<?xml version="1.0" encoding="utf-8"?>
<raweb xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="en" year="2013">
  <identification id="secsi" isproject="true">
    <shortname>SECSI</shortname>
    <projectName>Security of information systems</projectName>
    <theme-de-recherche>Programs, Verification and Proofs</theme-de-recherche>
    <domaine-de-recherche>Algorithmics, Programming, Software and Architecture</domaine-de-recherche>
    <urlTeam>http://www.lsv.ens-cachan.fr/~goubault/SECSI/secsi_en.html</urlTeam>
    <datefermeture>2013 December 31</datefermeture>
    <datecreation type="Project-Team">2002 November 15</datecreation>
    <dateupdate type="Team">2013 January 01</dateupdate>
    <structure_exterieure type="Labs">
      <libelle>Laboratoire specification et vérification (LSV)</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>CNRS</libelle>
    </structure_exterieure>
    <structure_exterieure type="Organism">
      <libelle>Ecole normale supérieure de Cachan</libelle>
    </structure_exterieure>
    <UR name="Saclay"/>
    <keywords>
      <term>Formal Methods</term>
      <term>Automated Theorem Proving</term>
      <term>Cryptography</term>
      <term>Protocols</term>
      <term>Model-checking</term>
      <term>Security</term>
    </keywords>
    <moreinfo>
      <p>SECSI is a project common to Inria and the Laboratoire Spécification et
Vérification (LSV), itself a common lab between CNRS (UMR 8643) and the
École Normale Supérieure (ENS) de Cachan. The team was created
in 2001, and became an Inria projet in December, 2002.</p>
    </moreinfo>
  </identification>
  <team id="uid1">
    <person key="secsi-2005-id18078">
      <firstname>Jean</firstname>
      <lastname>Goubault-Larrecq</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Team leader, ENS Cachan, Professor</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secsi-2005-id18250">
      <firstname>Stéphanie</firstname>
      <lastname>Delaune</lastname>
      <categoryPro>Chercheur</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>CNRS, Researcher</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="parsifal-2005-id18148">
      <firstname>David</firstname>
      <lastname>Baelde</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>ENS Cachan, Maître de Conférences</moreinfo>
    </person>
    <person key="secsi-2005-id18187">
      <firstname>Hubert</firstname>
      <lastname>Comon-Lundh</lastname>
      <categoryPro>Enseignant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>ENS Cachan, Professor</moreinfo>
      <hdr>oui</hdr>
    </person>
    <person key="secsi-2013-idp140536989930512">
      <firstname>Pierre-Arnaud</firstname>
      <lastname>Sentucq</lastname>
      <categoryPro>Technique</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria, granted by DGA SEREBC Bruz, from Apr 2013</moreinfo>
    </person>
    <person key="secsi-2013-idp140536989932816">
      <firstname>Lucca</firstname>
      <lastname>Hirschi</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>ENS Cachan, from Sep. 2013</moreinfo>
    </person>
    <person key="secsi-2013-idp140536989935120">
      <firstname>Rémy</firstname>
      <lastname>Chrétien</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>ANR JCJC VIP grant, Started Oct. 2012</moreinfo>
    </person>
    <person key="cassis-2011-idp140243370899792">
      <firstname>Guillaume</firstname>
      <lastname>Scerri</lastname>
      <categoryPro>PhD</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>ERC grant ProSecure, Started Oct. 2011</moreinfo>
    </person>
    <person key="mexico-2012-idp140466565467440">
      <firstname>Thida</firstname>
      <lastname>Iem</lastname>
      <categoryPro>Assistant</categoryPro>
      <research-centre>Saclay</research-centre>
      <moreinfo>Inria</moreinfo>
    </person>
  </team>
  <presentation id="uid2">
    <bodyTitle>Overall Objectives</bodyTitle>
    <subsection id="uid3" level="1">
      <bodyTitle>Overall Objectives</bodyTitle>
      <p>SECSI is a common project between Inria Saclay and the LSV
(Laboratoire Spécification et Vérification), itself a common
research unit of CNRS (UMR 8643) and the ENS (École Normale
Supérieure) de Cachan.</p>
      <p>The SECSI project is a research project on verification algorithms
for information system security, with two main thrusts: verification
of cryptographic protocols, intrusion detection.
</p>
    </subsection>
  </presentation>
  <fondements id="uid4">
    <bodyTitle>Research Program</bodyTitle>
    <subsection id="uid5" level="1">
      <bodyTitle>Foundations</bodyTitle>
      <p>Computer security has become more and more pressing as a concern since
the mid 1990s. There are several reasons to this: cryptography is no
longer a <i>chasse réservée</i> of the military, and has become
ubiquitous; and computer networks (e.g., the Internet) have grown
considerably and have generated numerous opportunities for attacks and
misbehaviors, notably.</p>
      <p>The aim of the SECSI project is to <i>develop logic-based
verification techniques for security properties of computer systems
and networks</i>. Let us explain what this means, and what this does
not mean.</p>
      <p>First, the scope of the research at SECSI started as a rather broad
subset of computer security, although the core of SECSI's activities
has always been on verifying cryptographic protocols.</p>
      <p>We took this for granted in 2006, and decided to concentrate
on the latter. This already includes a vast number of concerns.</p>
      <p>First, there is a plethora of distinct <i>security properties</i> one
may wish to verify. Beyond the standard properties of secrecy (weak
or strong forms), or authentication, one considers anonymity, fairness
in contract-signing, and the subtle security properties involved in
electronic voting such as accountability, receipt-freeness, resistance
to coercion, or user verifiability. Some of these properties are
trace properties, some are not, and are therefore more complex to
state and verify.</p>
      <p>Second, there are many available <i>models</i>. SECSI started with
the rather simple symbolic models of security known today as Dolev-Yao
models. One must then look at process algebra models (spi-calculus,
applied pi-calculus), which allow for a symbolic treatment of more
complex properties, especially those that are not trace properties.
And one must also look at the computational models favored by
cryptographers, e.g., the game-based approaches and the universal
composability/simulatability approaches. They are more realistic in
terms of security, but less directly amenable to automated
verification. One of the features of computational models that makes
them more complex is the need for computing, and bounding
probabilities of certain events. This led us into contributing to the
field of verification of probabilistic systems. One must also look at
the relations between these models.</p>
      <p>Third, there are many important <i>applications</i>. While SECSI
started looking at the rather simple and now mundane confidentiality
and authentication protocols, two important application domains have
emerged: the verification of electronic voting protocols, and the
verification of cryptographic APIs.</p>
      <p>Apart from cryptographic protocols, the initial vision of the SECSI
project was that computer security, being a global concern, should be
taken as a whole, as far as possible. This is why one of the initial
objectives of SECSI included topic in intrusion detection, again seen
from the logical point of view.</p>
      <p>One should remember the following. First, one of the key phrases in
the SECSI motto is “logic-based”. It is a founding theme of SECSI
that logic matters in security, and opportunities are to be grabbed.
Another key phrase is “verification techniques”. The expertise of
SECSI is not in designing protocols or security architectures.
Verifying protocols, formally, is an arduous task already, and has
proved to be an extremely rich area.</p>
    </subsection>
    <subsection id="uid6" level="1">
      <bodyTitle>Objectives</bodyTitle>
      <p>SECSI has five objectives:</p>
      <simplelist>
        <li id="uid7">
          <p noindent="true">Objective 1: symbolic verification of cryptographic protocols.
