Vincent Beroulle

dblp:51/5772 · DBLP profile ↗
← Back
55ranked-venue papers
3as first author
18since 2021 · last 2026
0000-0003-0617-3087ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 48 · 3 first-author · 15 since 2021Software engineering, systems software and programming languages · 15 · 1 first-author · 4 since 2021Security and privacy · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Fault Model-Driven Formal Verification of Cryptographic Hardware Against Fault Attacks
Daniel Thirion, George-Cristian Sercaianu, Valentin Egloff, Jean-Marc Daveau, Vincent Beroulle, David Hély, Philippe Roche
ETS5
2026 Reducing Safety False-Positives in Parity-Based Security AES Using a Hardware Fault Classifier
abstract
International audience
Daniel Thirion, Jean-Marc Daveau, Valentin Egloff, Vincent Beroulle, Philippe Roche, David Hély
IOLTS4
2026 Thermal Attack on RO-PUFs: The Cases of Bulk 65 nm and FDSOI 28 nm
abstract
Physical Unclonable Functions (PUFs) play a crucial role in enhancing the security of electronic devices by leveraging inherent manufacturing variations to generate unique and unclonable identifiers. This study explores the vulnerability of Ring Oscillator-based PUFs (RO-PUFs) to thermal attacks, focusing on two semiconductor technologies: Bulk 65 nm and Fully Depleted Silicon on Insulator (FDSOI) in 28 nm. Through detailed simulations, the effects of uniform and localized thermal variations on the stability of ring oscillator frequencies are analyzed. The results reveal that while the Bulk 65 nm technology shows resistance to uniform thermal attacks, it is highly sensitive to localized attacks. In contrast, the FDSOI 28 nm technology is vulnerable to both types of attacks due to its low variability. These observations underscore the need for robust countermeasures in the design of PUFs to ensure their reliability under varying thermal conditions.
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale
ACM Trans. Design Autom. Electr. Syst.5
2025 Comparative Study of Safety and Security-Protected AES Designs
abstract
With the increase in cybersecurity requirements and the growing connectivity of critical systems like vehicles and satellites, implementing both functional safety and hardware security is crucial. Although safety and security methods are well studied, combined analysis at the RTL or Netlist level remains under-explored. This paper provides an initial analysis of multiple AES designs—one unprotected, one with a safety-oriented countermeasure (Lockstep), and one with security-oriented countermeasures (Parity-Predictor)—using both simulation and formal methods. We identify the challenges and opportunities for enhancing combined safety and security assessments. Additionally, we evaluate the AES designs against ISO 26262 safety metrics and analyze their resilience to laser attacks, offering insight into their security robustness.
Daniel Thirion, Jean-Marc Daveau, Valentin Egloff, David Hély, Vincent Beroulle, Philippe Roche
DDECS5
2025 Reliability Under Stress: The Impact of Localized Aging on RO-PUF Architectures in FPGAs
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale
ETS5
2024 Securing Elapsed Time for Blockchain: Proof of Hardware Time and Some of its Physical Threats
abstract
Blockchain technology enables the creation of a time-stamped, shared, and replicated history of events among participants who do not trust each other. To agree on the shared history, the blockchain uses a consensus protocol, such as Nakamoto's protocol in Bitcoin. This protocol relies on a proof that ensures the elapsed time between two blocks by design with the Proof of Work mechanism. This paper focuses on the use of hardware security components to guarantee the time elapsed between two events by design and at low-power. It introduces a Proof of Hardware Time (PoHT), a hardware-based proof of elapsed time compatible with embedded systems and based on a System on Module (SoM) that features an ARM Cortex-A7 processor with a TrustZone and a Trusted Platform Module. The issue of modifying the digital elapsed time measured by hardware components is examined in relation to real elapsed time. It considers whether it is possible to alter this measurement by carrying out hardware attacks on the target. Two main dreaded events are considered: compression and elongation of the digital value of the elapsed time. Experimental attacks on the SoM are performed in terms of temperature and supply voltage targeting clock oscillators and time measurement functions, after which a security analysis and a discussion of possible countermeasures are presented.
Quentin Jayet, Christine Hennebert, Yann Kieffer, Vincent Beroulle
DSD4
2024 Modeling Thermal Effects For Biasing PUFs
abstract
Security primitives such as Physical Unclonable Functions (PUFs) or True Random Number Generators (TRNGs), have emerged as hardware roots of trust for ensuring the security of modern applications. However, these primitives display susceptibility to physical attacks, among them, in the face of temperature variations. Previous research has established the feasibility of attacks exploiting temperature fluctuations to compromise the security of these primitives. Specifically, when implemented on FPGAs, programmable components can be vulnerable to alterations induced by thermal changes. These findings underscore the need to deepen the understanding of the implications of temperature sensitivity on the security and robustness of these security mechanisms. This paper studies how heat affects, both instantaneously and permanently, the working of ring oscillators, which are the building blocks of PUFs based on Ring Oscillators. The study also suggests how to exploit these effects to bias the PUf responses, enabling thus the possibility of its cloning.
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale
ETS5
2024 Modeling Clock Glitch Fault Injection Effects on a RISC-V Microcontroller
abstract
Embedded systems face security concerns, vulnerable to physical attacks like fault injection. RISC-V processors are increasingly favored for their open-source architecture. In this article, we present practical fault models operating at the instruction encoding level, which effectively elucidate numerous observed faulty behaviors arising from clock glitch campaigns conducted on a 32-bit microcontroller (MCU) embedding a RISC-V core. We demonstrate that, owing to the variable-length encoding of instructions, the impact of these models at the execution level varies. Nevertheless, the proposed models consistently maintain their applicability irrespective of the encoding length. Furthermore, we illustrate that some of the observed faulty behaviors are comparable to those obtained when targeting Arm Cortex-M-based MCUs. In addition, we present new models that can explain new faulty behaviors. The presented models are able to explain more than $\mathbf{9 0} \%$ of the observed faulty behaviors.
