EDBT 2026 Demo / reviewers in the wild / expert
Philippe Maurine
dblp:32/2846
· DBLP profile ↗
57ranked-venue papers
2as first author
11since 2021 · last 2025
0000-0002-9706-5710ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 38 · 1 first-author · 5 since 2021Security and privacy · 18 · 1 first-author · 6 since 2021Software engineering, systems software and programming languages · 10 · 2 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Fault Analysis through Body Bias Injection on the FLASH Memory Accelerator of a MicrocontrollerabstractThe FLASH interface is a crucial component in modern Microcontrollers (MCUs), serving as an intermediary for transferring instructions between the processor and program memory. Previous studies have demonstrated the effectiveness of Electromagnetic Fault Injection (EMFI) and Laser Fault Injection (LFI) in disrupting the operation of FLASH accelerators, leading to instruction line replay and skip faults. However these studies are limited to the case of sequential code and to a single FLASH interface configuration of the target MCU. In this work, we present an investigation on the impact of Body Bias Injection (BBI) on the FLASH accelerator in a 32-bit MCU.The experiments confirm that BBI can similarly induce instruction line replay and skip faults. A detailed analysis of the fault manifestations under various operational configurations of the FLASH accelerator is provided. The study has also extended the fault model to the case of branch operation (non-sequential code).This research contributes a refined understanding of FLASH interface fault behavior under BBI, and highlights the security implication of the decorrelated design between the Program Counter and the FLASH interface. Ziling Liao, Florent Bruguier, Philippe Maurine |
FDTC | 3 |
| 2025 | PLL Over-Clocking Through Repeated Fault InjectionsabstractClock glitch attacks are among the least expensive fault injection methods that target integrated circuits (ICs). However, the widespread use of phase-locked loops (PLLs) has rendered traditional clock glitch attacks ineffective in most circuits. This article demonstrates that over-clocking can be obtained by injecting faults into the PLL itself, enabling the replication of clock glitch effects. This method is feasible even when the PLL reference clock is internally generated. The phase-frequency detector (PFD) is directly targeted, which makes this attack broadly applicable. Its theoretical fault model is derived and used to build a stochastic analysis of the impact of faults on the output frequency of the PLL. Finally, laser fault injection on a real PLL IC demonstrates the practical feasibility of this method. The PLL output frequency is accurately modified with relative variations ranging from 0% to 178%. This work provides a generic fault injection methodology that enables the replication of clock glitch effects on circuits previously considered immune to them. This work impacts the security of most ICs, and provides a better understanding of PLLs that could be used in the field of electromagnetic compatibility. Louis Dubois, Philippe Maurine |
IOLTS | 2 |
| 2025 | Body Bias Injection on the FLASH Memory Accelerator of a 32-Bit MicrocontrollerabstractProgram flow attacks involve disrupting the flow of instruction execution in microcontrollers (MCUs), thereby threatening their operation. While traditional studies focus on program counter or instruction corruptions within pipelines, little attention has been paid to the stages between FLASH memory and the CPU, such as memory accelerators. Body Bias Injection (BBI) is a fault injection technique in which a voltage pulse is applied to the backside of an integrated circuit, i.e. its substrate, causing localized disruptions in the power network. Despite its proven effectiveness in inducing transient faults, to the best of our knowledge, there is no information on its impact on MCU program flow. Within this context, this paper demonstrates that BBI can efficiently disrupt MCU program flow, causing entire instruction lines to be skipped or repeated. It also shows that the most sensitive part of the MCUs against BBI is likely to be the memory accelerator rather than the processor itself. Ziling Liao, Florent Bruguier, Philippe Maurine |
IOLTS | 3 |
| 2023 | Bernoulli at the Root of Horizontal Side Channel Attacks
Gauthier Cler, Sébastien Ordas, Philippe Maurine |
CARDIS | 3 |
| 2023 | A better practice for Body Biasing InjectionabstractBody Biasing Injection (BBI) is a fault injection method involving applying a voltage pulse onto the backside substrate of integrated circuits using a conductive needle. Some studies have been focusing on the characterization of BBI effects, but no fault model explaining the origin of the induced faults has yet been established. The repeatability of this method has been demonstrated, and electrical models have been proposed. However, up to the best of our knowledge, no successful differential fault attack using BBI and single bit fault model on hardware coprocessors has yet been reported in the literature. Within this context, this work presents enhanced practices to perform BBI in an even more reproducible and reliable way compared to previous works. It also brings insights on how and why faults occur under BBI and presents a fault attack performed on a hardware AES coprocessor embedded in a modern 32-bits microcontroller. Geoffrey Chancel, Jean-Marc Gallière, Philippe Maurine |
FDTC | 3 |
| 2023 | Revisiting Mutual Information Analysis: Multidimensionality, Neural Estimation and Optimality Proofs
Valence Cristiani, Maxime Lecomte, Philippe Maurine |
J. Cryptol. | 3 |
