{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T15:09:42Z","timestamp":1777648182070,"version":"3.51.4"},"reference-count":101,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2018,5,10]],"date-time":"2018-05-10T00:00:00Z","timestamp":1525910400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2018,5,10]],"date-time":"2018-05-10T00:00:00Z","timestamp":1525910400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1441710, 1314598"],"award-info":[{"award-number":["1441710, 1314598"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Hardw Syst Secur"],"published-print":{"date-parts":[[2018,6]]},"DOI":"10.1007\/s41635-018-0038-1","type":"journal-article","created":{"date-parts":[[2018,5,10]],"date-time":"2018-05-10T16:33:27Z","timestamp":1525970007000},"page":"111-130","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":68,"title":["Fault Attacks on Secure Embedded Software: Threats, Design, and Evaluation"],"prefix":"10.1007","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7734-8465","authenticated-orcid":false,"given":"Bilgiday","family":"Yuce","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Patrick","family":"Schaumont","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marc","family":"Witteman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,5,10]]},"reference":[{"key":"38_CR1","unstructured":"Lipp M, Schwarz M, Gruss D, Prescher T, Haas W, Mangard S, Kocher P, Genkin D, Yarom Y, Hamburg M (2018) Meltdown, arXiv:\n                    1801.01207"},{"key":"38_CR2","unstructured":"Kocher P, Genkin D, Gruss D, Haas W, Hamburg M, Lipp M, Mangard S, Prescher T, Schwarz M, Yarom Y (2018) Spectre attacks: exploiting speculative execution, arXiv:\n                    1801.01203"},{"key":"38_CR3","doi-asserted-by":"crossref","unstructured":"Piessens F, Verbauwhede I (2016) Software security: vulnerabilities and countermeasures for two attacker models. In: Design Automation &, test in Europe conference & exhibition (DATE), pp 990\u2013999","DOI":"10.3850\/9783981537079_0999"},{"key":"38_CR4","unstructured":"Witteman M, Oostdijk M (2008) Secure application programming in the presence of side channel attacks. In: RSA Conference, vol 2008"},{"key":"38_CR5","doi-asserted-by":"crossref","unstructured":"Yuce B, Ghalaty NF, Deshpande C, Patrick C, Nazhandali L, Schaumont P (2016) FAME: fault-attack aware microprocessor extensions for hardware fault detection and software fault response. In: Hardware and Architectural Support for Security and Privacy (HASP). ACM, p 8","DOI":"10.1145\/2948618.2948626"},{"issue":"11","key":"38_CR6","doi-asserted-by":"publisher","first-page":"3056","DOI":"10.1109\/JPROC.2012.2188769","volume":"100","author":"A Barenghi","year":"2012","unstructured":"Barenghi A, Breveglieri L, Koren I, Naccache D (2012) Fault injection attacks on cryptographic devices: theory, practice, and countermeasures. Proc IEEE 100(11):3056\u20133076","journal-title":"Proc IEEE"},{"key":"38_CR7","doi-asserted-by":"crossref","unstructured":"Joye M, Tunstall M (eds) (2012) Fault analysis in cryptography, ser. Information security and cryptography. Springer, Berlin","DOI":"10.1007\/978-3-642-29656-7"},{"key":"38_CR8","doi-asserted-by":"crossref","unstructured":"Galathy NF, Yuce B, Schaumont P (2017) A systematic approach to fault attack resistant design. In: Fundamentals of IP and SoC security, pp 223\u2013245. Springer","DOI":"10.1007\/978-3-319-50057-7_9"},{"key":"38_CR9","doi-asserted-by":"crossref","unstructured":"Moro N, Dehbaoui A, Heydemann K, Robisson B, Encrenaz E (2013) Electromagnetic fault injection: towards a fault model on a 32-bit microcontroller. In: 2013 Workshop on fault diagnosis and tolerance in cryptography (FDTC), pp 77\u201388. IEEE","DOI":"10.1109\/FDTC.2013.9"},{"key":"38_CR10","doi-asserted-by":"crossref","unstructured":"Courbon