Paolo Maistri

dblp:02/6402 · DBLP profile ↗
← Back
53ranked-venue papers
9as first author
23since 2021 · last 2026
0000-0001-9949-9929ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 47 · 8 first-author · 22 since 2021Software engineering, systems software and programming languages · 16 · 4 first-author · 7 since 2021Security and privacy · 6 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Future Result Capture: Timing Anomalies Reveal Data from Instructions in the Successor
abstract
Fault injection remains a critical threat to modern embedded processors, enabling adversaries to violate the expected execution of programs. In this paper, we introduce a new fault model, named Future Result Capture (FRC), observed on a commercial processor implementing the RISC-V instruction set architecture. Unlike classical models, FRC occurs when an instruction captures the result of a subsequent instruction, effectively creating a temporal inversion in the pipeline. Through extensive clock and voltage glitch experiments on a SiFive RISC-V core, we show that this phenomenon can be consistently triggered, producing instruction-level causality violations not explained by existing models. This new fault behavior exposes unexplored vulnerabilities in commercial processors, demonstrating that subtle microarchitectural effects can be exploited by physical attacks. Our findings highlight the necessity to revisit current fault models by taking into account a thorough understanding of the microarchitectural features of microprocessors, in order to design efficient countermeasures specifically addressing such vulnerabilities.
Roua Boulifa, Marwa Chehab, Paolo Maistri, Giorgio Di Natale
DATE3
2026 Pulsed Electromagnetic Fault Injection on Ro-Based True Random Number Generators in FPGAs
abstract
Ring oscillators (ROs) are widely used in on-chip sensors and security primitives due to their simplicity, scalability, and sensitivity to process variations. In true random number generators (TRNGs), ROs serve as an entropy source by exploiting jitter originating mainly from physical noises and other stochastic phenomena, enabling low-cost generation of unpredictable random numbers for cryptographic applications. Ensuring the robustness of such designs against fault injection attacks is therefore critical. In this paper, we introduce a novel attack scenario in which pulsed ElectroMagnetic Fault Injection (EMFI) degrades the randomness quality of RO-based TRNGs by exploiting their susceptibility to harmonic locking. Experimental results on FPGA demonstrate that carefully tuning EMFI parameters can deterministically reduce entropy, significantly impairing the statistical quality of the generated bits and calling into question the RO-TRNG robustness when deployed in adversarial environments.
Sami El Amraoui, Mahdi Allaw, Florian Pebay-Peyroula, Régis Leveugle, Paolo Maistri
DDECS5
2026 Thermal Attack on RO-PUFs: The Cases of Bulk 65 nm and FDSOI 28 nm
abstract
Physical Unclonable Functions (PUFs) play a crucial role in enhancing the security of electronic devices by leveraging inherent manufacturing variations to generate unique and unclonable identifiers. This study explores the vulnerability of Ring Oscillator-based PUFs (RO-PUFs) to thermal attacks, focusing on two semiconductor technologies: Bulk 65 nm and Fully Depleted Silicon on Insulator (FDSOI) in 28 nm. Through detailed simulations, the effects of uniform and localized thermal variations on the stability of ring oscillator frequencies are analyzed. The results reveal that while the Bulk 65 nm technology shows resistance to uniform thermal attacks, it is highly sensitive to localized attacks. In contrast, the FDSOI 28 nm technology is vulnerable to both types of attacks due to its low variability. These observations underscore the need for robust countermeasures in the design of PUFs to ensure their reliability under varying thermal conditions.
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale
ACM Trans. Design Autom. Electr. Syst.3
2025 Veritas-PUF: A Countermeasure against X-Ray Tampering and Side Channel Attacks
abstract
This paper presents Veritas-PUF, a novel solution based on Physical Unclonable Functions to counter non-invasive physical tampering attacks. This includes localized X-Ray irradiation techniques that can alter circuit behavior without modifying data, directly impacting side-channel leakages. These emerging threats pose significant challenges for secure circuits. To address such attacks, we propose leveraging a ring oscillator PUF to generate a unique identifier sensitive to ionizing radiations. The inherent entropy generated by the device’s physical properties ensures that any alterations will be reflected in the PUF response, providing a robust detection mechanism against these types of attacks. Our experimental results show that with only three reliable challenge-response pairs, we achieve over 95% detection rate for X-ray tampering.
Nasr-Eddine Ouldei Tebina, Luc Salvo, Marc Xander Makkes, Nacer-Eddine Zergainoh, Paolo Maistri
ATS5
2025 Pulsed ElectroMagnetic Fault Injection Attack on a Time Measurement-based Arbiter-PUF
abstract
Physically Unclonable Functions (PUFs) have emerged as a promising hardware-based solution that leverages inherent process variations during IC manufacturing for secure key generation and device authentication, by generating unique and irreproducible challenge-response pairs (CRPs). Among various PUF designs, arbiter PUFs are particularly attractive due to their simplicity, scalability, and compatibility with lightweight cryptographic systems. However, their resistance to fault injection attacks remains an underexplored area. In this work, we investigate the impact of pulsed ElectroMagnetic (EM) fault injection (FI) on a novel Time Measurement-based Arbiter-PUF (TMAPUF) implemented on an FPGA. Experimental results reveal that a single precisely tuned EM pulse can consistently alter the PUF’s output, exposing a critical security weakness. This finding highlight the need for improved fault resilience in PUF architectures and suggest that the studied PUF variant could serve as a foundation for developing inherent countermeasures against EMFI and similar fault-based attacks.