Tree-automata based methods, automated deduction, and
approximate/exact cryptographic protocol verification in the
Dolev-Yao model. Enriching the Dolev-Yao model with algebraic
theories, and associated decision problems.</p>
        </li>
        <li id="uid8">
          <p noindent="true">Objective 2: verification of cryptographic protocols in
computational models. Computational soundness of formal models
(Dolev-Yao, applied pi-calculus).</p>
        </li>
        <li id="uid9">
          <p noindent="true">Objective 3: security of group protocols, fair exchange, voting
and other protocols. Other security properties, other security
models. Security properties based on notions of indistinguishability.</p>
        </li>
        <li id="uid10">
          <p noindent="true">Objective 4: probabilistic transition systems. Security in the
presence of probabilistic and demonic non-deterministic choices.</p>
        </li>
        <li id="uid11">
          <p noindent="true">Objective 5: intrusion detection, network and host protection
in the large.</p>
        </li>
      </simplelist>
    </subsection>
  </fondements>
  <domaine id="uid12">
    <bodyTitle>Application Domains</bodyTitle>
    <subsection id="uid13" level="1">
      <bodyTitle>Application Domains</bodyTitle>
      <p>Here are a few examples of applications of research done in SECSI:</p>
      <simplelist>
        <li id="uid14">
          <p noindent="true">Security of electronic voting schemes: the case of the Helios
protocol, used in particular at University of Louvain-la-Neuve
(2010) and at the International Association for Cryptographic
Research (IACR).</p>
        </li>
        <li id="uid15">
          <p noindent="true">Security of the protocols involved in the TPM (Trusted
Platform Module) chip, a chip present in most PC laptops today,
and which is meant to act as a trusted base.</p>
        </li>
        <li id="uid16">
          <p noindent="true">Security of the European electronic passport—and the
discovery of an attack on the French implementation of it.</p>
        </li>
        <li id="uid17">
          <p noindent="true">Intrusion detection with the Orchids tool: several interested
partners, among which EADS Cassidian, Thales, Galois Inc. (USA),
the French Direction Générale de l'Armement (DGA).</p>
        </li>
      </simplelist>
    </subsection>
  </domaine>
  <logiciels id="uid18">
    <bodyTitle>Software and Platforms</bodyTitle>
    <subsection id="uid19" level="1">
      <bodyTitle>Orchids</bodyTitle>
      <participants>
        <person key="secsi-2005-id18078">
          <firstname>Jean</firstname>
          <lastname>Goubault-Larrecq</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
        <person key="secsi-2013-idp140536989930512">
          <firstname>Pierre-Arnaud</firstname>
          <lastname>Sentucq</lastname>
        </person>
      </participants>
      <p>The ORCHIDS real-time intrusion detection system was created in
2003-04 at SECSI. Orchids is at the core of a contract between
Inria and DGA, started in April 2013, for three years.</p>
      <p>Progress in 2013 included:</p>
      <simplelist>
        <li id="uid20">
          <p noindent="true">Creation of a collection of VirtualBox virtual machines with a
pre-installed instance of Orchids, for easy testing and/or installation.</p>
        </li>
        <li id="uid21">
          <p noindent="true">A collection of scripts, allowing one to rebuild the above cited
virtual machines automatically from the sources, as a nightly
build (in progress).</p>
        </li>
        <li id="uid22">
          <p noindent="true">A new algorithm for evaluating the worst-case thread complexity of
detection by Orchids, whose first principles were laid out by Jean
Goubault-Larrecq, and with two prototype implementations done by
Jean-Philippe Lachance, a young L2 intern from Université Laval,
Québec. The purpose is to warn users of the complexity of the
tasks they delegate to Orchids, and to avert denial of service
attacks on Orchids itself.</p>
        </li>
      </simplelist>
      <p>Objectives for 2014 include:</p>
      <simplelist>
        <li id="uid23">
          <p noindent="true">Simplifying the Orchids installation process, which has gotten
complicated over the years.</p>
        </li>
        <li id="uid24">
          <p noindent="true">Implementing a frontend tool incorporating the full-fledged
version of the worst-case thread complexity algorithm mentioned
above, plus some other checks.</p>
        </li>
      </simplelist>
    </subsection>
  </logiciels>
  <resultats id="uid25">
    <bodyTitle>New Results</bodyTitle>
    <subsection id="uid26" level="1">
      <bodyTitle>Dishonest keys (Objective 2)</bodyTitle>
      <participants>
        <person key="secsi-2005-id18187">
          <firstname>Hubert</firstname>
          <lastname>Comon-Lundh</lastname>
        </person>
        <person key="cassis-2011-idp140243370899792">
          <firstname>Guillaume</firstname>
          <lastname>Scerri</lastname>
        </person>
      </participants>
      <p>One of the main issues in the formal verification of the security
protocols is the validity (and scope) of the formal
model. Otherwise, it may happen that a protocol is proved and later
someone finds an attack. This paradoxical situation may happen when
the formal model used in the proof is too abstract.</p>
      <p>A main stream of research therefore consists in proving
full abstraction results (also called <i>soundness</i>): if the
protocol is secure in the (symbolic) model, then an attack can only
occur with negligible probability in a computational model. Such
results have two main drawbacks: first they are very complicated,
and have to be completed again and again for each combination of
security primitives. Second, they require strong hypotheses on the
primitives, some of which are not realistic. For instance, it is
assumed that the attacker cannot forge his own keys (or that all
keys come with their certificates, even for symmetric encryption
keys).</p>
      <p>Hubert Comon-Lundh, Véronique Cortier and Guillaume Scerri had
proposed an extension of the symbolic model in 2012, and proved it
computationally sound, without this restriction on the dishonest
keys.
</p>
    </subsection>
    <subsection id="uid27" level="1">
      <bodyTitle>Deciding trace equivalence</bodyTitle>
      <participants>
        <person key="parsifal-2005-id18148">
          <firstname>David</firstname>
          <lastname>Baelde</lastname>
        </person>
        <person key="secsi-2005-id18250">
          <firstname>Stéphanie</firstname>
          <lastname>Delaune</lastname>
        </person>
        <person key="secsi-2013-idp140536989935120">
          <firstname>Rémy</firstname>
          <lastname>Chrétien</lastname>
        </person>
        <person key="secsi-2013-idp140536989932816">
          <firstname>Lucca</firstname>
          <lastname>Hirschi</lastname>
        </person>
      </participants>
      <p>Most existing results focus on trace properties like secrecy or
authentication. There are however several security properties, which
cannot be defined (or cannot be naturally defined) as trace properties
and require the notion of indistinguishably. Typical examples are
anonymity, privacy related properties or statements closer to security
properties used in cryptography.</p>
      <p>In the framework of the applied pi-calculus as in similar languages
based on equational logics, indistinguishably corresponds to a
relation called trace equivalence. Roughly, two processes are trace
equivalent when an observer cannot see any difference between the two
processes. Static equivalence applies only to observations on finite
sets of messages, and do not take into account the dynamic behavior of
a process whereas the notion of trace equivalence is more general and
takes into account this aspect.</p>
      <subsection id="idp140536989995824" level="2">
        <bodyTitle>Static equivalence.</bodyTitle>
        <p>As explained above, static equivalence is a cornerstone to provide decision
procedures for observational equivalence.</p>
        <p>Stéphanie Delaune, in
collaboration with Mathieu Baudet and Véronique Cortier, has designed
a generic procedure for deducibility and static equivalence that takes
as input any convergent rewrite system <ref xlink:href="#secsi-2013-bid0" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.
They have shown that their algorithm covers most of the existing
decision procedures for convergent theories.
They also provide an efficient implementation.
