Silvia Mella

dblp:138/7333 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0002-4664-3541ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 2 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Comparing Gaston with Ascon-p: Side-Channel Analysis and Hardware Evaluation
Parisa A. Eliasi, Lejla Batina, Silvia Mella
CANS3
2025 ChiLow and ChiChi: New Constructions for Code Encryption
Yanis Belkheyar, Patrick Derbez, Shibam Ghosh, Gregor Leander, Silvia Mella, Léo Perrin, Shahram Rasoolzadeh, Lukas Stennes, Siwei Sun, Gilles Van Assche, Damian Vizár
EUROCRYPT (1)5
2025 Shaking up authenticated encryption
abstract
Authenticated encryption (AE) is a cryptographic mechanism that allows communicating parties to protect the confidentiality and integrity of messages exchanged over a public channel, provided they share a secret key. In this work, we present new AE schemes leveraging the SHA- 3 standard functions SHAKE128 and SHAKE256, offering 128 and 256 bits of security strength, respectively, and their “Turbo” counterparts. They support session-based communication, where a ciphertext authenticates the sequence of messages since the start of the session. The chaining in the session allows decryption in segments, avoiding the need to buffer the entire deciphered cryptogram between decryption and validation. And, thanks to the collision resistance of (Turbo)SHAKE, they provide so-called CMT-4 committing security, meaning that they provide strong guarantees that a ciphertext uniquely binds to the key, plaintext and associated data. The AE schemes we propose have a unique combination of advantages. The most important are that 1) their security is based on the security claim of SHAKE, that has received a large amount of public scrutiny, that 2) they make use of the standard KECCAK-p permutation that not only receives more and more dedicated hardware support, but also allows competitive software-only implementations thanks to the TurboSHAKE instances, and that 3) they do not suffer from a 64-bit birthday bound like most AES-based schemes. Of independent interest, we introduce the deck cipher as the stateful counterpart of the deck function and the duplex cipher generalizing keyed duplex and harmonize their security notions. Finally, we provide an elegant solution for multi-layer domain separation.
Joan Daemen, Seth Hoffert, Silvia Mella, Gilles Van Assche, Ronny Van Keer
EuroS&P3
2024 Xoodyak Under SCA Siege
abstract
In this paper, we conduct a detailed power side-channel analysis of Xoodyak, a lightweight cryptographic algorithm, on an FPGA platform. We focus on the initialization phase of Xoodyak in the authenticated encryption with associated data (AEAD) mode. First, we introduce a new leakage model and perform a leakage assessment. Then, we perform non-profiled and profiled attacks to determine if the observed leakages can be exploited. For a non-profiled attack, we perform a correlation power analysis on all key bits, achieving a success rate of 91.4% with 50 000 traces. Our approach for a profiled attack involves a template attack and a deep learning-based attack. The former achieves a success rate of 99.2%, recovering almost all key bits with 20 000 traces in the attack phase. The latter reaches a guessing entropy of zero after 550 traces and adapts to the leakage model within 50 epochs.
Parisa A. Eliasi, Silvia Mella, Leo Weissbart, Lejla Batina, Stjepan Picek
DDECS2
2024 Koala: A Low-Latency Pseudorandom Function
Parisa A. Eliasi, Yanis Belkheyar, Joan Daemen, Santosh Ghosh, Daniël Kuijsters, Alireza Mehrdad, Silvia Mella, Shahram Rasoolzadeh, Gilles Van Assche
SAC (2)7
2022 Profiled side channel attacks against the RSA cryptosystem using neural networks
Alessandro Barenghi, Diego Carrera, Silvia Mella, Andrea Pace, Gerardo Pelosi, Ruggero Susella
J. Inf. Secur. Appl.3
2021 Profiled Attacks Against the Elliptic Curve Scalar Point Multiplication Using Neural Networks
Alessandro Barenghi, Diego Carrera, Silvia Mella, Andrea Pace, Gerardo Pelosi, Ruggero Susella
NSS3
2015 J-DFA: A Novel Approach for Robust Differential Fault Analysis
abstract
Fault attacks are among the most effective techniquesto break real implementations of cryptographic algorithms. They usually require some kind of knowledge bythe attacker on the effect of the faults on the target device, which in practice turns to be a poorly reliable informationtypically affected by uncertainty. This paper is devoted toaddress this problem by softening the a-priori knowledge on the injection technique needed by the attacker in the contextof Differential Fault Analysis (DFA). We conceive an originalsolution, named J-DFA, based on translating the stage ofdifferential cryptanalysis of DFA attacks into terms of fittingmultiple models to data corrupted by outliers. Specifically, wetailor J-Linkage algorithm [9] to the fault analysis. In order toshow the effectiveness of J-DFA and its benefits in practicalscenarios, we applied the technique under different attackconditions.
Luca Magri 0002, Silvia Mella, Pasqualina Fragneto, Filippo Melzani, Beatrice Rossi
FDTC2
2015 New Results for Partial Key Exposure on RSA with Exponent Blinding
abstract
In 1998, Boneh, Durfee and Frankel introduced partial key exposure attacks, a novel application of Coppersmith's method, to retrieve an RSA private key given only a fraction of its bits.This type of attacks is of particular interest in the context of side-channel attacks.By applying the exponent blinding technique as a countermeasure for side-channel attacks, the private exponent becomes randomized at each execution.Thus the attacker has to rely only on a single trace, significantly incrementing the noise, making the exponent bits recovery less effective.This countermeasure has also the side-effect of modifying the RSA equation used by partial key exposure attacks, in a way studied by Joye and Lepoint in 2012.We improve their results by providing a simpler technique in the case of known least significant bits and a better bound for the known most significant bits case.Additionally, we apply partial key exposure attacks to CRT-RSA when exponent blinding is used, a case not yet analyzed in literature.Our findings, for which we provide theoretical and experimental results, aim to reduce the number of bits to be recovered through side-channel attacks in order to factor an RSA modulus when the implementation is protected by exponent blinding.
Stelvio Cimato, Silvia Mella, Ruggero Susella
SECRYPT2
2014 Differential Fault Attacks against AES Tampering with the Instruction Flow
abstract
Most of the attacks against the Advanced Encryption Standard based on faults mainly aim at either altering the temporary value of the message or key during the computation. Few other attacks tamper the instruction flow in order to reduce the number of round iterations to one or two. In this work, we extend this idea and present fault attacks against the AES algorithm that exploit the misbehavior of the instruction flow during the last round. In particular, we consider faults that cause the algorithm to skip, repeat or corrupt one of the four AES round functions. In principle, these attacks are applicable against both software and hardware implementations, by targeting the execution of instructions or the control logic. As conclusion countermeasures against fault attacks must also cover the instruction flow and not only the processed data.
Silvia Mella, Filippo Melzani, Andrea Visconti
SECRYPT1
2013 On the Homomorphic Computation of Symmetric Cryptographic Primitives
Silvia Mella, Ruggero Susella
IMACC1