EDBT 2026 Demo / reviewers in the wild / expert
David Hély
dblp:41/6112
· DBLP profile ↗
50ranked-venue papers
9as first author
10since 2021 · last 2026
0000-0003-3249-7667ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 45 · 9 first-author · 8 since 2021Software engineering, systems software and programming languages · 16 · 3 first-author · 3 since 2021Security and privacy · 2Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fault Model-Driven Formal Verification of Cryptographic Hardware Against Fault Attacks
Daniel Thirion, George-Cristian Sercaianu, Valentin Egloff, Jean-Marc Daveau, Vincent Beroulle, David Hély, Philippe Roche |
ETS | 6 |
| 2026 | Reducing Safety False-Positives in Parity-Based Security AES Using a Hardware Fault ClassifierabstractInternational audience Daniel Thirion, Jean-Marc Daveau, Valentin Egloff, Vincent Beroulle, Philippe Roche, David Hély |
IOLTS | 6 |
| 2026 | Thermal Attack on RO-PUFs: The Cases of Bulk 65 nm and FDSOI 28 nmabstractPhysical Unclonable Functions (PUFs) play a crucial role in enhancing the security of electronic devices by leveraging inherent manufacturing variations to generate unique and unclonable identifiers. This study explores the vulnerability of Ring Oscillator-based PUFs (RO-PUFs) to thermal attacks, focusing on two semiconductor technologies: Bulk 65 nm and Fully Depleted Silicon on Insulator (FDSOI) in 28 nm. Through detailed simulations, the effects of uniform and localized thermal variations on the stability of ring oscillator frequencies are analyzed. The results reveal that while the Bulk 65 nm technology shows resistance to uniform thermal attacks, it is highly sensitive to localized attacks. In contrast, the FDSOI 28 nm technology is vulnerable to both types of attacks due to its low variability. These observations underscore the need for robust countermeasures in the design of PUFs to ensure their reliability under varying thermal conditions. Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2025 | Comparative Study of Safety and Security-Protected AES DesignsabstractWith the increase in cybersecurity requirements and the growing connectivity of critical systems like vehicles and satellites, implementing both functional safety and hardware security is crucial. Although safety and security methods are well studied, combined analysis at the RTL or Netlist level remains under-explored. This paper provides an initial analysis of multiple AES designs—one unprotected, one with a safety-oriented countermeasure (Lockstep), and one with security-oriented countermeasures (Parity-Predictor)—using both simulation and formal methods. We identify the challenges and opportunities for enhancing combined safety and security assessments. Additionally, we evaluate the AES designs against ISO 26262 safety metrics and analyze their resilience to laser attacks, offering insight into their security robustness. Daniel Thirion, Jean-Marc Daveau, Valentin Egloff, David Hély, Vincent Beroulle, Philippe Roche |
DDECS | 4 |
| 2025 | Reliability Under Stress: The Impact of Localized Aging on RO-PUF Architectures in FPGAs
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale |
ETS | 4 |
| 2024 | Automated Hardware Security Countermeasure Integration Inside High Level SynthesisabstractHigh-level Synthesis (HLS) methodology has revolutionized the development of complex hardware designs. It enables the rapid conversion of algorithmic descriptions of functionalities to highly optimized hardware equivalents. While modern HLS tools excel in addressing classic design constraints, such as area, latency and power requirements, they fall short regarding security considerations. Security's role is significantly emphasized in today's digital environment, given the existence of powerful hardware attacks, such as Fault Injection (FI) and Side-Channel Analysis (SCA) attacks. HLS methodology can theoretically facilitate the integration of security measures from the high level, yet its core mechanisms do not actively address the preservation or the improvement of security levels of any countermeasure described. Instead, it may sacrifice security enhancement entirely in circuits of high optimization goals. In this work, first, we propose the automatic countermeasure insertion in a way so that both HLS optimization efforts and the secure addition of the countermeasure are implemented effectively. Secondly, we modify the internal mechanisms of the HLS scheduling algorithm and operation chaining to reduce vulnerable points of the design. We demonstrate our methodology by performing fault injection experiments and comparing the results with a straightforward countermeasure integration technique in terms of hardware security and traditional design metrics. Amalia-Artemis Koufopoulou, Athanasios Papadimitriou, Mihalis Psarakis, David Hély |
DATE | 4 |
| 2024 | Modeling Thermal Effects For Biasing PUFsabstractSecurity primitives such as Physical Unclonable Functions (PUFs) or True Random Number Generators (TRNGs), have emerged as hardware roots of trust for ensuring the security of modern applications. However, these primitives display susceptibility to physical attacks, among them, in the face of temperature variations. Previous research has established the feasibility of attacks exploiting temperature fluctuations to compromise the security of these primitives. Specifically, when implemented on FPGAs, programmable components can be vulnerable to alterations induced by thermal changes. These findings underscore the need to deepen the understanding of the implications of temperature sensitivity on the security and robustness of these security mechanisms. This paper studies how heat affects, both instantaneously and permanently, the working of ring oscillators, which are the building blocks of PUFs based on Ring Oscillators. The study also suggests how to exploit these effects to bias the PUf responses, enabling thus the possibility of its cloning. Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale |
ETS | 4 |
