Gemalto (France)
companyMeudon, France
Research output, citation impact, and the most-cited recent papers from Gemalto (France) (France). Aggregated across the NobleBlocks index of 300M+ scholarly works.
Top-cited papers from Gemalto (France)
In this paper, we show that Web protocols and technologies are good candidates to design the Internet of things. This approach allows anyone to access embedded devices through a Web application, via a standard Web browser. This Web of things requires to embed Web servers in hardware-constrained devices. We first analyze the traffics embedded Web servers have to handle. Starting from this analysis, we propose a new way to design embedded Web servers, using a dedicated TCP/IP stack and numerous cross-layer off-line pre-calculation (where information are shared between IP, TCP, HTTP and the Web application). We finally present a prototype - named Smews - as a proof of concept of our proposals. It has been embedded in tiny devices (smart cards, sensors and other embedded devices), with a requirement of only 200~bytes of RAM and 7~kilo-bytes of code. We show that it is significantly faster than other state of the art solutions. We made Smews source code publicly available under an open-source license.
Purpose The purpose of this paper is to provide a unique overview of business-to-business (B2B) companies engagement with and strategic approach to use of social media in brand building. This research complements the much more extensive knowledge base regarding social media use in business-to-consumer (B2C) contexts. Design/methodology/approach Since social media marketing is a relatively new activity for B2B companies an interpretivist stance that is inductive in nature is adopted. Semi-structured interviews were conducted with marketing professionals involved in managing social media programmes in France, Ireland, the UK and the USA. Findings The study found that the level of enagement with social media marketing varied, as summarised in the B2B Social Media Engagement Taxonomy. Enhancing brand image, extending brand awareness and facilitating customer engagement were the most common social media objectives. There was no evidence to suggest that companies saw social media as heralding a paradigm shift in brand management and control of the kind discussed and experienced in B2C social media contexts. The B2B social media strategy framework is proposed; this identifies the following six components of a social media strategy: monitoring and listening, empowering and enagaging employees, creating compelling content, stimulating electronic word of mouth, evaluating and selecting channels, and enhacning brand presence through integrating social media. Originality/value The research contributes to the knowledge base associated with social media marketing by offering insights into and a framework summarising B2B social media strategy.
Side-channel attacks have been deeply studied for years to ensure the tamper resistance of embedded implementations. Analysis are most of the time focused either on passive attack (side channel attack) or on active attacks (fault attack). In this article, a combination of both attacks is presented. It is named PACA for Passive and Active Combined Attacks. This new class of attacks allows us to recover the secret key with only one curve of leakages. Practical results on a secure implementation of RSA have been obtained and are presented here. Finally, a new kind of infective methodology is defined and countermeasures to counteract this type of analysis are introduced.
In the semiconductor market where more and more companies become fabless, malicious integrated circuits' modifications are seen as possible threats. Those Hardware Trojans can have various effects and can be implemented by different entities with different means. This article includes the integration of an almost automatic Hardware Trojan detection. The latter is based on a visual inspection implemented within the integrated circuit life cycle. The proposed detection methodology is quite efficient regarding tools, user experience and time needed. A single layer of the chip is accessed and then imaged with a Scanning Electron Microscope (SEM). The acquisition of several hundred images at high magnification is automated as does the images registration. Then depending on the reference availability, one can check if any supplementary gates have been inserted in the design using a golden reference or a graphic/text design file. Depending on the reference, either basic image processing is used to compare the chip extracted image with a golden model or some pattern recognition can be used to retrieve the number of occurrences of each standard cell. The depicted methodology aims to detect any gate modification, substitution, removal or addition and so far require an invasive approach and a reference.
Snow 3G is the backup encryption algorithm used in the mobile phone UMTS technology to ensure data confidentiality. Its design - a combiner with memory - is derived from the stream cipher Snow 2.0, with improvements against algebraic cryptanalysis and distinguishing attacks. No attack is known against Snow 3G today. In this paper, a fault attack against Snow 3G is proposed. Our attack recovers the secret key with only 22 fault injections.
GRAIN-v1 is a stream cipher that has been selected in the final portfolio of the eSTREAM project. GRAIN-128 is a variant of GRAIN-v1. The best known mathematical attack against GRAIN-128 is the brute force key-search. This paper introduces a fault attack on GRAIN-128 based on a realistic fault model and explores possible improvements of the attack. We also discuss countermeasures to counteract our fault attack.
