Svetla Nikova

dblp:24/3255 · also Svetla Petkova-Nikova · DBLP profile ↗
← Back
50ranked-venue papers
5as first author
12since 2021 · last 2025
0000-0003-3133-9261ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 38 · 5 first-author · 11 since 2021Theory of computation · 6 · 1 since 2021Systems, architecture and hardware · 3Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Bitcoin Under Volatile Block Rewards: How Mempool Statistics Can Influence Bitcoin Mining
abstract
The security of Bitcoin protocols is deeply dependent on the incentives provided to miners, which come from a combination of block rewards and transaction fees. As Bitcoin experiences more halving events, the protocol reward converges to zero, making transaction fees the primary source of miner rewards. This shift in Bitcoin's incentivization mechanism, which introduces volatility into block rewards, leads to the emergence of new security threats or intensifies existing ones. Previous security analyses of Bitcoin have either considered a fixed block reward model or a highly simplified volatile model, overlooking the complexities of Bitcoin's mempool behavior.
Roozbeh Sarenche, Alireza Aghabagherloo, Svetla Nikova, Bart Preneel
CCS3
2025 Mining Power Destruction Attacks in the Presence of Petty-Compliant Mining Pools
Roozbeh Sarenche, Svetla Nikova, Bart Preneel
FC (2)2
2025 Picking up the Fallen Mask: Breaking and Fixing the RS-Mask Countermeasure
Dilara Toprakhisar, Svetla Nikova, Ventzislav Nikov
SAC2
2025 On Decompositions of Permutations in Quadratic Functions
abstract
Abstract The algebraic degree of a vectorial Boolean function is one of the main parameters driving the cost of its hardware implementation. Thus, finding decompositions of functions into sequences of functions of lower algebraic degrees has been explored to reduce the cost of implementations. In this paper, we consider such decompositions of permutations over $$\mathbb {F}_{2^n}$$ F 2 n . We prove the existence of a decomposition of the inverse using quadratic and linear power permutations for all permutations when $$2^n-1$$ 2 n - 1 is a prime, and we prove the non-existence of such decompositions for power permutations of differential uniformity strictly lower than 16 when 4|n. We also prove that any permutation admits a decomposition into quadratic power permutations and affine permutations of the form $$ax+b$$ a x + b if $$4 \not \mid n$$ 4 ∤ n . Furthermore, we prove that any permutation admits a decomposition into cubic power permutations and affine permutations. Finally, we present a decomposition of the PRESENT S-Box using the power permutation $$x^7$$ x 7 and affine permutations.
Samuele Andreoli, Enrico Piccione, Lilya Budaghyan, Pantelimon Stanica, Svetla Nikova
J. Cryptol.5
2025 Selfish Mining Time-Averaged Analysis in Bitcoin: Is Orphan Reporting an Effective Countermeasure?
abstract
A Bitcoin miner who owns a sufficient amount of mining power can perform selfish mining to increase its relative revenue. Studies have demonstrated that the time-averaged profit of a selfish miner starts to rise once the mining difficulty level gets adjusted in favor of the attacker. Selfish mining profitability lies in the fact that orphan blocks are not incorporated into the current version of Bitcoin’s difficulty adjustment mechanism (DAM). Therefore, it is believed that considering the count of orphan blocks in the DAM can result in complete unprofitability for selfish mining. In this paper, we disprove this belief by providing a formal analysis of the selfish mining time-averaged profit. We present a precise definition of the orphan blocks that can be incorporated into calculating the next epoch’s target and then introduce two modified versions of DAM in which both main-chain blocks and orphan blocks are incorporated. We propose two versions of smart intermittent selfish mining, where the first one dominates the normal intermittent selfish mining, and the second one results in selfish mining profitability under the modified DAMs. Moreover, we present the orphan exclusion attack with the help of which the attacker can stop honest miners from reporting the orphan blocks. Using combinatorial tools, we analyze the profitability of selfish mining accompanied by the orphan exclusion attack under the modified DAMs. Our results show that even when considering orphan blocks in the DAM, selfish mining can still be profitable. However, the level of profitability under the modified DAMs is significantly lower than that observed under the current version of Bitcoin DAM, suggesting that orphan reporting can be an effective countermeasure against a payoff-maximizing selfish miner.