| 2022 | Elaborating on Sub-Space Modeling as an Enrollment Solution for Strong PUFabstractIn this work we present sub-space modeling of strong PUF as a cost efficient solution for PUF enrollment for the designers’ community. Our goal is to demonstrate a method which can reduce the overall cost in terms of number of CRPs required for training, training time and memory. Instead of modifying the estimated model structure, we propose to reduce the complexity of the modeling target. This means to provide secured access to the internal responses of strong PUF during the enrollment and capture internal CRPs to model each sub-component of the PUF independently. It also necessitates to permanently remove the internal access after the enrollment to prevent exposure of the internal responses. This means that the internal responses should not be directly accessible after enrollment. Our sub-space modeling method requires lesser number of CRPs compared to modeling the whole PUF. We experimentally prove that sub-space modeling can significantly reduce the cost of training compared to some of the latest works. For instance, we could model 128-stage 6-XOR Arbiter PUF with just above 90% prediction accuracy with 5000 CRPs. Here the response in the CRP is a vector including the responses of the sub-components. Our results show that sub-space modeling is potentially a cost-efficient solution to enroll strong PUF with high complexity. Amir Ali Pour, David Hély, Vincent Beroulle, Giorgio Di Natale |
DCOSS | 2 |
| 2022 | Security and Reliability Evaluation of Countermeasures implemented using High-Level SynthesisabstractAs the complexity of digital circuits increases, High-Level Synthesis (HLS) is becoming a valuable tool to increase productivity and design reuse by utilizing relevant Electronic Design Automation (EDA) flows, either for Application-Specific Integrated Circuits (ASIC) or for Field Programmable Gate Arrays (FPGA). Side Channel Analysis (SCA) and Fault Injection (FI) attacks are powerful hardware attacks, capable of greatly weakening the theoretical security levels of secure implementations. Furthermore, critical applications demand high levels of reliability including fault tolerance. The lack of security and reliability driven optimizations in HLS tools makes it necessary for the HLS-based designs to validate that the properties of the algorithm and the countermeasures have not been compromised due to the HLS flow. In this work, we provide results on the resilience evaluation of HLS-based FPGA implementations for the aforementioned threats. As a test case, we use multiple versions of an on-the-fly SBOX algorithm integrating different countermeasures (hiding and masking), written in C and implemented using Vivado HLS. We perform extensive evaluations for all the designs and their optimization scenarios. The results provide evidence of issues arising from HLS optimizations on the security and reliability of cryptographic implementations. Furthermore, the results put HLS algorithms to the test of designing secure accelerators and can lead to improving them towards the goal of increasing productivity in the domain of secure and reliable cryptographic implementations. Amalia-Artemis Koufopoulou, Kalliopi Xevgeni, Athanasios Papadimitriou, Mihalis Psarakis, David Hély |
IOLTS | 5 |
| 2021 | PUF-Based Protocol for Securing Constrained DevicesabstractIn networks of smart devices, managing the trust among devices is a key challenge to prevent malicious intrusions of rogue agents. One aspect of trust is to ensure the authenticity of each device. Authentication schemes already exist for resourceful nodes, but we lack solutions for constrained devices which are undoubtedly an important part of those networks. In this paper, we present a new PUF-based authentication protocol for smart devices with autonomy and cost constraints, which aims at filling the gap between current authentication protocols and no authentication at all. We also describe our first implementation of the protocol using a microcontroller of the NXP LPC55S6x family, which features secure storage and key generation using a SRAM PUF. Finally, we present our evaluation of the protocol's principle and performances to validate the feasibility of the solution in real-world applications. Arthur Desuert, Stéphanie Chollet, Laurent Pion, David Hély |
Intelligent Environments | 4 |
| 2020 | On the Performance of Non-Profiled Differential Deep Learning Attacks against an AES Encryption Algorithm Protected using a Correlated Noise Generation based Hiding CountermeasureabstractRecent works in the field of cryptography focus on Deep Learning based Side Channel Analysis (DLSCA) as one of the most powerful attacks against common encryption algorithms such as AES. As a common case, profiling DLSCA have shown great capabilities in revealing secret cryptographic keys against the majority of AES implementations. In a very recent study, it has been shown that Deep Learning can be applied in a non-profiling way (non-profiling DLSCA), making this method considerably more practical, and able to break powerful countermeasures for encryption algorithms such as AES including masking countermeasures, requiring considerably less power traces than a first order CPA attack. In this work, our main goal is to apply the non-profiling DLSCA against a hiding-based AES countermeasure which utilizes correlated noise generation so as to hide the secret encryption key. We show that this AES, with correlated noise generation as a lightweight countermeasure, can provide equivalent protection under CPA and under non-profiling DLSCA attacks, in terms of the required power traces to obtain the secret key. Amir Ali Pour, Athanasios Papadimitriou, Vincent Beroulle, Ehsan Aerabi, David Hély |
DATE | 5 |