| 2023 | (Adversarial) Electromagnetic Disturbance in the IndustryabstractFaults occur naturally and are responsible for reliability concerns. Faults are also an interesting tool for attackers to extract sensitive information from secure chips. In particular, non-invasive fault attacks have received a fair amount of attention. One easy way to perturb a chip without altering it is the so-called Electromagnetic Fault Injection (EMFI). Such attack has been studied in great depth, and nowadays, it is part and parcel of the state-of-the-art. Indeed, new capabilities have emerged where EM experimental benches are used to cryptanalyze chips. The progress of this “field” is fast, in terms ofreproducibility,accuracy, andnumber of use-cases. However, there is too little awareness about such advances. In this paper, we aim to expose the true harmfulness of EMFI (including reproducibility) to enable reasonable security quotations. We also analyze protections (at hardware/firmware/system levels) in light of their efficiency. We characterize the specificity of EM fault injection compared to other injection means (laser, glitch, probing). Arthur Beckers, Sylvain Guilley, Philippe Maurine, Colin O'Flynn, Stjepan Picek |
IEEE Trans. Computers | 3 |
| 2022 | Body Biasing Injection: Impact of substrate types on the induced disturbancesƒabstractBody Biasing Injection (BBI) is one of the most recent fault injection techniques. It consists of applying voltage pulses onto the substrate of integrated circuits (ICs) using a sharp needle. Because this technique is more recent, there is little information about the nature of the injected disturbances in the ICs. It is especially true if one considers that the substrate of microcontrollers can either be of dual or triple-well types, and thus can have different susceptibility to BBI. In previous work, a study of the effects of thinning the substrate of ICs on BBI and an electrical model were proposed. However, this study was only conducted for dual-well ICs. As a result, this paper provides enhanced electrical models to simulate the distribution of BBI disturbances through the different substrates, and it also gives a global view of the different BBI induced effects in relation to the nature of the substrate and the polarity of the injected voltage pulses. Geoffrey Chancel, Jean-Marc Gallière, Philippe Maurine |
FDTC | 3 |
| 2022 | Checking Robustness Against EM Side-Channel Attacks Prior to ManufacturingabstractElectromagnetic attacks, which in fact exploit essentially the magnetic field generated by ICs, are commonly used by adversaries to retrieve secret information manipulated by integrated circuits. Due to the increasing resolution and effectiveness of EM equipment used to perform these attacks, it is becoming increasingly difficult to design secure circuits robust enough to resist these attacks. The contribution of this article is threefold. First, it describes a simulation flow of the magnetic field radiated by ICs. The introduced flow is based on an industrial voltage drop tool: ANSYS RedHawk. Second, it introduces a methodology to localize the root cause of leakages in ICs as well as EM hotspots, i.e., positions above the IC surface, where an adversary can place its probe to capture secrets. The latter contribution is based on the concept of noise to add, which is introduced in this article in order to overcome the absence of noise in simulations (noise which is omnipresent in practice) that limits their interpretability. Finally, the article demonstrates the soundness of the proposed solution by confronting simulation results with measurements. Davide Poggi, Thomas Ordas, Alexandre Sarafianos, Philippe Maurine |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2021 | On the scaling of EMFI probesabstractElectromagnetic fault injection (EMFI), which is a quite recent fault injection technique compared to laser fault injection, has gained in popularity these last years. Its increasing popularity can be probably explained by its inherent advantages among which the limited required preparation of devices can be viewed as the main one. The principle of EMFI consists in generating a powerful EM pulse in the close vicinity of ICs. To that aim a voltage pulse generator is used to induce a sudden current variation in probes, i.e. coils made of several wire turns around a ferrite core. However, EMFI is considered a fault injection technique with a poor spatial resolution mainly because EMFI probes are quite large. Increasing the spatial resolution of EMFI could be achieved by reducing the dimensions of probes. However, such a task is difficult and implies using more powerful voltage generators. Among the challenges to be addressed to enhance the spatial resolution of probes, one of the first ones is to determine how should be scaled the voltage pulse generators with the scaling of probe dimensions. This paper addresses this question from theoretical and practical points of view. Julien Toulemont, Geoffrey Chancel, Jean-Marc Gallière, Frédérick Mailly, Pascal Nouet, Philippe Maurine |
FDTC | 6 |