F, Loubet-Moundi P, Fournier JJ, Tria A (2014) Adjusting laser injections for fully controlled faults. In: International Workshop on constructive side-channel analysis and secure design, pp 229\u2013242. Springer","DOI":"10.1007\/978-3-319-10175-0_16"},{"key":"38_CR11","doi-asserted-by":"crossref","unstructured":"Yuce B, Ghalaty NF, Schaumont P (2015) Improving fault attacks on embedded software using risc pipeline characterization. In: Proc. of FDTC\u201915, pp 97\u2013108","DOI":"10.1109\/FDTC.2015.16"},{"key":"38_CR12","doi-asserted-by":"crossref","unstructured":"Li Y, Sakiyama K, Gomisawa S, Fukunaga T, Takahashi J, Ohta K (2010) Fault sensitivity analysis. In: Proc. of CHES\u201910, pp 320\u2013334","DOI":"10.1007\/978-3-642-15031-9_22"},{"issue":"4","key":"38_CR13","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1007\/s13389-017-0165-6","volume":"7","author":"S Bhattacharya","year":"2017","unstructured":"Bhattacharya S, Mukhopadhyay D (2017) Formal fault analysis of branch predictors: attacking countermeasures of asymmetric key ciphers. J Cryptogr Eng 7(4):299\u2013310","journal-title":"J Cryptogr Eng"},{"issue":"2","key":"38_CR14","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1109\/JPROC.2005.862424","volume":"94","author":"H Bar-El","year":"2006","unstructured":"Bar-El H, Choukri H, Naccache D, Tunstall M, Whelan C (2006) The sorcerer\u2019s apprentice guide to fault attacks. Proc IEEE 94(2):370\u2013382","journal-title":"Proc IEEE"},{"key":"38_CR15","doi-asserted-by":"crossref","unstructured":"Guilley S, Sauvage L, Danger J-L, Selmane N, Pacalet R (2008) Silicon-level solutions to counteract passive and active attacks. In: 5th Workshop on fault diagnosis and tolerance in cryptography, 2008. FDTC\u201908. IEEE, pp 3\u201317","DOI":"10.1109\/FDTC.2008.18"},{"key":"38_CR16","unstructured":"Zussa L, Dutertre J-M, Cl\u00e9diere J, Robisson B, Tria A et al (2012) Investigation of timing constraints violation as a fault injection means. In: 27th Conference on design of circuits and integrated systems (DCIS). Avignon"},{"key":"38_CR17","doi-asserted-by":"crossref","unstructured":"Korak T, Hoefler M (2014) On the effects of clock and power supply tampering on two microcontroller platforms. In: Proc. of FDTC\u201914, pp 8\u201317","DOI":"10.1109\/FDTC.2014.11"},{"key":"38_CR18","unstructured":"Riscure Inspector FI \n                    https:\/\/www.riscure.com\/security-tools\/inspector-fi\/\n                    \n                  , Online; Accessed 18 May 2017"},{"key":"38_CR19","doi-asserted-by":"crossref","unstructured":"O\u2019Flynn C, Chen ZD (2014) ChipWhisperer: an open-source platform for hardware embedded security research. In: Constructive side-channel analysis and secure design. Springer, pp 243\u2013260","DOI":"10.1007\/978-3-319-10175-0_17"},{"key":"38_CR20","doi-asserted-by":"crossref","unstructured":"Barenghi A, Bertoni G, Parrinello E, Pelosi G (2009) Low voltage fault attacks on the RSA Cryptosystem. In: 2009 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 23\u201331","DOI":"10.1109\/FDTC.2009.30"},{"key":"38_CR21","doi-asserted-by":"crossref","unstructured":"Timmers N, Spruyt A, Witteman M (2016) Controlling PC on ARM using fault injection. In: Fault diagnosis and tolerance in cryptography (FDTC), pp 25\u201335","DOI":"10.1109\/FDTC.2016.18"},{"key":"38_CR22","unstructured":"Hutter M, Schmidt J-M (2013) The temperature side channel and heating fault attacks. In: International conference on smart card research and advanced applications. Springer, pp 219\u2013235"},{"key":"38_CR23","doi-asserted-by":"crossref","unstructured":"Skorobogatov S (2009) Local heating attacks on flash memory devices. In: IEEE International workshop on hardware-oriented security and trust. 