Ihab Alshaer, Ahmed Al-Kaf, Valentin Egloff, Vincent Beroulle
IOLTS4
2024 Proposal of a lightweight differential power analysis countermeasure method on elliptic curves for low-cost devices
Souhir Gabsi, Yassin Kortli, Vincent Beroulle, Yann Kieffer, Belgacem Hamdi
Multim. Tools Appl.3
2023 Microarchitectural Insights into Unexplained Behaviors Under Clock Glitch Fault Injection
Ihab Alshaer, Brice Colombier, Christophe Deleuze, Vincent Beroulle, Paolo Maistri
CARDIS4
2023 A Study of High Temperature Effects on Ring Oscillator Based Physical Unclonable Functions
abstract
PUFs (Physical Unclonable Functions) have been proposed as a cost-effective solution to provide a root of trust for electronic devices which exploit intrinsic process variability. They generate identification signatures and keys only when the devices are turned on, avoiding the storage of sensitive information in memories that could be targeted by attacks. Although PUFs have many perceived advantages, they also have disadvantages such as sensitivity to temperature. Indeed their behaviour can be affected by the fact that high temperatures can accelerate permanent and transient phenomena, such as aging and transistor switching speed. In this paper we show the effects of externally induced heat on the functioning of Ring Oscillators (ROs), which form the basis of RO-PUFs. Moreover, we discuss the feasibility of temperature attacks on PUFs.
Aghiles Douadi, Giorgio Di Natale, Paolo Maistri, Elena I. Vatajelu, Vincent Beroulle
IOLTS5
2023 Experimental Evaluation of Delayed-Based Detectors Against Power-off Attack
abstract
Embedded systems are vulnerable to significant security threats from Fault Injection Attacks (FIAs), which allow attackers to gain access to confidential information. While various attack detectors have been proposed in the literature to detect different types of FIAs, these detectors themselves are susceptible to such attacks and can be compromised. Hence, the robustness of these detectors is critical in maintaining the security of embedded systems. The focus of this study is to evaluate the robustness of digital circuits and delay-based digital detectors against a new type of FIA called Power-Off Attack (POA). POA occurs when the power to the chip is turned off, and the detectors are not active. Following a POA attack, the circuit or its detectors may not function properly when the power is turned back on, which can allow other attacks to be applied without being detected if the detectors are less sensitive. This study implements two detectors on Xilinx Artix-7 FPGAs and examines the impact of heating cycles on detector characteristics when the FPGA is in various states, including power-off, power-on, and inactive states (such as clock-freezing mode). Our experiments reveal that heating cycles in power-off mode can alter the FPGA component delays and the accuracy of its detectors, which highlights the vulnerability of these systems to POA and potential issues for embedded system security.
Maryam Esmaeilian, Aghiles Douadi, Zahra Kazemi, Vincent Beroulle, Amir-Pasha Mirbaha, Mahdi Fazeli, Elena I. Vatajelu, Paolo Maistri, Giorgio Di Natale
IOLTS4
2022 Elaborating on Sub-Space Modeling as an Enrollment Solution for Strong PUF
abstract
In this work we present sub-space modeling of strong PUF as a cost efficient solution for PUF enrollment for the designers’ community. Our goal is to demonstrate a method which can reduce the overall cost in terms of number of CRPs required for training, training time and memory. Instead of modifying the estimated model structure, we propose to reduce the complexity of the modeling target. This means to provide secured access to the internal responses of strong PUF during the enrollment and capture internal CRPs to model each sub-component of the PUF independently. It also necessitates to permanently remove the internal access after the enrollment to prevent exposure of the internal responses. This means that the internal responses should not be directly accessible after enrollment. Our sub-space modeling method requires lesser number of CRPs compared to modeling the whole PUF. We experimentally prove that sub-space modeling can significantly reduce the cost of training compared to some of the latest works. For instance, we could model 128-stage 6-XOR Arbiter PUF with just above 90% prediction accuracy with 5000 CRPs. Here the response in the CRP is a vector including the responses of the sub-components. Our results show that sub-space modeling is potentially a cost-efficient solution to enroll strong PUF with high complexity.
Amir Ali Pour, David Hély, Vincent Beroulle, Giorgio Di Natale
DCOSS3
2022 Variable-Length Instruction Set: Feature or Bug?
abstract
With the increasing complexity of digital applications, the use of variable-length instruction sets became essential, in order to achieve higher code density and thus better performance. However, security aspects must always be considered, in particular with the significant improvement of attack techniques and equipment. Fault injection, in particular, is among the most interesting and promising attack techniques thanks to the recent advancements. In this article, we provide proper characterization, at the instruction set architecture (ISA) level, for several faulty behaviors that can be obtained when targeting a variable-length instruction set. We take into account the binary encoding of instructions, and show how the obtained behaviors depend on the alignment of the instructions in the memory. Moreover, we are also able to give a better insight on previous results from the literature, that were still partially unexplained. We also show how the observed behaviors can be exploited in various security contexts.