This paper is a journal version of the work presented at RTA'09.</p>
      </subsection>
      <subsection id="idp140536989999376" level="2">
        <bodyTitle>Trace equivalence.</bodyTitle>
        <p>When the processes under study do not contain replication, trace
equivalence can be reduced to the problem of deciding symbolic
equivalence <ref xlink:href="#secsi-2013-bid1" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>. Thanks to this reduction and
relying on a result first proved by M. Baudet, this yields the first
decidability result of observational equivalence for a general class
of equational theories (for processes without else branches and
without replication). Moreover, based on another decidability result
for deciding equivalence between sets of constraint systems, we get
decidability of trace equivalence for processes with else branch for
standard primitives.</p>
        <p>Even though there are some implementations of the procedures described
above, this does not suffice to obtain practical tools. Current
prototypes suffer from a classical combinatorial explosion problem
caused by the exploration of many interleavings in the behaviour of
processes. David Baelde, Stéphanie Delaune, and Lucca Hirschi revisit
a work due to Mödersheim et al., generalize it and adapt it for
equivalence checking. They obtain an optimization in the form of a
reduced symbolic semantics that eliminates redundant interleavings on
the fly. This work will be published as:</p>
        <simplelist>
          <li id="uid28">
            <p noindent="true">D. Baelde, S. Delaune, and L. Hirschi. A Reduced Semantics for
Deciding Trace Equivalence using Constraint Systems. In
<i>Proc. 3rd Conference on Principles of Security and Trust (POST
2014)</i>, Grenoble, April 2014, France.</p>
          </li>
        </simplelist>
        <p>When processes under study contain replication, the approach relying
on symbolic equivalence does not work anymore. Moreover, since it is
well-known that deciding reachability properties is undecidable under
various restrictions, there is actually no hope to do better for
equivalence-based properties. Rémy Chrétien, Véronique Cortier, and
Stéphanie Delaune provide the first results of (un)decidability for
certain classes of protocols for the equivalence problem. They
consider a class of protocols shown to be decidable for reachability
properties, and establish a first undecidability result. Then, they
restrained the class of protocols a step further by making the
protocols deterministic in some sense and preventing it from
disclosing secret keys. This tighter class of protocols was then shown
to be decidable after reduction to an equivalence between
deterministic pushdown automata. This work has been published at
ICALP'13 <ref xlink:href="#secsi-2013-bid2" location="biblio" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest"/>.</p>
        <p>To deal with replication, another approach has been studied by Vincent
Cheval in collaboration with Bruno Blanchet. They propose an
extension of the automatic protocol verifier ProVerif. ProVerif can
prove observational equivalence between processes that have the same
structure but differ by the messages they contain. In order to extend
the class of equivalences that ProVerif handles, they extend the
language of terms by defining more functions (destructors) by rewrite
rules. These extensions have been implemented in ProVerif and allow
one to automatically prove anonymity in the private authentication
protocol by Abadi and Fournet. This work is part of Vincent Cheval's
PhD thesis, and was published as:</p>
        <simplelist>
          <li id="uid29">
            <p noindent="true">V. Cheval, B. Blanchet. Proving More Observational Equivalences
with ProVerif. In <i>2nd Conference on Principles of Security and
Trust (POST 2013)</i>. David Basin, John Mitchell, eds. Springer
Verlag, Lecture Notes in Computer Science 7796, 2013.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid30" level="1">
      <bodyTitle>Mobile ad-hoc networks</bodyTitle>
      <participants>
        <person key="secsi-2013-idp140536989935120">
          <firstname>Rémy</firstname>
          <lastname>Chrétien</lastname>
        </person>
        <person key="secsi-2005-id18250">
          <firstname>Stéphanie</firstname>
          <lastname>Delaune</lastname>
        </person>
      </participants>
      <p>Mobile ad hoc networks consist of mobile wireless devices which
autonomously organize their communication infrastructure: each node
provides the function of a router and relays packets on paths to
other nodes. Finding these paths in an a priori unknown and
constantly changing network topology is a crucial functionality of
any ad hoc network. Specific protocols, called <i>routing
protocols</i>, are designed to ensure this functionality known as
<i>route discovery</i>. Secured versions of routing protocols have
been proposed to provide more guarantees on the resulting routes, and
some of them have been designed to protect the privacy of the users.</p>
      <p>Rémy Chrétien and Stéphanie Delaune propose a framework for analysing
privacy-type properties for routing protocols. They use the notion
of equivalence between traces to formalise three security properties
related to privacy, namely indistinguishability, unlinkability, and
anonymity. They study the relationship between these definitions and
we illustrate them using two versions of the ANODR routing
protocol. This work was published as:</p>
      <simplelist>
        <li id="uid31">
          <p noindent="true">R. Chrétien, S. Delaune. Formal Analysis of Privacy for
Routing Protocols in Mobile Ad Hoc Networks. <i>Principles of
Security and Trust - Second International Conference, POST 2013</i>,
held as Part of the <i>European Joint Conferences on Theory and
Practice of Software, ETAPS 2013</i>, Rome, Italy, March 16-24,
2013. Proceedings. Springer 2013. Lecture Notes in Computer
Science. ISBN 978-3-642-36829-5. Pages 1-20.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid32" level="1">
      <bodyTitle>Composition results</bodyTitle>
      <participants>
        <person key="secsi-2005-id18250">
          <firstname>Stéphanie</firstname>
          <lastname>Delaune</lastname>
        </person>
      </participants>
      <p>Formal methods have proved their usefulness for analysing the
security of protocols. However, protocols are often analysed in
isolation, and this is well-known to be not sufficient as soon as the
protocols share some keys.</p>
      <p>Stéphanie Delaune, in collaboration with Céline Chevalier, Steve
Kremer, and Mark Ryan, study whether password protocols can be safely
composed, even when a same password is reused. More precisely, they
present a transformation which maps a password protocol that is
secure for a single protocol session (a decidable problem) to a
protocol that is secure for an unbounded number of sessions. Their
result provides an effective strategy to design secure password
protocols: (i) design a protocol intended to be secure for one
protocol session; (ii) apply their transformation and obtain a
protocol which is secure for an unbounded number of sessions. Their
technique also applies to compose different password protocols
allowing one to obtain both inter-protocol and inter-session
composition. This work was published as:</p>
      <simplelist>
        <li id="uid33">
          <p noindent="true">C. Chevalier, S. Delaune, S. Kremer and M. Ryan. Composition
of Password-based Protocols. <i>Formal Methods in System
Design</i> 43(3), pages 369-413, 2013.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid34" level="1">
      <bodyTitle>Unconditional Soundness (Objective 2)</bodyTitle>
      <participants>
        <person key="secsi-2005-id18187">
          <firstname>Hubert</firstname>
          <lastname>Comon-Lundh</lastname>
        </person>
        <person key="cassis-2011-idp140243370899792">
          <firstname>Guillaume</firstname>
          <lastname>Scerri</lastname>
        </person>
      </participants>
      <p>Hubert Comon-Lundh, Véronique Cortier and Guillaume Scerri had shown
in a 2012 CCS paper how one could drop one of the assumptions of
computational soundness results. However, the proofs remain very
complicated and there are still assumptions such as the absence of
key cycles, or no dynamic corruption... that are still necessary
for all these results.</p>
      <p>Gergei Bana and Hubert Comon-Lundh investigated a completely
different approach to formal security proofs in a 2012 POST paper,
which does not make any such assumptions. The idea can be stated in
a nutshell: whereas all existing formal models state the attacker's
abilities, they propose to formally state what the attacker
<i>cannot</i> do.</p>
      <p>This makes a big difference, since the soundness need only to be
proved formula by formula and only the very necessary assumptions
are used for such formulas (for instance, no absence of key cycles
is needed). This does not need to be proved again when a primitive
is added.</p>
      <p>Once the general setting is fixed, the question was how practical is
the method. We studied the complexity of the consistency proofs
in this setting and showed that we can complete such proofs in Polynomial
Time for a wide class of axioms in</p>
      <simplelist>
        <li id="uid35">
          <p noindent="true">H. Comon-Lundh, V. Cortier and G. Scerri. Tractable inference systems:
an extension with a deducibility predicate. In CADE'13, LNAI 7898, pages 91-108. Springer, 2013</p>
        </li>
      </simplelist>
      <p>The development of a prototype implementation is under development.
We expect to complete experiments on a number of protocols.
</p>
    </subsection>
    <subsection id="uid36" level="1">
      <bodyTitle>Static Analysis of Programs with Imprecise
Probabilities</bodyTitle>
      <participants>
        <person key="secsi-2005-id18078">
          <firstname>Jean</firstname>
          <lastname>Goubault-Larrecq</lastname>
          <moreinfo>correspondant</moreinfo>
        </person>
      </participants>
      <p>Static analyses allows one to obtain guarantees about the behavior
of programs, without running them. Programs that handle numerical
data such as feedback control loops pose a challenge in this area.