Azzadine Thajte, Sami El Amraoui, Paolo Maistri, Régis Leveugle, Giorgio Di Natale, Laurent Fesquet
DSD3
2025 Pulsed Electromagnetic Fault Injection Attack on Ring Oscillator-based PUFs in FPGAs
Sami El Amraoui, Aghiles Douadi, Régis Leveugle, Paolo Maistri
ETS4
2025 Early Result Capture: Racing Conditions in Pipeline due to Clock Glitches
Roua Boulifa, Paolo Maistri, Giorgio Di Natale
ETS2
2025 Reliability Under Stress: The Impact of Localized Aging on RO-PUF Architectures in FPGAs
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale
ETS3
2025 European Test Symposium Teams: an Anniversary Snapshot
abstract
The IEEE European Test Symposium (ETS) has been facilitating progress in electronic systems testing since its launch in 1996. On the occasion of its 30th anniversary, this collaborative paper gathers sections by 21 ETS teams to outline their influential ideas and milestones. Each team’s section highlights historical perspective, current research, frameworks and projects as well as forward-looking research agendas in the area of electronic-based circuits and systems testing, reliability, safety, security and validation. This anniversary summary documents how research of various ETS teams, exemplifying the test community, has been evolving and transitioning from concepts to practical standards and Electronic Design Automation (EDA) tools and flows. This legacy is a strong base to drive the next generation of advances in electronic systems testing.
Maksim Jenihhin, Jaan Raik, Artur Jutman, Natalia Cherezova, Raimund Ubar, Liviu Miclea, Szilárd Enyedi, Iulia Stefan, Ovidiu Stan, Cosmina Corches, Zebo Peng, Petru Eles, Rolf Drechsler, S. Eggersglüß, Görschwin Fey, Andreas Glowatz, Daniel Tille, Georges Gielen, Anthony Coyette, Wim Dobbelaere, Ronny Vanhooren, Po-Yao Chuang, Erik Jan Marinissen, Giorgio Di Natale, M. Barragan, Paolo Maistri, S. Mir, Vatajelu I. Vatajelu, Paolo Bernardi 0002, Stefano Di Carlo, Paolo Prinetto, Matteo Sonza Reorda, Massimo Violante, Haralampos-G. D. Stratigopoulos, M. K. Michael, Stelios Neophytou, Stavros Hadjitheophanous, Kyriakos Christou, M. Skitsas, Alberto Bosio, Bastien Deveautour, Patrick Girard 0001, Marcello Traiola, Arnaud Virazel, Fernando Santos 0001, Angeliki Kritikakou, Gioele Casagranda, Marzio Vallero, Flavio Vella, Paolo Rech, Letícia Maria Veiras Bolzani, Milos Krstic, Marko S. Andjelkovic, Fabian Vargas 0001, Grigor Tshagharyan, Gurgen Harutunyan, Valery A. Vardanian, Samvel K. Shoukourian, Yervant Zorian, Jennifer Dworak, Kundan Nepal, Theodore W. Manikas, Mottaqiallah Taouil, Moritz Fieback, Anteneh Gebregiorgis, Rajendra Bishnoi, Said Hamdioui, Abhijit Chatterjee, Anurup Saha, Suhasini Komarraju, K. Ma, Chandramouli N. Amarnath, Mehdi Baradaran Tahoori, Mahta Mayahinia, Maryam Rajabalipanah, Katayoon Basharkhah, N. Nosrati, Zahra Jahanpeima, Zainalabedin Navabi, Hans-Joachim Wunderlich, Sybille Hellebrand
ETS26
2025 Real-Time Fault Analysis in RISC-V Processors: A Case Study Using the Internal State Monitor
abstract
Embedded systems are widely used in critical applications, making them attractive targets for fault injection attacks. Understanding how these attacks affect microprocessors at the microarchitectural level is essential for assessing their impact and developing effective defenses. In this paper, we present a case study using the Internal State Monitor (ISM) to finely observe and analyze fault injection effects in real time. By capturing faulty microarchitectural signals during an attack, the ISM provides valuable insights into fault propagation and system behavior under adversarial conditions. This real-time observability allows for a more precise characterization of fault effects, aiding in the design of robust countermeasures to enhance processor security.
