EDBT 2026 Demo / reviewers in the wild / expert
Lejla Batina
dblp:67/1939
· DBLP profile ↗
95ranked-venue papers
24as first author
27since 2021 · last 2026
0000-0003-0727-3573ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 50 · 14 first-author · 17 since 2021Systems, architecture and hardware · 36 · 9 first-author · 8 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 5Computer networks · 3 · 2 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Reassessing Side-Channel Vulnerabilities and Countermeasures in PQC ImplementationsabstractPost-Quantum Cryptography (PQC) algorithms should remain secure even in the presence of quantum computers. Although the security of such schemes is guaranteed at the algorithmic level, real-world implementations often suffer from other vulnerabilities like Side-Channel Analysis (SCA) attacks. This Systematization of Knowledge (SoK) paper investigates SCA attacks targeting implementations of PQC algorithms. This work categorizes attacks from an adversarial perspective to identify the most vulnerable components of the algorithms' implementations and highlights unexplored parts in current implementations. In addition, it reviews and analyzes the efficiency and efficacy of existing countermeasures to SCA attacks in current hardware implementations. This approach helps identify countermeasures that provide broader protection and highlights characteristics needed for future secure implementations. Our findings offer guidance in strengthening existing systems and developing more efficient defenses against side-channel attacks. Patrik Dobias, Azade Rezaeezade, Lejla Batina, Lukasz Chmielewski, Lukas Malina |
AsiaCCS | 3 |
| 2026 | Focus Session: Exploring Semantic Leakage in Edge FPGA Implementations of Neural NetworksabstractEdge neural network implementations can be substantially accelerated on FPGAs. Open-source tools like FINN enable real-world deployment of applications in various domains. However, the privacy and security of FPGA-based edge neural network implementations have often been overlooked. Semantic leakage, a new type of side-channel vulnerability, has been identified in both software and hardware neural network implementations.In this paper, we provide an initial analysis of FPGA implementations of convolutional neural networks (CNNs) generated using the open-source FINN framework. Our work follows the recent semantic-leakage threat model, in which the adversary aims to differentiate between categories of input data based on side-channel leakage. We mount a side-channel attack on CNNs compiled with FINN for AMD ZCU104 FPGA and show that FINN-generated designs exhibit such leakage. To further explore how leakage varies, we tune various implementation aspects, including storage elements, arithmetic operations in computation elements, and folding. Our experiments demonstrate that implementing the arithmetic operations and storage elements using look-up tables (LUTs) may be less vulnerable to semantic leakage than using the specific-purpose FPGA blocks. More importantly, we show that more folding transformations enhance resistance against semantic leakage. Zhuoran Liu 0001, Konstantina Miteloudi, Durba Chatterjee, Lejla Batina |
DATE | 4 |
| 2025 | A Decomposition Approach for Evaluating Security of Masking
Vahid Jahandideh, Bart Mennink, Lejla Batina |
ASIACRYPT (1) | 3 |
| 2025 | Comparing Gaston with Ascon-p: Side-Channel Analysis and Hardware Evaluation
Parisa A. Eliasi, Lejla Batina, Silvia Mella |
CANS | 2 |
| 2025 | BarraCUDA: Edge GPUs do Leak DNN Weights
Lukasz Chmielewski, Leo Weissbart, Lejla Batina, Yuval Yarom |
USENIX Security Symposium | 4 |
| 2025 | Being Patient and Persistent: Optimizing An Early Stopping Strategy for Deep Learning in Profiled AttacksabstractThe absence of an algorithm that effectively monitors the deep learning models used in side-channel attacks increases the difficulty of a security evaluation. If an attack is unsuccessful, that could be due to multiple reasons. It can be that we are indeed dealing with a resistant implementation, but it is possible that the deep learning model used is faulty. In this contribution, we formalize two conditions,persistenceandpatience, for a deep learning model to be optimal and we propose an early stopping algorithm that reliably recognizes the model's optimal state during training. The novelty of our solution is in an efficient implementation of guessing entropy estimation as a success metric used to measure the strength of a side-channel adversary. As a result, the model which uses our strategy for learning converges with fewer traces than other known methods. Servio Paguada, Lejla Batina, Ileana Buhan, Igor Armendariz |
IEEE Trans. Computers | 2 |
| 2024 | ABBY: Automating leakage modelling for side-channel analysisabstractMitigating side-channel leakage in cryptographic components is a vital concern for developers working with embedded devices. Conventional side-channel analysis demands substantial manual effort for setup preparation and trace recording, rendering it more intricate during the dynamic design phase, where software alterations occur frequently. Additionally, identifying the specific instruction(s) responsible for leakage has been hindered by limited hardware descriptions and restricted access to process technology information. Omid Bazangani, Alexandre Iooss, Ileana Buhan, Lejla Batina |
AsiaCCS | 4 |
| 2024 | ASHES '24: Workshop on Attacks and Solutions in Hardware SecurityabstractThe workshop on "Attacks and Solutions in HardwarE Security (ASHES)" welcomes any theoretical and practical works on hardware security, including attacks, solutions, countermeasures, proofs, classification, formalization, and implementations. Besides mainstream research, ASHES puts some focus on new and emerging scenarios: This includes the Internet of Things (IoT), nuclear weapons inspections, arms control, consumer and infrastructure security, or supply chain security, among others. ASHES also welcomes works on special purpose hardware, such as lightweight, low-cost, and energy-efficient devices, or non-electronic security systems. Lejla Batina, Chip-Hong Chang, Ulrich Rührmair, Jakub Szefer |
CCS | 1 |
| 2024 | Can Machine Learn Pipeline Leakage?abstractSide-channel attacks cause a significant threat to security implementations in embedded devices. Accordingly, an automated framework simulating side-channel behaviours can offer invaluable insights into leakage origins and characteristics, helping developers improve those devices during the design phase. While there has been a substantial effort towards crafting leakage simulators, earlier methods either necessitated significant manual work for reverse engineering the micro-architectural layer or depended on Deep Learning (DL) models where the neural network's complexity increased considerably with the addition of pipeline stages. This paper presents a novel modelling approach using Recurrent Neural Networks (RNNs) to construct instruction-level power models that exhibit enhanced performance in detecting pipeline leakage. Our findings indicate that with memory-based machine learning models, it becomes unnecessary to input data accounting for the pipeline effect. This strategy reduces feature dimensionality by at least one-third for a three-stage pipeline, albeit at a modest compromise