EDBT 2026 Demo / reviewers in the wild / expert
Sylvain Guilley
dblp:86/2396
· DBLP profile ↗
137ranked-venue papers
13as first author
47since 2021 · last 2026
0000-0002-5044-3534ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 62 · 5 first-author · 25 since 2021Security and privacy · 57 · 8 first-author · 13 since 2021Software engineering, systems software and programming languages · 16 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 4 since 2021Theory of computation · 5 · 3 since 2021Artificial intelligence and machine learning · 2Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AttestaChain: A Chiplet-aware attestation system based on Blockchain and Zero-Trust ArchitectureabstractAs digital systems become more decentralized and interconnected, the zero-trust principle—"never trust, always verify"—demands continuous, hardware-backed attestation of device integrity. Traditional certification frameworks such as Common Criteria, which validate devices only once before deployment, are no longer sufficient to meet evolving security and compliance challenges. To address this gap, we propose AttestaChain, a novel attestation framework that leverages both cryptographic measurements and the physical characteristics of the Root of Trust (RoT) through Physical IP attestation, ensuring device trustworthiness at any point in its lifecycle. Our solution aligns with international regulations such as the EU Cyber Resilience Act (CRA), the US Executive Order 14028, and China’s Cybersecurity Law, by enabling continuous and verifiable assurance. Beyond extending certification into runtime, AttestaChain allows certification and validation results to be queried on demand, effectively reproducing acceptance tests throughout the product’s lifetime. Designed for flexibility, it supports both SoC architectures and emerging SiP platforms built from chiplets operating in zero-trust environments. Finally, we analyze the runtime complexity of AttestaChain and demonstrate its scalability, particularly in chiplet-based designs, through experimental evaluation. Together, these contributions establish AttestaChain as a robust and forward-compatible solution for trustworthy hardware verification in decentralized and regulated ecosystems. Abdellah Kaci, Sylvain Guilley |
CCNC | 2 |
| 2026 | HEED: A Highly Efficient Electromagnetic Fault Detection SchemeabstractElectroMagnetic Fault Injection (EMFI) is a hard-ware attack technique that uses EM perturbations to deliberately induce faults in integrated circuits for attack purposes. In this paper, we propose to use a Digital Sensor (DS) based on a Time-to-Digital Converter (TDC) to detect such EMFI attacks. A TDC uses a delay line to sense variations in a device’s core voltage at the rate of its clock. Thus, it can detect EMFI attacks involving voltage and clock signal perturbations. The sensor output is expressed as a digital index, FN, which captures EMFI-induced delay variations. We evaluated the sensor’s effectiveness on real silicon using an FPGA test vehicle through extensive experiments. The results demonstrate that a single sensor can efficiently detect 100% of faults injected into an AES crypto-accelerator while ensuring wide circuit area coverage, with a highly negligible 1% false alarms rate thanks to the proposed differential fault detection methodology. To ascertain the sensor’s robustness, experiments were conducted under various thermal and noise conditions. Beyond fault detection, the sensor provides insight into the EMFI mechanism. The observed behavior is consistent with a timing constraint violation fault model. Roukoz Nabhan, Mohammad Ebrahimabadi, Jean-Luc Danger, Jean-Max Dutertre, Sylvain Guilley, Naghmeh Karimi, Raphael Viera 0001, Iyad Zaarour |
DATE | 5 |
| 2026 | Glitch Propagation through Flip-Flops Endangers Masking Schemes: Why Time Separation Is RequiredabstractGlitches are hardware-level hazards that are capable of compromising secure implementations. Even dominant protections against side-channel attacks must demonstrate immunity in the potential presence of glitches. In this paper, we study two hardware masking schemes rationales, namely Ishai-Shai-Wagner (ISW) and its Enhanced version (E-ISW), as well as Domain-Oriented Masking (DOM). While other glitch-aware masking schemes have been proposed, our focus is specifically on the differences between E-ISW and DOM. Those two styles rely respectively on combinational and on sequential separation of shares. It is known that sequential separation, realized through pipelining stages, does impact the latency of the hardware masking scheme. Additionally, in this paper, we show another drawback: pipelining does not provide full independence between manipulated shares. Indeed, we show that pipelining elements (DFFs in practice) can propagate upstream activity downstream. This results in first-order leakage in real-world systems, especially when parasitic effects are considered. In this respect, we show that DOM is leaking at first-order, and that this leakage increases with both the complexity of the netlist (in terms of number of DOM gadgets) and with the extent to which the operational environment can be worsened by an attacker (e.g., lowering the voltage to increase the leakage). These findings provide valuable insights for advancing secure hardware design. Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Sofiane Takarabt, Sylvain Guilley, Naghmeh Karimi |
DATE | 4 |
| 2026 | ROCKET: Runtime Operating-Condition Aware KEy Refreshing Technique for Resisting Side-Channel Analysis Attacks
Hasin Ishraq Reefat, Hossein Pourmehrani, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
VTS | 4 |
| 2026 | Assessment of Security Risks and Defenses in Chiplet Systems
Hasin Ishraq Reefat, Hossein Pourmehrani, Junie Um, Sylvain Guilley, Naghmeh Karimi |
VTS | 4 |
| 2026 | Constructing optimal linear codes for code-based masking schemes of higher-orders
Jihao Fan, Wei Cheng 0003, Yongbin Zhou, Sylvain Guilley |
Des. Codes Cryptogr. | 4 |
| 2025 | Multi-Sensor Data Fusion for Enhanced Detection of Laser Fault Injection Attacks in Cryptographic Hardware: Practical ResultsabstractThough considered secure the cryptographic hardware can be compromised by fault injection attack, especially laser illumination due to its precision in targeting specific areas and its fine temporal control. To address this threat, this paper presents a low-cost detection scheme that utilizes Time-to-Digital Converters (TDCs) to sense the IR drops induced by laser illumination. To achieve a high detection rate while minimizing false alarms, the proposed approach incorporates multiple sensors, with as few as two sensors demonstrated in the study. The effectiveness of the scheme is validated using a real laser setup to illuminate a targeted AES module implemented on an AMD/Xilinx Artix-7 FPGA. Mohammad Ebrahimabadi, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi |
DATE | 3 |
| 2025 | BISSEL: Built-In Self Security via Embedded Sensors for Reproducible Side-Channel Leakage Assessment
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ETS | 4 |
| 2025 | TIGER: TrIaGing KEy Refreshing Frequency via Digital Sensors
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Javad Bahrami, Hossein Pourmehrani, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
SECRYPT | 7 |
| 2025 | CBM-TI: Code-Based Masking against Glitches by Hybridization with Threshold ImplementationabstractCode-Based Masking (CBM) has been introduced to enhance high-order Boolean masking by increasing its resistance order via further decorrelating the coordinates of each symbol involved in the computation. Additionally, CBM enables cost amortization and fault detection. Notably, as demonstrated at CHES 2024, CBM facilitates the computation of provably masked operations under the Strong Non-Interference (SNI) security assumption with quasi-linear complexity. On the other hand, Threshold Implementation (TI) serves as an extension of Boolean masking, armoring it against combinational hazards. In this article, we show that merits of CBM and TI can be combined, paving the way to more secure hardware (high-order) masked implementations. We demonstrate CBM-TI, which is proven secure as well under SNI assumption and security when glitches worsen the leakage model.The security of CBM-TI is studied in a n-share setting, where n = 3 (minimal random splitting order required for TI). We analyzed CBM-TI in simulation and in real hardware (FPGA) to validate its security property. Leveraging high-order T-test leakage detection tool, we show that CBM-TI is endowed with higher-order security. Namely, TI leaks at order d = 3, whereas CBM-TI does not. We study several CBM-TI variants and show that the smallest leaking order of CBM-TI can be tuned to be as high as 7. This represents a significant progress over TI as each marginally improved order translates into exponentially more traces to attack the implementation. Hasin Ishraq Reefat, Hossein Pourmehrani, Wei Cheng 0003, Claude Carlet, Abderrahman Daif, Cédric Tavernier, Sylvain Guilley, Naghmeh Karimi |
VTS | 7 |
| 2025 | Statistical Analysis of Non-Profiling Higher-Order Distinguishers Against Inner Product MaskingabstractInner Product Masking (IPM) is one representative masking scheme, which captivates by so-called Security Order Amplification (SOA) property. It is commonly recognized that SOA holds under linear leakages. In this paper, we revisit SOA from a non-profiling attack perspective. Specifically, we conduct statistical analyses on three non-profiling distinguishers, including Pearson Coefficient Distinguisher (PCD), Spearman Coefficient Distinguisher (SCD) and Kruskal-Wallis Distinguisher (KWD). We find a fundamental connection between SCD and KWD such that SCD is a more generic distinguisher which encompasses KWD. Theoretical explanations for why KWD outperforms SCD under non-linear leakages are provided. We also propose a new adjusted SCD and present its optimal form, which bridges the efficiency gap with KWD. Grounded on this, SOA is extensively assessed and the observations are two-fold. On the one hand, we confirm again the effectiveness of SOA under Hamming weight leakage through the statistical analysis of PCD. On the other hand, we show that SOA can not resist rank-based distinguishers even under linear leakages, which has never been revealed before (to the best of our knowledge). At last, we verify the theoretical findings through both simulated and real-world measurements. Our results demonstrate the advantage of rank-based distinguishers in uncovering non-linear relationships hidden in leakage, enriching the tool-set for non-profiling class of side-channel attacks. Remarkably, we provide an adversary perspective to investigate SOA, highlighting that the side-channel resistance promised by SOA is vulnerable even considering the ideal linear leakage models. Qianmei Wu, Wei Cheng 0003, Fan Zhang 0010, Sylvain Guilley |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Formal Security Proofs via Doeblin Coefficients: - Optimal Side-Channel Factorization from Noisy Leakage to Random Probing
Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul |
CRYPTO (6) | 3 |
| 2024 | Securing ISW Masking Scheme Against GlitchesabstractIshai-Sahai-Wagner (ISW) masking scheme has been proposed in literature to protect cryptographic circuitries against side-channel analysis attacks. Although provably secure from a theoretical standpoint, its hardware implementation may not be secure as such security proof holds true if the gates are only evaluated after all of their inputs are available, yet such requirement is not met in hardware as the gates are evaluated as soon as any single input of them is changed. This paper provides a repair for ISW to address its security concern and prevent the key recovery. Our method is based on inserting artificial delays and/or “refreshing” on some sensitive paths to ensure that the underlying combinational gates are evaluated in the order expected by the ISW rationale. We verify the security of our proposed structure by leakage detection. Our solution is called E-ISW standing for Enhanced-ISW. Sofiane Takarabt, Javad Bahrami, Mohammad Ebrahimabadi, Sylvain Guilley, Naghmeh Karimi |
DATE | 4 |
| 2024 | Quantum-resistant Transport Layer SecurityabstractThe reliance on asymmetric public key cryptography (PKC) and symmetric encryption for cyber-security in current telecommunication networks is threatened by the emergence of powerful quantum computing technology. This is due to the ability of quantum computers to efficiently solve problems such as factorization or discrete logarithms, which are the basis for classical PKC schemes. Thus, the assumption that communications networks are secure no longer holds true. Quantum Key Distribution (QKD) and post-quantum cryptography (PQC) are the first cyber-security technologies that allow communications to resist the attacks of a quantum computer. To achieve quantum-resistant communications, the aforementioned technologies need to be incorporated into a network security protocol such as Transport Layer Security (TLS). In this paper, we describe and implement two novel, hybrid solutions in which QKD and PQC are combined inside TLS for achieving quantum-resistant authenticated key exchange: Concatenation and Exclusively-OR (XOR). We present the results, in terms of complexity and security enhancement, of integrating state-of-the-art QKD and PQC technologies into a practical, industry-ready TLS implementation. Our findings demonstrate that the adoption of a PQC-only approach enhances the TLS handshake performance by approximately 9 % compared to classical methods. Furthermore, our hybrid PQC-QKD quantum-resistant TLS comes at a performance cost of approximately 117 % during the key establishment process. In return, we substantially augment the security of the handshake, paving the road for the development of future-proof quantum-resistant communication systems based on QKD and PQC. Carlos Rubio Garcia, Simon Rommel, Sofiane Takarabt, Juan Jose Vegas Olmos, Sylvain Guilley, Philippe Nguyen, Idelfonso Tafur Monroy |
Comput. Commun. | 5 |
| 2024 | Multi-modal Pre-silicon Evaluation of Hardware Masking StylesabstractAbstract Protecting sensitive logic functions in ASICs requires side-channel countermeasures. Many gate-level masking styles have been published, each with pros and cons. Some styles such as RSM, GLUT, and ISW are compact but can feature 1st-order leakage. Some other styles, such as TI, DOM, and HPC are secure at the 1st-order but incur significant overheads in terms of performance. Another requirement is that security shall be ensured even when the device is aged. Pre-silicon security evaluation is now a normatively approved method to characterize the expected resiliency against attacks ahead of time. However, in this regard, there is still a fragmentation in terms of leakage models, Points of Interest (PoI) selection, attack order, and distinguishers. Accordingly, in this paper we focus on such factors as they affect the success of side-channel analysis attacks and assess the resiliency of the state-of-the-art masking styles in various corners. Moreover, we investigate the impact of device aging as another factor and analyze its influence on the success of side-channel attacks targeting the state-of-the-art masking schemes. This pragmatic evaluation enables risk estimation in a complex PPA (Power, Performance, and Area) and security plane while also considering aging impacts into account. For instance, we explore the trade-off between low-cost secure styles attackable at 1st-order vs high-cost protection attackable only at 2nd-order. Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Wei Cheng 0003, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