Roua Boulifa, Yongxin Sun, Giorgio Di Natale, Paolo Maistri
IOLTS4
2025 On the Harmonic Locking of Ring Oscillators under Single ElectroMagnetic Pulsed Fault Injection in FPGAs
Sami El Amraoui, Aghiles Douadi, Régis Leveugle, Paolo Maistri
J. Electron. Test.4
2024 Enhancing Side-Channel Attacks Through X-Ray-Induced Leakage Amplification
abstract
In this paper, we propose a novel approach that utilizes localized X-ray irradiation to amplify data-dependent leakage currents in CMOS-based cryptography circuits. Our proposed technique strategically targets specific regions in a circuit using X-rays, inducing variations in dynamic and static power consumption due to Total Ionizing Dose (TID) effects, which increases or even reveals hidden data leakage. In this work, we present several experimental campaigns highlighting the benefits of our approach to combinational and sequential logic. Our experiments show a significant increase in information leakage in the targeted regions, which improves the signal-to-noise ratio coefficient and thus makes recovering the processed bytes easier. We envision the possibility of using this technique on full cryptographic designs on both FPGA and ASICs.
Nasr-Eddine Ouldei Tebina, Luc Salvo, Laurent Maingault, Nacer-Eddine Zergainoh, Guillaume Hubert, Paolo Maistri
DATE6
2024 Choose your Path: Control of Ring Oscillators EMFI Susceptibility through FPGA P&R Constraints
abstract
Ring Oscillators (ROs) are widely used in various electronic systems, contributing to their functionality, security, and reliability. Therefore, the characterization of the robustness of RO-based designs against fault attacks such as ElectroMagnetic Fault Injection (EMFI) is a real concern. In this paper, we study the impact of electromagnetic (EM) pulses on ROs implemented in FPGAs. We show that the induced harmonic response depends on the placement and routing of the inverters for different parameters of the pulse. Such a characterization can help developing RO-based structures optimized either for better robustness against attacks or on the opposite for higher sensitivity in order to implement on-chip detectors.
Sami El Amraoui, Régis Leveugle, Paolo Maistri
DDECS3
2024 Modeling Thermal Effects For Biasing PUFs
abstract
Security primitives such as Physical Unclonable Functions (PUFs) or True Random Number Generators (TRNGs), have emerged as hardware roots of trust for ensuring the security of modern applications. However, these primitives display susceptibility to physical attacks, among them, in the face of temperature variations. Previous research has established the feasibility of attacks exploiting temperature fluctuations to compromise the security of these primitives. Specifically, when implemented on FPGAs, programmable components can be vulnerable to alterations induced by thermal changes. These findings underscore the need to deepen the understanding of the implications of temperature sensitivity on the security and robustness of these security mechanisms. This paper studies how heat affects, both instantaneously and permanently, the working of ring oscillators, which are the building blocks of PUFs based on Ring Oscillators. The study also suggests how to exploit these effects to bias the PUf responses, enabling thus the possibility of its cloning.
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale
ETS3
2024 Capture the Pulse: Impact of FPGA Resource Utilization on EM Fault Injection Attacks Detection
abstract
With the increasing use of Field-Programmable Gate Arrays (FPGAs) in critical applications, safeguarding against malicious attacks becomes necessary. ElectroMagnetic Fault Injection (EMFI) stands out as a potent threat among localized fault attacks with its optimal compromise between cost and effectiveness, without the risk of damaging the target chip. Among potential targets, Ring Oscillators (ROs) are critical components that can be used in secure primitives, as well as detectors against physical attacks. In this paper, we analyze how the use of FPGA resources affects the outcome of EMFI attacks: we experimentally show with single EM pulse injections on three families of Xilinx FPGAs manufactured in 28nm process technology that the harmonic response of a RO heavily depends on its layout and density within the FPGA die. We also highlight the need of considering both EM pulse polarities when evaluating the efficiency of any proposed countermeasures, as this can reveal different sensitive locations on the chip. These findings can be leveraged for designing architectures that address the EMFI threat more effectively.
Sami El Amraoui, Régis Leveugle, Paolo Maistri
VLSI-SoC3
2023 Microarchitectural Insights into Unexplained Behaviors Under Clock Glitch Fault Injection
Ihab Alshaer, Brice Colombier, Christophe Deleuze, Vincent Beroulle, Paolo Maistri
CARDIS5
2023 A Study of High Temperature Effects on Ring Oscillator Based Physical Unclonable Functions
abstract
PUFs (Physical Unclonable Functions) have been proposed as a cost-effective solution to provide a root of trust for electronic devices which exploit intrinsic process variability. They generate identification signatures and keys only when the devices are turned on, avoiding the storage of sensitive information in memories that could be targeted by attacks. Although PUFs have many perceived advantages, they also have disadvantages such as sensitivity to temperature. Indeed their behaviour can be affected by the fact that high temperatures can accelerate permanent and transient phenomena, such as aging and transistor switching speed. In this paper we show the effects of externally induced heat on the functioning of Ring Oscillators (ROs), which form the basis of RO-PUFs. Moreover, we discuss the feasibility of temperature attacks on PUFs.