in model performance. This reduced feature set underscores our model's scalability, making it a preferred choice for analyzing microprocessors with extended pipeline stages. Importantly, our methodology accelerates the micro-architectural profiling phase in side-channel simulator design. When evaluated on an expansive dataset, the performance of our memory-based model closely matches that of the Multilayer Perceptron (MLP) with an R2 value of 0.79. On a reduced dataset (removing the pipeline effect), our model achieves an R2 value of 0.65, outperforming the MLP, which reaches an R2 value of 0.39. Moreover, our model is designed with scalability in mind, making it suitable for profiling microcontrollers with advanced pipeline stages. For the practical realisation of our approach, we employed the open-source ABBY-CM0 dataset from the ARM Cortex-M0 microcontroller, which has three pipeline stages. To provide a detailed analysis, we also consider a Convolutional Neural Network (CNN) besides two RNN architectures (Long Short-Term Memory and Gated Recurrent Unit). Omid Bazangani, Parisa A. Eliasi, Stjepan Picek, Lejla Batina |
DATE | 4 |
| 2024 | Xoodyak Under SCA SiegeabstractIn this paper, we conduct a detailed power side-channel analysis of Xoodyak, a lightweight cryptographic algorithm, on an FPGA platform. We focus on the initialization phase of Xoodyak in the authenticated encryption with associated data (AEAD) mode. First, we introduce a new leakage model and perform a leakage assessment. Then, we perform non-profiled and profiled attacks to determine if the observed leakages can be exploited. For a non-profiled attack, we perform a correlation power analysis on all key bits, achieving a success rate of 91.4% with 50 000 traces. Our approach for a profiled attack involves a template attack and a deep learning-based attack. The former achieves a success rate of 99.2%, recovering almost all key bits with 20 000 traces in the attack phase. The latter reaches a guessing entropy of zero after 550 traces and adapts to the leakage model within 50 epochs. Parisa A. Eliasi, Silvia Mella, Leo Weissbart, Lejla Batina, Stjepan Picek |
DDECS | 4 |
| 2024 | Optimised AES with RISC-V Vector ExtensionsabstractWith the advent of quantum computers, organizations and users should consider the potential impact of quantum threats on their cryptographic systems and be prepared to adopt Post-Quantum Cryptography (PQC) solutions when needed. However, PQC algorithms are often difficult to implement on standard processors and resource-constrained embedded devices, due to complicated mathematical algorithms and large parameters. The goal of this research is to design efficient HW/SW co-design of the PQC algorithm Classic McEliece (CM) using the RISC-V Instruction Set Architecture (ISA). In the first step, the acceleration of the AES algorithm, which is used as part of the key generation in CM, is explored using RISC-V Vector Extensions version 1.0 (RVV1.0). In this paper, we compare the vector-accelerated AES running on Vicuan coprocessor with the scalar AES running on Ibex. Mahnaz Namazi Rizi, Nusa Zidaric, Lejla Batina, Nele Mentens |
DDECS | 3 |
| 2024 | SoK: Neural Network Extraction Through Physical Side Channels
Dirk Lauret, Zhuoran Liu 0001, Lejla Batina |
USENIX Security Symposium | 4 |
| 2023 | ASHES '23: Workshop on Attacks and Solutions in Hardware SecurityabstractThe workshop on "Attacks and Solutions in HardwarE Security (ASHES)" welcomes any theoretical and practical works on hardware security, including attacks, solutions, countermeasures, proofs, classification, formalization, and implementations. Besides mainstream research, ASHES puts some focus on new and emerging scenarios: This includes the Internet of Things (IoT), nuclear weapons inspections, arms control, consumer and infrastructure security, or supply chain security, among others. ASHES also welcomes works on special purpose hardware, such as lightweight, low-cost, and energy-efficient devices, or non-electronic security systems. Lejla Batina, Chip-Hong Chang, Domenic Forte, Ulrich Rührmair |
CCS | 1 |
| 2023 | Label Correlation in Deep Learning-Based Side-Channel AnalysisabstractThe efficiency of the profiling side-channel analysis can be significantly improved with machine learning techniques. Although powerful, a fundamental machine learning limitation of being data-hungry received little attention in the side-channel community. In practice, the maximum number of leakage traces that evaluators/attackers can obtain is constrained by the scheme requirements or the limited accessibility of the target. Even worse, various countermeasures in modern devices increase the conditions on the profiling size to break the target. This work demonstrates a practical approach to dealing with the lack of profiling traces. Instead of learning from a one-hot encoded label, transferring the labels to their distribution can significantly speed up the convergence of guessing entropy. By studying the relationship between all possible key candidates, we propose a new metric, denoted Label Correlation (LC), to evaluate the generalization ability of the profiling model. We validate LC with two common use cases: early stopping and network architecture search, and the results indicate its superior performance. Lichao Wu, Leo Weissbart, Marina Krcek, Huimin Li 0004, Guilherme Perin, Lejla Batina, Stjepan Picek |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2022 | Deep Neural Networks Aiding Cryptanalysis: A Case Study of the Speck Distinguisher
Nicoleta-Norica Bacuieti, Lejla Batina, Stjepan Picek |
ACNS | 2 |
| 2022 | SoK: Design Tools for Side-Channel-Aware ImplementationsabstractSide-channel attacks that leak sensitive information through a computing device's interaction with its physical environment have proven to be a severe threat to devices' security, particularly when adversaries have unfettered physical access to the device. Traditional approaches for leakage detection measure the physical properties of the device. Hence, they cannot be used during the design process and fail to provide root cause analysis. An alternative approach that is gaining traction is to automate leakage detection by modeling the device. The demand to understand the scope, benefits, and limitations of the proposed tools intensifies with the increase in the number of proposals. In this SoK, we classify approaches to automated leakage detection based on the model's source of truth. We classify the existing tools on two main parameters: whether the model includes measurements from a concrete device and the abstraction level of the device specification used for constructing the model. We survey the proposed tools to determine the current knowledge level across the domain and identify open problems. In particular, we highlight the absence of evaluation methodologies and metrics that would compare proposals' effectiveness from across the domain. We believe that our results help practitioners who want to use automated leakage detection and researchers interested in advancing the knowledge and improving automated leakage detection. Ileana Buhan, Lejla Batina, Yuval Yarom, Patrick Schaumont |
AsiaCCS | 2 |
| 2022 | Fake It Till You Make It: Data Augmentation Using Generative Adversarial Networks for All the Crypto You Need on Small Devices