In this paper, we show that Web protocols and technologies are good candidates to design the Internet of Things, through a user-centric architecture (the user simply has to use a standard Web browser). We detail how this Web of Things can handle typical embedded devices interaction needs. We discuss the technical feasibility of embedded Web servers, and, thanks to an analysis of the Web protocols, we propose new cross-layer solutions for efficient tiny embedded Web servers design. The problem of event notification for Web applications is also discussed. We finally present a prototype - named Smews - as a proof of concept of the Web of Things. Smews implements our proposals and has been embedded in tiny devices (smart cards, sensors and other embedded devices), with a requirement of only 200 bytes of volatile memory and 7 kilo-bytes of code. We show that it is significantly faster than other state of the art solutions. We made Smews source code publically available under an open-source license.
The main practical limitation of the McEliece public-key encryption scheme is probably the size of its key. A famous trend to overcome this issue is to focus on subclasses of alternant/Goppa codes with a non-trivial automorphism group. Such codes display then symmetries allowing compact parity-check or generator matrices. For instance, a key-reduction is obtained by taking quasi-cyclic (QC) or quasi-dyadic (QD) alternant/Goppa codes. We show that the use of such symmetric alternant/Goppa codes in cryptography introduces a fundamental weakness. It is indeed possible to reduce the key-recovery on the original symmetric public-code to the key-recovery on a (much) smaller code that has no symmetry anymore. This result is obtained thanks to an operation on codes called folding that exploits the knowledge of the automorphism group. This operation consists in adding the coordinates of codewords which belong to the same orbit under the action of the automorphism group. The advantage is twofold. The reduction factor can be as large as the size of the orbits, and it preserves a fundamental property: folding the dual of an alternant (respectively, Goppa) code provides the dual of an alternant (respectively, Goppa) code. A key point is to show that all the existing constructions of alternant/Goppa codes with symmetries follow a common principal of taking codes whose support is globally invariant under the action of affine transformations (by building upon prior works of Berger and Dür). This enables not only to present a unified view but also to generalize the construction of QC, QD, and even quasi-monoidic Goppa codes. Finally, our results can be harnessed to boost up any key-recovery attack on McEliece systems based on symmetric alternant or Goppa codes, and in particular algebraic attacks.
The Internet of Things is taking hold in our everyday life. Regrettably, the security of IoT devices is often being overlooked. Among the vast array of security issues plaguing the emerging IoT, we decide to focus on access control, as privacy, trust, and other security properties cannot be achieved without controlled access. This article classifies IoT access control solutions from the literature according to their architecture (e.g., centralized, hierarchical, federated, distributed) and examines the suitability of each one for access control purposes. Our analysis concludes that important properties such as auditability and revocation are missing from many proposals while hierarchical and federated architectures are neglected by the community. Finally, we provide an architecture-based taxonomy and future research directions: a focus on hybrid architectures, usability, flexibility, privacy, and revocation schemes in serverless authorization.
In this paper, we present how SEMBA, a fast invasive technique for white team Hardware Trojan detection, has been used to differentiate between a maliciously infected integrated circuit and a genuine one. Our methodology is based on the observation of the component's hardware structure and includes the use of wet etching, Scanning Electron Microscopy and Multiple Image Alignment. Once the Integrated Circuits' image have been fully reconstructed, image processing allows to detect the presence of the Hardware Trojan (HT). SEMBA is a fully automated approach with a 100% success rate, detecting any ‘transistor-size’ HTs and requiring ‘affordable’ resources and time.
The ever-growing world of the Internet of Things (IoT) is yet to agree on an effective and practical access control solution. To overcome challenges such as limited resources, or unreliable connectivity, a number of schemes offload heavy computations onto a central entity, thus creating a single point of failure. Our contribution consists in the construction of a distributed attribute-based access control mechanism, relying on the blockchain technology to dynamically manage multi-endorsed attributes and trust anchors. The originality of our proposal is multifold. First, it enables the integration of multiple security domains into a single resilient access control system. Second, its focus on attributes offers flexibility, expressiveness, and user-centricity, accommodating the dynamic addition of subjects. Third, our attribute endorsement is open, scalable, and flexible, enabling multiple administrators without sacrificing ease of management. Finally, the final access control decision is taken by the device and only requires local connection to its gateway.
Today, increasing number of industrial application cases rely on the Machine to Machine (M2M) services exposed from physical devices. Such M2M services enable interaction of physical world with the core processes of company information systems. However, there are grand challenges related to complexity and “vertical silos” limiting the M2M market scale and interoperability. It is here expected that horizontal approach for the system architecture is required for solving these challenges. Therefore, a set of architectural principles and key enablers for the horizontal architecture have been specified in this work. A selected set of key enablers called as autonomic M2M manager, M2M service capabilities, M2M messaging system, M2M gateways towards energy constrained M2M asset devices and creation of trust to enable end-to-end security for M2M applications have been developed. The developed key enablers have been evaluated separately in different scenarios dealing with smart metering, car sharing and electric bike experiments. The evaluation results shows that the provided architectural principles, and developed key enablers establish a solid ground for future research and seem to enable communication between objects and applications, which are not initially been designed to communicate together. The aim as the next step in this research is to create a combined experimental system to evaluate the system interoperability and performance in a more detailed manner.