J. Electron. Test. | 5 |
| 2024 | Statistical Higher-Order Correlation Attacks Against Code-Based MaskingabstractMasking is one of the most well-established methods to thwart side-channel attacks. Many masking schemes have been proposed in the literature, and code-based masking emerges and unifies several masking schemes in a coding-theoretic framework. In this work, we investigate the side-channel resistance of code-based masking from a non-profiling perspective by utilizing correlation-based side-channel attacks. We present a systematic evaluation of correlation attacks with various higher-order (centered) moments and then present the form of optimal correlation attacks. Interestingly, the Pearson correlation coefficient between the hypothetical leakage and the measured traces is connected to the signal-to-noise ratio in higher-order moments, and it turns out to be easy to evaluate rather than launch repeated attacks. We also identify some ineffective higher-order correlation attacks at certain orders when the device leaks under the Hamming weight leakage model. Our theoretical findings are verified through both simulated and real-world measurements. Wei Cheng 0003, Jingdian Ming, Sylvain Guilley, Jean-Luc Danger |
IEEE Trans. Computers | 3 |
| 2024 | DELFINES: Detecting Laser Fault Injection Attacks via Digital SensorsabstractLaser Fault Injection Attacks (LFIA) are a major concern in physical security of electronic circuits as they allow an attacker to inject a fault with a very high spatial accuracy. They are also often considered by information technology security evaluation facilities (ITSEFs) to deliver security certification, as Common Criteria, of embedded systems. Time or spatial redundancy can be foreseen as protection methods but they are costly and do not ensure immunity against multiple laser injections. The detection would be efficient if the detecting sensors meet enough density and sensitivity to cover the functional blocks being protected. Most sensors rely on analog and specific technology. In this article, we propose a method to detect LFIAs via a fully digital sensor based on a time to digital converter (TDC) and show its efficacy in detecting such faults in various conditions related to the current induced by the laser, the characteristics of the power grid network (PGN) of the circuit and the environmental variables (voltage, temperature). The simulation results obtained using a 45nm Nangate technology confirms the high efficiency of the proposed scheme in detecting LFIAs in a large range of such conditions. Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2024 | On the Resiliency of Protected Masked S-Boxes Against Template Attack in the Presence of Temperature and Aging MisalignmentsabstractProfiling side-channel analysis (SCA) attacks have received a lot of attention in the recent years. To perpetrate these attacks, the adversary creates a profile of a sensitive device at her disposal, and uses it to model a target device with a similar implementation to extract its key. Template attacks are recognized to be the most powerful profiling attacks when the measurement noise is Gaussian. To tackle SCA attacks, different countermeasures have been proposed in the literature, among which masking schemes have received the utmost attention. By adding randomness to the circuit, masking schemes prevent the adversary from relating the power consumption to the evaluated data, thus making the attack more difficult. In this article, we study the protection provided by several masking schemes against template attacks. More precisely, we investigate how the success of the template attack is changed when there is a misalignment between the target and profiling devices in terms of temperature and process variations. As another innovative analysis angle, we extensively study the impact of device aging on the template attack and demonstrate quantitatively how aging misalignments in side-channel traces, between the profiling and the target devices, do hinder the attack. The main objective of this study is to get accurate and numerous results allowing the designer to compare different implementations of masking and accordingly choose one which corresponds to the best compromise among complexity, security, and sensitivity to temperature and aging. We target the S-Box module of the unprotected PRESENT cipher along with its five masking variants including global lookup table (GLUT), rotating S-Box masking (referred to as RSM-LOG hereafter), RSM with read-only memory (RSM-ROM), Ishai-Sahai–Wagner masking (ISW), and threshold implementation (TI). The unprotected circuit gets impacted by such aging misalignments with$\approx 12.5$% increase in the number of traces needed to reach 80% success rate (SR) in the course of 20 weeks of aging at 105 °C. Such increase is 23.3%, 37.19%, and 38.24% for ISW, GLUT, and RSM-LOG, respectively. For RSM-ROM such increase is 193.37% for ten weeks of aging. Interestingly, TI is not much affected by aging in this regard. Md Toufiq Hasan Anik, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2023 | Aging-Induced Failure Prognosis via Digital SensorsabstractAggressive scaling continues to push technology into smaller feature sizes and results in more complex systems in a single chip. With such scaling, various robustness concerns have come into account among which the change of circuits' properties during their lifetime, so-called device aging, has received a lot of attention. Due to aging, the electrical behavior of transistors deviates from its original intended one resulting in degrading the chip's performance, and ultimately the chip fails to provide correct outputs. Thereby, prognosis of circuit performance degradation during the runtime, before the chip actually fails is highly crucial in increasing the reliability of chips. Accordingly in this paper, we develop a machine-learning based framework that, leveraging the outcome of embedded time-to-digital-convertors (so-called "digital sensors''), predicts aging-induced degradation. This information can be used to prevent chip failures via deploying Dynamic Voltage and Frequency Scaling (DVFS). Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ACM Great Lakes Symposium on VLSI | 4 |
| 2023 | Maximal Leakage of Masked Implementations Using Mrs. Gerber's Lemma for Min-EntropyabstractA common countermeasure against side-channel attacks on secret key cryptographic implementations is $d$ thorder masking, which splits each sensitive variable into $d + 1$ random shares. In this paper, maximal leakage bounds on the probability of success of any side-channel attack are derived for any masking order. Maximal leakage (Sibson's information of order infinity) is evaluated between the sensitive variable and the noisy leakage, and is related to the conditional "min-entropy" (Arimoto's entropy of order infinity) of the sensitive variable given the leakage. The latter conditional entropy is then lower-bounded in terms of the conditional entropies for each share using majorization inequalities. This yields a generalization of Mrs. Gerber's lemma for min-entropy in finite Abelian groups. Julien Béguinot, Yi Liu 0066, Olivier Rioul, Wei Cheng 0003, Sylvain Guilley |
ISIT | 5 |
| 2023 | Improved Alpha-Information Bounds for Higher-Order Masked Cryptographic ImplementationsabstractEmbedded cryptographic devices are usually protected against side-channel attacks by masking strategies. In this paper, the security of protected cryptographic implementations is evaluated for any masking order, using alpha-information measures. Universal upper bounds on the probability of success of any type of side-channel attack are derived. These also provide lower bounds on the minimum number of queries required to achieve a given success rate. An important issue, solved in this paper, is to remove the loss factor due to the masking field size. Yi Liu 0066, Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Loïc Masure, Olivier Rioul, François-Xavier Standaert |
ITW | 4 |
| 2023 | Special Session: Security Verification & Testing for SR-Latch TRNGsabstractSecure chips implement cryptographic algorithms and protocols to ensure self-protection (e.g., firmware authenticity) as well as user data protection (e.g., encrypted data storage). In turn, cryptography needs to defer to incorruptible sources of entropy to implement their functions according to their mandatory usage guidance. Typically, keys, nonces, initialization vectors, tweaks, etc. shall not be guessed by attackers. In practice, True Random Number Generators (TRNGs) are in charge of producing such sensitive elements.Fully aware of the central role of TRNGs in the proper implementation of security in chips, stakeholders have been formalizing the requirements recently. The methods to strengthen such requirements are manifold. In this paper, we discuss and apply three of them by targeting the Set-Reset Latch TRNG which is an alternative to Ring-Oscillator (RO) TRNGs as it provides faster throughputs. The first method concerns the confidence in the TRNG being random enough. It explores how the TRNG properties can be reliably predicted by simulation, compared to real silicon experiments. The second aspect dealt with in this paper is the assessment of the TRNG properties over time, i.e., considering the impact of aging in the TRNG properties. Such knowledge is important as secure chips are expected to be in service for a long period, and it would be detrimental to the service they render if the quality of the entropy they deliver would be declining over time. Eventually, the third aspect of this paper is the timely detection of unforeseen failures or malevolent attacks. The mitigation lies in leveraging "health tests" launched prior to using random numbers.This paper focuses on a particular type of TRNG that is not prone to biasing by attackers: it is the so-called Set-Reset Latch (SR-latch) TRNG and exploits a race condition in an arbitration gate. Such kind of TRNG is of great practical interest as an alternative design compared to the mainstream "Ring Oscillator" TRNG, and it is also very amenable to analyses by various sorts of simulations aiming at properly characterizing its security in various operational environments. Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
VTS | 4 |
| 2023 | Exploiting the microarchitectural leakage of prefetching activities for side-channel attacks
Chong Xiao, Ming Tang 0002, Sylvain Guilley |
J. Syst. Archit. | 3 |
| 2023 | (Adversarial) Electromagnetic Disturbance in the IndustryabstractFaults occur naturally and are responsible for reliability concerns. Faults are also an interesting tool for attackers to extract sensitive information from secure chips. In particular, non-invasive fault attacks have received a fair amount of attention. One easy way to perturb a chip without altering it is the so-called Electromagnetic Fault Injection (EMFI). Such attack has been studied in great depth, and nowadays, it is part and parcel of the state-of-the-art. Indeed, new capabilities have emerged where EM experimental benches are used to cryptanalyze chips. The progress of this “field” is fast, in terms ofreproducibility,accuracy, andnumber of use-cases. However, there is too little awareness about such advances. In this paper, we aim to expose the true harmfulness of EMFI (including reproducibility) to enable reasonable security quotations. We also analyze protections (at hardware/firmware/system levels) in light of their efficiency. We characterize the specificity of EM fault injection compared to other injection means (laser, glitch, probing). Arthur Beckers, Sylvain Guilley, Philippe Maurine, Colin O'Flynn, Stjepan Picek |
IEEE Trans. Computers | 2 |
| 2023 | Reverse-Engineering and Exploiting the Frontend Bus of Intel ProcessorabstractThe frontend of modern Intel processors will decode instructions into$\mu$ops and stream them to the backend by the frontend bus, which is shared between two logical cores to maximize utilization without sharing mechanism fully disclosed. Taking Haswell as an example, we reverse the bus from Decoded ICache to Instruction Decode Queue and the bus from Instruction Decode Queue to backend. We find that they are dynamically shared between two logical cores, which makes it possible for observable timing differences in one another through different instructions. Based on these differences, we propose the Synthetical bus covert channel for LSD-enabled architectures like Haswell and the DI bus covert channel for LSD-disabled architectures like Cometlake. We test our covert channels in physical machines and virtual machines. The bandwidth of Synthetical bus covert channel achieves 870 Kbps with 95.69% accuracy in physical machines and 145 Kbps with 92.83% accuracy in virtual machines. The bandwidth of DI bus covert channel reaches 1450 Kbps with 97.2% accuracy in physical machines and 70.33 Kbps with 92.3% accuracy in virtual machines. We further demonstrate a new Spectre variant. Finally, we propose two possible mitigations against our covert channels due to the limitations of existing protection strategies. Ming Tang 0002, Han Wang 0057, Sylvain Guilley |
IEEE Trans. Computers | 4 |
| 2022 | Leakage Power Analysis in Different S-Box Masking Protection SchemesabstractInternet-of- Things (IoT) devices are natural targets for side-channel attacks. Still, side-channel leakage can be com-plex: its modeling can be assisted by statistical tools. Projection of the leakage into an orthonormal basis allows to understand its structure, typically linear (1st-order leakage) or non-linear (sometimes referred to as glitches). In order to ensure cryptosystems protection, several masking methods have been published. Unfortunately, they follow different strategies; thus it is hard to compare them. Namely, ISW is constructive, GLUT is systematic, RSM is a low-entropy version of GLUT, RSM-ROM is a further optimization aiming at balancing the leakage further, and TI aims at avoiding, by design, the leakage arising from the glitches. In practice, no study has compared these styles on an equal basis. Accordingly, in this paper, we present a consistent methodology relying on a Walsh-Hadamard transform in this respect. We consider different masked implementations of substitution boxes of PRESENT algorithm, as this function is the most leaking in symmetric cryptography. We show that ISW is the most secure among the considered masking implementations. For sure, it takes strong advantage of the knowledge of the PRESENT substitution box equation. Tabulated masking schemes appear as providing a lesser amount of security compared to unprotected counterparts. The leakage is assessed over time, i.e., considering device aging which contributes to mitigate the leakage differently according to the masking style. Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
DATE | 4 |
| 2022 | Be My Guess: Guessing Entropy vs. Success Rate for Evaluating Side-Channel Attacks of Secure ChipsabstractIn a theoretical context of side-channel attacks, optimal bounds between success rate and guessing entropy are derived with a simple majorization (Schur-concavity) argument. They are further theoretically refined for different versions of the classical Hamming weight leakage model, in particular assuming a priori equiprobable secret keys and additive white Gaussian measurement noise. Closed-form expressions and numerical computation are given. A study of the impact of the choice of the substitution box with respect to side-channel resistance reveals that its nonlinearity tends to homogenize the expressivity of success rate and guessing entropy. The intriguing approximate relation$GE=1/SR$is observed in the case of 8-bit bytes and low noise. Julien Béguinot, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul |
DSD | 3 |
| 2022 | Quantifying the Speed-Up Offered by Genetic Algorithms during Fault Injection CartographiesabstractIn the context of Fault Injection Analyses, the determination of the correct set of physical perturbation parameters is critical. When searching for vulnerabilities against fault injections, it is then a necessity to carry out a cartography in order to establish which tuples of parameters allow to disturb the target successfully, in a reliable way. In practice, this task is often time consuming because of the large number of dimensions to consider, hence an exhaustive cartography is most of the time impossible.This paper analyses three different cartography strategies: Linear-Scan, Monte-Carlo, and Genetic Algorithm-based methods. We compare them in real Electro-Magnetic Fault Injection Analyses on an hardware device, distinguishing two different contexts, namely with few, and, at the opposite, with more Points of Interest. We show that Genetic Algorithms are always better for identifying Areas of Interest, and so correct injection parameters, which is crucial for characterizing vulnerabilities in security evaluation contexts. Idris Rais-Ali, Antoine Bouvet, Sylvain Guilley |
FDTC | 3 |
| 2022 | Attacking Masked Cryptographic Implementations: Information-Theoretic BoundsabstractMeasuring the information leakage is critical for evaluating the practical security of cryptographic devices against side-channel analysis. Information-theoretic measures can be used (along with Fano’s inequality) to derive upper bounds on the success rate of any possible attack in terms of the number of side-channel measurements. Equivalently, this gives lower bounds on the number of queries for a given success probability of attack. In this paper, we consider cryptographic implementations protected by (first-order) masking schemes, and derive several information-theoretic bounds on the efficiency of any (second-order) attack. The obtained bounds are generic in that they do not depend on a specific attack but only on the leakage and masking models, through the mutual information between side-channel measurements and the secret key. Numerical evaluations confirm that our bounds reflect the practical performance of optimal maximum likelihood attacks. Wei Cheng 0003, Yi Liu 0066, Sylvain Guilley, Olivier Rioul |
ISIT | 3 |
| 2022 | On the Practicality of Relying on Simulations in Different Abstraction Levels for Pre-silicon Side-Channel AnalysisabstractInternational audience Javad Bahrami, Mohammad Ebrahimabadi, Sofiane Takarabt, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
SECRYPT | 5 |
| 2022 | Side-channel Analysis and Countermeasure for Implementation of Lattice-based Signature
Kazuhide Fukushima, Hiroki Okada 0001, Sofiane Takarabt, Amina Korchi, Meziane Hamoud, Khaled Karray, Youssef Souissy, Sylvain Guilley |
SECRYPT | 8 |
| 2022 | Cross-PUF Attacks: Targeting FPGA Implementation of Arbiter-PUFs
Trevor Kroeger, Wei Cheng 0003, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
J. Electron. Test. | 4 |
| 2022 | Aging Effects on Template Attacks Launched on Dual-Rail Protected ChipsabstractProfiling side-channel attacks in which an adversary creates a “profile” of a sensitive device and uses such a profile to model a target device with similar implementation has received the lion’s share of attention in the recent years. In particular, template attacks are known to be the most powerful profiling side-channel attacks from an information theoretic point of view. When launching such an attack, the adversary first builds a model based on the leakage of the profiling (training) device in his disposal, which is then exploited in the second phase of the attack (i.e., matching) to extract the key from the target device. Discrepancies between the device used for modeling and the target device affect the attack success. The effect of process variation and temperature misalignment between the profiling and target devices in the template attack’s success has been studied extensively in the literature, while the impact of device aging on the template attack’s success is yet to be investigated thoroughly. This article moves one step forward and studies the impact of device aging, mainly bias temperature instability (BTI) and hot carrier injection (HCI), in the devices that have been protected against power analysis attacks via dual rail logics. In particular, we focus on the wave dynamic differential logic (WDDL) circuits, and via extensive transistor-level simulations, we will show how device aging misalignments between the profiling and target devices can hinder template attacks for both unprotected and WDDL protected counterparts. We mounted several attacks on the PRESENT cipher, with and without WDDL protection, at different temperatures and aging times. Our results show that the attack is more difficult if there is an aging-duration mismatch between the training and target devices, and the attack-efficiency decrease is especially significant for mismatches of few weeks. Farzad Niknia, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2022 | Information Leakage in Code-Based Masking: A Systematic Evaluation by Higher-Order AttacksabstractCode-based masking is a recent line of research on masking schemes aiming at provably counteracting side-channel attacks. It generalizes and unifies many masking schemes within a coding-theoretic formalization. In code-based masking schemes, the tuning parameters are the underlying linear codes, whose choice significantly affects the side-channel resilience. In this paper, we investigate the exploitability of the information leakage in code-based masking and present attack-based evaluation results of higher-order optimal distinguisher (HOOD). Particularly, we consider two representative instances of code-based masking, namely inner product masking (IPM) and Shamir’s secret sharing (SSS) based masking. Our results do confirm the state-of-the-art theoretical derivatives in an empirical manner with numerically simulated measurements. Specifically, theoretical results are based on quantifying information leakage; we further complete the panorama with attack-based evaluations by investigating the exploitability of the leakage. Moreover, we classify all possible candidates of linear codes in IPM with 2 and 3 shares and (3, 1)-SSS based masking, and highlight both optimal and worst codes for them. Relying on our empirical evaluations, we therefore recommend investigating the coding-theoretic properties to find the best linear codes in strengthening instances of code-based masking. As for applications, our attack-based evaluation directly empowers designers, by employing optimal linear codes, to enhance the protection of code-based masking. Our framework leverages simulated leakage traces, hence allowing for source code validation or patching in case it is found to be attackable. Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Assessment and Mitigation of Power Side-Channel-Based Cross-PUF Attacks on Arbiter-PUFs and Their DerivativesabstractUnintentional uncontrollable variations in the manufacturing process of integrated circuits are used to realize silicon primitives known as physical unclonable functions (PUFs). These primitives are used to create unique signatures for security purposes. Investigating the vulnerabilities of PUFs is of utmost importance to uphold their usefulness in secure applications. One such investigation includes exploring the susceptibility of PUFs to modeling attacks that aim at extracting the PUFs’ behavior. To date, these attacks have mainly focused on a single PUF instance where the targeted PUF is attacked using the model built based on the very same PUF’s challenge–response pairs or power side channel. In this article, we move one step forward and introduceCross-PUFattacks where a model is created using the power consumption of one PUF instance to attack another PUF created from the same GDSII file. Through SPICE simulations, we show that these attacks are highly effective in modeling PUF behaviors even in the presence of noise and mismatches in temperature and aging of the PUF used for modeling versus the targeted PUF. To mitigate theCross-PUFattacks, we then propose a lightweight countermeasure based on dual-rail and random initialization logic approaches called DRILL. We show that DRILL is highly effective in thwartingCross-PUFattacks. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2021 | Profiled Side-Channel Analysis in the Efficient Attacker Framework
Stjepan Picek, Annelie Heuser, Guilherme Perin, Sylvain Guilley |
CARDIS | 4 |
| 2021 | Making Obfuscated PUFs Secure Against Power Side-Channel Based Modeling AttacksabstractTo enhance the security of digital circuits, there is often a desire to dynamically generate, rather than statically store, random values used for identification and authentication purposes. Physically Unclonable Functions (PUFs) provide the means to realize this feature in an efficient and reliable way by utilizing commonly overlooked process variations that unintentionally occur during the manufacturing of integrated circuits (ICs) due to the imperfection of fabrication process. When given a challenge, PUFs produce a unique response. However, PUFs have been found to be vulnerable to modeling attacks where by using a set of collected challenge response pairs (CRPs) and training a machine learning model, the response can be predicted for unseen challenges. To combat this vulnerability, researchers have proposed techniques such as Challenge Obfuscation. However, as shown in this paper, this technique can be compromised via modeling the PUF's power side-channel. We first show the vulnerability of a state-of-the-art Challenge Obfuscated PUF (CO-PUF) against power analysis attacks by presenting our attack results on the targeted CO-PUF. Then we propose two countermeasures, as well as their hybrid version, that when applied to the CO-PUFs make them resilient against power side-channel based modeling attacks. We also provide some insights on the proper design metrics required to be taken when implementing these mitigations. Our simulation results show the high success of our attack in compromising the original Challenge Obfuscated PUFs (success rate > 98%) as well as the significant improvement on resilience of the obfuscated PUFs against power side-channel based modeling when equipped with our countermeasures. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
DATE | 3 |
| 2021 | Implementing Secure Applications Thanks to an Integrated Secure ElementabstractInternational audience Sylvain Guilley, Michel Le Rolland, Damien Quenson |
ICISSP | 1 |
| 2021 | Cumulant Expansion of Mutual Information for Quantifying Leakage of a Protected SecretabstractThe information leakage of a cryptographic implementation with a given degree of protection is evaluated in a typical situation when the signal-to-noise ratio is small. This is solved by expanding Kullback-Leibler divergence, entropy, and mutual information in terms of moments/cumulants. Olivier Rioul, Wei Cheng 0003, Sylvain Guilley |
ISIT | 3 |
| 2021 | Bent Sequences over Hadamard Codes for Physically Unclonable FunctionsabstractWe study challenge codes for physically unclonable functions (PUFs). Starting from the classical Hadamard challenge code, we augment it by one vector. Numerical values suggest that the optimal choice of this vector for maximizing the entropy is to pick a vector the farthest away from the code formed by the challenges and their binary complements. This leads us to study the covering radius of Hadamard codes. A notion of bent sequence that generalizes the classical notion from Hadamard matrices of Sylvester type to general Hadamard matrices is given. Lower bounds for Paley-type Hadamard matrices are given. Patrick Solé, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul |
ISIT | 3 |
| 2021 | On Conditional Alpha-Information and its Application to Side-Channel AnalysisabstractA conditional version of Sibson’s $\alpha$-information is defined using a simple closed-form “log-expectation” expression, which satisfies important properties such as consistency, uniform expansion, and data processing inequalities. This definition is compared to previous ones, which in contrast do not satisfy all of these properties. Based on our proposal and on a generalized Fano inequality, we extend the case $\alpha=1$ of previous works to obtain sharp universal upper bounds for the probability of success of any type side-channel attack, particularly when $\alpha=2$. Yi Liu 0066, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul |
ITW | 3 |
| 2021 | Linear Programming Bounds on the Kissing Number of q-ary CodesabstractWe use linear programming (LP) to derive upper and lower bounds on the “kissing number” $A_{d}$ of any q-ary linear code C with distance distribution frequencies $A_{i}$, in terms of the given parameters $[n,\ k,\ d]$. In particular, a polynomial method gives explicit analytic bounds in a certain range of parameters, which are sharp for some low-rate codes like the first-order Reed-Muller codes. The general LP bounds are more suited to numerical estimates. Besides the classical estimation of the probability of decoding error and of undetected error, we outline recent applications in hardware protection against side-channel attacks using code-based masking countermeasures, where the protection is all the more efficient a s the kissing number is low. Patrick Solé, Yi Liu 0066, Wei Cheng 0003, Sylvain Guilley, Olivier Rioul |
ITW | 4 |
| 2021 | Reducing Aging Impacts in Digital Sensors via Run-Time Calibration
Md Toufiq Hasan Anik, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
J. Electron. Test. | 4 |