Naila Mukhtar, Lejla Batina, Stjepan Picek, Yinan Kong |
CT-RSA | 2 |
| 2022 | Playing With Blocks: Toward Re-Usable Deep Learning Models for Side-Channel Profiled AttacksabstractThis paper introduces a deep learning modular network for side-channel analysis. Our approach features a deep learning architecture with the capability to exchange parts (modules) with other neural networks. We aim to introduce reusable trained modules into side-channel analysis instead of building architectures from scratch for each evaluation, reducing the body of work. Our experiments demonstrate that our architecture feasibly assesses a side-channel evaluation, suggesting that learning transferability is possible using the architecture we propose in this paper. Servio Paguada, Lejla Batina, Ileana Buhan, Igor Armendariz |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Towards Human Dependency Elimination: AI Approach to SCA Robustness AssessmentabstractEvaluating the side-channel resistance in practice is a problematic and arduous process. Current certification schemes require to attack the device under test with an ever-growing number of techniques to validate its security. In addition, the success or failure of these techniques strongly depends on the individual implementing them due to the fallible and human intrinsic nature of several steps of this path. To alleviate this problem, we propose a battery of automated (Estimation of Distribution Algorihm(EDA)-based) attacks as a side-channel analysis robustness assessment of an embedded device. To prove our approach, we conduct realistic experiments on two different devices, creating a new dataset (AES_RA) as a part of our contribution. Furthermore, in this context of automation, we propose several novel improvements over current EDA-based attacks, as follows: 1) optimization of the search process by employing two proposed initialization techniques; 2) improvement and analysis of the generalization of the obtained templates; 3) acceleration of the search process by combining EDAs with Principal Component Analysis (PCA). The last contribution also serves as an alternative way of selecting optimal principal components automatically. We support our claims with experiments on AES_RA and a public dataset (ASCAD), showing how our, although fully automated, approach can straightforwardly provide state-of-the-art results. Unai Rioja, Lejla Batina, Igor Armendariz, Jose Luis Flores 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Rosita++: Automatic Higher-Order Leakage Elimination from Cryptographic CodeabstractSide-channel attacks are a major threat to the security of cryptographic implementations, particularly for small devices that are under the physical control of the adversary. While several strategies for protecting against side-channel attacks exist, these often fail in practice due to unintended interactions between values deep within the CPU. To detect and protect from side-channel attacks, several automated tools have recently been proposed; one of their common limitations is that they only support first-order leakage. Madura A. Shelton, Lukasz Chmielewski, Niels Samwel, Markus Wagner 0007, Lejla Batina, Yuval Yarom |
CCS | 5 |
| 2021 | Invited: Security Beyond Bulk Silicon: Opportunities and Challenges of Emerging DevicesabstractWhile traditional chips in bulk silicon technology are widely used for reliable and highly efficient systems, there are applications that call for devices in other technologies. On the one hand, novel device technologies need to be re-evaluated with respect to potential threats and attacks, and how these can be faced with existing and novel security solutions and methods. On the other hand, emerging device technologies bring opportunities for building the secure systems of the future. In this paper, we will give an overview of applications and security primitives developed in three important emerging device technologies, namely memristors, fully depleted silicon on insulator (FD-SOI) and flexible electronics. Lejla Batina, Rosario Cammarota, Nele Mentens, Ahmad-Reza Sadeghi, Martha Johanna Sepúlveda, Shaza Zeitouni |
DAC | 1 |
| 2021 | Screen Gleaning: A Screen Reading TEMPEST Attack on Mobile Devices Exploiting an Electromagnetic Side Channel
Zhuoran Liu 0001, Niels Samwel, Leo Weissbart, Zhengyu Zhao 0001, Dirk Lauret, Lejla Batina, Martha A. Larson |
NDSS | 6 |
| 2021 | Rosita: Towards Automatic Elimination of Power-Analysis Leakage in Ciphers
Madura A. Shelton, Niels Samwel, Lejla Batina, Francesco Regazzoni 0001, Markus Wagner 0007, Yuval Yarom |
NDSS | 3 |
| 2021 | Evaluating the ROCKY Countermeasure for Side-Channel LeakageabstractROCKY is a recently introduced countermeasure against fault attacks for authenticated encryption algorithms. It is based on the random rotation of the internal state. In this work, we evaluate the effectiveness of ROCKY as a countermeasure against side-channel attacks. We implement four different types of FPGA-oriented architectures of Xoodoo: an unprotected version and three different versions protected with ROCKY. Xoodoo is used as round function of Xoodyak, which is a scheme in the NIST lightweight cryptography standardization competition. For the experimental setup, the SAKURA-G target board with Spartan-6 FPGA is used. The evaluation of the results is done through test vector leakage assessment (TVLA). This is the first work looking into the side-channel security of the ROCKY countermeasure. Konstantina Miteloudi, Lukasz Chmielewski, Lejla Batina, Nele Mentens |
VLSI-SoC | 3 |
| 2021 | Toward practical autoencoder-based side-channel analysis evaluationsabstractIn the field of side-channel analysis, profiled attacks are one of the most powerful types of attacks. Nevertheless, major issues with profiled attacks are in sensitivity to noise and the high-dimensional nature of the signals used for training, generating a less efficient classifier to conduct the attack phase. Consequently, evaluating the security of cryptographic implementation in hardware devices like IoT becomes more complex as side-channel analysis evaluation easily falls into false-positive results. This paper assesses the efficacy of applying a feature reduction process to deal with high-dimensional signals. We propose a practical procedure to conduct feature reduction using autoencoders for profiled side-channel leakage evaluations. Two autoencoder architectures are compared while performing feature reduction showing that our proposed architecture keeps most of the relevant information. Our proposal is tested on the ASCAD random key database with a high desynchronization value and produced results that outperform other state-of-the-art techniques. The guessing entropy value converges to 1 after around 500 leakage traces. Servio Paguada, Lejla Batina, Igor Armendariz |
Comput. Networks | 2 |
| 2021 | Auto-tune POIs: Estimation of distribution algorithms for efficient side-channel analysisabstract\n Contains fulltext :\n 237439.pdf (Publisher’s version ) (Open Access)\n Unai Rioja, Lejla Batina, Jose Luis Flores 0001, Igor Armendariz |
Comput. Networks | 2 |