Roozbeh Sarenche, Ren Zhang 0003, Svetla Nikova, Bart Preneel
IEEE Trans. Inf. Forensics Secur.3
2024 Glitch-Stopping Circuits: Hardware Secure Masking without Registers
abstract
Masking is one of the most popular countermeasures to protect implementations against power and electromagnetic side-channel attacks because it offers provable security.Masking has been shown secure against d-threshold probing adversaries by Ishai et al. at CRYPTO'03, but this adversary's model doesn't consider any physical hardware defaults and thus such masking schemes were shown to be still vulnerable when implemented as hardware circuits.To address these limitations glitch-extended probing adversaries and correspondingly glitch-immune masking schemes have been introduced.This paper introduces glitch-stopping circuits, which coincide with circuits protected via glitch-immune masking when instantiated with registers.Then we show that one can instantiate glitch-stopping circuits without registers by using clocked logic gates or latches.This is illustrated for both ASIC and FPGA, offering a promising alternative to conventional register-based masked implementations.Compared to the traditional register-based approach, these register-free solutions can reduce the latency to a single cycle and achieve a lower area cost.We prove and experimentally confirm that the proposed solution is as secure as the register-based one.In summary, this paper proposes a novel method to address the latency of register-based hardware masking without jeopardizing their security.This method not only reduces the latency down to one clock cycle but also improves the area costs of the implementations. CCS CONCEPTS• Security and privacy → Side
Zhenda Zhang, Svetla Nikova, Ventzislav Nikov
CCS2
2024 SoK: Parameterization of Fault Adversary Models Connecting Theory and Practice
Dilara Toprakhisar, Svetla Nikova, Ventzislav Nikov
CT-RSA2
2024 Deep Selfish Proposing in Longest-Chain Proof-of-Stake Protocols
Roozbeh Sarenche, Svetla Nikova, Bart Preneel
FC (1)2
2023 The Random Fault Model
Siemen Dhooghe, Svetla Nikova
SAC2
2023 An Optimal Universal Construction for the Threshold Implementation of Bijective S-Boxes
abstract
Threshold implementation is a method based on secret sharing to secure cryptographic ciphers (and in particular S-boxes) against differential power analysis side-channel attacks which was proposed by Nikova, Rechberger, and Rijmen in 2006. Until now, threshold implementations were only constructed for specific types of functions and some small S-boxes, but no generic construction was ever presented. In this paper, we present the first universal threshold implementation with$t+2$shares that is applicable to any bijective S-box, where$t$is its algebraic degree (or is larger than the algebraic degree). While being universal, our construction is also optimal with respect to the number of shares, since the theoretically smallest possible number,$t+1$, is not attainable for some bijective S-boxes. Our results enable low latency secure hardware implementations without the need for additional randomness. In particular, we apply this result to find two uniform sharings of the AES S-box. The first sharing is obtained by using the threshold implementation of the inversion in$\mathbb {F}_{2^{8}}$and the second by using two threshold implementations of two cubic power permutations that decompose the inversion. Area and performance figures for hardware implementations are provided.
