Vincent Grosso

dblp:132/0856 · DBLP profile ↗
← Back
27ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-3874-7527ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 7 first-author · 6 since 2021Systems, architecture and hardware · 4 · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2025 SIFA on Nonce-based Authenticated Encryption: When Does It Fail? Application to Ascon
abstract
In nonce-based authenticated encryption schemes, fault attacks such as differential fault analysis are not applicable to due to the uniqueness of the nonce. In this context, Dobraunig et al. (SAC 2018) showed that Statistical Ineffective Fault Attacks (SIFA) remain applicable and powerful. The authors proposed a SIFA-based attack strategy targeting the initialization in nonce-based authenticated encryption schemes and demonstrated its practicality using a common fault method: instruction skip.In this work, we provide a more in-depth analysis of this attack strategy, with a focus on instruction skip as the fault method. First, we model common instruction skip scenarios in practice and formalize the probability that a fault is ineffective. Our analysis reveals that this probability depends on the instruction type and the device architecture. Notably, we show that it is practically inefficient to obtain a sufficient number of ineffective faults for SIFA when skipping an XOR instruction on 32-bit or 64-bit systems, where register data tends to be uniformly distributed. Second, we prove that, in certain authenticated encryption implementations, the intermediate value targeted by the attack unexpectedly remains unbiased under ineffective faults, making SIFA inapplicable. As a case study, we demonstrate this behavior in an 8-bit Ascon implementation.
Viet Sang Nguyen, Vincent Grosso, Pierre-Louis Cayrel
FDTC2
2025 Side-Channel Extraction of Dataflow AI Accelerator Hardware Parameters
abstract
Dataflow neural network accelerators efficiently process AI tasks on FPGAs, with deployment simplified by ready-to-use frameworks and pre-trained models. However, this convenience makes them vulnerable to malicious actors seeking to reverse engineer valuable Intellectual Property (IP) through Side-Channel Attacks (SCA). This paper proposes a methodology to recover the hardware configuration of dataflow accelerators generated with the FINN framework. Through unsupervised dimensionality reduction, we reduce the computational overhead compared to the state-of-the-art, enabling lightweight classifiers to recover both folding and quantization parameters. We demonstrate an attack phase requiring only 337 ms to recover the hardware parameters with an accuracy of more than 95% and 421 ms to fully recover these parameters with an averaging of 4 traces for a FINN-based accelerator running a CNN, both using a random forest classifier on side-channel traces, even with the accelerator dataflow fully loaded. This approach offers a more realistic attack scenario than existing methods, and compared to SoA attacks based on tsfresh, our method requires 940x and 110x less time for preparation and attack phases, respectively, and gives better results even without averaging traces.
Guillaume Lomet, Rubén Salvador, Brice Colombier, Vincent Grosso, Olivier Sentieys, Cédric Killian
IOLTS4
2025 Algebraic Key-Recovery Side-Channel Attack on Classic McEliece
Michaël Bulois, Pierre-Louis Cayrel, Vlad Dragoi, Vincent Grosso
SAC4
2025 Correlation Power Analysis on Ascon with Multi-Bit Selection Function
abstract
International audience
Viet Sang Nguyen, Vincent Grosso, Pierre-Louis Cayrel
SECRYPT2
2024 Lightweight Active Fences for FPGAs
abstract
The use of active fences has been proposed as a protection against remote power analysis attacks. This counter-measure relies on reserving a reconfigurable space within the FPGA which will separate it into sub-regions. These “fences” will then generate some electrical interference to hinder the performance of an attack. As FPGAs can be configured in multiple ways, there are different approaches for connecting the hardware inside the fence. In this work, we describe a LUT-based configuration which can achieve the same instantaneous power drop as a ring oscillator bank with less LUTs. This contributes to reducing the hardware costs of active fences.