| 2021 | The Uncertainty of Side-channel Analysis: A Way to Leverage from HeuristicsabstractPerforming a comprehensive side-channel analysis evaluation of small embedded devices is a process known for its variability and complexity. In real-world experimental setups, the results are largely influenced by a huge amount of parameters, some of which are not easily adjusted without trial and error and are heavily relying on the experience of professional security analysts. In this article, we advocate the usage of an existing statistical methodology called Six Sigma (6 ) for side-channel analysis optimization. This well-known methodology is commonly used in other industrial fields, such as production and quality engineering, to reduce the variability of industrial processes. We propose a customized Six Sigma methodology, which allows even a less-experienced security analysis to select optimal values for the different variables that are critical for the side-channel analysis procedure. Moreover, we show how our methodology helps in improving different phases in the side-channel analysis process. Unai Rioja, Servio Paguada, Lejla Batina, Igor Armendariz |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2020 | Breaking a fully Balanced ASIC Coprocessor Implementing Complete Addition Formulas on Weierstrass Elliptic CurvesabstractIn this paper we report on the results of selected horizontal SCA attacks against two open-source designs that implement hardware accelerators for elliptic curve cryptography. Both designs use the complete addition formula to make the point addition and point doubling operations indistinguishable. One of the designs uses in addition means to randomize the operation sequence as a countermeasure. We used the comparison to the mean and an automated SPA to attack both designs. Despite all these countermeasures, we were able to extract the keys processed with a correctness of 100%. Ievgen Kabin, Zoya Dyka, Dan Klann, Nele Mentens, Lejla Batina, Peter Langendörfer |
DSD | 5 |
| 2020 | Friet: An Authenticated Encryption Scheme with Built-in Fault Detection
Thierry Simon, Lejla Batina, Joan Daemen, Vincent Grosso, Pedro Maat Costa Massolino, Kostas Papagiannopoulos, Francesco Regazzoni 0001, Niels Samwel |
EUROCRYPT (1) | 2 |
| 2019 | Location, Location, Location: Revisiting Modeling and Exploitation for Location-Based Side Channel Leakages
Christos Andrikos, Lejla Batina, Lukasz Chmielewski, Liran Lerman, Vasilios Mavroudis, Kostas Papagiannopoulos, Guilherme Perin, Georgios Rassias, Alberto Sonnino |
ASIACRYPT (3) | 2 |
| 2019 | Poster: Recovering the Input of Neural Networks via Single Shot Side-channel AttacksabstractThe interplay between machine learning and security is becoming more prominent. New applications using machine learning also bring new security risks. Here, we show it is possible to reverse-engineer the inputs to a neural network with only a single-shot side-channel measurement assuming the attacker knows the neural network architecture being used. Lejla Batina, Shivam Bhasin, Dirmanto Jap, Stjepan Picek |
CCS | 1 |
| 2019 | In Hardware We Trust: Gains and Pains of Hardware-assisted SecurityabstractData processing and communication in almost all electronic systems are based on Central Processing Units (CPUs). In order to guarantee confidentiality and integrity of the software running on a CPU, hardware-assisted security architectures are used. However, both the threat model and the non-functional platform requirements, i.e. performance and energy budget, differ when we go from high-end desktop computers and servers to low-end embedded devices that populate the internet of things (IoT). For high-end platforms, a relatively large energy budget is available to protect software against attacks. However, measures to optimize performance give rise to microarchitectural side-channel attacks. IoT devices, in contrast, are constrained in terms of energy consumption and do not incorporate the performance enhancements found in high-end CPUs. Hence, they are less likely to be susceptible to microarchitectural attacks, but give rise to physical attacks, exploiting, e.g., leakage in power consumption or through fault injection. Whereas previous work mostly concentrates on a specific architecture, this paper covers the whole spectrum of computing systems, comparing the corresponding hardware architectures, and most relevant threats. Lejla Batina, Patrick Jauernig, Nele Mentens, Ahmad-Reza Sadeghi, Emmanuel Stapf |
DAC | 1 |
| 2019 | CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel
Lejla Batina, Shivam Bhasin, Dirmanto Jap, Stjepan Picek |
USENIX Security Symposium | 1 |
| 2019 | Introduction to the Special Issue on Cryptographic Engineering for Internet of Things: Security Foundations, Lightweight Solutions, and Attacksabstract\n Contains fulltext :\n 204495.pdf (Publisher’s version ) (Open Access)\n Lejla Batina, Sherman S. M. Chow, Gerhard P. Hancke 0002, Zhe Liu 0001 |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2019 | A Systematic Evaluation of Profiling Through Focused Feature SelectionabstractProfiled side-channel attacks consist of several steps one needs to take. An important, but sometimes ignored, step is a selection of the points of interest (features) within side-channel measurement traces. A large majority of the related works start the analyses with an assumption that the features are preselected. Contrary to this assumption, here, we concentrate on the feature selection step. We investigate how advanced feature selection techniques stemming from the machine learning domain can be used to improve the attack efficiency. To this end, we provide a systematic evaluation of the methods of interest. The experiments are performed on several real-world data sets containing software and hardware implementations of AES, including the random delay countermeasure. Our results show that wrapper and hybrid feature selection methods perform extremely well over a wide range of test scenarios and a number of features selected. We emphasize L1 regularization (wrapper approach) and linear support vector machine (SVM) with recursive feature elimination used after chi-square filter (Hybrid approach) that performs well in both accuracy and guessing entropy. Finally, we show that the use of appropriate feature selection techniques is more important for an attack on the high-noise data sets, including those with countermeasures, than on the low-noise ones. Stjepan Picek, Annelie Heuser, Alan Jovic, Lejla Batina |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2018 | Breaking Ed25519 in WolfSSL
Niels Samwel, Lejla Batina, Guido Bertoni, Joan Daemen, Ruggero Susella |
CT-RSA | 2 |
| 2018 | Design of a Fully Balanced ASIC Coprocessor Implementing Complete Addition Formulas on Weierstrass Elliptic CurvesabstractThis paper discusses the first design of an ASIC coprocessor for Elliptic Curve Cryptography (ECC) using the complete addition law of Renes et al. The main reason for using the complete addition law is the reduced vulnerability to side-channel analysis (SCA) attacks, since point addition and point doubling can be performed with the same addition formulas. Further, all inputs are valid, so there is no need for conditional statements handling special cases such as the point at infinity. The proposed hardware architecture is optimized for area efficiency, targeting applications such as smart cards and RFID tags. A bottom-up design approach is used, minimizing the total implementation area by optimizations in each abstraction layer. The design implements a full-word Montgomery Multiplier ALU (MMALU) with built-in adder functionality. Additionally, an exploration is done on the design parameters of the MMALU and the scheduling of the modular operations in order to minimize the size of the register file. For point multiplication, a Montgomery ladder is implemented with the option of randomizing the execution order of the point operations as a countermeasure against SCA attacks. The post-synthesis implementation results are generated using the open source NANGATE45 library. Niels Pirotte, Jo Vliegen, Lejla Batina, Nele Mentens |
