Formal Modeling of Clock Glitch Attacks for Security Verification of Processors H/F

CEA

Grenoble

Sur place

EUR 36 000 - 45 000

Plein temps

14 jours+
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV personnalisé et une lettre de motivation en environ une minute.

Passez les filtres ATS

Résumé du poste

CEA-List (Grenoble) invites applications for a 12-month postdoctoral position focused on formal modeling of clock glitch attacks for security verification of processors. The project will bridge physical fault injection experiments with formal verification to evaluate hardware/software countermeasures on RISC-V CV32E40S and OpenTitan Ibex.

Applicants should hold a PhD in computer science, electrical engineering, or embedded systems and have experience in hardware security, fault injection, formal

Qualifications

  • PhD in related field required.
  • Experience in hardware security and fault injection is desirable.

Responsabilités

  • Formally model clock glitch effects based on experiments and ETFM.
  • Validate fault models experimentally using TRAITOR and µArchiFI.
  • Analyze protected processors (e.g., RISC-V CV32E40S, OpenTitan Ibex) and assess countermeasures.

Connaissances

Hardware security
Fault injection
Formal verification
RTL design
RISC-V
Embedded software
Processor architectures

Formation

PhD in computer science/engineering

Description du poste

Formal Modeling of Clock Glitch Attacks for Security Verification of Processors H/F
Category

Mathematics, information, scientific, software

Job title

Formal Modeling of Clock Glitch Attacks for Security Verification of Processors H/F

Executive

12

Research context

Embedded processors are increasingly deployed in security-critical applications, making their protection against physical attacks a major challenge. Among these threats, clock glitch attacks remain a powerful and accessible fault injection technique, especially relevant for IoT and embedded systems due to their low-cost implementation.

Recent research at Inria Rennes led to the development of TRAITOR [1-2], an experimental platform capable of generating synchronous clock perturbations and characterizing their impact on processor microarchitectures. These experiments suggest that clock glitches induce sampling faults on sensitive sequential elements, but the corresponding fault models remain to be formally validated.

In parallel, CEA-List has developed µArchiFI [3-4], a formal framework enabling pre-silicon analysis of fault injection effects at RTL level, from hardware implementation details up to software execution. While µArchiFI currently supports fault models representative of laser-based attacks, formal modeling of clock glitch effects remains an open challenge.

Research objective and activities

The goal of this postdoctoral project is to develop the first formal methodology for analyzing processor robustness against clock glitch attacks by combining experimental characterization of clock glitches using the TRAITOR platform, and formal verification of their impact using the µArchiFI framework. The project will establish a bridge between physical fault injection experiments and formal security verification, enabling rigorous evaluation of hardware/software countermeasures.

The postdoctoral researcher will contribute to the following tasks:

  • Formal modeling of clock glitch effects. Develop a discrete fault model suitable for formal verification, based on the Energy Threshold Fault Model (ETFM) and experimental observations. The objective is to represent the effects of clock-induced sampling faults while maintaining the scalability of formal analysis.
  • Experimental validation of fault models. Conduct clock glitch injection campaigns using TRAITOR and compare experimental results with µArchiFI predictions. This iterative approach will refine and validate the formal models.
  • Security analysis of protected processors. Apply the developed methodology to secure embedded processors such as RISC-V CV32E40S and OpenTitan Secure Ibex. The analysis will identify potential vulnerabilities and evaluate the effectiveness of hardware/software countermeasures against clock glitch attacks.
Research environment

The researcher will join a joint effort between CEA-List (Grenoble, Saclay) and Inria Rennes (PACAP team), combining expertise in: hardware security, fault injection attacks, processor microarchitecture analysis, formal verification, embedded systems, numerical systems designs. The project builds on complementary developments from both teams: TRAITOR for experimental fault injection and µArchiFI for formal securi

Applicants should hold a PhD in computer science, electrical engineering, embedded systems, or a related field.

Strong candidates will have experience in one or more of the following areas:

  • hardware security and fault injection attacks
  • formal methods and verification
  • RTL design and digital circuits
  • processor architectures (RISC-V experience is a plus)
  • embedded software

The position offers an opportunity to work at the intersection of hardware security, formal methods, and secure processor design, combining theoretical research with experimental validation.