At CHES 2008, Vigilant proposed an efficient way of implementing a CRT-RSA resistant against Fault Analysis. In this paper, we investigate the fault-resistance of this scheme and we show that it is not immune to fault injection. Indeed, we highlight two weaknesses which can lead an attacker to recover the whole private key by using only one faulty signature. We also suggest some modifications with a negligible cost to improve the fault-resistance of Vigilant's scheme. Therefore the scheme including modifications remains suited to embedded device constraints.
In the area of physical attacks, system-on-chip (SoC) designs have not received the same level of attention as simpler micro-controllers. We try to model the behavior of secure software running on a superscalar out-of-order microprocessor typical of more complex SoC, in the presence of electromagnetic (EM) pulses. We first show that it is possible, in a black box approach, to corrupt the loop iteration count of both original and hardened versions of two sensitive loops. We propose a characterization methodology based on very simple codes, to understand and classify the fault effects at the level of the instruction set architecture (ISA). The resulting classification includes the well established instruction skip and register corruption models, as well as new effects specific to more complex processors, such as operand substitution, multiple correlated register corruptions, advanced control-flow hijacking, and combinations of all reported effects. This diversity and complexity of effects can lead to powerful attacks. The proposed methodology and fault classification at ISA level is a first step towards a more complete characterization. It is also a tool supporting the designers of software and hardware countermeasures.
Laser fault injections have been evolving rapidly with the advent of more precise, sophisticated and cost-efficient sources, optics and control circuits. In this paper, we show a methodology to improve the test coverage and to speed up analysis based on laser fault injections by only targeting standard cells of interest. We describe how to identify interesting spatial positions thanks to the use of some chemicals along with an automated Scanning Electron Microscope image acquisition, alignment and processing. Using the latter information, fault injections with a high success rate have been obtained against a hardware implemented AES module using a laser beam. With such tools and methodology, we show that attacks become much faster.
The concept of reserve appears in the neurological literature in the 1940s arising from the observation that there is no linear relationship between neurological damage and severity of the clinical symptoms. Basically, this concept sustains that the experiences pursued during life-span enrich the brain by making it more resilient to neuronal damage. However, in the last three decades the reserve concept has become very popular in the scientific field, mainly associated with the pathophysiological mechanisms underlying the Alzheimer’s Disease (AD) (Serra et al., 2018; Stern et al., 2018). In this time period the concept has been substantially modified (Serra et al., 2018; Stern et al., 2018), passing from a structural concept–the brain reserve (BR)–to a more functional concept–the neural reserve (NR)–by way of a cognitive concept-the cognitive reserve (CR). The BR is related to the brain structure in terms of number of neurons, synapses, and dendrites, and postulates that individuals with larger brain cope better with the neurological damage than subjects with smaller brains (Serra et al., 2018; Stern et al., 2018). The concept of CR is related to the efficiency of cognitive functioning, and postulates that subjects with higher level of CR use more efficiently the pre-existent cognitive processes or are able to enlist alternative cognitive functions to cope better with brain damages (Serra et al., 2018; Stern et al., 2018). The NR is a sort of summa of the previous concepts. Indeed, NR is related to the efficiency of brain networks, namely subjects with higher NR are able to engage more efficiently different brain routes to use more effectively the cognitive functions withstanding the cerebral damage (Serra et al., 2017b). Moreover, Stern (2017) introduced the concept of brain maintenance that postulates that life experiences (including cognitive, social and physical activities) reshape the brain, such increasing the ability to maintain the cognitive integrity. It is well known that several factors that may be associated with genetic background and also with environmental factors impact positively or negatively on brain resilience making subjects able or not to counteract the damages (Serra et al., 2018). An important part of the research on the reserves is dedicated to identify the better proxy measure to capture brain changes due to reserves’ mechanisms (BR, CR, NR). To evaluate the BR and NR in vivo, in the human being the best indicators derive from neuroimaging techniques. Indeed, several studies that use magnetic resonance imaging reported brain structural and functional changes related to reserves in patients with AD at different clinical stages (Serra et al., 2017b, 2018; Stern et al., 2018). On the same slipstream CR has been evaluated using two kinds of indicators. The first to be studied and the most common indicators are the level of education, the type of occupation and the quantity and quality of leisure activities. These indicators are defined as static measures of reserve because are not directly related to cognitive functioning and are relatively stable during life (Serra et al., 2018). More recently, the dynamic CR measures have been introduced in the literature (Reed et al., 2010; Serra et al., 2017a). These measures are directly linked to cognitive changes and they express the