Lilian Bossuet

dblp:12/6779 · also Lilian Hubert Bossuet · DBLP profile ↗
← Back
42ranked-venue papers
9as first author
14since 2021 · last 2025
0000-0001-7964-3137ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 34 · 8 first-author · 9 since 2021Security and privacy · 7 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021
YearPublicationVenuePosition
2025 Low-Latency FFT/iFFT RTL Implementation for the FALCON Post-Quantum Signature Algorithm
abstract
FALCON is one of the three post-quantum digital signature schemes that have been recently standardized by NIST due to the future threat that quantum computers pose to classical cryptographic schemes. Despite this, there is currently no full hardware register-transfer level (RTL) implementation of FALCON. One possible explanation is the rather unusual requirement for a double-precision floating-point Fast Fourier Transform (FFT), which is used in FALCON to speed up polynomial multiplication. In this article, we describe a full RTL implementation of the FFT and its inverse, on FPGA, tailored for the specific context of FALCON. Fitting in this specific cryptographic context, the implementation is also constant-time. The proposed hardware implementation achieves the best latency of the literature. This work paves the way for the first complete fine-tuned RTL implementation of FALCON as well as the security evaluation of such implementations against physical attacks.
Alexandre Ortega, Lilian Bossuet, Brice Colombier
FCCM2
2025 Power and Frequency Intrinsic Channels on gem5
abstract
Recent works have highlighted the vulnerability of System-on-a-Chip (SoC) platforms against intrinsic channels attacks. In this threat model, an adversary can leverage vulnerabilities in the SoC’s firmware, the operating system, or the design tools to gain access to shared resources in the platform and transfer data covertly. Given the diversity of attack avenues and the constant evolution of heterogeneous SoCs, it is not practical to study these attacks using conventional approaches. To address this issue, we propose to employ gem5 in the study of power and frequency intrinsic channels. Our work studies heterogeneous SoCs which feature a processor system and an FPGA. We employ the full system simulation of gem5 to emulate a reference physical device. We then describe the emulation of different intrinsic channels which leverage the clock tree and power distribution network of the SoC to transfer data covertly. Our findings demonstrate that gem5 can accurately replicate the logical behavior of power and frequency intrinsic channels.
Lilian Bossuet, Carlos Andres Lara-Nino
IEEE Trans. Circuits Syst. I Regul. Pap.1
2025 Efficient Adaptive Multi-Level Privilege Partitioning With RTrustSoC
abstract
In recent years, heterogeneous SoCs—comprised of multiple processor cores and programmable logic—have greatly progressed both complexity and performance. From a security point of view, this leads to an expansion of the attack surface exposed to adversaries. To address this issue, in this article, we propose a novel heterogeneous SoC architecture called RTrustSoC. Our proposal includes an innovative fully-reconfigurable post-deployment strategy for partitioning the SoC architecture into multiple exclusion levels—worlds—with customizable degrees of privilege. We aim to provide SoC designers with fine control over the security of the system by segregating trusted hardware components from third-party IPs with “on-demand” hardware isolation. Therefore, we expect that an RTrustSoC instance could evolve from a multi-world SoC to a fully trusted platform as IPs progressively develop. RTrustSoC also proposes a dynamic reconfigurable penalty system to monitor the third-party IPs and take measures in case of a detected abnormal behavior. Our experimental testing on an AMD-Xilinx Zynq-7000 SoC-FPGA showed the penalty of the proposed isolation strategy to be small, up to 1% in LUT and 0.7% Flip Flop utilization, thus enabling to an efficient security solution. RTrustSoC introduces a novel design paradigm, evolving from the binary notion of security—trusted vs untrusted—into a flexible set of worlds that can be adapted to any scenario. We demonstrate a real case scenario of RTrustSoC use on time-based cache memory attacks with implementation results.
Raphaële Milan, Lilian Bossuet, Loïc Lagadec, Carlos Andres Lara-Nino, Brice Colombier, Théotime Bollengier
IEEE Trans. Circuits Syst. I Regul. Pap.2
2024 Lightweight Active Fences for FPGAs
abstract
The use of active fences has been proposed as a protection against remote power analysis attacks. This counter-measure relies on reserving a reconfigurable space within the FPGA which will separate it into sub-regions. These “fences” will then generate some electrical interference to hinder the performance of an attack. As FPGAs can be configured in multiple ways, there are different approaches for connecting the hardware inside the fence. In this work, we describe a LUT-based configuration which can achieve the same instantaneous power drop as a ring oscillator bank with less LUTs. This contributes to reducing the hardware costs of active fences.
