This result was further investigated through electrical simulations based on the use of an electrical model of MOS transistors under laser illumination. Then, fault injections have been performed on the RAM memory of a micro-controller to check the validity of the previous results based on experiments and simulations. Cyril Roscian, Alexandre Sarafianos, Jean-Max Dutertre, Assia Tria |
FDTC | 3 |
| 2013 | Power supply glitch induced faults on FPGA: An in-depth analysis of the injection mechanismabstractSecure circuits are prone to a wide range of physical attacks. Among those are fault attacks based on modifying the circuit environment in order to change its behaviour or to induce faults into its computations. There are many common means used to inject such faults: laser shots, electromagnetic pulses, overclocking, chip underpowering, temperature increase, etc. In this paper we study the effect of negative power supply glitches on a FPGA. The obtained faults were compared to faults injected by clock glitches. As a result, both power and clock glitch induced faults were found to be identical. Because clock glitches are related to timing constraint violations, we shall consider that both power and clock glitches share this common fault injection mechanism. We also further studied the properties of this fault injection means. Loïc Zussa, Jean-Max Dutertre, Jessy Clédière, Assia Tria |
IOLTS | 2 |
| 2012 | Electromagnetic Transient Faults Injection on a Hardware and a Software Implementations of AESabstractThis paper considers the use of electromagnetic pulses (EMP) to inject transient faults into the calculations of a hardware and a software AES. A pulse generator and a 500 um-diameter magnetic coil were used to inject the localized EMP disturbances without any physical contact with the target. EMP injections were performed against a software AES running on a CPU, and a hardware AES (with and without countermeasure) embedded in a FPGA. The purpose of this work was twofold: (a) reporting actual faults injection induced by EMPs in our targets and describing their main properties, (b) explaining the coupling mechanism between the antenna used to produce the EMP and the targeted circuit, which causes the faults. The obtained results revealed a localized effect of the EMP since the injected faults were found dependent on the spatial position of the antenna on top of the circuit's surface. The assumption that EMP faults are related to the violation of the target's timing constraints was also studied and ascertained thanks to the use of a countermeasure based on monitoring such timing violations. Amine Dehbaoui, Jean-Max Dutertre, Bruno Robisson, Assia Tria |
FDTC | 2 |
| 2012 | A DFA on AES Based on the Entropy of Error DistributionsabstractDifferential fault analysis (DFA) techniques have been widely studied during the past decade. To our best knowledge, most DFA techniques on the Advanced Encryption Standard (AES) either impose strong constraints on the fault injection process or require numerous faults in order to recover the secret key. This article presents a simple methodology based on information theory which allows to adapt the number of required faults for the analysis to the fault injection process. With this technique, the constraints on the fault model to recover the last round key are considerably lowered. Additionally, entropy is proposed as a tool to apprehend the most complex fault models in DFA. A practical realization and simulations are presented to illustrate our methodology. Ronan Lashermes, Guillaume Reymond, Jean-Max Dutertre, Jacques J. A. Fournier, Bruno Robisson, Assia Tria |
FDTC | 3 |
| 2010 | When Clocks Fail: On Critical Paths and Clock Faults
Michel Agoyan, Jean-Max Dutertre, David Naccache, Bruno Robisson, Assia Tria |
CARDIS | 2 |
| 2010 | How to flip a bit?abstractThis note describes laser fault experiments on an 8-bit 0.35μm microcontroller with no countermeasures. We show that reproducible single-bit faults, often considered unfeasible, can be obtained by careful beam-size and shot-instant tuning. Michel Agoyan, Jean-Max Dutertre, Amir-Pasha Mirbaha, David Naccache, Anne-Lise Ribotta, Assia Tria |
IOLTS | 2 |