amount of cognitive functioning residual after removing the effect of brain damage. Actually, in the studies on human beings the indicators of BR, NR, and dynamic (but not static) CR can be indifferently used as proxy measures of reserve or as measures of the effects of reserve. Although from a methodological point of view both these strategies are equally correct, this ambiguity affects the strength and the clinical value of such heterogeneous studies. This topic remains very intriguing and, in our opinion, deserves of further studies specifically finalized to disentangle and compare the “two faces” of the reserve measures. In animals, the effects of the experience on cognitive functions are investigated by using the model of environmental enrichment. This model is realized by exposing the animals– usually, rodents-to a complex of multifarious stimulations (such as rearing in large cages and numerous groups, with the access to running wheels and ever-changing objects) (Rosenzweig et al., 1978; Petrosini et al., 2009). Thus, the “reserve-builders” that are considered in humans are paralleled in the controlled manipulation of some variables, such as social interactions (human factor), complex and ever-changing environment (cognitive factor), and physical activity and exploration (physical factor). In this model, the researcher is able to fix the beginning and the duration of the exposure to the enriching factors, and also to choose a unimodal or multimodal sensory stimulation (Gelfo et al., 2018). In this way, the environmental enrichment model overcomes some issues that are present in the human studies. Indeed, it allows comparing individuals to verify the effects of well-defined factors, by ensuring comparable background and by making possible the analysis of a great number of cellular and molecular brain indexes (Serra et al., 2018). In animal studies two reserve measures are principally considered, such as BR and CR. To investigate BR, molecular and supra-molecular biological indices are considered (Gelfo et al., 2018). To investigate CR, the performances in behavioral tests are taken into account (Petrosini et al., 2009). Also, evidence on NR may be inferred from some brain structural adjustments, such as neurogenesis, gliogenesis, angiogenesis, synaptogenesis, etc. (Gelfo et al., 2018). In contrast to human studies (in which static indexes of reserve are not experimentally manipulable but only observable), the high-level control of the “reserve-builders” allowed by animal models permits the direct manipulation of all factors involved in the experimental design. As a consequence, the indicators of BR, CR, and NR are generally analyzed as dependent variables that indicate the effects of the reserve (Serra et al., 2018). Anyway, also in animal models these reserve measures could be analyzed as causal factors. The effects of the exposure to environmental enrichment are investigated in a large number of disease models characterized by cognitive decline (such as models of physiological or pathological aging). Strong evidence is provided by research on animals about the BR and CR by which the exposure to the environmental enrichment equips the animals. Several studies documented that enriched animals show superior cognitive performance in behavioral tasks (that allow to evaluate a number of cognitive functions), in healthy conditions and also in the presence of neurological damage (Mandolesi et al., 2008; Petrosini et al., 2009; Serra et al., 2018). Moreover, the exposure to environmental enrichment provokes a large range of molecular and supra-molecular plastic changes (such as neurogenesis, gliogenesis, angiogenesis, synaptogenesis, modifications in neurotransmitter and neurotrophic factor systems, etc.) that support the amelioration in behavioral performance (Gelfo et al., 2009, 2018; Petrosini et al., 2009). Overall, a plethora of human and animal studies supports the existence of reserve mechanisms. However, a majority of these studies are focalized on the conceptual framework of reserves, but disregards the real impact and potential usefulness of reserves in the clinical setting. Indeed, although it is mandatory to deepen the knowledge of the different aspects of reserves, nevertheless we retain that the time is ripe to push down these theoretical concept to the real clinical practice in the physician room. A better usability of the reserve concepts could aid the physician to obtain a more “on the patient-tailored” medical decision-making finalised to increase the awareness in designing therapeutic pathways. To realize this point of view, it is important to outline some fundamental hot-points on which the future studies should be focused. First of all, a more accurate definition of the variables considered in the operationalization process of the proxy measures of reserve is required. This is an exigency regarding both human and animal research. Animal models permit a better control of the experimental setting with a more precise definition of the variables involved in the design. This is an advantage and it should be exploited to directly investigate the peculiar and different levels of the factors that regard the human being. As stated above, the disentangling of the “two faces” of reserve measures should be closely pursued in the studies. In addition, it is not completely clear the time-window of action of the reserves’ mechanisms. Indeed, some studies report that reserves have a modulatory effect in aging, in pre-clinical and even severe stages of AD. However, by now this point is still under debate, since some studies find reserve effects only in one of these stages. A more precise definition of the time-window of action of the reserves is needed, because it could consent a more tailored therapeutic intervention (Serra et al., 2018). We are not able to directly manipulate the timing of