Régis Leveugle

dblp:05/2696 · DBLP profile ↗
← Back
73ranked-venue papers
17as first author
9since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 66 · 16 first-author · 9 since 2021Software engineering, systems software and programming languages · 27 · 8 first-author · 1 since 2021Security and privacy · 4Theory of computation · 1
YearPublicationVenuePosition
2026 Pulsed Electromagnetic Fault Injection on Ro-Based True Random Number Generators in FPGAs
abstract
Ring oscillators (ROs) are widely used in on-chip sensors and security primitives due to their simplicity, scalability, and sensitivity to process variations. In true random number generators (TRNGs), ROs serve as an entropy source by exploiting jitter originating mainly from physical noises and other stochastic phenomena, enabling low-cost generation of unpredictable random numbers for cryptographic applications. Ensuring the robustness of such designs against fault injection attacks is therefore critical. In this paper, we introduce a novel attack scenario in which pulsed ElectroMagnetic Fault Injection (EMFI) degrades the randomness quality of RO-based TRNGs by exploiting their susceptibility to harmonic locking. Experimental results on FPGA demonstrate that carefully tuning EMFI parameters can deterministically reduce entropy, significantly impairing the statistical quality of the generated bits and calling into question the RO-TRNG robustness when deployed in adversarial environments.
Sami El Amraoui, Mahdi Allaw, Florian Pebay-Peyroula, Régis Leveugle, Paolo Maistri
DDECS4
2025 Pulsed ElectroMagnetic Fault Injection Attack on a Time Measurement-based Arbiter-PUF
abstract
Physically Unclonable Functions (PUFs) have emerged as a promising hardware-based solution that leverages inherent process variations during IC manufacturing for secure key generation and device authentication, by generating unique and irreproducible challenge-response pairs (CRPs). Among various PUF designs, arbiter PUFs are particularly attractive due to their simplicity, scalability, and compatibility with lightweight cryptographic systems. However, their resistance to fault injection attacks remains an underexplored area. In this work, we investigate the impact of pulsed ElectroMagnetic (EM) fault injection (FI) on a novel Time Measurement-based Arbiter-PUF (TMAPUF) implemented on an FPGA. Experimental results reveal that a single precisely tuned EM pulse can consistently alter the PUF’s output, exposing a critical security weakness. This finding highlight the need for improved fault resilience in PUF architectures and suggest that the studied PUF variant could serve as a foundation for developing inherent countermeasures against EMFI and similar fault-based attacks.
Azzadine Thajte, Sami El Amraoui, Paolo Maistri, Régis Leveugle, Giorgio Di Natale, Laurent Fesquet
DSD4
2025 Pulsed Electromagnetic Fault Injection Attack on Ring Oscillator-based PUFs in FPGAs
Sami El Amraoui, Aghiles Douadi, Régis Leveugle, Paolo Maistri
ETS3
2025 On the Harmonic Locking of Ring Oscillators under Single ElectroMagnetic Pulsed Fault Injection in FPGAs
Sami El Amraoui, Aghiles Douadi, Régis Leveugle, Paolo Maistri
J. Electron. Test.3
2024 Choose your Path: Control of Ring Oscillators EMFI Susceptibility through FPGA P&R Constraints
abstract
Ring Oscillators (ROs) are widely used in various electronic systems, contributing to their functionality, security, and reliability. Therefore, the characterization of the robustness of RO-based designs against fault attacks such as ElectroMagnetic Fault Injection (EMFI) is a real concern. In this paper, we study the impact of electromagnetic (EM) pulses on ROs implemented in FPGAs. We show that the induced harmonic response depends on the placement and routing of the inverters for different parameters of the pulse. Such a characterization can help developing RO-based structures optimized either for better robustness against attacks or on the opposite for higher sensitivity in order to implement on-chip detectors.
Sami El Amraoui, Régis Leveugle, Paolo Maistri
DDECS2
2024 Capture the Pulse: Impact of FPGA Resource Utilization on EM Fault Injection Attacks Detection
abstract
With the increasing use of Field-Programmable Gate Arrays (FPGAs) in critical applications, safeguarding against malicious attacks becomes necessary. ElectroMagnetic Fault Injection (EMFI) stands out as a potent threat among localized fault attacks with its optimal compromise between cost and effectiveness, without the risk of damaging the target chip. Among potential targets, Ring Oscillators (ROs) are critical components that can be used in secure primitives, as well as detectors against physical attacks. In this paper, we analyze how the use of FPGA resources affects the outcome of EMFI attacks: we experimentally show with single EM pulse injections on three families of Xilinx FPGAs manufactured in 28nm process technology that the harmonic response of a RO heavily depends on its layout and density within the FPGA die. We also highlight the need of considering both EM pulse polarities when evaluating the efficiency of any proposed countermeasures, as this can reveal different sensitive locations on the chip. These findings can be leveraged for designing architectures that address the EMFI threat more effectively.
Sami El Amraoui, Régis Leveugle, Paolo Maistri
VLSI-SoC2
2022 Recovering Information on the CVA6 RISC-V CPU with a Baremetal Micro-Architectural Covert Channel
abstract
In this work, we study the micro architectural vulnerabilities of the open-source RISC-V CPU named CVA6. We build a realistic scenario for extracting information and propose an analysis on how to reduce the impact of noise on the attack, while staying as close as possible to hardware level through baremetal simulations.
Valentin Martinoli, Yannick Teglia, Abdellah Bouagoun, Régis Leveugle
IOLTS4
2021 Security EDA Extension through P1687.1 and 1687 Callbacks
abstract
In recent years, the world of VLSI testing has been living a huge transformation pushed by constraints and requirements coming from a large variety of sources and applications. The traditional need for higher accessibility and controllability led to solutions such as IEEE 1687, while the need for reuse is pushing for innovations like P1687.1. All the while, these same features are raising security concerns for malicious attacks or reverse engineering. Standards usual approach of relying on Domain-Specific Languages to convey information to the EDA tools has difficulty in handling such disparate and often conflicting needs, with the risk of dangerous proliferation of custom and incompatible solutions. In this paper, we show how the usage of Callbacks, defined in P1687.1, can help solve this issue.
