Davide Galli

dblp:319/7300 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2025
0009-0005-9430-7699ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 3 first-author · 7 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Rabbit: Dynamic Clock Randomization to Protect against Side-Channel Attacks
abstract
The continuous evolution of side-channel analysis motivates a continuous investigation to deliver novel countermeasures. This work presents a hiding countermeasure leveraging a randomized Dynamic Frequency Scaling (DFS) actuator built on top of the clocking resources available in modern FPGAs. In contrast to state-of-the-art DFS-based solutions, our approach is meant to optimize security and performance metrics with a modest increase in power consumption. We experimentally validated our countermeasure on real hardware by comparing it against recently proposed hiding methods employing clock desynchronization. To strengthen our security assessment, we also considered a large variety of state-of-the-art side-channel attacks, including recent deep-learning ones. The experimental results confirm that none of the evaluated attack techniques can breach our protected target, and TLVA shows no information leakage with 10 million traces. The performance overhead is zero, while the power overhead is limited to 1.55×.
Davide Galli, Matteo Matteucci, Davide Zoni
ISCAS1
2025 A Deep Learning-Assisted Template Attack Against Dynamic Frequency Scaling Countermeasures
abstract
In the last decades, machine learning techniques have been extensively used in place of classical template attacks to implement profiled side-channel analysis. This manuscript focuses on the application of machine learning to counteract Dynamic Frequency Scaling defenses. While state-of-the-art attacks have shown promising results against desynchronization countermeasures, a robust attack strategy has yet to be realized. Motivated by the simplicity and effectiveness of template attacks for devices lacking desynchronization countermeasures, this work presents a Deep Learning-assisted Template Attack (DLaTA) methodology specifically designed to target highly desynchronized traces through Dynamic Frequency Scaling. A deep learning-based pre-processing step recovers information obscured by desynchronization, followed by a template attack for key extraction. Specifically, we developed a three-stage deep learning pipeline to resynchronize traces to a uniform reference clock frequency. The experimental results on the AES cryptosystem executed on a RISC-V System-on-Chip reported a Guessing Entropy equal to 1 and a Guessing Distance greater than 0.25. Results demonstrate the method's ability to successfully retrieve secret keys even in the presence of high desynchronization. As an additional contribution, we publicly release ourDFS_DESYNCHdatabase11https://github.com/hardware-fab/DLaTAcontaining the first set of real-world highly desynchronized power traces from the execution of a software AES cryptosystem.
Davide Galli, Francesco Lattari, Matteo Matteucci, Davide Zoni
IEEE Trans. Computers1
2025 An FPGA-Based Open-Source Hardware-Software Framework for Side-Channel Security Research
abstract
Attacks based on side-channel analysis (SCA) pose a severe security threat to modern computing platforms, further exacerbated on IoT devices by their pervasiveness and handling of private and critical data. Designing SCA-resistant computing platforms requires a significant additional effort in the early stages of the IoT devices’ life cycle, which is severely constrained by strict time-to-market deadlines and tight budgets. This manuscript introduces a hardware-software framework meant for SCA research on FPGA targets. It delivers an IoT-class system-on-chip (SoC) that includes a RISC-V CPU, provides observability and controllability through an ad-hoc debug infrastructure to facilitate SCA attacks and evaluate the platform's security, and streamlines the deployment of SCA countermeasures through dedicated hardware and software features such as a DFS actuator and FreeRTOS support. The open-source release of the framework includes the SoC, the scripts to configure the computing platform, compile a target application, and assess the SCA security, as well as a suite of state-of-the-art attacks and countermeasures. The goal is to foster its adoption and novel developments in the field, empowering designers and researchers to focus on studying SCA countermeasures and attacks while relying on a sound and stable hardware-software platform as the foundation for their research.