2009. HOST\u201909. IEEE, pp 1\u20136","DOI":"10.1109\/HST.2009.5225028"},{"key":"38_CR24","doi-asserted-by":"crossref","unstructured":"Govindavajhala S, Appel AW (2003) Using memory errors to attack a virtual machine. In: 2003 Symposium on security and privacy, 2003. Proceedings. IEEE, pp 154\u2013165","DOI":"10.1109\/SECPRI.2003.1199334"},{"key":"38_CR25","doi-asserted-by":"crossref","unstructured":"Korak T, Hutter M, Ege B, Batina L (2014) Clock glitch attacks in the presence of heating. In: 2014 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 104\u2013114","DOI":"10.1109\/FDTC.2014.20"},{"key":"38_CR26","unstructured":"Skorobogatov S, Anderson RJ (2002) Optical fault induction attacks. In: Revised Papers from the 4th international workshop on cryptographic hardware and embedded systems. Springer-Verlag, pp 2\u201312"},{"key":"38_CR27","unstructured":"Schmidt J-M, Hutter M Optical and EM fault-attacks on CRT-based RSA: concrete results"},{"key":"38_CR28","doi-asserted-by":"crossref","unstructured":"Van Woudenberg JG, Witteman MF, Menarini F (2011) Practical optical fault injection on secure microcontrollers. In: 2011 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 91\u201399","DOI":"10.1109\/FDTC.2011.12"},{"key":"38_CR29","doi-asserted-by":"crossref","unstructured":"Maistri P, Leveugle R, Bossuet L, Aubert A, Fischer V, Robisson B, Moro N, Maurine P, Dutertre J-M, Lisart M (2014) Electromagnetic analysis and fault injection onto secure circuits. In: 2014 22nd International conference on very large scale integration (VLSI-SoC). IEEE, pp 1\u20136","DOI":"10.1109\/VLSI-SoC.2014.7004182"},{"key":"38_CR30","unstructured":"Moro N, Dehbaoui A, Heydemann K, Robisson B, Encrenaz E (2014) Electromagnetic fault injection: towards a fault model on a 32-bit microcontroller, CoRR, vol. abs\/1402.6421. [Online]. Available: arXiv:\n                    1402.6421"},{"key":"38_CR31","unstructured":"Velegalati R, Van Spyk R, van Woudenberg J (2013) Electro magnetic fault injection in practice. In: International Cryptographic module conference (ICMC)"},{"key":"38_CR32","unstructured":"Tang A, Sethumadhavan S, Stolfo S (2017) CLKSCREW: exposing the perils of security-oblivious energy management. In: 26th USENIX security symposium (USENIX Security 17). Vancouver, BC: USENIX Association, pp 1057\u20131074. [Online]. Available: \n                    https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/tang"},{"key":"38_CR33","doi-asserted-by":"crossref","unstructured":"Cai Y, Ghose S, Luo Y, Mai K, Mutlu O, Haratsch EF (2017) Vulnerabilities in MLC NAND flash memory programming: experimental analysis, exploits, and mitigation techniques. In: 2017 IEEE International symposium on high performance computer architecture (HPCA). IEEE, pp 49\u201360","DOI":"10.1109\/HPCA.2017.61"},{"key":"38_CR34","doi-asserted-by":"crossref","unstructured":"Kim Y, Daly R, Kim J, Fallin C, Lee JH, Lee D, Wilkerson C, Lai K, Mutlu O (2014) Flipping bits in memory without accessing them: an experimental study of dram disturbance errors. In: ACM SIGARCH Computer architecture news, vol 42, no 3. IEEE Press, pp 361\u2013372","DOI":"10.1145\/2678373.2665726"},{"key":"38_CR35","unstructured":"Gruss D, Maurice C, Mangard S (2016) Rowhammer. js: a remote software-induced fault attack in javascript. In: Detection of intrusions and malware, and vulnerability assessment. Springer, pp 300\u2013321"},{"key":"38_CR36","doi-asserted-by":"crossref","unstructured":"van der Veen V, Fratantonio Y, Lindorfer M, Gruss D, Maurice C, Vigna G, Bos H, Razavi K, Giuffrida C (2016) Drammer: deterministic rowhammer attacks on mobile platforms. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. ACM, pp 1675\u20131689","DOI":"10.1145\/2976749.2978406"},{"key":"38_CR37","unstructured":"Razavi K, Gras B, Bosman E, Preneel B, Giuffrida C, Bos H (2016) Flip feng shui: hammering a needle in the software stack. In: USENIX Security symposium, pp 1\u201318"},{"key":"38_CR38","unstructured":"Kurmus A, Ioannou N, Papandreou N, Parnell T (2017) From random block corruption to privilege escalation: a filesystem attack vector for rowhammer-like attacks. In: USENIX Workshop on offensive technologies (WOOT)"},{"issue":"12","key":"38_CR39","doi-asserted-by":"publisher","first-page":"2295","DOI":"10.1109\/TVLSI.2012.2231707","volume":"21","author":"D Karaklajic","year":"2013","unstructured":"Karaklajic D, Schmidt J, Verbauwhede I (2013) Hardware designer\u2019s guide to fault attacks. IEEE Trans VLSI Syst 21(12):2295\u20132306","journal-title":"IEEE Trans VLSI Syst"},{"key":"38_CR40","unstructured":"Otto M (2005) Fault attacks and countermeasures. Ph.D. dissertation, University of Paderborn"},{"key":"38_CR41","doi-asserted-by":"crossref","unstructured":"Anceau S, Bleuet P, Cl\u0117di\u0117re J, Maingault L, Rainard J, Tucoulou R (2017) Nanofocused x-ray beam to reprogram secure circuits. In: Cryptographic hardware and embedded systems (CHES), pp 175\u2013188","DOI":"10.1007\/978-3-319-66787-4_9"},{"key":"38_CR42","unstructured":"Barbu G, Thiebeauld H, Guerin V (2010) Attacks on java card 3.0 combining fault and logical attacks. Smart Card Research Adv Appl, 148\u2013163"},{"key":"38_CR43","doi-asserted-by":"crossref","unstructured":"Dehbaoui A, Mirbaha A-P, Moro N, Dutertre J-M, Tria A (2013) Electromagnetic glitch on the AES round counter. In: International Workshop on constructive side-channel analysis and secure design. Springer, pp 17\u201331","DOI":"10.1007\/978-3-642-40026-1_2"},{"key":"38_CR44","doi-asserted-by":"crossref","unstructured":"Riviere L, Najm Z, Rauzy P, Danger J-L, Bringer J, Sauvage L (2015) High precision fault injections on the instruction cache of ARmV7-m architectures. In: 2015 IEEE International symposium on hardware oriented security and trust (HOST). IEEE, pp 62\u201367","DOI":"10.1109\/HST.2015.7140238"},{"issue":"1","key":"38_CR45","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/s13389-016-0136-3","volume":"7","author":"S Nashimoto","year":"2017","unstructured":"Nashimoto S, Homma N, Hayashi Y-i, Takahashi J, Fuji H, Aoki T (2017) Buffer overflow attack with multiple fault injection and a proven countermeasure. J Cryptogr Eng 7(1):35\u201346","journal-title":"J Cryptogr Eng"},{"key":"38_CR46","doi-asserted-by":"publisher","unstructured":"Balasch J, Gierlichs B, Verbauwhede I (2011) An in-depth and black-box characterization of the effects of clock glitches on 8-bit MCUs. In: Workshop on fault diagnosis and tolerance in cryptography (FDTC 2011), pp 105\u2013114. [Online]. Available: \n                    https:\/\/doi.org\/10.1109\/FDTC.2011.9","DOI":"10.1109\/FDTC.2011.9"},{"key":"38_CR47","doi-asserted-by":"crossref","unstructured":"V\u00e9tillard E, Ferrari A (2010) Combined attacks and countermeasures. In: International conference on smart card research and advanced applications. Springer, pp 133\u2013147","DOI":"10.1007\/978-3-642-12510-2_10"},{"key":"38_CR48","unstructured":"Potet M-L, Mounier L, Puys M, Dureuil L (2014) Lazart: a symbolic approach for evaluation the robustness of secured codes against control flow injections. In 2014 IEEE Seventh International conference on software testing, verification and validation (ICST). IEEE, pp 213\u2013222"},{"key":"38_CR49","first-page":"13","volume":"5","author":"H Choukri","year":"2005","unstructured":"Choukri H, Tunstall M (2005) Round reduction using faults. FDTC 5:13\u201324","journal-title":"FDTC"},{"key":"38_CR50","unstructured":"Dutertre J-M, Mirbaha A-P, Naccache D, Ribotta A-L, Tria A, Vaschalde T (2012) Fault round modification analysis of the advanced encryption standard. In: 2012 IEEE International symposium on hardware-oriented