EDBT 2026 Demo / reviewers in the wild / expert
Carlos Andres Lara-Nino
dblp:159/2687
· DBLP profile ↗
10ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0003-0333-2564ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Security and privacy · 3 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PQCUARK: A Scalar RISC-V ISA Extension for ML-KEM and ML-DSAabstractRecent advances in quantum computing pose a threat to the security of digital communications, as large-scale quantum machines can break commonly used public-key cryptographic algorithms. To mitigate this risk, post-quantum cryptography (PQC) schemes are being standardized, with recent NIST recommendations selecting two lattice-based schemes, ML-KEM for key encapsulation and ML-DSA for digital signatures, alongside other schemes. Two computationally intensive kernels dominate the execution of these schemes: the Number-Theoretic Transform (NTT) for polynomial multiplication and the Keccak-f1600 permutation function for polynomial sampling and hashing. This paper presents PQCUARK, a scalar RISC-V ISA extension that accelerates these key operations. PQCUARK integrates two novel accelerators within the core pipeline: (i) a packed SIMD butterfly unit capable of performing NTT butterfly operations on 2×32bit or 4×16bit polynomial coefficients, and (ii) a permutation engine that delivers two Keccak rounds per cycle, hosting a private state and a direct interface to the core Load Store Unit, eliminating the need for a custom register file interface. We have integrated PQCUARK into an RV64 core and deployed it on an FPGA. Experimental results demonstrate that PQCUARK provides up to 10.1× speedup over the NIST baselines and 2.3× over the optimized software, and it outperforms similar state-of-the-art approaches between 1.4-12.3× in performance. ASIC synthesis in GF22-FDSOI technology shows a moderate core area increase of 8% at 1.2 GHz, with PQCUARK units being outside the critical path. Xavier Carril, Alicia Manuel Pasoot, Emanuele Parisi, Oriol Farràs, Carlos Andres Lara-Nino, Miquel Moretó |
DATE | 5 |
| 2026 | Non-complete set coverings for higher order threshold implementations
Oriol Farràs, Óscar Fidalgo, Carlos Andres Lara-Nino |
Des. Codes Cryptogr. | 3 |
| 2025 | RISC-B: Hardware Blocks for the design of RISC-V-based SoCsabstractOpen-source descriptions of RISC-V processors have been around for a while. Making hardware designs freely available is a key part of open silicon initiatives. An open-source implementation allows peers to easily reproduce each other's findings and to improve on previous results. The challenge lies in the integration of third-party technologies into new projects. The best known open-source RISC-V platforms are described in SystemVerilog. This language allows for the description of hardware and the automatic verification of complex systems. However, as more components are aggregated into a project, it becomes challenging to keep up with development times. Hardware “blocks” can alleviate this problem. By packaging HDL components as individual modules and connecting them through a graphic interface, it is possible to deploy large architectures in a matter of minutes. In our work, we discuss the adoption of this design methodology in the design flow of RISC-V-based SoCs. We show that by wrapping RISC-V cores as individual modules, it is much easier to prototype these platforms. As proof of concept, we introduce RISC-B, a freely available repository for RISC-V blocks compatible with the AMD-Xilinx design flow. Carlos Andres Lara-Nino |
RSP | 1 |
| 2025 | Power and Frequency Intrinsic Channels on gem5abstractRecent works have highlighted the vulnerability of System-on-a-Chip (SoC) platforms against intrinsic channels attacks. In this threat model, an adversary can leverage vulnerabilities in the SoC’s firmware, the operating system, or the design tools to gain access to shared resources in the platform and transfer data covertly. Given the diversity of attack avenues and the constant evolution of heterogeneous SoCs, it is not practical to study these attacks using conventional approaches. To address this issue, we propose to employ gem5 in the study of power and frequency intrinsic channels. Our work studies heterogeneous SoCs which feature a processor system and an FPGA. We employ the full system simulation of gem5 to emulate a reference physical device. We then describe the emulation of different intrinsic channels which leverage the clock tree and power distribution network of the SoC to transfer data covertly. Our findings demonstrate that gem5 can accurately replicate the logical behavior of power and frequency intrinsic channels. Lilian Bossuet, Carlos Andres Lara-Nino |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2025 | Efficient Adaptive Multi-Level Privilege Partitioning With RTrustSoCabstractIn