| 2021 | Modeling and Simulating Electromagnetic Fault InjectionabstractElectromagnetic fault injection (EMFI) has recently gained popularity as a mean to induce faults because of its inherent advantages. Despite this popularity, there is only a little information on how EMFI generates faults. Within this context, this article aims at filling this lack by proposing a complete understanding and modeling of EM induction on integrated circuits (ICs). The presented model is confronted to experiments to endorse its soundness. Mathieu Dumont, Mathieu Lisart, Philippe Maurine |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2020 | Simulation and Experimental Demonstration of the Importance of IR-Drops During Laser Fault InjectionabstractLaser fault injections induce transient faults into ICs by locally generating transient currents that temporarily flip the outputs of the illuminated gates. Laser fault injection can be anticipated or studied by using simulation tools at different abstraction levels: physical, electrical, or logical. At the electrical level, the classical laser fault injection model is based on the addition of current sources to the various sensitive nodes of CMOS transistors. However, this model does not take into account the large transient current components also induced between the VDD and GND of ICs designed with advanced CMOS technologies. These short-circuit currents provoke a significant IR-drop that contribute to the fault injection process. This paper describes our research on the assessment of this contribution. It shows through simulation and experiments that during laser fault injection campaigns, laser-induced IR-drop is always present when considering circuits designed with deep submicron technologies. It introduces an enhanced electrical fault model taking the laser-induced IR-drop into account. It also proposes a methodology that allows the use of the model to simulate laser-induced faults at the electrical level in large-scale circuits. On the basis of further simulations and experimental results, we found that, depending on the laser pulse characteristics, the number of injected faults may be underestimated by a factor of up to 2.4 if the laser-induced IR-drop is ignored. This could lead to incorrect estimations of the fault injection threshold, which is especially relevant to the design of countermeasure techniques for secure integrated systems. Raphael Viera 0001, Philippe Maurine, Jean-Max Dutertre, Rodrigo Possamai Bastos |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2019 | Electromagnetic Fault Injection : How Faults OccurabstractElectromagnetic Fault Injection (EMFI) has recently gained popularity as a mean to induce faults because of its inherent advantages. Among them, the most interesting is probably its ability to generate faults in Systems on Chips without removing the package, and this even if only the frontside is exposed to the EM field. Despite this popularity, there is only little information on how EMFI generates faults. Within this context, this paper first aims at filling this lack by proposing a complete modeling of EM induction fault mechanism. In a second step, the introduced model is confronted to experimental data in order to demonstrate its soundness. Mathieu Dumont, Mathieu Lisart, Philippe Maurine |
FDTC | 3 |
| 2018 | Electromagnetic Activity vs. Logical Activity: Near Field Scans for Reverse Engineering
Marc Lacruche, Philippe Maurine |
CARDIS | 2 |
| 2018 | Exploiting Phase Information in Thermal Scans for Stealthy Trojan DetectionabstractInfrared thermography has been recognized for its ability to investigate integrated circuits in a non destructive way. Coupled to lock-in correlation it has proven efficient in detecting thermal hot spots. Most of the state of the Art measurement systems are based on amplitude analysis. In this paper we propose to investigate weak thermal hot spots using the phase of infrared signals. We demonstrate that phase analysis is a formidable alternative to amplitude to detect small heat signatures. Finally, we apply our measurement platform and its detection method to the identification of stealthy hardware Trojans. Maxime Cozzi, Jean-Marc Gallière, Philippe Maurine |
DSD | 3 |
| 2018 | The Impact of Pulsed Electromagnetic Fault Injection on True Random Number GeneratorsabstractRandom number generation is a key function of today's secure devices. Commonly used for key generation, random number streams are more and more frequently used as the anchor of trust of several countermeasures such as masking. True Random Number Generators (TRNGs) thus become a relevant entry point for attacks that aim at lowering the security of integrated systems. Within this context, this paper investigates the robustness of TRNGs based on Ring Oscillators (focusing on the delay chain TRNG) against pulsed electromagnetic fault injection. Indeed, weaknesses in generating random bits for masking scheme degenerate the Side Channel resistance. Finally by exploiting fault results on delay chain TRNG some general guidelines to harden them are derived. Maxime Madau, Michel Agoyan, Josep Balasch, Milos Grujic, Patrick Haddad, Philippe Maurine, Vladimir Rozic, Dave Singelée, Bohan Yang 0001, Ingrid Verbauwhede |
FDTC | 6 |
| 2018 | Standard CAD Tool-Based Method for Simulation of Laser-Induced Faults in Large-Scale CircuitsabstractDesigning secure integrated systems requires methods and tools dedicated to simulating that early design stages' the effects of laser-induced transient faults maliciously injected by attackers. Existing methods for simulation of laser-induced transient faults do not take into account IR drop effects that are able to cause timing failures, abnormal reset, and SRAM flipping. This paper proposes a novel standard CAD tool-based method allowing to simulate laser-induced faults in large-scale circuits. Thanks to a power-grid network modeled by a commercial IR drop CAD tool, an additional transient current component causing laser-induced IR drop is taken into consideration. This current component flows from Vdd to Gnd and may have a significant effect on the fault injection process. The method provides fault sensitivity maps that enable a quick assessment of laser-induced fault effects on the circuit under analysis. As shown in the results, the number of induced faults is underestimated by a factor as large as 3.1 if laser-induced IR drop is ignored. This may lead to incorrect estimations of the fault injection threshold, which is especially relevant for the design of countermeasure techniques for secure integrated systems. Simulation times regarding four different circuits are also presented in the results section. Raphael Viera 0001, Jean-Max Dutertre, Philippe Maurine, Rodrigo Possamai Bastos |