Aghiles Douadi, Giorgio Di Natale, Paolo Maistri, Elena I. Vatajelu, Vincent Beroulle
IOLTS3
2023 Experimental Evaluation of Delayed-Based Detectors Against Power-off Attack
abstract
Embedded systems are vulnerable to significant security threats from Fault Injection Attacks (FIAs), which allow attackers to gain access to confidential information. While various attack detectors have been proposed in the literature to detect different types of FIAs, these detectors themselves are susceptible to such attacks and can be compromised. Hence, the robustness of these detectors is critical in maintaining the security of embedded systems. The focus of this study is to evaluate the robustness of digital circuits and delay-based digital detectors against a new type of FIA called Power-Off Attack (POA). POA occurs when the power to the chip is turned off, and the detectors are not active. Following a POA attack, the circuit or its detectors may not function properly when the power is turned back on, which can allow other attacks to be applied without being detected if the detectors are less sensitive. This study implements two detectors on Xilinx Artix-7 FPGAs and examines the impact of heating cycles on detector characteristics when the FPGA is in various states, including power-off, power-on, and inactive states (such as clock-freezing mode). Our experiments reveal that heating cycles in power-off mode can alter the FPGA component delays and the accuracy of its detectors, which highlights the vulnerability of these systems to POA and potential issues for embedded system security.
Maryam Esmaeilian, Aghiles Douadi, Zahra Kazemi, Vincent Beroulle, Amir-Pasha Mirbaha, Mahdi Fazeli, Elena I. Vatajelu, Paolo Maistri, Giorgio Di Natale
IOLTS8
2023 Ray-Spect: Local Parametric Degradation for Secure Designs: An application to X-Ray Fault Injection
abstract
International audience
Nasr-Eddine Ouldei Tebina, Laurent Maingault, Nacer-Eddine Zergainoh, Guillaume Hubert, Paolo Maistri
IOLTS5
2022 A Low-Cost Methodology for EM Fault Emulation on FPGA
abstract
In embedded systems, the presence of a security layer is now a well-established requirement. In order to guarantee the suitable level of performance and resistance against attacks, dedicated hardware implementations are often proposed to accelerate cryptographic computations in a controllable environment. On the other hand, these same implementations may be vulnerable to physical attacks, such as side channel analysis or fault injections. In this scenario, the designer must hence be able to assess the robustness of the implementation (and of the adopted countermeasures) as soon as possible in the design flow against several different threats. In this paper, we propose a methodology to characterize the robustness of a generic hardware design described at RTL against EM fault injections. Thanks to our framework, we are able to emulate the EM faults on FPGA platforms, without the need of expensive equipment or lengthy experimental campaigns. We present a tool supporting our methodology and the first validations tests done on several AES designs confirming the feasibility of the proposed approach.
Paolo Maistri, Jiayun Po
DATE1
2022 Variable-Length Instruction Set: Feature or Bug?
abstract
With the increasing complexity of digital applications, the use of variable-length instruction sets became essential, in order to achieve higher code density and thus better performance. However, security aspects must always be considered, in particular with the significant improvement of attack techniques and equipment. Fault injection, in particular, is among the most interesting and promising attack techniques thanks to the recent advancements. In this article, we provide proper characterization, at the instruction set architecture (ISA) level, for several faulty behaviors that can be obtained when targeting a variable-length instruction set. We take into account the binary encoding of instructions, and show how the obtained behaviors depend on the alignment of the instructions in the memory. Moreover, we are also able to give a better insight on previous results from the literature, that were still partially unexplained. We also show how the observed behaviors can be exploited in various security contexts.
Ihab Alshaer, Brice Colombier, Christophe Deleuze, Vincent Beroulle, Paolo Maistri
DSD5
2022 Electromagnetic Leakage Assessment of a Proven Higher-Order Masking of AES S-Box
abstract
Many digital systems need to provide cryptographic capabilities. A large part of these devices is easily accessible by the malicious user, and may be vulnerable to side channel attacks such as power or electromagnetic analysis. From one side, the designer has to protect the architecture with proven countermeasures; on the other, the actual implementation must be validated in order to prove the absence of undesired leakages. In this paper, we present an implementation of two optimized and proven masking schemes of order 3 and 7 for an embedded software AES, and prove its robustness by showing the absence of significant leakage in the nonlinear layer.
Nicolas Bordes, Paolo Maistri
DSD2
2021 Security EDA Extension through P1687.1 and 1687 Callbacks
abstract
In recent years, the world of VLSI testing has been living a huge transformation pushed by constraints and requirements coming from a large variety of sources and applications. The traditional need for higher accessibility and controllability led to solutions such as IEEE 1687, while the need for reuse is pushing for innovations like P1687.1. All the while, these same features are raising security concerns for malicious attacks or reverse engineering. Standards usual approach of relying on Domain-Specific Languages to convey information to the EDA tools has difficulty in handling such disparate and often conflicting needs, with the risk of dangerous proliferation of custom and incompatible solutions. In this paper, we show how the usage of Callbacks, defined in P1687.1, can help solve this issue.
