Nicola Tuveri

dblp:54/10083 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0001-5172-4568ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Multi-Partner Project: Quantum-Secure IoT-based Digital Manufacturing Pilot in QUBIP project
abstract
Connectivity has become essential to modern manufacturing, but it also introduces new security challenges. Industrial IoT ecosystems rely on public-key cryptography to protect communications, firmware, and operational data. However, the emergence of quantum computing threatens to undermine these cryptographic foundations, exposing long-lived manufacturing systems to future attacks. This paper presents the Quantum-Secure IoT-based Digital Manufacturing Pilot, developed within the EU-funded QUBIP project, which investigates the integration of post-quantum cryptography (PQC) into IoT environments. The pilot aims to demonstrate how quantum resistant algorithms can be efficiently deployed across heterogeneous devices with limited resources to ensure data exchange and authentication. By combining software and hardware-based approaches, the proposed pilot provides a replicable model for PQC migration in digital manufacturing, ensuring long-term data integrity and resilience in the quantum era.
Eros Camacho-Ruiz, Pablo Navarro-Torrero, Piedad Brox Jiménez, Maria Chiara Molteni, Alberto Battistello, Davide Bellizia, Agostino Sette, Enrico Bisio, Nicola Tuveri, Enrico Bravi, Francesco Vaccaro, Grazia D'Onghia, Andrea Vesco
DATE9
2025 External Entropy Supply for IoT Devices Employing a RISC-V Trusted Execution Environment
Arttu Paju, Juha Nurmi, Alejandro Cabrera Aldaya, Nicola Tuveri, Juha Savimäki, Marko Kivikangas, Brian McGillion
CRiSIS4
2022 OpenSSLNTRU: Faster post-quantum TLS key exchange
Daniel J. Bernstein, Billy Bob Brumley, Ming-Shing Chen, Nicola Tuveri
USENIX Security Symposium4
2020 Certified Side Channels
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, Billy Bob Brumley
USENIX Security Symposium3
2019 Triggerflow: Regression Testing by Advanced Execution Path Inspection
Iaroslav Gridin, Cesar Pereida García, Nicola Tuveri, Billy Bob Brumley
DIMVA3
2019 Port Contention for Fun and Profit
abstract
Simultaneous Multithreading (SMT) architectures are attractive targets for side-channel enabled attackers, with their inherently broader attack surface that exposes more per physical core microarchitecture components than cross-core attacks. In this work, we explore SMT execution engine sharing as a side-channel leakage source. We target ports to stacks of execution units to create a high-resolution timing side-channel due to port contention, inherently stealthy since it does not depend on the memory subsystem like other cache or TLB based attacks. Implementing our channel on Intel Skylake and Kaby Lake architectures featuring Hyper-Threading, we mount an end-to-end attack that recovers a P-384 private key from an OpenSSL-powered TLS server using a small number of repeated TLS handshake attempts. Furthermore, we show that traces targeting shared libraries, static builds, and SGX enclaves are essentially identical, hence our channel has wide target application.
Alejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García, Nicola Tuveri
IEEE Symposium on Security and Privacy5
2018 Side-Channel Analysis of SM2: A Late-Stage Featurization Case Study
abstract
SM2 is a public key cryptography suite originating from Chinese standards, including digital signatures and public key encryption. Ahead of schedule, code for this functionality was recently mainlined in OpenSSL, marked for the upcoming 1.1.1 release. We perform a security review of this implementation, uncovering various deficiencies ranging from traditional software quality issues to side-channel risks. To assess the latter, we carry out a side-channel security evaluation and discover that the implementation hits every pitfall seen for OpenSSL's ECDSA code in the past decade. We carry out remote timings, cache timings, and EM analysis, with accompanying empirical data to demonstrate secret information leakage during execution of both digital signature generation and public key decryption. Finally, we propose, implement, and empirically evaluate countermeasures.
Nicola Tuveri, Sohaib ul Hassan, Cesar Pereida García, Billy Bob Brumley
ACSAC1
2011 Remote Timing Attacks Are Still Practical
Billy Bob Brumley, Nicola Tuveri
ESORICS2