ISPD | 3 |
| 2018 | Estimating the Signal-to-Noise Ratio Under Repeated Sampling of the Same Centered Signal: Applications to Side-Channel Attacks on a CryptoprocessorabstractThis paper introduces an estimator of the signal-to-noise ratio in the framework where a noisy source emits the same signal a number n of times. The estimator has the structure of a U-statistic from which derives many desirable properties: it is unbiased, consistent and, being a Rao-Blackwellisation of existing proposals, is closer to optimal variance-wise. However, its variance is numerically difficult to evaluate and two approximations are obtained to facilitate its use in practice. These allow quantifying the improvement in variance, which is found to be substantial as the estimator needs roughly one-third of the data previously required to perform similarly. Moreover, a simulation shows that the estimator is approximately normally distributed for n as small as 10, which allows for accurate inference. The estimator is then applied to data arising in a cryptanalysis, where the numerical security of a cryptoprocessor is tested against a side-channel attack. This problem is a representative of situations where the signal-to-noise ratio must be precisely estimated for small n. We derive a rigorous data-driven approach that is shown to much enhance the efficiency of standard side-channel attacks. Gilles R. Ducharme, Philippe Maurine |
IEEE Trans. Inf. Theory | 2 |
| 2017 | An EM Fault Injection Susceptibility Criterion and Its Application to the Localization of Hotspots
Maxime Madau, Michel Agoyan, Philippe Maurine |
CARDIS | 3 |
| 2017 | Role of Laser-Induced IR Drops in the Occurrence of Faults: Assessment and SimulationabstractLaser fault injection attacks induce transient faults into ICs by locally generating transient currents capable of temporarily flipping the outputs of logic gates. Laser fault injection may be anticipated or studied by using simulation tools at different abstraction levels: physical, electrical or logical. At the electrical level, the general laser-fault injection model is based on the addition of current sources to the various sensitive nodes of CMOS transistors. This type of electrical model does not take into account the large transient current components also induced between VDD and GND as a result of laser illumination. Such current components have no direct effect on the logic gate output nodes. Still, they provoke a significant IR-drop that may, in turn, contribute to the fault injection process. This paper describes our research on the assessment of this contribution. It introduces an upgraded electrical model taking the laser-induced IR-drop into account. It also proposes a methodology that allows the model's use to simulate laser-induced faults at electrical level in large-scale circuits. On the basis of simulations with a case-study circuit, we found that, depending on the parameters of the laser pulse, the number of injected faults may be underestimated by a factor as large as 48 if the laser-induced IR-drop is ignored. This may lead to incorrect estimations of the fault injection threshold, which is especially relevant for the design of countermeasure techniques for secure integrated systems. Raphael Viera 0001, Jean-Max Dutertre, Rodrigo Possamai Bastos, Philippe Maurine |
DSD | 4 |
| 2017 | An On-Chip Technique to Detect Hardware Trojans and Assist Counterfeit IdentificationabstractInternational audience Maxime Lecomte, Jacques J. A. Fournier, Philippe Maurine |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2016 | A fully-digital EM pulse detector
David El-Baze, Jean-Baptiste Rigaud, Philippe Maurine |
DATE | 3 |
| 2016 | On-chip fingerprinting of IC topology for integrity verification
Maxime Lecomte, Jacques J. A. Fournier, Philippe Maurine |
DATE | 3 |
| 2016 | An Embedded Digital Sensor against EM and BB Fault InjectionabstractFault Attacks methods like Electro-Magnetic PulseInjection or Body Biasing Injection have recently been demon-strated to be efficient against smartcards and Systems on Chip. As of now, security is a main constraint in product development, even for low-cost products riding the trend of the IoT (mostof these devices operate in hostile environments). Unfortunately, the implementation of hardware countermeasures has a costin silicon area, design time and performance. Therefore, it isimportant to develop protections while taking into account theircosts and easyness of implementation. One way to achieve theseends would be to have an all-in-one fully digital detector whoseintegration is compliant with the standard cell design flow. Inthis perspective, we propose an enhanced sensor to detect severaltypes of attacks by exploiting analog phenomena induced at thegate level, instead of the attack itself. This paper describes thedesign and the implementation into FPGAs of this sensor, as wellas experimental tests demonstrating its effectiveness for detectingelectro-magnetic and body bias fault injection attempts. David El-Baze, Jean-Baptiste Rigaud, Philippe Maurine |
FDTC | 3 |
| 2015 | Collision for Estimating SCA Measurement Quality and Related Applications
Ibrahima Diop, Mathieu Carbone, Sébastien Ordas, Yanis Linge, Pierre-Yvan Liardet, Philippe Maurine |
CARDIS | 6 |