Anis Fellah-Touta, Lilian Bossuet, Vincent Grosso, Carlos Andres Lara-Nino
VLSI-SoC3
2023 Deep Stacking Ensemble Learning Applied to Profiling Side-Channel Attacks
Dorian Llavata, Eleonora Cagli, Rémi Eyraud, Vincent Grosso, Lilian Bossuet
CARDIS4
2023 BALoo: First and Efficient Countermeasure Dedicated to Persistent Fault Attacks
abstract
Persistent fault analysis is a novel and efficient cryptanalysis method. The persistent fault attacks take advantage of a persistent fault injected in a non-volatile memory, then present on the device until the reboot of the device. Contrary to classical physical fault injection, where differential analysis can be performed, persistent fault analysis requires new analyses and dedicated countermeasures. Persistent fault analysis requires a persistent fault injected in the S-box such that the bijective characteristic of the permutation function is not present anymore. In particular, the analysis will use the non-uniform distribution of the S-box values: when one of the possible S-box values never appears and one of the possible S-box values appears twice. In this paper, we present the first dedicated protection to prevent persistent fault analysis. This countermeasure, called BALoo for Bijection Assert with Loops, checks the property of bijectivity of the S-box. We show that this countermeasure has a 100% fault coverage for the persistent fault analysis, with a very small software overhead (memory overhead) and reasonable hardware overhead (logical resources, memory and performance). To evaluate the overhead of BALoo, we provide experimental results obtained with the software and the hardware (FPGA) implementations of an AES-128.
Pierre-Antoine Tissot, Lilian Bossuet, Vincent Grosso
IOLTS3
2022 Self-timed Masking: Implementing Masked S-Boxes Without Registers
Mateus Simões, Lilian Bossuet, Nicolas Bruneau, Vincent Grosso, Patrick Haddad, Thomas Sarno
CARDIS4
2022 Integer Syndrome Decoding in the Presence of Noise
abstract
Code-based cryptography received attention after the NIST started the post-quantum cryptography standardization process in 2016. A central NP-hard problem is the binary syndrome decoding problem, on which the security of many code-based cryptosystems lies. The best known methods to solve this problem all stem from the information-set decoding strategy. A recent line of work considers augmented versions of this strategy, with hints provided by side-channel information. In this work, we consider the integer syndrome decoding problem, where the integer syndrome is available but might be noisy. We study how the performance of the decoder is affected by the noise. We provide experimental results on cryptographic parameters for the Classic McEliece and BIKE cryptosystems, which are in the fourth round of the NIST standardization process.
Vlad Dragoi, Brice Colombier, Pierre-Louis Cayrel, Vincent Grosso
ITW4
2022 Profiled Side-Channel Attack on Cryptosystems Based on the Binary Syndrome Decoding Problem
abstract
The NIST standardization process for post-quantum cryptography has been drawing the attention of researchers to the submitted candidates. One direction of research consists in implementing those candidates on embedded systems and that exposes them to physical attacks in return. TheClassic McEliececryptosystem, which is among the four finalists of round 3 in the Key Encapsulation Mechanism category, builds its security on the hardness of the syndrome decoding problem, which is a classic hard problem in code-based cryptography. This cryptosystem was recently targeted by a laser fault injection attack leading to message recovery. Regrettably, the attack setting is very restrictive and it does not tolerate any error in the faulty syndrome. Moreover, it depends on the very strong attacker model of laser fault injection, and does not apply to optimised implementations of the algorithm that make optimal usage of the machine words capacity. In this article, we propose a to change the angle and perform a message-recovery attack that relies on side-channel information only. We improve on the previously published work in several key aspects. First, we show that side-channel information, obtained with power consumption analysis, is sufficient to obtain an integer syndrome, as required by the attack framework. This is done by leveraging classic machine learning techniques that recover the Hamming weight information very accurately. Second, we put forward a computationally-efficient method, based on a simple dot product and information-set decoding algorithms, to recover the message from the, possibly inaccurate, recovered integer syndrome. Finally, we present a masking countermeasure against the proposed attack.
