EDBT 2026 Demo / reviewers in the wild / expert
Brice Colombier
dblp:138/3364
· DBLP profile ↗
16ranked-venue papers
7as first author
9since 2021 · last 2025
0000-0002-6028-3028ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 4 first-author · 4 since 2021Security and privacy · 7 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Low-Latency FFT/iFFT RTL Implementation for the FALCON Post-Quantum Signature AlgorithmabstractFALCON is one of the three post-quantum digital signature schemes that have been recently standardized by NIST due to the future threat that quantum computers pose to classical cryptographic schemes. Despite this, there is currently no full hardware register-transfer level (RTL) implementation of FALCON. One possible explanation is the rather unusual requirement for a double-precision floating-point Fast Fourier Transform (FFT), which is used in FALCON to speed up polynomial multiplication. In this article, we describe a full RTL implementation of the FFT and its inverse, on FPGA, tailored for the specific context of FALCON. Fitting in this specific cryptographic context, the implementation is also constant-time. The proposed hardware implementation achieves the best latency of the literature. This work paves the way for the first complete fine-tuned RTL implementation of FALCON as well as the security evaluation of such implementations against physical attacks. Alexandre Ortega, Lilian Bossuet, Brice Colombier |
FCCM | 3 |
| 2025 | Side-Channel Extraction of Dataflow AI Accelerator Hardware ParametersabstractDataflow neural network accelerators efficiently process AI tasks on FPGAs, with deployment simplified by ready-to-use frameworks and pre-trained models. However, this convenience makes them vulnerable to malicious actors seeking to reverse engineer valuable Intellectual Property (IP) through Side-Channel Attacks (SCA). This paper proposes a methodology to recover the hardware configuration of dataflow accelerators generated with the FINN framework. Through unsupervised dimensionality reduction, we reduce the computational overhead compared to the state-of-the-art, enabling lightweight classifiers to recover both folding and quantization parameters. We demonstrate an attack phase requiring only 337 ms to recover the hardware parameters with an accuracy of more than 95% and 421 ms to fully recover these parameters with an averaging of 4 traces for a FINN-based accelerator running a CNN, both using a random forest classifier on side-channel traces, even with the accelerator dataflow fully loaded. This approach offers a more realistic attack scenario than existing methods, and compared to SoA attacks based on tsfresh, our method requires 940x and 110x less time for preparation and attack phases, respectively, and gives better results even without averaging traces. Guillaume Lomet, Rubén Salvador, Brice Colombier, Vincent Grosso, Olivier Sentieys, Cédric Killian |
IOLTS | 3 |
| 2025 | Efficient Adaptive Multi-Level Privilege Partitioning With RTrustSoCabstractIn recent years, heterogeneous SoCs—comprised of multiple processor cores and programmable logic—have greatly progressed both complexity and performance. From a security point of view, this leads to an expansion of the attack surface exposed to adversaries. To address this issue, in this article, we propose a novel heterogeneous SoC architecture called RTrustSoC. Our proposal includes an innovative fully-reconfigurable post-deployment strategy for partitioning the SoC architecture into multiple exclusion levels—worlds—with customizable degrees of privilege. We aim to provide SoC designers with fine control over the security of the system by segregating trusted hardware components from third-party IPs with “on-demand” hardware isolation. Therefore, we expect that an RTrustSoC instance could evolve from a multi-world SoC to a fully trusted platform as IPs progressively develop. RTrustSoC also proposes a dynamic reconfigurable penalty system to monitor the third-party IPs and take measures in case of a detected abnormal behavior. Our experimental testing on an AMD-Xilinx Zynq-7000 SoC-FPGA showed the penalty of the proposed isolation strategy to be small, up to 1% in LUT and 0.7% Flip Flop utilization, thus enabling to an efficient security solution. RTrustSoC introduces a novel design paradigm, evolving from the binary notion of security—trusted vs untrusted—into a flexible set of worlds that can be adapted to any scenario. We demonstrate a real case scenario of RTrustSoC use on time-based cache memory attacks with implementation results. Raphaële Milan, Lilian Bossuet, Loïc Lagadec, Carlos Andres Lara-Nino, Brice Colombier, Théotime Bollengier |
IEEE Trans. Circuits Syst. I Regul. Pap. | 5 |
| 2023 | Microarchitectural Insights into Unexplained Behaviors Under Clock Glitch Fault Injection
Ihab Alshaer, Brice Colombier, Christophe Deleuze, Vincent Beroulle, Paolo Maistri |
CARDIS | 2 |
| 2022 | Variable-Length Instruction Set: Feature or Bug?abstractWith the increasing complexity of digital applications, the use of variable-length instruction sets became essential, in order to achieve higher code density and thus better performance. However, security aspects must always be considered, in particular with the significant improvement of attack techniques and equipment. Fault injection, in particular, is among the most interesting and promising attack techniques thanks to the recent advancements. In this article, we provide proper characterization, at the instruction set architecture (ISA) level, for several faulty behaviors that can be obtained when targeting a variable-length instruction set. We take into account the binary encoding of instructions, and show how the obtained behaviors depend on the alignment of the instructions in the memory. Moreover, we are also able to give a better insight on previous results from the literature, that were still partially unexplained. We also show how the observed behaviors can be exploited in various security contexts. Ihab Alshaer, Brice Colombier, Christophe Deleuze, Vincent Beroulle, Paolo Maistri |