| 2015 | Collision Based Attacks in PracticeabstractChosen-Message Simple Power Analysis, also called Collision Based Attacks (CBA), have been proposed by Fouque, Yen and Homma. These attacks aim at inducing and detecting collisions during modular operations. However, detecting collisions is a challenging task in real environments. Doing it in an automated manner is even more challenging. In this paper, we propose and compare some methods and criteria allowing to automatically (without any visual inspection) detect the occurrence of collisions in leakage traces acquired on modern (and thus noisy) circuits. Ibrahima Diop, Pierre-Yvan Liardet, Yanis Linge, Philippe Maurine |
DSD | 4 |
| 2015 | EM Injection: Fault Model and LocalityabstractEM injection recently emerged as an effective medium for fault injection. This paper presents an analysis of the IC susceptibility to EM pulses. It highlights that faults produced by EM pulse injection are not timing faults but correspond to a different model which is presented in this paper. This model also allows to explain experimental results introduced in former communications. Sébastien Ordas, Ludovic Guillaume-Sage, Philippe Maurine |
FDTC | 3 |
| 2014 | Evidence of a Larger EM-Induced Fault Model
Sébastien Ordas, Ludovic Guillaume-Sage, Karim Tobich, Jean-Max Dutertre, Philippe Maurine |
CARDIS | 5 |
| 2014 | Efficiency of a glitch detector against electromagnetic fault injectionabstractThe use of electromagnetic glitches has recently emerged as an effective fault injection technique for the purpose of conducting physical attacks against integrated circuits. First research works have shown that electromagnetic faults are induced by timing constraint violations and that they are also located in the vicinity of the injection probe. This paper reports the study of the efficiency of a glitch detector against EM injection. This detector was originally designed to detect any attempt of inducing timing violations by means of clock or power glitches. Because electromagnetic disturbances are more local than global, the use of a single detector proved to be inefficient. Our subsequent investigation of the use of several detectors to obtain a full fault detection coverage is reported, it also provides further insights into the properties of electromagnetic injection and into the key role played by the injection probe. Loïc Zussa, Amine Dehbaoui, Karim Tobich, Jean-Max Dutertre, Philippe Maurine, Ludovic Guillaume-Sage, Jessy Clédière, Assia Tria |
DATE | 5 |
| 2014 | Electromagnetic analysis, deciphering and reverse engineering of integrated circuits (E-MATA HARI)abstractElectromagnetic fault injections are produced on secured ICs aiming to break crypto codes. We describe in this paper the whole chain of optimization necessary to achieve this goal, namely 1/ physical optimization of near-field probe and setup, 2/ signal management in timing, shape, and localization to induce the fault while beating countermeasures and 3/ understanding of fault propagation in logic to eventually protect future ICs. Laurent Chusseau, Rachid Omarouayache, Jérémy Raoult, Sylvie Jarrix, Philippe Maurine, Karim Tobich, Alexandre Boyer, Bertrand Vrignon, John Shepherd 0004, Maël Berthier, Lionel Rivière, Bruno Robisson, Anne-Lise Ribotta |
VLSI-SoC | 5 |
| 2014 | Electromagnetic analysis and fault injection onto secure circuitsabstractImplementation attacks are a major threat to hardware cryptographic implementations. These attacks exploit the correlation existing between the computed data and variables such as computation time, consumed power, and electromagnetic (EM) emissions. Recently, the EM channel has been proven as an effective passive and active attack technique against secure implementations. In this paper, we resume the recent results obtained on this subject, with a particular focus on EM as a fault injection tool. Paolo Maistri, Régis Leveugle, Lilian Bossuet, Alain Aubert, Viktor Fischer, Bruno Robisson, Nicolas Moro, Philippe Maurine, Jean-Max Dutertre, Mathieu Lisart |
VLSI-SoC | 8 |
| 2013 | Practical Analysis of RSA Countermeasures Against Side-Channel Electromagnetic Attacks
Guilherme Perin, Laurent Imbert, Lionel Torres, Philippe Maurine |
CARDIS | 4 |
| 2013 | Electromagnetic Analysis on RSA Algorithm Based on RNSabstractThis paper proposes a robustness evaluation of an RSA cryptosystem against collision attacks and correlation electromagnetic analysis. Our hardware co-processor is based on the Residue Number System (RNS) in order to perform modular operations over large numbers. To increase its robustness against Side-Channel Analysis, we implemented two different countermeasures. The first one spatially permutates the elements of the RNS bases in order to blur electromagnetic emanations. The second countermeasure aims at randomizing RNS bases before each modular exponentiation. To the best knowledge of authors, this is the first paper that explores the robustness of RNS-RSA against EM analyses. Guilherme Perin, Laurent Imbert, Lionel Torres, Philippe Maurine |
DSD | 4 |
| 2013 | Voltage Spikes on the Substrate to Obtain Timing FaultsabstractFault attacks are widely deployed against secure devices by hardware evaluation centers. While the least expensive fault injection techniques, like clock or voltage glitches, are well taken into account in secure devices by dedicated hardware counter-measures, more advanced techniques, such as light based attacks, require huge investments. This paper presents a new way to induce faults at a moderate cost that may defeat already in place hardware counter-measures. To demonstrate its effectiveness we applied this technique on an ASIC component. For this demonstration, fault exploitation is operated using the classic Bell core attack applied on a modular exponentiation supported by a modular arithmetic co-processor. Karim Tobich, Philippe Maurine, Pierre-Yvan Liardet, Mathieu Lisart, Thomas Ordas |
DSD | 2 |