DSD | 3 |
| 2018 | Genetic Algorithm-Based Electromagnetic Fault InjectionabstractElectromagnetic fault injection (EMFI) is a powerful active attack, requiring minimal modifications of the device under attack while having excellent penetration capabilities. The number of possible parameter combinations when characterizing an attack is usually huge, rendering exhaustive search impossible. In this work we present a novel evolutionary algorithm for optimizing the parameters for EM fault injection, which out-performs previous search methods for EMFI. The cryptographic device under attack is treated as a black box, with only a few very general assumptions on its inner workings. We test our evolutionary algorithm by attacking SHA-3 where we are able to obtain 40 times more faulty measurements and 20 times more distinct fault measurements than the random search. When coupled with the algebraic fault attack, we get 25% more exploitable faults per individual measurement. Antun Maldini, Niels Samwel, Stjepan Picek, Lejla Batina |
FDTC | 4 |
| 2017 | Area-optimized montgomery multiplication on IGLOO 2 FPGAsabstractThis paper presents the first area-optimized Montgomery modular multiplication module on low-power reconfigurable IGLOO® 2 FPGAs, from Microsemi. In order to obtain a good response time with few resources, the FPGA pipelined Math blocks and the embedded memory blocks are fully leveraged. As a result, 256-bit modular multiplications can be done in 2.33 μs, at a cost of 505 LUT4 cells, 257 Flip Flops, 1 Math block and 1 64×18 RAM block. If more area resources are considered, a modular multiplication can be performed in 1.25 μ8 at a cost of 680 LUT4s, 341 Flip Flops, 2 Math blocks and 2 64×18 RAM blocks. This work is the first fundamental step towards area-efficient public-key cryptography on the Microsemi IGLOO® 2 FPGAs. Pedro Maat Costa Massolino, Lejla Batina, Ricardo Chaves, Nele Mentens |
FPL | 2 |
| 2016 | SPARTA: A scheduling policy for thwarting differential power analysis attacksabstractEmbedded systems (ESs) have been widely used in various application domains. It is very important to design ESs that guarantee functional correctness of the system under strict timing constraints. Such systems are known as the real-time embedded systems (RTESs). More recently, RTESs started to be utilized in safety and reliability critical areas, which made the overlooked security issues, especially confidentiality of the communication, a serious problem. Differential power analysis attacks (DPAs) pose serious threats to confidentiality protection mechanisms, i.e., implementations of cryptographic algorithms, on embedded platforms. In this work, we present a scheduling policy, SPARTA, that thwarts DPAs. Theoretical guarantees and preliminary experimental results are presented to demonstrate the efficiency of the SPARTA scheduler. Petru Eles, Zebo Peng, Sudipta Chattopadhyay 0001, Lejla Batina |
ASP-DAC | 5 |
| 2016 | \mu Kummer: Efficient Hyperelliptic Signatures and Key Exchange on Microcontrollers
Joost Renes, Peter Schwabe, Benjamin Smith 0003, Lejla Batina |
CHES | 4 |
| 2016 | Complete Addition Formulas for Prime Order Elliptic Curves
Joost Renes, Craig Costello, Lejla Batina |
EUROCRYPT (1) | 3 |
| 2015 | Evolutionary Methods for the Construction of Cryptographic Boolean Functions
Stjepan Picek, Domagoj Jakobovic, Julian Francis Miller, Elena Marchiori, Lejla Batina |
EuroGP | 5 |
| 2015 | Correlation Immunity of Boolean Functions: An Evolutionary Algorithms PerspectiveabstractBoolean functions are essential in many stream ciphers. When used in combiner generators, they need to have sufficiently high values of correlation immunity, alongside other properties. In addition, correlation immune functions with small Hamming weight reduce the cost of masking countermeasures against side-channel attacks. Various papers have examined the applicability of evolutionary algorithms for evolving cryptographic Boolean functions. However, even when authors considered correlation immunity, it was not given the highest priority. Here, we examine the effectiveness of three different EAs, namely, Genetic Algorithms, Genetic Programming (GP) and Cartesian GP for evolving correlation immune Boolean functions. Besides the properties of balancedness and correlation immunity, we consider several other relevant cryptographic properties while maintaining the optimal trade-offs among them. We show that evolving correlation immune Boolean functions is an even harder objective than maximizing nonlinearity. Stjepan Picek, Claude Carlet, Domagoj Jakobovic, Julian Francis Miller, Lejla Batina |
GECCO | 5 |
| 2015 | Improving DPA resistance of S-boxes: How far can we go?abstractSide-channel analysis (SCA) is an important issue for numerous embedded cryptographic devices that carry out secure transactions on a daily basis. Consequently, it is of utmost importance to deploy efficient countermeasures. In this context, we investigate the intrinsic side-channel resistance of lightweight cryptographic S-boxes. We propose improved versions of S-boxes that offer increased power analysis resistance, whilst remaining secure against linear and differential cryptanalyses. To evaluate the side-channel resistance, we work under the Confusion Coefficient model [1] and employ heuristic techniques to produce those improved S-boxes. We evaluate the proposed components in software (AVR microprocessors) and hardware (SASEBO FPGA). Our conclusions show that the model and our approach are heavily platform-dependent and that different principles hold for software and hardware implementations. Baris Ege, Kostas Papagiannopoulos, Lejla Batina, Stjepan Picek |
ISCAS | 3 |
| 2015 | Challenges in designing trustworthy cryptographic co-processorsabstractSecurity is becoming ubiquitous in our society. However, the vulnerability of electronic devices that implement the needed cryptographic primitives has become a major issue. This paper starts by presenting a comprehensive overview of the existing attacks to cryptography implementations. Thereafter, the state-of-the-art on some of the most critical aspects of designing cryptographic co-processors are presented. This analysis starts by considering the design of asymmetrical and symmetrical cryptographic primitives, followed by the discussion on the design and online testing of True Random Number Generation. To conclude, techniques for the detection of Hardware Trojans are also discussed. Ricardo Chaves, Giorgio Di Natale, Lejla Batina, Shivam Bhasin, Baris Ege, Apostolos P. Fournaris, Nele Mentens, Stjepan Picek, Francesco Regazzoni 0001, Vladimir Rozic, Nicolas Sklavos 0001, Bohan Yang 0001 |
ISCAS | 3 |
| 2015 | Near Collision Side Channel Attacks
Baris Ege, Thomas Eisenbarth 0001, Lejla Batina |