recent years, heterogeneous SoCs—comprised of multiple processor cores and programmable logic—have greatly progressed both complexity and performance. From a security point of view, this leads to an expansion of the attack surface exposed to adversaries. To address this issue, in this article, we propose a novel heterogeneous SoC architecture called RTrustSoC. Our proposal includes an innovative fully-reconfigurable post-deployment strategy for partitioning the SoC architecture into multiple exclusion levels—worlds—with customizable degrees of privilege. We aim to provide SoC designers with fine control over the security of the system by segregating trusted hardware components from third-party IPs with “on-demand” hardware isolation. Therefore, we expect that an RTrustSoC instance could evolve from a multi-world SoC to a fully trusted platform as IPs progressively develop. RTrustSoC also proposes a dynamic reconfigurable penalty system to monitor the third-party IPs and take measures in case of a detected abnormal behavior. Our experimental testing on an AMD-Xilinx Zynq-7000 SoC-FPGA showed the penalty of the proposed isolation strategy to be small, up to 1% in LUT and 0.7% Flip Flop utilization, thus enabling to an efficient security solution. RTrustSoC introduces a novel design paradigm, evolving from the binary notion of security—trusted vs untrusted—into a flexible set of worlds that can be adapted to any scenario. We demonstrate a real case scenario of RTrustSoC use on time-based cache memory attacks with implementation results. Raphaële Milan, Lilian Bossuet, Loïc Lagadec, Carlos Andres Lara-Nino, Brice Colombier, Théotime Bollengier |
IEEE Trans. Circuits Syst. I Regul. Pap. | 4 |
| 2024 | Lightweight Active Fences for FPGAsabstractThe use of active fences has been proposed as a protection against remote power analysis attacks. This counter-measure relies on reserving a reconfigurable space within the FPGA which will separate it into sub-regions. These “fences” will then generate some electrical interference to hinder the performance of an attack. As FPGAs can be configured in multiple ways, there are different approaches for connecting the hardware inside the fence. In this work, we describe a LUT-based configuration which can achieve the same instantaneous power drop as a ring oscillator bank with less LUTs. This contributes to reducing the hardware costs of active fences. Anis Fellah-Touta, Lilian Bossuet, Vincent Grosso, Carlos Andres Lara-Nino |
VLSI-SoC | 4 |
| 2020 | Lightweight elliptic curve cryptography accelerator for internet of things applications
Carlos Andres Lara-Nino, Arturo Díaz-Pérez, Miguel Morales-Sandoval |
Ad Hoc Networks | 1 |
| 2018 | FPGA-Based Assessment of Midori and Gift Lightweight Block Ciphers
Carlos Andres Lara-Nino, Arturo Díaz-Pérez, Miguel Morales-Sandoval |
ICICS | 1 |
| 2018 | Energy and Area Costs of Lightweight Cryptographic Algorithms for Authenticated Encryption in WSNabstractWireless Sensor Networks (WSN) aim at linking the cyber and physical worlds. Their security has taken relevance due to the sensitive data these networks might process under unprotected physical and cybernetic environments. The operational constraints in the sensor nodes demand security primitives with small implementation size and low power consumption. Authenticated encryption is a mechanism to provide these systems with confidentiality, integrity, and authentication of sensitive data. In this paper we explore hardware implementation alternatives of authenticated encryption through generic compositions, to assess the costs of this security approach in WSN. Two symmetric ciphers, AES and PRESENT, and two hash functions, SHA andSPONGENT, are used as the underlying primitives for the generic compositions. All the architectures studied in this work are implemented and evaluated in an FPGA-based WSN mote. The life time of the sensor node is used as the main evaluation metric but FPGA resources are also reported. From the experimental results obtained, it is shown how lightweight ciphers significantly contribute to reduce implementation area and energy consumption overheads, extending the lifetime of the sensor node. Carlos Andres Lara-Nino, Arturo Díaz-Pérez, Miguel Morales-Sandoval |
Secur. Commun. Networks | 1 |
| 2016 | Novel FPGA-Based Low-Cost Hardware Architecture for the PRESENT Block CipherabstractThis paper presents a novel FPGA-based design for the lightweight block cipher PRESENT and its implementation results. The proposed design allows to study area-performance trade-offs and thus constructing smaller or faster implementations. When optimized by area, the proposed design exhibits smaller latency and fewer FPGA resources than representative related works in the literature. Carlos Andres Lara-Nino, Miguel Morales-Sandoval, Arturo Díaz-Pérez |
DSD | 1 |