| 2013 | An evaluation of an AES implementation protected against EM analysisabstractEM emissions can be a rich source of leakage for side-channel analysis of cipher implementations. In this paper, we describe a set of novel countermeasures based on dynamic spatial relocation and dynamic mappings, and validate the protection provided by them against EM attacks. The countermeasures improve significantly the security of the circuit. Paolo Maistri, Sébastien Tiran, Philippe Maurine, Israel Koren, Régis Leveugle |
ACM Great Lakes Symposium on VLSI | 3 |
| 2012 | SCA with Magnitude Squared Coherence
Sébastien Tiran, Philippe Maurine |
CARDIS | 2 |
| 2012 | Embedding statistical tests for on-chip dynamic voltage and temperature monitoringabstractAll mobile applications require high performances with very long battery life. The speed and power consumption trade-off clearly appears as a prominent challenge to optimize the overall energy efficiency. In Multiprocessor System-On-Chip architectures, the trade-off is usually achieved by dynamically adapting the supply voltage and the operating frequency of a processor cluster or of each processor at fine grain. This requires monitoring accurately, on-chip and at runtime, the supply voltage and temperature across the die. Within this context, this paper introduces a method to estimate, from on-chip measurements, using embedded statistical tests, the supply voltage and temperature of small die area using low-cost digital sensors featuring a set of ring oscillators solely. The results obtained, considering a 32nm process, demonstrate the efficiency of the proposed method. Indeed, voltage and temperature measurement errors are kept, in average, below 5mV and 7°C, respectively. Lionel Vincent, Philippe Maurine, Suzanne Lesecq, Edith Beigné |
DAC | 2 |
| 2012 | Amplitude demodulation-based EM analysis of different RSA implementationsabstractThis paper presents a fully numeric amplitude-demodulation based technique to enhance simple electromagnetic analyses. The technique, thanks to the removal of the clock harmonics and some noise sources, allows efficiently disclosing the leaking information. It has been applied to three different modular exponentiation algorithms, mapped onto the same multiplexed architecture. The latter is able to perform the exponentiation with successive modular multiplications using the Montgomery method. Experimental results demonstrate the efficiency of the applied demodulation based technique and also point out the remaining weaknesses of the considered architecture to retrieve secret keys. Guilherme Perin, Lionel Torres, Pascal Benoit, Philippe Maurine |
DATE | 4 |
| 2012 | Techniques for EM Fault Injection: Equipments and Experimental ResultsabstractThis paper will show that EM backside injection (case of flip chip bga packages) has little or no interest. Indeed, a new fault injection technique, called Forward Body Biaising Injection (FBBI), must be preferred to EM injection to produce transient faults, especially when LASER shots are detected by the target. The equipment required to apply a FBBI is low cost and really similar to the one used to produce an EM pulse. It is shown in 3. The main difference is the replacement of the coil producing the magnetic field by a thin tungsten rod in order to directly establish an electrical contact with the substrate. With such a direct contact (instead of a magnetic coupling), the fault can be produced with a low amplitude pulse generator. Additionally, the spatial resolution is expected to be better than with an EM pulse. The two electrical behaviors underlying this simple technique will be described before giving some experimental results obtained on a CRT based RSA, running on a secure device featuring a modular arithmetic co-processor. Philippe Maurine |
FDTC | 1 |
| 2012 | Enhancing Electromagnetic Analysis Using Magnitude Squared IncoherenceabstractThis paper demonstrates that magnitude squared incoherence (MSI) analysis is efficient to localize hot spots, i.e., points at which focused electromagnetic (EM) analyses can be applied with success. It is also demonstrated that MSI may be applied to enhance differential EM analyses (DEMA) based on difference of means (DoM). Amine Dehbaoui, Victor Lomné, Thomas Ordas, Lionel Torres, Michel Robert, Philippe Maurine |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2011 | Local and Direct EM Injection of Power Into CMOS Integrated CircuitsabstractThe paper aims at demonstrating experimentally that the tiny Electro Magnetic (EM) coupling between the tip end of a micro-antenna is sufficient to locally and directly inject power into CMOS Integrated Circuits (IC). More precisely, experimental results show that such electrical couplings are sufficient to disturb, with and without removing the IC package, the behavior of 90nm CMOS Ring Oscillators, a representative structure of CMOS logic but also a constituting element of some True Random Number Generators (TRNGs) or clock generator. François Poucheret, Karim Tobich, Mathieu Lisart, Laurent Chusseau, Bruno Robisson, Philippe Maurine |
FDTC | 6 |
| 2011 | A New Process Characterization Method for FPGAs Based on Electromagnetic AnalysisabstractThanks to their inherent regularity and reconfigurability, FPGAs offer an ideal structure to manage process variability. Recent works from the literature have addressed the process characterization problem for FPGAs: proposed approaches rely on process sensors (ring oscillators) and a measurement subsystem implemented into the configurable logic blocks. In this article, we propose for the first time in the literature a non-invasive characterization method based on electromagnetic analysis. The whole experimental set-up is described and the characterization accuracy is discussed. This paper proves the feasibility of this new method on FPGAs. Florent Bruguier, Pascal Benoit, Philippe Maurine, Lionel Torres |