Anis Fellah-Touta, Lilian Bossuet, Vincent Grosso, Carlos Andres Lara-Nino
VLSI-SoC2
2023 Deep Stacking Ensemble Learning Applied to Profiling Side-Channel Attacks
Dorian Llavata, Eleonora Cagli, Rémi Eyraud, Vincent Grosso, Lilian Bossuet
CARDIS5
2023 BALoo: First and Efficient Countermeasure Dedicated to Persistent Fault Attacks
abstract
Persistent fault analysis is a novel and efficient cryptanalysis method. The persistent fault attacks take advantage of a persistent fault injected in a non-volatile memory, then present on the device until the reboot of the device. Contrary to classical physical fault injection, where differential analysis can be performed, persistent fault analysis requires new analyses and dedicated countermeasures. Persistent fault analysis requires a persistent fault injected in the S-box such that the bijective characteristic of the permutation function is not present anymore. In particular, the analysis will use the non-uniform distribution of the S-box values: when one of the possible S-box values never appears and one of the possible S-box values appears twice. In this paper, we present the first dedicated protection to prevent persistent fault analysis. This countermeasure, called BALoo for Bijection Assert with Loops, checks the property of bijectivity of the S-box. We show that this countermeasure has a 100% fault coverage for the persistent fault analysis, with a very small software overhead (memory overhead) and reasonable hardware overhead (logical resources, memory and performance). To evaluate the overhead of BALoo, we provide experimental results obtained with the software and the hardware (FPGA) implementations of an AES-128.
Pierre-Antoine Tissot, Lilian Bossuet, Vincent Grosso
IOLTS2
2023 Secured-by-design systems-on-chip: a MBSE Approach
abstract
Security by Design (SbD) has gained increasing interest over the past decade. While iterative processes and legacy preservation aim to reduce costs and mitigate risks through continuity, SbD encourages a break in the way we do things with a simple idea: dealing with new threats, leading to new risks, requires a complete rethink of our design processes.
Raphaële Milan, Loïc Lagadec, Théotime Bollengier, Lilian Bossuet, Ciprian Teodorov
RSP4
2022 Self-timed Masking: Implementing Masked S-Boxes Without Registers
Mateus Simões, Lilian Bossuet, Nicolas Bruneau, Vincent Grosso, Patrick Haddad, Thomas Sarno
CARDIS2
2022 SecDec: Secure Decode Stage thanks to masking of instructions with the generated signals
abstract
Physical attacks are becoming a major security issue in IOT applications. One of the main vectors of attacks on processors is the corruption of the execution flow. Fault injections allow the modification of instructions, in particular jumps and branches. The proposed approach involves making a RISC-V processor's instruction path more resistant by introducing dependencies between succeeding instructions. The signals extracted from the instruction decoding stage is used to unmask the following instruction. Whereas all instructions have been previously masked during compilation with the expected mask. We show that this solution has a very low hardware overhead of 3.25% and power consumption of 4.33%. But also overhead software of 1.61% in code size and 1.12% in execution time. An instruction corruption or a jump will be detected on average in fewer than 2 cycles after the fault while making disassembling from side-channel leakages becomes more difficult.
Gaëtan Leplus, Olivier Savry, Lilian Bossuet
DSD3
2021 Multi-Spot Laser Fault Injection Setup: New Possibilities for Fault Injection Attacks
Brice Colombier, Paul Grandamme, Julien Vernay, Émilie Chanavat, Lilian Bossuet, Lucie de Laulanié, Bruno Chassagne
CARDIS5
2021 Message-Recovery Laser Fault Injection Attack on the Classic McEliece Cryptosystem
Pierre-Louis Cayrel, Brice Colombier, Vlad Dragoi, Alexandre Menu, Lilian Bossuet
EUROCRYPT (2)5
2021 Security Assessment of Heterogeneous SoC-FPGA: On the Practicality of Cache Timing Attacks
abstract
Cache attacks are widespread on microprocessors and multi-processor system-on-chips but have not yet spread to heterogeneous systems-on-chip such as SoC-FPGA that are found in increasing numbers of applications on servers or in the cloud. This type of SoC has two parts, a processing system that includes hard components and ARM processor cores and a programmable logic part that includes logic gates to be used to implement custom designs. The two parts communicate via memory mapped interfaces. One of these interfaces is the accelerator coherency port that provides optional cache coherency between the two parts. In this paper, we discuss the practicability and potential threat of inside-SoC cache attacks using the cache coherency mechanism of a complex heterogeneous SoC-FPGA. For the first time, we provide proof of two cache timing attacks Flush+Reload and Evict+Time when SoC-FPGA is targeted, and proof of hidden communication using a cache-based covert channel. The heterogeneous SoC-FPGA Xilinx Zynq-7010 is used as an experimental target.
Lilian Bossuet, El Mehdi Benhani
VLSI-SoC1
2021 Cross-layer Approach to Assess FMEA on Critical Systems and Evaluate High-Level Model Realism
abstract
Embedded systems in critical applications are constrained by very strict standards. The safety of such systems is crucial, however, their safety analysis (e.g., Failure Mode and Effects Analysis, or FMEA) is often empirical and mainly relies on the experience of engineers. Performing empirical analyses on complex designs is a major challenge that leads engineers to make very pessimistic assumptions and consequently to over-design multiple countermeasures. Many fault injection techniques have been developed to evaluate the robustness of hardware designs from Register Transfer Level to Transaction Level. At the RT-level, these techniques are circuit-centered, and therefore do not rely on the overall system specifications. Besides, with complex hardware designs, fault simulations become very time-consuming. Conversely, at the transaction level, fault simulation is fast to the detriment of the realism of high-level models. In this paper, we present a new iterative cross-layer robustness analysis flow taking into account the overall critical system specifications and verifying the realism of high-level models. The first step of the flow leads to extract critical parameter ranges. Then, these ranges are used to quickly evaluate the robustness of each RTL block in the circuit. In the last step, we compute some metrics reflecting the realism of the high-level models. According to these metrics, we can determine if the high-level models must be improved. We apply this methodology to a case study of a real airborne system.