Michele Portolan, Vincent Reynaud, Paolo Maistri, Régis Leveugle, Giorgio Di Natale
ITC3
2020 Dynamic Authentication-Based Secure Access to Test Infrastructure
abstract
The complexity of modern Systems-on-Chips is steadily increasing, which poses hard challenges for testing. In order to be able to face those challenges, several standards have been proposed through history, such as the latest IEEE 1687 on Reconfigurable Scan Networks (RSNs), which allows dynamic configuration of the test infrastructure for an easier access to embedded instruments and data. This ease of access, however, may constitute a serious threat from the point of view of security, as it may be used by an attacker as an entry point to the internal state of the circuit, especially if the test infrastructure is reused for life-time testing. Some approaches exist to protect the access, but their performances and security levels are limited by the legacy view of test as a static process. In this paper, we propose an innovative solution that exploits the dynamic nature of the IEEE 1687 standard to obtain an Authentication-based Secure Access framework able to provide a trusted and personalized interface to the test infrastructure depending on user-defined security levels.
Michele Portolan, Vincent Reynaud, Paolo Maistri, Régis Leveugle
ETS3
2020 A Comprehensive End-to-end Solution for a Secure and Dynamic Mixed-signal 1687 System
abstract
The disruptive potential of the IEEE 1687 standard does not come from a single innovation, but rather from its capacity of providing a unified framework where heterogeneous approaches can co-exist and interact. In this Special Session, we will present the complementary research activities performed in the TIMA laboratory covering different aspects of the standard (Mixed-Signal instrument testing, Embedded Aging Monitors and Test Access Securization), and their coordination thanks to the Manager-for SoC Test (MAST) software environment.
Michele Portolan, R. Silveira Feitoza, Ghislain Takam Tchendjou, Vincent Reynaud, Kalpana Senthamarai Kannan, Manuel J. Barragan Asian, Emmanuel Simeu, Paolo Maistri, Lorena Anghel, Régis Leveugle, Salvador Mir
IOLTS8
2018 Laser Fault Injection at the CMOS 28 nm Technology Node: an Analysis of the Fault Model
abstract
S. Skorobogatov and R. Anderson identified laser illumination as an effective technique to conduct fault attacks in 2002. In these early days of laser-induced fault injection, it was proven to be possible to inject single-bit faults into integrated circuits. This corresponds to the more restrictive fault model found in the fault attack bibliography. The target area under laser illumination (a few micrometers, down to ~1 µm) broadly matched that of a single transistor. It was consistent with a single-bit fault model. However, since then the technology of secure devices has evolved. In current circuits even the smallest laser spots may illuminate several logic cells. This raises the question of the validity of the single-bit fault model: does it still hold? In this work, we report an assessment of its validity through experimental results obtained from circuits designed at the 28 nm CMOS technology node. We also describe the main properties of the corresponding fault model obtained from both static and dynamic experiments.
Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Stephan De Castro, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre
FDTC10
2018 The case of using CMOS FD-SOI rather than CMOS bulk to harden ICs against laser attacks
abstract
At first used to emulate the effects of radioactive ionizing particules passing through integrated circuits (ICs), laser illumination is also used to inject faults into the computations of secure ICs for the purpose of retrieving secret data. The CMOS FD-SOI technology is expected to be less sensitive to laser faults injection than the more usual CMOS bulk technology. We report in this work an experimental assessment of the interest of using FD-SOI rather than CMOS bulk to decrease laser sensitivity. Our experiments were conducted on test chips at the 28nm node for both technologies with laser pulse durations in the picosecond and nanosecond ranges.
Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre
IOLTS9
2017 HLS design of a hardware accelerator for Homomorphic Encryption
abstract
Modular polynomial multiplication is the most computationally intensive operation in many homomorphic encryption schemes. In order to accelerate homomorphic computations, we propose a software/hardware (SW/HW) co-designed accelerator integrating fast software algorithms with a configurable hardware polynomial multiplier. The hardware accelerator is implemented through a High-Level Synthesis (HLS) flow. We show that our approach is highly flexible, since the same generic high-level description can be configured and re-used to generate a new design with different parameters and very large sizes in negligible time. We show that flexibility does not preclude efficiency: the proposed solution is competitive in comparison with hand-made designs and can provide good performance at low cost.
Asma Mkhinini, Paolo Maistri, Régis Leveugle, Rached Tourki
DDECS2
2016 On the development of a new countermeasure based on a laser attack RTL fault model
Charalampos Ananiadis, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle
DATE5
2016 HLS-Based Methodology for Fast Iterative Development Applied to Elliptic Curve Arithmetic
abstract
High-Level Synthesis (HLS) is used by hardware developers to achieve higher abstraction in circuit descriptions. In order to shorten the hardware development time via HLS, we present an adjustment of the Iterative and Incremental Design (IID) methodology, frequently used in software development. In particular, our methodology is relevant for the development of applications with unusual complexity: the method was applied here to the development of large modular arithmetic, commonly used for cryptography applications (e.g., Elliptic Curves). Rapid feedback on circuit characteristics is used to evaluate deep architectural changes in short time, greatly reducing the time-to-market with respect to hand-made designs. In addition, our approach is highly flexible, since the same generic high-level description can be used to produce an entire set of circuits, each with different area/performance trade-offs. Thanks to the proposed approach, any change to the initial specification (e.g., the curve used) is also very fast, while it may require a large effort in the case of hand-made designs.