SAC | 3 |
| 2014 | Clock Glitch Attacks in the Presence of HeatingabstractFault attacks have been widely studied in the past but most of the literature describes only individual fault-injection techniques such as power/clock glitches, EM pulses, optical inductions, or heating/cooling. In this work, we investigate combined fault attacks by performing clock-glitch attacks under the impact of heating. We performed practical experiments on an 8-bit AVR microcontroller which resulted in the following findings. First, we identified that the success rate of glitch attacks performed at an ambient temperature of 100°C is higher than under room temperature. We were able to induce more faults and significantly increase the time frame when the device is susceptible to glitches which makes fault attacks easier to perform in practice. Second, and independently of the ambient temperature, we demonstrate that glitches cause individual instructions to repeat, we are able to add new random instructions, and we identified that opcode gets modified such that address registers of individual instructions get changed. Beside these new results, this is the first work that reports results of combined glitch and thermo attacks. Thomas Korak, Michael Hutter, Baris Ege, Lejla Batina |
FDTC | 4 |
| 2014 | Evolving DPA-Resistant Boolean Functions
Stjepan Picek, Lejla Batina, Domagoj Jakobovic |
PPSN | 2 |
| 2014 | Combining Evolutionary Computation and Algebraic Constructions to Find Cryptography-Relevant Boolean Functions
Stjepan Picek, Elena Marchiori, Lejla Batina, Domagoj Jakobovic |
PPSN | 3 |
| 2014 | S-box, SET, Match: A Toolbox for S-box Analysis
Stjepan Picek, Lejla Batina, Domagoj Jakobovic, Baris Ege, Marin Golub |
WISTP | 2 |
| 2013 | Glitch It If You Can: Parameter Search Strategies for Successful Fault Injection
Rafael Boix Carpi, Stjepan Picek, Lejla Batina, Federico Menarini, Domagoj Jakobovic, Marin Golub |
CARDIS | 3 |
| 2013 | Security Analysis of Industrial Test Compression SchemesabstractTest compression is widely used for reducing test time and cost of a very large scale integration circuit. It is also claimed to provide security against scan-based side-channel attacks. This paper pursues the legitimacy of this claim and presents scan attack vulnerabilities of test compression schemes used in commercial electronic design automation tools. A publicly available advanced encryption standard design is used and test compression structures provided by Synopsys, Cadence, and Mentor Graphics design for testability tools are inserted into the design. Experimental results of the differential scan attacks employed in this paper suggest that tools using X-masking and X-tolerance are vulnerable and leak information about the secret key. Differential scan attacks on these schemes have been demonstrated to have a best case success rate of 94.22% and 74.94%, respectively, for a random scan design. On the other hand, time compaction seems to be the strongest choice with the best case success rate of 3.55%. In addition, similar attacks are also performed on existing scan attack countermeasures proposed in the literature, thus experimentally evaluating their practical security. Finally, a suitable countermeasure is proposed and compared to the previously proposed countermeasures. Amitabh Das, Baris Ege, Santosh Ghosh, Lejla Batina, Ingrid Verbauwhede |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2012 | Power Analysis of Atmel CryptoMemory - Recovering Keys from Secure EEPROMs
Josep Balasch, Benedikt Gierlichs, Roel Verdult, Lejla Batina, Ingrid Verbauwhede |
CT-RSA | 4 |
| 2012 | Getting More from PCA: First Results of Using Principal Component Analysis for Extensive Power Analysis
Lejla Batina, Jip Hogenboom, Jasper G. J. van Woudenberg |
CT-RSA | 1 |
| 2012 | PCA, Eigenvector Localization and Clustering for Side-Channel Attacks on Cryptographic Hardware Devices
Dimitrios Mavroeidis, Lejla Batina, Twan van Laarhoven, Elena Marchiori |
ECML/PKDD (1) | 2 |
| 2012 | Extending ECC-based RFID authentication protocols to privacy-preserving multi-party grouping proofs
Lejla Batina, Yong Ki Lee, Stefaan Seys, Dave Singelée, Ingrid Verbauwhede |
Pers. Ubiquitous Comput. | 1 |
| 2011 | RAM: Rapid Alignment Method
Ruben A. Muijrers, Jasper G. J. van Woudenberg, Lejla Batina |
CARDIS | 3 |
| 2011 | The communication and computation cost of wireless security: extended abstractabstract\n Contains fulltext :\n 92444.pdf (Publisher’s version ) (Open Access)\n Dave Singelée, Stefaan Seys, Lejla Batina, Ingrid Verbauwhede |
WISEC | 3 |
| 2011 | Design and design methods for unified multiplier and inverter and its application for HECC
Junfeng Fan, Lejla Batina, Ingrid Verbauwhede |
Integr. | 2 |
| 2011 | Mutual Information Analysis: a Comprehensive Study
Lejla Batina, Benedikt Gierlichs, Emmanuel Prouff, Matthieu Rivain, François-Xavier Standaert, Nicolas Veyrat-Charvillon |
J. Cryptol. | 1 |
| 2010 | Developing Efficient Blinded Attribute Certificates on Smart Cards via Pairings
Lejla Batina, Jaap-Henk Hoepman, Bart Jacobs 0001, Wojciech Mostowski, Pim Vullers |
CARDIS | 1 |
| 2010 | Revisiting Higher-Order DPA Attacks:
Benedikt Gierlichs, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
CT-RSA | 2 |
| 2010 | Power Variance Analysis breaks a masked ASIC implementation of AESabstractTo obtain a better trade-off between cost and security, practical DPA countermeasures are not likely to deploy full masking that uses one distinct mask bit for each signal. A common approach is to use the same mask on several instances of an algorithm. This paper proposes a novel power analysis method called Power Variance Analysis (PVA) to reveal the danger of such implementations. PVA uses the fact that the side-channel leakage of parallel circuits has a big variance when they are given the same but random inputs. This paper introduces the basic principle of PVA and a series of PVA experiments including a successful PVA attack against a prototype RSL-AES implemented on SASEBO-R. Yang Li 0001, Kazuo Sakiyama, Lejla Batina, Daisuke Nakatsu, Kazuo Ohta |
DATE | 3 |
| 2010 | Breaking Elliptic Curve Cryptosystems Using Reconfigurable HardwareabstractThis paper reports a new speed record for FPGAs in cracking Elliptic Curve Cryptosystems. We conduct a detailed analysis of different F2(m)multiplication approaches in this application. A novel architecture using optimized normal basis multipliers is proposed to solve the Certicom challenge ECC2K-130. We compare the FPGA performance against CPUs, GPUs, and the Sony PlayStation 3. Our implementations show low-cost FPGAs outperform even multicore desktop processors and graphics cards by a factor of 2. Junfeng Fan, Daniel V. Bailey, Lejla Batina, Tim Güneysu, Christof Paar, Ingrid Verbauwhede |
FPL | 3 |
| 2010 | Privacy-Preserving ECC-Based Grouping Proofs for RFID
Lejla Batina, Yong Ki Lee, Stefaan Seys, Dave Singelée, Ingrid Verbauwhede |
ISC | 1 |