Julie Roux, Katell Morin-Allory, Vincent Beroulle, Régis Leveugle, Lilian Bossuet, Frédéric Cézilly, Frédéric Berthoz, Gilles Genévrier, François Cerisier
VLSI-SoC5
2021 Improving Deep Learning Networks for Profiled Side-channel Analysis Using Performance Improvement Techniques
abstract
The use of deep learning techniques to perform side-channel analysis attracted the attention of many researchers as they obtained good performances with them. Unfortunately, the understanding of the neural networks used to perform side-channel attacks is not very advanced yet. In this article, we propose to contribute to this direction by studying the impact of some particular deep learning techniques for tackling side-channel attack problems. More precisely, we propose to focus on three existing techniques: batch normalization, dropout, and weight decay, not yet used in side-channel context. By combining adequately these techniques for our problem, we show that it is possible to improve the attack performance, i.e., the number of traces needed to recover the secret, by more than 55%. Additionally, they allow us to have a gain of more than 34% in terms of training time. We also show that an architecture trained with such techniques is able to perform attacks efficiently even in the context of desynchronized traces.
Damien Robissout, Lilian Bossuet, Amaury Habrard, Vincent Grosso
ACM J. Emerg. Technol. Comput. Syst.2
2020 Backtracking Search for Optimal Parameters of a PLL-based True Random Number Generator
abstract
The phase-locked loop-based true random number generator (PLL-TRNG) extracts randomness from clock jitter. It is an interesting construct because it comes with a stochastic model, making it certifiable by certification bodies. However, bringing it to good performance is difficult since it comes with multiple parameters to tune. This article proposes to use backtracking to determine these parameters. Compared to existing methods, based on genetic algorithms or exhaustive search of a feasible set of parameters, backtracking has several advantages. Indeed, since this method is expressible by constraint programming, it provides very good readability. Constraints can be specified in a very straightforward and maintainable way. It also exhibits good performance and generates PLL-TRNG configurations rapidly. Finally, it allows to integrate new exploratory design constraints for the PLL-TRNG very easily. We provide experimental results with a PLL-TRNG implemented on three FPGA families that come with different physical constraints, showing that the method allows to find good parameters for every one of them. Moreover, we were able to obtain configurations that lead to an increase 59 % in throughput and 82 % in jitter sensitivity on average, thereby generating random numbers of higher quality at a faster rate. This approach also paves the way for new design exploration strategies for PLL-TRNG. The source code of our implementation is open source and available online for reproducibility and reuse.
Brice Colombier, Nathalie Bochard, Florent Bernard, Lilian Bossuet
DATE4
2020 Cross Layer Fault Simulations for Analyzing the Robustness of RTL Designs in Airborne Systems
abstract
Embedded systems in critical applications are constrained by very strict standards. Safety analysis (e.g., Failure Mode and Effect Analysis) of these systems are often empirically done and mainly based on engineer experience. Many fault injection techniques exist to evaluate the robustness of Register Transfer Level (RTL) hardware designs, but, when the designs interact with software components (e.g., micro-controllers) or are embedded in complex systems, fault simulations or emulations can be very time consuming. High level system modeling can speed up the analysis of fault propagation through the whole system but raises some realism issues. In this paper, we propose a cross-layer fault simulation method to perform the robustness evaluation of RTL architectures used in critical embedded systems. This method uses both fault simulation in RTL and Transaction Level Model (TLM) descriptions to make a trade-off between simulation time and the realism of the simulated high level faulty behaviors. Early results on an airborne case study are discussed.
Julie Roux, Vincent Beroulle, Katell Morin-Allory, Régis Leveugle, Lilian Bossuet, Frédéric Cézilly, Frédéric Berthoz, Gilles Genévrier, François Cerisier
DDECS5
2020 Pipelined Hardware Implementation of COPA, ELmD, and COLM
abstract
Authenticated encryption algorithms offer privacy, authentication, and data integrity, as well. In recent years, they have received special attention after the call for submissions of Competition for Authenticated Encryption: Security, Applicability, and Robustness (CAESAR) was published. The CAESAR goal is to generate a portfolio with recommendations of authenticated encryption algorithms for three different scenarios: Lightweight, high speed, and defense in deep. ELmD and COPA are two on-line authenticated encryption algorithms submitted to CAESAR; because of their similarities, they were merged as COLM during the third-round of CAESAR. COLM is a finalist in the use case 3 defense in depth. ELmD, COPA, and COLM are based on the ECB-mix-ECB structure, which is highly parallelizable and pipelineable. In this paper, we present optimized single-chip implementations of ELmD, COPA, and COLM using pipelining. For ELmD, we present implementations for eight combinations of its parameters set: For intermediate tags, fixed, variable tag length, and 10 and 6 AES rounds. COLM implementation is for variable tag length without intermediate tags. In the case of COPA, it does not have parameters set. The implementation results with a Xilinx Virtex 6 FPGA show that ELmD is the best option concerning area and speed for single-chip implementation. The area of COPA and COLM are 1.65 and 1.69 times ELmD's respectively. Regarding throughput, the range of our implementations goes from 33.34 Gbits/s for COLM to more than 35 Gbits/s for several versions of ELmD.