the reserve in the humans. Conversely, the animal model represent the ideal experimental setting to investigate this issue by direct manipulating the duration of the exposure to environmental enrichment. Another critical point that currently is not still adequately addressed is the interaction between different levels of reserve and therapeutic interventions. Namely, a fundamental question regards the eventual variability in the efficacy of pharmaceutical/not-pharmaceutical treatments in the presence of different levels of reserve. By now, this relationship appears scarcely investigated in the literature, since the research spotlight omitted the importance of clinical application of reserve mechanisms. Therefore, specific studies that investigate the reserve/intervention relationship are currently lacking. This limitation has important repercussions in the clinical practice. According to the classical Stern model, patients with higher reserve accumulate more neuropathological damage and they arrive later to diagnosis. In this picture, it is conceivable that an intervention following the late diagnosis may be partially or completely inefficacious. If evidence is provided that high-level reserve patients could obtain more benefit from interventions in comparison to the low-level reserve ones, then it could be desirable to early assess the reserve level together with the risk to develop dementia (by using different biomarkers), in order to offer precocious treatments that maximize the advantages (Figure 1).Figure 1: Panel representing the main topics that are addressed in the perspective.On the left, the key issues on the reserves that should be investigated and clarified are listed. On the right, the principal benefits that could be gained by clarifying the listed issues are in turn listed.In conclusion, we have to remember that the world population is in ever-increasing aging with an exponential augment of the risk of developing neurodegenerative disorders. It is by now established that life-style shapes brain resilience. Thus, the promotion of a precocious attention to the care of the individual brain maintenance is fundamental. Also, it has to be beneficially inserted in the active clinical managing of the risk to develop cognitive decline.
This experimental study addresses the problem of assessing the digital security of System on Chip (SoC) against electromagnetic (EM) hardware attacks through their packages. With large and complex circuits such as SoC, finding the right location and the right time to examine attacks such as side channel analysis and fault injection is a real challenge. In addition, setting up properly the parameters of these attacks is time consuming. Through an application on a commercial SoC, this article presents an approach which from a side channel analysis results, performs a fault injection attack. This approach shows firstly, the potential time saved to determine the injection time parameter of the fault attack and secondly, it enables to analyze the duality between the emission fields and the areas where errors occur. Thus, a security test of the SoC against EM field is presented in this study.
This chapter contains sections titled: Introduction WLAN and WPAN Security GSM and 3GPP Security Mobile Platform Layer Security Hardware Attacks on Mobile Equipment Conclusion References
Nowadays, the security level of secure integrated circuits makes simple attacks less efficient. The combination of invasive approaches and fault attacks can be seen as more and more pertinent to retrieve secrets from integrated circuits. This paper includes a practical methodology and its application. We first describe how to retrieve the physical areas of interest for the attack. Then, we perform a deep fault injection characterization of the area of found. For the former, a methodology based on circuit preparation, scanning electron microscope acquisitions, image registration and processing is given allowing to perform a controlled and localized laser fault attack with a state-of-the-art injection platform. The laser fault injection presented here allows the attacker to perform a “bit-set,” a “bit-reset” or a full register “reset”. Controlling the value stored in a flip-flop is critical for security. To illustrate this methodology, an encryption algorithm is targeted. We see that efficient methods that take advantage of the comparison between faulty and correct cipher texts, such as differential fault analysis or “safe error”, are particularly relevant with the proposed methodology. The overall methodology can efficiently be used to speed up an attack and to improve the test coverage.
The number of industrial applications relying on the Machine to Machine (M2M) services exposed from physical world has been increasing in recent years. Such M2M services enable communication of devices with the core processes of companies. However, there is a big challenge related to complexity and to application-specific M2M systems called “vertical silos”. This paper focuses on reviewing the technologies of M2M service networks and discussing approaches from the perspectives of M2M information and services, M2M communication and M2M security. Finally, a discussion on technologies and approaches potentially enabling future autonomic M2M service networks are provided. According to our conclusions, it is seen that clear definition of the architectural principles is needed to solve the “vertical silo” problem and then, proceeding towards enabling autonomic capabilities for solving complexity problem appears feasible. Several areas of future research have been identified, e.g., autonomic information based services, optimization of communications with limited capability devices, real-time messaging, creation of trust and end to end security, adaptability, reliability, performance, interoperability, and maintenance.