Simon Pontié, Alban Bourge, Adrien Prost-Boucle, Paolo Maistri, Olivier Muller, Régis Leveugle, Frédéric Rousseau 0001
DSD4
2014 Randomized windows for secure scalar multiplication on elliptic curves
abstract
Elliptic curve cryptosystems (ECCs) may be chosen instead of RSA in secure embedded systems, thanks to shorter keys. However, ECC may be vulnerable, as any other cryptographic implementation, to side channel analysis, which may reveal secret information by analyzing collateral sources of information, such as power consumption. To protect the device against Timing, Simple and Differential Power Analysis, we propose the implementation of a new scalar multiplication algorithm based on randomized windows method.
Simon Pontié, Paolo Maistri
ASAP2
2014 A multiple fault injection methodology based on cone partitioning towards RTL modeling of laser attacks
abstract
Laser attacks, especially on circuits manufactured with recent deep submicron semiconductor technologies, pose a threat to secure integrated circuits due to the multiplicity of errors induced by a single attack. An efficient way to neutralize such effects is the design of appropriate countermeasures, according to the circuit implementation and characteristics. Therefore tools which allow the early evaluation of security implementations are necessary. Our efforts involve the development of an RTL fault injection approach more representative of laser attacks than random multi-bit fault injections and the utilization and evolution of state of the art emulation techniques to reduce the duration of the fault injection campaigns. This will ultimately lead to the design and validation of new countermeasures against laser attacks, on ASICs implementing cryptographic algorithms.
Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle
DATE4
2014 An Elliptic Curve Crypto-Processor Secured by Randomized Windows
abstract
Embedded systems are increasingly providing secure functionalities, which often rely on some dedicated hardware for symmetric and public-key cryptography. When resources are limited, elliptic curve cryptography (ECC) may be chosen instead of the more widely known RSA, which needs much longer keys for the same security level. However, ECC may be vulnerable, as any other cryptographic implementation, to side channel analysis, which may reveal secret information by analyzing collateral sources of information, such as power consumption. Countermeasures must be thus adopted at the design level, in order to ensure robust and secure operation of the device. We propose here a new scalar multiplication algorithm on an elliptic curve, based on a novel randomized window method. This design is protected against side channel attacks (Timing, Simple and Differential Power Analysis) and it is implemented over prime fields, but it can be applied to binary fields as well. In order to evaluate this countermeasure, we provide its costs, and an estimation of the additional entropy added to the computation against side channels attacks.
Simon Pontié, Paolo Maistri, Régis Leveugle
DSD2
2014 Laser-induced fault effects in security-dedicated circuits
abstract
Lasers have become one of the most efficient means to attack secure integrated systems. Actual faults or errors induced in the system depend on many parameters, including the circuit technology and the laser characteristics. Understanding the physical effects is mandatory to correctly evaluate during the design flow the potential consequences of a laser-based attack and implement efficient counter-measures. This paper presents results obtained within the LIESSE project, aiming at defining a comprehensive approach for designers. Outcomes include the definition of fault/error models at several levels of abstraction, specific CAD tools using these models and new counter-measures well-suited to thwart laser-based attacks. Actual measures on components manufactured in the new 28 nm FDSOI technology are also presented.
Régis Leveugle, Paolo Maistri, Pierre Vanhauwaert, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Guillaume Hubert, Stephan De Castro, Jean-Max Dutertre, Alexandre Sarafianos, Noemie Beringuier-Boher, Mathieu Lisart, Joel Damiens, Philippe Candelier, Clément Tavernier
VLSI-SoC2
2014 Electromagnetic analysis and fault injection onto secure circuits
abstract
Implementation attacks are a major threat to hardware cryptographic implementations. These attacks exploit the correlation existing between the computed data and variables such as computation time, consumed power, and electromagnetic (EM) emissions. Recently, the EM channel has been proven as an effective passive and active attack technique against secure implementations. In this paper, we resume the recent results obtained on this subject, with a particular focus on EM as a fault injection tool.
Paolo Maistri, Régis Leveugle, Lilian Bossuet, Alain Aubert, Viktor Fischer, Bruno Robisson, Nicolas Moro, Philippe Maurine, Jean-Max Dutertre, Mathieu Lisart
VLSI-SoC1
2013 An evaluation of an AES implementation protected against EM analysis
abstract
EM emissions can be a rich source of leakage for side-channel analysis of cipher implementations. In this paper, we describe a set of novel countermeasures based on dynamic spatial relocation and dynamic mappings, and validate the protection provided by them against EM attacks. The countermeasures improve significantly the security of the circuit.
