Guillaume Bouffard

dblp:96/10595 · DBLP profile ↗
← Back
14ranked-venue papers
6as first author
3since 2021 · last 2025
0000-0002-2046-369XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 6 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Do Not Trust Power Management: A Survey on Internal Energy-based Attacks Circumventing Trusted Execution Environments Security Properties
abstract
Over the past few years, several research groups have introduced innovative hardware designs for Trusted Execution Environments (TEEs), aiming to secure applications against potentially compromised privileged software, including the kernel [ 10 , 63 ]. Since 2015 [ 94 ], a new class of software-enabled hardware attacks leveraging energy management mechanisms has emerged. These internal energy-based attacks comprise fault [ 86 ], side-channel [ 46 ], and covert channel attacks [ 28 ]. Their aim is to bypass TEE security guarantees and expose sensitive information such as cryptographic keys. They have increased in prevalence in the past few years [ 9 , 24 , 40 ]. Popular TEE implementations, such as ARM TrustZone and Intel SGX, incorporate countermeasures against these attacks. However, these countermeasures either hinder the capabilities of the power management mechanisms or have been shown to provide insufficient system protection [ 9 , 55 ]. This article presents the first comprehensive knowledge survey of these attacks, along with an evaluation of literature countermeasures. We believe that this study will spur further community efforts toward this increasingly important type of attacks.
Owen Le Gonidec, Guillaume Bouffard, Jean-Christophe Prévotet, Maria Mendez Real
ACM Trans. Embed. Comput. Syst.2
2021 PhiAttack - Rewriting the Java Card Class Hierarchy
Jean Dubreuil, Guillaume Bouffard
CARDIS2
2021 EM Fault Model Characterization on SoCs: From Different Architectures to the Same Fault Model
abstract
Recently, several Fault Attacks (FAs) which target modern Central Processing Units (CPUs) have emerged. These attacks are studied from a practical point of view and, due to the modern CPUs complexity, the underlying fault effect is usually unknown. Only few works try to characterize them at the Instruction Set Architecture (ISA) level.In this article, we apply a state-of-the-art faults model characterization approach on modern CPU to evaluate the fault model on two different CPUs from different architectures with the same injection mediums. We target the CPU of the Raspberry Pi 3 (ARM) and an Intel Core i3 (x86) and perturbing them with ElectroMagnetic Fault Injection (EMFI). From the ISA point of view, we disclose a similar fault model on each component. Additionally, we evaluate a widely used complex software, OpenSSL, against this fault model.
Thomas Trouchkine, Guillaume Bouffard, Jessy Clédière
FDTC2
2019 Fault Injection Characterization on Modern CPUs
Thomas Trouchkine, Guillaume Bouffard, Jessy Clédière
WISTP2
2015 Java Card Virtual Machine Compromising from a Bytecode Verified Applet
Julien Lancia, Guillaume Bouffard
CARDIS2
2015 The ultimate control flow transfer in a Java based smart card
Guillaume Bouffard, Jean-Louis Lanet
Comput. Secur.1
2014 Heap ... Hop! Heap Is Also Vulnerable
Guillaume Bouffard, Michael Lackner, Jean-Louis Lanet, Johannes Loinig
CARDIS1
2014 Memory Forensics of a Java Card Dump
Jean-Louis Lanet, Guillaume Bouffard, Rokia Lamrani Alaoui, Ranim Chakra, Afef Mestiri, Mohammed Monsif, Abdellatif Fandi
CARDIS2
2013 Accessing secure information using export file fraudulence
abstract
Java Card specification allows to load applications after the post-issuance. Each application to be installed into the card is verified by a Byte Code Verifier which ensures that the application is in compliance with the Java security rules.
Guillaume Bouffard, Tom Khefif, Jean-Louis Lanet, Ismael Kane, Sergio Casanova Salvia
CRiSIS1
2013 Vulnerability Analysis on Smart Cards Using Fault Tree
Guillaume Bouffard, Bhagyalekshmy N. Thampi, Jean-Louis Lanet
SAFECOMP1
2012 Type Classification against Fault Enabled Mutant in Java Based Smart Card
abstract
Smart card are often the target of software or hardware attacks. For instance the most recent attacks are based on fault injection which can modify the behavior of applications loaded in the card, changing them as mutant application. In this paper, we propose a new protection mechanism which makes application to be less prone to mutant generation. This countermeasure requires a transformation of the original program byte codes which remains semantically equivalent. It requires a modification of the Java Virtual Machine which remains backward compatible and a dedicated framework to deploy the applications. Hence, our proposition improves the ability of the platform to resist to Fault Enabled Mutant.
Jean Dubreuil, Guillaume Bouffard, Jean-Louis Lanet, Julien Iguchi-Cartigny
ARES2
2012 A Friendly Framework for Hidding fault enabled virus for Java Based Smartcard
Tiana Razafindralambo, Guillaume Bouffard, Jean-Louis Lanet
DBSec2
2011 Combined Software and Hardware Attacks on the Java Card Control Flow
Guillaume Bouffard, Julien Iguchi-Cartigny, Jean-Louis Lanet
CARDIS1
2011 Evaluation of the Ability to Transform SIM Applications into Hostile Applications
Guillaume Bouffard, Jean-Louis Lanet, Jean-Baptiste Machemie, Jean-Yves Poichotte, Jean-Philippe Wary
CARDIS1