Maria Chiara Molteni

dblp:227/9149 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0003-2901-2972ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Multi-Partner Project: Quantum-Secure IoT-based Digital Manufacturing Pilot in QUBIP project
abstract
Connectivity has become essential to modern manufacturing, but it also introduces new security challenges. Industrial IoT ecosystems rely on public-key cryptography to protect communications, firmware, and operational data. However, the emergence of quantum computing threatens to undermine these cryptographic foundations, exposing long-lived manufacturing systems to future attacks. This paper presents the Quantum-Secure IoT-based Digital Manufacturing Pilot, developed within the EU-funded QUBIP project, which investigates the integration of post-quantum cryptography (PQC) into IoT environments. The pilot aims to demonstrate how quantum resistant algorithms can be efficiently deployed across heterogeneous devices with limited resources to ensure data exchange and authentication. By combining software and hardware-based approaches, the proposed pilot provides a replicable model for PQC migration in digital manufacturing, ensuring long-term data integrity and resilience in the quantum era.
Eros Camacho-Ruiz, Pablo Navarro-Torrero, Piedad Brox Jiménez, Maria Chiara Molteni, Alberto Battistello, Davide Bellizia, Agostino Sette, Enrico Bisio, Nicola Tuveri, Enrico Bravi, Francesco Vaccaro, Grazia D'Onghia, Andrea Vesco
DATE4
2025 AttackDefense Framework (ADF): Enhancing IoT Devices and Lifecycles Threat Modeling
abstract
Threat modeling (TM) is essential to manage, prevent, and fix security and privacy issues in our society. TM requires a data model to represent threats and tools to exploit such data. Current TM data models and tools have significant limitations preventing their usage in real-world scenarios. For example, it is challenging to TM embedded devices with current data models and tools as they cannot model their hardware, firmware, and low-level software. Moreover, it is impossible to TM a device lifecycle or security-privacy tradeoffs as these data models and tools were developed for other use cases (e.g., software security or user privacy). We fill this relevant gap by presenting the AttackDefense Framework (ADF), which provides a novel data model and related tools to augment TM. ADF’s building block is the AD object that can be used to represent heterogeneous and complex threats. Moreover, ADF provides automations to process a collection of AD objects, including ways to create sets, maps, chains, trees, and wordclouds of AD objects. We present ADF , a toolkit implementing ADF composed of four modules (Catalog, Parse, Check, and Analyze). We confirm that the data model and tools provided by ADF are useful by running an extensive set of experiments while threat modeling a crypto wallet and its lifecycle. Our experiments involved seven expert groups from academia and industry, each using the ADF on an orthogonal threat class. The evaluation generated 175 high-quality ADs covering ISA/IEC 62433-4-1 SecDev Lifecycle, side-channels, fault injection, microarchitectural attacks, speculative execution, pre-silicon testing, invasive physical chip modifications, Bluetooth protocol and implementation threats, and FIDO2 authentication.
Tommaso Sacchetti, Marton Bognar, Jesse De Meulemeester, Benedikt Gierlichs, Frank Piessens, Volodymyr Bezsmertnyi, Maria Chiara Molteni, Stefano Cristalli, Arianna Gringiani, Olivier Thomas, Daniele Antonioli
ACM Trans. Embed. Comput. Syst.7
2024 Analysis and contributions to an open source Kyber library in Rust
abstract
This work focuses on analyzing the efficiency of a purely Rust-written Kyber library for ARM Cortex-M4 microcontrollers. The analysis includes performance comparisons with a C-written Kyber library, as well as the identification and resolution of minor issues within the Rust-written Kyber library. Contributions to the library include proposed solutions for unhandled TRNG exceptions, enhancements in code quality, and improvements in code coverage, all of which have been approved by the library maintainers and released.
Francesco Medina, Maria Chiara Molteni, Antonio Josè Di Scala, Lorenzo Nava
ISCC2
2022 ADD-based Spectral Analysis of Probing Security
abstract
In this paper, we introduce a novel exact verification methodology for non-interference properties of cryptographic circuits. The methodology exploits the Algebraic Decision Diagram representation of the Walsh spectrum to overcome the potential slow down associated with its exact verification against non-interference constraints. Benchmarked against a standard set of use cases, the methodology speeds-up 1.88x the median verification time over the existing state-of-the art tools for exact verification.