Michele Portolan, Vincent Reynaud, Paolo Maistri, Régis Leveugle, Giorgio Di Natale
ITC4
2021 Cross-layer Approach to Assess FMEA on Critical Systems and Evaluate High-Level Model Realism
abstract
Embedded systems in critical applications are constrained by very strict standards. The safety of such systems is crucial, however, their safety analysis (e.g., Failure Mode and Effects Analysis, or FMEA) is often empirical and mainly relies on the experience of engineers. Performing empirical analyses on complex designs is a major challenge that leads engineers to make very pessimistic assumptions and consequently to over-design multiple countermeasures. Many fault injection techniques have been developed to evaluate the robustness of hardware designs from Register Transfer Level to Transaction Level. At the RT-level, these techniques are circuit-centered, and therefore do not rely on the overall system specifications. Besides, with complex hardware designs, fault simulations become very time-consuming. Conversely, at the transaction level, fault simulation is fast to the detriment of the realism of high-level models. In this paper, we present a new iterative cross-layer robustness analysis flow taking into account the overall critical system specifications and verifying the realism of high-level models. The first step of the flow leads to extract critical parameter ranges. Then, these ranges are used to quickly evaluate the robustness of each RTL block in the circuit. In the last step, we compute some metrics reflecting the realism of the high-level models. According to these metrics, we can determine if the high-level models must be improved. We apply this methodology to a case study of a real airborne system.
Julie Roux, Katell Morin-Allory, Vincent Beroulle, Régis Leveugle, Lilian Bossuet, Frédéric Cézilly, Frédéric Berthoz, Gilles Genévrier, François Cerisier
VLSI-SoC4
2020 Cross Layer Fault Simulations for Analyzing the Robustness of RTL Designs in Airborne Systems
abstract
Embedded systems in critical applications are constrained by very strict standards. Safety analysis (e.g., Failure Mode and Effect Analysis) of these systems are often empirically done and mainly based on engineer experience. Many fault injection techniques exist to evaluate the robustness of Register Transfer Level (RTL) hardware designs, but, when the designs interact with software components (e.g., micro-controllers) or are embedded in complex systems, fault simulations or emulations can be very time consuming. High level system modeling can speed up the analysis of fault propagation through the whole system but raises some realism issues. In this paper, we propose a cross-layer fault simulation method to perform the robustness evaluation of RTL architectures used in critical embedded systems. This method uses both fault simulation in RTL and Transaction Level Model (TLM) descriptions to make a trade-off between simulation time and the realism of the simulated high level faulty behaviors. Early results on an airborne case study are discussed.
Julie Roux, Vincent Beroulle, Katell Morin-Allory, Régis Leveugle, Lilian Bossuet, Frédéric Cézilly, Frédéric Berthoz, Gilles Genévrier, François Cerisier
DDECS4
2020 Dynamic Authentication-Based Secure Access to Test Infrastructure
abstract
The complexity of modern Systems-on-Chips is steadily increasing, which poses hard challenges for testing. In order to be able to face those challenges, several standards have been proposed through history, such as the latest IEEE 1687 on Reconfigurable Scan Networks (RSNs), which allows dynamic configuration of the test infrastructure for an easier access to embedded instruments and data. This ease of access, however, may constitute a serious threat from the point of view of security, as it may be used by an attacker as an entry point to the internal state of the circuit, especially if the test infrastructure is reused for life-time testing. Some approaches exist to protect the access, but their performances and security levels are limited by the legacy view of test as a static process. In this paper, we propose an innovative solution that exploits the dynamic nature of the IEEE 1687 standard to obtain an Authentication-based Secure Access framework able to provide a trusted and personalized interface to the test infrastructure depending on user-defined security levels.
Michele Portolan, Vincent Reynaud, Paolo Maistri, Régis Leveugle
ETS4
2020 A Comprehensive End-to-end Solution for a Secure and Dynamic Mixed-signal 1687 System
abstract
The disruptive potential of the IEEE 1687 standard does not come from a single innovation, but rather from its capacity of providing a unified framework where heterogeneous approaches can co-exist and interact. In this Special Session, we will present the complementary research activities performed in the TIMA laboratory covering different aspects of the standard (Mixed-Signal instrument testing, Embedded Aging Monitors and Test Access Securization), and their coordination thanks to the Manager-for SoC Test (MAST) software environment.
Michele Portolan, R. Silveira Feitoza, Ghislain Takam Tchendjou, Vincent Reynaud, Kalpana Senthamarai Kannan, Manuel J. Barragan Asian, Emmanuel Simeu, Paolo Maistri, Lorena Anghel, Régis Leveugle, Salvador Mir
IOLTS10
2019 Alternatives to Fault Injections for Early Safety/Security Evaluations
abstract
Functional Safety standards like ISO 26262 require a detailed analysis of the dependability of components subjected to perturbations. Radiation testing or even much more abstract RTL fault injection campaigns are costly and complex to set up especially for SoCs and Cyber Physical Systems (CPSs) comprising intertwined hardware and software. Moreover, some approaches are only applicable at the very end of the development cycle, making potential iterations difficult when market pressure and cost reduction are paramount. In this tutorial, we present a summary of classical state-of-the-art approaches, then alternative approaches for the dependability analysis that can give an early yet accurate estimation of the safety or security characteristics of HW-SW systems. Designers can rely on these tools to identify issues in their design to be addressed by protection mechanisms, ensuring that system dependability constraints are met with limited risk when subjected later to usual fault injections and to e.g., radiation testing or laser attacks for certification.
