Formal Modeling Of Clock Glitch Attacks For Security Verification Of Processors H/F

CEA Industrie
Grenoble, France
about 1 month ago
Apply on www.hellowork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Embedded Software Hardware Design Information Technology

Job description

La conscience des responsabilités

  • La coopération
  • La curiosité

Research context

Embedded processors are increasingly deployed in security-critical applications, making their protection against physical attacks a major challenge. Among these threats, clock glitch attacks remain a powerful and accessible fault injection technique, especially relevant for IoT and embedded systems due to their low-cost implementation.

Recent research at Inria Rennes led to the development of TRAITOR [1-2], an experimental platform capable of generating synchronous clock perturbations and characterizing their impact on processor microarchitectures. These experiments suggest that clock glitches induce sampling faults on sensitive sequential elements, but the corresponding fault models remain to be formally validated.

In parallel, CEA-List has developed µArchiFI [3-4], a formal framework enabling pre-silicon analysis of fault injection effects at RTL level, from hardware implementation details up to software execution. While µArchiFI currently supports fault models representative of laser-based attacks, formal modeling of clock glitch effects remains an open challenge.

Research objective and activities

The goal of this postdoctoral project is to develop the first formal methodology for analyzing processor robustness against clock glitch attacks by combining experimental characterization of clock glitches using the TRAITOR platform, and formal verification of their impact using the µArchiFI framework. The project will establish a bridge between physical fault injection experiments and formal security verification, enabling rigorous evaluation of hardware/software countermeasures.

The postdoctoral researcher will contribute to the following tasks:

  • Formal modeling of clock glitch effects. Develop a discrete fault model suitable for formal verification, based on the Energy Threshold Fault Model (ETFM) and experimental observations. The objective is to represent the effects of clock-induced sampling faults while maintaining the scalability of formal analysis.
  • Experimental validation of fault models. Conduct clock glitch injection campaigns using TRAITOR and compare experimental results with µArchiFI predictions. This iterative approach will refine and validate the formal models.
  • Security analysis of protected processors. Apply the developed methodology to secure embedded processors such as RISC-V CV32E40S and OpenTitan Secure Ibex. The analysis will identify potential vulnerabilities and evaluate the effectiveness of hardware/software countermeasures against clock glitch attacks.

Research environment

The researcher will join a joint effort between CEA-List (Grenoble, Saclay) and Inria Rennes (PACAP team), combining expertise in: hardware security, fault injection attacks, processor microarchitecture analysis, formal verification, embedded systems, numerical systems designs. The project builds on complementary developments from both teams: TRAITOR for experimental fault injection and µArchiFI for formal securi

Requirements

Applicants should hold a PhD in computer science, electrical engineering, embedded systems, or a related field.Strong candidates will have experience in one or more of the following areas:hardware security and fault injection attacks,formal methods and verification,RTL design and digital circuits,processor architectures (RISC-V experience is a plus),embedded software.The position offers an opportunity to work at the intersection of hardware security, formal methods, and secure processor design, combining theoretical research with experimental validation.Location: CEA-List (Grenoble or Paris-Saclay)Duration: 12 months with possible extensionsKeywords: Hardware security · Clock glitch attacks · Fault injection · Formal verification · RISC-V · Secure processors · Embedded systems · RTL analysis, Applicants should hold a PhD in computer science, electrical engineering, embedded systems, or a related field.

Strong candidates will have experience in one or more of the following areas:

hardware security and fault injection attacks, formal methods and verification, RTL design and digital circuits, processor architectures (RISC-V experience is a plus), embedded software. The position offers an opportunity to work at the intersection of hardware security, formal methods, and secure processor design, combining theoretical research with experimental validation.

Benefits & conditions

Location: CEA-List (Grenoble or Paris-Saclay)

Duration: 12 months with possible extensions

Keywords: Hardware security · Clock glitch attacks · Fault injection · Formal verification · RISC-V · Secure processors · Embedded systems · RTL analysis

About the company

Le CEA est un acteur majeur de la recherche, au service des citoyens, de l’économie et de l’Etat.

Il apporte des solutions concrètes à leurs besoins dans quatre domaines principaux : transition énergétique, transition numérique, technologies pour la médecine du futur, défense et sécurité sur un socle de recherche fondamentale. Le CEA s’engage depuis plus de 75 ans au service de la souveraineté scientifique, technologique et industrielle de la France et de l’Europe pour un présent et un avenir mieux maîtrisés et plus sûrs.

Implanté au coeur des territoires équipés de très grandes infrastructures de recherche, le CEA dispose d’un large éventail de partenaires académiques et industriels en France, en Europe et à l’international.

Les 20 000 collaboratrices et collaborateurs du CEA partagent trois valeurs fondamentales, Le CEA est un acteur majeur de la recherche, au service des citoyens, de l’économie et de l’Etat.Il apporte des solutions concrètes à leurs besoins dans quatre domaines principaux : transition énergétique, transition numérique, technologies pour la médecine du futur, défense et sécurité sur un socle de recherche fondamentale. Le CEA s’engage depuis plus de 75 ans au service de la souveraineté scientifique, technologique et industrielle de la France et de l’Europe pour un présent et un avenir mieux maîtrisés et plus sûrs.Implanté au coeur des territoires équipés de très grandes infrastructures de recherche, le CEA dispose d’un large éventail de partenaires académiques et industriels en France, en Europe et à l’international. Les 20 000 collaboratrices et collaborateurs du CEA partagent trois valeurs fondamentales : - La conscience des responsabilités- La coopération- La curiosité

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.hellowork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Aligning hardware development cycles with software evolution

Stephen Jones · Coffee With Developers

5:59 min

Compiling routing logic into certified safety microcontrollers

Ulrich Wurstbauer +1 · LIVE

3:06 min

Moving from basic embedded software to system functionalities

Réka Leisztner Réka Leisztner · World Congress 2025

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:34 min

Software-driven hardware design and microcontroller virtualization

Georg Kühberger +1 · LIVE

1:14 min

Addressing automotive mission-critical safety in embedded software development

David Romić · World Congress 2023

Videos

See all

Related articles

See all