FPL | 3 |
| 2010 | Differential Power Analysis enhancement with statistical preprocessingabstractDifferential Power Analysis (DPA) is a powerful Side-Channel Attack (SCA) targeting as well symmetric as asymmetric ciphers. Its principle is based on a statistical treatment of power consumption measurements monitored on an Integrated Circuit (IC) computing cryptographic operations. A lot of works have proposed improvements of the attack, but no one focuses on ordering measurements. Our proposal consists in a statistical preprocessing which ranks measurements in a statistically optimized order to accelerate DPA and reduce the number of required measurements to disclose the key. Victor Lomné, Amine Dehbaoui, Philippe Maurine, Lionel Torres, Michel Robert |
DATE | 3 |
| 2010 | Spatial EM jamming: A countermeasure against EM Analysis?abstractElectro-Magnetic Analysis has been identified as an efficient technique to retrieve the secret key of cryptographic algorithms. Although similar mathematically speaking, Power or Electro-Magnetic Analysis have different advantages in practice. Among the advantages of EM Analysis, the feasibility of attacking limited and bounded area of integrated systems is the key one. Within this context, the contribution of this paper is a countermeasure against local EM attack performed with tiny magnetic probes. The basic idea is to design circuits such that all datapaths and D-type Flip-Flops, involved in the computation of intermediate values of cryptographic elements, randomly change within a set of logically equivalent electrical paths that are spatially distributed within the Integrated Circuit (IC) die. François Poucheret, Lyonel Barthe, Pascal Benoit, Lionel Torres, Philippe Maurine, Michel Robert |
VLSI-SoC | 5 |
| 2009 | Evaluation on FPGA of triple rail logic robustness against DPA and DEMAabstractSide channel attacks are known to be efficient techniques to retrieve secret data. In this context, this paper concerns the evaluation of the robustness of triple rail logic against power and electromagnetic analyses on FPGA devices. More precisely, it aims at demonstrating that the basic concepts behind triple rail logic are valid and may provide interesting design guidelines to get DPA resistant circuits which are also more robust against DEMA. Victor Lomné, Philippe Maurine, Lionel Torres, Michel Robert, Rafael Soares, Ney Laert Vilar Calazans |
DATE | 2 |
| 2009 | Enhancing Electromagnetic Attacks Using Spectral Coherence Based Cartography
Amine Dehbaoui, Victor Lomné, Philippe Maurine, Lionel Torres, Michel Robert |
VLSI-SoC | 3 |
| 2008 | Editorial
Nadine Azémard, Philippe Maurine, Johan Vounckx |
Integr. | 2 |
| 2007 | Temperature and voltage aware timing analysis: application to voltage dropsabstractIn the nanometer era, the physical verification of CMOS digital circuit becomes a complex task. Designers must account of new factors that impose a significant change in validation methods. One of these major changes in timing verification to handle process variation lies in the progressive development of statistical static timing engines. However the statistical approach cannot capture accurately the deterministic variations of both the voltage and temperature variations. Therefore, we define a novel method, based on non-linear derating coefficients, to account of these environmental variations. Based on temperature and voltage drop CAD tool reports, this method allows computing the delay of logical paths considering more realistic operating conditions for each cell. Application is given to the analysis of voltage drop effects on timings B. Lasbouygues, Robin Wilson, Nadine Azémard, Philippe Maurine |
DATE | 4 |
| 2007 | Improvement of dual rail logic as a countermeasure against DPAabstractDual rail logic is considered as a relevant hardware countermeasure against Differential Power Analysis (DPA) by making power consumption data independent. In this paper, we deduce from a thorough analysis of the robustness of dual rail logic against DPA the design range in which it can be considered as effectively robust. Surprisingly this secure design range is quite narrow. We therefore propose the use of an improved logic, called Secure Triple Track Logic, as an alternative to more conventional dual rail logics. To validate the claimed benefits of the logic introduced herein, we have implemented a sensitive block of the Data Encryption Standard algorithm (DES) and carried out by simulation DPA attacks. Alin Razafindraibe, Michel Robert, Philippe Maurine |
VLSI-SoC | 3 |
| 2007 | Temperature- and Voltage-Aware Timing AnalysisabstractIn the nanometer era, the physical verification of a CMOS digital circuit becomes a long, tedious, and complex task. Designers must indeed account for numerous new factors that impose a drastic change in validation and physical-verification methods. One of these major changes in timing verification to handle process variation lies in the progressive development of statistical static-timing engines. However, the statistical approach cannot capture accurately the deterministic variations of both the voltage and temperature variations. Therefore, we define a novel method, based on nonlinear-derating coefficients, to account for these environmental variations. Based on temperature- and voltage-drop computer-aided-design tool reports, this method allows computing the propagation delay of logical paths considering the operating conditions of each cell. As the statistical timing analysis does, the proposed approach reduces design margins compared to worst/best case corner analysis with fixed voltage and temperature values, a gain of 10% on the delay has been observed for critical paths B. Lasbouygues, Robin Wilson, Nadine Azémard, Philippe Maurine |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2006 | Circuit sizing method under delay constraintabstractIn the last step of the design flow, circuit performance optimization is a difficult task to realize. The goal of this work is to avoid the use of CPU time expensive random mathematical methods, by defining an accurate and deterministic circuit sizing protocol, allowing easy and fast sizing of circuits at the required speed. We propose a coefficient based approach to solve the divergence branch problem for circuit sizing. Validation is given by comparing, in a standard 180nm CMOS process, the performance of different ISCAS benchmarks sized with an industrial tool and following our methodology Alexandre Verle, A. Landrault, Philippe Maurine, Nadine Azémard |