| 2020 | BackFlow: Backward Edge Control Flow Enforcement for Low End ARM MicrocontrollersabstractThis paper presents BackFlow, a compiler-based toolchain that enforces indirect backward edge control flow integrity for low-end ARM Cortex-M microprocessors. BackFlow is implemented within the Clang/LLVM compiler and supports the ARM instruction set and its subset Thumb. The control flow integrity generated by the compiler relies on a bitmap, where each set bit indicates a valid pointer destination. The efficiency of the framework is benchmarked using an STM32 NUCLEO F446RE microcontroller. The obtained results show that the control flow integrity solution incurs an execution time overhead ranging from 1.5 to 4.5%. Cyril Bresch, Roman L. Lysecky, David Hély |
DATE | 3 |
| 2020 | PUF Enrollment and Life Cycle Management: Solutions and Perspectives for the Test CommunityabstractPhysically Unclonable Functions (PUFs) allow to extract unique fingerprints from silicon chips. The applications are numerous: chip identification, chip master key extraction, authentication protocol, unique seeding, etc. However, secure usage of PUF requires some precautions. This paper reviews industrial concerns associated with PUF operation, including those occurring before and after market. Namely, starting from PUF “secure” specifications, aligned with state-of-the-art standards, we explore innovative techniques to handle enrollment and subsequent PUF queries, in nominal as well as in adversarial environment. Amir Ali Pour, Vincent Beroulle, Bertrand Cambou, Jean-Luc Danger, Giorgio Di Natale, David Hély, Sylvain Guilley, Naghmeh Karimi |
ETS | 6 |
| 2020 | Machine Learning and Hardware security: Challenges and Opportunities -Invited Talk-abstractMachine learning techniques have significantly changed our lives. They helped improving our everyday routines, but they also demonstrated to be an extremely helpful tool for more advanced and complex applications. However, the implications of hardware security problems under a massive diffusion of machine learning techniques are still to be completely understood. This paper first highlights novel applications of machine learning for hardware security, such as evaluation of post quantum cryptography hardware and extraction of physically unclonable functions from neural networks. Later, practical model extraction attack based on electromagnetic side-channel measurements are demonstrated followed by a discussion of strategies to protect proprietary models by watermarking them. Francesco Regazzoni 0001, Shivam Bhasin, Amir Ali Pour, Ihab Alshaer, Furkan Aydin, Aydin Aysu, Vincent Beroulle, Giorgio Di Natale, Paul D. Franzon, David Hély, Naofumi Homma, Akira Ito 0002, Dirmanto Jap, Priyank Kashyap, Ilia Polian, Seetal Potluri, Rei Ueno, Elena I. Vatajelu, Ville Yli-Mäyry |
ICCAD | 10 |
| 2020 | Hardware Security Vulnerability Assessment to Identify the Potential Risks in A Critical Embedded ApplicationabstractInternet of Things (IoT) is experiencing significant growth in the safety-critical applications which have caused new security challenges. These devices are becoming targets for different types of physical attacks, which are exacerbated by their diversity and accessibility. Therefore, there is a strict necessity to support embedded software developers to identify and remediate the vulnerabilities and create resilient applications against such attacks. In this paper, we propose a hardware security vulnerability assessment based on fault injection of an embedded application. In our security assessment, we apply a fault injection attack by using our clock glitch generator on a critical medical IoT device. Furthermore, we analyze the potential risks of ignoring these attacks in this embedded application. The results will inform the embedded software developers of various security risks and the required steps to improve the security of similar MCU-based applications. Our hardware security assessment approach is easy to apply and can lead to secure embedded IoT applications against fault attacks. Zahra Kazemi, Mahdi Fazeli, David Hély, Vincent Beroulle |
IOLTS | 3 |
| 2020 | Cryptography with Analog Scheme Using MemristorsabstractNetworks of low-power Internet of Things do not have always access to enough computing power to support mainstream cryptographic schemes; such schemes also consume computing power that can be exposed to side channel attacks. This article describes a method, that we call “cryptography with analog scheme using memristors,” leveraging the physical properties of memristors, which are active elements suitable for the design of components such as artificial neurons. The proposed devices encrypt messages by segmenting them into blocks of bits, each modulating the injected currents into randomly selected memristor cells, resulting into sets of resistance values turned into cipher texts. Through hash-protected handshakes, identical addresses are independently generated by both communicating devices, to concurrently point at the same set of cells in the arrays, and their images. These block ciphers, for example, 1 KB long, can only be decrypted with the same memristor array driven by analog circuitry or its image, rather than digital key-based schemes. The proposed methods generate cipher text, and decrypt them, with approximately one femto joule per bit, which is below observable level through differential power analysis. The article explains how the use of different cells for each message to encrypt, driven under different conditions, has the potential to mitigate mainstream attacks. It provides a detailed characterization of memristors to evaluate the feasibility of the approach and discusses some hardware and architectures to implement the scheme. Bertrand Cambou, David Hély, Sareh Assiri |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2020 | Design Space Exploration for Ultra-Low-Energy and Secure IoT MCUsabstractThis article explores the design space of secure communication in ultra-low-energy IoT devices based on Micro-Controller Units (MCUs). It tries to identify, benchmark, and compare security-related design choices in a Commercial-Off-The-Shelf (COTS) embedded IoT system which contributes to the energy consumption. We conduct a study over a large group of software crypto