EDBT 2026 Demo / reviewers in the wild / expert
Jessy Clédière
dblp:35/6084
· DBLP profile ↗
20ranked-venue papers
0as first author
3since 2021 · last 2024
0000-0001-6239-8825ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 since 2021Systems, architecture and hardware · 9Software engineering, systems software and programming languages · 5Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | PoP DRAM: A new EMFI approach based on EM-induced glitches on SoCabstractModern mobile devices such as smartphones make use of complex Systems-on-Chip (SoC) that often come with a DRAM chip stacked above the SoC. This packaging method that was designed to increase space efficiency is called a Package-on-Package (PoP). PoP has also an incidental impact on local Fault Injection methods such as Electromagnetic Fault Injection (EMFI). This paper shows that conventional EMFI may not always be the most effective approach for inducing faults into a SoC implemented in a PoP. We provide and compare methodologies to successfully induce faults within this kind of target. A PoP DRAM can be removed while keeping the SoC operationnal during the first boot stages. We applied this method and used conventional EMFI on a SoC without DRAM. We also present a new way to induce voltage glitches on the target power supply rail by using EM pulses. Conventional voltage glitches are also performed in order to compare the faults obtained. It appeared that faults injected by EM-induced glitches are closer to faults obtained with conventional EMFI than faults induced by conventional voltage glitches. Clément Fanjas, Driss Aboulkassimi, Simon Pontié, Jessy Clédière |
FDTC | 4 |
| 2021 | Laboratory X-rays Operando Single Bit Attacks on Flash Memory Cells
Laurent Maingault, Stéphanie Anceau, Manuel Sulmont, Luc Salvo, Jessy Clédière, Pierre Lhuissier, Emrick Beliard, Jean-Luc Rainard |
CARDIS | 5 |
| 2021 | EM Fault Model Characterization on SoCs: From Different Architectures to the Same Fault ModelabstractRecently, several Fault Attacks (FAs) which target modern Central Processing Units (CPUs) have emerged. These attacks are studied from a practical point of view and, due to the modern CPUs complexity, the underlying fault effect is usually unknown. Only few works try to characterize them at the Instruction Set Architecture (ISA) level.In this article, we apply a state-of-the-art faults model characterization approach on modern CPU to evaluate the fault model on two different CPUs from different architectures with the same injection mediums. We target the CPU of the Raspberry Pi 3 (ARM) and an Intel Core i3 (x86) and perturbing them with ElectroMagnetic Fault Injection (EMFI). From the ISA point of view, we disclose a similar fault model on each component. Additionally, we evaluate a widely used complex software, OpenSSL, against this fault model. Thomas Trouchkine, Guillaume Bouffard, Jessy Clédière |
FDTC | 3 |
| 2019 | Fault Injection Characterization on Modern CPUs
Thomas Trouchkine, Guillaume Bouffard, Jessy Clédière |
WISTP | 3 |
| 2017 | Nanofocused X-Ray Beam to Reprogram Secure Circuits
Stéphanie Anceau, Pierre Bleuet, Jessy Clédière, Laurent Maingault, Jean-Luc Rainard, Rémi Tucoulou |
CHES | 3 |
| 2015 | From Code Review to Fault Injection Attacks: Filling the Gap Using Fault Model Inference
Louis Dureuil, Marie-Laure Potet, Philippe de Choudens, Cécile Canovas, Jessy Clédière |
CARDIS | 5 |
| 2014 | Efficiency of a glitch detector against electromagnetic fault injectionabstractThe use of electromagnetic glitches has recently emerged as an effective fault injection technique for the purpose of conducting physical attacks against integrated circuits. First research works have shown that electromagnetic faults are induced by timing constraint violations and that they are also located in the vicinity of the injection probe. This paper reports the study of the efficiency of a glitch detector against EM injection. This detector was originally designed to detect any attempt of inducing timing violations by means of clock or power glitches. Because electromagnetic disturbances are more local than global, the use of a single detector proved to be inefficient. Our subsequent investigation of the use of several detectors to obtain a full fault detection coverage is reported, it also provides further insights into the properties of electromagnetic injection and into the key role played by the injection probe. Loïc Zussa, Amine Dehbaoui, Karim Tobich, Jean-Max Dutertre, Philippe Maurine, Ludovic Guillaume-Sage, Jessy Clédière, Assia Tria |
DATE | 7 |