Maria Chiara Molteni, Vittorio Zaccaria, Valentina Ciriani
DATE1
2022 On robust strong-non-interferent low-latency multiplications
abstract
Abstract The overarching goal of this work is to present new theoretical and practical tools to implement −probing security. In this work, a low‐latency multiplication gadget that is secure against probing attacks that exploit logic glitches in the circuit is presented. The gadget is the first of its kind to present a 1‐cycle input‐to‐output latency while belonging to the class of probing security by optimized composition gadgets [6]. In particular, the authors show that it is possible to construct robust‐‐strong‐non‐interferent gadgets without compromising on latency with a moderate increase in area. The authors provide a theoretical proof for the robustness of the gadget and show that, for , the amount of randomness required can even be reduced without compromising on robustness.
Maria Chiara Molteni, Jürgen Pulkus, Vittorio Zaccaria
IET Inf. Secur.1
2022 Multiplicative Complexity of XOR Based Regular Functions
abstract
XOR-AND Graphs (XAGs) are an enrichment of the classical AND-Inverter Graphs (AIGs) with XOR nodes. In particular, XAGs are networks composed by ANDs, XORs, and inverters. Besides several emerging technologies applications, XAGs are often exploited in cryptography-related applications based on the multiplicative complexity of a Boolean function. The multiplicative complexity of a function is the minimum number of AND gates (i.e., multiplications) that are sufficient to represent the function over the basis {AND, XOR, NOT}. In fact, the minimization of the number of AND gates is important for high-level cryptography protocols such as secure multiparty computation, where processing AND gates is more expensive than processing XOR gates. Moreover, it is an indicator of the degree of vulnerability of the circuit, as a small number of AND gates corresponds to a high vulnerability to algebraic attacks. In this paper we study the multiplicative complexity of Boolean functions characterized by two particular regularities, called autosymmetry and D-reducibility. Moreover, we exploit these regularities for decreasing the number of AND nodes in XAGs. The experimental results validate the proposed approaches.
Anna Bernasconi 0001, Stelvio Cimato, Valentina Ciriani, Maria Chiara Molteni
IEEE Trans. Computers4
2020 Multiplicative Complexity of Autosymmetric Functions: Theory and Applications to Security
abstract
The multiplicative complexity of a Boolean function is the minimum number of AND gates (i.e., multiplications) that are sufficient to represent the function over the basis {AND, XOR, NOT}. The multiplicative complexity measure plays a crucial role in cryptography-related applications. In fact, the minimization of the number of AND gates is important for high-level cryptography protocols such as secure multiparty computation, where processing AND gates is more expensive than processing XOR gates. Moreover, it is an indicator of the degree of vulnerability of the circuit, as a small number of AND gates corresponds to a high vulnerability to algebraic attacks. In this paper we study a particular structure regularity of Boolean functions, called autosymmetry, and exploit it to decrease the number of ANDs in XOR-AND Graphs (XAGs), i.e., Boolean networks composed by ANDs, XORs, and inverters. The interest in autosymmetric functions is motivated by the fact that a considerable amount of standard Boolean functions of practical interest presents this regularity; indeed, about 24% of the functions in the classical ESPRESSO benchmark suite have at least one autosymmetric output. The experimental results validate the proposed approach.
Anna Bernasconi 0001, Stelvio Cimato, Valentina Ciriani, Maria Chiara Molteni
DAC4
2018 Darth's Saber: A Key Exfiltration Attack for Symmetric Ciphers Using Laser Light
abstract
This paper evaluates the effectiveness of exfiltrating a key from an AES primitive by injecting double transient faults into the digital circuit using two laser lights. We present some theoretical consideration on the effectiveness of this approach and show a few experimental results supporting our reasoning.
Vittorio Zaccaria, Maria Chiara Molteni, Filippo Melzani, Guido Bertoni
FDTC2