This gets even harder when one considers programs that read
numerical data from sensors, and write to actuators, as these data
are imprecise, and are governed by probability distributions that
may themselves be unknown, and only know to fall into some interval
of distributions.</p>
      <p>As part of the ANR projet blanc CPP, an efficient static analysis
framework that deals with this kind of programs was proposed in 2011
by J. Goubault-Larrecq, O. Bouissou, E. Goubault, Sylvie Putot,
based on P-boxes and Dempster-Shafer structures to handle imprecise
probabilities.</p>
      <p>The semantic foundations were made clearer, a new, improved
algorithm was proposed, and new applications were examined in:</p>
      <simplelist>
        <li id="uid37">
          <p noindent="true">A. Adjé, O. Bouissou, J. Goubault-Larrecq, E. Goubault and
S. Putot. Static Analysis of Programs with Imprecise
Probabilistic Inputs. In <i>VSTTE'13</i>, LNCS. Springer, 2013.</p>
        </li>
      </simplelist>
    </subsection>
  </resultats>
  <partenariat id="uid38">
    <bodyTitle>Partnerships and Cooperations</bodyTitle>
    <subsection id="uid39" level="1">
      <bodyTitle>National Initiatives</bodyTitle>
      <subsection id="uid40" level="2">
        <bodyTitle>ANR</bodyTitle>
        <simplelist>
          <li id="uid41">
            <p noindent="true">ANR programme blanc CPP (“Confidence, Probability, and
Proofs”), 2009-April 2013. Partners: LSV (scientific leader),
CEA LIST (co-leader), Inria (Comète, Parsifal), Ecole Supérieure
d'Electricité (L2S, SSE). External partners: Safran, Dassault
Systèmes.</p>
            <p>In the context of proofs of safety properties for critical
software, The CPP project proposes to study the joint use of
probabilistic and formal (deterministic) semantics and analysis
methods, in a way to improve the applicability and precision of
static analysis methods on numerical programs. See
<ref xlink:href="http://www.lix.polytechnique.fr/~bouissou/cpp/index.php" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lix.<allowbreak/>polytechnique.<allowbreak/>fr/<allowbreak/>~bouissou/<allowbreak/>cpp/<allowbreak/>index.<allowbreak/>php</ref>.</p>
          </li>
          <li id="uid42">
            <p noindent="true">ANR VERSO program ProSe (“Proofs of Security”), 2010-2014.
Partners: Inria (Cascade, leader; Cassis), LSV, Verimag.</p>
            <p>The goal of the ProSe project is to increase the confidence in
security protocols, and in order to reach this goal, provide
security proofs at three levels: the <i>symbolic</i> level, in
which messages are terms; the <i>computational</i> level, in which
messages are bitstrings; and the <i>implementation</i> level: the
program itself. This project is a continuation of the FormaCrypt
project. See <ref xlink:href="https://crypto.di.ens.fr/projects:prose:main" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">https://<allowbreak/>crypto.<allowbreak/>di.<allowbreak/>ens.<allowbreak/>fr/<allowbreak/>projects:prose:main</ref>.</p>
          </li>
          <li id="uid43">
            <p noindent="true">ANR JCJC project VIP, 2012-2015. Awarded to Stéphanie Delaune.</p>
            <p>The aim of this project is to formally analyze modern applications
in which privacy plays an important role. Many applications
having an important societal impact are concerned by privacy, e.g.
electronic voting, electronic auction protocols, RFID tags, safety
critical application in vehicular ad hoc networks, routing
protocols in mobile ad hoc networks, etc. Moreover, each
application comes with its own specificities. E.g. e-voting
protocols often rely on complex cryptographic primitives, some
routing protocols rely on recursive tests, and so on. In mobile
ad hoc networks, taking into account mobility issues is also an
important challenge.</p>
            <p>Because security protocols are notoriously difficult to design and
analyse, formal verification techniques are extremely important.
However, nearly all studies focus on trace-based security
properties, and thus to not allow one to analyse privacy-type
properties that play an important role in many modern
applications. Moreover, the envisioned applications have some
specificities that prevent them to be modelled in an accurate way
with existing verification tools.</p>
            <p>The goal of this project is to design verification algorithms to
analyse privacy-type properties on several applications having an
important societal impact. The project is accompanied by an
effort in case studies and application domains which will allow at
the end of the project an assessment of the pragmatic potential
both in terms of modelling and effective analysis. More details
are available on the web page of the
project: <ref xlink:href="http://www.lsv.ens-cachan.fr/Projects/anr-vip/" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Projects/<allowbreak/>anr-vip/</ref>.</p>
          </li>
          <li id="uid44">
            <p noindent="true">Inria-DGA contract, on evaluation of the Orchids tool. This
is a 3-year contract, starting in April 2013, on the evaluation
and improvement of the Orchids intrusion detection tool. The
actual contents of the contract is not public.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid45" level="1">
      <bodyTitle>International Initiatives</bodyTitle>
      <subsection id="uid46" level="2">
        <bodyTitle>Inria International Partners</bodyTitle>
        <subsection id="uid47" level="3">
          <bodyTitle>Informal International Partners</bodyTitle>
          <simplelist>
            <li id="uid48">
              <p noindent="true">Mark D. Ryan, U. Birmingham</p>
            </li>
            <li id="uid49">
              <p noindent="true">Alwen Tiu, Australian National University</p>
            </li>
            <li id="uid50">
              <p noindent="true">Achim Jung, U. Birmingham</p>
            </li>
            <li id="uid51">
              <p noindent="true">Frédéric Mynard, Georgia Southern University</p>
            </li>
            <li id="uid52">
              <p noindent="true">Roberto Segala, U. Verona</p>
            </li>
            <li id="uid53">
              <p noindent="true">Dominique Unruh, U. Tallinn</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
      <subsection id="uid54" level="2">
        <bodyTitle>Participation In other International Programs</bodyTitle>
        <simplelist>
          <li id="uid55">
            <p noindent="true">Inria Project Lab CAPPRIS (Collaborative Action on the
Protection of Privacy Rights in the Information Society). Member:
Stéphanie Delaune.</p>
            <p>The goal of CAPPRIS is to provide solutions to enhance the privacy
protection in the Information Society. The targeted applications
are Online Social Networks, Location Based Services, and
Electronic Health Record Systems.</p>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid56" level="1">
      <bodyTitle>International Research Visitors</bodyTitle>
      <subsection id="uid57" level="2">
        <bodyTitle>Visits of International Scientists</bodyTitle>
        <simplelist>
          <li id="uid58">
            <p noindent="true">Dominique Unruh, Tallinn, 1 month, January 2013.</p>
          </li>
          <li id="uid59">
            <p noindent="true">Mark Ryan, Birmingham, 2 weeks, July 2013.</p>
          </li>
          <li id="uid60">
            <p noindent="true">Achim Jung, Birmingham, 1 month, April-May 2013.</p>
          </li>
        </simplelist>
        <subsection id="uid61" level="3">
          <bodyTitle>Internships</bodyTitle>
          <p>Stéphanie Delaune et David Baelde co-supervised the following master student:</p>
          <simplelist>
            <li id="uid62">
              <p noindent="true">Lucca Hirschi, ENS Lyon, “Réduction d'ordre
partiel pour les propriétés d'équivalence”, 2013.</p>
            </li>
          </simplelist>
          <p>Jean Goubault-Larrecq supervised the following L2 student:</p>
          <simplelist>
            <li id="uid63">
              <p noindent="true">Jean-Philippe Lachance, U. Laval, Québec, “Evaluation
automatique de la complexité de détection des signatures Orchids”, 2013.</p>
            </li>
          </simplelist>
        </subsection>
      </subsection>
    </subsection>
  </partenariat>
  <diffusion id="uid64">
    <bodyTitle>Dissemination</bodyTitle>
    <subsection id="uid65" level="1">
      <bodyTitle>Scientific Animation</bodyTitle>
      <p>Administrative charges:</p>
      <simplelist>
        <li id="uid66">
          <p noindent="true">Hubert Comon-Lundh is member of the “comité de pilotage”,
labex Digicosme.</p>
        </li>
        <li id="uid67">
          <p noindent="true">Hubert Comon-Lundh is member of the “commission formation”,
labex Digicosme.</p>
        </li>
        <li id="uid68">