Michele Portolan, Alessandro Savino 0001, Régis Leveugle, Stefano Di Carlo, Alberto Bosio, Giorgio Di Natale
ETS3
2019 Approximate computing design exploration through data lifetime metrics
abstract
When designing an approximate computing system, the selection of the resources to modify is key. It is important that the error introduced in the system remains reasonable, but the size of the design exploration space can make this extremely difficult. In this paper, we propose to exploit a new metric for this selection: data lifetime. The concept comes from the field of reliability, where it can guide selective hardening: the more often a resource handles “live” data, the more critical it becomes, the more important it will be to protect it. In this paper, we propose to use this same metric in a new way: identify the less critical resources as approximation targets in order to minimize the impact on the global system behavior and therefore decrease the impact of approximation while increasing gains on other criteria.
Alessandro Savino 0001, Michele Portolan, Régis Leveugle, Stefano Di Carlo
ETS3
2018 Laser Fault Injection at the CMOS 28 nm Technology Node: an Analysis of the Fault Model
abstract
S. Skorobogatov and R. Anderson identified laser illumination as an effective technique to conduct fault attacks in 2002. In these early days of laser-induced fault injection, it was proven to be possible to inject single-bit faults into integrated circuits. This corresponds to the more restrictive fault model found in the fault attack bibliography. The target area under laser illumination (a few micrometers, down to ~1 µm) broadly matched that of a single transistor. It was consistent with a single-bit fault model. However, since then the technology of secure devices has evolved. In current circuits even the smallest laser spots may illuminate several logic cells. This raises the question of the validity of the single-bit fault model: does it still hold? In this work, we report an assessment of its validity through experimental results obtained from circuits designed at the 28 nm CMOS technology node. We also describe the main properties of the corresponding fault model obtained from both static and dynamic experiments.
Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Stephan De Castro, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre
FDTC9
2018 The case of using CMOS FD-SOI rather than CMOS bulk to harden ICs against laser attacks
abstract
At first used to emulate the effects of radioactive ionizing particules passing through integrated circuits (ICs), laser illumination is also used to inject faults into the computations of secure ICs for the purpose of retrieving secret data. The CMOS FD-SOI technology is expected to be less sensitive to laser faults injection than the more usual CMOS bulk technology. We report in this work an experimental assessment of the interest of using FD-SOI rather than CMOS bulk to decrease laser sensitivity. Our experiments were conducted on test chips at the 28nm node for both technologies with laser pulse durations in the picosecond and nanosecond ranges.
Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre
IOLTS8
2017 HLS design of a hardware accelerator for Homomorphic Encryption
abstract
Modular polynomial multiplication is the most computationally intensive operation in many homomorphic encryption schemes. In order to accelerate homomorphic computations, we propose a software/hardware (SW/HW) co-designed accelerator integrating fast software algorithms with a configurable hardware polynomial multiplier. The hardware accelerator is implemented through a High-Level Synthesis (HLS) flow. We show that our approach is highly flexible, since the same generic high-level description can be configured and re-used to generate a new design with different parameters and very large sizes in negligible time. We show that flexibility does not preclude efficiency: the proposed solution is competitive in comparison with hand-made designs and can provide good performance at low cost.
Asma Mkhinini, Paolo Maistri, Régis Leveugle, Rached Tourki
DDECS3
2017 Reliability of computing systems: From flip flops to variables
abstract
Reliability evaluation is a critical task in computing systems. From one side, the results must be accurate enough not to under-or over-estimate the overall system reliability (thus either resulting in a non-reliable system, or a system for which too expensive solutions have been adopted). On the other side, the time required for the analysis should be kept at the minimum. This paper presents some new advances in the reliability assessment of computing systems, by showing techniques targeting both hardware and software levels, and the combination of both.
Giorgio Di Natale, Maha Kooli, Alberto Bosio, Michele Portolan, Régis Leveugle
IOLTS5
2016 On the development of a new countermeasure based on a laser attack RTL fault model
Charalampos Ananiadis, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle
DATE6
2016 HLS-Based Methodology for Fast Iterative Development Applied to Elliptic Curve Arithmetic
abstract
High-Level Synthesis (HLS) is used by hardware developers to achieve higher abstraction in circuit descriptions. In order to shorten the hardware development time via HLS, we present an adjustment of the Iterative and Incremental Design (IID) methodology, frequently used in software development. In particular, our methodology is relevant for the development of applications with unusual complexity: the method was applied here to the development of large modular arithmetic, commonly used for cryptography applications (e.g., Elliptic Curves). Rapid feedback on circuit characteristics is used to evaluate deep architectural changes in short time, greatly reducing the time-to-market with respect to hand-made designs. In addition, our approach is highly flexible, since the same generic high-level description can be used to produce an entire set of circuits, each with different area/performance trade-offs. Thanks to the proposed approach, any change to the initial specification (e.g., the curve used) is also very fast, while it may require a large effort in the case of hand-made designs.
Simon Pontié, Alban Bourge, Adrien Prost-Boucle, Paolo Maistri, Olivier Muller, Régis Leveugle, Frédéric Rousseau 0001
DSD6
2016 Evaluating application-aware soft error effects in digital circuits without fault injections or probabilistic computations
abstract
Evaluating the robustness of circuits with respect to soft errors has become of utmost importance in many application areas. This evaluation must in most cases be refined taking into account the application characteristics in order to avoid too pessimistic results. The main approach used today at design time is based on fault injection campaigns. Emulation can be used to speed up the evaluations, but requires noticeable effort to implement the circuit prototype. This paper presents an approach based on an automated analysis of register lifetime, requiring only one functional simulation of the target application. The approach has been demonstrated on significant circuits. The results show that the proposed approach can be more efficient than emulation in terms of experimental time, without requiring any specific hardware and achieving a good accuracy. The global intrinsic robustness is evaluated and the most critical registers or execution cycles can also be identified with good confidence.