Paolo Maistri, Sébastien Tiran, Philippe Maurine, Israel Koren, Régis Leveugle
ACM Great Lakes Symposium on VLSI1
2011 10-Gigabit Throughput and Low Area for a Hardware Implementation of the Advanced Encryption Standard
abstract
Current secure applications often need encrypted channels with high throughput, of the order of several gigabits per second. This level of performance is usually obtained with a considerable cost in terms of silicon area. In this paper, we present an implementation of the Advanced Encryption Standard based on heavy pipelining and partial unrolling, which is capable of a 10-Gbps throughput when encrypting with 128-bit keys.
Paolo Maistri, Régis Leveugle
DSD1
2011 Countermeasures against fault attacks: The good, the bad, and the ugly
abstract
Hardware implementations of cryptographic systems are becoming common, due to new market needs and to reduced costs. However, the security of a system may be seriously compromised by implementation attacks, such as side channel analysis or fault analysis. Thus, a large number of solutions have been proposed to counteract these threats. In this paper, we present most common architectural countermeasures against natural or malicious fault injections, highlighting their strengths, weaknesses, and giving a few nontrivial considerations.
Paolo Maistri
IOLTS1
2011 Glitch and Laser Fault Attacks onto a Secure AES Implementation on a SRAM-Based FPGA
Gaetan Canivet, Paolo Maistri, Régis Leveugle, Jessy Clédière, Florent Valette, Marc Renaudin
J. Cryptol.2
2010 Dependability analysis of a countermeasure against fault attacks by means of laser shots onto a SRAM-based FPGA
abstract
Laser-based fault injections are currently the most efficient technique that can be used to attack a secure system, since they have very high timing and location precision. Several papers have shown that a secret key may be recovered from ASICs and countermeasures have been proposed. But little research has been addressed at the specific case of secure protected implementations in SRAM-based FPGAs. This paper presents the results of laser-based fault injections on an architecture computing the AES encryption algorithm, protected by an error detection scheme, and implemented on a Virtex device. The results are compared to previous emulated fault injection campaigns and prove the criticality of remnant errors in the configuration of a FPGA used for secure applications. An improved countermeasure is also proposed and validated with a new experimental campaign.
Gaetan Canivet, Paolo Maistri, Régis Leveugle, Frédéric Valette, Jessy Clédière, Marc Renaudin
ASAP2
2009 Statistical fault injection: Quantified error and confidence
abstract
Fault injection has become a very classical method to determine the dependability of an integrated system with respect to soft errors. Due to the huge number of possible error configurations in complex circuits, a random selection of a subset of potential errors is usual in practical experiments. The main limitation of such a selection is the confidence in the outcomes that is never quantified in the articles. This paper proposes an approach to quantify both the error on the presented results and the confidence on the presented interval. The computation of the required number of faults to inject in order to achieve a given confidence and error interval is also discussed. Experimental results are shown and fully support the presented approach.
Régis Leveugle, A. Calvez, Paolo Maistri, Pierre Vanhauwaert
DATE3
2009 Towards automated fault pruning with Petri Nets
abstract
Embedded systems design is starting considering dependability issues even for mass-market systems. Soft error consequences must in particular be carefully analyzed. Usually, fault injection campaigns are run to analyze the consequences of transient faults, but the length of a comprehensive evaluation often collides with the severe requirements on design cycle times. We propose a new fault pruning technique to identify harmless components and computation cycles as soon as possible, thus avoiding useless fault injection experiments. The technique is based on a formal model of the system and we show that it can be used for both SEUs and SETs.
Paolo Maistri, Régis Leveugle
IOLTS1
2008 Software Self-Testing of a Symmetric Cipher with Error Detection Capability
abstract
Cryptographic devices are recently implemented with different countermeasures against side channel attacks and fault analysis. Moreover, some usual testing techniques, such as scan chains, are not allowed or restricted for security requirements. In this paper, we analyze the impact that error detecting schemes have on the testability of an implementation of the advanced encryption standard, in particular when software-based self-test techniques are envisioned. We show that protection schemes can improve concurrent error detection, but make initial testing more difficult.
Paolo Maistri, Cyril Excoffon, Régis Leveugle
IOLTS1
2008 Double-Data-Rate Computation as a Countermeasure against Fault Analysis
abstract
Differential Fault Analysis (DFA) is one of the most powerful techniques to attack cryptosystems. Several countermeasures have been proposed, which are based either on information or temporal redundancy. In this work, we propose a novel approach based on a Double-Data-Rate (DDR) computation template. A few sample architectures have been implemented: they are compared to other existing architectures and countermeasures, and a thorough dependability analysis is given.
Paolo Maistri, Régis Leveugle
IEEE Trans. Computers1
2007 A Novel Double-Data-Rate AES Architecture Resistant against Fault Injection
abstract
Several techniques have been proposed for encryption blocks in order to provide protection against faults. These techniques usually exploit some form of redundancy, e.g. by means of error detection codes. However, protection schemes that offer an acceptable error detection rate are in general expensive, while temporal redundancy heavily affects the throughput. In this paper, we propose a new design solution that exploits temporal redundancy by DDR techniques without affecting adversely the throughput at lower clock frequencies. We will also show that the overall costs can be comparable to other solutions recently proposed.