| 2021 | Detecting Failures and Attacks via Digital SensorsabstractDetection of abnormal behaviors is essential in complex and/or strategic systems requiring a high level of safety and security. Sensing environmental conditions to ensure that the device is not operating out-of-specifications is highly useful in detecting anomalies caused by failures or malevolent actions. In this regard, digital sensors (DSs) are particularly attractive as they are portable and can be easily calibrated. In contrast to analog sensors, DSs have an interesting property that considers the operating environmental conditions as a whole, i.e., they are sensitive to temperature, voltage, and process altogether, without precise knowledge about each. This property endows DSs with fewer false positives compared to analog sensors. This article studies a low-cost DS, discusses its presilicon architecture and post-silicon calibration such that it detects system failures accurately in the designer's preferable range of operating conditions. The impact of aging in this sensor is studied extensively. Tradeoffs between false positive and undetection rates are discussed. As an example, we target the substitution box (S-Box) of the PRESENT cipher assuming that it can be the target of fault injection attacks launched via abruptly changing the operating temperature and voltage. We show that such malfunction can be accurately detected by our DS, i.e., with a very negligible percentage of false and missed alarms (<; 1% totally). The results show that the number of false alarms raises with aging (while the rate is highly negligible), whereas the number of missed alarms remains at a reasonable low rate. Md Toufiq Hasan Anik, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2021 | Intrinsic Resiliency of S-Boxes Against Side-Channel Attacks-Best and Worst ScenariosabstractConstructing S-boxes that are inherently resistant against side-channel attacks is an important problem in cryptography. By using an optimal distinguisher under an additive Gaussian noise assumption, we clarify how a defender (resp., an attacker) can make side-channel attacks as difficult (resp., easy) as possible, in relation with the auto-correlation spectrum of Boolean functions. We then construct balanced Boolean functions that are optimal for each of these two scenarios. Generalizing the objectives for an S-box, we analyze the auto-correlation spectra of some well-known S-box constructions in dimensions at most 8 and compare their intrinsic resiliency against side-channel attacks. Finally, we perform several simulations of side-channel attacks against the aforementioned constructions, which confirm our theoretical approach. Claude Carlet, Eloi de Chérisey, Sylvain Guilley, Selçuk Kavut, Deng Tang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Optimizing Inner Product Masking Scheme by a Coding Theory ApproachabstractMasking is one of the most popular countermeasures to protect cryptographic implementations against side-channel analysis since it is provably secure and can be deployed at the algorithm level. To strengthen the original Boolean masking scheme, several works have suggested using schemes with high algebraic complexity. The Inner Product Masking (IPM) is one of those. In this paper, we propose a unified framework to quantitatively assess the side-channel security of the IPM in a coding-theoretic approach. Specifically, starting from the expression of IPM in a coded form, we use two defining parameters of the code to characterize its side-channel resistance. In order to validate the framework, we then connect it to two leakage metrics (namely signal-to-noise ratio and mutual information, from an information-theoretic aspect) and one typical attack metric (success rate, from a practical aspect) to build a firm foundation for our framework. As an application, our results provide ultimate explanations on the observations made by Balasch et al. at EUROCRYPT'15 and at ASIACRYPT'17, Wang et al. at CARDIS'16 and Poussier et al. at CARDIS'17 regarding the parameter effects in IPM, like higher security order in bounded moment model. Furthermore, we show how to systematically choose optimal codes (in the sense of a concrete security level) to optimize IPM by using this framework. Eventually, we present a simple but effective algorithm for choosing optimal codes for IPM, which is of special interest for designers when selecting optimal parameters for IPM. Wei Cheng 0003, Sylvain Guilley, Claude Carlet, Sihem Mesnager, Jean-Luc Danger |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Analysis of Multiplicative Low Entropy Masking Schemes Against Correlation Power AttackabstractLow Entropy Masking Schemes (LEMS) had been proposed to mitigate the high-performance overhead results from the Full Entropy Masking Schemes (FEMS) while offering good protection against side-channel attacks. The masking schemes usually rely on Boolean masking, however, splitting sensitive variables in a multiplicative way is more amenable to non-linear functions and it had been applied to both software and hardware with a competitive alternative to state-of-the-art masked design. Compared to the comprehensive analysis done for Boolean LEMS, the specific leakage characteristics of Multiplicative LEMS have not yet been analyzed. In this paper, we introduce security models for LEMS to characterize the balance of the mask set. Based on the security model, we present an inherent weakness of Multiplicative LEMS. We prove that this defect of Multiplicative LEMS cannot be compensated by choosing a proper mask set, and the security of FEMS is guaranteed thanks to the Dirac function which is used to resist zero-value attack. Then, we exhibit the leakages in the implementation of Multiplicative LEMS. In particular, we propose a new attack against Multiplicative LEMS more efficient by utilizing the distribution of masked intermediate values. The feasibility of the attack is verified by both simulation and practical experiments. Yanbin Li 0001, Zhe Liu 0001, Sylvain Guilley, Ming Tang 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Feasibility study of a camera-based PUF in a realistic scenarioabstractSupply chain management is critical in industrial efforts to reduce costs and time, stabilize product supply, and improve profitability. Surveillance cameras play a significant role in supply chain management, as they can record work activities to achieve appropriate monitoring of company operations. A solution for ensuring the reliability of the video taken by a surveillance camera is to achieve data integrity using a cryptographic algorithm. Another important solution is the identification of a surveillance camera to ensure the traceability of video. This paper proposes a novel approach for video-based fingerprint extraction and key generation, that can be used for camera PUF construction. Our experiment shows that a 256-bit key can be extracted from 50 frames of a normal video with a resolution of 800 X 600 pixels, and we theoretically prove that our methodology satisfies the randomness, uniqueness, steadiness, and unpredictability requirements. Our PUF construction can thus be used to identify a surveillance camera from a video. Kazuhide Fukushima, Thomas Perianin, Victor Dyseryn, Shinsaku Kiyomoto, Sylvain Guilley, Adrien Facon |
ARES | 5 |
| 2020 | Effect of Aging on PUF Modeling Attacks based on Power Side-Channel ObservationsabstractThanks to the imperfections in manufacturing process, Physically Unclonable Functions (PUFs) produce their unique outputs for given input signals (challenges) fed to identical circuitry designs. PUFs are often used as hardware primitives to provide security, e.g., for key generation or authentication purposes. However, they can be vulnerable to modeling attacks that predict the output for an unknown challenge, based on a set of known challenge/response pairs (CRPs). In addition, an attacker may benefit from power side-channels to break a PUFs' security. Although such attacks have been extensively discussed in literature, the effect of device aging on the efficacy of these attacks is still an open question. Accordingly, in this paper, we focus on the impact of aging on Arbiter-PUFs and one of its modeling-resistant counterparts, the Voltage Transfer Characteristic (VTC) PUF. We present the results of our SPICE simulations used to perform modeling attack via Machine Learning (ML) schemes on the devices aged from 0 to 20 weeks. We show that aging has a significant impact on modeling attacks. Indeed, when the training dataset for ML attack is extracted at a different age than the evaluation dataset, the attack is greatly hindered despite being performed on the same device. We show that the ML attack via power traces is particularly efficient to recover the responses of the anti-modeling VTC PUF, yet aging still contributes to enhance its security. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
DATE | 3 |
| 2020 | PUF Enrollment and Life Cycle Management: Solutions and Perspectives for the Test CommunityabstractPhysically Unclonable Functions (PUFs) allow to extract unique fingerprints from silicon chips. The applications are numerous: chip identification, chip master key extraction, authentication protocol, unique seeding, etc. However, secure usage of PUF requires some precautions. This paper reviews industrial concerns associated with PUF operation, including those occurring before and after market. Namely, starting from PUF “secure” specifications, aligned with state-of-the-art standards, we explore innovative techniques to handle enrollment and subsequent PUF queries, in nominal as well as in adversarial environment. Amir Ali Pour, Vincent Beroulle, Bertrand Cambou, Jean-Luc Danger, Giorgio Di Natale, David Hély, Sylvain Guilley, Naghmeh Karimi |
ETS | 7 |
| 2020 | Failure and Attack Detection by Digital SensorsabstractTimely notification of abnormal behaviors is essential in strategic systems requiring a high level of safety and security. Sensing environmental conditions to ensure that the device is not operating out-of-specifications is highly useful in detecting anomalies caused by failures or malevolent actions. Digital sensors consider the operating environmental conditions as a whole, i.e. they are sensitive to temperature, voltage and process altogether, without precise knowledge about each. This paper proposes a low-cost digital sensor that can detect system failures accurately in the designer's preferable range of operating conditions. Our experimental results show the high accuracy of this sensor in detecting circuits failure which occurred due to change of the operating temperature and supply voltage. Md Toufiq Hasan Anik, Rachit Saini, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ETS | 4 |
| 2020 | On-Chip Voltage and Temperature Digital Sensor for Security, Reliability, and PortabilityabstractThe integrated circuits can be exposed to various stresses during run-time due to unexpected environmental conditions or attacks. Ensuring that a circuit is not working out-of-specification via sensing its operating conditions, e.g., temperature and voltage, is highly useful in detecting anomalies. Analog sensors have been used to monitor the operating conditions for a long time, however, weaknesses including lack of portability to thin technology nodes, costly & complex calibration process, and low attack resistance make such sensors inefficient. Digital sensors, via considering the temperature and voltage effects altogether instead of treating each separately, have been demonstrated as a qualified replacement. In this paper, we develop an integrated framework for continuous monitoring of the operating voltage and temperature of each chip. The framework includes an embedded on-chip sensor circuitry along with a Neural Network model that quantifies the temperature and voltage values via processing the data collected by this sensor. The experimental results confirm the high accuracy of the proposed framework in tracking on-chip voltage and temperature variations, i.e., with the average error of 0.014V in a range of 0.65V to 1.4V, and the average error of 3.9°C in a range of -10°C to 150°C, respectively. Md Toufiq Hasan Anik, Mohammad Ebrahimabadi, Hamed Pirsiavash, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ICCD | 5 |
| 2020 | Machine Learning Based Hardware Trojan Detection Using Electromagnetic Emanation
Junko Takahashi, Keiichi Okabe, Hiroki Itoh, Xuan Thuy Ngo, Sylvain Guilley, Ritu Ranjan Shrivastwa, Mushir Ahmed, Patrick Lejoly |
ICICS | 5 |
| 2020 | Cross-PUF Attacks on Arbiter-PUFs through their Power Side-ChannelabstractThe silicon primitives known as Physically Unclonable Functions (PUFs) are used for various security purposes including key generation, device authentication, etc. Due to the imperfections in manufacturing process, PUFs produce their unique outputs (responses) for given input signals (challenges) fed to identical circuitry designs. Although PUFs are deployed to preserve security and are assumed to be unclonable, their functionality may still be compromised by modeling attacks. However, such attacks only target one single PUF aiming at reversing its behavior (based on a subset of its challenge-response pairs), and are not useful for attacking other PUFs. Moreover a subset of the target PUF's response has to be known by the attacker. This paper moves one step forward and investigates the possibility of Cross-PUF attacks in which a particular PUF's power fingerprints can be used to break another PUF's security. In these Cross-PUF attacks, the attacker has at his disposal a reference PUF, and uses its power side-channel to train a machine learning model which can be deployed to attack other identical PUFs. The experimental results show the high success of the proposed attacks even in presence of noise and temperature differences between the target PUF and the one used to train the model. We target arbiter-PUFs but we deduce that the findings extend to all its derivatives, e.g., XOR-PUFs and Feed-Forward-PUFs. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
ITC | 3 |
| 2020 | Side-Channel Analysis and Countermeasure Design on ARM-Based Quantum-Resistant SIKEabstractThe implementations of post-quantum cryptographic algorithms have been newly explored, whereas, the protection against side-channel attacks shall be considered upfront, since it can have a non-negligible impact on security and performance. In this article, the security of supersingular isogeny key encapsulation (SIKE), a second-round candidate of NIST's on-going post-quantum standardization process, is thoroughly evaluated under side-channel analysis. First, the vulnerabilities of reference and optimized implementations of SIKE are thoroughly analyzed in terms of both horizontal and vertical side-channel leakage. After the optimized SIKE, which is based on Three-point Montgomery Differential Ladder algorithm, is proved to be constant-time and there is no horizontal leakage, a vertical vulnerability is analyzed based on the source code at the algorithmic level, and a theoretical differential power analysis (DPA) attack is proposed. In order to exploit this vulnerability, the differential electromagnetic attack (DEMA) is put into practice to extract the private key of SIKE based on a 32-bit ARM platform. To the best of our knowledge, this is the first practical side-channel attack at SIKE implemented on real ARM-based devices. Our experiments show that the DEMA needs only hundreds of electromagnetic traces to carry out the attack. More importantly, an efficient window-based countermeasure is proposed to eliminate the vertical leakage and prevent side-channel attacks with only a little overhead. The security of our countermeasure is carefully evaluated against most of well-known power analysis attacks. Through careful evaluation and comparison with other countermeasures, this method can lead to higher security at a very small cost in terms of time and memory. Fan Zhang 0010, Bolin Yang, Xiaofei Dong, Sylvain Guilley, Zhe Liu 0001, Wei He 0015, Fangguo Zhang, Kui Ren 0001 |
IEEE Trans. Computers | 4 |
| 2020 | Lightweight Ciphers and Their Side-Channel ResilienceabstractSide-channel attacks represent a powerful category of attacks against cryptographic devices. Still, side-channel analysis for lightweight ciphers is much less investigated than for instance for AES. Although intuition may lead to the conclusion that lightweight ciphers are weaker in terms of side-channel resistance, that remains to be confirmed and quantified. In this paper, we consider various side-channel analysis metrics which should provide an insight on the resistance of lightweight ciphers against side-channel attacks. In particular, for the non-profiled scenario we use the theoretical confusion coefficient and empirical optimal distinguisher. Our study considers side-channel attacks on the first, the last, or both rounds simultaneously. Furthermore, we conduct a profiled side-channel analysis using various machine learning attacks to recover 4-bit and 8-bit intermediate states of the cipher. Our results show that the difference between AES and lightweight ciphers is smaller than one would expect, and even find scenarios in which lightweight ciphers may be more resistant. Interestingly, we observe that the studied 4-bit S-boxes have a different side-channel resilience, while the difference in the 8-bit ones is only theoretically present. Annelie Heuser, Stjepan Picek, Sylvain Guilley, Nele Mentens |
