David Champagne

dblp:61/167 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
0since 2021 · last 2010
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 1 first-authorSecurity and privacy · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Hardware security and side channels · 87% Systems and software security · 13%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Processor architecture and microarchitecture · 46% Cloud and datacenter computing · 46% Memory systems · 9%

Topics — the 7 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels
trusted execution environments
0.112010
Scalable architectural support for trusted software · HPCA 2010
Cloud and datacenter computing › virtualization › virtualization security
hypervisor security
0.112010
Scalable architectural support for trusted software · HPCA 2010
Processor architecture and microarchitecture › hardware-assisted security
secure processor architecture
0.112010
Scalable architectural support for trusted software · HPCA 2010
Hardware security and side channels › hardware attacks
side-channel and fault attacks
0.112007
TEC-Tree: A Low-Cost, Parallelizable Tree for Efficient Defense Against Memory Replay Attacks · CHES 2007
Systems and software security
trusted computing
0.012010
Scalable architectural support for trusted software · HPCA 2010
Hardware security and side channels › trusted execution environments
trusted platform module
0.012010
Scalable architectural support for trusted software · HPCA 2010
Memory systems
memory protection
0.012007
TEC-Tree: A Low-Cost, Parallelizable Tree for Efficient Defense Against Memory Replay Attacks · CHES 2007

Methods — techniques the papers use, named apart from their topics

proof-of-concept implementation · 0.2parallelizable authentication tree · 0.1hash tree · 0.1
YearPublicationVenuePosition
2010 Scalable architectural support for trusted software
abstract
We present Bastion, a new hardware-software architecture for protecting security-critical software modules in an untrusted software stack. Our architecture is composed of enhanced microprocessor hardware and enhanced hypervisor software. Each trusted software module is provided with a secure, fine-grained memory compartment and its own secure persistent storage area. Bastion is the first architecture to provide direct hardware protection of the hypervisor from both software and physical attacks, before employing the hypervisor to provide the same protection to security-critical OS and application modules. Our implementation demonstrates the feasibility of bypassing an untrusted commodity OS to provide application security and shows better security with higher performance when compared to the Trusted Platform Module (TPM), the current industry state-of-the-art security chip. We provide a proof-of-concept implementation on the OpenSPARC platform.
David Champagne, Ruby B. Lee
HPCA1
2010 SARFUM: Security Architecture for Remote FPGA Update and Monitoring
abstract
Remote update of hardware platforms or embedded systems is a convenient service enabled by Field Programmable Gate Array (FPGA)-based systems. This service is often essential in applications like space-based FPGA systems or set-top boxes. However, having the source of the update be remote from the FPGA system opens the door to a set of attacks that may challenge the confidentiality and integrity of the FPGA configuration, the bitstream. Existing schemes propose to encrypt and authenticate the bitstream to thwart these attacks. However, we show that they do not prevent the replay of old bitstream versions, and thus give adversaries an opportunity for downgrading the system. In this article, we propose a new architecture called sarfum that, in addition to ensuring bitstream confidentiality and integrity, precludes the replay of old bitstreams. sarfum also includes a protocol for the system designer to remotely monitor the running configuration of the FPGA. Following our presentation and analysis of the security protocols, we propose an example of implementation with the CCM (Counter with CBC-MAC) authenticated encryption standard. We also evaluate the impact of our architecture on the configuration time for different FPGA devices.
Benoît Badrignans, David Champagne, Reouven Elbaz, Catherine H. Gebotys, Lionel Torres
ACM Trans. Reconfigurable Technol. Syst.2
2008 The Reduced Address Space (RAS) for Application Memory Authentication
David Champagne, Reouven Elbaz, Ruby B. Lee
ISC1
2007 TEC-Tree: A Low-Cost, Parallelizable Tree for Efficient Defense Against Memory Replay Attacks
Reouven Elbaz, David Champagne, Ruby B. Lee, Lionel Torres, Gilles Sassatelli, Pierre Guillemin
CHES2