security and trust (HOST). IEEE, pp 140\u2013145"},{"key":"38_CR51","doi-asserted-by":"crossref","unstructured":"Biham E, Shamir A (1997) Differential fault analysis of secret key cryptosystems. In: Advances in cryptology\u2014CRYPTO\u201997. Springer, pp 513\u2013525","DOI":"10.1007\/BFb0052259"},{"key":"38_CR52","unstructured":"Hoch JJ, Shamir A (2004) Fault analysis of stream ciphers. In: International Workshop on cryptographic hardware and embedded systems. Springer, pp 240\u2013253"},{"key":"38_CR53","doi-asserted-by":"crossref","unstructured":"Biehl I, Meyer B, M\u00fcller V (2000) Differential fault attacks on elliptic curve cryptosystems. In: Annual International cryptology conference. Springer, pp 131\u2013146","DOI":"10.1007\/3-540-44598-6_8"},{"key":"38_CR54","unstructured":"Taha M, Eisenbarth T (2015) Implementation attacks on post-quantum cryptographic schemes, Cryptology ePrint Archive, Report 2015\/1083. \n                    http:\/\/eprint.iacr.org\/"},{"key":"38_CR55","unstructured":"Giraud C (2004) DFA on AES. In: International conference on advanced encryption standard. Springer, pp 27\u201341"},{"key":"38_CR56","doi-asserted-by":"crossref","unstructured":"Ferretti C, Mella S, Melzani F (2014) The role of the fault model in DFA against AES. In: Proceedings of the workshop on hardware and architectural support for security and privacy (HASP). ACM, p 4","DOI":"10.1145\/2611765.2611769"},{"issue":"1","key":"38_CR57","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1109\/TIFS.2011.2174984","volume":"7","author":"K Sakiyama","year":"2012","unstructured":"Sakiyama K, Li Y, Iwamoto M, Ohta K (2012) Information-theoretic approach to optimal differential fault analysis. IEEE Trans Inf Forens Secur 7(1):109\u2013120","journal-title":"IEEE Trans Inf Forens Secur"},{"issue":"2","key":"38_CR58","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/s13389-012-0046-y","volume":"3","author":"SS Ali","year":"2013","unstructured":"Ali SS, Mukhopadhyay D, Tunstall M (2013) Differential fault analysis of AES: towards reaching its limits. J Cryptogr Eng 3(2):73\u201397","journal-title":"J Cryptogr Eng"},{"key":"38_CR59","doi-asserted-by":"crossref","unstructured":"Ghalaty NF, Yuce B, Taha M, Schaumont P (2014) Differential fault intensity analysis. In: 2014 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 49\u201358","DOI":"10.1109\/FDTC.2014.15"},{"issue":"1","key":"38_CR60","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1109\/TIFS.2011.2169666","volume":"7","author":"Y Li","year":"2012","unstructured":"Li Y, Ohta K, Sakiyama K (2012) New fault-based side-channel attack using fault sensitivity. IEEE Trans Inf Forens Secur 7(1):88\u201397","journal-title":"IEEE Trans Inf Forens Secur"},{"key":"38_CR61","doi-asserted-by":"crossref","unstructured":"Liu Y, Zhang J, Wei L, Yuan F, Xu Q (2015) Dera: yet another differential fault attack on cryptographic devices based on error rate analysis. In: Design Automation conference (DAC). ACM, p 31","DOI":"10.1145\/2744769.2744816"},{"key":"38_CR62","doi-asserted-by":"crossref","unstructured":"Fuhr T, Jaulmes E, Lomn\u00e9 V, Thillard A (2013) Fault attacks on AES with faulty ciphertexts only. In: 2013 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 108\u2013118","DOI":"10.1109\/FDTC.2013.18"},{"key":"38_CR63","doi-asserted-by":"crossref","unstructured":"J\u00e4rvinen K, Blondeau C, Page D, Tunstall M (2012) Harnessing biased faults in attacks on ECC-based signature schemes. In: 2012 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 72\u201382","DOI":"10.1109\/FDTC.2012.13"},{"key":"38_CR64","doi-asserted-by":"crossref","unstructured":"Joye M, Jean-Jacques Q, Sung-Ming Y, Yung M (2002) Observability analysis-detecting when improved cryptosystems fail. In: Cryptographers\u2019 track at the RSA