Lilian Bossuet, Cuauhtemoc Mancillas-López, Brisbane Ovilla-Martínez
IEEE Trans. Computers1
2019 The Security of ARM TrustZone in a FPGA-Based SoC
abstract
Cybersecurity of embedded systems has become a major challenge for the development of the Internet of Things, of Cloud computing and other trendy applications without devoting a significant part of the design budget to industrial players. Technologies like TrustZone, provided by ARM, support a Trusted Execution Environment (TEE) software architecture and are inexpensive integrated solutions. While this technology allows isolation and secure execution of critical software applications (e.g., banking), recent preliminary works highlighted some security breaches or limitations when the ARM processors are embedded in a FPGA-based heterogeneous SoCs such as the Xilinx Zynq or Intel SoC FPGA devices. This paper highlights the security issue of such complex SoCs and details six efficient attacks on the ARM TrustZone extension in the SoC. A prototype system design on a Xilinx Zynq SoC is the target of the attacks presented in this paper but they could be adapted to other SoCs. This paper also includes recommendations and security solutions to design a trustworthy embedded system with a FPGA-based heterogeneous SoC.
El Mehdi Benhani, Lilian Bossuet, Alain Aubert
IEEE Trans. Computers2
2018 Implementation and Characterization of a Physical Unclonable Function for IoT: A Case Study With the TERO-PUF
abstract
Today, life is becoming increasingly connected. From TVs to smartphones, including vehicles, buildings, and household appliances, everything is interconnected in what we call the “Internet of Things” (IoT). IoT is now part of our life and we have to deal with it. More than ten billion devices are already connected and five times more are expected to be deployed in the next five years. While deployment and integration of IoT is expanding, one of the main challenge is to provide practical solutions to security, privacy, and trust issues in IoT. Protection and security mechanisms need to include features such as interoperability and scalability but also traceability, authentication, and access control while remaining lightweight. Among the most promising approaches to such security mechanisms, physical unclonable functions (PUFs) provide a unique identifier for similar but different integrated circuits using some of their physical characteristics. These types of functions can thus be used to authenticate integrated circuits, provide traceability and access control. This paper presents a comprehensive case study of the transient effect ring oscillator (RO) PUF from its implementation on FPGAs to its complete characterization. The implementation of the PUF is detailed for two different families of FPGAs: 1) Xilinx Spartan 6 and 2) Altera Cyclone V. All the metrics used for the characterization are explained in detail and the results of the characterization include robustness to environmental parameters including variations in temperature and voltage. Finally, we compare our results with those obtained for another PUF: the RO PUF. All the design files are available online to ensure repeatability and enable comparison of our contribution with other studies.
Cédric Marchand 0002, Lilian Bossuet, Ugo Mureddu, Nathalie Bochard, Abdelkarim Cherkaoui, Viktor Fischer
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2017 Complete activation scheme for FPGA-oriented IP cores design protection
abstract
Intellectual Property (IP) illegal copying is a major threat in today's integrated circuits industry which is massively based on a design-and-reuse paradigm. In order to fight this threat, a designer must track how many times an IP has been instantiated. Moreover, illegal copies of an IP must be unusable. We propose a hardware/software scheme which allows a designer to remotely activate an IP with minimal area overhead. The software modifies the IP efficiently and can handle very large netlists. Unique identification of hardware instances is achieved by integrating a TERO-PUF along with a lightweight key reconciliation module. A cryptographic core guarantees security and triggers a logic locking/masking module which makes the IP unusable unless the correct encrypted activation word is applied.
Brice Colombier, Ugo Mureddu, Marek Laban, Oto Petura, Lilian Bossuet, Viktor Fischer
FPL5
2017 A comprehensive hardware/software infrastructure for IP cores design protection
abstract
Core-based design, which is widely used nowadays due to the high complexity of electronic systems, comes with specific threats against design data. Cases of intellectual property infringement and illegal copying have risen in the last decade. To fight this threat, must be aware of how many instantiations of an IP core have been carried out. Based on this, illegal copies can be detected and precise metering is achieved. To work toward this goal, we propose a comprehensive hardware/software infrastructure that allows a designer to modify an IP core to make it remotely activable later on when it is implemented on an FPGA. We focus on industrial applicability and ease of integration. On the one hand, hardware implementation on FPGA focuses on achieving a medium level of security at reduced cost. On the other hand, the software side aims at computational efficiency and industrial applicability for smooth integration into EDA tools.
Brice Colombier, Lilian Bossuet, Ugo Mureddu, David Hély
FPT2
2017 Restoration protocol: Lightweight and secur devices authentication based on PUF
abstract
Several authentication protocols based on Physically Unclonable Functions (PUF) have been proposed to authenticate hardware devices. The preliminary steps of a PUF-based authentication protocol are to obtain and store on a remote server the reference device's secret identifier (known as the PUF response) by the manufacturer. This reference response is compared (accurately or with a small threshold) with the response given by the device during its normal use. However, the responses provided by a PUF are not fully stable over time and with environmental variations. Consequently, correction mechanisms have to be used to increase the PUF responses steadiness. In most of the proposed correction schemes in the literature, the correction mechanisms consume more area than the PUF; hence, these solutions are unfeasible for area cost restricted devices such as consumer items used for IoT applications. This article presents the use of a preliminary PUF noise characterization to perform an ultra-lightweight device authentication. The proposed PUF-based authentication protocol, called restoration protocol, adapts the reference PUF response (stored on the remote server) to the generated PUF response on the device without leaking any information to an adversary. In addition, the restoration protocol is implemented without the need of an expensive hardware system on the device side. The workload is performed only on the server side, which has more resources. The security analysis and the experimental validation results using real PUF responses obtained from TERO-PUF demonstrate the viability of the proposed protocol.