DSD | 2 |
| 2022 | Integer Syndrome Decoding in the Presence of NoiseabstractCode-based cryptography received attention after the NIST started the post-quantum cryptography standardization process in 2016. A central NP-hard problem is the binary syndrome decoding problem, on which the security of many code-based cryptosystems lies. The best known methods to solve this problem all stem from the information-set decoding strategy. A recent line of work considers augmented versions of this strategy, with hints provided by side-channel information. In this work, we consider the integer syndrome decoding problem, where the integer syndrome is available but might be noisy. We study how the performance of the decoder is affected by the noise. We provide experimental results on cryptographic parameters for the Classic McEliece and BIKE cryptosystems, which are in the fourth round of the NIST standardization process. Vlad Dragoi, Brice Colombier, Pierre-Louis Cayrel, Vincent Grosso |
ITW | 2 |
| 2022 | Profiled Side-Channel Attack on Cryptosystems Based on the Binary Syndrome Decoding ProblemabstractThe NIST standardization process for post-quantum cryptography has been drawing the attention of researchers to the submitted candidates. One direction of research consists in implementing those candidates on embedded systems and that exposes them to physical attacks in return. TheClassic McEliececryptosystem, which is among the four finalists of round 3 in the Key Encapsulation Mechanism category, builds its security on the hardness of the syndrome decoding problem, which is a classic hard problem in code-based cryptography. This cryptosystem was recently targeted by a laser fault injection attack leading to message recovery. Regrettably, the attack setting is very restrictive and it does not tolerate any error in the faulty syndrome. Moreover, it depends on the very strong attacker model of laser fault injection, and does not apply to optimised implementations of the algorithm that make optimal usage of the machine words capacity. In this article, we propose a to change the angle and perform a message-recovery attack that relies on side-channel information only. We improve on the previously published work in several key aspects. First, we show that side-channel information, obtained with power consumption analysis, is sufficient to obtain an integer syndrome, as required by the attack framework. This is done by leveraging classic machine learning techniques that recover the Hamming weight information very accurately. Second, we put forward a computationally-efficient method, based on a simple dot product and information-set decoding algorithms, to recover the message from the, possibly inaccurate, recovered integer syndrome. Finally, we present a masking countermeasure against the proposed attack. Brice Colombier, Vlad Dragoi, Pierre-Louis Cayrel, Vincent Grosso |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Multi-Spot Laser Fault Injection Setup: New Possibilities for Fault Injection Attacks
Brice Colombier, Paul Grandamme, Julien Vernay, Émilie Chanavat, Lilian Bossuet, Lucie de Laulanié, Bruno Chassagne |
CARDIS | 1 |
| 2021 | Message-Recovery Laser Fault Injection Attack on the Classic McEliece Cryptosystem
Pierre-Louis Cayrel, Brice Colombier, Vlad Dragoi, Alexandre Menu, Lilian Bossuet |
EUROCRYPT (2) | 2 |
| 2020 | Backtracking Search for Optimal Parameters of a PLL-based True Random Number GeneratorabstractThe phase-locked loop-based true random number generator (PLL-TRNG) extracts randomness from clock jitter. It is an interesting construct because it comes with a stochastic model, making it certifiable by certification bodies. However, bringing it to good performance is difficult since it comes with multiple parameters to tune. This article proposes to use backtracking to determine these parameters. Compared to existing methods, based on genetic algorithms or exhaustive search of a feasible set of parameters, backtracking has several advantages. Indeed, since this method is expressible by constraint programming, it provides very good readability. Constraints can be specified in a very straightforward and maintainable way. It also exhibits good performance and generates PLL-TRNG configurations rapidly. Finally, it allows to integrate new exploratory design constraints for the PLL-TRNG very easily. We provide experimental results with a PLL-TRNG implemented on three FPGA families that come with different physical constraints, showing that the method allows to find good parameters for every one of them. Moreover, we were able to obtain configurations that lead to an increase 59 % in throughput and 82 % in jitter sensitivity on average, thereby generating random numbers of higher quality at a faster rate. This approach also paves the way for new design exploration strategies for PLL-TRNG. The source code of our implementation is open source and available online for reproducibility and reuse. Brice Colombier, Nathalie Bochard, Florent Bernard, Lilian Bossuet |
DATE | 1 |
| 2020 | Single-bit Laser Fault Model in NOR Flash Memories: Analysis and ExploitationabstractLaser injection is a powerful fault injection technique with a high spatial accuracy which allows an adversary to efficiently extract the secret information from an electronic device. The control and the repeatability of faults requires the attacker to understand the relation of the fault model to the setup (notably the laser spot size) and the process node of the target device. Most studies on laser fault injection report fault models resulting from a photo-electric current in CMOS transistors. This study provides a black-box analysis of the effect of a photo-electric current in floating-gate transistors of two embedded NOR Flash memories from two different manufacturers. Experimental results demonstrate that single-bit bit-set faults can be injected in code and data without corrupting the Flash memory, even with a laser spot of more than 20 μm in diameter, which is several orders of magnitude larger than the process node of the floating-gate transistors in the experiments. This article also presents the specifics of performing a "safe-error" attack on AES, leveraging the previously detailed single-bit bit-set fault model. Alexandre Menu, Jean-Max Dutertre, Jean-Baptiste Rigaud, Brice Colombier, Pierre-Alain Moëllic, Jean-Luc Danger |