Enrico Piccione, Samuele Andreoli, Lilya Budaghyan, Claude Carlet, Siemen Dhooghe, Svetla Nikova, George Petrides, Vincent Rijmen
IEEE Trans. Inf. Theory6
2022 Guarding the First Order: The Rise of AES Maskings
Amund Askeland, Siemen Dhooghe, Svetla Nikova, Vincent Rijmen, Zhenda Zhang
CARDIS3
2021 LLTI: Low-Latency Threshold Implementations
abstract
With the enormous increase in portable cryptographic devices, physical attacks are becoming similarly popular. One of the most common physical attacks is Side-Channel Analysis (SCA), extremely dangerous due to its non-invasive nature. Threshold Implementations (TI) was proposed as the first countermeasure to provide provable security in masked hardware implementations. While most works on hardware masking are focused on optimizing the area requirements, with the newer and smaller technologies area is taking a backseat, and lowlatency is gaining importance. In this work, we revisit the scheme proposed by Arribas et al. in TCHES 2018 to secure unrolled implementations. We formalize and expand this methodology, to devise a masking scheme, derived from TI, designed to secure hardware implementations optimized for latency named Low-Latency Threshold Implementations (LLTI). By applying the distributive property and leveraging a divide-and-conquer strategy, we split a non-linear operation in layers which are masked separately. The result is a more efficient scheme than the former TI for any operation of algebraic degree greater than two, achieving great optimizations both in terms of speed and area. We compare the performance of first-order LLTI with first-order TI in securing a cubic gate and a degree-7 AND gate without using any registers in between. We achieve a 137% increase in maximum frequency and a 60% reduction in area for the cubic gate, and 3131 times reduction in area in the case of a degree-7 AND gate compared to TI. To further illustrate the power of our scheme we take a low-latency PRINCE implementation from the literature and, by simply changing the secure S-box with the LLTI version, we achieve a 46% max. frequency improvement and a 38% area reduction. Moreover, we apply LLTI to a secure a low-latency AES implementation and compare it with the TI version, achieving a 6.9 times max. freq. increase and a 47.2% area reduction.
Victor Arribas, Zhenda Zhang, Svetla Nikova
IEEE Trans. Inf. Forensics Secur.3
2020 Let's Tessellate: Tiling for Security Against Advanced Probe and Fault Adversaries
Siemen Dhooghe, Svetla Nikova
CARDIS2
2020 My Gadget Just Cares for Me - How NINA Can Prove Security Against Combined Attacks
Siemen Dhooghe, Svetla Nikova
CT-RSA2
2019 TIS'19: Theory of Implementation Security Workshop 2019
abstract
In this workshop, we focus on physical attacks and their countermeasures. With the advent of the Internet of Things, the interest in embedded cryptographic systems and physical attacks on these systems is steadily increasing, both in academia and industry. Sophisticated security certification and evaluation methods have been established to give assurance about the security claims by independent evaluation and testing. The certification has a drawback that it is time consuming and expensive. There is a need for further developing provably secure protection methods and automated verification tools, but also improving the efficiency and quality of certification by integrating these tools and methods. All these challenges motivate even more research on the Theory of Implementation Security.
Begül Bilgin, Svetla Nikova, Vincent Rijmen
CCS2
2018 CAPA: The Spirit of Beaver Against Physical Attacks
Oscar Reparaz, Lauren De Meyer, Begül Bilgin, Victor Arribas, Svetla Nikova, Ventzislav Nikov, Nigel P. Smart
CRYPTO (1)5
2018 Guards in Action: First-Order SCA Secure Implementations of Ketje Without Additional Randomness
abstract
Recently the CAESAR competition has announced several finalists among the submitted authenticated encryption algorithms, after an open selection process during the last 5 years. Applications using these algorithms are rapidly increasing today. Devices implementing these applications are enormously susceptible to physical attacks, which are able to retrieve secret data through side-channel information such as the power consumption or the electromagnetic radiations. In this work we present a Side-Channel Analysis resistant hardware implementation of the whole family of authenticated encryption schemes Ketje. By changing just one parameter, any of the Ketje designs can be obtained, and tailored for different applications, either lightweight or high throughput. We introduce a new protected Keccak implementation, as well as unprotected and protected Ketje implementations, which allow both encryption and decryption modes in the same module. In order to secure these implementations we make use of the masking scheme known as Threshold Implementations and complement it with the technique of "Changing of the Guards", achieving a first-order Side-Channel Analysis protected implementation with zero extra randomness needed. This way, no dedicated PRNG needs to be additionally implemented, avoiding issues such as the security of the PRNG itself or the quality of the randomness.