Brisbane Ovilla-Martínez, Lilian Bossuet
VLSI-SoC2
2017 Key Reconciliation Protocols for Error Correction of Silicon PUF Responses
abstract
Physical unclonable functions (PUFs) are promising primitives for the lightweight authentication of an integrated circuit (IC). Indeed, by extracting an identifier from random process variations, they allow each instance of a design to be uniquely identified. However, the extracted identifiers are not stable enough to be used as is, and hence, need to be corrected first. This is currently achieved using error-correcting codes in secure sketches that generate helper data through a one-time procedure. As an alternative, we propose key reconciliation protocols. This interactive method, originating from quantum key distribution, allows two entities to correct errors in their respective correlated keys by discussing over a public channel. We believe that this can also be used by a device and a remote server to agree on two different responses to the same challenge from the same PUF obtained at different times. This approach has the advantage of requiring very few logic resources on the device side. The information leakage caused by the key reconciliation process is limited and easily computable. Results of implementation on field-programmable gate array (FPGA) targets are presented, showing that it is the most lightweight error-correction module to date.
Brice Colombier, Lilian Bossuet, Viktor Fischer, David Hély
IEEE Trans. Inf. Forensics Secur.2
2016 Enhanced TERO-PUF Implementations and Characterization on FPGAs (Abstract Only)
abstract
Physical unclonable functions (PUF) are a promising approach in design for trust and security. A PUF derives a unique identifier using physical characteristics of different dies containing an identical circuit, so it can be used to authenticate chips and for identification. The transient effect ring oscillator (TERO) PUF is based on the extraction of entropy due to process variations by comparing TERO cells characteristics. The TERO cell is designed and implemented with a symmetric structure that requires special selection of the gates used and the delays of all connections inside the cell. Implementing this cell in FPGAs is challenging because the structure of FPGAs does not automatically allow designers to choose connections between elements. However, by manually specifying constraints and using specific features of the target FPGA family, the symmetry of the TERO cell can be established and reproduced in larger designs. In this work, the design of the TERO cell is described for two different FGPA technologies (45nm Xilinx Spartan 6 and 28nm Altera Cyclone V). The statistical characterization of the TERO-PUF with the two targeted FPGAs has resulted in a uniqueness of 48.46% with Spartan 6 and 47.62% with Cyclone V. The result for the steadiness is 2.63% with Spartan 6 and 1.8% with Cyclone V. These results are close to the results obtained by several works that use ring oscillator RO-PUF which are considered the best candidate for PUF implementation on FPGAs. However, TERO-PUF is less sensitive to electromagnetic analysis than RO-PUF. Additionally, unlike RO-PUF, TERO-PUF is able to generate multiple bits per challenge (from one to three) and we have shown during the statistical characterization that the TERO-PUF provides from 0.85 to 1 bits of entropy per response bit.
Cédric Marchand 0002, Lilian Bossuet, Abdelkarim Cherkaoui
FPGA2
2016 A survey of AIS-20/31 compliant TRNG cores suitable for FPGA devices
abstract
FPGAs are widely used to integrate cryptographic primitives, algorithms, and protocols in cryptographic systems-on-chip (CrySoC). As a building block of CrySoCs, True Random Number Generators (TRNGs) exploit analog noise sources in electronic devices to generate confidential keys, initialization vectors, challenges, nonces, and random masks in cryptographic protocols. TRNGs aimed at cryptographic applications must fulfill the security requirements defined in the German Federal Bureau for Information Security's (BSI) recommendations AIS-20/31, which has become a de facto standard in Europe. Many TRNG cores have already been published, only a few of which are suitable for FPGAs and even fewer comply with AIS-20/31. Here we present the results of the implementation of AIS-20/31 compliant TRNG cores in three FPGA families: Xilinx Spartan 6, Altera Cyclone V and Microsemi SmartFusion 2. In addition to common design parameters like area, bit rate and power/energy consumption, we compare and discuss the feasibility of generator cores in different FPGAs and the statistical quality of their output. These results will help designers select the best generator and the device family to match the requirements of the data security application. To ensure reproducibility of the results, the open source VHDL code of all generators adapted to individual families can be downloaded from the dedicated web page.