K. Chibani, Michele Portolan, Régis Leveugle
IOLTS3
2014 A multiple fault injection methodology based on cone partitioning towards RTL modeling of laser attacks
abstract
Laser attacks, especially on circuits manufactured with recent deep submicron semiconductor technologies, pose a threat to secure integrated circuits due to the multiplicity of errors induced by a single attack. An efficient way to neutralize such effects is the design of appropriate countermeasures, according to the circuit implementation and characteristics. Therefore tools which allow the early evaluation of security implementations are necessary. Our efforts involve the development of an RTL fault injection approach more representative of laser attacks than random multi-bit fault injections and the utilization and evolution of state of the art emulation techniques to reduce the duration of the fault injection campaigns. This will ultimately lead to the design and validation of new countermeasures against laser attacks, on ASICs implementing cryptographic algorithms.
Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle
DATE5
2014 An Elliptic Curve Crypto-Processor Secured by Randomized Windows
abstract
Embedded systems are increasingly providing secure functionalities, which often rely on some dedicated hardware for symmetric and public-key cryptography. When resources are limited, elliptic curve cryptography (ECC) may be chosen instead of the more widely known RSA, which needs much longer keys for the same security level. However, ECC may be vulnerable, as any other cryptographic implementation, to side channel analysis, which may reveal secret information by analyzing collateral sources of information, such as power consumption. Countermeasures must be thus adopted at the design level, in order to ensure robust and secure operation of the device. We propose here a new scalar multiplication algorithm on an elliptic curve, based on a novel randomized window method. This design is protected against side channel attacks (Timing, Simple and Differential Power Analysis) and it is implemented over prime fields, but it can be applied to binary fields as well. In order to evaluate this countermeasure, we provide its costs, and an estimation of the additional entropy added to the computation against side channels attacks.
Simon Pontié, Paolo Maistri, Régis Leveugle
DSD3
2014 Fast accurate evaluation of register lifetime and criticality in a pipelined microprocessor
abstract
The probability of application failures due to soft errors in microprocessors is directly related to the lifetime of data stored in the internal registers. For high performance processors, the accurate analysis of this lifetime is difficult due to the various micro-architecture features, including pipeline registers and fast-forwarding connections managing data dependencies. Using fault injections to evaluate the robustness of a given application program is very time-consuming, even when emulation is used. In consequence, the comparison of several program implementations is often not affordable. We propose a new approach for the evaluation of lifetimes in all the registers of a pipelined processor, ensuring accurate results while reducing drastically the time required for evaluation, thus enabling more software optimizations. In addition, the most critical registers can be quickly identified.
K. Chibani, Mohamed Ben Jrad, Michele Portolan, Régis Leveugle
VLSI-SoC4
2014 Laser-induced fault effects in security-dedicated circuits
abstract
Lasers have become one of the most efficient means to attack secure integrated systems. Actual faults or errors induced in the system depend on many parameters, including the circuit technology and the laser characteristics. Understanding the physical effects is mandatory to correctly evaluate during the design flow the potential consequences of a laser-based attack and implement efficient counter-measures. This paper presents results obtained within the LIESSE project, aiming at defining a comprehensive approach for designers. Outcomes include the definition of fault/error models at several levels of abstraction, specific CAD tools using these models and new counter-measures well-suited to thwart laser-based attacks. Actual measures on components manufactured in the new 28 nm FDSOI technology are also presented.
Régis Leveugle, Paolo Maistri, Pierre Vanhauwaert, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Guillaume Hubert, Stephan De Castro, Jean-Max Dutertre, Alexandre Sarafianos, Noemie Beringuier-Boher, Mathieu Lisart, Joel Damiens, Philippe Candelier, Clément Tavernier
VLSI-SoC1
2014 Electromagnetic analysis and fault injection onto secure circuits
abstract
Implementation attacks are a major threat to hardware cryptographic implementations. These attacks exploit the correlation existing between the computed data and variables such as computation time, consumed power, and electromagnetic (EM) emissions. Recently, the EM channel has been proven as an effective passive and active attack technique against secure implementations. In this paper, we resume the recent results obtained on this subject, with a particular focus on EM as a fault injection tool.
Paolo Maistri, Régis Leveugle, Lilian Bossuet, Alain Aubert, Viktor Fischer, Bruno Robisson, Nicolas Moro, Philippe Maurine, Jean-Max Dutertre, Mathieu Lisart
VLSI-SoC2
2013 An evaluation of an AES implementation protected against EM analysis
abstract
EM emissions can be a rich source of leakage for side-channel analysis of cipher implementations. In this paper, we describe a set of novel countermeasures based on dynamic spatial relocation and dynamic mappings, and validate the protection provided by them against EM attacks. The countermeasures improve significantly the security of the circuit.
Paolo Maistri, Sébastien Tiran, Philippe Maurine, Israel Koren, Régis Leveugle
ACM Great Lakes Symposium on VLSI5
2013 Evaluating a low cost robustness improvement in SRAM-based FPGAs
abstract
Soft errors in the configuration memory of SRAM-based FPGAs cause significant application disturbances. We demonstrate on Xilinx and Altera FPGAs the feasibility of a very low cost and automated mitigation approach and we evaluate its efficiency.
Mohamed Ben Jrad, Régis Leveugle
IOLTS2
2013 Detailed Analysis of Compilation Options for Robust Software-based Embedded Systems
Salma Bergaoui, A. Wecxsteen, Régis Leveugle
J. Electron. Test.3
2011 10-Gigabit Throughput and Low Area for a Hardware Implementation of the Advanced Encryption Standard
abstract
Current secure applications often need encrypted channels with high throughput, of the order of several gigabits per second. This level of performance is usually obtained with a considerable cost in terms of silicon area. In this paper, we present an implementation of the Advanced Encryption Standard based on heavy pipelining and partial unrolling, which is capable of a 10-Gbps throughput when encrypting with 128-bit keys.
