EDBT 2026 Demo / reviewers in the wild / expert
Mustafa Khairallah
dblp:127/2364
· DBLP profile ↗
10ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0002-2144-4829ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Efficient Authentication Protocols from the Restricted Syndrome Decoding ProblemabstractIn this paper, we introduce an oracle version of the Restricted Syndrome Decoding Problem (RSDP) and propose novel authentication protocols based on the hardness of this problem. They follow the basic structure of the HB-family of authentication protocols and later improvements but demonstrate several advantages.An appropriate choice of multiplicative subgroup and ring structure gives rise to a very efficient hardware implementation compared to other Learning Parity with Noise based approaches. In addition, the new protocols also have lower key size, lower communication costs, and potentially better completeness/soundness compared to learning-based alternatives. This is appealing in the context of low-cost, low-powered authenticating devices such as radio frequency identification (RFID) systems. Lastly, we show that with additional assumptions, RSDP can be used to instantiate a Man-in-the-Middle secured authentication protocol. Thomas Johansson 0001, Mustafa Khairallah |
EuroS&P | 2 |
| 2024 | Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW Paradigm
Ashwin Jha 0001, Mustafa Khairallah, Mridul Nandi, Abishanka Saha |
EUROCRYPT (1) | 2 |
| 2024 | Fast Parallelizable Misuse-Resistant Authenticated Encryption - Low Latency (Decryption-Fast) SIV
Mustafa Khairallah |
SAC (2) | 1 |
| 2021 | DEFAULT: Cipher Level Resistance Against Differential Fault Attack
Anubhab Baksi, Shivam Bhasin, Jakub Breier, Mustafa Khairallah, Thomas Peyrin, Sumanta Sarkar, Siang Meng Sim |
ASIACRYPT (2) | 4 |
| 2021 | On the Cost of ASIC Hardware Crackers: A SHA-1 Case Study
Anupam Chattopadhyay, Mustafa Khairallah, Gaëtan Leurent, Zakaria Najm, Thomas Peyrin, Vesselin Velichkov |
CT-RSA | 2 |
| 2019 | Recruiting Fault Tolerance Techniques for Microprocessor SecurityabstractThe growing threat of various attacks on modern microprocessors and systems calls for major design overhauls ranging from plugging micro-architectural side channels such as due to speculative execution to implementing cryptographic accelerators for side-channel and fault attack resistance. In this paper, we suggest to focus on the similarities and the differences between fault tolerance techniques and countermeasures against attacks on security sensitive systems. Modern digital circuits and systems use a diverse set of techniques to ensure operational correctness in the presence of faults. From a security perspective, the goal is to ensure a set of stated security properties hold in the presence of 'security faults' (extending the notion of conventional faults to include injected faults as well as vulnerabilities such as passive side-channels). A point of note here is that under some security faults, the operational correctness may not be compromised. This paper advocates the re-purposing of some of the known fault tolerance techniques, and show how those can be useful for enhancing security in the presence of active side-channel attacks. As a simple illustration of these ideas, we present an experimental case study in fortifying a cryptographic sub-component of a RISC-V based secure system-on-chip, against a formidable fault attack called SIFA. Vinay B. Y. Kumar, Mustafa Khairallah, Anupam Chattopadhyay, Avi Mendelson |
ATS | 4 |
| 2019 | SoK: On DFA Vulnerabilities of Substitution-Permutation NetworksabstractRecently, the NIST launched a competition for lightweight cryptography and a large number of ciphers are expected to be studied and analyzed under this competition. Apart from the classical security, the candidates are desired to be analyzed against physical attacks. Differential Fault Analysis (DFA) is an invasive physical attack method for recovering key information from cipher implementations. Up to date, almost all the block ciphers have been shown to be vulnerable against DFA, while following similar attack patterns. However, so far researchers mostly focused on particular ciphers rather than cipher families, resulting in works that reuse the same idea for different ciphers. In this article, we aim at bridging this gap, by providing a generic DFA attack method targeting Substitution-Permutation Network (SPN) based families of symmetric block ciphers. We provide the overview of the state-of-the-art of the fault attacks on SPNs, followed by generalized conditions that hold on all the ciphers of this design family. We show that for any SPN, as long as the fault mask injected before a non-linear layer in the last round follows a non-uniform distribution, the key search space can always be reduced. This shows that it is not possible to design an SPN-based cipher that is completely secure against DFA, without randomization. Furthermore, we propose a novel approach to find good fault masks that can leak the key with a small number of instances. We then developed a tool, called Joint Difference Distribution Table (JDDT) for pre-computing the solutions for the fault equations, which allows us to recover the last round key with a very small number of pairs of faulty and non-faulty ciphertexts. We evaluate our methodology on various block ciphers, including PRESENT-80, PRESENT-128, GIFT-64, GIFT-128, AES-128, LED-64, LED-128, Skinny, Pride and Prince. The developed technique would allow automated DFA analysis of several candidates in the NIST competitio Mustafa Khairallah, Xiaolu Hou, Zakaria Najm, Jakub Breier, Shivam Bhasin, Thomas Peyrin |
AsiaCCS | 1 |
| 2018 | DFARPA: Differential fault attack resistant physical design automationabstractDifferential Fault Analysis (DFA), aided by sophisticated mathematical analysis techniques for ciphers and precise fault injection methodologies, has become a potent threat to cryptographic implementations. In this paper, we propose, to the best of the our knowledge, the first “DFA-aware” physical design automation methodology, that effectively mitigates the threat posed by DFA. We first develop a novel floorplan heuristic, which resists the simultaneous corruption of cipher states necessary for successful fault attack, by exploiting the fact that most fault injections are localized in practice. Our technique results in the computational complexity of the fault attack to shoot up to exhaustive search levels, making them practically infeasible. In the second part of the work, we develop a routing mechanism, which tackles more precise and costly fault injection techniques, like laser and electromagnetic guns. We propose a routing technique by integrating a specially designed ring oscillator based sensor circuit around the potential fault attack targets without incurring any performance overhead. We demonstrate the effectiveness of our technique by applying it on state of the art ciphers. Mustafa Khairallah, Rajat Sadhukhan, Radhamanjari Samanta, Jakub Breier, Shivam Bhasin, Rajat Subhra Chakraborty, Anupam Chattopadhyay, Debdeep Mukhopadhyay |
DATE | 1 |
| 2018 | On Hardware Implementation of Tang-Maitra Boolean Functions
Mustafa Khairallah, Anupam Chattopadhyay, Bimal Mandal, Subhamoy Maitra |
WAIFI | 1 |
| 2015 | New polynomial basis versatile multiplier over GF(2m) for low-power on-chip crypto-systemsabstractThis paper presents a low-power, reduced-area finite field multiplier over GF(2m) for ultra-low-power devices. The proposed design supports any field GF(2m) with low-weight irreducible polynomial. The different implementations presented in this paper support 99% of fields with prime m1024, and all standard elliptic curves consuming 28.7μW and 4μW respectively, using the TSMC 65nm technology library. The design is demonstrated to operate at frequencies up to 500 MHz, allowing various trade-offs between power, energy and performance. The proposed design is shown to use around 40% less area and 40% less power than the other designs proposed in the literature. Hence, it enables implementing more secure ciphers for almost the lower cost than other available designs. Mustafa Khairallah, Maged Ghoneima |
ISCAS | 1 |