conference. Springer, pp 17\u201329","DOI":"10.1007\/3-540-45760-7_2"},{"issue":"9","key":"38_CR65","doi-asserted-by":"publisher","first-page":"967","DOI":"10.1109\/12.869328","volume":"49","author":"S-M Yen","year":"2000","unstructured":"Yen S-M, Joye M (2000) Checking before output may not be enough against fault-based cryptanalysis. IEEE Trans Comput 49(9):967\u2013970","journal-title":"IEEE Trans Comput"},{"key":"38_CR66","doi-asserted-by":"crossref","unstructured":"Karaklajic D, Fan J, Verbauwhede I (2012) A systematic M safe-error detection in hardware implementations of cryptographic algorithms. In: 2012 IEEE International Symposium on hardware-oriented security and trust (HOST), pp 96\u2013101","DOI":"10.1109\/HST.2012.6224327"},{"key":"38_CR67","doi-asserted-by":"crossref","unstructured":"Bl\u00f6mer J, Seifert J-P (2003) Fault based cryptanalysis of the advanced encryption standard (AES). In: Computer Aided verification. Springer, pp 162\u2013181","DOI":"10.1007\/978-3-540-45126-6_12"},{"key":"38_CR68","doi-asserted-by":"crossref","unstructured":"Boneh D, DeMillo RA, Lipton RJ (1997) On the importance of checking cryptographic protocols for faults. In: International Conference on the theory and applications of cryptographic techniques. Springer, pp 37\u201351","DOI":"10.1007\/3-540-69053-0_4"},{"issue":"1","key":"38_CR69","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/s10623-003-1160-8","volume":"36","author":"M Ciet","year":"2005","unstructured":"Ciet M, Joye M (2005) Elliptic curve cryptosystems in the presence of permanent and transient faults. Des Codes Cryptograph 36(1):33\u201343","journal-title":"Des Codes Cryptograph"},{"key":"38_CR70","unstructured":"Fouque P-A, Lercier R, R\u00e9al D, Valette F (2008) Fault attack on elliptic curve montgomery ladder implementation. In: 5th Workshop on Fault diagnosis and tolerance in cryptography. 2008. FDTC\u201908. IEEE, pp 92\u201398"},{"key":"38_CR71","doi-asserted-by":"crossref","unstructured":"Kocher P, Jaffe J, Jun B (1999) Differential power analysis. In: Advances in cryptology\u2014CRYPTO\u201999. Springer, pp 789\u2013789","DOI":"10.1007\/3-540-48405-1_25"},{"key":"38_CR72","doi-asserted-by":"crossref","unstructured":"Fan J, Guo X, De Mulder E, Schaumont P, Preneel B, Verbauwhede I (2010) State-of-the-art of secure ECC implementations: a survey on known side-channel attacks and countermeasures. In: 2010 IEEE International Symposium on hardware-oriented security and trust (HOST). IEEE, pp 76\u201387","DOI":"10.1109\/HST.2010.5513110"},{"key":"38_CR73","unstructured":"Oswald D (2013) Implementation attacks: from theory to practice, Ph.D dissertation"},{"key":"38_CR74","doi-asserted-by":"crossref","unstructured":"Spreitzer R, Moonsamy V, Korak T, Mangard S (2017) Systematic classification of side-channel attacks: a case study for mobile devices. IEEE Communications Surveys & Tutorials","DOI":"10.1109\/COMST.2017.2779824"},{"key":"38_CR75","doi-asserted-by":"publisher","first-page":"228","DOI":"10.1007\/978-3-540-85053-3_15","volume":"5154","author":"S Tillich","year":"2008","unstructured":"Tillich S, Herbst C (2008) Attacking state-of-the-art software countermeasures\u2014a case study for AES. Lect Notes Comput Sci 5154:228\u2013243","journal-title":"Lect Notes Comput Sci"},{"key":"38_CR76","first-page":"413","volume":"2010","author":"M Rivain","year":"2010","unstructured":"Rivain M, Prouff E (2010) Provably secure higher-order masking of AES. Cryptograph Hardware Embedded Syst CHES 2010:413\u2013427","journal-title":"Cryptograph Hardware Embedded Syst CHES"},{"issue":"1","key":"38_CR77","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/s13389-014-0073-y","volume":"4","author":"V Grosso","year":"2014","unstructured":"Grosso V, Standaert F-X, Faust S (2014) Masking vs. multiparty computation: how large is the gap for AES? J Cryptogr Eng 4(1):47\u201357","journal-title":"J Cryptogr Eng"},{"issue":"6","key":"38_CR78","doi-asserted-by":"publisher","first-page":"760","DOI":"10.1109\/TC.2004.13","volume":"53","author":"B Chevallier-Mames","year":"2004","unstructured":"Chevallier-Mames B, Ciet M, Joye M (2004) Low-cost solutions for preventing simple side-channel analysis: side-channel atomicity. IEEE Trans Comput 53(6):760\u2013768","journal-title":"IEEE Trans Comput"},{"key":"38_CR79","first-page":"61","volume":"2006","author":"S Skorobogatov","year":"2006","unstructured":"Skorobogatov S (2006) Optically enhanced position-locked power analysis. Cryptograph Hardware Embedded Syst-CHES 2006:61\u201375","journal-title":"Cryptograph Hardware Embedded Syst-CHES"},{"key":"38_CR80","doi-asserted-by":"crossref","unstructured":"Amiel F, Villegas K, Feix B, Marcel L (2007) Passive and active combined attacks: combining fault attacks and side channel analysis. In: Workshop on Fault diagnosis and tolerance in cryptography, 2007. FDTC 2007. IEEE, pp 92\u2013102","DOI":"10.1109\/FDTC.2007.12"},{"key":"38_CR81","doi-asserted-by":"crossref","unstructured":"Clavier C, Feix B, Gagnerot G, Roussellet M (2010) Passive and active combined attacks on AES combining fault attacks and side channel analysis. In: 2010 Workshop on fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 10\u201319","DOI":"10.1109\/FDTC.2010.17"},{"key":"38_CR82","doi-asserted-by":"crossref","unstructured":"Roche T, Lomn\u00e9 V, Khalfallah K (2011) Combined fault and side-channel attack on protected implementations of AES. Smart Card Res Adv Appl, 65\u201383","DOI":"10.1007\/978-3-642-27257-8_5"},{"key":"38_CR83","doi-asserted-by":"crossref","unstructured":"Dassance F, Venelli A (2012) Combined fault and side-channel attacks on the AES key schedule. In: 2012 Workshop on Fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 63\u201371","DOI":"10.1109\/FDTC.2012.10"},{"key":"38_CR84","first-page":"305","volume":"6212","author":"J-M Schmidt","year":"2010","unstructured":"Schmidt J-M, Tunstall M, Avanzi RM, Kizhvatov I, Kasper T, Oswald D (2010) Combined implementation attack resistant exponentiation. LATINCRYPT 6212:305\u2013322","journal-title":"LATINCRYPT"},{"key":"38_CR85","unstructured":"Yao Y, Yang M, Patrick C, Yuce B, Schaumont P (2018) Fault-assisted side-channel analysis of masked implementations (to appear). In IEEE International Symposium on hardware oriented security and trust (HOST), 2018. IEEE, pp 72\u201377"},{"key":"38_CR86","doi-asserted-by":"crossref","unstructured":"Durumeric Z, Kasten J, Adrian D, Halderman JA, Bailey M, Li F, Weaver N, Amann J, Beekman J, Payer M, Paxson V (2014) The matter of heartbleed. In: Internet Measurement conference (IMC), pp 475\u2013488","DOI":"10.1145\/2663716.2663755"},{"key":"38_CR87","unstructured":"Obermaier J, Tatschner S (2017) Shedding too much light on a microcontroller\u2019s firmware protection. In: USENIX Workshop on offensive technologies (WOOT)"},{"key":"38_CR88","unstructured":"Scott ME Glitchy descriptor firmware grab, \n                    https:\/\/www.youtube.com\/watch?v=TeCQatNcF20\n                    \n                  , Online; Accessed 14 Nov 2017"},{"key":"38_CR89","doi-asserted-by":"crossref","unstructured":"Bouffard G, Iguchi-Cartigny J, Lanet J-L (2011) Combined software and hardware attacks on the java card control flow. In CARDIS, vol 7079. Springer, pp 283\u2013296","DOI":"10.1007\/978-3-642-27257-8_18"},{"key":"38_CR90","doi-asserted-by":"crossref","unstructured":"Vasselle A, Thiebeauld H, Maouhoub Q, Morisset A, Ermeneux S (2017) Laser-induced fault injection on smartphone bypassing the secure boot. In: 2017 Workshop on Fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 