Ihab Alshaer, Brice Colombier, Christophe Deleuze, Vincent Beroulle, Paolo Maistri
DSD4
2022 A Comprehensive Survey of Attacks without Physical Access Targeting Hardware Vulnerabilities in IoT/IIoT Devices, and Their Detection Mechanisms
abstract
With the advances in the field of the Internet of Things (IoT) and Industrial IoT (IIoT), these devices are increasingly used in daily life or industry. To reduce costs related to the time required to develop these devices, security features are usually not considered. This situation creates a major security concern. Many solutions have been proposed to protect IoT/IIoT against various attacks, most of which are based on attacks involving physical access. However, a new class of attacks has emerged targeting hardware vulnerabilities in the micro-architecture that do not require physical access. We present attacks based on micro-architectural hardware vulnerabilities and the side effects they produce in the system. In addition, we present security mechanisms that can be implemented to address some of these attacks. Most of the security mechanisms target a small set of attack vectors or a single specific attack vector. As many attack vectors exist, solutions must be found to protect against a wide variety of threats. This survey aims to inform designers about the side effects related to attacks and detection mechanisms that have been described in the literature. For this purpose, we present two tables listing and classifying the side effects and detection mechanisms based on the given criteria.
Nikolaos Foivos Polychronou, Pierre-Henri Thevenon, Maxime Puys, Vincent Beroulle
ACM Trans. Design Autom. Electr. Syst.4
2021 MaDMAN: Detection of Software Attacks Targeting Hardware Vulnerabilities
abstract
The increasing complexity of modern microprocessors created new attack areas. Attackers exploit these areas using Software Attacks Targeting Hardware Vulnerabilities (SATHV) such as Cache Side-Channel, Spectre, and Rowhammer attacks. These attacks target the microarchitecture to extract privileged information. As their target is the hardware, antivirus programs cannot detect them. But, they modify the normal behavior of the microarchitecture. Modern systems are equipped with hardware performance counters (HPCs), which measure events related to hardware components. Designers can take advantage of these counters to monitor and protect the system. In the literature, there exist many solutions that use HPCs to detect SATHV. But, due to the limited number of counters, proposed solutions only protect the microprocessor against a limited set of SATHV. In contrast, we propose MaDMAN, a Malware Detector, which gathers information from HPCs to detect a large set of SATHV. MaDMAN uses a Logistic Regression classifier. In our threat model, we include Cache Side-Channel, Rowhammer, and Spectre SATHV. Our detection mechanism succeeds to detect these attacks with 98.96% accuracy, 96.3% F-score, and 0% false positive rate. In addition, MaDMAN works in noisy environments and can detect successfully evasive malware.
Nikolaos Foivos Polychronou, Pierre-Henri Thevenon, Maxime Puys, Vincent Beroulle
DSD4
2021 Cross-layer Approach to Assess FMEA on Critical Systems and Evaluate High-Level Model Realism
abstract
Embedded systems in critical applications are constrained by very strict standards. The safety of such systems is crucial, however, their safety analysis (e.g., Failure Mode and Effects Analysis, or FMEA) is often empirical and mainly relies on the experience of engineers. Performing empirical analyses on complex designs is a major challenge that leads engineers to make very pessimistic assumptions and consequently to over-design multiple countermeasures. Many fault injection techniques have been developed to evaluate the robustness of hardware designs from Register Transfer Level to Transaction Level. At the RT-level, these techniques are circuit-centered, and therefore do not rely on the overall system specifications. Besides, with complex hardware designs, fault simulations become very time-consuming. Conversely, at the transaction level, fault simulation is fast to the detriment of the realism of high-level models. In this paper, we present a new iterative cross-layer robustness analysis flow taking into account the overall critical system specifications and verifying the realism of high-level models. The first step of the flow leads to extract critical parameter ranges. Then, these ranges are used to quickly evaluate the robustness of each RTL block in the circuit. In the last step, we compute some metrics reflecting the realism of the high-level models. According to these metrics, we can determine if the high-level models must be improved. We apply this methodology to a case study of a real airborne system.
Julie Roux, Katell Morin-Allory, Vincent Beroulle, Régis Leveugle, Lilian Bossuet, Frédéric Cézilly, Frédéric Berthoz, Gilles Genévrier, François Cerisier
VLSI-SoC3
2021 Bridging the Gap between RTL and Software Fault Injection
abstract
Protecting programs against hardware fault injection requires accurate software fault models. However, typical models, such as the instruction skip, do not take into account the microarchitecture specificities of a processor. We propose in this article an approach to study the relation between faults at the Register Transfer Level (RTL) and faults at the software level. The goal is twofold: accurately model RTL faults at the software level and materialize software fault models to actual RTL injections. These goals lead to a better understanding of a system's security against hardware fault injection, which is important to design effective and cost-efficient countermeasures. Our approach is based on the comparison between results from RTL simulations and software injections (using a program mutation tool). Various analyses are included in this article to give insight on the relevance of software fault models, such as the computation of a coverage and fidelity metric, and to link software fault models to hardware RTL descriptions. These analyses are applied on various single-bit and multiple-bit injection campaigns to study the faulty behaviors of a RISC-V processor.
Johan Laurent, Christophe Deleuze, Florian Pebay-Peyroula, Vincent Beroulle
ACM J. Emerg. Technol. Comput. Syst.4
2020 On the Performance of Non-Profiled Differential Deep Learning Attacks against an AES Encryption Algorithm Protected using a Correlated Noise Generation based Hiding Countermeasure
abstract
Recent works in the field of cryptography focus on Deep Learning based Side Channel Analysis (DLSCA) as one of the most powerful attacks against common encryption algorithms such as AES. As a common case, profiling DLSCA have shown great capabilities in revealing secret cryptographic keys against the majority of AES implementations. In a very recent study, it has been shown that Deep Learning can be applied in a non-profiling way (non-profiling DLSCA), making this method considerably more practical, and able to break powerful countermeasures for encryption algorithms such as AES including masking countermeasures, requiring considerably less power traces than a first order CPA attack. In this work, our main goal is to apply the non-profiling DLSCA against a hiding-based AES countermeasure which utilizes correlated noise generation so as to hide the secret encryption key. We show that this AES, with correlated noise generation as a lightweight countermeasure, can provide equivalent protection under CPA and under non-profiling DLSCA attacks, in terms of the required power traces to obtain the secret key.