          <p noindent="true">Hubert Comon-Lundh is member of the “Jury prix de these
Gilles Kahn/SIF”.</p>
        </li>
        <li id="uid69">
          <p noindent="true">Hubert Comon-Lundh is member of the jury “appel à projets Digiteo”</p>
        </li>
        <li id="uid70">
          <p noindent="true">Hubert Comon-Lundh is member of the Master MPRI studies
committee and director of the MPRI until sept. 2013.</p>
        </li>
        <li id="uid71">
          <p noindent="true">Stéphanie Delaune has been a member of the scientific committee of
Inria Saclay since February 2012.</p>
        </li>
        <li id="uid72">
          <p noindent="true">Stéphanie Delaune has been “Déléguée aux thèses” at the École
Doctorale Sciences Pratiques at ENS Cachan since September 2012.</p>
        </li>
        <li id="uid73">
          <p noindent="true">Jean Goubault-Larrecq is in charge of computer science
questions, common Ecole Polytechnique-ENS Paris, Lyon,
Cachan-ESPCI entrance competitive exam, starting September 2012.</p>
        </li>
      </simplelist>
      <p>Editorial boards:</p>
      <simplelist>
        <li id="uid74">
          <p noindent="true">Hubert Comon-Lundh is associate editor of the ACM Transactions
on Computational Logic.</p>
        </li>
      </simplelist>
      <p>Participation to program committes of conferences:</p>
      <simplelist>
        <li id="uid75">
          <p noindent="true">16th International Conference on Foundations of Software
Science and Computation Structures FoSSaCS'13, Rome, Italy,
March 2013 (Jean Goubault-Larrecq).</p>
        </li>
        <li id="uid76">
          <p noindent="true">24th International Conference on Automated Deduction (CADE),
Lake Placid, New York, USA, 2013 (Stéphanie Delaune)</p>
        </li>
        <li id="uid77">
          <p noindent="true">26th IEEE Computer Security Foundations Symposium (CSF),
Tulane University, New Orleans LA, USA, 2013 (Stéphanie Delaune)</p>
        </li>
        <li id="uid78">
          <p noindent="true">24th International Conference on Rewriting Techniques and
Applications (RTA), Eindhoven, The Netherlands, 2013 (Stéphanie
Delaune)</p>
        </li>
        <li id="uid79">
          <p noindent="true">20th Workshop on Logic, Language, Information and Computation
(WoLLIC), Darmstadt, Germany, 2013 (Stéphanie Delaune)</p>
        </li>
        <li id="uid80">
          <p noindent="true">Worshop <i>Formal and Computational Cryptography (FCC)</i>,
president of the program commitee. June 30, 2013, New Orleans
(Hubert Comon-Lundh).</p>
        </li>
        <li id="uid81">
          <p noindent="true">Workshop on <i>Logical Frameworks and Meta-Languages:
Theory and Practice</i> LFMTP'13, Boston, U.S.A., September 2013
(David Baelde).</p>
        </li>
        <li id="uid82">
          <p noindent="true">Workshop on <i>Fixed Points in Computer Science</i> FICS'13,
Torino, Italy, September 2013 (David Baelde).</p>
        </li>
        <li id="uid83">
          <p noindent="true">24th Journées Francophones des Langages Applicatifs
JFLA'13, Aussois, France, February 2013 (David Baelde).</p>
        </li>
      </simplelist>
      <p>Organization of conferences:</p>
      <simplelist>
        <li id="uid84">
          <p noindent="true">Workshop on <i>Fixed Points in Computer Science</i> FICS'13,
Torino, Italy, September 2013 (David Baelde).</p>
        </li>
        <li id="uid85">
          <p noindent="true">25th Journées Francophones des Langages Applicatifs
JFLA'14, Fréjus, France, January 2014 (David Baelde).</p>
        </li>
      </simplelist>
      <p>Selection committees:</p>
      <simplelist>
        <li id="uid86">
          <p noindent="true">Hubert Comon-Lundh was president of the “Maitre de
Conférences” selection committee, ENS Paris, 2013.</p>
        </li>
        <li id="uid87">
          <p noindent="true">Hubert Comon-Lundh was member of the selection committee of
“Maitre de conférences” selection committee,
Univ. Paris-Diderot, 2013.</p>
        </li>
        <li id="uid88">
          <p noindent="true">Hubert Comon-Lundh was member of the Inria Paris-Rocquencourt junior
researche selection committee, 2013.</p>
        </li>
        <li id="uid89">
          <p noindent="true">Jean Goubault-Larrecq was member of the Inria
Saclay-Ile-de-France junior researcher selection committee, 2013.</p>
        </li>
      </simplelist>
      <p>Scientific boards:</p>
      <simplelist>
        <li id="uid90">
          <p noindent="true">Hubert Comon-Lundh, CNRS INSII, Oct. 2010-Oct 2014</p>
        </li>
        <li id="uid91">
          <p noindent="true">Hubert Comon-Lundh, scientific committee, labex CPU.</p>
        </li>
        <li id="uid92">
          <p noindent="true">Hubert Comon-Lundh, scientific committee, LIPN.</p>
        </li>
        <li id="uid93">
          <p noindent="true">Jean Goubault-Larrecq, external member of the selection
committee of the Formal Methods and Security Inria-DGA seminar, Rennes</p>
        </li>
        <li id="uid94">
          <p noindent="true">Jean Goubault-Larrecq, external member of the selection
committee of the Formal Methods and Security Inria-DGA seminar, Rennes</p>
        </li>
        <li id="uid95">
          <p noindent="true">Jean Goubault-Larrecq, member of the scientific committee of
the Labex “Fondation Sciences Mathématiques de Paris”.</p>
        </li>
        <li id="uid96">
          <p noindent="true">Jean Goubault-Larrecq, member of the scientific committe of
the “Ecole de Printemps d'Informatique Théorique” (EPIT).</p>
        </li>
      </simplelist>
      <p>Invited talks:</p>
      <simplelist>
        <li id="uid97">
          <p noindent="true">Hubert Comon-Lundh, <i>LICS: Logic in Computer Security</i>,
invited tutorial, IEEE Symp. Logic in Computer Science, New
Orleans, July 2013.</p>
        </li>
        <li id="uid98">
          <p noindent="true">Jean Goubault-Larrecq, <i>A few Pearls in the Theory of
Quasi-Metric Spaces</i>, semi-plenary talk, Summer Topology
Conference, North Bay, Ontario, Canada, July 23-26, 2013.</p>
        </li>
        <li id="uid99">
          <p noindent="true">Jean Goubault-Larrecq, <i>A Simple Proof of the
Schröder-Simpson Theorem</i>, session on Asymmetric Topology,
Summer Topology Conference, North Bay, Ontario, Canada, July
23-26, 2013.</p>
        </li>
        <li id="uid100">
          <p noindent="true">Jean Goubault-Larrecq, <i>A Constructive Proof of the
Topological Kruskal Theorem</i>, Mathematical Foundations of
Computer Science (MFCS), IST Austria, near Vienna, Austria, August
26-30, 2013.</p>
        </li>
        <li id="uid101">
          <p noindent="true">Jean Goubault-Larrecq, <i>Is Mathematical Rigor Needed in
Intrusion Detection?</i>, Foundations and Practice of Security
(FPS), La Rochelle, France, October 21, 2013.</p>
        </li>
      </simplelist>
      <p>Invitation to seminars:</p>
      <simplelist>
        <li id="uid102">
          <p noindent="true">Hubert Comon-Lundh, <i>Towards Unconditonal Soundness</i>,
IRISA, Rennes, Feb 1, 2013.</p>
        </li>
        <li id="uid103">
          <p noindent="true">Hubert Comon-Lundh, <i>Computationally Sound Automated
Proofs of Security</i>, LRI, Orsay, March 15, 2013.</p>
        </li>
        <li id="uid104">
          <p noindent="true">Jean Goubault-Larrecq, <i>Orchids, ou: de l'importance de
la sémantique</i>, séminaire DGA Innosciences, DGA, Bagneux, June
25, 2013.</p>
        </li>
        <li id="uid105">
          <p noindent="true">Jean Goubault-Larrecq, <i>Full Abstraction for
Non-Deterministic and Probabilistic Extensions of PCF</i>,
Pierre-Louis Curien Festschrift, Venice, Italy, September 9-11, 2013.</p>
        </li>
      </simplelist>
    </subsection>
    <subsection id="uid106" level="1">
      <bodyTitle>Teaching - Supervision - Juries</bodyTitle>
      <subsection id="uid107" level="2">
        <bodyTitle>Teaching</bodyTitle>
        <sanspuceslist>
          <li id="uid108">
            <p noindent="true">Licence :</p>
            <simplelist>
              <li id="uid109">
                <p noindent="true">Rémy Chrétien, <i>Initiation à l'informatique</i>
(TP), 39h., L1, Université Paris 7, Paris, France</p>
              </li>
              <li id="uid110">
                <p noindent="true">Hubert Comon-Lundh <i>Logic and Computability</i>, 42h., L3,
ENS Cachan, France</p>
              </li>
              <li id="uid111">
                <p noindent="true">Jean Goubault-Larrecq, <i>Programming</i>, 42h., L3, ENS
Cachan, France</p>
              </li>
              <li id="uid112">
                <p noindent="true">Jean Goubault-Larrecq, <i>Logic and Computer Science</i>
(a.k.a., the lambda-calculus), 36h., L3, ENS Cachan and ENS
Paris, France</p>
              </li>
              <li id="uid113">