Paolo Maistri, Régis Leveugle
DSD2
2011 Towards Robustness Analysis Using PVS
Renaud Clavel, Laurence Pierre, Régis Leveugle
ITP3
2011 Glitch and Laser Fault Attacks onto a Secure AES Implementation on a SRAM-Based FPGA
Gaetan Canivet, Paolo Maistri, Régis Leveugle, Jessy Clédière, Florent Valette, Marc Renaudin
J. Cryptol.3
2010 Dependability analysis of a countermeasure against fault attacks by means of laser shots onto a SRAM-based FPGA
abstract
Laser-based fault injections are currently the most efficient technique that can be used to attack a secure system, since they have very high timing and location precision. Several papers have shown that a secret key may be recovered from ASICs and countermeasures have been proposed. But little research has been addressed at the specific case of secure protected implementations in SRAM-based FPGAs. This paper presents the results of laser-based fault injections on an architecture computing the AES encryption algorithm, protected by an error detection scheme, and implemented on a Virtex device. The results are compared to previous emulated fault injection campaigns and prove the criticality of remnant errors in the configuration of a FPGA used for secure applications. An improved countermeasure is also proposed and validated with a new experimental campaign.
Gaetan Canivet, Paolo Maistri, Régis Leveugle, Frédéric Valette, Jessy Clédière, Marc Renaudin
ASAP3
2010 Robustness evaluation and improvements under laser-based fault attacks of an AES crypto-processor implemented on a SRAM-based FPGA
abstract
Programmable devices like SRAM-based FPGAs, thanks to their low cost and high flexibility, are increasingly used for security applications; the mam drawback is their configuration memory, sensitive to perturbations. Symmetric cryptosystems are highly vulnerable to fault injections [1], but very few papers have reported laser-based fault attacks onto a secure implementation on a SRAM-based FPGA.
Gaetan Canivet, P. Maistn, Régis Leveugle, Frédéric Valette, Jessy Clédière, Marc Renaudin
ETS3
2010 Early Robustness Evaluation of Digital Integrated Systems
Régis Leveugle
FDL1
2009 Statistical fault injection: Quantified error and confidence
abstract
Fault injection has become a very classical method to determine the dependability of an integrated system with respect to soft errors. Due to the huge number of possible error configurations in complex circuits, a random selection of a subset of potential errors is usual in practical experiments. The main limitation of such a selection is the confidence in the outcomes that is never quantified in the articles. This paper proposes an approach to quantify both the error on the presented results and the confidence on the presented interval. The computation of the required number of faults to inject in order to achieve a given confidence and error interval is also discussed. Experimental results are shown and fully support the presented approach.
Régis Leveugle, A. Calvez, Paolo Maistri, Pierre Vanhauwaert
DATE1
2009 Towards automated fault pruning with Petri Nets
abstract
Embedded systems design is starting considering dependability issues even for mass-market systems. Soft error consequences must in particular be carefully analyzed. Usually, fault injection campaigns are run to analyze the consequences of transient faults, but the length of a comprehensive evaluation often collides with the severe requirements on design cycle times. We propose a new fault pruning technique to identify harmless components and computation cycles as soon as possible, thus avoiding useless fault injection experiments. The technique is based on a formal model of the system and we show that it can be used for both SEUs and SETs.
Paolo Maistri, Régis Leveugle
IOLTS2
2009 Characterization of Effective Laser Spots during Attacks in the Configuration of a Virtex-II FPGA
abstract
SRAM-based FPGAs are an appealing platform to implement many systems, including secure ones. However, secure systems are subject to attacks and one of the main threats is fault-based attacks using lasers. The sensitivity of the configuration memory in a SRAM-based FPGA has to be studied in this context. This paper reports on the characterization of the effective laser spot, or effective sensitive area, with respect to the laser focus and to the attacked configuration bits. The test vehicle is a Virtex II FPGA. It is shown in particular that the initial value of the bit has a strong influence on the effective sensitive area of the spot. Such data can be used to better understand the actual effects of an attack and to design more efficient counter-measures. Also, it is shown that attacks based on single bit flips in the configuration are possible in practice even with relatively large laser spots.
Gaetan Canivet, Régis Leveugle, Jessy Clédière, Frédéric Valette, Marc Renaudin
VTS2
2008 Detailed Analyses of Single Laser Shot Effects in the Configuration of a Virtex-II FPGA
abstract
Due to their reconfigurability and their high density of resources, SRAM-based FPGAs are more and more used in embedded systems. For some applications (Pay-TV,Banking, Telecommunication ...), a high level of security is needed. FPGAs are intrinsically sensitive to ionizing effects, such as light stimulation, and attackers can try to exploit faults injected in the downloaded configuration. Previous studies presented the results obtained with multiple laser shots across different elements of the device. The exact effect of a single laser shot was not studied; a global picture of the type of generated errors was rather drawn. This work analyses the effects of a single laser shot onto the configuration memory. Results take into account several diameters of pulsed laser spots targeted on several types of logical blocks and compare theirs effects.
Gaetan Canivet, Jessy Clédière, Jean Baptiste Ferron, Frédéric Valette, Marc Renaudin, Régis Leveugle
IOLTS6
2008 Software Self-Testing of a Symmetric Cipher with Error Detection Capability
abstract
Cryptographic devices are recently implemented with different countermeasures against side channel attacks and fault analysis. Moreover, some usual testing techniques, such as scan chains, are not allowed or restricted for security requirements. In this paper, we analyze the impact that error detecting schemes have on the testability of an implementation of the advanced encryption standard, in particular when software-based self-test techniques are envisioned. We show that protection schemes can improve concurrent error detection, but make initial testing more difficult.