algorithms: symmetric, stream, hash, AEAD, MAC, digital signature, and key exchange. A comprehensive report of the targeted optimization attributes (memory, performance, and specifically energy) will be presented from over 450 experiments and 170 different crypto source codes. The article also briefly explores a few system-related choices which can affect the energy consumption of secure communication, namely, architecture choice, communication bandwidth, signal strength, and processor frequency. In the end, the article gives an overview of the obtained results and the contribution of all. Finally, it shows, in a case study, how the results could be utilized to have a secure communication in an exemplary IoT device. This article gives IoT designers insight into ultra-low-energy security, helps them to choose appropriate cryptographic algorithms, reduce trial-and-error of alternatives, save effort, and hence cut the design costs. Ehsan Aerabi, Milad Bohlouli, Mohammad Hasan Ahmadi Livany, Mahdi Fazeli, Athanasios Papadimitriou, David Hély |
ACM Trans. Embed. Comput. Syst. | 6 |
| 2020 | TrustFlow-X: A Practical Framework for Fine-grained Control-flow Integrity in Critical SystemsabstractThis article addresses the challenges of memory safety in life-critical medical devices. Since the last decade, healthcare manufacturers have embraced the Internet of Things, pushing technological innovations to increase market share. Medical devices, including the most critical ones, tend to be increasingly connected to the Internet. Unfortunately, as critical devices often rely on unsafe programming languages such as C, they are no exception to memory safety issues. Given a memory vulnerability, a skillful attacker can take over a system and perform remote code execution. Combined with the fact that medical devices directly impact the safety of their users, a security vulnerability can lead to disastrous scenarios. To address this issue, this article presents TrustFlow-X, a novel hardware/software co-designed framework that provides efficient fine-grained control-flow integrity protection against memory-based attacks. The TrustFlow-X framework is composed of an LLVM-based compiler toolchain that generates a secure code. This secure code is then executed on an extended RISC-V processor that keeps track of sensitive data using a trusted memory. The obtained results show that the contribution is practical, providing a high level of trust in life-critical embedded systems. Cyril Bresch, David Hély, Roman L. Lysecky, Stéphanie Chollet, Ioannis Parissis |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2019 | On a Side Channel and Fault Attack Concurrent Countermeasure Methodology for MCU-based Byte-sliced Cipher ImplementationsabstractAs IoT applications are increasingly being deployed, there comes along an ever increasing need for the security and privacy of the involved data. Since cryptographic implementations are used to achieve these goals, it is important for embedded software developers to take into consideration hardware attacks. Side Channel Analysis (SCA) and Fault Attacks (FA) are the main classes of such attacks, which can either reduce or even eliminate the security levels of an embedded design. Therefore, cryptographic implementations must address both of them at the same time. To this end, multiple solutions have been proposed to address both attacks in one solution, such as Dual Pre-charge Logic (DPL) and Encoding countermeasures. In this work, we discuss the advantages and disadvantages of the state of the art, concurrent SCA and FA countermeasures. Additionally, we propose a software countermeasure in order to provide protection against both types of attacks. The proposed countermeasure is a general approach, applicable to any byte-sliced cipher and any modern (32/64-bit) Micro-Controller Units (MCU). The proposed countermeasure is applied to an AES S-BOX implementation, for a 32-bit MCU (ARM Cortex-M3). The countermeasure has been experimentally evaluated against Correlation Power Analysis (CPA) attacks for both platforms while its fault detection capabilities are theoretically described. Ehsan Aerabi, Athanasios Papadimitriou, David Hély |
IOLTS | 3 |
| 2019 | Implementation of Password Management System Using Ternary Addressable PUF GeneratorabstractOne of the crucial cyber-attacks which has been reported is hacking the databases of users' identification and passwords. Surprisingly, the typical procedure in most networks is the saving of passwords or password hashes in the look-up tables, which can be accessed later via the identification of each user. This paper seeks to find a remedy to this problem by adding a hardware security layer to the hash function-based password management systems. Also, the hardware security module, which is utilized as a solution in this paper, accelerates the computationally intense cryptographic operations. Addressable PUF Generator (APG) is utilized as a hardware layer. A significant problem with PUFs, i.e., the instability of their responses, is addressed in this paper. Ternary APG is implemented by using the ternary PUFs to solve this problem. The architecture takes advantage of known technology modules such as SRAM PUFs, hash functions, and microcontrollers. Furthermore, the protocol is used as a solution in this paper does not need saving passwords or hash of passwords. To the best of our knowledge, this paper presents the first prototype implementation of ternary APG usage in the password management system. Mohammad Mohammadinodoushan, Bertrand Cambou, Christopher Robert Philabaum, David Hély, Duane Booher |
SECON | 4 |