Victor Arribas, Svetla Nikova, Vincent Rijmen
DSD2
2017 A Privacy-Preserving Device Tracking System Using a Low-Power Wide-Area Network
Tomer Ashur, Jeroen Delvaux, Sanghan Lee, Pieter Maene, Eduard Marin, Svetla Nikova, Oscar Reparaz, Vladimir Rozic, Dave Singelée, Bohan Yang 0001, Bart Preneel
CANS6
2017 Securing the PRESENT Block Cipher Against Combined Side-Channel Analysis and Fault Attacks
abstract
In this paper, we present and evaluate a hardware implementation of the PRESENT block cipher secured against both side-channel analysis and fault attacks (FAs). The side-channel security is provided by the first-order threshold implementation masking scheme of the serialized PRESENT proposed by Poschmann et al. For the FA resistance, we employ the Private Circuits II countermeasure presented by Ishai et al. at Eurocrypt 2006, which we tailor to resist arbitrary 1-bit faults. We perform a side-channel evaluation using the state-of-the-art leakage detection tests, quantify the resource overhead of the Private Circuits II countermeasure, subdue the implementation to established differential FAs against the PRESENT block cipher, and contemplate on the structural resistance of the countermeasure. This paper provides the detailed instructions on how to successfully achieve a secure Private Circuits II implementation for the data path as well as the control logic.
Thomas De Cnudde, Svetla Nikova
IEEE Trans. Very Large Scale Integr. Syst.2
2016 Theory of Implementation Security Workshop (TIs 2016)
abstract
The Internet of Things (IoT) enables a network of communication between people-to-people, people-to-things and things-to-things. The security of these communications against all possible attacks is a significant part of todays security and privacy. Due to the design nature of IoT systems, IoT devices are easily accessible by attackers which increases the importance of their security against physical attacks. This workshop is dedicated to research on the design of cryptographic algorithms and implementations secure against physical attacks.
Begül Bilgin, Svetla Nikova, Vincent Rijmen
CCS2
2016 Masking AES with d+1 Shares in Hardware
Thomas De Cnudde, Oscar Reparaz, Begül Bilgin, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen
CHES4
2016 More Efficient Private Circuits II through Threshold Implementations
abstract
Since the introduction of Private Circuits at CRYPTO 2003, several works have attempted its implementation in hardware. Only very recently was an implementation of this masking scheme shown to survive state-of-the-art leakage detection tests. The overhead introduced to achieve the provable security was significant. Similarly, the implementational aspect of Private Circuits II, the tamper-resistant extension of Private Circuits presented at EUROCRYPT 2006, was only recently presented at RECONFIG 2015. It however relied on a combinational PC-I implementation, which is susceptible to both glitches and early evaluation. In this work, we evaluate a recently proposed Private Circuits implementation and its corresponding Threshold Implementation side by side and give a full comparison in an equal and fair setting. In succession, we take the smallest resulting masking scheme as basis for a new approach towards a secure PC-II implementation. In addition to quantifying the resource overhead of PC-II, our work provides detailed instructions on how to achieve PC-II in FPGAs.
Thomas De Cnudde, Svetla Nikova
FDTC2
2015 Compact Implementations of Multi-Sbox Designs
Begül Bilgin, Miroslav Knezevic, Ventzislav Nikov, Svetla Nikova
CARDIS4
2015 Higher-Order Threshold Implementation of the AES S-Box
Thomas De Cnudde, Begül Bilgin, Oscar Reparaz, Ventzislav Nikov, Svetla Nikova
CARDIS5
2015 Consolidating Masking Schemes
Oscar Reparaz, Begül Bilgin, Svetla Nikova, Benedikt Gierlichs, Ingrid Verbauwhede
CRYPTO (1)3
2015 Trade-Offs for Threshold Implementations Illustrated on AES
abstract
Embedded cryptographic devices are vulnerable to power analysis attacks. Threshold implementations (TIs) provide provable security against first-order power analysis attacks for hardware and software implementations. Like masking, the approach relies on secret sharing but it differs in the implementation of logic functions. While masking can fail to provide protection due to glitches in the circuit, TIs rely on few assumptions about the hardware and are fully compatible with standard design flows. We investigate two important properties of TIs in detail and point out interesting trade-offs between circuit area and randomness requirements. We propose two new TIs of AES that, starting from a common previously published implementation, illustrate possible trade-offs. We provide concrete ASIC implementation results for all three designs using the same library, and we evaluate the practical security of all three designs on the same FPGA platform. Our analysis allow us to directly compare the security provided by the different trade-offs, and to quantify the associated hardware cost.