| 2010 | Low-cost untraceable authentication protocols for RFIDabstractThe emergence of pervasive computing devices has raised several privacy issues. In this paper, we address the risk of tracking attacks in RFID networks. Our contribution is threefold: (1) We repair three revised EC-RAC protocols of Lee, Batina and Verbauwhede and show that two of the improved authentication protocols are wide-strong privacy-preserving and one wide-weak privacy-preserving; (2) We present the search protocol, a novel scheme which allows for privately querying a particular tag, and proof its security properties; and (3) We design a hardware architecture to demonstrate the implementation feasibility of our proposed solutions for a passive RFID tag. Due to the specific design of our authentication protocols, they can be realized with an area significantly smaller than other RFID schemes proposed in the literature, while still achieving the required security and privacy properties. Yong Ki Lee, Lejla Batina, Dave Singelée, Ingrid Verbauwhede |
WISEC | 2 |
| 2009 | Differential Cluster Analysis
Lejla Batina, Benedikt Gierlichs, Kerstin Lemke-Rust |
CHES | 1 |
| 2009 | FPGA-based testing strategy for cryptographic chips: A case study on Elliptic Curve Processor for RFID tagsabstractTesting of cryptographic chips or components has one extra dimension: physical security. The chip designers should improve the design if it leaks too much information through side-channels, such as timing, power consumption, electric-magnetic radiation, and so on. This requires an evaluation of the security level of the chip under different side-channel attacks before it is manufactured. This paper presents an FPGA-based testing strategy for cryptographic chips. Using a block-based architecture, a testing bus and a shadow FPGA, we are able to check information leakage of each block. We describe this strategy with an Elliptic Curve Cryptosystem (ECC) for RFID tags. Junfeng Fan, Miroslav Knezevic, Dusko Karaklajic, Roel Maes, Vladimir Rozic, Lejla Batina, Ingrid Verbauwhede |
IOLTS | 6 |
| 2009 | Modular Reduction without Precomputational PhaseabstractIn this paper we show how modular reduction for integers with Barrett and Montgomery algorithms can be implemented efficiently without using a precomputational phase. We propose four distinct sets of moduli for which this method is applicable. The proposed modifications of existing algorithms are very suitable for fast software and hardware implementations of some public-key cryptosystems and in particular of Elliptic Curve Cryptography. Additionally, our results show substantial improvement when a small number of reductions with a single modulus is performed. Miroslav Knezevic, Lejla Batina, Ingrid Verbauwhede |
ISCAS | 2 |
| 2008 | A Very Compact "Perfectly Masked" S-Box for AES
David Canright, Lejla Batina |
ACNS | 2 |
| 2008 | Low-cost implementations of NTRU for pervasive securityabstractNTRU is a public-key cryptosystem based on the shortest vector problem in a lattice which is an alternative to RSA and ECC. This work presents a compact and low power NTRU design that is suitable for pervasive security applications such as RFIDs and sensor nodes. We have designed two architectures, one is only capable of encryption and the other one performs both encryption and decryption. The strategy for the designs includes clock gating of registers, operand isolation and precomputation. This work is also the first one to present a complete NTRU design with encryption/decryption circuitry. Our encryption-only NTRU design has a gate-count of 2:8 kgates and dynamic power consumption of 1:72μW. Moreover, encryption-decryption NTRU design consumes about 6μW dynamic power and consists of 10:5 kgates. Ali Can Atici, Lejla Batina, Junfeng Fan, Ingrid Verbauwhede, Siddika Berna Örs Yalçin |
ASAP | 2 |
| 2008 | Mutual Information Analysis
Benedikt Gierlichs, Lejla Batina, Pim Tuyls, Bart Preneel |
CHES | 2 |
| 2008 | FPGA Design for Algebraic Tori-Based Public-Key CryptographyabstractAlgebraic torus-based cryptosystems are an alternative for Public-Key Cryptography (PKC). It maintains the security of a larger group while the actual computations are performed in a subgroup. Compared with RSA for the same security level, it allows faster exponentiation and much shorter bandwidth for the transmitted data. In this work we implement a torus-based cryptosystem, the so-called CEILIDH, on a multicore platform with an FPGA. This platform consists of a Xilinx MicroBlaze core and a multicore coprocessor. The platform supports CEILIDH, RSA and ECC over prime fields. The results show that one 170-bit torus T6exponentiation requires 20 ms, which is 5 times faster than 1024-bit RSA implementation on the same platform. Junfeng Fan, Lejla Batina, Kazuo Sakiyama, Ingrid Verbauwhede |
DATE | 2 |
| 2008 | Comparative Evaluation of Rank Correlation Based DPA on an AES Prototype Chip
Lejla Batina, Benedikt Gierlichs, Kerstin Lemke-Rust |
ISC | 1 |
| 2008 | Elliptic-Curve-Based Security Processor for RFIDabstractRFID (Radio Frequency IDentification) tags need to include security functions, yet at the same time their resources are extremely limited. Moreover, to provide privacy, authentication and protection against tracking of RFID tags without loosing the system scalability, a public-key based approach is inevitable, which is shown by M. Burmester et al. In this paper, we present an architecture of a state-of-the-art processor for RFID tags with an Elliptic Curve (EC) processor over GF(2^163). It shows the plausibility of meeting both security and efficiency requirements even in a passive RFID tag. The proposed processor is able to perform EC scalar multiplications as well as general modular arithmetic (additions and multiplications) which are needed for the cryptographic protocols. As we work with large numbers, the register file is the most critical component in the architecture. By combining several techniques, we are able to reduce the number of registers from 9 to 6 resulting in EC processor of 10.1K gates. To obtain an efficient modulo arithmetic, we introduce a redundant modular operation. Moreover the proposed architecture can support multiple cryptographic protocols. The synthesis results with a 0.13 um CMOS technology show that the gate area of the most compact version is 12.5K gates. Yong Ki Lee, Kazuo Sakiyama, Lejla Batina, Ingrid Verbauwhede |
IEEE Trans. Computers | 3 |
| 2007 | Public-Key Cryptography on the Top of a NeedleabstractThis work describes the smallest known hardware implementation for Elliptic/Hyperelliptic Curve Cryptography (ECC/HECC). We propose two solutions for Public-key Cryptography (PKC), which are based on arithmetic on elliptic/hyperelliptic curves. One solution relies on ECC over binary fields 𝔽2𝓃where 𝓃 is a composite number of the form2𝑝(𝑝is a prime) and another on HECC on curves of genus 2 over 𝔽2𝑝. This implies the same arithmetic unit for both cases which supports arithmetic in a field 𝔽2𝑝. Our best solution that still results in a feasible performance features less than 5 kgates with an average power consumption smaller than 10μW. Lejla Batina, Nele Mentens, Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede |
ISCAS | 1 |
| 2007 | HW/SW co-design of a hyperelliptic curve cryptosystem using a microcode instruction set coprocessor
Alireza Hodjat, Lejla Batina, David Hwang 0001, Ingrid Verbauwhede |
Integr. | 2 |
| 2007 | High-performance Public-key Cryptoprocessor for Wireless Mobile Applications
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
Mob. Networks Appl. | 2 |