| 2018 | Laser Fault Injection at the CMOS 28 nm Technology Node: an Analysis of the Fault ModelabstractS. Skorobogatov and R. Anderson identified laser illumination as an effective technique to conduct fault attacks in 2002. In these early days of laser-induced fault injection, it was proven to be possible to inject single-bit faults into integrated circuits. This corresponds to the more restrictive fault model found in the fault attack bibliography. The target area under laser illumination (a few micrometers, down to ~1 µm) broadly matched that of a single transistor. It was consistent with a single-bit fault model. However, since then the technology of secure devices has evolved. In current circuits even the smallest laser spots may illuminate several logic cells. This raises the question of the validity of the single-bit fault model: does it still hold? In this work, we report an assessment of its validity through experimental results obtained from circuits designed at the 28 nm CMOS technology node. We also describe the main properties of the corresponding fault model obtained from both static and dynamic experiments. Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Stephan De Castro, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre |
FDTC | 8 |
| 2018 | The case of using CMOS FD-SOI rather than CMOS bulk to harden ICs against laser attacksabstractAt first used to emulate the effects of radioactive ionizing particules passing through integrated circuits (ICs), laser illumination is also used to inject faults into the computations of secure ICs for the purpose of retrieving secret data. The CMOS FD-SOI technology is expected to be less sensitive to laser faults injection than the more usual CMOS bulk technology. We report in this work an experimental assessment of the interest of using FD-SOI rather than CMOS bulk to decrease laser sensitivity. Our experiments were conducted on test chips at the 28nm node for both technologies with laser pulse durations in the picosecond and nanosecond ranges. Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre |
IOLTS | 7 |
| 2018 | Hardware Trojan Detection Using an Advised Genetic Algorithm Based Logic Testing
M. A. Nourian, Mahdi Fazeli, David Hély |
J. Electron. Test. | 3 |
| 2017 | IoT Components LifeCycle Based Security AnalysisabstractWe present in this paper a security analysis of electronic devices which considers the lifecycle properties of embedded systems. We first define a generic model of electronic devices lifecycle showing the complex interactions between the numerous assets and the actors. The method is illustrated through a case study: a connected insulin pump. The lifecycle induced vulnerabilities are analyzed using the EBIOS methodology. An analysis of associated countermeasures points out the lack of consideration of the life cycle in order to provide an acceptable security level of each assets of the device. Johan Marconot, Florian Pebay-Peyroula, David Hély |
DSD | 3 |
| 2017 | A comprehensive hardware/software infrastructure for IP cores design protectionabstractCore-based design, which is widely used nowadays due to the high complexity of electronic systems, comes with specific threats against design data. Cases of intellectual property infringement and illegal copying have risen in the last decade. To fight this threat, must be aware of how many instantiations of an IP core have been carried out. Based on this, illegal copies can be detected and precise metering is achieved. To work toward this goal, we propose a comprehensive hardware/software infrastructure that allows a designer to modify an IP core to make it remotely activable later on when it is implemented on an FPGA. We focus on industrial applicability and ease of integration. On the one hand, hardware implementation on FPGA focuses on achieving a medium level of security at reduced cost. On the other hand, the software side aims at computational efficiency and industrial applicability for smooth integration into EDA tools. Brice Colombier, Lilian Bossuet, Ugo Mureddu, David Hély |
FPT | 4 |
| 2017 | Key Reconciliation Protocols for Error Correction of Silicon PUF ResponsesabstractPhysical unclonable functions (PUFs) are promising primitives for the lightweight authentication of an integrated circuit (IC). Indeed, by extracting an identifier from random process variations, they allow each instance of a design to be uniquely identified. However, the extracted identifiers are not stable enough to be used as is, and hence, need to be corrected first. This is currently achieved using error-correcting codes in secure sketches that generate helper data through a one-time procedure. As an alternative, we propose key reconciliation protocols. This interactive method, originating from quantum key distribution, allows two entities to correct errors in their respective correlated keys by discussing over a public channel. We believe that this can also be used by a device and a remote server to agree on two different responses to the same challenge from the same PUF obtained at different times. This approach has the advantage of requiring very few logic resources on the device side. The information leakage caused by the key reconciliation process is limited and easily computable. Results of implementation on field-programmable gate array (FPGA) targets are presented, showing that it is the most lightweight error-correction module to date. Brice Colombier, Lilian Bossuet, Viktor Fischer, David Hély |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | Secure and Flexible Trace-Based Debugging of Systems-on-ChipabstractThis work tackles the conflict between enforcing security of a system-on-chip (SoC) and providing observability during trace-based debugging. On one hand, security objectives require that assets remain confidential at different stages of the SoC life cycle. On the other hand, the trace-based debug infrastructure exposes values of internal signals that can leak the assets to untrusted third parties. We propose a secure trace-based debug infrastructure to resolve this conflict. The secure infrastructure tags each asset to identify its owner (to whom it can be exposed during debug) and nonintrusively enforces the confidentiality of the assets during runtime debug. We implement a prototype of the enhanced infrastructure on an FPGA to validate its functional correctness. ASIC estimations show that our approach incurs practical area and power costs. Jerry Backer, David Hély, Ramesh Karri |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2016 | On the development of a new countermeasure based on a laser attack RTL fault model