                <p noindent="true">Jean Goubault-Larrecq, Internship reviews, 4h., L3, ENS
Cachan, France</p>
              </li>
              <li id="uid114">
                <p noindent="true">David Baelde, <i>Logic and Computer Science</i>, 24h., L3,
ENS Cachan, France</p>
              </li>
              <li id="uid115">
                <p noindent="true">David Baelde, <i>Logic II</i>, 22.5h., L3, ENS Cachan,
France</p>
              </li>
              <li id="uid116">
                <p noindent="true">David Baelde, <i>Programming II</i>, 22.5h., L3, ENS Cachan,
France</p>
              </li>
              <li id="uid117">
                <p noindent="true">David Baelde, Internship reviews, 3h., L3, ENS Cachan,
France</p>
              </li>
            </simplelist>
          </li>
          <li id="uid118">
            <p noindent="true">Master :</p>
            <simplelist>
              <li id="uid119">
                <p noindent="true">Jean Goubault-Larrecq, <i>Cryptography, Cryptographic
Protocols and Quantum Cryptography</i>, Part 1/3, 3h., M1,
Séminaire Regards Croisés Mathématiques-Physique, ENS Cachan,
France</p>
              </li>
              <li id="uid120">
                <p noindent="true">Stéphanie Delaune, <i>Cryptography, Cryptographic
Protocols and Quantum Cryptography</i>, Part 2/3, 3h., M1,
Séminaire Regards Croisés Mathématiques-Physique, ENS Cachan,
France</p>
              </li>
              <li id="uid121">
                <p noindent="true">Jean Goubault-Larrecq, <i>Advanced Complexity</i>, 42h., M1,
MPRI course 1-17, France</p>
              </li>
              <li id="uid122">
                <p noindent="true">David Baelde, <i>Software Engineering Project</i>, 30h., M1,
ENS Cachan, France</p>
              </li>
              <li id="uid123">
                <p noindent="true">Jean Goubault-Larrecq, Internship reviews, 4h., M1, ENS
Cachan, France</p>
              </li>
              <li id="uid124">
                <p noindent="true">Hubert Comon-Lundh, Internship reviews, 32h, M2 MPRI</p>
              </li>
              <li id="uid125">
                <p noindent="true">Jean Goubault-Larrecq, Internship reviews, 16h., M2, MPRI,
France</p>
              </li>
              <li id="uid126">
                <p noindent="true">Hubert Comon-Lundh <i>Preparation option info agreg:
logique</i>, 24h, préparation à l'agrégation de Mathématiques,
Jan-May 2012, ENS Cachan, France</p>
              </li>
              <li id="uid127">
                <p noindent="true">Hubert Comon-Lundh, rehearsal of Computer Science Lessons,
préparation à l'agrégation de Mathématiques, 18h., ENS Cachan,
France</p>
              </li>
              <li id="uid128">
                <p noindent="true">Hubert Comon-Lundh, <i>Tree Automata</i>, M1, MPRI, 22h</p>
              </li>
              <li id="uid129">
                <p noindent="true">Jean Goubault-Larrecq, rehearsal of Computer Science
Lessons, préparation à l'agrégation de Mathématiques, 18h., ENS
Cachan, France</p>
              </li>
            </simplelist>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid130" level="2">
        <bodyTitle>Supervision</bodyTitle>
        <sanspuceslist>
          <li id="uid131">
            <p noindent="true">PhD in progress :</p>
            <simplelist>
              <li id="uid132">
                <p noindent="true">Rémy Chrétien, <i>Trace equivalence for an unbounded
number of sessions</i>, Started Oct. 2012, supervised by
Stéphanie Delaune and Véronique Cortier</p>
              </li>
              <li id="uid133">
                <p noindent="true">Lucca Hirschi, <i>Reduction techniques for
equivalence-based properties</i>, Started Sep. 2013, supervised
by David Baelde and Stéphanie Delaune</p>
              </li>
              <li id="uid134">
                <p noindent="true">Guillaume Scerri, <i>Preuves abstraites de protocoles
cryptographiques concrets</i>, Started Oct. 2011, supervised by
Hubert Comon-Lundh</p>
              </li>
            </simplelist>
          </li>
        </sanspuceslist>
      </subsection>
      <subsection id="uid135" level="2">
        <bodyTitle>Juries</bodyTitle>
        <simplelist>
          <li id="uid136">
            <p noindent="true">PhD:</p>
            <simplelist>
              <li id="uid137">
                <p noindent="true">Jean Goubault-Larrecq, member of the jury: Rémi Bonnet,
<i>Decidability and Undecidability in Vector Addition Systems
with one (or more !) Zero-Tests</i>, ENS Cachan, January 22,
2013.</p>
              </li>
              <li id="uid138">
                <p noindent="true">Jean Goubault-Larrecq, president of the jury: Song Fu,
<i>On Pushdown Systems Model Checking: Application to Malware
Detection and Software Model-Checking</i>, U. Paris Diderot,
April 12, 2013.</p>
              </li>
              <li id="uid139">
                <p noindent="true">Jean Goubault-Larrecq, president of the jury: Alexis Goyet,
<i>The <formula type="inline"><math xmlns="http://www.w3.org/1998/Math/MathML" overflow="scroll"><mrow><mi>λ</mi><mover><mi>λ</mi><mo>¯</mo></mover></mrow></math></formula>-calculus, A Dual Calculus
for Unconstrained Strategies</i>, U. Paris Diderot, December 11,
2013.</p>
              </li>
              <li id="uid140">
                <p noindent="true">Jean Goubault-Larrecq, member of the jury: David Cadé,
<i>Implémentations de protocoles cryptographiques prouvées
dans le modèle calculatoire</i>, U. Paris Diderot, December 16, 2014.</p>
              </li>
              <li id="uid141">
                <p noindent="true">Jean Goubault-Larrecq, member of the mid-term evaluation
jury: Pablo Rauzy, SupTelecom Paris Tech, December 4, 2013.</p>
              </li>
            </simplelist>
          </li>
          <li id="uid142">
            <p noindent="true">HdR:</p>
            <simplelist>
              <li id="uid143">
                <p noindent="true">Hubert Comon-Lundh, president of the jury: Jérôme
Leroux. <i>Presburger Counter Machines</i>, Bordeaux, Dec.6,
2012.</p>
              </li>
              <li id="uid144">
                <p noindent="true">Jean Goubault-Larrecq, reviewer and member of the jury:
Michele Pagani, <i>Some Advances in Linear Logic</i>, U. Paris
Nord Villetaneuse, December 5, 2013.</p>
              </li>
              <li id="uid145">
                <p noindent="true">Jean Goubault-Larrecq, reviewer and member of the jury:
Michele Pagani, <i>Some Advances in Linear Logic</i>, U. Paris
Nord Villetaneuse, December 5, 2013.</p>
              </li>
            </simplelist>
          </li>
        </simplelist>
      </subsection>
    </subsection>
    <subsection id="uid146" level="1">
      <bodyTitle>Popularization</bodyTitle>
      <simplelist>
        <li id="uid147">
          <p noindent="true">Stéphanie Delaune, member of the scientific mediation
committee at Inria Saclay. (“Mediation” is the new name for
popularization.)</p>
        </li>
        <li id="uid148">
          <p noindent="true">Rémy Chrétien and Stéphanie Delaune, <i>La protection des
informations sensibles</i>, article in <i>Pour La Science</i>,
Nov. 2013.</p>
        </li>
      </simplelist>
    </subsection>
  </diffusion>
  <biblio id="bibliography" html="bibliography" numero="10" titre="Bibliography">
    
    <biblStruct id="secsi-2013-bid9" type="article" rend="refer" n="refercite:BCK-IC09">
      <identifiant type="doi" value="10.1016/j.ic.2008.12.005"/>
      <analytic>
        <title level="a">Computationally Sound Implementations of Equational Theories against Passive Adversaries</title>
        <author>
          <persName key="secsi-2005-id18206">
            <foreName>Mathieu</foreName>
            <surname>Baudet</surname>
            <initial>M.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18118">
            <foreName>Steve</foreName>
            <surname>Kremer</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Information and Computation</title>
        <imprint>
          <biblScope type="volume">207</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <month>April</month>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">496-520</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/BCK-ic09.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/>BCK-ic09.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid15" type="inproceedings" rend="refer" n="refercite:BCFS-ccs10">
      <identifiant type="doi" value="10.1145/1866307.1866337"/>
      <analytic>
        <title level="a">Attacking and Fixing PKCS#11 Security Tokens</title>
        <author>
          <persName>
            <foreName>Matteo</foreName>
            <surname>Bortolozzo</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Matteo</foreName>
            <surname>Centenaro</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>Riccardo</foreName>