Oto Petura, Ugo Mureddu, Nathalie Bochard, Viktor Fischer, Lilian Bossuet
FPL5
2016 ELmD: A Pipelineable Authenticated Encryption and Its Hardware Implementation
abstract
Authenticated encryption schemes which resist misuse of nonce at some desired level of privacy are two-pass or Mac-then-Encrypt constructions (inherently inefficient but provide full privacy) and online constructions like McOE, sponge-type authenticated encryptions (such as duplex) and COPA. Only the last one is almost parallelizable except that for associated data processing, the final block-cipher call is sequential (it needs to wait for the encryption of all the previous ones). In this paper, we design a new online secure authenticated encryption, called ELmD or Encrypt-Linear mix-Decrypt, which is completely (two-stage) parallel (even in associated data) and fully pipeline implementable. It also provides full privacy when associated data is not repeated. Like COPA, our construction is based on EME, an Encrypt-Mix-Encrypt type SPRP construction (secure against chosen plaintext and ciphertext). But unlike EME, we have used an online computable efficient linear mixing instead of a non-linear mixing. We have also provided the hardware implementation of the construction and compare the performance with similar constructions like COPA and EME2.
Lilian Bossuet, Nilanjan Datta, Cuauhtemoc Mancillas-López, Mridul Nandi
IEEE Trans. Computers1
2016 Comments on "A PUF-FSM Binding Scheme for FPGA IP Protection and Pay-per-Device Licensing"
abstract
IP protection is a recent field of research. If passive protection schemes, mainly IP watermarking and fingerprinting, have been studied for more than fifteen years, active protection schemes using remote activation / unlocking / metering of IPs are highlighted by several recent works. Like any other new field of research, new concepts appear with sometimes not such good ideas. IP unlocking scheme without cryptography, as recently proposed in this journal, is one of these ideas. Expecting to obtain low overhead and high security this way is very hard. This comment proves this by presenting a short yet deep study.
Lilian Bossuet, Brice Colombier
IEEE Trans. Inf. Forensics Secur.1
2016 Design, Evaluation, and Optimization of Physical Unclonable Functions Based on Transient Effect Ring Oscillators
abstract
This paper proposes a theoretical study and a full overview of the design, evaluation, and optimization of a PUF based on transient element ring oscillators (TERO-PUF). We show how, by following some simple design rules and strategies, designers can build and optimize a TERO-PUF with the state-of-the-art PUF characteristics in a standard CMOS technology. To this end, we analyzed the uniqueness, steadiness, and randomness of responses generated from 30 test chips in a CMOS 350-nm process in nominal and corner voltage and temperature conditions. Response generation schemes are proposed and discussed to optimize the PUF performances and reduce its area without noticeable loss in its output quality. In particular, we show that the large area of the basic blocks in the TERO-PUF is balanced by the high level of entropy extracted in each basic block. Guidelines are provided to balance reliability and randomness of the responses and the design area.
Abdelkarim Cherkaoui, Lilian Bossuet, Cédric Marchand 0002
IEEE Trans. Inf. Forensics Secur.2
2015 Functional Locking Modules for Design Protection of Intellectual Property Cores
abstract
IP cores are now widely used as building blocks in the design of electronic systems. Moreover, since FPGAs are increasingly powerful and contain millions of logic cells, they are now a platform of choice for such electronic systems. Due to their reconfigurability, they are particularly suited to receiving IP cores. However, for the current IP core distribution process to be fair for all parties, the designer needs to maintain control over his IP to limit illegal copying and non-contracted reuse. To this end, a key point is functional locking, which can be used remotely to render the circuit practically useless. Current state-of-the-art lacks a comprehensive comparison of the different locking points that can be found on a usual IP core. This paper presents the first comparative study of the performance of IP core locking schemes.
Brice Colombier, Lilian Bossuet
FCCM2
2015 Contactless transmission of intellectual property data to protect FPGA designs
abstract
Over the past 10 years, the designers of intellectual properties (IP) have faced increasing threats including illegal copy or cloning, counterfeiting, reverse-engineering. This is now a critical issue for the microelectronics industry, mainly for fabless designers and FPGA designers. The design of a secure, efficient, lightweight protection scheme for design data is a serious challenge for the hardware security community. In this context, this paper presents the first ultra-lightweight transmitter using side channel leakage based on electromagnetic emanation to send embedded IP identity discreetly and quickly. In addition, we present our electromagnetic test bench and a coherent demodulation method using slippery window spectral analysis to recover data outside the device. The hardware resources occupied by the transmitter represent less than 0.022% of a 130 nm Microsemi Fusion FPGA. Experimental results show that the demodulation method success to provide IP data with a bit rate equal to 500 Kbps.
Lilian Bossuet, Viktor Fischer, Pierre Bayon
VLSI-SoC1
2014 Electromagnetic analysis and fault injection onto secure circuits
abstract
Implementation attacks are a major threat to hardware cryptographic implementations. These attacks exploit the correlation existing between the computed data and variables such as computation time, consumed power, and electromagnetic (EM) emissions. Recently, the EM channel has been proven as an effective passive and active attack technique against secure implementations. In this paper, we resume the recent results obtained on this subject, with a particular focus on EM as a fault injection tool.
Paolo Maistri, Régis Leveugle, Lilian Bossuet, Alain Aubert, Viktor Fischer, Bruno Robisson, Nicolas Moro, Philippe Maurine, Jean-Max Dutertre, Mathieu Lisart
VLSI-SoC3
2013 Teaching FPGA security
abstract
Teaching FPGA security to electrical engineering students is new at graduate level. It requires a wide field of knowledge and a lot of time. This paper describes a compact course on FPGA security that is available to electrical engineering master's students at the Saint-Etienne Institute of Telecom, University of Lyon, France. It is intended for instructors who wish to design a new course on this topic. The paper reviews the motivation for the course, the pedagogical issues involved, the curriculum, the lab materials and tools used, and the results. Details are provided on two original lab sessions, in particular, a compact lab that requires students to perform differential power analysis of FPGA implementation of the AES symmetric cipher.