FDTC | 4 |
| 2017 | Complete activation scheme for FPGA-oriented IP cores design protectionabstractIntellectual Property (IP) illegal copying is a major threat in today's integrated circuits industry which is massively based on a design-and-reuse paradigm. In order to fight this threat, a designer must track how many times an IP has been instantiated. Moreover, illegal copies of an IP must be unusable. We propose a hardware/software scheme which allows a designer to remotely activate an IP with minimal area overhead. The software modifies the IP efficiently and can handle very large netlists. Unique identification of hardware instances is achieved by integrating a TERO-PUF along with a lightweight key reconciliation module. A cryptographic core guarantees security and triggers a logic locking/masking module which makes the IP unusable unless the correct encrypted activation word is applied. Brice Colombier, Ugo Mureddu, Marek Laban, Oto Petura, Lilian Bossuet, Viktor Fischer |
FPL | 1 |
| 2017 | A comprehensive hardware/software infrastructure for IP cores design protectionabstractCore-based design, which is widely used nowadays due to the high complexity of electronic systems, comes with specific threats against design data. Cases of intellectual property infringement and illegal copying have risen in the last decade. To fight this threat, must be aware of how many instantiations of an IP core have been carried out. Based on this, illegal copies can be detected and precise metering is achieved. To work toward this goal, we propose a comprehensive hardware/software infrastructure that allows a designer to modify an IP core to make it remotely activable later on when it is implemented on an FPGA. We focus on industrial applicability and ease of integration. On the one hand, hardware implementation on FPGA focuses on achieving a medium level of security at reduced cost. On the other hand, the software side aims at computational efficiency and industrial applicability for smooth integration into EDA tools. Brice Colombier, Lilian Bossuet, Ugo Mureddu, David Hély |
FPT | 1 |
| 2017 | Key Reconciliation Protocols for Error Correction of Silicon PUF ResponsesabstractPhysical unclonable functions (PUFs) are promising primitives for the lightweight authentication of an integrated circuit (IC). Indeed, by extracting an identifier from random process variations, they allow each instance of a design to be uniquely identified. However, the extracted identifiers are not stable enough to be used as is, and hence, need to be corrected first. This is currently achieved using error-correcting codes in secure sketches that generate helper data through a one-time procedure. As an alternative, we propose key reconciliation protocols. This interactive method, originating from quantum key distribution, allows two entities to correct errors in their respective correlated keys by discussing over a public channel. We believe that this can also be used by a device and a remote server to agree on two different responses to the same challenge from the same PUF obtained at different times. This approach has the advantage of requiring very few logic resources on the device side. The information leakage caused by the key reconciliation process is limited and easily computable. Results of implementation on field-programmable gate array (FPGA) targets are presented, showing that it is the most lightweight error-correction module to date. Brice Colombier, Lilian Bossuet, Viktor Fischer, David Hély |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Comments on "A PUF-FSM Binding Scheme for FPGA IP Protection and Pay-per-Device Licensing"abstractIP protection is a recent field of research. If passive protection schemes, mainly IP watermarking and fingerprinting, have been studied for more than fifteen years, active protection schemes using remote activation / unlocking / metering of IPs are highlighted by several recent works. Like any other new field of research, new concepts appear with sometimes not such good ideas. IP unlocking scheme without cryptography, as recently proposed in this journal, is one of these ideas. Expecting to obtain low overhead and high security this way is very hard. This comment proves this by presenting a short yet deep study. Lilian Bossuet, Brice Colombier |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Functional Locking Modules for Design Protection of Intellectual Property CoresabstractIP cores are now widely used as building blocks in the design of electronic systems. Moreover, since FPGAs are increasingly powerful and contain millions of logic cells, they are now a platform of choice for such electronic systems. Due to their reconfigurability, they are particularly suited to receiving IP cores. However, for the current IP core distribution process to be fair for all parties, the designer needs to maintain control over his IP to limit illegal copying and non-contracted reuse. To this end, a key point is functional locking, which can be used remotely to render the circuit practically useless. Current state-of-the-art lacks a comprehensive comparison of the different locking points that can be found on a usual IP core. This paper presents the first comparative study of the performance of IP core locking schemes. Brice Colombier, Lilian Bossuet |
FCCM | 1 |