Begül Bilgin, Benedikt Gierlichs, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2014 Higher-Order Threshold Implementations
Begül Bilgin, Benedikt Gierlichs, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen
ASIACRYPT (2)3
2014 TuLP: A Family of Lightweight Message Authentication Codes for Body Sensor Networks
Pieter H. Hartel, Svetla Nikova, Shaohua Tang, Bo Zhu 0007
J. Comput. Sci. Technol.3
2013 Efficient and First-Order DPA Resistant Implementations of Keccak
Begül Bilgin, Joan Daemen, Ventzislav Nikov, Svetla Nikova, Vincent Rijmen, Gilles Van Assche
CARDIS4
2012 Threshold Implementations of All 3 ×3 and 4 ×4 S-Boxes
Begül Bilgin, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen, Georg Stütz
CHES2
2011 Public-Key Encryption with Delegated Search
Luan Ibraimi, Svetla Nikova, Pieter H. Hartel, Willem Jonker
ACNS2
2011 Privacy Enhanced Access Control by Means of Policy Blinding
Saeed Sedghi, Pieter H. Hartel, Willem Jonker, Svetla Nikova
ISPEC4
2011 Secure Hardware Implementation of Nonlinear Functions in the Presence of Glitches
Svetla Nikova, Vincent Rijmen, Martin Schläffer
J. Cryptol.1
2010 Whirlwind: a new cryptographic hash function
abstract
A new cryptographic hash function Whirlwind is presented. We give the full specification and explain the design rationale. We show how the hash function can be implemented efficiently in software and give first performance numbers. A detailed analysis of the security against state-of-the-art cryptanalysis methods is also provided. In comparison to the algorithms submitted to the SHA-3 competition, Whirlwind takes recent developments in cryptanalysis into account by design. Even though software performance is not outstanding, it compares favourably with the 512-bit versions of SHA-3 candidates such as LANE or the original CubeHash proposal and is about on par with ECHO and MD6.
Paulo S. L. M. Barreto, Ventzislav Nikov, Svetla Nikova, Vincent Rijmen, Elmar Tischhauser
Des. Codes Cryptogr.3
2010 Galois geometries and applications
Jan De Beule, Yves Edel, Emilia Käsper, Andreas Klein 0001, Svetla Nikova, Bart Preneel, Jeroen Schillewaert, Leo Storme
Des. Codes Cryptogr.5
2007 A Modification of Jarecki and Saxena Proactive RSA Signature Scheme
abstract
Luo and Lu proposed URSA proactive signature scheme, the core of which is based on a new threshold signature protocol - the so-called t-bounded offsetting algorithm. Jarecki et al. have shown that the t-bounded offsetting algorithm leaks information for the shared secret which can be extended to a key-recovery attack on the URSA proactive signature scheme. Jarecki and Saxena proposed a fix to the scheme of Luo and Lu, turning it to a provably secure proactive RSA signature scheme. The authors also posed two open questions on the proactive RSA signature schemes. In this paper we give a solution to the second open problem posed by Jarecki and Saxena. Namely, we propose a proactive RSA signature scheme which does not require all participants to be active in the signature generation protocol.
