Nusa Zidaric

dblp:140/6461 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0001-9308-7392ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 4 since 2021Security and privacy · 1Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 POSTER: Security and Cost Trade-offs of Side-Channel Countermeasures for AES Software on RISC-V SoCs
abstract
Power side-channel attacks remain a practical concern for cryptographic software deployed on lightweight RISC-V platforms. This poster discusses how several protection strategies influence both leakage resilience and implementation overhead for AES software executed on an FPGA-based RISC-V SoC. Our experiments focus on Tiny-AES running on the Ibex RISC-V core and compare the following protection strategies: software masking, software-generated noise, hardware-generated noise, Secure-Ibex, and CoCo-Ibex. The results show that first-order Correlation Power Analysis succeeds quickly on unprotected SoCs, whereas masking and Secure-Ibex provide the strongest resilience. In contrast, noise-based protection strategies mainly complicate the attack without fully removing exploitable leakage. In addition to security, we compare execution time, code size, hardware usage, power, and energy consumption.
Abolfazl Sajadi, Nusa Zidaric, Todor Stefanov, Nele Mentens
CF2
2024 Optimised AES with RISC-V Vector Extensions
abstract
With the advent of quantum computers, organizations and users should consider the potential impact of quantum threats on their cryptographic systems and be prepared to adopt Post-Quantum Cryptography (PQC) solutions when needed. However, PQC algorithms are often difficult to implement on standard processors and resource-constrained embedded devices, due to complicated mathematical algorithms and large parameters. The goal of this research is to design efficient HW/SW co-design of the PQC algorithm Classic McEliece (CM) using the RISC-V Instruction Set Architecture (ISA). In the first step, the acceleration of the AES algorithm, which is used as part of the key generation in CM, is explored using RISC-V Vector Extensions version 1.0 (RVV1.0). In this paper, we compare the vector-accelerated AES running on Vicuan coprocessor with the scalar AES running on Ibex.
Mahnaz Namazi Rizi, Nusa Zidaric, Lejla Batina, Nele Mentens
DDECS2
2023 Tower field support for synthesis of datapaths
abstract
With the rise of new technologies the demand for efficient cryptographic hardware and design space exploration is rising. This work presents a framework for the automated synthesis of datapaths that use tower-field constructions for finite field arithmetic. The key idea is a novel encoding of the underlying algebraic structure with the dual view as both a finite field and a vector space. The framework uses symbolic computation capabilities of GAP to generate the expressions, needed for hardware implementations, on-the-fly, and compiles them into synthesizable datapaths, test-vectors and testbenches. It supports implementation of expressions defined over different sized finite fields, tower fields, or even several isomorphic finite fields within the same hardware module.
Nusa Zidaric, Mark D. Aagaard
CF1
2023 A Survey of Recent Developments in Testability, Safety and Security of RISC-V Processors
abstract
With the continued success of the open RISC-V architecture, practical deployment of RISC-V processors necessitates an in-depth consideration of their testability, safety and security aspects. This survey provides an overview of recent developments in this quickly-evolving field. We start with discussing the application of state-of-the-art functional and system-level test solutions to RISC-V processors. Then, we discuss the use of RISC-V processors for safety-related applications; to this end, we outline the essential techniques necessary to obtain safety both in the functional and in the timing domain and review recent processor designs with safety features. Finally, we survey the different aspects of security with respect to RISC-V implementations and discuss the relationship between cryptographic protocols and primitives on the one hand and the RISC-V processor architecture and hardware implementation on the other. We also comment on the role of a RISC-V processor for system security and its resilience against side-channel attacks.
Jens Anders, Pablo Andreu, Bernd Becker 0001, Steffen Becker 0001, Riccardo Cantoro, Nikolaos Ioannis Deligiannis, Nourhan Elhamawy, Tobias Faller, Carles Hernández 0001, Nele Mentens, Mahnaz Namazi Rizi, Ilia Polian, Abolfazl Sajadi, Matthias Sauer 0002, Denis Schwachhofer, Matteo Sonza Reorda, Todor Stefanov, Ilya Tuzov, Stefan Wagner 0001, Nusa Zidaric
ETS20
2020 Correlation Power Analysis and Higher-Order Masking Implementation of WAGE
Yunsi Fei, Guang Gong, Cheng Gongye, Kalikinkar Mandal, Raghvendra Rohit 0001, Tianhong Xu, Yunjie Yi, Nusa Zidaric
SAC8
2019 Hardware Optimizations and Analysis for the WG-16 Cipher with Tower Field Arithmetic
abstract
This paper explores tower field constructions and hardware optimizations for the WG-16 stream cipher. The constructions${\mathbb {F}}_{(((2^2)^2)^2)^2}$and${\mathbb {F}}_{(2^{4})^4}$were chosen because their small subfields enable high speed arithmetic implementations and their regularity provides flexibility in pipeline granularity. A design methodology is presented where the tower field constructions guide how to proceed systematically from algebraic optimizations, through initial hardware implementation, selection of submodules, pipelining, and finally detailed hardware optimizations to increase clock speed. The highest frequency WG(16, 32) keystream generator, obtained for the 65 nm ASIC library, reached a clock speed of 2.44 GHz at 26.3 kGE, and the smallest area keystream generator achieved a clock speed of 0.33 GHz at 9.9 kGE. The highest frequency FPGA implementation on a Xilinx Spartan 6 reached a clock speed of 256 MHz using 631 slices. In addition, the paper demonstrates that LFSR feedback polynomials can be optimized to increase security without hurting performance, and retiming optimizations can be used to increase clock speed without increasing area.
Nusa Zidaric, Mark D. Aagaard, Guang Gong
IEEE Trans. Computers1
2018 Rapid Hardware Design for Cryptographic Modules with Filtering Structures over Small Finite Fields
Nusa Zidaric, Mark D. Aagaard, Guang Gong
WAIFI1