Lilian Bossuet
FPT1
2013 Electromagnetic analysis on ring oscillator-based true random number generators
abstract
Security of implementation of ciphers in hardware has already been well studied, nevertheless ciphers are not the only hardware block used for cryptography. True random number generators (TRNGs) are also significant cryptography blocks since they are used to provide secret keys, random protection masks, initial values to other security blocks such as ciphers. The security of TRNG implementations is thus of paramount importance. Recently, electromagnetic channel has been used to efficiently attack ring oscillator based TRNG by fault injection. The work presented in this paper shows that by analyzing electromagnetic emanation of the TRNG under attack in varying conditions, it is possible to obtain significant information on the TRNG such as its position and oscillator frequency, in order to improve the previously published electromagnetic attack.
Pierre Bayon, Lilian Bossuet, Alain Aubert, Viktor Fischer
ISCAS2
2012 An Easy-to-Design PUF Based on a Single Oscillator: The Loop PUF
abstract
This paper presents an easy to design Physically Unclonable Function (PUF). The proposed PUF implementation is a loop composed of N identical and controllable delay chains which are serially assembled in a loop to create a single ring oscillator. The frequency discrepancies resulting from the oscillator driven by complementary combinations of the delay chains allows to characterize one device. The presented PUF, nicknamed the Loop PUF (LPUF), returns a frequency comparison of loops made of N delay chains (N ≥ 2). The comparisons are done sequentially on the same structure. Unlike others PUFs based on delays, there is no specific routing constraints. Hence the LPUF is particularly flexible and easy to design. The basic use of the Loop PUF is to generate intrinsic device keys for cryptographic algorithms. It can also be used to generate challenge response pairs for simple authentication. Experiments have been carried out on CYCLONE II FPGAs to assess the performance of the LPUF, such as randomness, uniqueness and steadiness. They clearly show both the easiness of design and the quality level of the LPUF. The measurement time vs steadiness, as well as resistance against side-channel and modeling attacks are discussed.
Zouha Cherif, Jean-Luc Danger, Sylvain Guilley, Lilian Bossuet
DSD4
2012 Secure Extension of FPGA General Purpose Processors for Symmetric Key Cryptography with Partial Reconfiguration Capabilities
abstract
In data security systems, general purpose processors (GPPs) are often extended by a cryptographic accelerator. The article presents three ways of extending GPPs for symmetric key cryptography applications. Proposed extensions guarantee secure key storage and management even if the system is facing protocol, software and cache memory attacks. The system is partitioned into processor, cipher, and key memory zones. The three security zones are separated at protocol, system, architecture and physical levels. The proposed principle was validated on Altera NIOS II, Xilinx MicroBlaze and Microsemi Cortex M1 soft-core processor extensions. We show that stringent separation of the cipher zone is helpful for partial reconfiguration of the security module, if the enciphering algorithm needs to be dynamically changed. However, the key zone including reconfiguration controller must remain static in order to maintain the high level of security required. We demonstrate that the principle is feasible in partially reconfigurable field programmable gate arrays (FPGAs) such as Altera Stratix V or Xilinx Virtex 6 and also to some extent in FPGAs featuring hardwired general purpose processors such as Cortex M3 in Microsemi SmartFusion FPGA. Although the three GPPs feature different data interfaces, we show that the processors with their extensions reach the required high security level while maintaining partial reconfiguration capability.
Lubos Gaspar, Viktor Fischer, Lilian Bossuet, Robert Fouquet
ACM Trans. Reconfigurable Technol. Syst.3
2011 Cryptographic Extension for Soft General-Purpose Processors with Secure Key Management
abstract
General-purpose processors are not suitable for secure cryptographic key management. Secret keys are usually stored in the internal registers of the processor, and simple attacks on protocols, software/firmware or cache memory can often lead to key disclosure causing a system security failure. The paper presents a novel principle of processor extensions that enable secure key management. This principle is based on the creation and physical separation of three security zones: processor, cipher and key storage. In each of the three zones, the secret keys are manipulated in a different manner - as ordinary data or keys, in clear or encrypted. In order to increase security, the security zones are separated from each other on the protocol, architectural and physical level. The proposed principle is validated as extensions to both NIOS II and MicroBlaze processors. The NIOS II processor needs fewer clock cycles per data block encryption, because the security module is included in the processor's data path. The data path of the MicroBlaze is unchanged, and thus shorter, but additional clock cycles are necessary for data transfers between the processor and the security module. Although the interfacing is different, both processors attain the required high security level.