Paolo Maistri, Cyril Excoffon, Régis Leveugle
IOLTS3
2008 Double-Data-Rate Computation as a Countermeasure against Fault Analysis
abstract
Differential Fault Analysis (DFA) is one of the most powerful techniques to attack cryptosystems. Several countermeasures have been proposed, which are based either on information or temporal redundancy. In this work, we propose a novel approach based on a Double-Data-Rate (DDR) computation template. A few sample architectures have been implemented: they are compared to other existing architectures and countermeasures, and a thorough dependability analysis is given.
Paolo Maistri, Régis Leveugle
IEEE Trans. Computers2
2007 Experimental evaluation of protections against laser-induced faults and consequences on fault modeling
Régis Leveugle, Abdelaziz Ammari, Vincent Maingot, E. Teyssou, Pascal Moitrel, Christophe Mourtel, Nathalie Feyt, Jean-Baptiste Rigaud, Assia Tria
DATE1
2007 A Novel Double-Data-Rate AES Architecture Resistant against Fault Injection
abstract
Several techniques have been proposed for encryption blocks in order to provide protection against faults. These techniques usually exploit some form of redundancy, e.g. by means of error detection codes. However, protection schemes that offer an acceptable error detection rate are in general expensive, while temporal redundancy heavily affects the throughput. In this paper, we propose a new design solution that exploits temporal redundancy by DDR techniques without affecting adversely the throughput at lower clock frequencies. We will also show that the overall costs can be comparable to other solutions recently proposed.
Paolo Maistri, Pierre Vanhauwaert, Régis Leveugle
FDTC3
2007 Formal Analysis of Quasi Delay Insensitive Circuits Behavior in the Presence of SEUs
abstract
Asynchronous circuits are often claimed as being an interesting alternative to design robust systems against faults. In this study, a method is proposed to model the behavior of quasi delay insensitive (QDI) asynchronous circuits in the presence of SEUs (memory bit flips). The circuits and the fault injection process are both described using this model. The method, based on symbolic simulation, consists of exploring all the reachable states in the presence of faults in order to draw up an exhaustive list of behaviors. A case study shows that this method enables us to verify some properties on the circuits. SEU resistance can be formally proven using this analysis.
Yannick Monnet, Marc Renaudin, Régis Leveugle
IOLTS3
2007 Early Analysis of Fault-based Attack Effects in Secure Circuits
abstract
Security often relies on functions implemented in hardware. But, various types of attacks have been developed, in particular, fault-based attacks allowing a hacker to observe abnormal behaviors from which secret data can be inferred. Analyzing very early, during a circuit design, the potential impact of faults therefore becomes necessary to avoid security flaws. Dependability analysis environments have been developed to analyze the effect of "natural" faults, for example, those induced by particles. This paper discusses the similarities and differences between the two types; of application areas and proposes extensions of the classical fault models to cover security-related constraints. Experimental results on a coprocessor for RSA encryption demonstrate the need for such an extended fault model.
Régis Leveugle
IEEE Trans. Computers1
2006 Case Study of a Fault Attack on Asynchronous DES Crypto-Processors
Yannick Monnet, Marc Renaudin, Régis Leveugle, Christophe Clavier, Pascal Moitrel
FDTC3
2006 Practical Evaluation of Fault Countermeasures on an Asynchronous DES Crypto Processor
abstract
This paper presents practical results on the evaluation of fault countermeasures implemented in an asynchronous DES coprocessor. The theory underlying the countermeasures was previously published in IOLTS 2005. For the first time this work reports a practical evaluation of fault countermeasures applied on asynchronous DES ASICs. Two DES crypto processors were fabricated using the 130 nm STmicroelectronics CMOS process; one as a reference and one hardened using a specific technique. This work enables us to compare the resistance of both circuits against fault injection and to validate the proposed countermeasures. The practical set-up of the fault injection, using a laser, is presented and the test campaign described. The practical results prove the efficiency of the method. The techniques can be applied to protect logic blocks in any applications.
Yannick Monnet, Marc Renaudin, Régis Leveugle, Nathalie Feyt, Pascal Moitrel, F. M'Buwa Nzenguet
IOLTS3
2006 Reduced Instrumentation and Optimized Fault Injection Control for Dependability Analysis
abstract
Fault-injection based dependability analysis has proved to be an efficient mean to predict the behavior of a circuit in presence of faults. Instrumentation-based techniques are in general used to perform the injection during simulation or emulation. The weak point of these techniques remains the characteristics obtained after modification of either the high-level description or the circuit netlist, especially when emulation is used. This paper proposes an instrumentation technique reducing the extra hardware and accelerating the fault injection campaigns thanks to optimized fault location addressing and parallel injection
Pierre Vanhauwaert, Régis Leveugle, Philippe Roche
VLSI-SoC2
2006 Designing Resistant Circuits against Malicious Faults Injection Using Asynchronous Logic
abstract
This paper presents hardening techniques against fault attacks and the practical evaluation of their efficiency. The circuit technology investigated to improve the resistance against fault attacks is asynchronous logic. Specific properties of asynchronous circuits make them inherently resistant against a large class of faults. An analysis of their behavior in the presence of faults shows that they are an interesting alternative to design robust systems. A behavior diagnosis enables us to propose hardening techniques that improve fault tolerance and resistance. They are applied at design time and aim at exploiting quasi-delay insensitive (QDI) circuit properties to significantly harden the architecture with a very low area overhead and a reasonable performance penalty. To validate these techniques, a hardened DES crypto-processor is presented. The countermeasures are evaluated using laser beam fault injection
Yannick Monnet, Marc Renaudin, Régis Leveugle
IEEE Trans. Computers3
2005 Asynchronous circuits transient faults sensitivity evaluation
abstract
This paper presents a transient faults sensitivity evaluation for Quasi Delay Insensitive (QDI) asynchronous circuits. Because of their specific architecture, asynchronous circuits have a very different behavior than synchronous circuits in the presence of faults. We address the effects of transient faults in QDI circuits and describe the causes that lead the faults to be memorized into one or more soft errors. Therefore, a refined fault sensitivity criterion is defined for this class of circuits. This methodology enables us to point out the weak parts of a circuit. An analysis tool is implemented to support this evaluation. This tool provides a quantitative study of the fault sensitivity, and enables us to compare the robustness of different architectures of a circuit along the steps of its design flow. The objective of this work is to evaluate the circuits robustness against natural faults (single fault model) and intentional fault injection (multiple faults model).