IEEE Trans. Computers | 3 |
| 2019 | Experiment on Side-Channel Key-Recovery using a Real LPWA End-deviceabstractThe Internet of things (IoT) has come into widespread use, and data protection and integrity are critical for connected IoT devices in order to maintain security and privacy. Low-power wide-area (LPWA) technologies for IoT wireless communication achieve data protection and integrity by using encryption and message authentication. However, side-channel analysis techniques exist that have the capacity to recover secret information from a device. In this paper, we apply a side-channel analysis technique to the payload encryption process and message authentication code generation process on a real LoRaWAN end-device. The entire AES-128 key for the payload encryption can be recovered with 260 electromagnetic(EM)-leakage traces and 12 bytes of the key for message authentication code generation can be recovered with 140 EM-leakage traces. Kazuhide Fukushima, Damien Marion 0001, Yuto Nakano, Adrien Facon, Shinsaku Kiyomoto, Sylvain Guilley |
ICISSP | 6 |
| 2019 | An Information-Theoretic Model for Side-Channel Attacks in Embedded HardwareabstractUsing information-theoretic tools, this paper establishes a mathematical link between the probability of success of a side-channel attack and the minimum number of queries to reach a given success rate, valid for any possible distinguishing rule and with the best possible knowledge on the attacker's side. This link is a lower bound on the number of queries, which depends on the mutual information between the traces and the secret key. This leads us to derive upper bounds on the mutual information that are as tight as possible and can be easily calculated. It turns out that, in the case of additive white Gaussian noise, the bound on the probability of success of any attack is directly related to the signal-to-noise ratio (SNR). This leads to easy computations and predictions of the success rate for any leakage model. Eloi de Chérisey, Sylvain Guilley, Olivier Rioul, Pablo Piantanida |
ISIT | 2 |
| 2019 | CC Meets FIPS: A Hybrid Test Methodology for First Order Side Channel AnalysisabstractCommon Criteria (CC) and FIPS 140-3 are two popular side channel testing methodologies. Test Vector Leakage Assessment Methodology (TVLA), a potential candidate for FIPS, can detect the presence of side-channel information in leakage measurements. However, TVLA results cannot be used to quantify side-channel vulnerability and it is an open problem to derive its relationship with side channel attack success rate (SR), i.e., a common metric for CC. In this paper, we extend the TVLA testing beyond its current scope. Precisely, we derive a concrete relationship between TVLA and signal to noise ratio (SNR). The linking of the two metrics allows direct computation of success rate (SR) from TVLA for given choice of intermediate variable and leakage model and thus unify these popular side channel detection and evaluation metrics. An end-to-end methodology is proposed, which can be easily automated, to derive attack SR starting from TVLA testing. The methodology works under both univariate and multivariate setting and is capable of quantifying any first order leakage. Detailed experiments have been provided using both simulated traces and real traces on SAKURA-GW platform. Additionally, the proposed methodology is benchmarked against previously published attacks on DPA contest v4.0 traces, followed by extension to jitter based countermeasure. The result shows that the proposed methodology provides a quick estimate of SR without performing actual attacks, thus bridging the gap between CC and FIPS. Debapriya Basu Roy, Shivam Bhasin, Sylvain Guilley, Annelie Heuser, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 3 |
| 2018 | Confused yet Successful: - Theoretical Comparison of Distinguishers for Monobit Leakages in Terms of Confusion Coefficient and SNR
Eloi de Chérisey, Sylvain Guilley, Olivier Rioul |
Inscrypt | 2 |
| 2018 | OpenSSL Bellcore's Protection Helps Fault AttackabstractFaults in software implementations target both data and instructions at different locations. Bellcore attack is a well-known fault attack that is able to break CRT-RSA. In response, cryptographic libraries such as OpenSSL are designed with protections. In this paper, we show two new fault locations on OpenSSL implementation of the CRT-RSA signature that restore the Bellcore attack and break OpenSSL protection against it. Quite surprisingly, one of the fault we found is made possible because of the existence of such protection. Sébastien Carré, Matthieu Desjardins, Adrien Facon, Sylvain Guilley |
DSD | 4 |
| 2018 | CCFI-Cache: A Transparent and Flexible Hardware Protection for Code and Control-Flow IntegrityabstractIn this paper we present a hardware based solution to verify simultaneously Code and Control-Flow Integrity (CCFI), aiming at protecting microcontrollers against both cyber-and physical attacks. This solution is non-intrusive as it does not require any modification of the CPU core. It relies on two additional hardware blocks external to the CPU: The first one – called CCFI-cache – acts as a dedicated cache for the storage of information to check the code and control-flow integrity, and the second one – CCFI-checker – performs control-flow and code integrity verification. Based on a RISC-V platform implementation, we show that the proposed scheme is able to perform online CCFI validation at the price of a small hardware area overhead and doubling the size of the. text section. In most cases, the impact on the run-time performance is on average 32 percent, offering for the first time a generic and practical hardware-enabled cyber-security solution. Jean-Luc Danger, Adrien Facon, Sylvain Guilley, Karine Heydemann, Ulrich Kühne, Abdelmalek Si-Merabet, Michaël Timbert |
DSD | 3 |
| 2018 | An Improved Analysis of Reliability and Entropy for Delay PUFsabstractPhysicallyunclonable functions(PUF) have been used in various applications, such as device authentication, secure storage of sensitive data, and anti-counterfeiting. Different applications require various levels of reliability from the PUF. However, as of today, nopredictivemodel to characterize the PUF reliability has been developed. This is particularly a problem for PUFs with low error rates, because the lower the error rate, the larger the number of measurements required to obtain a good estimate. In this paper, we develop a predictive framework, which enables us to derive a closed-form expression of bothentropyandreliabilityfor several families of delay PUFs: the ring oscillator (RO) PUF, the RO sum PUF as well as the Loop PUF. Improving reliability with bit-filtering, we provide an explicit tradeoff between complexity, reliability and entropy. Error rates as low as 10-9or even lower can be achieved. Our theoretical results are validated by experiments on Loop PUFs implemented in 65 nm CMOS ASIC technology, also used to simulate the behavior of the RO PUF and the RO sum PUF. Alexander Schaub 0001, Jean-Luc Danger, Sylvain Guilley, Olivier Rioul |
DSD | 3 |
| 2018 | Random Numbers Generation: Tests and AttacksabstractThe generation of random numbers is a keystone function in any cryptographic protocol. Indeed, in a security context, the random numbers generation shall withstand assaults from adversaries. It is thus paramount to validate both its functionality and its robustness in front of attacks, including fault injection attacks. The verification implies tests, which shall thus be carried out in nominal but also in perturbed operational environments. In this paper, we review standard tests already existing and still under development. As a first contribution, we suggest a new kind of metrics to assess the quality of the random sequences of bits. As a second contribution, we analyse fault injections in true random number generators and explore whether such faulted behavior can be self-induced within the circuit itself. This analysis reveals a plausible interpretation of the behavior of circuits based on the analysis of long term noise, e.g., TRNGs based on ring oscillators. Sylvain Guilley, Youssef El Housni |
FDTC | 1 |
| 2018 | Impact of Aging on Template AttacksabstractTemplate attack is the most powerful side-channel attack from an information theoretic point of view. This attack is launched in two phases. In the first phase (training) the attacker uses a training device to estimate leakage models for targeted intermediate computations, which are then exploited in the second phase (matching) to extract secret information from the target device. Process variation and discrepancy of operating conditions (e.g., temperature) between training and matching phases adversely affect the success probability of the attack. Attack-success degradation is exacerbated when device aging comes into account. Due to aging, electrical specifications of transistors change over time. Thereby, if the training and target devices have experienced different usage time, the attack will be more difficult. Aging alignment between training and target devices is difficult as aging degradation is highly affected by operating conditions and technological variations. This paper investigates the effect of aging on the success rate of template attacks. In particular, we focus on NBTI and HCI aging mechanisms. We mount several attacks on the PRESENT cipher at different temperatures and aging times. Our results show that the attack is more difficult if there is an aging-duration mismatch between the training and target devices. Naghmeh Karimi, Sylvain Guilley, Jean-Luc Danger |
ACM Great Lakes Symposium on VLSI | 2 |
| 2018 | On the Effect of Aging in Detecting Hardware Trojan Horses with Template AnalysisabstractWith the outsourcing of design flow, ensuring the security and trustworthiness of integrated circuits has become more challenging. Potential malicious modification of circuits, so-called Hardware Trojans Horses (HTH), has emerged as a major security threat. When triggered, the HTH delivers its payload resulting in denial of service, decreasing the device performance, or leaking sensitive information. Deploying VLSI testing schemes to detect HTH may fail in most cases as HTH are designed such that they are rarely activated. Side-channel analysis schemes have a higher detection coverage. The template analysis is the most powerful side-channel tool from an information theoretic point of view. In this paper, we focus on the template analysis used for detecting HTH in cryptographic devices, and study the effect of device aging on the success of these HTH detection schemes. Due to aging, electrical specifications of transistors, and in turn the power signatures used by template schemes change over time. We focus on Negative-Bias Temperature Instability and Hot-Carrier Injection aging mechanisms. We use the PRESENT cipher as a target, and mount several template attacks at different aging times on target devices and a genuine device used as reference. We deduce the authenticity of the target devices based on the attack success rates obtained by template analysis. Our results show that aging makes template-based HTH detection easier as it needs less traces in old devices compared to the new one (137 traces for a 20-week old device versus 195 traces for a new one). Naghmeh Karimi, Jean-Luc Danger, Sylvain Guilley |
IOLTS | 3 |
| 2018 | Prediction-Based Intrusion Detection System for In-Vehicle Networks Using Supervised Learning and Outlier-Detection
Khaled Karray, Jean-Luc Danger, Sylvain Guilley, M. Abdelaziz Elaabid |
WISTP | 3 |
| 2018 | Impact of Aging on the Reliability of Delay PUFs
Naghmeh Karimi, Jean-Luc Danger, Sylvain Guilley |
J. Electron. Test. | 3 |
| 2018 | Multivariate High-Order Attacks of Shuffled Tables Recomputation
Nicolas Bruneau, Sylvain Guilley, Zakaria Najm, Yannick Teglia |
J. Cryptol. | 2 |
| 2017 | Connecting and Improving Direct Sum Masking and Inner Product Masking
Romain Poussier, Qian Guo 0001, François-Xavier Standaert, Claude Carlet, Sylvain Guilley |
CARDIS | 5 |
| 2017 | Analyzing security breaches of countermeasures throughout the refinement process in hardware design flowabstractSide-channel and fault injection attacks are two threats on devices carrying sensitive information. Protections are thus implemented at design time. However, CAD (Computer Aided Design) tools can compromise them, in ways we detail pedagogically in this paper. Then, we explain how a simulation-based methodology allows to check for non-regression, and find problems in case some are introduced while refining the design description from RTL (Register Transfer Level) source code to GDS (Graphic Display System) stream format. Jean-Luc Danger, Sylvain Guilley, Philippe Nguyen, Robert Nguyen, Youssef Souissi |
DATE | 2 |
| 2017 | Impact of the switching activity on the aging of delay-PUFsabstractPhysically Unclonable Functions (PUFs) are mainly used for generating unique keys to identify electronic devices. The reliability of PUFs needs to be assured under a wide variety of environmental conditions and aging mechanisms. In this paper, we evaluate the impact of NBTI and HCI aging on two types of delay-PUFs (arbiter-PUFs and loop-PUFs). The results show that the switching activity has a limited impact on delay chains and a significant impact on the arbiter (RS latch) of the arbiter-PUF. Naghmeh Karimi, Jean-Luc Danger, Mariem Slimani, Sylvain Guilley |
ETS | 4 |
| 2017 | Use of Simulators for Side-Channel AnalysisabstractStart of the above-titled section of the conference proceedings record. Nikita Veshchikov, Sylvain Guilley |
EuroS&P | 2 |
| 2017 | Side-channel analysis and machine learning: A practical perspectiveabstractThe field of side-channel analysis has made significant progress over time. Side-channel analysis is now used in practice in design companies as well as in test laboratories, and the security of products against side-channel attacks has significantly improved. However, there are still some remaining issues to be solved for side-channel analysis to become more effective. Side-channel analysis consists of two steps, commonly referred to as identification and exploitation. The identification consists of understanding the leakage and building suitable models. The exploitation consists of using the identified leakage models to extract the secret key. In scenarios where the model is poorly known, it can be approximated in a profiling phase. There, machine learning techniques are gaining value. In this paper, we conduct extensive analysis of several machine learning techniques, showing the importance of proper parameter tuning and training. In contrast to what is perceived as common knowledge in unrestricted scenarios, we show that some machine learning techniques can significantly outperform template attacks when properly used. We therefore stress that the traditional worst case security assessment of cryptographic implementations, that mainly includes template attacks, might not be accurate enough. Besides that, we present a new measure called the Data Confusion Factor that can be used to assess how well machine learning techniques will perform on a certain dataset. Stjepan Picek, Annelie Heuser, Alan Jovic, Simone A. Ludwig, Sylvain Guilley, Domagoj Jakobovic, Nele Mentens |
IJCNN | 5 |