Lubos Gaspar, Viktor Fischer, Lilian Bossuet, Milos Drutarovský
FPL3
2008 A new orthogonal online digital calibration for time-interleaved analog-to-digital converters
abstract
Modern communication technologies need faster analog-to-digital converters (ADC). To significantly increase the sampling rate of an ADC, time-interleaved ADC (TIADC) is an efficient solution. A M-channels TIADC is composed of M ADCs which operate at interleaved sampling times. Due to the manufacturing process, the main drawback of a TIADC system is that the M ADCs are not exactly the same. This means that offset, gain and time mismatch errors are introduced. As a result, these errors cause distortions in the output sampled signal and introduce unwanted tones and noise, and hence, reduce the spurious free dynamic range (SFDR) as well as the signal to noise ratio (SNR). In this paper, we propose a new orthogonal online digital calibration, for timing skew, offset and gain mismatches, based on Code Division Multiple Access (CDMA) technique already used in communications. Our calibration is online, this means that errors can be estimated while the ADC is running. Since most of the calibration processes are carried out on the digital outputs, very little change is needed on the analog part of the ADC. Simulations results showed the efficiency of our proposed calibration architecture.
Guillaume Ferré, Maher Jridi, Lilian Bossuet, Bertrand Le Gal, Dominique Dallet
ISCAS3
2008 Reconfigurable Hardware for High-Security/ High-Performance Embedded Systems: The SAFES Perspective
abstract
Embedded systems present significant security challenges due to their limited resources and power constraints. This paper focuses on the issues of building secure embedded systems on reconfigurable hardware and proposes a security architecture for embedded systems (SAFES). SAFES leverages the capabilities of reconfigurable hardware to provide efficient and flexible architectural support for security standards and defenses against a range of hardware attacks. The SAFES architecture is based on three main ideas: (1) reconfigurable security primitives; (2) reconfigurable hardware monitors; and (3) a hierarchy of security controllers at the primitive, system and executive level. Results are presented for reconfigurable AES and RC6 security primitives and highlight the value of such an architecture. This paper also emphasizes that reconfigurable hardware is not just a technology for hardware accelerators dedicated to security primitives as has been focused on by most studies but a real solution to provide high-security and high-performance for a system.
Guy Gogniat, Tilman Wolf, Wayne P. Burleson, Jean-Philippe Diguet, Lilian Bossuet, Romain Vaslin
IEEE Trans. Very Large Scale Integr. Syst.5
2006 A Low Cost Alternative Method for Harmonics Estimation in a BIST Context
abstract
Spectral analysis represents a key component in signal processing. The on-chip implementation of classical spectral estimation techniques is generally not considered as a viable BIST solution because of the huge amount of required additional circuitry (multipliers, complex operators). This paper describes a new method for spectral parameter estimation allowing the extraction of the first harmonic with only very simple operators. This method is based on Fourier series expansion and a piecewise algorithm. The results are validated using simulations and experiments, and the method showed relevant results to an embedded solution
Vincent Fresnaud, Lilian Bossuet, Dominique Dallet, Serge Bernard, Jean-Marie Janik, B. Agnus, Philippe Cauvet, Ph. Gandy
ETS2
2006 Design Space Pruning Through Early Estimations of Area/Delay Tradeoffs for FPGA Implementations
abstract
Early performance feedback and design space exploration of complete field-programmable gate array (FPGA) designs are still time consuming tasks. This paper proposes an original methodology based on estimations to reduce the impact on design time. It promotes a hierarchical exploration to mitigate the complexity of the exploration process. Therefore, this work takes place before any design step, such as compilation or behavioral synthesis, where the specification is still provided as a C program. The goal is to provide early area and delay evaluations of many register-transfer level (RTL) implementations to prune the design space. Two main steps compose the flow: 1) a structural exploration step defines several RTL implementations, and 2) a physical mapping estimation step computes the mapping characteristics of these onto a given FPGA device. For the structural exploration, a simple yet realistic RTL model reduces the complexity and permits a fast definition of solutions. At this stage, it focuses on the computation parallelism and memory bandwidth. Advanced optimizations using for instance loop tiling, scalar replacement, or data layout are not considered. For the physical estimations, an analytical approach is used to provide fast and accurate area/delay tradeoffs. The paper also do not consider the impact of routing on critical paths or other optimizations. The reduction of the complexity allows the evaluation of key design alternatives, namely target device and parallelism that can also include the effect of resource allocation, bitwidth, or clock period. Due to this, a designer can quickly identify a reliable subset of solutions for which further refinement can be applied to enhance the relevance of the final architecture and reach a better use of FPGA resources, i.e., an optimal level of performance. Experiments performed with Xilinx (VirtexE) and Altera (Apex20K) FPGAs for a two-dimensional Discrete Wavelet Transform and a G722 speech coder lead to an average error of 10% for temporal values and 18% for area estimations
Sébastien Bilavarn, Guy Gogniat, Jean Luc Philippe, Lilian Bossuet
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2004 Dynamically Configurable Security for SRAM FPGA Bitstreams
abstract
Summary form only given. We propose a solution to improve the security of SRAM FPGAs through bitstream encryption. This proposition is distinct from other works because it uses the latest capabilities of SRAM FPGAs like partial and dynamic reconfiguration. It doesn't need any external battery to store the secret key. It opens a new way of application partitioning according to the security policy.
Lilian Bossuet, Guy Gogniat, Wayne P. Burleson
IPDPS1
2003 Communication Costs Driven Design Space Exploration for Reconfigurable Architectures
Lilian Bossuet, Guy Gogniat, Jean Luc Philippe
FPL1