Charalampos Ananiadis, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle |
DATE | 3 |
| 2016 | How logic masking can improve path delay analysis for Hardware Trojan detectionabstractHardware Trojan (HT), Integrated Circuit (IC) piracy, and overproduction are three important threats which may happen in untrusted foundries. Modifying structurally the IC design at different abstraction level to counter the HT threats is known as Design-For-Hardware-Trust (DFHT). DFHT methods are used in order to facilitate HT detection methods. In addition, logic masking has been proposed against IC piracy and overproduction. Logic masking modifies the circuit such that it does not work correctly without applying the correct key. In this paper, we propose a DFHT method reusing logic masking approach. The proposed DFHT method modifies the design to improve the HT detection methods that are based on the path delay analysis. The objective of the proposed approach is to generate fake short paths for nets which only belong to long paths, because the delay of shorter paths varies less than longer ones. Our experiments, after technology mapping, show that the proposed DFHT method increases the HT detectability and also provides the advantages of usual logic masking methods. Arash Nejat, David Hély, Vincent Beroulle |
ICCD | 2 |
| 2016 | Comparison of RTL fault models for the robustness evaluation of aerospace FPGA devicesabstractConfronted to more and more demanding standards in terms of safety and reliability, aerospace companies are investigating new methodologies to evaluate the robustness of their FPGA designs against energetic particles. In this paper, this evaluation is realized early in the design flow to avoid costly design re-spins. It permits to have a first evaluation of the RTL design robustness and of the design protections efficiency. To deal with the low accuracy of classical RTL fault models, we use a new RTL fault model taking into account the local effects of particles. We compare the fault model characteristics of different high level fault models (RTL) and low level fault models (layout) on a RTL design dedicated to the plane power supply control. These evaluations show that the new RTL fault model have best characteristics than the classical register fault model. Romain Champon, Vincent Beroulle, Athanasios Papadimitriou, David Hély, Gilles Genévrier, Frédéric Cézilly |
IOLTS | 4 |
| 2016 | Reusing logic masking to facilitate path-delay-based hardware Trojan detectionabstractHardware Trojan (HT), Integrated Circuit (IC) piracy, and overproduction are three important threats which may happen in untrusted foundries. Design changes against HTs, so-called Design-For-Hardware-Trust (DFHT), are used in order to facilitate the HT detection. In addition, logic masking has been proposed against IC piracy and overproduction. In this work, we propose a DFHT method reusing the circuitry dedicated to logic masking in order to improve the HT detection based on the path delay analysis. Arash Nejat, David Hély, Vincent Beroulle |
IOLTS | 2 |
| 2016 | ECDSA Passive Attacks, Leakage Sources, and Common Design MistakesabstractElliptic Curves Cryptography (ECC) tends to replace RSA for public key cryptographic services. ECC is involved in many secure schemes such as Elliptic Curve Diffie-Hellman (ECDH) key agreement, Elliptic Curve Integrated Encryption Scheme (ECIES), and Elliptic Curve Digital Signature Algorithm (ECDSA). As for every cryptosystem, implementation of such schemes may jeopardize the inherent security provided by the mathematical properties of the ECC. Unfortunate implementation or algorithm choices may create serious vulnerabilities. The elliptic curve scalar operation is particularly sensitive among these schemes. This article surveys passive attacks against well-spread elliptic curve scalar multiplication algorithms highlighting leakage sources and common mistakes that can be used to attack the ECDSA scheme. Experimental results are provided to illustrate and demonstrate the effectiveness of each vulnerability. Finally, the article describes the link between partial leakage and lattice attack in order to understand and demonstrate the impact of small leakages on the security of ECDSA. An example of side channel and lattice attack combination on NIST P-256 is provided in the case where the elliptic curve scalar multiplication is not protected against DPA/CPA and a controllable device is not accessible. Jeremy Dubeuf, David Hély, Vincent Beroulle |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2015 | A secure design-for-test infrastructure for lifetime security of SoCsabstractModular design of a system-on-chip (SoC) exposes intellectual property (IP) and SoC assets to attacks in test, debug, and functional modes. We enhance the SoC Design-for-Test (DfT) infrastructure with security countermeasures to thwart these attacks. We first secure IP and SoC assets from attacks in test and debug modes, then reuse the DfT infrastructure to detect attacks in functional mode. Jerry Backer, Subidh Ali, Kurt Rosenfeld, David Hély, Ozgur Sinanoglu, Ramesh Karri |
ISCAS | 4 |
| 2015 | Secure design-for-debug for Systems-on-ChipabstractThis work tackles the conflict between security and debugging of modern Systems-on-Chip (SoC). On one hand, security objectives require confidentiality of assets such as cryptographic keys, configuration and calibration data, and proprietary firmware. On the other hand, debugging instrumentation enables tracing of internal SoC signals that expose these assets via a debug port or debug memory. Mechanisms proposed to tackle this conflict either disable debugging before the SoC is released, or provide binary (all-or-nothing) access to the debugging instrumentation based on an authentication mechanism. The first approach is not practical because the debugging instrumentation is needed for in-field maintenance. The second approach does not protect against a rogue insider in a debugging team. We enhance the debugging instrumentation with security features to ensure that assets are only exposed to their owners during debug. The features first tag each asset with a unique ID of its owner, authenticate each debugger to verify access privileges, and filter the assets to determine which ones to expose given the debugger privileges. The proposed features incur 6% area and power costs, and do not impact firmware execution during debug. Jerry Backer, David Hély, Ramesh Karri |