            <surname>Focardi</surname>
            <initial>R.</initial>
          </persName>
          <persName key="secsi-2007-id18538">
            <foreName>Graham</foreName>
            <surname>Steel</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS'10)</title>
        <loc>Chicago, Illinois, USA</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2010</year>
          </dateStruct>
          <biblScope type="pages">260-269</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/BCFS-ccs10.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/>BCFS-ccs10.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid14" type="inproceedings" rend="refer" n="refercite:CCD-ccs11">
      <analytic>
        <title level="a">Trace Equivalence Decision: Negative Tests and Non-determinism</title>
        <author>
          <persName key="alice-2007-id18452">
            <foreName>Vincent</foreName>
            <surname>Cheval</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18187">
            <foreName>Hubert</foreName>
            <surname>Comon-Lundh</surname>
            <initial>H.</initial>
          </persName>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS'11)</title>
        <loc>Chicago, Illinois, USA</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2011</year>
          </dateStruct>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/CCD-ccs11.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/><allowbreak/>CCD-ccs11.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
      <note type="bnote">To appear</note>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid12" type="article" rend="refer" n="refercite:ComonCortier-TCS1">
      <identifiant type="doi" value="10.1016/j.tcs.2004.09.036"/>
      <analytic>
        <title level="a">Tree Automata with One Memory, Set Constraints and Cryptographic Protocols</title>
        <author>
          <persName key="secsi-2005-id18187">
            <foreName>Hubert</foreName>
            <surname>Comon-Lundh</surname>
            <initial>H.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">331</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <month>February</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">143-214</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PS/ComonCortierTCS1.ps" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PS/<allowbreak/>ComonCortierTCS1.<allowbreak/>ps</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid13" type="inproceedings" rend="refer" n="refercite:CLC-ccs08">
      <identifiant type="doi" value="10.1145/1455770.1455786"/>
      <analytic>
        <title level="a">Computational soundness of observational equivalence</title>
        <author>
          <persName key="secsi-2005-id18187">
            <foreName>Hubert</foreName>
            <surname>Comon-Lundh</surname>
            <initial>H.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <title level="m">Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS'08)</title>
        <loc>Alexandria, Virginia, USA</loc>
        <imprint>
          <publisher>
            <orgName>ACM Press</orgName>
          </publisher>
          <dateStruct>
            <month>October</month>
            <year>2008</year>
          </dateStruct>
          <biblScope type="pages">109-118</biblScope>
          <ref xlink:href="http://dx.doi.org/10.1145/1455770.1455786" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>dx.<allowbreak/>doi.<allowbreak/>org/<allowbreak/>10.<allowbreak/>1145/<allowbreak/>1455770.<allowbreak/>1455786</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid10" type="article" rend="refer" n="refercite:DKR-jcs08">
      <analytic>
        <title level="a">Verifying Privacy-type Properties of Electronic Voting Protocols</title>
        <author>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
          <persName key="secsi-2005-id18118">
            <foreName>Steve</foreName>
            <surname>Kremer</surname>
            <initial>S.</initial>
          </persName>
          <persName key="secsi-2007-id18490">
            <foreName>Mark D.</foreName>
            <surname>Ryan</surname>
            <initial>M. D.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Computer Security</title>
        <imprint>
          <biblScope type="volume">17</biblScope>
          <biblScope type="number">4</biblScope>
          <dateStruct>
            <month>July</month>
            <year>2009</year>
          </dateStruct>
          <biblScope type="pages">435-487</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/DKR-jcs08.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/>DKR-jcs08.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid11" type="article" rend="refer" n="refercite:DKS-jcs09">
      <analytic>
        <title level="a">Formal Analysis of PKCS#11 and Proprietary Extensions</title>
        <author>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
          <persName key="secsi-2005-id18118">
            <foreName>Steve</foreName>
            <surname>Kremer</surname>
            <initial>S.</initial>
          </persName>
          <persName key="secsi-2007-id18538">
            <foreName>Graham</foreName>
            <surname>Steel</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="j">Journal of Computer Security</title>
        <imprint>
          <dateStruct>
            <year>2009</year>
          </dateStruct>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/DKS-jcs09.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/>DKS-jcs09.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
      <note type="bnote">To appear</note>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid6" type="inproceedings" rend="refer" n="refercite:Gou-lics07">
      <identifiant type="doi" value="10.1109/LICS.2007.34"/>
      <analytic>
        <title level="a">On Noetherian Spaces</title>
        <author>
          <persName key="secsi-2005-id18078">
            <foreName>Jean</foreName>
            <surname>Goubault-Larrecq</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <title level="m">Proceedings of the 22nd Annual IEEE Symposium on Logic in Computer Science (LICS'07)</title>
        <loc>Wrocław, Poland</loc>
        <imprint>
          <publisher>
            <orgName>IEEE Computer Society Press</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2007</year>
          </dateStruct>
          <biblScope type="pages">453-462</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/JGL-lics07.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/>JGL-lics07.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid8" type="inproceedings" rend="refer" n="refercite:GLP:VMCAI">
      <identifiant type="doi" value="10.1007/b105073"/>
      <analytic>
        <title level="a">Cryptographic Protocol Analysis on Real C Code</title>
        <author>
          <persName key="secsi-2005-id18078">
            <foreName>Jean</foreName>
            <surname>Goubault-Larrecq</surname>
            <initial>J.</initial>
          </persName>
          <persName>
            <foreName>Fabrice</foreName>
            <surname>Parrennes</surname>
            <initial>F.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName key="abstraction-2007-id18145">
            <foreName>Radhia</foreName>
            <surname>Cousot</surname>
            <initial>R.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 6th International Conference on Verification, Model Checking and Abstract Interpretation (VMCAI'05)</title>
        <loc>Paris, France</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3385</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>January</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">363-379</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/GouPar-VMCAI2005.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/><allowbreak/>GouPar-VMCAI2005.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid7" type="inproceedings" rend="refer" n="refercite:Orchids-cav05">
      <identifiant type="doi" value="10.1007/11513988_28"/>
      <analytic>
        <title level="a">The Orchids Intrusion Detection Tool</title>
        <author>
          <persName key="secsi-2005-id18132">
            <foreName>Julien</foreName>
            <surname>Olivain</surname>
            <initial>J.</initial>
          </persName>
          <persName key="secsi-2005-id18078">
            <foreName>Jean</foreName>
            <surname>Goubault-Larrecq</surname>
            <initial>J.</initial>
          </persName>
        </author>
      </analytic>
      <monogr>
        <editor role="editor">
          <persName>
            <foreName>Kousha</foreName>
            <surname>Etessami</surname>
            <initial>K.</initial>
          </persName>
          <persName>
            <foreName>Sriram</foreName>