Yannick Monnet, Marc Renaudin, Régis Leveugle
DAC3
2005 Towards a Secure and Reliable System
Michele Portolan, Régis Leveugle
EUC2
2005 Evaluation of SET and SEU Effects at Multiple Abstraction Levels
abstract
This paper reviews the main approaches used to evaluate the effect of single event transients and single event upsets in digital circuits described at different abstraction levels. The two fault models are first discussed with respect to the circuit description levels, then complementary dependability evaluation methods are summarized.
Lorena Anghel, Régis Leveugle, Pierre Vanhauwaert
IOLTS2
2005 Introduction to the Special Session on Secure Implementations
abstract
This paper briefly introduces online testing and its evolution towards very sub micron technologies. How secure circuit designers and online testing experts collaboration can help detect online the occurrence of natural faults that may be used as a basis to counter fault-based attacks taking into account the particular needs of secure application.
Régis Leveugle
IOLTS1
2005 A New Approach for Early Dependability Evaluation Based on Formal Property Checking and Controlled Mutations
abstract
The interest for early analyses of the functional impact of faults in a circuit is growing, due to the increasing probability of transient faults. However, experiments are often very long, especially when spatial and temporal multiplicity has to be taken into account in the fault model. Formal property checking is an appealing approach to perform comprehensive functional validations but is intended to validate properties only in nominal operation, not after a fault has occurred. This paper proposes a new approach combining formal property checking and the generation of specific circuit mutants to achieve efficient early identification of unacceptable effects of multiple faults.
Régis Leveugle
IOLTS1
2005 On-Line Testing for Secure Implementations: Design and Validation
abstract
On-line testing approaches can today be useful when designing circuits with severe security constraints. The reasons are summarized in the introduction to the special session on secure implementations (in these proceedings). The presentations in this special session aimed at introducing the specific concerns related to security as well as some approaches used to protect the circuits and to validate their robustness for certification. This panel aims at discussing in more details how on-line testing techniques can help in improving security and how the achieved level of security can be evaluated at different stages in the design flow. Various aspects are covered by the participants, including: counter-measures for fault attacks in hardware cryptographic primitives, design for test versus design for security, use of fault injection tools in evaluating the robustness against attacks and validation of security at the system level.
Régis Leveugle, Yervant Zorian, Luca Breveglieri, André K. Nieuwland, Klaus Rothbart, Jean-Pierre Seifert
IOLTS1
2005 Hardening Techniques against Transient Faults for Asynchronous Circuits
abstract
This paper presents hardening techniques against transient faults for quasi delay insensitive (QDI) circuits. Because of their specific architecture, asynchronous circuits have a very different behavior than synchronous circuits in the presence of faults. We address the effects of transient faults in QDI circuits and describe consequences on the circuit behavior. Three techniques exploiting QDI circuit properties are proposed for hardening. These techniques improve the tolerance to transient faults, and make their detection easier. These techniques are compared in terms of efficiency and cost.
Yannick Monnet, Marc Renaudin, Régis Leveugle
IOLTS3
2005 On the Need for Common Evaluation Methods for Fault Tolerance Costs in Microprocessors
abstract
Technological evolution is making fault tolerance more and more important in all application fields and it is therefore mandatory to have good strategies to measure its impact on existing systems. A lot of work has been done on fault characterization and modelling, but confusion still abounds when coming to performance loss evaluation. This is especially true for microprocessors, where "performance" is a tricky word to define, cause of a lot of debates and controversies. This article proposes a new and easy-to-apply framework to evaluate performance costs implied by fault tolerance in systems made of both hardware and software. Results are presented on a system based on a Sparc v8 processor and the eCoS operating system.
Michele Portolan, Régis Leveugle
IOLTS2
2005 Combined Fault Classification and Error Propagation Analysis to Refine RT-Level Dependability Evaluation
Abdelaziz Ammari, K. Hadjiat, Régis Leveugle
J. Electron. Test.3
2004 Early SEU Fault Injection in Digital, Analog and Mixed Signal Circuits: A Global Flow
abstract
Fault injection techniques have been proposed for years to early analyze the dependability characteristics of digital circuits. Very few attempts have however been reported to perform the same task in analog parts. Furthermore, these attempts are all based on parametric variations. With the increasing number of mixed signal circuits, a unified approach becomes mandatory to globally validate the digital and analog parts, while taking into account real faults occurring in the field, e.g. SEUs. In this paper, a global analysis flow is proposed, based on a high-level model of the circuit. The possibility to inject transient faults in the different parts is discussed. The results obtained on a case study are reported to show the feasibility of the injection in analog blocks.
Régis Leveugle, Abdelaziz Ammari
DATE1
2004 On Combining Fault Classification and Error Propagation Analysis in RT-Level Dependability Evaluation
Abdelaziz Ammari, K. Hadjiat, Régis Leveugle
IOLTS3
2004 Asynchronous Circuits Sensitivity to Fault Injection
Yannick Monnet, Marc Renaudin, Régis Leveugle
IOLTS3
2004 Operating System Function Reuse to Achieve Low-Cost Fault Tolerance
Michele Portolan, Régis Leveugle
IOLTS2
2003 Multi-Level Fault Injections in VHDL Descriptions: Alternative Approaches and Experiments
Régis Leveugle, K. Hadjiat
J. Electron. Test.1
2002 Automatic Modifications of High Level VHDL Descriptions for Fault Detection or Tolerance
abstract
The need for integrated mechanisms providing on-line error detection or fault tolerance is becoming a major concern due to the increasing sensitivity of the circuits to their environment. This paper reports on a tool automating the implementation of such mechanisms by modifying high-level VHDL descriptions. The modifications are compatible with industrial design flows based on commercial synthesis and simulation tools. The results demonstrate the feasibility and the efficiency of the approach.