ITC | 2 |
| 2014 | A multiple fault injection methodology based on cone partitioning towards RTL modeling of laser attacksabstractLaser attacks, especially on circuits manufactured with recent deep submicron semiconductor technologies, pose a threat to secure integrated circuits due to the multiplicity of errors induced by a single attack. An efficient way to neutralize such effects is the design of appropriate countermeasures, according to the circuit implementation and characteristics. Therefore tools which allow the early evaluation of security implementations are necessary. Our efforts involve the development of an RTL fault injection approach more representative of laser attacks than random multi-bit fault injections and the utilization and evolution of state of the art emulation techniques to reduce the duration of the fault injection campaigns. This will ultimately lead to the design and validation of new countermeasures against laser attacks, on ASICs implementing cryptographic algorithms. Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle |
DATE | 2 |
| 2014 | Emulation based fault injection on UHF RFID transponderabstractRFID tags are increasingly used for critical applications within harsh environments or for secure applications such as identification, counterfeiting protection... However, such low cost systems, initially designed for non-critical applications with a high volume, are not robust by themselves. This paper presents an UHF RF Identification (RFID) tag emulation platform with fault injection and real time monitoring capabilities. The proposed tag emulator is used to increase UHF tags robustness against transient and permanent faults and aims at providing a tool for robust and secure UHF RFID circuit designers. Omar Abdelmalek, David Hély, Vincent Beroulle |
DDECS | 2 |
| 2014 | Voltage Glitch Attacks on Mixed-Signal SystemsabstractSupply voltage glitches are a well-known fault injection method used to attack electronic circuits. The aim of this paper is to identify the specific threats of mixed signal systems and to provide some solutions to ensure their security. Indeed, many Systems on Chip use both analog and digital circuits but, most of the time, the security of such application is considered only from an exclusively digital or sometimes analog point of view. However, in mixed-signals systems, analog and digital solutions coexist and must be considered as a unique system to ensure the security of the whole application. In this purpose, this paper gives an overview of voltage glitch attacks effects and countermeasures for analog and digital blocks as part of Mixed-Signal SoCs (AMS-SoCs). It also emphasizes the unique behavior of mixed-signal circuits during glitch attacks and suggest some guidelines to associate efficiently analog and digital solutions to secure a mixed-signal system. Noemie Beringuier-Boher, Kamil Gomina, David Hély, Jean-Baptiste Rigaud, Vincent Beroulle, Assia Tria, Joel Damiens, Philippe Gendrier, Philippe Candelier |
DSD | 3 |
| 2014 | Laser-induced fault effects in security-dedicated circuitsabstractLasers have become one of the most efficient means to attack secure integrated systems. Actual faults or errors induced in the system depend on many parameters, including the circuit technology and the laser characteristics. Understanding the physical effects is mandatory to correctly evaluate during the design flow the potential consequences of a laser-based attack and implement efficient counter-measures. This paper presents results obtained within the LIESSE project, aiming at defining a comprehensive approach for designers. Outcomes include the definition of fault/error models at several levels of abstraction, specific CAD tools using these models and new counter-measures well-suited to thwart laser-based attacks. Actual measures on components manufactured in the new 28 nm FDSOI technology are also presented. Régis Leveugle, Paolo Maistri, Pierre Vanhauwaert, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Guillaume Hubert, Stephan De Castro, Jean-Max Dutertre, Alexandre Sarafianos, Noemie Beringuier-Boher, Mathieu Lisart, Joel Damiens, Philippe Candelier, Clément Tavernier |
VLSI-SoC | 9 |
| 2013 | Run-time detection of hardware Trojans: The processor protection unitabstractTypical SOC designs use processors and therefore, trust in such processor cores is essential. The 2011 Embedded Systems Challenge (ESC 2011) [1] showed a wide range of possibilities to attack a processor through hardware Trojans. We propose an approach to detect suspicious behavior of a processor and thus assess if the processor is trustworthy or not. A countermeasure, called Processor Protection Unit (PPU) is presented focusing on its design to be particularly resilient against hardware Trojan insertion. Jeremy Dubeuf, David Hély, Ramesh Karri |
ETS | 2 |
| 2013 | Experiences in side channel and testing based Hardware Trojan detectionabstractIn this work, we present and comment several experiments in Hardware Trojan detection based on both testing techniques and side channel analysis. This work has been developed by two teams of Grenoble INP students (Julien Martin, Gerson Dario Piraquive Triana, Simon Piroux Mounier, Elie Rivière, Thibault Sahuc, Jérémy Savonet and Laura Soundararadjou) during the secure IC design labs of the Grenoble INP Esisar and was then presented for the Embedded System Challenge during the Cyber Security Awareness Week (CSAW) 2012 organized by Polytechnic Institute of New York University. David Hély, Julien Martin, Gerson Dario Piraquive Triana, Simon Piroux Mounier, Elie Riviere, Thibault Sahuc, Jeremy Savonet, Laura Soundararadjou |