Amir Ali Pour, Athanasios Papadimitriou, Vincent Beroulle, Ehsan Aerabi, David Hély
DATE3
2020 Cross Layer Fault Simulations for Analyzing the Robustness of RTL Designs in Airborne Systems
abstract
Embedded systems in critical applications are constrained by very strict standards. Safety analysis (e.g., Failure Mode and Effect Analysis) of these systems are often empirically done and mainly based on engineer experience. Many fault injection techniques exist to evaluate the robustness of Register Transfer Level (RTL) hardware designs, but, when the designs interact with software components (e.g., micro-controllers) or are embedded in complex systems, fault simulations or emulations can be very time consuming. High level system modeling can speed up the analysis of fault propagation through the whole system but raises some realism issues. In this paper, we propose a cross-layer fault simulation method to perform the robustness evaluation of RTL architectures used in critical embedded systems. This method uses both fault simulation in RTL and Transaction Level Model (TLM) descriptions to make a trade-off between simulation time and the realism of the simulated high level faulty behaviors. Early results on an airborne case study are discussed.
Julie Roux, Vincent Beroulle, Katell Morin-Allory, Régis Leveugle, Lilian Bossuet, Frédéric Cézilly, Frédéric Berthoz, Gilles Genévrier, François Cerisier
DDECS2
2020 PUF Enrollment and Life Cycle Management: Solutions and Perspectives for the Test Community
abstract
Physically Unclonable Functions (PUFs) allow to extract unique fingerprints from silicon chips. The applications are numerous: chip identification, chip master key extraction, authentication protocol, unique seeding, etc. However, secure usage of PUF requires some precautions. This paper reviews industrial concerns associated with PUF operation, including those occurring before and after market. Namely, starting from PUF “secure” specifications, aligned with state-of-the-art standards, we explore innovative techniques to handle enrollment and subsequent PUF queries, in nominal as well as in adversarial environment.
Amir Ali Pour, Vincent Beroulle, Bertrand Cambou, Jean-Luc Danger, Giorgio Di Natale, David Hély, Sylvain Guilley, Naghmeh Karimi
ETS2
2020 Machine Learning and Hardware security: Challenges and Opportunities -Invited Talk-
abstract
Machine learning techniques have significantly changed our lives. They helped improving our everyday routines, but they also demonstrated to be an extremely helpful tool for more advanced and complex applications. However, the implications of hardware security problems under a massive diffusion of machine learning techniques are still to be completely understood. This paper first highlights novel applications of machine learning for hardware security, such as evaluation of post quantum cryptography hardware and extraction of physically unclonable functions from neural networks. Later, practical model extraction attack based on electromagnetic side-channel measurements are demonstrated followed by a discussion of strategies to protect proprietary models by watermarking them.
Francesco Regazzoni 0001, Shivam Bhasin, Amir Ali Pour, Ihab Alshaer, Furkan Aydin, Aydin Aysu, Vincent Beroulle, Giorgio Di Natale, Paul D. Franzon, David Hély, Naofumi Homma, Akira Ito 0002, Dirmanto Jap, Priyank Kashyap, Ilia Polian, Seetal Potluri, Rei Ueno, Elena I. Vatajelu, Ville Yli-Mäyry
ICCAD7
2020 Hardware Security Vulnerability Assessment to Identify the Potential Risks in A Critical Embedded Application
abstract
Internet of Things (IoT) is experiencing significant growth in the safety-critical applications which have caused new security challenges. These devices are becoming targets for different types of physical attacks, which are exacerbated by their diversity and accessibility. Therefore, there is a strict necessity to support embedded software developers to identify and remediate the vulnerabilities and create resilient applications against such attacks. In this paper, we propose a hardware security vulnerability assessment based on fault injection of an embedded application. In our security assessment, we apply a fault injection attack by using our clock glitch generator on a critical medical IoT device. Furthermore, we analyze the potential risks of ignoring these attacks in this embedded application. The results will inform the embedded software developers of various security risks and the required steps to improve the security of similar MCU-based applications. Our hardware security assessment approach is easy to apply and can lead to secure embedded IoT applications against fault attacks.
Zahra Kazemi, Mahdi Fazeli, David Hély, Vincent Beroulle
IOLTS4
2019 Fault Injection on Hidden Registers in a RISC-V Rocket Processor and Software Countermeasures
abstract
To protect against hardware fault attacks, developers can use software countermeasures. They are generally designed to thwart software fault models such as instruction skip or memory corruption. However, these typical models do not take into account the actual implementation of a processor. By analyzing the processor microarchitecture, it is possible to bypass typical software countermeasures. In this paper, we analyze the vulnerability of a secure code from FISSC (Fault Injection and Simulation Secure Collection), by simulating fault injections in a RISC-V Rocket processor RTL description. We highlight the importance of hidden registers in the processor pipeline, which temporarily hold data during code execution. Secret data can be leaked by attacking these hidden registers. Software countermeasures against such attacks are also proposed.