Paolo Maistri, Pierre Vanhauwaert, Régis Leveugle
FDTC1
2007 An Operation-Centered Approach to Fault Detection in Symmetric Cryptography Ciphers
abstract
One of the most effective ways of attacking a cryptographic device is by deliberate fault injection during computation, which allows retrieving the secret key with a small number of attempts. Several attacks on symmetric and public-key cryptosystems have been described in the literature and some dedicated error-detection techniques have been proposed to foil them. The proposed techniques are ad hoc ones and exploit specific properties of the cryptographic algorithms. In this paper, we propose a general framework for error detection in symmetric ciphers based on an operation-centered approach. We first enumerate the arithmetic and logic operations included in the cipher and analyze the efficacy and hardware complexity of several error-detecting codes for each such operation. We then recommend an error-detecting code for the cipher as a whole based on the operations it employs. We also deal with the trade-off between the frequency of checking for errors and the error coverage. We demonstrate our framework on a representative group of 11 symmetric ciphers. Our conclusions are supported by both analytical proofs and extensive simulation experiments
Luca Breveglieri, Israel Koren, Paolo Maistri
IEEE Trans. Computers3
2006 A Fault Attack Against the FOX Cipher Family
Luca Breveglieri, Israel Koren, Paolo Maistri
FDTC3
2006 Incorporating Error Detection in an RSA Architecture
Luca Breveglieri, Israel Koren, Paolo Maistri, M. Ravasio
FDTC3
2006 A Note on Error Detection in an RSA Architecture by Means of Residue Codes
abstract
Recently, various attacks have been proposed against many crypto systems, exploiting deliberate error injection during the computation process. In this paper, we add a residue-based error detection scheme to an RSA architecture to protect against such attacks. We then evaluate the error coverage and the expected area and latency overheads
Luca Breveglieri, Paolo Maistri, Israel Koren
IOLTS2
2004 Detecting Faults in Four Symmetric Key Block Ciphers
Luca Breveglieri, Israel Koren, Paolo Maistri
ASAP3
2003 Concurrent Fault Detection in a Hardware Implementation of the RC5 Encryption Algorithm
abstract
Recent research has shown that fault diagnosis and possibly fault tolerance are important features when implementing cryptographic algorithms by means of hardware devices. In fact, some security attack procedures are based on the injection of faults. At the same time, hardware implementations of cryptographic algorithms, i.e. crypto-processors, are becoming widespread. There is however, only very limited research on implementing fault diagnosis and tolerance in crypto-algorithms. Fault diagnosis is studied for the RC5 crypto-algorithm, a recently proposed block-cipher algorithm that is suited for both software and hardware implementations. RC5 is based on a mix of arithmetic and logic operations, and is therefore a challenge for fault diagnosis. We study fault propagation in RC5, and propose and evaluate the cost/performance tradeoffs of several error detecting codes for RC5. Costs are estimated in terms of hardware overhead, and performances in terms of fault coverage. Our most important conclusion is that, despite its nonuniform nature, RC5 can be efficiently protected by using low-cost error detecting codes.
Guido Bertoni, Luca Breveglieri, Israel Koren, Paolo Maistri, Vincenzo Piuri
ASAP4
2003 Error Analysis and Detection Procedures for a Hardware Implementation of the Advanced Encryption Standard
abstract
The goal of the Advanced Encryption Standard (AES) is to achieve secure communication. The use of AES does not, however, guarantee reliable communication. Prior work has shown that even a single transient error occurring during the AES encryption (or decryption) process will very likely result in a large number of errors in the encrypted/decrypted data. Such faults must be detected before sending to avoid the transmission and use of erroneous data. Concurrent fault detection is important not only to protect the encryption/decryption process from random faults. It will also protect the encryption/decryption circuitry from an attacker who may maliciously inject faults in order to find the encryption secret key. In this paper, we first describe some studies of the effects that faults may have on a hardware implementation of AES by analyzing the propagation of such faults to the outputs. We then present two fault detection schemes: The first is a redundancy-based scheme while the second uses an error detecting code. The latter is a novel scheme which leads to very efficient and high coverage fault detection. Finally, the hardware costs and detection latencies of both schemes are estimated.
Guido Bertoni, Luca Breveglieri, Israel Koren, Paolo Maistri, Vincenzo Piuri
IEEE Trans. Computers4
2002 On the Propagation of Faults and Their Detection in a Hardware Implementation of the Advanced Encryption Standard
abstract
High reliability is a desirable property of any implementation of the Advanced Encryption Standard (AES). To achieve high reliability, all possible faults must be detected to avoid the use and transmission of erroneous encrypted/decrypted data. In this paper we first study the behavior of faults which may occur during the encryption and decryption procedures of AES, and the way such faults eventually propagate to the final result. We then describe an appropriate detection technique for these faults. This work extends our preliminary results (G. Bertoni et al, MPCS 2002) by considering more general fault models (e.g., permanent and multiple transient faults), and the possibility of fault masking.
Guido Bertoni, Luca Breveglieri, Israel Koren, Paolo Maistri, Vincenzo Piuri
ASAP4