EDBT 2026 Demo / reviewers in the wild / expert
Antoon Purnal
dblp:237/4710
· DBLP profile ↗
9ranked-venue papers
4as first author
7since 2021 · last 2024
0000-0002-1426-0853ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 4 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Masked Iterate-Fork-Iterate: A New Design Paradigm for Tweakable Expanding Pseudorandom Function
Elena Andreeva 0001, Benoit Cogliati, Virginie Lallemand, Marine Minier, Antoon Purnal, Arnab Roy 0005 |
ACNS (2) | 5 |
| 2023 | ShowTime: Amplifying Arbitrary CPU Timing Side ChannelsabstractMicroarchitectural attacks typically rely on precise timing sources to uncover short-lived secret-dependent activity in the processor. In response, many browsers and even CPU vendors restrict access to fine-grained timers. While some attacks are still possible, several state-of-the-art microarchitectural attack vectors are actively hindered or even eliminated by these restrictions. Antoon Purnal, Marton Bognar, Frank Piessens, Ingrid Verbauwhede |
AsiaCCS | 1 |
| 2023 | Scatter and Split Securely: Defeating Cache Contention and Occupancy AttacksabstractIn this paper, we propose SassCache, a secure skewed associative cache with keyed index mapping. For this purpose, we design a new two-layered, low-latency cryptographic construction with configurable output coverage based on state-of-the-art cryptographic primitives. Based on this construction, SassCache is the first secure randomized cache with secure spacing. Victim cache lines automatically hide in locations the attacker cannot reach after less than 1 access on average. Consequently, attackers cannot evict the cache line, no matter which and how many memory accesses they perform. Our security analysis shows that all existing techniques for eviction set construction fail, and state-of-the-art attacks only apply to 1 in 3 million addresses, where SassCache is still as secure as ScatterCache. Compared to standard caches, Sass Cache has a single-threaded performance penalty of 1.75 % on the last-level cache hit rate in the SPEC2017 benchmark, and an average decrease of 11.7 p.p. in hit rate for MiBench, GAP and Scimark for our high-security settings. Lukas Giner, Stefan Steinegger, Antoon Purnal, Maria Eichlseder, Thomas Unterluggauer, Stefan Mangard, Daniel Gruss |
SP | 3 |
| 2023 | SpectrEM: Exploiting Electromagnetic Emanations During Transient Execution
Jesse De Meulemeester, Antoon Purnal, Lennert Wouters, Arthur Beckers, Ingrid Verbauwhede |
USENIX Security Symposium | 2 |
| 2022 | Double Trouble: Combined Heterogeneous Attacks on Non-Inclusive Cache Hierarchies
Antoon Purnal, Furkan Turan, Ingrid Verbauwhede |
USENIX Security Symposium | 1 |
| 2021 | Prime+Scope: Overcoming the Observer Effect for High-Precision Cache Contention AttacksabstractModern processors expose software to information leakage through shared microarchitectural state. One of the most severe leakage channels is cache contention, exploited by attacks referred to as PRIME+PROBE, which can infer fine-grained memory access patterns while placing only limited assumptions on attacker capabilities. Antoon Purnal, Furkan Turan, Ingrid Verbauwhede |
CCS | 1 |
| 2021 | Systematic Analysis of Randomization-based Protected Cache ArchitecturesabstractRecent secure cache designs aim to mitigate side-channel attacks by randomizing the mapping from memory addresses to cache sets. As vendors investigate deployment of these caches, it is crucial to understand their actual security.In this paper, we consolidate existing randomization-based secure caches into a generic cache model. We then comprehensively analyze the security of existing designs, including CEASER-S and SCATTERCACHE, by mapping them to instances of this model. We tailor cache attacks for randomized caches using a novel PRIME+PRUNE+PROBE technique, and optimize it using burst accesses, bootstrapping, and multi-step profiling. PRIME+ PRUNE+PROBE constructs probabilistic but reliable eviction sets, enabling attacks previously assumed to be computationally infeasible. We also simulate an end-to-end attack, leaking secrets from a vulnerable AES implementation. Finally, a case study of CEASER-S reveals that cryptographic weaknesses in the randomization algorithm can lead to a complete security subversion.Our systematic analysis yields more realistic and comparable security levels for randomized caches. As we quantify how design parameters influence the security level, our work leads to important conclusions for future work on secure cache designs. Antoon Purnal, Lukas Giner, Daniel Gruss, Ingrid Verbauwhede |
SP | 1 |
| 2020 | Optimized Software Implementations for the Lightweight Encryption Scheme ForkAE
Arne Deprez, Elena Andreeva 0001, Jose Maria Bermudo Mera, Angshuman Karmakar, Antoon Purnal |
CARDIS | 5 |
| 2019 | Forkcipher: A New Primitive for Authenticated Encryption of Very Short Messages
Elena Andreeva 0001, Virginie Lallemand, Antoon Purnal, Reza Reyhanitabar, Arnab Roy 0005, Damian Vizár |
ASIACRYPT (2) | 3 |