Johan Laurent, Vincent Beroulle, Christophe Deleuze, Florian Pebay-Peyroula
DATE2
2019 Analyzing Software Security Against Complex Fault Models with Frama-C Value Analysis
abstract
As technology evolves, digital systems are becoming more vulnerable to hardware faults, while also increasing in complexity. Analyzing the security of a program hence requires powerful techniques such as static code analysis. The methods developed so far usually apply these techniques with a specific software fault model. Yet, the effects a fault can have on a program are very diverse, and are not entirely captured by typical software fault models. In this paper, we present a method to instrument a code with complex fault models, and we use it with a tool based on abstract interpretation to verify that some security properties hold whatever the user inputs. The tool allowed us to find vulnerabilities (validated with RTL simulation) that would be hard to find with other tools. Finally, we discuss the benefits and drawbacks of the method.
Johan Laurent, Christophe Deleuze, Vincent Beroulle, Florian Pebay-Peyroula
FDTC3
2019 Security Evaluation with an Indoor UWB Localization Open Platform: Acknowledgment Attack Case Study
abstract
Indoor localization is a growing field of the Internet of Things (IoT) which is used in various sensitive applications such as manufacturing chain optimization or location-based authentication. Localization protocols rely on physical properties of the transmitted signals, such as Time-of-Flight or Received Signal Strength, which can be altered or impersonated by various types of attacks. Therefore, classical encryption techniques cannot guarantee the security of these localization protocols. Most off-the-shelf positioning platforms do not address the flaws related to localization. In addition, designers have a limited access to the various protocols, filters and algorithms involved in the localization chain, which poses a considerable obstacle to propose security solutions. This paper presents a prototyping platform called SecureLoc, open at every layer, for evaluating secure indoor localization methods based on Ultra-Wide Band Impulse Response (UWB-IR) technology, with respect to the cost and integration constraints of the IoT. We show the potential of SecureLoc for security evaluation and countermeasures through the case study of a spoofed acknowledgment attack. A novel analysis and evaluation of this attack is proposed. The robustness of SecureLoc localization chain against this attack is evaluated. Insights on future enhancements of this attack and possible low-cost countermeasures are provided.
Baptiste Pestourie, Vincent Beroulle, Nicolas Fourty
PIMRC2
2019 An Optimized NS2 Module for UHF Passive RFID Systems
Rahma Ben Fraj, Vincent Beroulle, Nicolas Fourty, Aref Meddeb
J. Electron. Test.2
2018 Time Modeling with NS2 in UHF RFID Anti-Collision Protocols
abstract
In UHF RFID systems, many collisions happen due to the numerous tag responses generated by the inventory process. This is a serious worry faced by the RFID technology which can limit RFID system performances. As a matter of fact, the extra identification delays added by these collisions and the extra energy consumed can bring a waste of bandwidth to the interrogation process. Considering these collisions has been identified as a critical task in RFID systems. Indeed, the efficiency of tag identification is related to the performance of the algorithm of anti-collision, which is implemented on the tag and the reader. To evaluate this performance, an RFID module has already been developed in the NS2 Simulator. This NS2 RFID module implements an RFID system based on the Q-Algorithm of EPC global Radio-Frequency Identification Protocols Class1 Generation-2 Standard (EPC C1 Gen2). The focus of this module is the network layer and its mechanisms for anticollision. In this paper, we propose an optimization of the time model of this NS2 RFID module. This optimization is based on the use of several slots time durations. First, we validate our RFID module model by simulation with NS2 and comparison with theoretical results. Secondly, we conduct a performance evaluation of two recent RFID anti-collision algorithms (Q+ and Split Q-Algorithm), evaluate their performances with this novel model and compared them to the Q-Algorithm of the EPC C1 Gen2 standard. By evaluating the performance of these protocols in our RFID module, we validate that the Split Q-Algorithm and the Q+ minimize the Q-Algorithm identification time. Our new model much more realistic in terms of timing can be of great help in further investigating the performance of the Q-Algorithm and for actual UHF RFID systems performance analysis.
Rahma Ben Fraj, Vincent Beroulle, Nicolas Fourty, Aref Meddeb
AINA2
2018 On the Importance of Analysing Microarchitecture for Accurate Software Fault Models
abstract
Fault injection is a powerful technique for attacking digital systems. Software developers have to take into account fault effects when system security is a concern. To this end, software fault models have been developed. However, these models are often designed independently of any hardware consideration and thus raise the problem of realism. The generality of these models cannot account for the specificities of each architecture. As a consequence, software countermeasures based on such software fault models do not guarantee a good protection against faults. Processor microarchitecture should be precisely analysed to better understand faulty behaviours and design stronger software countermeasures. To illustrate this assumption, we will show in this paper some faulty behaviours that have been observed on a RISC-V processor, and their consequences on typical software countermeasures.
Johan Laurent, Vincent Beroulle, Christophe Deleuze, Florian Pebay-Peyroula, Athanasios Papadimitriou
DSD2
2018 Laser Fault Injection at the CMOS 28 nm Technology Node: an Analysis of the Fault Model
abstract
S. Skorobogatov and R. Anderson identified laser illumination as an effective technique to conduct fault attacks in 2002. In these early days of laser-induced fault injection, it was proven to be possible to inject single-bit faults into integrated circuits. This corresponds to the more restrictive fault model found in the fault attack bibliography. The target area under laser illumination (a few micrometers, down to ~1 µm) broadly matched that of a single transistor. It was consistent with a single-bit fault model. However, since then the technology of secure devices has evolved. In current circuits even the smallest laser spots may illuminate several logic cells. This raises the question of the validity of the single-bit fault model: does it still hold? In this work, we report an assessment of its validity through experimental results obtained from circuits designed at the 28 nm CMOS technology node. We also describe the main properties of the corresponding fault model obtained from both static and dynamic experiments.
Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Stephan De Castro, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre
FDTC2
2018 The case of using CMOS FD-SOI rather than CMOS bulk to harden ICs against laser attacks
abstract
At first used to emulate the effects of radioactive ionizing particules passing through integrated circuits (ICs), laser illumination is also used to inject faults into the computations of secure ICs for the purpose of retrieving secret data. The CMOS FD-SOI technology is expected to be less sensitive to laser faults injection than the more usual CMOS bulk technology. We report in this work an experimental assessment of the interest of using FD-SOI rather than CMOS bulk to decrease laser sensitivity. Our experiments were conducted on test chips at the 28nm node for both technologies with laser pulse durations in the picosecond and nanosecond ranges.
Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre
IOLTS2
2018 Security Enhancements of a Mutual Authentication Protocol Used in a HF Full-Fledged RFID Tag
Yassine Naija, Vincent Beroulle, Mohsen Machhout
J. Electron. Test.2
2016 On the development of a new countermeasure based on a laser attack RTL fault model
Charalampos Ananiadis, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle
DATE4
2016 How logic masking can improve path delay analysis for Hardware Trojan detection
abstract
Hardware Trojan (HT), Integrated Circuit (IC) piracy, and overproduction are three important threats which may happen in untrusted foundries. Modifying structurally the IC design at different abstraction level to counter the HT threats is known as Design-For-Hardware-Trust (DFHT). DFHT methods are used in order to facilitate HT detection methods. In addition, logic masking has been proposed against IC piracy and overproduction. Logic masking modifies the circuit such that it does not work correctly without applying the correct key. In this paper, we propose a DFHT method reusing logic masking approach. The proposed DFHT method modifies the design to improve the HT detection methods that are based on the path delay analysis. The objective of the proposed approach is to generate fake short paths for nets which only belong to long paths, because the delay of shorter paths varies less than longer ones. Our experiments, after technology mapping, show that the proposed DFHT method increases the HT detectability and also provides the advantages of usual logic masking methods.
Arash Nejat, David Hély, Vincent Beroulle
ICCD3
2016 Comparison of RTL fault models for the robustness evaluation of aerospace FPGA devices
abstract
Confronted to more and more demanding standards in terms of safety and reliability, aerospace companies are investigating new methodologies to evaluate the robustness of their FPGA designs against energetic particles. In this paper, this evaluation is realized early in the design flow to avoid costly design re-spins. It permits to have a first evaluation of the RTL design robustness and of the design protections efficiency. To deal with the low accuracy of classical RTL fault models, we use a new RTL fault model taking into account the local effects of particles. We compare the fault model characteristics of different high level fault models (RTL) and low level fault models (layout) on a RTL design dedicated to the plane power supply control. These evaluations show that the new RTL fault model have best characteristics than the classical register fault model.
Romain Champon, Vincent Beroulle, Athanasios Papadimitriou, David Hély, Gilles Genévrier, Frédéric Cézilly
IOLTS2
2016 Reusing logic masking to facilitate path-delay-based hardware Trojan detection
abstract
Hardware Trojan (HT), Integrated Circuit (IC) piracy, and overproduction are three important threats which may happen in untrusted foundries. Design changes against HTs, so-called Design-For-Hardware-Trust (DFHT), are used in order to facilitate the HT detection. In addition, logic masking has been proposed against IC piracy and overproduction. In this work, we propose a DFHT method reusing the circuitry dedicated to logic masking in order to improve the HT detection based on the path delay analysis.
Arash Nejat, David Hély, Vincent Beroulle
IOLTS3
2016 ECDSA Passive Attacks, Leakage Sources, and Common Design Mistakes
abstract
Elliptic Curves Cryptography (ECC) tends to replace RSA for public key cryptographic services. ECC is involved in many secure schemes such as Elliptic Curve Diffie-Hellman (ECDH) key agreement, Elliptic Curve Integrated Encryption Scheme (ECIES), and Elliptic Curve Digital Signature Algorithm (ECDSA). As for every cryptosystem, implementation of such schemes may jeopardize the inherent security provided by the mathematical properties of the ECC. Unfortunate implementation or algorithm choices may create serious vulnerabilities. The elliptic curve scalar operation is particularly sensitive among these schemes. This article surveys passive attacks against well-spread elliptic curve scalar multiplication algorithms highlighting leakage sources and common mistakes that can be used to attack the ECDSA scheme. Experimental results are provided to illustrate and demonstrate the effectiveness of each vulnerability. Finally, the article describes the link between partial leakage and lattice attack in order to understand and demonstrate the impact of small leakages on the security of ECDSA. An example of side channel and lattice attack combination on NIST P-256 is provided in the case where the elliptic curve scalar multiplication is not protected against DPA/CPA and a controllable device is not accessible.
Jeremy Dubeuf, David Hély, Vincent Beroulle
ACM Trans. Design Autom. Electr. Syst.3
2014 A multiple fault injection methodology based on cone partitioning towards RTL modeling of laser attacks
abstract
Laser attacks, especially on circuits manufactured with recent deep submicron semiconductor technologies, pose a threat to secure integrated circuits due to the multiplicity of errors induced by a single attack. An efficient way to neutralize such effects is the design of appropriate countermeasures, according to the circuit implementation and characteristics. Therefore tools which allow the early evaluation of security implementations are necessary. Our efforts involve the development of an RTL fault injection approach more representative of laser attacks than random multi-bit fault injections and the utilization and evolution of state of the art emulation techniques to reduce the duration of the fault injection campaigns. This will ultimately lead to the design and validation of new countermeasures against laser attacks, on ASICs implementing cryptographic algorithms.
