Go to main content

SCCyPhy

Security and Cryptology for Cyber-Physical Systems

Action Team

Scientific description

The core mission of this task force is to analyze, design, and implement effective, certified cryptographic components, security protocols, and privacy components—both hardware and software—for cyber-physical systems that are vulnerable to various types of attacks or privacy issues, using a "secure by design" or "privacy by design" approach.

We also propose developing a common framework for protecting software and hardware components and their interactions. The goal is to focus on complementary protections against various attacks in order to provide a comprehensive assessment of an embedded application, both in terms of security and privacy and, more generally, in terms of cyber-physical components. Thanks to our diverse expertise, this interdisciplinary action team offers the ideal structure to conduct such research and aims to become a major player at the European level.

Key findings and future work

We obtained a variety of results, ranging from:

  • The design and cryptanalysis of FPGA-based cryptographic components using fast and robust elliptic curve cryptography, including proposals for new arithmetic implementations [1] and newSimple Power Analysis(SPA) attacks [2]
  • A privacy analysis of widely used methods (based on Bloom filters) with compelling results. In particular, we developed a new framework for modeling attackers on Bloom filters and identified vulnerabilities in several software programs [4]. Our study [5] also showed that Google’s“Safe Browsing” service had several privacy vulnerabilities that could be exploited to track users. This research recently forced Google to revise its privacy policies.
  • Solutions for preserving the confidentiality of outsourced data using homomorphic encryption. Although the practical implementation of fully homomorphic schemes is still a long way off, thanks to FPGAs [3], we have demonstrated that we can accelerate the modular polynomial multiplications used in Ring-LWE (one of the leading homomorphic schemes) by a factor of 20 compared to the best software implementation on high-end processors, and three times faster than previous hardware implementations. Our method also has significant room for improvement.
  • New techniques [6] based on hidden Markov chains for assessing randomness, which make it possible to identify specific patterns produced by given non-deterministic random bit generators. Further work is underway on this topic to incorporate these techniques into new standards.
  • An end-to-end methodology for assessing code robustness in the face of fault injection has been developed. We have proposed a method for characterizing the probabilistic fault models associated with physical attacks and metrics based on code evaluation, in accordance with a Common Criteria approach.

Coordinators

Claude Castellucia (INRIA)

Jessy Clédière (CEA)

Philippe Elbaz-Vincent (Fourier Institute)

Régis Leveugle (TIMA)

Valuation

The SCCyPhy Action Team has raised the profile of the Grenoble cybersecurity community through the following collaborations and leadership initiatives.

Industrial partnerships

  • The Action Team is part of the ARAMIS consortium (Robust Architecture for Controllers and Hardware in Sensitive Infrastructures), led by Atos Worldgrid, which has been selected as a global-scale R&D initiative by the French government’s “Investissements d’Avenir” program. It focuses on developing an innovative system capable of providing an unparalleled level of security for existing or new industrial control system architectures. This innovation involves physically segmenting networks and filtering data exchanges to reject all data flows identified as unauthorized and therefore potentially malicious. The ARAMIS consortium is composed of key players with unique expertise in industrial control systems and cybersecurity.
  • We are also part of the new Cybersecurity research initiative at the CEA's IRT Nanoelec.

Leadership Initiatives

  • SCCyPhy is involved in RESSI (
    e Research and Education Forum on Information Systems Security), a network of cybersecurity academics, and is responsible for organizing the RESSI Event 2017.
  • SCCyPhy is also part of the CNRS's emerging cybersecurity network (pre-GDR "Computer Security"), as well as Allistene ("Alliance for Digital Sciences and Technologies").

Notable publications

[1] Marie-Angela Cornelie; Implementation and Protection of Software and Hardware Cryptographic Mechanisms,
PhD thesis, University of Grenoble Alpes, April 2016 (https://tel.archives-ouvertes.fr/tel-01377372v1).

[2] Simon Pontié; Hardware Security for Elliptic Curve Cryptography, PhD thesis, University of Grenoble Alpes (
), November 2016 (https://theses.hal.science/tel-01581829v1).

[3] C. Jayet-Griffon, M.-A. Cornelie, P. Maistri, Ph. Elbaz-Vincent, R. Leveugle; Polynomial multipliers for fully homomorphic encryption on FPGAs, IEEE ReConfig 2015.

[4] T. Gerbet, A. Kumar, and C. Lauradoux; “The Power of Evil Choices in Bloom Filters,” IEEE/IFIP 45th International Conference on Dependable Systems and Networks (
, DSN 2015).

[5] T. Gerbet, A. Kumar, and C. Lauradoux; “A Privacy Analysis of Google and Yandex Safe Browsing,” *
* IEEE/IFIP 46th International Conference on Dependable Systems and Networks (DSN 2016).

[6] Kevin Layat; Modeling and Validation of Cryptographic Random Number Generators for Embedded Systems, PhD thesis, University of Grenoble Alpes, December 2015 (https://tel.archives-ouvertes.fr/tel-01271983).

Published on April 9, 2025

Updated on April 9, 2025