| 2017 | Implementation flaws in the masking scheme of DPA Contest v4abstractThis study presents an implementation flaw in Differential Power Analysis Contest (DPA) Contest v4. This version of DPA Contest uses Advanced Encryption Standard (AES) protected against side‐channel attacks using rotating s‐box masking (RSM) countermeasure. The authors identify a flaw in the masking scheme that was used in this contest. More specifically, the problem lies in an unfortunate choice of values for masks. An unbalance in the masking scheme leads to a first order leakage. This vulnerability could be used in order to mount a first order side‐channel attack against AES‐RSM. The attack was implemented and tested on DPA Contest v4 reference traces. The authors also provide a way to avoid the newly discovered problem and suggest new values for masks. Nikita Veshchikov, Sylvain Guilley |
IET Inf. Secur. | 2 |
| 2017 | Cryptographically Secure Shield for Security IPs ProtectionabstractProbing attacks are serious threats on integrated circuits. Security products often include a protective layer called shield that acts like a digital fence. In this article, we demonstrate a new shield structure that is cryptographically secure. This shield is based on the lightweight block cipher and independent mesh lines to ensure the security against probing attacks of the hardware located behind the shield. Such structure can be proven secure against state-of-the-art invasive attacks. Then, we evaluate the impact of active shield on the performance of security IPs as PUF, TRNG, secure clock and AES using a set of fabricated ASICs with 65 nm CMOS technology of STMicroelectronics. Also, the impact of active shield on Side-Channel Attack (SCA) is evaluated. Xuan Thuy Ngo, Jean-Luc Danger, Sylvain Guilley, Tarik Graba, Yves Mathieu, Zakaria Najm, Shivam Bhasin |
IEEE Trans. Computers | 3 |
| 2017 | Stochastic Collision AttackabstractOn the one hand, collision attacks have been introduced in the context of side-channel analysis for attackers who exploit repeated code with the same data without having any knowledge of the leakage model. On the other hand, stochastic attacks have been introduced to recover leakage models of internally processed intermediate secret variables. Both techniques have shown advantages and intrinsic limitations. Most collision attacks, for instance, fail in exploiting all the leakages (e.g., only a subset of matching samples are analyzed), whereas stochastic attacks cannot involve linear regression with the full basis (while the latter basis is the most informative one). In this paper, we present an innovative attacking approach, which combines the flavors of stochastic and collision attacks. Importantly, our attack is derived from the optimal distinguisher, which maximizes the success rate when the model is known. Notably, we develop an original closed-form expression, which shows many benefits by using the full algebraic description of the leakage model. Using simulated data, we show in the unprotected case that, for low noise, the stochastic collision attack is superior to the state of the art, whereas asymptotically and thus, for higher noise, it becomes equivalent to the correlation-enhanced collision attack. Our so-called stochastic collision attack is extended to the scenario where the implementation is protected by masking. In this case, our new stochastic collision attack is more efficient in all scenarios and, remarkably, tends to the optimal distinguisher. We confirm the practicability of the stochastic collision attack thanks to experiments against a public data set (DPA contest v4). Furthermore, we derive the stochastic collision attack in case of zero-offset leakage that occurs in protected hardware implementations and use simulated data for comparison. Eventually, we underline the capability of the new distinguisher to improve its efficiency when the attack multiplicity increases. Nicolas Bruneau, Claude Carlet, Sylvain Guilley, Annelie Heuser, Emmanuel Prouff, Olivier Rioul |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Taylor Expansion of Maximum Likelihood Attacks for Masked and Shuffled Implementations
Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Olivier Rioul, François-Xavier Standaert, Yannick Teglia |
ASIACRYPT (1) | 2 |
| 2016 | Correlated Extra-Reductions Defeat Blinded Regular Exponentiation
Margaux Dugardin, Sylvain Guilley, Jean-Luc Danger, Zakaria Najm, Olivier Rioul |
CHES | 2 |
| 2016 | Inter-class vs. mutual information as side-channel distinguishersabstractA novel “interclass information” side-channel distinguisher is compared to mutual information analysis. Interclass information possesses properties similar to mutual information but uses a different comparing strategy between the underlying conditional distributions. It is shown that interclass information can outperform mutual information in side-channel analysis, especially under low noise. The theoretical comparison is confirmed by simulations. Olivier Rioul, Annelie Heuser, Sylvain Guilley, Jean-Luc Danger |
ISIT | 3 |
| 2016 | On the entropy of Physically Unclonable FunctionsabstractA physically unclonable function (PUF) is a hardware device that can generate intrinsic responses from challenges. The responses serve as unique identifiers and it is required that they be as little predictable as possible. A loop-PUF is an architecture where n single-bit delay elements are chained. Each PUF generates one bit response per challenge. We model the relationship between responses and challenges in a loop-PUF using Gaussian random variables and give a closed-form expression of the total entropy of the responses. It is shown that n bits of entropy can be obtained with n challenges if and only if the challenges constitute a Hadamard code. Contrary to a previous belief, it is shown that adding more challenges results in an entropy strictly greater than n bits. A greedy code construction is provided for this purpose. Olivier Rioul, Patrick Solé, Sylvain Guilley, Jean-Luc Danger |
ISIT | 3 |
| 2016 | Evolutionary Algorithms for Boolean Functions in Diverse Domains of CryptographyabstractThe role of Boolean functions is prominent in several areas including cryptography, sequences, and coding theory. Therefore, various methods for the construction of Boolean functions with desired properties are of direct interest. New motivations on the role of Boolean functions in cryptography with attendant new properties have emerged over the years. There are still many combinations of design criteria left unexplored and in this matter evolutionary computation can play a distinct role. This article concentrates on two scenarios for the use of Boolean functions in cryptography. The first uses Boolean functions as the source of the nonlinearity in filter and combiner generators. Although relatively well explored using evolutionary algorithms, it still presents an interesting goal in terms of the practical sizes of Boolean functions. The second scenario appeared rather recently where the objective is to find Boolean functions that have various orders of the correlation immunity and minimal Hamming weight. In both these scenarios we see that evolutionary algorithms are able to find high-quality solutions where genetic programming performs the best. Stjepan Picek, Claude Carlet, Sylvain Guilley, Julian Francis Miller, Domagoj Jakobovic |
Evol. Comput. | 3 |
| 2015 | Less is More - Dimensionality Reduction from a Theoretical PerspectiveabstractInternational audience Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Damien Marion 0001, Olivier Rioul |
CHES | 2 |
| 2015 | Multi-variate High-Order Attacks of Shuffled Tables Recomputation
Nicolas Bruneau, Sylvain Guilley, Zakaria Najm, Yannick Teglia |
CHES | 2 |
| 2015 | Hardware trojan detection by delay and electromagnetic measurements
Xuan Thuy Ngo, Ingrid Exurville, Shivam Bhasin, Jean-Luc Danger, Sylvain Guilley, Zakaria Najm, Jean-Baptiste Rigaud, Bruno Robisson |
DATE | 5 |
| 2015 | Integrated Sensor: A Backdoor for Hardware Trojan Insertions?abstractEmbedded system face a serious threat from physical attacks when applied in critical applications. Therefore, modern systems have several integrated sensors to detect potential threats. In this paper, we put forward a new issue where these sensors can open other security loopholes. We demonstrate that sensors, which are deployed to prevent faults, can be exploited to insert effective and almost zero-overhead hardware Trojans. Two case studies are presented on Xilinx Virtex-5 FPGA. The first case study exploits the in-build temperature sensor of Virtex-5 system monitors while the other exploits a user deployed sensor. Both the sensor can be used to trigger a powerful Trojan with minimal and at times zero overhead. Xuan Thuy Ngo, Zakaria Najm, Shivam Bhasin, Debapriya Basu Roy, Jean-Luc Danger, Sylvain Guilley |
DSD | 6 |
| 2015 | From theory to practice of private circuit: A cautionary noteabstractPrivate circuits, from their publication, have been really popular among the researchers. They also form the basis for provable masking schemes. There are several works which try to improve the results of bit-level private circuits based on 2-input gates for the combinational logic. However, strangely, no practical side-channel analysis of private circuits has been presented so far, which is the focus of the present paper. In this paper, we have tried to identify the `ambush' or hidden dangers in the implementation of private circuits, which can compromise its security in practical scenarios. We have implemented block cipher SIMON with private circuit and have performed side-channel analysis on it. The result shows that, in practice, there is significant amount of information leakage which can be exploited by adversaries. Some leakage comes from practical optimization applied by standard CAD tools, if they restructure the netlists. But even with immutable netlists, we identify leakage caused by a kind of glitch known as early evaluation. Lastly, we demonstrate how to translate theoretically secure private circuit to practically secure private circuit with added overhead, by clocking every combinational gate. Leakage detection tests are applied to attest the security of considered variants of private circuits. Debapriya Basu Roy, Shivam Bhasin, Sylvain Guilley, Jean-Luc Danger, Debdeep Mukhopadhyay |
ICCD | 3 |
| 2015 | Exploiting FPGA Block Memories for Protected Cryptographic ImplementationsabstractModern field programmable gate arrays (FPGAs) are power packed with features to facilitate designers. Availability of features like large block memory (BRAM), digital signal processing cores, and embedded CPU makes the design strategy of FPGAs quite different from ASICs. FPGAs are also widely used in security-critical applications where protection against known attacks is of prime importance. We focus on physical attacks that target physical implementations. To design countermeasures against such attacks, the strategy for FPGA designers should be different from that in ASIC. The available features should be exploited to design compact and strong countermeasures. In this article, we propose methods to exploit the BRAMs in FPGAs for designing compact countermeasures. Internal BRAM can be used to optimize intrinsic countermeasures such as masking and dual-rail logics, which otherwise have significant overhead (at least 2 × ) compared to unprotected ones. The optimizations are applied on a real AES-128 co-processor and tested for area overhead and resistance on Xilinx Virtex-5 chips. The presented masking countermeasure has an overhead of only 16% when applied on AES. Moreover, the dual-rail precharge logic (DPL) countermeasure has been optimized to pack the whole sequential part in the BRAM, hence enhancing the security. Proper robustness evaluations are conducted to analyze the optimization in terms of area and security. Shivam Bhasin, Jean-Luc Danger, Sylvain Guilley, Wei He 0015 |
ACM Trans. Reconfigurable Technol. Syst. | 3 |
| 2014 | Detecting Hidden Leakages
Amir Moradi 0001, Sylvain Guilley, Annelie Heuser |
ACNS | 2 |
| 2014 | Masks Will Fall Off - Higher-Order Optimal Distinguishers
Nicolas Bruneau, Sylvain Guilley, Annelie Heuser, Olivier Rioul |
ASIACRYPT (2) | 2 |
| 2014 | Good Is Not Good Enough - Deriving Optimal Distinguishers from Communication Theory
Annelie Heuser, Olivier Rioul, Sylvain Guilley |
CHES | 3 |
| 2014 | Attacking Suggest Boxes in Web Applications Over HTTPS Using Side-Channel Stochastic Algorithms
Alexander Schaub 0001, Emmanuel Schneider, Alexandros Hollender, Vinicius Calasans, Laurent Jolie, Robin Touillon, Annelie Heuser, Sylvain Guilley, Olivier Rioul |
CRiSIS | 8 |
| 2014 | Countermeasures against High-Order Fault-Injection Attacks on CRT-RSAabstractIn this paper we study the existing CRT-RSA countermeasures against fault-injection attacks. In an attempt to classify them we get to achieve deep understanding of how they work. We show that the many countermeasures that we study (and their variations) actually share a number of common features, but optimize them in different ways. We also show that there is no conceptual distinction between test-based and infective countermeasures and how either one can be transformed into the other. Furthermore, we show that faults on the code (skipping instructions) can be captured by considering only faults on the data. These intermediate results allow us to improve the state of the art in several ways: (a) we fix an existing and that was known to be broken countermeasure (namely the one from Shamir), (b) we drastically optimize an existing countermeasure (namely the one from Vigilant) which we reduce to 3 tests instead of 9 in its original version, and prove that it resists not only one fault but also an arbitrary number of randomizing faults, (c) we also show how to upgrade countermeasures to resist any given number of faults: given a correct first-order countermeasure, we present a way to design a provable high-order countermeasure (for a well-defined and reasonable fault model). Finally, we pave the way for a generic approach against fault attacks for any modular arithmetic computations, and thus for the automatic insertion of countermeasures. Pablo Rauzy, Sylvain Guilley |
FDTC | 2 |
| 2014 | Orthogonal Direct Sum Masking - A Smartcard Friendly Computation Paradigm in a Code, with Builtin Protection against Side-Channel and Fault Attacks
Julien Bringer, Claude Carlet, Hervé Chabanne, Sylvain Guilley, Houssem Maghrebi |
WISTP | 4 |
| 2014 | A Pre-processing Composition for Secret Key Recovery on Android Smartphone
Yuto Nakano, Youssef Souissi, Robert Nguyen, Laurent Sauvage, Jean-Luc Danger, Sylvain Guilley, Shinsaku Kiyomoto, Yutaka Miyake |
WISTP | 6 |
| 2014 | Higher-Order CIS CodesabstractWe introduce complementary information set codes of higher order. A binary linear code of length tk and dimension k is called a complementary information set code of order t (t-CIS code for short) if it has t pairwise disjoint information sets. The duals of such codes permit to reduce the cost of masking cryptographic algorithms against side-channel attacks. As in the case of codes for error correction, given the length and the dimension of a t-CIS code, we look for the highest possible minimum distance. In this paper, this new class of codes is investigated. The existence of good long CIS codes of order 3 is derived by a counting argument. General constructions based on cyclic and quasi-cyclic codes and on the building up construction are given. A formula similar to a mass formula is given. A classification of 3-CIS codes of length ≤ 12 is given. Nonlinear codes better than linear codes are derived by taking binary images of Z4-codes. A general algorithm based on Edmonds' basis packing algorithm from matroid theory is developed with the following property: given a binary linear code of rate 1/t, it either provides t disjoint information sets or proves that the code is not t-CIS. Using this algorithm, all optimal or best known [tk, k] codes, where t = 3, 4, . . . , 256 and 1≤ k ≤⌊256/t⌋ are shown to be t-CIS for all such k and t, except for t = 3 with k = 44 and t = 4 with k = 37. Claude Carlet, Finley Freibert, Sylvain Guilley, Michael Kiermaier, Jon-Lark Kim, Patrick Solé |