Athanasios Papadimitriou, David Hély, Vincent Beroulle, Paolo Maistri, Régis Leveugle
DATE3
2014 Emulation based fault injection on UHF RFID transponder
abstract
RFID tags are increasingly used for critical applications within harsh environments or for secure applications such as identification, counterfeiting protection... However, such low cost systems, initially designed for non-critical applications with a high volume, are not robust by themselves. This paper presents an UHF RF Identification (RFID) tag emulation platform with fault injection and real time monitoring capabilities. The proposed tag emulator is used to increase UHF tags robustness against transient and permanent faults and aims at providing a tool for robust and secure UHF RFID circuit designers.
Omar Abdelmalek, David Hély, Vincent Beroulle
DDECS3
2014 Voltage Glitch Attacks on Mixed-Signal Systems
abstract
Supply voltage glitches are a well-known fault injection method used to attack electronic circuits. The aim of this paper is to identify the specific threats of mixed signal systems and to provide some solutions to ensure their security. Indeed, many Systems on Chip use both analog and digital circuits but, most of the time, the security of such application is considered only from an exclusively digital or sometimes analog point of view. However, in mixed-signals systems, analog and digital solutions coexist and must be considered as a unique system to ensure the security of the whole application. In this purpose, this paper gives an overview of voltage glitch attacks effects and countermeasures for analog and digital blocks as part of Mixed-Signal SoCs (AMS-SoCs). It also emphasizes the unique behavior of mixed-signal circuits during glitch attacks and suggest some guidelines to associate efficiently analog and digital solutions to secure a mixed-signal system.
Noemie Beringuier-Boher, Kamil Gomina, David Hély, Jean-Baptiste Rigaud, Vincent Beroulle, Assia Tria, Joel Damiens, Philippe Gendrier, Philippe Candelier
DSD5
2014 Laser-induced fault effects in security-dedicated circuits
abstract
Lasers have become one of the most efficient means to attack secure integrated systems. Actual faults or errors induced in the system depend on many parameters, including the circuit technology and the laser characteristics. Understanding the physical effects is mandatory to correctly evaluate during the design flow the potential consequences of a laser-based attack and implement efficient counter-measures. This paper presents results obtained within the LIESSE project, aiming at defining a comprehensive approach for designers. Outcomes include the definition of fault/error models at several levels of abstraction, specific CAD tools using these models and new counter-measures well-suited to thwart laser-based attacks. Actual measures on components manufactured in the new 28 nm FDSOI technology are also presented.
Régis Leveugle, Paolo Maistri, Pierre Vanhauwaert, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Guillaume Hubert, Stephan De Castro, Jean-Max Dutertre, Alexandre Sarafianos, Noemie Beringuier-Boher, Mathieu Lisart, Joel Damiens, Philippe Candelier, Clément Tavernier
VLSI-SoC10
2012 Evaluation of a new RFID system performance monitoring approach
abstract
Several performance monitoring approaches allowing the detection of RFID system defects have been proposed in the past. This article evaluates 3 of these approaches using a SystemC model, SERFID, of a UHF RFID system. SERFID can simulate the EPC C1G2 standard for the UHF tag-reader communication and also allows a realistic bit error injection in their RF channel.
Gilles Fritz, Vincent Beroulle, Oum-El-Kheir Aktouf, David Hély
DATE2
2011 Towards an unified IP verification and robustness analysis platform
abstract
In this work, we propose to develop and to combine in a same tool functional verification and robustness analysis of IP cores. The overall purpose of this methodology unifying functional verification and robustness analysis is to help designers in getting more quickly “first right time” hardened IP designs. Indeed, re-using the results of the functional verification analysis, i.e. mutation score, will help us to analyze more quickly the IP robustness. In this paper, we discuss about the synthesizable Mutation Function performing the transient fault injection. We focus on its efficiency to model realistic transient faults and to fit with the already existing Aligator platform performing the functional verification analysis of digital IP.
David Hély, Vincent Beroulle, José Ramón García Oya
DDECS2
2011 RFID System On-line Testing Based on the Evaluation of the Tags Read-Error-Rate
Gilles Fritz, Vincent Beroulle, Oum-El-Kheir Aktouf, David Hély
J. Electron. Test.2
2008 A Design-for-Test Implementation of an Asynchronous Network-on-Chip Architecture and its Associated Test Pattern Generation and Application
Xuan-Tu Tran, Yvain Thonnart, Jean Durupt, Vincent Beroulle, Chantal Robach
NOCS4
2007 Functional Verification of RTL Designs driven by Mutation Testing metrics
abstract
The level of confidence in a VHDL description directly depends on the quality of its verification. This quality can be evaluated by mutation-based test, but the improvement of this quality requires tremendous efforts. In this paper, we propose a new approach that both qualifies and improves the functional verification process. First, we qualify test cases thanks to the mutation testing metrics: faults are injected in the design under verification (DUV) (making DUV's mutants) to check the capacity of test cases to detect theses mutants. Then, a heuristic is used to automatically improve IPs validation data. Experimental results obtained on RTL descriptions from ITC'99 benchmark show how efficient is our approach.