Ventzislav Nikov, Svetla Nikova
ISIT2
2006 A Weakness in Some Oblivious Transfer and Zero-Knowledge Protocols
Ventzislav Nikov, Svetla Nikova, Bart Preneel
ASIACRYPT2
2006 Threshold Implementations Against Side-Channel Attacks and Glitches
Svetla Nikova, Christian Rechberger, Vincent Rijmen
ICICS1
2006 Classification of cubic (n-4)-resilient Boolean functions
abstract
Carlet and Charpin classified the set of cubic (n-4)-resilient Boolean functions into four different types with respect to the Walsh spectrum and the dimension of the linear space. Based on the classification of RM(3,6)/RM(1,6), we have completed this classification of cubic (n-4)-resilient Boolean functions by deriving the corresponding algebraic normal form (ANF) and autocorrelation spectrum for each of the four types. At the same time, we have solved an open problem by proving that all plateaued cubic (n-4)-resilient Boolean functions have dimension of the linear space equal either to n-5 or n-6.
An Braeken, Yuri L. Borissov, Svetla Nikova, Bart Preneel
IEEE Trans. Inf. Theory3
2005 Error-Set Codes and Related Objects
An Braeken, Ventzislav Nikov, Svetla Nikova
COCOON3
2005 Classification of Boolean Functions of 6 Variables or Less with Respect to Some Cryptographic Properties
An Braeken, Yuri L. Borissov, Svetla Nikova, Bart Preneel
ICALP3
2005 On the covering radii of binary Reed-Muller codes in the set of resilient Boolean functions
abstract
Let R/sub t,n/ be the set of t-resilient Boolean functions in n variables, and let /spl rho//spl circ/(t,r,n) be the maximum distance between t-resilient functions and the rth-order Reed-Muller code RM(r,n). We prove that /spl rho//spl circ/(t,2,6)=16 for t=0,1,2 and /spl rho//spl circ/(3,2,7)=32, from which we derive the lower bound /spl rho//spl circ/(t,2,n) /spl ges/ 2/sup n-2/ with t /spl les/ n-4. Using a result from coding theory on the covering radius of (n-3)th- and (n-4)th-order Reed-Muller codes, we establish exact values of the covering radius of RM(n-3,n) in the set of 1-resilient Boolean functions in n variables, when /spl lfloor/n/2/spl rfloor/=1 mod 2 and lower bounds of RM(n-4,n) in the set of 2-resilient Boolean functions in n variables. This result leads again to different lower bounds for general dimensions n and r=0 or 3 mod 4.
Yuri L. Borissov, An Braeken, Svetla Nikova, Bart Preneel
IEEE Trans. Inf. Theory3
2004 Robust Metering Schemes for General Access Structures
Ventzislav Nikov, Svetla Nikova, Bart Preneel
ICICS2
2003 Multi-party Computation from Any Linear Secret Sharing Scheme Unconditionally Secure against Adaptive Adversary: The Zero-Error Case
Ventzislav Nikov, Svetla Nikova, Bart Preneel
ACNS2
2003 On the Covering Radius of Second Order Binary Reed-Muller Code in the Set of Resilient Boolean Functions
Yuri L. Borissov, An Braeken, Svetla Nikova, Bart Preneel
IMACC3
2003 On the Non-minimal Codewords in Binary Reed-Muller Codes
Yuri L. Borissov, Nikolai L. Manev, Svetla Nikova
Discret. Appl. Math.3
2003 Improvement of the Delsarte Bound for t-Designs When It Is Not the Best Bound Possible
Svetla Nikova, Ventzislav Nikov
Des. Codes Cryptogr.1
2001 Improvement of the Delsarte Bound for tau-Designs in Finite Polynomial Metric Spaces
Svetla Nikova, Ventzislav Nikov
IMACC1
1999 Some Applications of Bounds for Designs to the Cryptography
Svetla Nikova, Ventzislav Nikov
IMACC1
1999 Nonexistence of Certain Spherical Designs of Odd Strengths and Cardinalities
Peter G. Boyvalenkov, Danyo Danev, Svetla Nikova
Discret. Comput. Geom.3