Location

Grenoble

Location: CEA-List (Grenoble or Paris-Saclay)

Duration: 12 months with possible extensions

Keywords: Hardware security, Clock glitch attacks, Fault injection, Formal verification, RISC-V, Secure processors, Embedded systems, RTL analysis

Site

Grenoble

Recommended training

Master's or doctorate degree

Requester

01/10/2026

Reference

2026-41245

Organisation

The French Alternative Energies and Atomic Energy Commission (CEA) is a key player in research, development and innovation in four main areas: defence and security, nuclear energy (fission and fusion), technological research for industry, fundamental research in the physical sciences and life sciences. Drawing on its widely acknowledged expertise, and thanks to its 16000 technicians, engineers, researchers and staff, the CEA actively participates in collaborative projects with a large number of academic and industrial partners. The CEA is established in ten centers spread throughout France.

The CEA's technology research division (DRT) develop a broad portfolio of technologies in the fields of information and communication, energy and health. CEA technology research division leverages a unique innovation-driven culture and unrivalled expertise to develop and disseminate new technologies for industry, effectively bridging the gap between the worlds of research and industry. CEA-List is a research institute specialized in smart digital systems, located in the heart of the Paris-Saclay science and technology cluster, and in Grenoble in the heard of FrenchAlps.

Within the DSCIN department of CEA List, the LECA and LFIM laboratories invest R&D efforts in the analysis of the robustness of embedded systems against fault-injection attacks.

The Innovative Functions for Mixed Circuits Laboratory (LFIM) is focused on electronic design and software systems that meet requirements in terms of energy efficiency, size, operating reliability, real-time performance and safety. These systems are used in a wide range of fields, including embedded systems (transport, energy, connected objects), and consumer and professional electronics. The technologies developed within the laboratory draw on the latest advances in nanoelectronics, automation, embedded artificial intelligence and cryptographic acceleration. They respond to the societal challenges of sustainable development and trust in digital systems, while offering new applications made possible by new information and communication technologies. To this end, the LFIM studies, designs and integrates digital and mixed processing architectures on silicon for application needs in the fields of IoT, radio frequency circuits and cyber-physical systems.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Secure Processor Verification via Clock Glitch Modeling
Secure Processor Verification via Clock Glitch Modeling

CEA • Grenoble

Sur place
EUR 36 000 - 45 000
Stage de fin d'études (Ecole d'Ingénieurs / Master 2)
Stage de fin d'études (Ecole d'Ingénieurs / Master 2)

CEA • Grenoble

Sur place
EUR 12 000 - 17 000
Verification Engineer
Verification Engineer

Codasip • Villeneuve-Loubet

Hybride
EUR 55 000 - 85 000
Ingénieur-Chercheur Sécurité des composants H/F
Ingénieur-Chercheur Sécurité des composants H/F

CEA • Grenoble

Sur place
EUR 55 000 - 75 000
STAGE 6 MOIS CYBERSECURITÉ H/F
STAGE 6 MOIS CYBERSECURITÉ H/F

CEA • Grenoble

Sur place
EUR 7 800 - 12 000
PhD in microelectronics – Security sensors and countermeasures for detecting physical X-ray attacks
PhD in microelectronics – Security sensors and countermeasures for detecting physical X-ray attacks

Grenoble INP - Institute of Engineering • France

Sur place
EUR 32 000 - 42 000
Senior/Principal Design Verification Engineer
Senior/Principal Design Verification Engineer

Codasip • Nice

Sur place
EUR 70 000 - 90 000
Stage - Modélisation de mémoires DRAM haute performance pour de l'émulation-Grenoble-H/F
Stage - Modélisation de mémoires DRAM haute performance pour de l'émulation-Grenoble-H/F

CEA • Grenoble

Sur place
EUR 10 000 - 13 000
CENTRALE LYON - Post Doctoral Open and Flexible System-Level Evaluation Framework for Emerging AI Computing Architectures
CENTRALE LYON - Post Doctoral Open and Flexible System-Level Evaluation Framework for Emerging AI Computing Architectures

CENTRALE LYON • Écully

Hybride
EUR 38 000 - 54 000
CENTRALE LYON - Post Doctoral Open and Flexible System-Level Evaluation Framework for Emerging AI Computing Architectures
CENTRALE LYON - Post Doctoral Open and Flexible System-Level Evaluation Framework for Emerging AI Computing Architectures

ecolecentraledelyon • Écully

Hybride
EUR 40 000 - 56 000