            <surname>Rajamani</surname>
            <initial>S.</initial>
          </persName>
        </editor>
        <title level="m">Proceedings of the 17th International Conference on Computer Aided Verification (CAV'05)</title>
        <loc>Edinburgh, Scotland, UK</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">3576</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <month>July</month>
            <year>2005</year>
          </dateStruct>
          <biblScope type="pages">286-290</biblScope>
          <ref xlink:href="http://www.lsv.ens-cachan.fr/Publis/PAPERS/PDF/OG-cav05.pdf" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>www.<allowbreak/>lsv.<allowbreak/>ens-cachan.<allowbreak/>fr/<allowbreak/>Publis/<allowbreak/>PAPERS/<allowbreak/>PDF/<allowbreak/>OG-cav05.<allowbreak/>pdf</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct subtype="nonparu-n" id="secsi-2013-bid3" type="article" rend="year" n="cite:arnaud:hal-00881009">
      <identifiant type="hal" value="hal-00881009"/>
      <analytic>
        <title level="a">Modeling and Verifying Ad Hoc Routing Protocols</title>
        <author>
          <persName key="secsi-2008-id18246">
            <foreName>Mathilde</foreName>
            <surname>Arnaud</surname>
            <initial>M.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes" id="rid00905">
        <idno type="issn">0890-5401</idno>
        <title level="j">Information and Computation</title>
        <imprint>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00881009" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00881009</ref>
        </imprint>
      </monogr>
      <note type="bnote">To appear</note>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid0" type="article" rend="year" n="cite:baudet:hal-00732901">
      <identifiant type="doi" value="10.1145/2422085.2422089"/>
      <identifiant type="hal" value="hal-00732901"/>
      <analytic>
        <title level="a">YAPA: A generic tool for computing intruder knowledge</title>
        <author>
          <persName key="secsi-2005-id18206">
            <foreName>Mathieu</foreName>
            <surname>Baudet</surname>
            <initial>M.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes" id="rid00021">
        <idno type="issn">1529-3785</idno>
        <title level="j">ACM Transactions on Computational Logic</title>
        <imprint>
          <biblScope type="volume">14</biblScope>
          <biblScope type="number">1</biblScope>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00732901" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00732901</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid1" type="article" rend="year" n="cite:cheval:hal-00881060">
      <identifiant type="doi" value="10.1016/j.tcs.2013.04.016"/>
      <identifiant type="hal" value="hal-00881060"/>
      <analytic>
        <title level="a">Deciding equivalence-based properties using constraint solving</title>
        <author>
          <persName key="alice-2007-id18452">
            <foreName>Vincent</foreName>
            <surname>Cheval</surname>
            <initial>V.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-editorial-board="yes" x-international-audience="yes" id="rid01946">
        <idno type="issn">0304-3975</idno>
        <title level="j">Theoretical Computer Science</title>
        <imprint>
          <biblScope type="volume">492</biblScope>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <biblScope type="pages">1-39</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00881060" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00881060</ref>
        </imprint>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid2" type="inproceedings" rend="year" n="cite:chretien:hal-00881066">
      <identifiant type="doi" value="10.1007/978-3-642-39212-2_15"/>
      <identifiant type="hal" value="hal-00881066"/>
      <analytic>
        <title level="a">From security protocols to pushdown automata</title>
        <author>
          <persName>
            <foreName>Rémy</foreName>
            <surname>Chrétien</surname>
            <initial>R.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName key="mascotte-2006-id18951">
            <foreName>Fedor V.</foreName>
            <surname>Fomin</surname>
            <initial>F. V.</initial>
          </persName>
          <persName>
            <foreName>Rūsiņš</foreName>
            <surname>Freivalds</surname>
            <initial>R.</initial>
          </persName>
          <persName>
            <foreName>Marta</foreName>
            <surname>Kwiatkowska</surname>
            <initial>M.</initial>
          </persName>
          <persName>
            <foreName>David</foreName>
            <surname>Peleg</surname>
            <initial>D.</initial>
          </persName>
        </editor>
        <title level="m">ICALP'2013 - 40th International Colloquium on Automata, Languages and Programming - 2013</title>
        <loc>Riga, Lithuania</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">7966</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <biblScope type="pages">137-149</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00881066" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00881066</ref>
        </imprint>
        <meeting id="cid106057">
          <title>International Colloquium on Automata, Languages and Programming</title>
          <num>40</num>
          <abbr type="sigle">ICALP</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid4" type="inproceedings" rend="year" n="cite:comonlundh:hal-00881068">
      <identifiant type="doi" value="10.1007/978-3-642-38574-2_6"/>
      <identifiant type="hal" value="hal-00881068"/>
      <analytic>
        <title level="a">Tractable inference systems: an extension with a deducibility predicate</title>
        <author>
          <persName key="secsi-2005-id18187">
            <foreName>Hubert</foreName>
            <surname>Comon-Lundh</surname>
            <initial>H.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="cassis-2011-idp140243370899792">
            <foreName>Guillaume</foreName>
            <surname>Scerri</surname>
            <initial>G.</initial>
          </persName>
        </author>
      </analytic>
      <monogr x-international-audience="yes" x-proceedings="yes">
        <editor role="editor">
          <persName>
            <foreName>Maria Paola</foreName>
            <surname>Bonacina</surname>
            <initial>M. P.</initial>
          </persName>
        </editor>
        <title level="m">CADE'24 - 24th International Conference on Automated Deduction - 2013</title>
        <loc>Lake Placid, United States</loc>
        <title level="s">Lecture Notes in Computer Science</title>
        <imprint>
          <biblScope type="volume">7898</biblScope>
          <publisher>
            <orgName>Springer</orgName>
          </publisher>
          <dateStruct>
            <year>2013</year>
          </dateStruct>
          <biblScope type="pages">91-108</biblScope>
          <ref xlink:href="http://hal.inria.fr/hal-00881068" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00881068</ref>
        </imprint>
        <meeting id="cid112188">
          <title>International Conference on Automated Deduction</title>
          <num>24</num>
          <abbr type="sigle">CADE</abbr>
        </meeting>
      </monogr>
    </biblStruct>
    
    <biblStruct id="secsi-2013-bid5" type="techreport" rend="year" n="cite:chretien:hal-00817230">
      <identifiant type="hal" value="hal-00817230"/>
      <monogr>
        <title level="m">From security protocols to pushdown automata</title>
        <author>
          <persName>
            <foreName>Rémy</foreName>
            <surname>Chrétien</surname>
            <initial>R.</initial>
          </persName>
          <persName key="cassis-2005-id18152">
            <foreName>Véronique</foreName>
            <surname>Cortier</surname>
            <initial>V.</initial>
          </persName>
          <persName key="secsi-2005-id18250">
            <foreName>Stéphanie</foreName>
            <surname>Delaune</surname>
            <initial>S.</initial>
          </persName>
        </author>
        <imprint>
          <biblScope type="number">RR-8290</biblScope>
          <publisher>
            <orgName type="institution">Inria</orgName>
          </publisher>
          <dateStruct>
            <month>April</month>
            <year>2013</year>
          </dateStruct>
          <ref xlink:href="http://hal.inria.fr/hal-00817230" location="extern" xlink:type="simple" xlink:show="replace" xlink:actuate="onRequest">http://<allowbreak/>hal.<allowbreak/>inria.<allowbreak/>fr/<allowbreak/>hal-00817230</ref>
        </imprint>
      </monogr>
      <note type="typdoc">Research Report</note>
    </biblStruct>
  </biblio>
</raweb>