| 2013 | Power supply glitch induced faults on FPGA: An in-depth analysis of the injection mechanismabstractSecure circuits are prone to a wide range of physical attacks. Among those are fault attacks based on modifying the circuit environment in order to change its behaviour or to induce faults into its computations. There are many common means used to inject such faults: laser shots, electromagnetic pulses, overclocking, chip underpowering, temperature increase, etc. In this paper we study the effect of negative power supply glitches on a FPGA. The obtained faults were compared to faults injected by clock glitches. As a result, both power and clock glitch induced faults were found to be identical. Because clock glitches are related to timing constraint violations, we shall consider that both power and clock glitches share this common fault injection mechanism. We also further studied the properties of this fault injection means. Loïc Zussa, Jean-Max Dutertre, Jessy Clédière, Assia Tria |
IOLTS | 3 |
| 2013 | Fault Analysis and Evaluation of a True Random Number Generator Embedded in a Processor
Mathilde Soucarros, Jessy Clédière, Cécile Canovas, Philippe Elbaz-Vincent |
J. Electron. Test. | 2 |
| 2011 | Glitch and Laser Fault Attacks onto a Secure AES Implementation on a SRAM-Based FPGA
Gaetan Canivet, Paolo Maistri, Régis Leveugle, Jessy Clédière, Florent Valette, Marc Renaudin |
J. Cryptol. | 4 |
| 2010 | Dependability analysis of a countermeasure against fault attacks by means of laser shots onto a SRAM-based FPGAabstractLaser-based fault injections are currently the most efficient technique that can be used to attack a secure system, since they have very high timing and location precision. Several papers have shown that a secret key may be recovered from ASICs and countermeasures have been proposed. But little research has been addressed at the specific case of secure protected implementations in SRAM-based FPGAs. This paper presents the results of laser-based fault injections on an architecture computing the AES encryption algorithm, protected by an error detection scheme, and implemented on a Virtex device. The results are compared to previous emulated fault injection campaigns and prove the criticality of remnant errors in the configuration of a FPGA used for secure applications. An improved countermeasure is also proposed and validated with a new experimental campaign. Gaetan Canivet, Paolo Maistri, Régis Leveugle, Frédéric Valette, Jessy Clédière, Marc Renaudin |
ASAP | 5 |
| 2010 | Robustness evaluation and improvements under laser-based fault attacks of an AES crypto-processor implemented on a SRAM-based FPGAabstractProgrammable devices like SRAM-based FPGAs, thanks to their low cost and high flexibility, are increasingly used for security applications; the mam drawback is their configuration memory, sensitive to perturbations. Symmetric cryptosystems are highly vulnerable to fault injections [1], but very few papers have reported laser-based fault attacks onto a secure implementation on a SRAM-based FPGA. Gaetan Canivet, P. Maistn, Régis Leveugle, Frédéric Valette, Jessy Clédière, Marc Renaudin |
ETS | 5 |
| 2009 | Characterization of Effective Laser Spots during Attacks in the Configuration of a Virtex-II FPGAabstractSRAM-based FPGAs are an appealing platform to implement many systems, including secure ones. However, secure systems are subject to attacks and one of the main threats is fault-based attacks using lasers. The sensitivity of the configuration memory in a SRAM-based FPGA has to be studied in this context. This paper reports on the characterization of the effective laser spot, or effective sensitive area, with respect to the laser focus and to the attacked configuration bits. The test vehicle is a Virtex II FPGA. It is shown in particular that the initial value of the bit has a strong influence on the effective sensitive area of the spot. Such data can be used to better understand the actual effects of an attack and to design more efficient counter-measures. Also, it is shown that attacks based on single bit flips in the configuration are possible in practice even with relatively large laser spots. Gaetan Canivet, Régis Leveugle, Jessy Clédière, Frédéric Valette, Marc Renaudin |
VTS | 3 |
| 2008 | An overview of side channel analysis attacksabstractDuring the last ten years, power analysis attacks have been widely developed under many forms. They analyze the relation between the power consumption or electromagnetic radiation of a cryptographic device and the handled data during cryptographic operations. The goal of this paper is to give a global view of statistical attacks based on side channel analysis. These techniques are classified into two classes: attacks without reference device (e.g. Differential Power Analysis, Correlation Power Analysis) and attacks using a reference device (e.g. Template Attack, Stochastic Model Attack). In this paper, we present the attacks with an easy comprehensible way and focus on their implementation aspect. The pros and cons of each attack is highlighted in details with concrete electromagnetic signals. At least, our paper proposes also some solutions to enhance the existing attacks. Cécile Canovas, Jessy Clédière |
AsiaCCS | 3 |