VTS | 1 |
| 2012 | Evaluation of a new RFID system performance monitoring approachabstractSeveral performance monitoring approaches allowing the detection of RFID system defects have been proposed in the past. This article evaluates 3 of these approaches using a SystemC model, SERFID, of a UHF RFID system. SERFID can simulate the EPC C1G2 standard for the UHF tag-reader communication and also allows a realistic bit error injection in their RF channel. Gilles Fritz, Vincent Beroulle, Oum-El-Kheir Aktouf, David Hély |
DATE | 4 |
| 2012 | Malicious key emission via hardware Trojan against encryption systemabstractIn this work, we propose a hardware Trojan within a given encryption platform. This malicious hardware aims at leaking the secret key used for encryption without perturbing the system so that the user does not notice it. We propose a hardware Trojan which detects any new encryption start and then transmit the used expended key on the system serial link. This hardware Trojan does not require any processor modification. The paper presents the way the hardware Trojan has been developed according the given platform and the associated information. This work has been developed by Grenoble INP students (M. Augagneur, Y. Clauzel and J. Dubeuf) during the secure IC design labs of the Grenoble INP Esisar and was then presented for the Embedded System Challenge during the Cyber Security Awareness Week (CSAW) 2011 organized by Polytechnic Institute of New York University. David Hély, Maurin Augagneur, Yves Clauzel, Jeremy Dubeuf |
ICCD | 1 |
| 2012 | A physical unclonable function based on setup time violationabstractIn this work, we propose a physical unclonable function (i.e. PUF) based on setup time violations. The paper presents the way the PUF has been developed detailing the successive design iterations. This work has been developed by Grenoble INP students (J. Dubeuf, M. Augagneur and Y. Clauzel) during the secure IC design course at Grenoble INP Esisar for the Embedded System Challenge during the Cyber Security Awareness Week (CSAW) 2011 organized by Polytechnic Institute of New York University. David Hély, Maurin Augagneur, Yves Clauzel, Jeremy Dubeuf |
ICCD | 1 |
| 2011 | Towards an unified IP verification and robustness analysis platformabstractIn this work, we propose to develop and to combine in a same tool functional verification and robustness analysis of IP cores. The overall purpose of this methodology unifying functional verification and robustness analysis is to help designers in getting more quickly “first right time” hardened IP designs. Indeed, re-using the results of the functional verification analysis, i.e. mutation score, will help us to analyze more quickly the IP robustness. In this paper, we discuss about the synthesizable Mutation Function performing the transient fault injection. We focus on its efficiency to model realistic transient faults and to fit with the already existing Aligator platform performing the functional verification analysis of digital IP. David Hély, Vincent Beroulle, José Ramón García Oya |
DDECS | 1 |
| 2011 | RFID System On-line Testing Based on the Evaluation of the Tags Read-Error-Rate
Gilles Fritz, Vincent Beroulle, Oum-El-Kheir Aktouf, David Hély |
J. Electron. Test. | 5 |
| 2007 | Securing Scan Control in Crypto Chips
David Hély, Frédéric Bancel, Marie-Lise Flottes, Bruno Rouzeyre |
J. Electron. Test. | 1 |
| 2006 | A secure scan design methodologyabstractIt has been proven that scan path is a potent hazard for secure chips. Scan based attacks have been recently demonstrated against DES or AES and several solutions have been presented in the literature in order to securize the scan chain. Nevertheless, the different proposed techniques are all ad hoc techniques, which are not always easy to integrate into a completely automated design flow or in an IP reuse environment. In this paper, we propose a scan chain integrity detection mechanism, which respects both automated design flow and IP reuse environment David Hély, Frédéric Bancel, Marie-Lise Flottes, Bruno Rouzeyre |
DATE | 1 |
| 2006 | Secure Scan Techniques: A ComparisonabstractDesigning secure ICs requires fulfilling many design rules in order to protect access to secret data. However, these security design requirements may be in opposition to test needs and testability improvement techniques that increase both observability and controllability. Nevertheless, secure chip designers cannot neglect the testability of their chip; a high quality production testing is primordial to ensure a good level of security since any faulty devices could induce major security vulnerability. In this paper, we present different techniques securing the scan chain technique and compare them to point out their pros and cons David Hély, Frédéric Bancel, Marie-Lise Flottes, Bruno Rouzeyre |
IOLTS | 1 |
| 2005 | Test control for secure scan designsabstractDesigning secure ICs requires fulfilling many design rules in order to protect access to secret data. However, these security design requirements may be in opposition to test needs and testability improvement techniques that increase both observability and controllability. Nevertheless, secure chip designers cannot neglect the testability of their chip; a high quality production testing is primordial to ensure a good level of security since any faulty devices could induce major security vulnerability. In this paper, we propose to merge security requirements with testability ones in a control-oriented design for security scan technique. David Hély, Frédéric Bancel, Marie-Lise Flottes, Bruno Rouzeyre |
ETS | 1 |
| 2004 | Scan Design and Secure Chip
David Hély, Marie-Lise Flottes, Frédéric Bancel, Bruno Rouzeyre, Nicolas Bérard, Michel Renovell |
IOLTS | 1 |