IEEE Trans. Inf. Theory | 3 |
| 2014 | Multiply Constant-Weight Codes and the Reliability of Loop Physically Unclonable FunctionsabstractWe introduce the class of multiply constant-weight codes to improve the reliability of certain physically unclonable function response, and extend classical coding methods to construct multiply constant-weight codes from known \(q\) -ary and constant-weight codes. We derive analogs of Johnson bounds and give constructions showing these bounds to be asymptotically tight up to a constant factor under certain conditions. We also examine the rates of multiply constant-weight codes and demonstrate that these rates are the same as those of constant-weight codes of corresponding parameters. Yeow Meng Chee, Zouha Cherif, Jean-Luc Danger, Sylvain Guilley, Han Mao Kiah, Jon-Lark Kim, Patrick Solé, Xiande Zhang |
IEEE Trans. Inf. Theory | 4 |
| 2013 | Time-Frequency Analysis for Second-Order Attacks
Pierre Belgarric, Shivam Bhasin, Nicolas Bruneau, Jean-Luc Danger, Nicolas Debande, Sylvain Guilley, Annelie Heuser, Zakaria Najm, Olivier Rioul |
CARDIS | 6 |
| 2013 | Hardware Trojan Horses in Cryptographic IP CoresabstractDetecting hardware trojans is a difficult task in general. In this article we study hardware trojan horses insertion and detection in cryptographic intellectual property (IP) blocks. The context is that of a fabless design house that sells IP blocks as GDSII hard macros, and wants to check that final products have not been infected by trojans during the foundry stage. First, we show the efficiency of a medium cost hardware trojans detection method if the placement or the routing have been redone by the foundry. It consists in the comparison between optical microscopic pictures of the silicon product and the original view from a GDSII layout database reader. Second, we analyze the ability of an attacker to introduce a hardware trojan horse without changing neither the placement nor the routing of the cryptographic IP logic. On the example of an AES engine, we show that if the placement density is beyond 80%, the insertion is basically impossible. Therefore, this settles a simple design guidance to avoid trojan horses insertion in cryptographic IP blocks: have the design be compact enough, so that any functionally discreet trojan necessarily requires a complete replace and re-route, which is detected by mere optical imaging (and not complete chip reverse-engineering). Shivam Bhasin, Jean-Luc Danger, Sylvain Guilley, Xuan Thuy Ngo, Laurent Sauvage |
FDTC | 3 |
| 2013 | Multiply constant weight codesabstractThe function M(m, n, d, w), the largest size of an unrestricted binary code made of m by n arrays, with constant row weight w, and minimum distance d is introduced and compared to the classical functions of combinatorial coding theory Aq(n, d) and A(n, d, w). The analogues for systematic codes of A(n, d) and A(n, d, w) are introduced apparently for the first time. An application to the security of embedded systems is given: these codes happen to be efficient challenges for physically unclonable functions. Zouha Cherif, Jean-Luc Danger, Sylvain Guilley, Jon-Lark Kim, Patrick Solé |
ISIT | 3 |
| 2012 | Low-Cost Countermeasure against RPA
Jean-Luc Danger, Sylvain Guilley, Philippe Hoogvorst, Cédric Murdica, David Naccache |
CARDIS | 2 |
| 2012 | 3D Hardware Canaries
Sébastien Briais, Stéphane Caron, Jean-Michel Cioranesco, Jean-Luc Danger, Sylvain Guilley, Jacques-Henri Jourdan, Arthur Milchior, David Naccache, Thibault Porteboeuf |
CHES | 5 |
| 2012 | A First-Order Leak-Free Masking Countermeasure
Houssem Maghrebi, Emmanuel Prouff, Sylvain Guilley, Jean-Luc Danger |
CT-RSA | 3 |
| 2012 | Towards Different Flavors of Combined Side Channel Attacks
Youssef Souissi, Shivam Bhasin, Sylvain Guilley, Maxime Nassar, Jean-Luc Danger |
CT-RSA | 3 |
| 2012 | RSM: A small and fast countermeasure for AES, secure against 1st and 2nd-order zero-offset SCAsabstractAmongst the many existing countermeasures against Side Channel Attacks (SCA) on symmetrical cryptographic algorithms, masking is one of the most widespread, thanks to its relatively low overhead, its low performance loss and its robustness against first-order attacks. However, several articles have recently pinpointed the limitations of this countermeasure when matched with variance-based and other high-order analyses. In this article, we present a new form of Boolean masking for the Advanced Encryption Standard (AES) called “RSM”, which shows the same level in performances as the state-of-the-art, while being less area consuming, and secure against Variance-based Power Analysis (VPA) and second-order zero-offset CPA. Our theoretical security evaluation is then validated with simulations as well as real-life CPA and VPA on an AES 256 implemented on FPGA. Maxime Nassar, Youssef Souissi, Sylvain Guilley, Jean-Luc Danger |
DATE | 3 |
| 2012 | An Easy-to-Design PUF Based on a Single Oscillator: The Loop PUFabstractThis paper presents an easy to design Physically Unclonable Function (PUF). The proposed PUF implementation is a loop composed of N identical and controllable delay chains which are serially assembled in a loop to create a single ring oscillator. The frequency discrepancies resulting from the oscillator driven by complementary combinations of the delay chains allows to characterize one device. The presented PUF, nicknamed the Loop PUF (LPUF), returns a frequency comparison of loops made of N delay chains (N ≥ 2). The comparisons are done sequentially on the same structure. Unlike others PUFs based on delays, there is no specific routing constraints. Hence the LPUF is particularly flexible and easy to design. The basic use of the Loop PUF is to generate intrinsic device keys for cryptographic algorithms. It can also be used to generate challenge response pairs for simple authentication. Experiments have been carried out on CYCLONE II FPGAs to assess the performance of the LPUF, such as randomness, uniqueness and steadiness. They clearly show both the easiness of design and the quality level of the LPUF. The measurement time vs steadiness, as well as resistance against side-channel and modeling attacks are discussed. Zouha Cherif, Jean-Luc Danger, Sylvain Guilley, Lilian Bossuet |
DSD | 3 |
| 2012 | Random Active ShieldabstractRecently, some active shielding techniques have been broken (e.g. by FlyLogic). The caveat is that their geometry is easy to guess, and thus they can be bypassed with an affordable price. This paper has two contributions. First of all, it provides a definition of the objectives of shielding, which is seldom found in publicly available sources. Notably, we precise the expected functionality, but also the constraints it must meet to be both manufacturable and secure. Second, we propose an innovative solution based on random shielding. The goal of this shielding is to make the geometry of the shield difficult to recognize, thereby making the "identification" phase of the attack harder than in previous schemes. Also, a proof of the shielding existence for two layers of metal is provided, which guarantees that the generation of the layout will succeed. Finally, we provide real tests of the shield generation algorithm, that show it is computationally tractable even for large areas to protect. Sébastien Briais, Jean-Michel Cioranesco, Jean-Luc Danger, Sylvain Guilley, David Naccache, Thibault Porteboeuf |
FDTC | 4 |
| 2012 | Comparison between Side-Channel Analysis Distinguishers
Houssem Maghrebi, Olivier Rioul, Sylvain Guilley, Jean-Luc Danger |
ICICS | 3 |
| 2012 | On the Optimality of Correlation Power Attack on Embedded Cryptographic Systems
Youssef Souissi, Nicolas Debande, Sami Mekki, Sylvain Guilley, Ali Maalaoui, Jean-Luc Danger |
WISTP | 4 |
| 2011 | Enhancement of simple electro-magnetic attacks by pre-characterization in frequency domain and demodulation techniques
Olivier Meynard, Denis Réal, Florent Flament, Sylvain Guilley, Naofumi Homma, Jean-Luc Danger |
DATE | 4 |
| 2011 | Formal Framework for the Evaluation of Waveform Resynchronization Algorithms
Sylvain Guilley, Karim Khalfallah, Victor Lomné, Jean-Luc Danger |
WISTP | 1 |
| 2011 | Leakage Squeezing Countermeasure against High-Order Attacks
Houssem Maghrebi, Sylvain Guilley, Jean-Luc Danger |
WISTP | 2 |
| 2011 | FIRE: Fault Injection for Reverse Engineering
Manuel San Pedro, Mate Soos, Sylvain Guilley |
WISTP | 3 |
| 2011 | Security evaluation of application-specific integrated circuits and field programmable gate arrays against setup time violation attacksabstractFault attacks are real threats against hardware implementations of robust cryptographic algorithms such as advanced encryption standard (AES). The authors present an active non-invasive attack to inject faults during the execution of the algorithm and describe setup time violation attacks by under-powering and overclocking an application-specific integrated circuit. Then a security evaluation is presented against setup time violation attacks of several AES architectures on two field programmable gate arrays (FPGA) brands, namely Altera Stratix and Xilinx Virtex5. The authors notice that the architecture of the substitution box greatly impacts the faults statistics. These statistics are furthermore different depending on the FPGA vendor, and also notice that it is more difficult to inject single fault in the most recent technology. Also, the use-cases show how difficult it is to predict the most vulnerable resource in an FPGA. Finally, a low-cost countermeasure against this kind of attack is presented. Nidhal Selmane, Shivam Bhasin, Sylvain Guilley, Jean-Luc Danger |
IET Inf. Secur. | 3 |
| 2010 | Characterization of the Electromagnetic Side Channel in Frequency Domain
Olivier Meynard, Denis Réal, Sylvain Guilley, Florent Flament, Jean-Luc Danger, Frédéric Valette |
Inscrypt | 3 |
| 2010 | Unrolling Cryptographic Circuits: A Simple Countermeasure Against Side-Channel Attacks
Shivam Bhasin, Sylvain Guilley, Laurent Sauvage, Jean-Luc Danger |
CT-RSA | 2 |
| 2010 | Far Correlation-based EMA with a precharacterized leakage modelabstractElectromagnetic analysis is an important class of attacks against cryptographic devices. In this article, we prove that Correlation-based on ElectroMagnetic Analysis (CEMA) on a hardware-based high-performance AES module is possible from a distance as far as 50 cm. First we show that the signal-to-noise ratio (SNR) tends to a non-zero limit when moving the antenna away from the cryptographic device. An analysis of the leakage structure shows that the Hamming distance model, although suitable for small distances gets more and more distorted when the antenna is displaced far from the device. As we cannot devise any physical model that would predict the observations, we instead pre-characterized it using a first order templates construction. With this model, we enhanced the CEMA by a factor up to ten. Therefore, we conclude that EMA at large distance is feasible with our amplification strategy coupled to an innovative training phase aiming at precharacterizing accurate coefficients of a parametric weighted distance leakage model. Olivier Meynard, Sylvain Guilley, Jean-Luc Danger, Laurent Sauvage |
DATE | 2 |
| 2010 | BCDL: A high speed balanced DPL for FPGA with global precharge and no early evaluationabstractIn this paper, we present BCDL (Balanced Cell-based Dual-rail Logic), a new counter-measure against Side Channel Attacks (SCA) on cryptoprocessors implementing symmetrical algorithms on FPGA. BCDL is a DPL (Dual-rail Precharge Logic), which aims at overcoming most of the usual vulnerabilities of such counter-measures, by using specific synchronization schemes, while maintaining a reasonable complexity. We compare our architecture in terms of complexity, performances and easiness to design with other DPLs (WDDL, IWDDL, MDPL, iMDPL, STTL, DRSL, SecLib). It is shown that BCDL can be optimized to achieve higher performances than any other DPLs (more than 1/2 times the nominal data rate) with an affordable complexity. Finally, we implement a BCDL AES on an FPGA and compare its robustness against DPA by using the number of Measurements To Disclosure (MTD) required to find the key with regards to unprotected AES. It is observed that the SCA on a BCDL implementation failed for 150,000 power consumption traces which represents a gain greater than 20 w.r.t. the unprotected version. Moreover the fault attack study has pointed out the natural resistance of BCDL against simple faults attacks. Maxime Nassar, Shivam Bhasin, Jean-Luc Danger, Guillaume Duc, Sylvain Guilley |
DATE | 5 |
| 2010 | Fault Injection ResilienceabstractFault injections constitute a major threat to the security of embedded systems. Errors occurring in the cryptographic algorithms have been shown to be extremely dangerous, since powerful attacks can exploit few of them to recover the full secrets. Most of the resistance techniques to perturbation attacks have relied so far on the detection of faults. We present in this paper another strategy, based on the resilience against fault attacks. The core idea is to allow an erroneous result to be outputted, but with the assurance that this faulty information conveys no information about the secrets concealed in the chip. We first underline the benefits of FIR: false positive are never raised, secrets are not erased uselessly in case of uncompromising faults injections, which increases the card lifespan if the fault is natural and not malevolent, and FIR enables a high potential of resistance even in the context of multiple faults. Then we illustrate two families of fault injection resilience (FIR) schemes suitable for symmetric encryption. The first family is a protocol-level scheme that can be formally proved resilient. The second family mobilizes a special logic-level architecture of the cryptographic module. We notably detail how a countermeasure of this later family, namely dual-rail with precharge logic style, can both protect both against active and passive attacks, thereby bringing a combined global protection of the device. The cost of this logic is evaluated as lower than detection schemes. Finally, we also give some ideas about the modalities of adjunction of FIR to some certification schemes. Sylvain Guilley, Laurent Sauvage, Jean-Luc Danger, Nidhal Selmane |
FDTC | 1 |
| 2010 | Improvement of power analysis attacks using Kalman filterabstractPower analysis attacks are non intrusive and easily mounted. As a consequence, there is a growing interest in efficient implementation of these attacks against block cipher algorithms such as Data Encryption Standard (DES) and Advanced Encryption Standard (AES). In our paper we propose a new technique based on the Kalman theory. We show how this technique could be useful for the cryptographic domain by making power analysis attacks faster. Moreover we prove that the Kalman filter is more powerful than the High Order Statistics technique. Youssef Souissi, Sylvain Guilley, Jean-Luc Danger, Sami Mekki, Guillaume Duc |
ICASSP | 2 |