| 2007 | Multicore Curve-Based Cryptoprocessor with Reconfigurable Modular Arithmetic Logic Units over GF(2n)abstractThis paper presents a reconfigurable curve-based cryptoprocessor that accelerates scalar multiplication of Elliptic Curve Cryptography (ECC) and HyperElliptic Curve Cryptography (HECC) of genus 2 over GF(2n). By allocating a copies of processing cores that embed reconfigurable Modular Arithmetic Logic Units (MALUs) over GF(2n), the scalar multiplication of ECC/HECC can be accelerated by exploiting Instruction-Level Parallelism (ILP). The supported field size can be arbitrary up to a(n + 1) - 1. The superscaling feature is facilitated by defining a single instruction that can be used for all field operations and point/divisor operations. In addition, the cryptoprocessor is fully programmable and it can handle various curve parameters and arbitrary irreducible polynomials. The cost, performance, and security trade-offs are thoroughly discussed for different hardware configurations and software programs. The synthesis results with a 0.13-mum CMOS technology show that the proposed reconfigurable cryptoprocessor runs at 292 MHz, whereas the field sizes can be supported up to 587 bits. The compact and fastest configuration of our design is also synthesized with a fixed field size and irreducible polynomial. The results show that the scalar multiplication of ECC over GF(2163) and HECC over GF(283) can be performed in 29 and 63 mus, respectively. Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
IEEE Trans. Computers | 2 |
| 2006 | Superscalar Coprocessor for High-Speed Curve-Based Cryptography
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
CHES | 2 |
| 2006 | RFID-Tags for Anti-counterfeiting
Pim Tuyls, Lejla Batina |
CT-RSA | 2 |
| 2006 | Reconfigurable Architectures for Curve-Based Cryptography on Embedded Micro-ControllersabstractThis paper discusses architectures for embedded security to enable various cryptographic services at low cost. To realize the large bit-lengths and complex arithmetic on an 8-bit embedded micro-controller, several hardware acceleration options for elliptic and hyperelliptic curve cryptography (ECC and HECC) are studied and systematically evaluated. Two key factors influence the performance: one is the communication interface i.e. I/O transfers between processor and co-processor and the other one is the boundary between hardware and software. Our experiments are run on an 8051 and an AVR micro-controller with the crypto co-processors implemented on a FPGA Lejla Batina, Alireza Hodjat, David Hwang 0001, Kazuo Sakiyama, Ingrid Verbauwhede |
FPL | 1 |
| 2006 | Fpga-Oriented Secure Data Path Design: Implementation of a Public Key CoprocessorabstractThis paper introduces a secure FPGA implementation of a coprocessor for public key cryptography. It supports Elliptic Curve Cryptography (ECC) as well as the older RSA standard. When choosing adequate key lengths, RSA and ECC are assumed to be secure from an algorithmic point of view. On the other hand, an implementation of these algorithms should also guarantee side-channel security. This feature does not only cause an inevitable performance degradation, but also an area increase. We overcome these drawbacks by fitting the public key architecture and algorithms into a coprocessor that optimally exploites the dedicated features on a Spartan XC3S4000. Although this is a very low-cost FPGA, the performance results of our implementation meet the requirements of a broad range of high-end applications. Nele Mentens, Kazuo Sakiyama, Lejla Batina, Ingrid Verbauwhede, Bart Preneel |
FPL | 3 |
| 2006 | Flexible hardware architectures for curve-based cryptographyabstractThis paper compares implementations of elliptic and hyperelliptic curve cryptography (ECC and HECC) on an FPGA platform. We use the same low-level blocks to implement the basic operations and we choose the bit-lengths so that both systems have equal security levels. The results are in favor of HECC. Our HECC implementation is slightly larger than ECC, but at the same time around 35% faster Lejla Batina, Nele Mentens, Bart Preneel, Ingrid Verbauwhede |
ISCAS | 1 |
| 2005 | Side-channel aware design: Algorithms and Architectures for Elliptic Curve Cryptography over GF(2n)abstractThis paper proposes efficient algorithms for Elliptic Curve Cryptography (ECC). As an example a compact and efficient FPGA architecture for ECC over finite fields of even characteristic is presented. The implementation is balanced in order to increase the security w.r.t. simple side-channel attacks. Multiplication in GF(2 n ), Hardware implementation, Systolic array architecture, Elliptic Curve Cryptography (ECC), Montgomery method for point multiplication © 2005 IEEE. Lejla Batina, Nele Mentens, Bart Preneel, Ingrid Verbauwhede |
ASAP | 1 |
| 2005 | Hardware/Software Co-design for Hyperelliptic Curve Cryptography (HECC) on the 8051µP
Lejla Batina, David Hwang 0001, Alireza Hodjat, Bart Preneel, Ingrid Verbauwhede |
CHES | 1 |
| 2005 | A Systematic Evaluation of Compact Hardware Implementations for the Rijndael S-Box
Nele Mentens, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
CT-RSA | 2 |
| 2005 | Side-Channel Issues for Designing Secure Hardware ImplementationsabstractSelecting a strong cryptographic algorithm makes no sense if the information leaks out of the device through side-channels. Sensitive information, such as secret keys, can be obtained by observing the power consumption, the electromagnetic radiation, etc. This class of attacks is called side-channel attacks. Another type of attacks, namely fault attacks, reveal secret information by inserting faults into the device. Because both side-channel attacks and fault attacks are based on weaknesses in the implementation, they both belong to the category of implementation attacks. This work gives an overview of the state-of-the-art in implementation attacks, reviews the origin of this problem at the CMOS circuit level and discusses countermeasures. Lejla Batina, Nele Mentens, Ingrid Verbauwhede |
IOLTS | 1 |
| 2004 | Flexible Hardware Design for RSA and Elliptic Curve Cryptosystems
Lejla Batina, Geeke Bruin-Muurling, Siddika Berna Örs Yalçin |
CT-RSA | 1 |
| 2003 | Hardware Implementation of an Elliptic Curve Processor over GF(p)abstractWe describe a hardware implementation of an arithmetic processor which is efficient for bit-lengths suitable for both commonly used types of public key cryptography (PKC), i.e., elliptic curve (EC) and RSA cryptosystems. Montgomery modular multiplication in a systolic array architecture is used for modular multiplication. The processor consists of special operational blocks for Montgomery modular multiplication, modular addition/subtraction, EC point doubling/addition, modular multiplicative inversion, EC point multiplier, projective to affine coordinates conversion and Montgomery to normal representation conversion. Siddika Berna Örs Yalçin, Lejla Batina, Bart Preneel, Joos Vandewalle |
ASAP | 2 |
| 2003 | Hardware architectures for public key cryptography
Lejla Batina, Siddika Berna Örs Yalçin, Bart Preneel, Joos Vandewalle |
Integr. | 1 |
| 2002 | Montgomery in Practice: How to Do It More Efficiently in Hardware
Lejla Batina, Geeke Muurling |
CT-RSA | 1 |
| 2001 | Another Way of Doing RSA Cryptography in Hardware
Lejla Batina, Geeke Muurling |
IMACC | 1 |
| 2001 | Efficient Implementation of Elliptic Curve Cryptosystems on an ARM7 with Hardware Accelerator
Sheng-Bo Xu, Lejla Batina |
ISC | 2 |