41\u201348","DOI":"10.1109\/FDTC.2017.18"},{"key":"38_CR91","doi-asserted-by":"crossref","unstructured":"Timmers N, Mune C (2017) Escalating privileges in Linux using voltage fault injection. In: Fault Diagnosis and tolerance in cryptography (FDTC), pp 25\u201335","DOI":"10.1109\/FDTC.2017.16"},{"key":"38_CR92","unstructured":"Seaborn M, Dullien T (2015) Exploiting the dram rowhammer bug to gain kernel privileges. Black Hat"},{"key":"38_CR93","doi-asserted-by":"crossref","unstructured":"San Pedro M, Soos M, Guilley S (2011) Fire: fault injection for reverse engineering. In: WISTP. Springer, pp 280\u2013293","DOI":"10.1007\/978-3-642-21040-2_20"},{"key":"38_CR94","doi-asserted-by":"crossref","unstructured":"Le Bouder H, Guilley S, Robisson B, Tria A (2014) Fault injection to reverse engineer DES-like cryptosystems. In: Foundations and practice of security. Springer, pp 105\u2013121","DOI":"10.1007\/978-3-319-05302-8_7"},{"key":"38_CR95","doi-asserted-by":"crossref","unstructured":"Clavier C, Wurcker A (2013) Reverse engineering of a secret AES-like cipher by ineffective fault analysis. In: 2013 Workshop on Fault diagnosis and tolerance in cryptography (FDTC). IEEE, pp 119\u2013128","DOI":"10.1109\/FDTC.2013.16"},{"key":"38_CR96","unstructured":"Jacob M, Boneh D, Felten E (2002) Attacking an obfuscated cipher by injecting faults. In: Digital Rights management workshop, vol 2696, pp 16\u201331"},{"issue":"6","key":"38_CR97","doi-asserted-by":"publisher","first-page":"928","DOI":"10.1109\/TCAD.2015.2391773","volume":"34","author":"F Courbon","year":"2015","unstructured":"Courbon F, Fournier JJ, Loubet-Moundi P, Tria A (2015) Combining image processing and laser fault injections for characterizing a hardware AES. IEEE Trans Comput-aided Des Integr Circ Syst 34(6):928\u2013936","journal-title":"IEEE Trans Comput-aided Des Integr Circ Syst"},{"key":"38_CR98","unstructured":"Common Criteria Community \n                    https:\/\/www.commoncriteriaportal.org\n                    \n                  , Online Sccessed 18 Jan 2018"},{"key":"38_CR99","unstructured":"United States Government Accountability Office, Information assurance, national partnership offers benefits, but faces considerable challenges, Technical Report GAO-06-392, 2006. \n                    http:\/\/www.gao.gov\/new.items\/d06392.pdf"},{"key":"38_CR100","unstructured":"EMVCo Product Approval Processes \n                    http:\/\/nvlpubs.nist.gov\/nistpubs\/FIPS\/NIST.FIPS.140-2.pdf\n                    \n                  , Online Accessed 18 Jan 2018"},{"key":"38_CR101","unstructured":"National Institute of Standards and Technology (NIST), Security requirements for cryptographic modules, FIPS PUB 140-2, 2001. \n                    https:\/\/www.emvco.com\/processes-forms\/product-approval\/"}],"container-title":["Journal of Hardware and Systems Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s41635-018-0038-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s41635-018-0038-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s41635-018-0038-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,17]],"date-time":"2020-05-17T05:30:25Z","timestamp":1589693425000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s41635-018-0038-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,5,10]]},"references-count":101,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,6]]}},"alternative-id":["38"],"URL":"https:\/\/doi.org\/10.1007\/s41635-018-0038-1","relation":{},"ISSN":["2509-3428","2509-3436"],"issn-type":[{"value":"2509-3428","type":"print"},{"value":"2509-3436","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,5,10]]},"assertion":[{"value":"2 February 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 April 2018","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 May 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}