| 2010 | Evaluation of Power Constant Dual-Rail Logics Countermeasures against DPA with Design Time Security MetricsabstractCryptographic circuits are nowadays subject to attacks that no longer focus on the algorithm but rather on its physical implementation. Attacks exploiting information leaked by the hardware implementation are called side-channel attacks (SCAs). Among these attacks, the differential power analysis (DPA) established by Paul Kocher et al. in 1998 represents a serious threat for CMOS VLSI implementations. Different countermeasures that aim at reducing the information leaked by the power consumption have been published. Some of these countermeasures use sophisticated back-end-level constraints to increase their strength. As suggested by some preliminary works (e.g., by Li from Cambridge University), the prediction of the actual security level of such countermeasures remains an open research area. This paper tackles this issue on the example of the AES SubBytes primitive. Thirteen implementations of SubBytes, in unprotected, WDDL, and SecLib logic styles with various back-end-level arrangements are studied. Based on simulation and experimental results, we observe that static evaluations on extracted netlists are not relevant to classify variants of a countermeasure. Instead, we conclude that the fine-grained timing behavior is the main reason for security weaknesses. In this respect, we prove that SecLib, immune to early-evaluation problems, is much more resistant against DPA than WDDL. Sylvain Guilley, Laurent Sauvage, Florent Flament, Vinh-Nga Vong, Philippe Hoogvorst, Renaud Pacalet |
IEEE Trans. Computers | 1 |
| 2009 | Deconvolving Protected SignalsabstractThe variable clock (VC) side-channel countermeasure consists in clocking a chip with an internal oscillator whose parameters (frequency, duty cycle, shape, etc.) vary randomly in time. In this paper, we use parametric deconvolution to process VC-power consumption curves. We also analyze experimental results in order to show its efficiency. Mohaned Kafi, Sylvain Guilley, Sandra Marcello, David Naccache |
ARES | 2 |
| 2009 | Successful attack on an FPGA-based WDDL DES cryptoprocessor without place and route constraintsabstractIn this paper, we propose a preprocessing method to improve side channel attacks (SCAs) on dual-rail with precharge logic (DPL) countermeasure family. The strength of our method is that it uses intrinsic characteristics of the countermeasure: classical methods fail when the countermeasure is perfect, whereas our method still works and enables us to perform advanced attacks. We have experimentally validated the proposed method by attacking a DES cryptoprocessor embedded in a field programmable gates array (FPGA), and protected by the wave dynamic differential logic (WDDL) countermeasure. This successful attack, unambiguous as the full key is retrieved, is the first to be reported. Laurent Sauvage, Sylvain Guilley, Jean-Luc Danger, Yves Mathieu, Maxime Nassar |
DATE | 2 |
| 2009 | WDDL is Protected against Setup Time Violation AttacksabstractIn order to protect crypto-systems against side channel attacks various countermeasures have been implemented such as dual-rail logic or masking. Faults attacks are a powerful tool to break some implementations of robust cryptographic algorithms such as AES and DES. Various kind of fault attacks scenarios have been published. However, very few publications available in the public literature detail the practical realization of such attacks. In this paper we present the result of a practical fault attack on AES in WDDL and its comparison with its non-protected equivalent. The practical faults on an FPGA running an AES encrypt or are realized by under-powering it and further exploited using Piret's attack. The results show that WDDL is protected against setup violation attacks by construction because a faulty bit is replaced by a null bit in the cipher text. Therefore, the fault leaks no exploitable information. We also give a theoretical model for the above results. Other references have already studied the potential of fault protection of the resynchronizing gates (delay-insensitive). In this paper, we show that non-resynchronizing gates (hence combinatorial DPL such as WDDL) are natively immune to setup time violation attacks. Nidhal Selmane, Shivam Bhasin, Sylvain Guilley, Tarik Graba, Jean-Luc Danger |
FDTC | 3 |
| 2009 | Electromagnetic Radiations of FPGAs: High Spatial Resolution Cartography and Attack on a Cryptographic ModuleabstractSince the first announcement of a Side Channel Analysis (SCA) about ten years ago, considerable research has been devoted to studying these attacks on Application Specific Integrated Circuits (ASICs), such as smart cards or TPMs. In this article, we compare power-line attacks with ElectroMagnetic (EM) attacks, specifically targeting Field Programmable Gate Array devices (FPGAs), as they are becoming widely used for sensitive applications involving cryptography. We show experimentally that ElectroMagnetic Analysis (EMA) is always faster than the historical Differential Power Analysis (DPA) in retrieving keys of symmetric ciphers. In addition, these analyses prove to be very convenient to conduct, as they are totally non-invasive. Research reports indicate that EMA can be conducted globally, typically with macroscopic home-made coils circling the device under attack, with fair results. However, as accurate professional EM antennas are now becoming more accessible, it has become commonplace to carry out EM analyses locally. Cartography has been carried out by optical means on circuits realized with technology greater than 250 nanometers. Nonetheless, for deep submicron technologies, the feature size of devices that are spied upon is too small to be visible with photographic techniques. In addition, the presence of the 6+ metallization layers obviously prevents a direct observation of the layout. Therefore, EM imaging is emerging as a relevant means to discover the underlying device structure. In this article, we present the first images of deep-submicron FPGAs. The resolution is not as accurate as photographic pictures: we notably compare the layout of toy design examples placed at the four corners of the FPGAs with the EM images we collected. We observe that EM imaging has the advantage of revealing active regions, which can be useful in locating a particular processor (visible while active---invisible when inactive). In the context of EM attacks, we stress that the exact localization of the cryptographic target is not necessary: the coarse resolution we obtain is sufficient. We note that the EM imaging does not reveal the exact layout of the FPGA, but instead directly guides the attacker towards the areas which are leaking the most. We achieve attacks with an accurate sensor, both far from (namely on a SMC capacitor on the board) and close to (namely directly over the FPGA) the encryption co-processor. As compared to the previously published attacks, we report a successful attack on a DES module in fewer than 6,300 measurements, which is currently the best cracking performance against this encryption algorithm implemented in FPGAs. Laurent Sauvage, Sylvain Guilley, Yves Mathieu |
ACM Trans. Reconfigurable Technol. Syst. | 2 |
| 2008 | An 8x8 run-time reconfigurable FPGA embedded in a SoCabstractThis paper presents a RTR FPGA embedded in a System on Chip fabricated in 130nm CMOS process. Various aspects of the design flow, from automation to floor-planning are discussed. We explain the measures taken in the FPGA design to guarantee RTR functionality free of electrical conflicts, and we present a flow based on Altera synthesis tools to implement IPs(Hardware Blocks) in this FPGA. We demonstrate the full functionality with experiments on the FPGA, and as conclusion we highlight the limitations and future research directions. Sumanta Chaudhuri, Sylvain Guilley, Florent Flament, Philippe Hoogvorst, Jean-Luc Danger |
DAC | 2 |
| 2008 | Silicon-level Solutions to Counteract Passive and Active AttacksabstractThis article presents a family of cryptographic ASICs, called SecMat, designed in CMOS 130 nanometer technology by the authors with the help of STMicroelectronics.The purpose of these prototype circuits is to experience with the published ``implementation-level'' attacks(SPA, DPA, EMA, templates, DFA). We report our conclusions about the practicability of these attacks:which ones are the most simple to mount, and which ones require more skill, time, equipments, etc.The potential of FPGAs as security evaluation commodities at design time is also detailed.Then, we discuss about ``dual counter-measures'', that are meant to resist both passive and active attacks.This study started four years ago with TIMA (Grenoble), in the framework of the project MARS. We highlight some research directions towards dependable and cost-effective dual counter-measures. Sylvain Guilley, Laurent Sauvage, Jean-Luc Danger, Nidhal Selmane, Renaud Pacalet |
FDTC | 1 |
| 2008 | Efficient tiling patterns for reconfigurable gate arraysabstractThis article does a purely mathematical analysis based on generic models, and the idea is to investigate the possibility of using tiling patterns other than Manhattan grid in FPGAs. The goal of our research is to evolve FPGA architectures with advances in technology, and specifically better utilization of available interconnect layers. We propose a method to evaluate tiling patterns based on the first principles ( i.e Rent's Rule, Donath's result, equivalence of wire flux and wire length). We show that, use of tiling patterns formed with higher order polygons can improve the speed and area performances of an FPGA. This gain is highly dependent on depopulation schemes and other parameters. However for generic tiling patterns with crossbar switchboxes there is a 22% gain in area for the hexagonal tiling pattern, and a 30% gain in area for the octagonal tiling pattern. Moreover the average interconnect length is around 15% lesser for hexagonal and 31% lesser for the octagonal tiling compared to square tiling. We can expect a proportional increase in speed. We also present a comparative plot of total interconnect lengths for these tiling patterns and the hierarchical gate arrays Sumanta Chaudhuri, Jean-Luc Danger, Philippe Hoogvorst, Sylvain Guilley |
FPGA | 4 |
| 2008 | Area optimization of cryptographic co-processors implemented in dual-rail with precharge positive logicabstractField programmable gate arrays (FPGAs) become very popular for embedded cryptographic operations. In order to resist side-channel attacks, FPGAs must implement reasoned countermeasures. The most efficient way to mitigate attacks is to adopt a gate-level protection. Two secure gates families exist: those that ldquohiderdquo and those that ldquomaskrdquo side-channel leakage. In this article, we detail methods to reduce the size of wave dynamic differential logic (WDDL) implementations. These circuits are designed to hide any physical leak by ensuring a data-independent activity. This study is meant to be generic, and thus applies to any 4 rarr 1 LUT-based FPGAs. Further optimizations can be reached by taking advantage of some FPGAs proprietary features. Our solutions include RTL code modification, synthesizer usage (potentially in a re-entrant way), and ad hoc mapping. We show that linear parts of algorithms can be delegated to a synthesizer, but that non-linear parts are better off to be handled with heuristics. We present a 23 % area gain over the state-of-the-art as for the positive WDDL triple-DES symmetric encryption algorithm. Sylvain Guilley, Laurent Sauvage, Jean-Luc Danger, Philippe Hoogvorst |
FPL | 1 |
| 2008 | Security Evaluation of WDDL and SecLib Countermeasures against Power AttacksabstractLogic styles with constant power consumption are promising solutions to counteract side-channel attacks on sensitive cryptographic devices. Recently, one vulnerability has been identified in a standard-cell-based power-constant logic called WDDL. Another logic, nicknamed SecLib, is considered and does not present the flaw of WDDL. In this paper, we evaluate the security level of WDDL and SecLib. The methodology consists in embedding in a dedicated circuit one unprotected DES coprocessor along with two others, implemented in WDDL and in SecLib. One essential part of this paper is to describe the conception of the cryptographic ASIC, devised to foster side-channel cryptanalyses, in a view to model the strongest possible attacker. The same analyses are carried out successively on the three DES modules. We conclude that, provided that the back-end of the WDDL module is carefully designed, its vulnerability cannot be exploited by the state-of-the-art attacks. Similarly, the SecLib DES module resists all assaults. However, using a principal component analysis, we show that WDDL is more vulnerable than SecLib. The statistical dispersion of WDDL, which reflects the correlation between the secrets and the power dissipation, is proved to be an order of magnitude higher than that of SecLib. Sylvain Guilley, Laurent Sauvage, Philippe Hoogvorst, Renaud Pacalet, Guido Bertoni, Sumanta Chaudhuri |
IEEE Trans. Computers | 1 |
| 2007 | Efficient Modeling and Floorplanning of Embedded-FPGA FabricabstractIn this paper we present an automatic design flow for generating customized embedded FPGA (eFPGA) fabric and a domain specific SOC+eFPGA architecture. This design flow encompasses both the eFPGA user and automatic layout generator perspectives. We discuss generic FPGA modeling based on VPR tool, simulation and high-level models of reconfigurable components, and we present an innovative floor-planing for island style FPGAs using rectilinear macros. Several system integration issues are highlighted. Layout of a real life SOC with an embedded RTR FPGA for cryptographic applications, designed with this flow, is also presented. Sumanta Chaudhuri, Jean-Luc Danger, Sylvain Guilley |
FPL | 3 |
| 2007 | A Novel Asynchronous e-FPGA Architecture for Security ApplicationsabstractWith the growing security needs of applications such as homeland security or banking, the frequent updates in cryptographic standards and the high ASIC costs, the ciphering algorithms on an asynchronous embedded FPGA co-processor are becoming a viable alternative. Within the SAFE project, a novel architecture of asynchronous e-FPGA has been proposed. This architecture is natively robust against side channel attacks such as simple and differential power analysis or clock based fault attacks. Simulation-based security proofs are also presented. Taha Beyrouthy, Alin Razafindraibe, Laurent Fesquet, Marc Renaudin, Sumanta Chaudhuri, Sylvain Guilley, Jean-Luc Danger, Philippe Hoogvorst |
FPT | 6 |
| 2007 | A fast pipelined multi-mode DES architecture operating in IP representation
Sylvain Guilley, Philippe Hoogvorst, Renaud Pacalet |
Integr. | 1 |
| 2005 | The "Backend Duplication" Method
Sylvain Guilley, Philippe Hoogvorst, Yves Mathieu, Renaud Pacalet |
CHES | 1 |
| 2005 | The Proof by 2M-1: a Low-Cost Method to Check Arithmetic Computations
Sylvain Guilley, Philippe Hoogvorst |
SEC | 1 |
| 2004 | Differential Power Analysis Model and Some Results
Sylvain Guilley, Philippe Hoogvorst, Renaud Pacalet |
CARDIS | 1 |
| 2004 | CMOS Structures Suitable for Secured HardwareabstractUnsecured electronic circuits leak physical syndromes correlated to the data they handle. Side-channels attacks, like SPA or DPA, exploit this information leakage. We provide balanced and memoryless CMOS structures for a 2-input secured NAND gate. Sylvain Guilley, Philippe Hoogvorst, Yves Mathieu, Renaud Pacalet, Jean Provost |
DATE | 1 |