Activez les alertes d’offres d’emploi par e-mail !
Mulipliez les invitations à des entretiens
Une entreprise innovante recherche un chercheur postdoctoral motivé pour travailler sur des contrats de sécurité pour les modèles d'attaquants par injection de fautes. Ce rôle implique la définition et la mise en œuvre de contrats de sécurité, soutenant une approche multi-niveaux pour analyser les contre-mesures hybrides. Le candidat idéal aura un doctorat en informatique ou dans un domaine connexe, avec une expertise en attaques par injection de fautes et en vérification formelle. Rejoignez une équipe dynamique dans le cadre du projet TwinSec et contribuez à des méthodologies et outils de pointe pour la sécurité microarchitecturale.
Fault-injection attacks exploit hardware perturbations to move a processor into unexpected states or execution paths, potentially exposing secrets or escalating privileges. Recent research has highlighted the need to consider the consequences of fault injection in the processor micro-architecture. In this area, we have developed pre-silicon methodologies and tools that have shown to be successful to find microarchitectural vulnerabilities and/or formally prove the robustness, for a given fault model, of various RISC-V based processors. We have also developed binary-level program analysis methods (BINSEC/ASE) able to efficiently take into account some predefined ISA-level fault injection models. Yet, a major and common challenge of all these approaches lies in the state space generated by the modeling of processor’s behavior executing a sequence of instructions and under a fault model.
Objective.
This position focuses on defining and implementing security contracts for fault-injection attacker models. The proposed security contracts should support a multi-level approach, enabling the design and analysis of hybrid countermeasures, while also bridging fault models derived from experimental characterizations to the software level. They will also be used to revisit our k-fault-resistant partitioning methodology to analyze multi-fault models within complex systems, such as applications processors, and to help our binary-level code analyzers to handle more generic classes of fault models.
Within the TwinSec research project, your main missions will be to:
We are seeking a motivated researcher with:
In accordance with the commitments made by the CEA in favor of the integration of people with disabilities, this job is open to everyone.
The TwinSec project is also recruiting a PhD candidate to work on the topic of security contracts for fault-injection attacker models. The Post-doc researcher will participate in the co-supervision of this PhD project and contribute to the development of the methodologies and tools designed by the PhD student.