Sami El Amraoui

dblp:375/2216 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
6since 2021 · last 2026
0009-0003-9865-3340ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 5 first-author · 6 since 2021
YearPublicationVenuePosition
2026 Pulsed Electromagnetic Fault Injection on Ro-Based True Random Number Generators in FPGAs
abstract
Ring oscillators (ROs) are widely used in on-chip sensors and security primitives due to their simplicity, scalability, and sensitivity to process variations. In true random number generators (TRNGs), ROs serve as an entropy source by exploiting jitter originating mainly from physical noises and other stochastic phenomena, enabling low-cost generation of unpredictable random numbers for cryptographic applications. Ensuring the robustness of such designs against fault injection attacks is therefore critical. In this paper, we introduce a novel attack scenario in which pulsed ElectroMagnetic Fault Injection (EMFI) degrades the randomness quality of RO-based TRNGs by exploiting their susceptibility to harmonic locking. Experimental results on FPGA demonstrate that carefully tuning EMFI parameters can deterministically reduce entropy, significantly impairing the statistical quality of the generated bits and calling into question the RO-TRNG robustness when deployed in adversarial environments.
Sami El Amraoui, Mahdi Allaw, Florian Pebay-Peyroula, Régis Leveugle, Paolo Maistri
DDECS1
2025 Pulsed ElectroMagnetic Fault Injection Attack on a Time Measurement-based Arbiter-PUF
abstract
Physically Unclonable Functions (PUFs) have emerged as a promising hardware-based solution that leverages inherent process variations during IC manufacturing for secure key generation and device authentication, by generating unique and irreproducible challenge-response pairs (CRPs). Among various PUF designs, arbiter PUFs are particularly attractive due to their simplicity, scalability, and compatibility with lightweight cryptographic systems. However, their resistance to fault injection attacks remains an underexplored area. In this work, we investigate the impact of pulsed ElectroMagnetic (EM) fault injection (FI) on a novel Time Measurement-based Arbiter-PUF (TMAPUF) implemented on an FPGA. Experimental results reveal that a single precisely tuned EM pulse can consistently alter the PUF’s output, exposing a critical security weakness. This finding highlight the need for improved fault resilience in PUF architectures and suggest that the studied PUF variant could serve as a foundation for developing inherent countermeasures against EMFI and similar fault-based attacks.
Azzadine Thajte, Sami El Amraoui, Paolo Maistri, Régis Leveugle, Giorgio Di Natale, Laurent Fesquet
DSD2
2025 Pulsed Electromagnetic Fault Injection Attack on Ring Oscillator-based PUFs in FPGAs
Sami El Amraoui, Aghiles Douadi, Régis Leveugle, Paolo Maistri
ETS1
2025 On the Harmonic Locking of Ring Oscillators under Single ElectroMagnetic Pulsed Fault Injection in FPGAs
Sami El Amraoui, Aghiles Douadi, Régis Leveugle, Paolo Maistri
J. Electron. Test.1
2024 Choose your Path: Control of Ring Oscillators EMFI Susceptibility through FPGA P&R Constraints
abstract
Ring Oscillators (ROs) are widely used in various electronic systems, contributing to their functionality, security, and reliability. Therefore, the characterization of the robustness of RO-based designs against fault attacks such as ElectroMagnetic Fault Injection (EMFI) is a real concern. In this paper, we study the impact of electromagnetic (EM) pulses on ROs implemented in FPGAs. We show that the induced harmonic response depends on the placement and routing of the inverters for different parameters of the pulse. Such a characterization can help developing RO-based structures optimized either for better robustness against attacks or on the opposite for higher sensitivity in order to implement on-chip detectors.
Sami El Amraoui, Régis Leveugle, Paolo Maistri
DDECS1
2024 Capture the Pulse: Impact of FPGA Resource Utilization on EM Fault Injection Attacks Detection
abstract
With the increasing use of Field-Programmable Gate Arrays (FPGAs) in critical applications, safeguarding against malicious attacks becomes necessary. ElectroMagnetic Fault Injection (EMFI) stands out as a potent threat among localized fault attacks with its optimal compromise between cost and effectiveness, without the risk of damaging the target chip. Among potential targets, Ring Oscillators (ROs) are critical components that can be used in secure primitives, as well as detectors against physical attacks. In this paper, we analyze how the use of FPGA resources affects the outcome of EMFI attacks: we experimentally show with single EM pulse injections on three families of Xilinx FPGAs manufactured in 28nm process technology that the harmonic response of a RO heavily depends on its layout and density within the FPGA die. We also highlight the need of considering both EM pulse polarities when evaluating the efficiency of any proposed countermeasures, as this can reveal different sensitive locations on the chip. These findings can be leveraged for designing architectures that address the EMFI threat more effectively.
Sami El Amraoui, Régis Leveugle, Paolo Maistri
VLSI-SoC1