Bonjour à tous,
La prochaine session du séminaire SemSecuElec (Sécurité des systèmes électroniques embarqués) aura lieu le Vendredi 24 Novembre de 10h à 12h.
Le programme de cette session est le suivant :
10h - 11h : Dennis Gnad (Karlsruhe Institute of Technology (KIT))
titre : Timing-based Power Side-Channels in FPGAs and beyond
résumé : FPGAs are getting more widely used for computing accelerators, even in the cloud, where sharing between multiple users is interesting for efficiency reasons. Of course, such setups also ask for new security evaluations. We show how a new class of internal attacks uses standard FPGA primitives to measure or manipulate on-chip voltage, and how that can be used for various side-channel attacks inside the FPGA, FPGA-SoCs, or even other chips on the same PCB. In detail, these attacks use very fine measurement of transistor delay as an indirect measurement of voltage. We show how these measurements can even be used for side channel attacks on devices behind galvanically isolated communication channels by measuring their signal jitter. In the end, there will be a demo presenting one of these attacks on real hardware.
11h - 12h : Olivier Potin (Mines Saint-Etienne, centre CMP - Gardanne)
titre : "Control Flow Integrity verification scheme based on the RISC-V Trace Encoder"
résumé : "The increasingly complex nature of embedded systems is accompanied by a strong security requirement: the security level of systems must grow to counter new attacks that exploit hardware and/or software vulnerabilities. Among these threats, the so-called 'physical' attacks are considered particularly serious and potent in targeting the confidentiality, integrity, and authenticity of systems. Traditionally, research on side-channel analysis and fault injection has focused on cryptographic primitives. However, recently, fault attacks have been used to compromise the integrity of program execution, broadening the spectrum of applications susceptible to such attacks (bootloaders, firmware updates, etc.). The countermeasures exposed during the presentation enable the verification of whether a program is executed correctly and remains not tampered by these attacks. Their designs are approached using a co-design strategy that involves both software and hardware, taking into account potential interactions between the open micro-architecture of the RISC-V processor and the flexibility of software development (dedicated code, compilation strategy, etc.). The effectiveness of these countermeasures verifying the integrity of the control flow, the code integrity, and the execution integrity of program instructions on a RISC-V processor against fault injections will be detailed. These solutions are based on a module designed by the RISC-V community, known as the Trace Encoder. Several solutions with different levels of granularity and characteristics have been proposed. In comparison to existing solutions in the state of the art, our solutions require no modifications to the RISC-V compilation toolchain or user code."
Le séminaire est ouvert à tous en présentiel et en distanciel.
Pour assister au séminaire en présentiel, l'inscription est obligatoire au moins 48h à l'avance pour tous les participants en présentiel auprès de Nadia Derouault <nadia [*] derouaultinria [*] fr>. Les participants externes devront se présenter à l'accueil avec une pièce d'identité.
Le séminaire aura lieu dans les locaux de l'Inria Rennes, salle Turing-Petri.
Pour assister au séminaire en distanciel, vous trouverez ci-dessous les informations de connexion.
--------------------------------
REJOINDRE LA RÉUNION WEBEX
https://inria.webex.com/inria/j.php?MTID=m8a0d58598b7dfa4b554b38939f314…
Numéro de la réunion (code d’accès) : 2743 073 4937
Mot de passe de la réunion : 1234
TAPEZ POUR REJOINDRE LA RÉUNION À PARTIR D’UN PÉRIPHÉRIQUE MOBILE (UNIQUEMENT POUR LES PARTICIPANTS)
+33-1-7091-8646,,27430734937## tel:%2B33-1-7091-8646,,*01*27430734937%23%23*01*
REJOINDRE PAR TÉLÉPHONE
+33-1-7091-8646
Numéros d'appel internationaux
https://inria.webex.com/inria/globalcallin.php?MTID=maf02b3636b1c331ed6…
REJOINDRE À PARTIR D’UN SYSTÈME OU D’UNE APPLICATION VIDÉO
Composer le numéro sip:27430734937inria [*] webex [*] com
Vous pouvez également composer le 62.109.219.4 et saisir votre numéro de votre réunion.