Davide Zoni, Andrea Galimberti, Davide Galli
IEEE Trans. Computers3
2024 A Deep- Learning Technique to Locate Cryptographic Operations in Side-Channel Traces
abstract
Side-channel attacks allow extracting secret infor-mation from the execution of cryptographic primitives by cor-relating the partially known computed data and the measured side-channel signal. However, to set up a successful side-channel attack, the attacker has to perform i) the challenging task of locating the time instant in which the target cryptographic primitive is executed inside a side-channel trace and then ii) the time-alignment of the measured data on that time instant. This paper presents a novel deep-learning technique to locate the time instant in which the target computed cryptographic operations are executed in the side-channel trace. In contrast to state-of-the-art solutions, the proposed methodology works even in the presence of trace deformations obtained through random delay insertion techniques. We validated our proposal through a successful attack against a variety of unprotected and protected cryptographic primitives that have been executed on an FPGA-implemented system-on-chip featuring a RISC- V CPU.
Giuseppe Chiari, Davide Galli, Francesco Lattari, Matteo Matteucci, Davide Zoni
DATE2
2024 Hound: Locating Cryptographic Primitives in Desynchronized Side-Channel Traces using Deep-Learning
abstract
Side-channel attacks allow the extraction of sensitive information from cryptographic primitives by correlating the partially known computed data and the measured side-channel signal. Starting from the raw side-channel trace, the preprocessing of the side-channel trace to pinpoint the time at which each cryptographic primitive is executed, and, then, to re-align all the collected data to this specific time represent a critical step to setup a successful side-channel attack. The use of hiding techniques has been widely adopted as a low-cost solution to hinder the preprocessing of side-channel traces, thus limiting side-channel attacks in real scenarios. This work introduces Hound, a novel deep-learning-based pipeline to locate the execution of cryptographic primitives within the side-channel trace even in the presence of trace deformations introduced by the use of dynamic frequency scaling actuators. Hound has been validated through successful attacks on various cryptographic primitives executed on an FPGA-based system-on-chip incorporating a RISC- V CPU while dynamic frequency scaling is active. Experimental results demonstrate the possibility of identifying the cryptographic primitives in DFS-deformed side-channel traces.
Davide Galli, Giuseppe Chiari, Davide Zoni
ICCD1
2022 On the use of hardware accelerators in QC-MDPC code-based cryptography
abstract
Public-key cryptography (PKC) allows exchanging keys over an insecure channel without sharing a secret key. However, quantum computers threaten to break traditional PKC, thus, to mitigate such risk, post-quantum cryptography (PQC) aims to develop cryptosystems that are secure against attacks from quantum and classical computers. BIKE [1] is a key encapsulation mechanism (KEM) based on quasi-cyclic moderate-density parity-check (QC-MDPC) codes that is a candidate within the NIST standardization process to identify a set of PQC algorithms [4]. Figure 1 depicts the key exchange between two client and server nodes, which requires the sequential execution of the key generation, encapsulation, and decapsulation KEM primitives. Key generation and decapsulation are performed on the client side, while encapsulation is carried out by the server. Despite the vast literature targeting efficient hardware support for BIKE, each proposal delivered computing platforms meant either to maximize performance or minimize resource utilization.
Andrea Galimberti, Davide Galli, Gabriele Montanaro, William Fornaciari, Davide Zoni
CF2
2022 FPGA implementation of BIKE for quantum-resistant TLS
abstract
The recent advances in quantum computers impose the adoption of post-quantum cryptosystems into secure communication protocols. This work proposes two FPGA-based, client- and server-side hardware architectures to support the integration of the BIKE post-quantum KEM within TLS. Thanks to the parametric hardware design, the paper explores the best option between hardware and software implementations, given a set of available hardware resources and a realistic use-case scenario. The experimental evaluation comparing our client and server designs against the reference AVX2 and hardware implementations of BIKE highlighted two aspects. First, the proposed client and server architectures outperform the reference hardware implementation of BIKE by eight and four times, respectively. Second, the performance comparison between our client and server designs against the reference AVX2 implementation strongly depends on the available resource. Our solution is almost twice as fast as the AVX2 implementation while implemented on the Artix-7 200 FPGA, while it is up to six times slower when targeting smaller FPGAs, thus motivating a careful analysis of the available hardware resources and the optimization of the design's parallelism before opting for hardware support.
Andrea Galimberti, Davide Galli, Gabriele Montanaro, William Fornaciari, Davide Zoni
DSD2