Régis Leveugle
DATE1
1996 Standard and ROM-based synthesis of FSMs with control flow checking capabilities
abstract
This paper deals with the detection of sequencing errors in finite state machines. Several control-flow checking methods, implemented in an automatic synthesis tool, are presented. The contribution of this paper lies in that these methods are introduced in the ROM-based architecture, and compared to equivalent methods available in the standard synthesis flow.
X. Wendling, Raphaël Rochet, Régis Leveugle
VTS3
1994 The Hyeti Defect Tolerant Microprocessor: A Practical Experiment and its Cost-Effectiveness Analysis
abstract
This paper summarizes a practical experiment in designing a defect tolerant microprocessor and presents the underlying principles. Unlike memory integrated circuits, microprocessors have an irregular structure which complicates both the task of incorporating redundancy for defect tolerance in the design and the task of analyzing the resulting yield increase. The main goal of this paper is to present the detailed yield analysis of a defect tolerant microprocessor with an irregular structure which has been successfully fabricated. The approaches employed for achieving the goal of yield enhancement in the data path and the control part of the microprocessor are described first. Then, the yield enhancement due to the incorporated redundancy is analyzed. Finally, some practical and theoretical conclusions are drawn.>
Régis Leveugle, Zahava Koren, Israel Koren, Gabriele Saucier, Norbert Wehn
IEEE Trans. Computers1
1993 Optimized State Assignment of single fault Tolerant FSMs Based on SEC Codes
abstract
The synthesis of single fault tolerant FSMs requires state codes with a minimal Hamming distance equal to 3 (SEC code). The classical state assignment optimizations assume codes at distance 1 and do not directly apply. This paper shows that the optimization principles can be extended to SEC codes. A state assignment algorithm is proposed and results demonstrate its efficiency.
Régis Leveugle
DAC1
1993 Influence of Error Correlations on the Signature Analysis Aliasing
abstract
Signature analysis is often used in the test area to reduce the amount of information to check. The drawback of this compaction is its non-zero aliasing probability, i.e. the possibility to obtain a correct signature in spite of errors in the compacted words. Up to now, the studies on aliasing have focused on BIST applications and do not consider correlations between errors in two compacted words. However, online test methods also use signature analysis. The reported experiments show that, in this context and for some types of faults, the existing correlations have a noticeable impact on the aliasing probability. Further theoretical studies taking into account these correlations are therefore required to model the aliasing observed at each compaction step. It also seems that checking a signature in the middle of a linear block of instructions is better than checking it just before or after a branching instruction.>
Régis Leveugle, X. Delord, Gabriele Saucier
ICCD1
1991 Hierarchical Test Generation Based on Delayed Propagation
abstract
A hierarchical test generation method is presented which is based on a functional approach to guide backward and forward propagations. The proposed algorithm permits solving most propagation conflicts by taking advantage of the functionality of the implemented block and avoids costly unnecessary design modifications. It has been implemented and its effectiveness has been proved on a set of datapaths. The formalism and the algorithms are general enough to handle any type of synchronous digital circuit.
Margot Karam, Régis Leveugle, Gabriele Saucier
ITC2
1990 Optimized Synthesis of Concurrently Checked Controllers
abstract
A method for introducing online test facilities in a controller with a very low overhead is presented. This online test consists of detecting illegal paths in the control flow graph. These illegal paths may be due either to permanent faults or to transient errors. The state code flow is compacted through polynomial division. An implicit justifying signature method is applied at the state code level and ensures identical signatures before each join mode of the control flow graph. The signatures are then independent of the path followed previously in the graph, and the comparison to reference data is greatly facilitated. This property is obtained by a state assignment, nearly without area overhead. The controllers can then be checked by signature analysis, either by a built-in monitor or by an external checker.>
Régis Leveugle, Gabriele Saucier
IEEE Trans. Computers1
1989 Concurrent checking in dedicated controllers
abstract
A novel method for introducing online test facilities in a controller with a very low overhead is presented. This online test consists of detecting illegal paths in the control flow graph. These illegal paths may be due to either permanent faults or transient errors. The implementation of the detection facilities relies on a clever choice of the state codes of the controller, which can then be checked by signature analysis by either a built-in monitor or an external checker.>
Régis Leveugle, Gabriele Saucier
ICCD1
1989 A channelless layout for multilevel synthesis with compiled cells
abstract
A novel method for optimized multilevel synthesis of CMOS circuitry in terms of compiled cells is presented. A compiled cell is the implementation on silicon of a lexicographical factorized Boolean expression. How a compiled cell is obtained automatically from the Boolean expression (layout synthesis) is recalled, and the rewriting of Boolean functions in terms of compiled cells is addressed. This approach leads to a dense and regular layout by abutment of compiled cells. The wiring channels are thus suppressed.>
Gabriele Saucier, Régis Leveugle, Pierre Abouzeid
ICCD2
1989 Optimized Synthesis of Dedicated Controllers with Concurrent Checking Capabilities
abstract
The authors present a novel synthesis method of dedicated controllers which aims at the detection of faults which cause errors in the state sequences. The state code flow is compacted through polynomial division. An implicit 'justifying signature' method is applied at the state code level and ensures identical signatures before each join node of the control flow graph. The signatures are then independent of the path followed previously in the graph, and the comparison with reference data is greatly facilitated. This property is obtained by a clever state assignment, nearly without area overhead. The controllers can therefore be checked by signature analysis, either by a built-in monitor or by an external checker. The software implementation of the synthesis tool is presented, and the hardware implementation of the concurrent checking is described.>
Régis Leveugle, Gabriele Saucier
ITC1