Youssef Serrestou, Vincent Beroulle, Chantal Robach
DSD2
2007 Implementation of a Design-for-Test Architecture for Asynchronous Networks-on-Chip
abstract
In order to improve the testability of asynchronous NoCs, we have developed a design-for-test (DfT) architecture. In this architecture, each asynchronous network node is surrounded by an asynchronous test wrapper and the network communication channels are reused to establish high throughput TAMs. A special block, the generator-analyzer-controller (GAC) unit, has also been developed to generate test vectors, to control test flows, and to analyze the test results. This unit can be implemented on-chip or off-chip (in our experiments, it has been implemented off-chip). The operation of the test wrappers is controlled by a dedicated 2-bit configuration channel. Thanks to its scalability and versatility, the proposed architecture can be configured to adapt to any NoC topology and to any specific application.
Xuan-Tu Tran, Jean Durupt, Yvain Thonnart, François Bertrand, Vincent Beroulle, Chantal Robach
NOCS5
2007 Qualification of behavioral level design validation for AMS & RF SoCs
abstract
The expansion of Wireless Systems-on-Chip leads to a rapid development of design and manufacturing methods In this paper, the test vectors used for design validation of AMS & RF SoCs are evaluated and optimized. This qualification is based on a fault injection method. A fault model based on variation of behavioral parameters and a related qualification metric are proposed. This approach is used in the receiver’s design of a WCDMA transceiver. A test set defined by verification engineers during the validation of this system is qualified and optimized. Then, this test set is compared with a second test set automatically generated by a developed tool.
Yves Joannon, Vincent Beroulle, Chantal Robach, Smail Tedjini, Jean-Louis Carbonéro
VLSI-SoC2
2007 Impact of hardware emulation on the verification quality improvement
abstract
Software simulation remains the most used method for VHDL RTL functional verification. The functional verification process essentially consists of two parts. The first one is the functional qualification; the second one is the qualification- driven stimuli generation. Currently, the qualification and the generation tasks are iterative processes based on VHDL simulation which is dramatically time consuming. The simulation time increases with the circuits’ size and the required level of quality. In our previous works, we have proposed some approaches based on the mutation testing technique to evaluate and to improve functional validation quality. Now, to reduce this simulation time, we propose in this paper a new approach based on FPGA emulation. So, an hardware-software platform called “Meta-Mutant Testbench” is used to emulate mutants. Experimental results for some ITC’99 benchmark circuits show that our mutation emulator is about 20 times faster than classical software simulators; this speedup increases with the circuits’ size.
Youssef Serrestou, Vincent Beroulle, Chantal Robach
VLSI-SoC2
2006 A DFT Architecture for Asynchronous Networks-on-Chip
abstract
The Networks-on-Chip (NoCs) paradigm is emerging as a solution for the communication of SoCs. Many NoC architecture propositions are presented but few works on testing these network architectures. To test the SoCs, the main challenge is to reach into the embedded cores (i.e, the IPs). In this case, the DFT techniques that integrate test architectures into the SoCs to ease the test of these SoCs are really favoured. In this paper, we present a new methodology for testing NoC architectures. A modular, generic, scalable and configurable DFT architecture is developed in order to ease the test of NoC architectures. The target of this test architecture is asynchronous NoC architectures that are implemented in GALS systems. The proposed architecture is therefore named ANoC-TEST and is implemented in QDI asynchronous circuits. In addition, this architecture can be used to test the computing resources of the networked SoCs. Some initial results and conclusions are also given.
Xuan-Tu Tran, Jean Durupt, François Bertrand, Vincent Beroulle, Chantal Robach
ETS4
2005 Mutation Sampling Technique for the Generation of Structural Test Data
abstract
The authors' goal is to produce validation data that can be used as an efficient (pre) test set for structural stuck-at faults. In this paper, we detail an original test-oriented mutation sampling technique used for generating such data and we present a first evaluation on these validation data with regard to a structural test.
Mathieu Scholivé, Vincent Beroulle, Chantal Robach, Marie-Lise Flottes, Bruno Rouzeyre
DATE2
2004 Design of CMOS MEMS based on mechanical resonators using a RF simulation approach
abstract
This paper, which is mostly tutorial in nature, deals with the design of CMOS microelectromechanical systems MEMS using standard microelectronic computer-aided design tools. The proposed case study is an on-chip spectrum analyzer with an electronic mixer and a mechanical filter. Based on both analytical modeling and characterization, the filter is described using an analog hardware description language. System level simulations are then performed using a recently released simulation tool that offer new possibilities regarding the analysis of multidomain, multifrequency designs. Presented results include periodic steady state determination, small-signal analysis and noise investigation. The simulations demonstrate the ability of the proposed system to identify the harmonics of a 50-Hz square-wave signal, owing to the selectivity of the mechanical filter.
Laurent Latorre, Vincent Beroulle, Pascal Nouet
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2002 On the Use of an Oscillation-Based Test Methodology for CMOS Micro-Electro-Mechanical Systems
abstract
This paper introduces the use of the oscillation test technique for MEMS testing. This well-known test technique is here adapted to MEMS. Its efficiency is evaluated based on a case study: A CMOS electromechanical magnetometer.
Vincent Beroulle, Yves Bertrand, Laurent Latorre, Pascal Nouet
DATE1
2002 Evaluation of the Oscillation-based Test Methodology for Micro-Electro-Mechanical Systems
abstract
In this paper, Oscillation-based Test Methodology (OTM) is evaluated in the context of MEMS testing. Both qualitative and quantitative evaluations of fault coverage are discussed and the impact of test on production yield is addressed. This article also introduces the Lorentz force as a low-cost stimulus for electro-mechanical structures.
Vincent Beroulle, Yves Bertrand, Laurent Latorre, Pascal Nouet
VTS1
2001 Test and Testability of a Monolithic MEMS for Magnetic Field Sensing
Vincent Beroulle, Yves Bertrand, Laurent Latorre, Pascal Nouet
J. Electron. Test.1