Tristan Claverie

dblp:296/9376 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Formal Analysis of Random Nonce Misuses in Cryptographic Protocols
abstract
Cryptographic protocols commonly use (random) nonces to guarantee security properties. Although it is known for a long time that nonces should benefit from clear security properties, modern standards regularly miss this fundamental requirement. The lack of clear recommendations leads to error-prone cryptographic implementations, especially vulnerabilities due to nonce reuse and nonce leakage. This paper introduces a method based on TAMARIN to identify with a systematic approach the nonce-related properties an implementation should guarantee to ensure the security of a cryptographic protocol. As a corollary, the method also determines the security impact of a nonce misuse. Our method also applies to other types of random values used in protocols, namely ephemeral keys, masks, and nonces used in randomized primitives. This approach is then extended to take into account the well-known weaknesses of some randomized primitives when nonces are reused. The paper finally applies the method to real-life cryptographic protocols, discovering so new vulnerabilities related to nonce misuses in Dragonfly, WPA3, and Bluetooth.
Gildas Avoine, Tristan Claverie, Stéphanie Delaune
CSF2
2024 Time-Memory Trade-Offs Sound the Death Knell for GPRS and GSM
Gildas Avoine, Xavier Carpent, Tristan Claverie, Christophe Devine, Diane Leblanc-Albarel
CRYPTO (4)3
2023 Tamarin-Based Analysis of Bluetooth Uncovers Two Practical Pairing Confusion Attacks
Tristan Claverie, Gildas Avoine, Stéphanie Delaune, José Lopes-Esteves
ESORICS (3)1