| 2008 | Defeating classical Hardware Countermeasures: a new processing for Side Channel AnalysisabstractIn the field of the side channel analysis, hardware distortions such as glitches and random frequency are classical countermeasures. A glitch influences the side channel amplitude while a random frequency damages the signal both in time and in amplitude. For minimizing these countermeasures effects, some trace treatments based on peak extraction or auto-correlation methods exist. However, none of them takes into account the amplitude mistake. In this paper, we show that this amplitude mistake is created by glitches but also by a random frequency. We propose then a reshaping processing that erases these effects on side channel traces both on the time and amplitude axis. The solution reconstructed a side channel signal, avoiding the hardware countermeasures and the clock relativity consequences which can be meaningful for Side Channel Attacks. Its efficiency is demonstrated on a Differential Power Attack performed on a DES implementation and on a Template Attack performed on a RSA implementation. Denis Réal, Cécile Canovas, Jessy Clédière, M'hamed Drissi, Frédéric Valette |
DATE | 3 |
| 2008 | Detailed Analyses of Single Laser Shot Effects in the Configuration of a Virtex-II FPGAabstractDue to their reconfigurability and their high density of resources, SRAM-based FPGAs are more and more used in embedded systems. For some applications (Pay-TV,Banking, Telecommunication ...), a high level of security is needed. FPGAs are intrinsically sensitive to ionizing effects, such as light stimulation, and attackers can try to exploit faults injected in the downloaded configuration. Previous studies presented the results obtained with multiple laser shots across different elements of the device. The exact effect of a single laser shot was not studied; a global picture of the type of generated errors was rather drawn. This work analyses the effects of a single laser shot onto the configuration memory. Results take into account several diameters of pulsed laser spots targeted on several types of logical blocks and compare theirs effects. Gaetan Canivet, Jessy Clédière, Jean Baptiste Ferron, Frédéric Valette, Marc Renaudin, Régis Leveugle |
IOLTS | 2 |
| 2007 | Efficient Solution for Misalignment of Signal in Side Channel AnalysisabstractSide channel analysis like differential power analysis (DPA) has been known as an efficient attack for uncovering secret data of cryptosystems. However, the temporal misalignment of side channel signals is an issue of concern that destabilizes side channel attack efficiency. In this paper, we propose a new method to surmount the misalignment problem in DPA. The performance of the proposed method is then evaluated while analyzing the electromagnetic signals of a synthesized ASIC (application specific integrated circuit) during a DES (data encryption standard) operation. The experimental results show that our method allows to detect efficiently the secret key with a small number of side channel signals during a short time. Its performance is then compared to that of the original DPA and of the frequency-based DPA, the current solution for the signal misalignment in side channel attacks. Jessy Clédière, Christine Servière, Jean-Louis Lacoume |
ICASSP (2) | 2 |
| 2007 | Noise Reduction in Side Channel Attack Using Fourth-Order CumulantabstractSide channel attacks exploit physical information leaked during the operation of a cryptographic device (e.g., a smart card). The confidential data, which can be leaked from side channels, are timing of operations, power consumption, and electromagnetic emanation. In this paper, we propose a preprocessing method based on the fourth-order cumulant, which aims to improve the performance of side channel attacks. It takes advantages of the Gaussian and nonGaussian properties, that respectively characterize the noise and the signal, to remove the effects due to Gaussian noise coupled into side channel signals. The proposed method is then applied to analyze the electromagnetic signals of a synthesized application-specific integrated circuit during a data encryption standard operation. The theoretical and experimental results show that our method significantly reduces the number of side channel signals needed to detect the encryption key. Jessy Clédière, Christine Servière, Jean-Louis Lacoume |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2006 | A Proposition for Correlation Power Analysis Enhancement
Jessy Clédière, Cécile Canovas, Bruno Robisson, Christine Servière, Jean-Louis Lacoume |
CHES | 2 |
| 2005 | Security Testing for Hardware Products: The Security Evaluations PracticeabstractThis paper introduces the security evaluations process and focus on the tests done on hardware products, specifically smartcards. Some examples, issued from the CESTI LETI experience, an accredited laboratory of the French Certification Scheme, are given. In addition the paper tries to point out the differences with functional testing. Alain Merle, Jessy Clédière |
IOLTS | 2 |