Brice Colombier, Vlad Dragoi, Pierre-Louis Cayrel, Vincent Grosso
IEEE Trans. Inf. Forensics Secur.4
2021 Improving Deep Learning Networks for Profiled Side-channel Analysis Using Performance Improvement Techniques
abstract
The use of deep learning techniques to perform side-channel analysis attracted the attention of many researchers as they obtained good performances with them. Unfortunately, the understanding of the neural networks used to perform side-channel attacks is not very advanced yet. In this article, we propose to contribute to this direction by studying the impact of some particular deep learning techniques for tackling side-channel attack problems. More precisely, we propose to focus on three existing techniques: batch normalization, dropout, and weight decay, not yet used in side-channel context. By combining adequately these techniques for our problem, we show that it is possible to improve the attack performance, i.e., the number of traces needed to recover the secret, by more than 55%. Additionally, they allow us to have a gain of more than 34% in terms of training time. We also show that an architecture trained with such techniques is able to perform attacks efficiently even in the context of desynchronized traces.
Damien Robissout, Lilian Bossuet, Amaury Habrard, Vincent Grosso
ACM J. Emerg. Technol. Comput. Syst.4
2020 Mode-Level vs. Implementation-Level Physical Security in Symmetric Cryptography - A Practical Guide Through the Leakage-Resistance Jungle
Davide Bellizia, Olivier Bronchain, Gaëtan Cassiers, Vincent Grosso, Chun Guo 0002, Charles Momin, Olivier Pereira, Thomas Peters, François-Xavier Standaert
CRYPTO (1)4
2020 Friet: An Authenticated Encryption Scheme with Built-in Fault Detection
Thierry Simon, Lejla Batina, Joan Daemen, Vincent Grosso, Pedro Maat Costa Massolino, Kostas Papagiannopoulos, Francesco Regazzoni 0001, Niels Samwel
EUROCRYPT (1)4
2019 Optimal Collision Side-Channel Attacks
Cezary Glowacz, Vincent Grosso
CARDIS2
2018 Scalable Key Rank Estimation (and Key Enumeration) Algorithm for Large Keys
Vincent Grosso
CARDIS1
2018 Masking Proofs Are Tight and How to Exploit it in Security Evaluations
Vincent Grosso, François-Xavier Standaert
EUROCRYPT (2)1
2016 Strong 8-bit Sboxes with Efficient Masking in Hardware
Erik Boss, Vincent Grosso, Tim Güneysu, Gregor Leander, Amir Moradi 0001, Tobias Schneider 0002
CHES2
2016 Simple Key Enumeration (and Rank Estimation) Using Histograms: An Integrated Approach
Romain Poussier, François-Xavier Standaert, Vincent Grosso
CHES3
2015 ASCA, SASCA and DPA with Enumeration: Which One Beats the Other and When?
Vincent Grosso, François-Xavier Standaert
ASIACRYPT (2)1
2015 Comparing Approaches to Rank Estimation for Side-Channel Security Evaluations
Romain Poussier, Vincent Grosso, François-Xavier Standaert
CARDIS2
2015 Simpler and More Efficient Rank Estimation for Side-Channel Security Assessment
Cezary Glowacz, Vincent Grosso, Romain Poussier, Joachim Schüth, François-Xavier Standaert
FSE2
2014 On the Cost of Lazy Engineering for Masked Software Implementations
Josep Balasch, Benedikt Gierlichs, Vincent Grosso, Oscar Reparaz, François-Xavier Standaert
CARDIS3
2014 Combining Leakage-Resilient PRFs and Shuffling - Towards Bounded Security for Small Embedded Devices
Vincent Grosso, Romain Poussier, François-Xavier Standaert, Lubos Gaspar
CARDIS1
2014 LS-Designs: Bitslice Encryption for Efficient Masked Software Implementations
Vincent Grosso, Gaëtan Leurent, François-Xavier Standaert, Kerem Varici
FSE1
2013 Low Entropy Masking Schemes, Revisited
Vincent Grosso, François-Xavier Standaert, Emmanuel Prouff
CARDIS1
2013 Block Ciphers That Are Easier to Mask: How Far Can We Go?
Benoît Gérard, Vincent Grosso, María Naya-Plasencia, François-Xavier Standaert
CHES2
2013 Masking vs. Multiparty Computation: How Large Is the Gap for AES?
Vincent Grosso, François-Xavier Standaert, Sebastian Faust
CHES1