ISCAS | 3 |
| 2006 | Timing analysis in presence of supply voltage and temperature variationsabstractIn the nanometer era, the physical verification of CMOS digital circuit becomes a complex task. Designers must account of numerous new factors that impose a drastic change in validation and physical verification methods. One of these major changes in timing verification to handle process variation lies in the progressive development of statistical static timing engines. However the statistical approach cannot capture accurately the deterministic variations of both the voltage and temperature variations. Therefore, we define a novel method, based on non-linear derating coefficients, to account of these environmental variations. Based on temperature and voltage drop CAD tool reports, this method allows computing the delay of logical paths considering the operating conditions of each cell. B. Lasbouygues, Robin Wilson, Nadine Azémard, Philippe Maurine |
ISPD | 4 |
| 2006 | Security evaluation of dual rail logic against DPA attacksabstractBased on a first order model of the switching current flowing in CMOS cell, an investigation of the robustness against DPA attacks of dual rail logic is carried out. The result of this investigation, performed on 130nm process, is the formal identification of the design range in which dual rail logic can be considered as robust Alin Razafindraibe, Philippe Maurine, Michel Robert, Marc Renaudin |
VLSI-SoC | 2 |
| 2006 | A comprehensive performance macro-modeling of on-chip RC interconnects considering line shielding effects
Sylvain Engels, Robin Wilson, Nadine Azémard, Philippe Maurine |
Integr. | 4 |
| 2006 | Logical effort model extension to propagation delay representationabstractThe logical effort method is widely recognized as a pedagogical way allowing designers to quickly estimate and optimize single paths by modeling equivalently propagation delay and transition time. However, this method necessitates a calibration of all the gates of the library and appears suboptimal in real combinatorial paths for satisfying tight timing constraints. This is due to the inability of the logical effort model in capturing I/O coupling and input ramp effects that distinguish the transition time from the propagation delay. Using an analytical modeling of the supply current that flows in simple gates during their switching process, this paper introduces an extension of the logical effort model that considers the I/O coupling capacitance and the input ramp effect. Validation of this model is performed on 130-nm STMicroelectronics technology. A compact representation of CMOS library timing performance is given as a possible application of the proposed model. The choice of sampling points to be used in look-up tables as representative steps of the design range is also discussed B. Lasbouygues, Sylvain Engels, Robin Wilson, Philippe Maurine, Nadine Azémard, Daniel Auvergne |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2005 | Low Power Oriented CMOS Circuit Optimization ProtocolabstractLow power oriented circuit optimization consists in selecting the best alternative between gate sizing, buffer insertion and logic structure transformation, for satisfying a delay constraint at minimum area cost. In this paper, we used a closed form model of delay in CMOS structures to define metrics for a deterministic selection of the optimization alternative. The target is delay constraint satisfaction with minimum area cost. We validate the design space exploration method, defining maximum and minimum delay bounds on logical paths. Then we adapt this method to a "constant sensitivity method" allowing us to size a circuit at minimum area under a delay constraint. An optimisation protocol is finally defined to manage the performance constraint/circuit structure trade-off. These methods are implemented in an optimization tool (POPS) and validated by comparing, on a 0.25 /spl mu/m process, the optimization efficiency obtained on various benchmarks (ISCAS'85) to that resulting from an industrial tool. Alexandre Verle, Xavier Michel, Nadine Azémard, Philippe Maurine, Daniel Auvergne |
DATE | 4 |
| 2002 | Transition time modeling in deep submicron CMOSabstractAs generally recognized, the performance of a CMOS gate, such as propagation delay time or short circuit power dissipation, is strongly affected by the nonzero input signal transition time. This paper presents an analytical model of the transition time of CMOS structures. The authors first develop the model for inverters, considering fast and slow input signal conditions, over a large design range of input-output coupling capacitance and capacitive load. They then extend this model to more complex gates. The validity of the presented model is demonstrated through a comparison with HSPICE simulations on a 0.18 /spl mu/m CMOS process. Philippe Maurine, Mustapha Rezzoug, Nadine Azémard, Daniel Auvergne |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |