VLDB 2026 Research / reviewers in the wild / expert
Domenic Forte
dblp:02/8217 · also Domenic J. Forte
· DBLP profile ↗
108ranked-venue papers
12as first author
36since 2021 · last 2026
0000-0002-2794-7320ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 92 · 10 first-author · 28 since 2021Security and privacy · 12 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 4 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bridging Backscattering and On-chip EM Sensing for Golden-Model Free Hardware Trojan DetectionabstractHardware Trojans (HTs) embedded in integrated circuits often remain dormant and activate only under rare conditions, making run-time detection particularly challenging. The problem is more severe for stealthy designs whose small impedance perturbations produce weak electromagnetic signatures that elude conventional side-channel analysis. This work presents an on-chip EM backscattering framework for HT detection based on a Programmable Sensor Array (PSA). Instead of measuring switching-current emissions, the method captures impedance-modulated reflections from a continuous-wave excitation. The PSA is repurposed as a reconfigurable on-chip H-field receiver whose coil geometry can be dynamically tuned to improve magnetic coupling and spatial observability. We validate the approach on a fabricated TSMC 65 nm AES-128 test chip containing four digital Trojans and an analog A2 Trojan. The PSA achieves a 40–55 dB SNR improvement over external probes and enables reliable detection with fewer than five measured traces, including the A2 Trojan, which is difficult to observe using conventional EM side-channel analysis. Moyao Huang, Hanqiu Wang, Shuo Wang 0003, Domenic Forte |
ACM Great Lakes Symposium on VLSI | 4 |
| 2025 | Dynamic Hierarchical Bloom Filters for Scalable Biometric Authentication SystemsabstractBiometric authentication systems must handle large and constantly evolving datasets and maintain high authentication accuracy and scalability. Existing probabilistic data structures like Bloom Filters (BFs) efficiently handle membership testing, but their conventional forms are inherently static and lack tolerance for noisy data. It is also an inherent challenge in biometric systems, where factors such as lighting or camera angle can introduce noise because of these variability. This paper proposes the Dynamic Hierarchical Bloom Filter (DHBF), a novel variant of the Bloom Filter designed to integrate noise tolerance and substring handling capabilities, while simultaneously offering enhanced scalability and dynamic adaptability. The DHBF accommodates fluctuating dataset sizes and mitigates the impact of noisy biometric samples on authentication accuracy by supporting flexible memory allocation. In this paper, experimental validation was performed on a dataset of 30,000 facial images. The results demonstrate that the DHBF achieves 100% authentication accuracy in dynamic operations such as enrollment, querying, insertion, and deletion. Additionally, our experiments demonstrate a reduction (≈ 30%) in storage requirements in terms of storing biometric templates compared to HBFs. Md. Mashfiq Rizvee, Pallabi Ghosh, Domenic Forte, Sumaiya Shomaji |
IJCB | 3 |
| 2025 | Designing with Deception: ML- and Covert Gate-Enhanced Camouflaging to Thwart IC Reverse EngineeringabstractIntegrated circuits (ICs) are essential to electronic systems, yet they face significant risks from physical reverse engineering (RE) attacks that compromise intellectual property (IP) and overall system security. While IC camouflaging has emerged to mitigate these risks, existing approaches largely focus on localized gate modifications, neglecting comprehensive deception strategies. To address this gap, we present a machine learning (ML)-driven methodology – IP Camouflage – that integrates cryptic and mimetic deception principles to enhance IC security against RE. Our approach leverages a novel And-Inverter Graph Variational Autoencoder (AIG-VAE) to encode circuit representations, enabling dual-layered camouflage through functional preservation and appearance mimicry. By introducing new variants of covert gates – Fake Inverters, Fake Buffers, and Universal Transmitters – our methodology achieves robust protection by obscuring circuit functionality while presenting misleading appearances. Experimental results demonstrate the effectiveness of our strategy in maintaining circuit functionality while achieving strong resistance to SAT-based attacks with low structural overhead. Additionally, we validate the robustness of our method against advanced artificial intelligence (AI)-based RE attacks. Junling Fan, David Selasi Koblah, Domenic Forte |
ICCAD | 3 |
| 2025 | Asynchronous Threshold Voltage Defined Logic Family Resistant to LLSI AttacksabstractDigital Circuits are extremely vulnerable to reverse engineering which can reveal the design and functionality of an integrated circuit (IC) and expose valuable intellectual property (IP). A solution to this problem is to use different IC camouflaging techniques or gates to hinder the attacker’s ability to discover the functionality of the design. One type of camouflaged gate is the Threshold Voltage Defined (TVD) logic family. This gate type uses different threshold voltage transistors to disguise the functionality of the circuit. One of the drawbacks of the TVD logic family is that it is a synchronous logic family which makes it extremely vulnerable to Logic Laser State Imaging (LLSI) Attacks. This paper proposes using handshaking logic to create an asynchronous version of the TVD logic family to remove its vulnerability to LLSI attacks and to increase the speed of the TVD gates. Morgan Thomas, Domenic Forte, Nima Maghari |
ISCAS | 2 |
| 2025 | MUX-based Polymorphic Registers and FSMs to Protect Roots of Trust from Voltage Fault InjectionabstractModern electronic systems such as FPGAs, processors and SoCs are equipped with roots of trust (RoT) to ensure confidentiality, availability and integrity. However, malicious parties can carry out noninvasive voltage fault injection (VFI) attacks to break the RoT. VFI or voltage glitch attack is powerful enough to break security of modern processors from top vendors such as Arm, Intel, AMD etc. Existing voltage glitch detectors require separate response mechanism, and the latency between detection and response make them ineffective. In an effort to integrate detection and response in one countermeasure, recently a NAND/NOR-based polymorphic latch was introduced which changes its behavior with supply voltage. In this work, multiplexer (MUX)-based polymorphic latches, registers, and FSMs are designed and implemented in cryptographic benchmarks capable of destroying data within about 1ns of attack initiation which is about 80× improvement compared to the previous NAND/NOR-based designs. Domenic Forte |
ITC | 2 |
| 2025 | QuEST: Quantitative Entropy based Security and Trojan Detection Framework for Confidentiality VerificationabstractModern semiconductor design heavily relies on the integration of IPs from 3PIP vendors to improve design efficiency and reduce time to market. However, such collaboration introduces security concerns, including unintentional bugs and opportunities for adversaries to insert hardware Trojans. Confidentiality verification is widely applied for detecting design weaknesses capable of leaking sensitive information through output ports of a chip or IP module. In this paper, we present QuEST, a novel confidentiality verification framework that identifies data leakage by analyzing statistical dependencies between multiple input and output ports. Moreover, QuEST augments traditional leakage detection techniques through Shannon entropy-based metrics, most notably mutual information and conditional mutual information, to quantify the extent of data leakage. This quantitative feature enables designers to systematically verify and assess security vulnerabilities more effectively that existing approaches. Experiments show that QuEST successfully detects data leakage caused by hardware Trojans in 11 Trust-hub benchmarks. In general, QuEST serves as a promising confidentiality analysis tool that enables designers to detect and quantify data leakage, thus bolstering the security posture of modern hardware designs. Domenic Forte |
ITC | 2 |
| 2025 | A Persistent Hierarchical Bloom Filter-based Framework for Scalable Authentication and Tracking of ICsabstractDue to the reliance on untrusted supply chain entities, tracking and authentication of Integrated Circuits (ICs) has become crucial to prevent the rapid proliferation of counterfeits. Physically Unclonable Functions (PUFs) can be used for such IC authentication since they generate unique identifiers for individual ICs. However, PUF-generated signatures are often noisy and traditional solutions like Error Correcting Codes (ECC) are expensive and vulnerable to attacks. Moreover, comprehensive PUF-based authentication at multiple locations of the supply chain at any given time suffers from large storage requirements, high query processing time, and security threats. This article proposes a Persistent Hierarchical Bloom Filter (PHBF) to enable fast, storage-efficient and noise-tolerant authentication to track ICs across the supply chain. The proposed framework is demonstrated using 4,000 PUF-generated signatures from several FPGAs and achieved the highest possible authentication accuracy under temperature-induced and synthetic noise of varied degrees without any ECC. Our comparative analysis of storage and query time requirements against four different solutions for detecting wide range counterfeit ICs shows the significant benefit of PHBF, providing up to \(10^{5}\) times faster query processing and 39 times lower storage requirement compared to blockchain. Md. Mashfiq Rizvee, Fairuz Shadmani Shishir, Tanvir Hossain, Tamzidul Hoque, Domenic Forte, Sumaiya Shomaji |
ACM J. Emerg. Technol. Comput. Syst. | 5 |
| 2025 | Sense and React: Self-Destructive Polymorphic Mechanism Against Voltage Tampered Active Physical AttacksabstractSecrets such as cryptographic keys and obfuscation keys are used in modern computing systems to protect the sensitive and private information as well as intellectual property (IP). During typical operations, they are stored in volatile memories, e.g., registers and SRAMs, which are vulnerable to active physical attacks whereby environmental parameters such as temperature, system clock, and supply voltage, are manipulated to extract information. A common way to protect assets against such attacks are sensors that detect active physical attacks and trigger the destruction of secrets. Often, this requires several thousand clock cycles to accomplish. On top of that, the detection and destruction mechanisms are implemented as separate circuitry, which can be identified and disabled by an attacker. In this article, active physical attacks based on supply voltage manipulation are considered. Storage elements, specifically latches and registers, are designed to change their behavior with supply voltage manipulation and automatically destroy their stored data in an integrated sense and response countermeasure. The ability of an electronic circuit to change its behavior under different environmental conditions is known as polymorphism and such circuits are called polymorphic circuits. In the proposed designs, a genetic algorithm (GA) is used to optimize polymorphic gates designed using two separate approaches, namely, multithreshold null convention logic (MTNCL) and voltage-controlled polymorphism termed in this article as Non-MTNCL. These polymorphic gates are used to design polymorphic latches and registers and both approaches are compared using power, performance, area overhead, reliability criteria, and application in cryptographic benchmarks. It is observed that while the GA-optimized MTNCL-based implementation has 75% less area overhead, the GA-optimized Non-MTNCL implementation is 14% more reliable according to simulation results. Apart from the simulations, proof-of-concept is further provided with an FPGA implementation. Andrew Cannon, Luis de la Mata, Rabin Yu Acharya, Tasnuva Farheen, Shahin Tajik, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 7 |
| 2024 | Time Is Money, Friend! Timing Side-Channel Attack Against Garbled Circuit Constructions
Domenic Forte, Fatemeh Ganji |
ACNS (3) | 2 |
| 2024 | Programmable EM Sensor Array for Golden-Model Free Run-Time Trojan Detection and LocalizationabstractSide-channel analysis has been proven effective at detecting hardware Trojans in integrated circuits (ICs). However, most detection techniques rely on large external probes and antennas for data collection and require a long measurement time to detect Trojans. Such limitations make these techniques impractical for run-time deployment and ineffective in detecting small Trojans with subtle side-channel signatures. To overcome these challenges, we propose a Programmable Sensor Array (PSA) for run-time hardware Trojan detection, localization, and identification. PSA is a tampering-resilient integrated on-chip magnetic field sensor array that can be re-programmed to change the sensors' shape, size, and location. Using PSA, EM side-channel measurement results collected from sensors at different locations on an IC can be analyzed to localize and identify the Trojan. The PSA has better performance than conventional external magnetic probes and state-of-the-art on-chip single-coil magnetic field sensors. We fabricated an AES-128 test chip with four AES Hardware Trojans. They were successfully detected, located, and identified with the proposed on-chip PSA within 10 milliseconds using our proposed cross-domain analysis. Hanqiu Wang, Max Panoff, Zihao Zhan, Shuo Wang 0003, Christophe Bobda, Domenic Forte |
DATE | 6 |
| 2024 | Amnesiac Memory: A Self-Destructive Polymorphic Mechanism Against Cold Boot Data Remanence AttackabstractVolatile memories, like registers and SRAM, are integral parts of any CPU or system-on-chip (SoC). They store a variety of on-chip sensitive assets, such as cryptographic keys, intermediate cipher computations, passwords, obfuscation keys, and hardware security primitive outputs. Although such data should be erased as soon as the power is off, it can be susceptible to cold boot attacks. Cold boot attack is based on remanence effect of memories, which says that memory contents do not disappear immediately after power is cut; they fade gradually over time, which can be significantly prolonged at low temperatures. This effect can be exploited by rebooting a running machine and reading what is left in memory. This paper proposes a self-destructive latch extending to amnesiac register, protecting sensitive data when temperature goes to freezing conditions. Our proposed latch senses the temperature drop required during such attacks and reacts instantaneously by entering a forbidden data state, erasing registers stored data. The design uses a NULL convention logic (NCL)-based polymorphic NOR/NAND gate, which changes its functionality with temperature. Our results show that latch and register are stable across process variation, corresponding to attack with 99% and 80% confidence. Even for the 20% where data is not destroyed, in 9.5% of cases data flips its state, making reliable extraction difficult for an attacker. The polymorphic mechanism is straightforward to implement due to its easy implementation, and temperature threshold for self-destructive behavior is easily programmed using only one gate voltage. Tasnuva Farheen, Andrew Cannon, Jia Di, Shahin Tajik, Domenic Forte |
ACM Great Lakes Symposium on VLSI | 6 |
| 2024 | Kin-Wolf: Kinship-established Wolfs in Indirect Synthetic AttackabstractTwo common attacks against biometric systems are direct (or physical) access and indirect (or logical) access. While most detection techniques focus on the former, often called presentation attacks, that occur at pre-sensor level, the attack surface for indirect access, that takes place post-sensor, is larger. In this paper, an indirect attack in the realm of faces is explored that utilizes a unique soft-biometric feature called ‘Kinship Cues’. Unlike gender and ethnicity, kinship is less explored but powerful; we find that its knowledge can significantly increase the chances of an attacker getting access to a system. Due to lack of kin data in other domains, our attack is only performed against facial biometric systems. Nevertheless, the results underscore the impact of kinship cues and their need to be investigated in other domains such as fingerprint and iris. This kinship artifact boosts the convergence speed of state-of-the-art iterative adaptive Bayesian hill climbing attacks. Further, it is exploited to generate a dictionary of input images, commonly called wolf images, in a novel kinship-based non-iterative indirect attack that we call Kin-Wolf. A classical image fusion technique (morphing) and a deep learning based kinship framework utilizing pre-trained StyleGAN2 are investigated to generate the wolf images. The trade-off between kinship cues and randomization is also studied and a 6× average improvement in attack accuracy is achieved for Kin-Wolf over random probes. Pallabi Ghosh, Sumaiya Shomaji, Mengdi Zhu, Damon L. Woodard, Domenic Forte |
IJCB | 5 |
| 2024 | RandOhm: Mitigating Impedance Side-channel Attacks using Randomized Circuit ConfigurationsabstractPhysical side-channel attacks can compromise the security of integrated circuits. Most physical side-channel attacks (e.g., power or electromagnetic) exploit the dynamic behavior of a chip, typically manifesting as changes in current consumption or voltage fluctuations where algorithmic countermeasures, such as masking, can effectively mitigate them. However, as demonstrated recently, these mitigation techniques are not entirely effective against backscattered side-channel attacks such as impedance analysis. In the case of an impedance attack, an adversary exploits the data-dependent impedance variations of the chip's power delivery network (PDN) to extract secret information. In this work, we introduce RandOhm, which exploits a moving target defense (MTD) strategy based on the partial reconfiguration (PR) feature of mainstream FPGAs and programmable SoCs to defend against impedance side-channel attacks. We demonstrate that the information leakage through the PDN's impedance could be significantly reduced via runtime reconfiguration of the secret-sensitive parts of the circuitry. Hence, by constantly randomizing the placement and routing of the circuit, one can decorrelate the data-dependent computation from the impedance value. Moreover, in contrast to existing PR-based countermeasures, RandOhm deploys open-source bitstream manipulation tools on programmable SoCs to speed up the randomization and provide real-time protection. To validate our claims, we apply RandOhm to AES ciphers realized on 28-nm FPGAs. We analyze the resiliency of our approach by performing non-profiled and profiled impedance analysis attacks and investigate the overhead of our mitigation in terms of delay and performance. Saleh Khalaj Monfared, Domenic Forte, Shahin Tajik |
ICCAD | 2 |
| 2024 | LaserEscape: Detecting and Mitigating Optical Probing AttacksabstractThe security of integrated circuits (ICs) can be broken by sophisticated physical attacks relying on failure analysis methods. Optical probing is one of the most prominent examples of such attacks, which can be accomplished in a matter of days, even with limited knowledge of the IC under attack. Unfortunately, few countermeasures are proposed in the literature, and none have been fabricated and tested in practice. These countermeasures usually require changing the standard cell libraries and, thus, are incompatible with digital and programmable platforms, such as field programmable gate arrays (FPGAs). In this work, we shift our attention from preventing the attack to detecting and responding to it. We introduce LaserEscape, the first fully digital and FPGA-compatible countermeasure to detect and mitigate optical probing attacks. LaserEscape incorporates digital delay-based sensors to reliably detect the physical alteration of the fabric caused by laser beam irradiations in real time. Furthermore, as a response to the attack, LaserEscape deploys real-time hiding approaches using randomized hardware reconfigurability. It realizes 1) moving target defense (MTD) to physically move the sensitive circuity under attack out of the probing field of focus to protect secret keys and 2) polymorphism to logically obfuscate the functionality of the targeted circuit to counter function extraction and reverse engineering attempts. We demonstrate the effectiveness and resiliency of our approach by performing optical probing attacks on protected and unprotected designs on a 28-nm FPGA. Our results show that optical probing attacks can be reliably detected and mitigated without interrupting the chip's operation. Saleh Khalaj Monfared, Kyle Mitard, Andrew Cannon, Domenic Forte, Shahin Tajik |
ICCAD | 4 |
| 2023 | ASHES '23: Workshop on Attacks and Solutions in Hardware SecurityabstractThe workshop on "Attacks and Solutions in HardwarE Security (ASHES)" welcomes any theoretical and practical works on hardware security, including attacks, solutions, countermeasures, proofs, classification, formalization, and implementations. Besides mainstream research, ASHES puts some focus on new and emerging scenarios: This includes the Internet of Things (IoT), nuclear weapons inspections, arms control, consumer and infrastructure security, or supply chain security, among others. ASHES also welcomes works on special purpose hardware, such as lightweight, low-cost, and energy-efficient devices, or non-electronic security systems. Lejla Batina, Chip-Hong Chang, Domenic Forte, Ulrich Rührmair |
CCS | 3 |
| 2023 | HT-EMIS: A Deep Learning Tool for Hardware Trojan Detection and Identification through Runtime EM Side-ChannelsabstractHardware Trojans (HTs) are malicious circuits planted in Integrated Circuits (ICs). Multiple techniques using Side-Channel signals to detect HTs have been developed over the past decade. However, most of this research focuses on HT detection. Few of them explore the possibility of either identifying different Hardware Trojans implemented inside ICs or detecting inactive HTs. We propose a runtime EM side-channel analysis workflow (HT-EMIS) that uses a convolutional neural network to address the shortcomings above. By analyzing EM side-channel leakage from an FPGA, our tool can identify known types of HTs implemented inside a design and reports whether they are inactive or active with 100% accuracy. Additionally, we are able to successfully detect new unseen HTs with this model in 98.7% of test cases, due to the fact that HTs inserted at the Register Transfer Level with similar triggers and payloads often have similar effects on a floorplan, and thus the EM radiation of a device. Hanqiu Wang, Max Panoff, Shuo Wang 0003, Domenic Forte |
ACM Great Lakes Symposium on VLSI | 4 |
| 2023 | KinfaceNet: A New Deep Transfer Learning based Kinship Feature Extraction FrameworkabstractAdvances in vision and deep learning have revolutionized feature extraction for face recognition and verification systems, yet, performing kinship verification from such features is still challenging. Ongoing research attempts to imitate a human by identifying features for kinship verification. In this paper, we propose KinfaceNet, a deep learning based kinship feature extractor, capable of extracting kinship features from a single input image independently without requiring its kin pair image. The base model of the method is adopted from face recognition domain which is then transfer learned in the domain of kinship by learning a distance mapping from face images to a compact Euclidean space where distances directly correspond to a measure of kinship similarity. Thus, unlike most of the works in deep learning based kinship domain, the extracted features can be used in many other applications such as image generation and family based clustering, etc. Training is performed by rearranging the data into classes of kin pairs and using a state-of-the-art triplet mining algorithm to address the unbalanced kinship data problem which causes overfitting. Also, one of the major advantages of our framework is that training can be performed on any face feature extractor model pre-trained on large face recognition data, thereby reducing training time by a considerable amount. Comparable verification accuracy is obtained from simple MLP network at only 20th epoch with KinfaceNet features extracted from the Family-In-the-Wild dataset, the largest in the wild kinship dataset available, as well as KinfaceW-I and II datasets. Pallabi Ghosh, Sumaiya Shomaji, Damon L. Woodard, Domenic Forte |
IJCB | 4 |
| 2023 | Protection Against Physical Attacks Through Self-Destructive Polymorphic LatchabstractOn-chip assets, such as cryptographic keys, intermediate cipher computations, obfuscation keys, and hardware security primitive outputs, are usually stored in volatile memories, e.g., registers and SRAMs. Such volatile memories could be read out using active physical attacks, such laser-assisted side-channels. One way to protect assets stored in volatile memories can be the employment of sensors that detect active physical attacks and trigger complete zeroization of sensitive data. However, hundreds or thousands of clock cycles are often needed to accomplish this. Further, the sensing and self-destruction mechanisms are decoupled from the sensitive circuitry and can be disabled separately by an adversary. Moreover, defensive actions (e.g., zeroization) may be disabled by bringing the CPU/SoC into an inoperable condition, while registers may still hold their data, making them susceptible. This paper proposes a self-destructive latch to protect sensitive data from active side-channel attacks, which require supply voltage manipulations. Our proposed latch senses supply voltage interference required during such attacks, and reacts instantaneously by entering a forbidden data state, erasing its stored data. The design uses a NULL convention logic (NCL)-based polymorphic NOR/NAND gate, which changes its functionality with supply voltage. Our results show that the latch is stable across temperature and process variation reacting to attacks with 91% confidence. Even for the 9% where data is not destroyed, in 3.33 % of cases data flips its state which makes reliable extraction difficult for an attacker. The polymorphic latch is straightforward to implement due to its NCL implementation and the voltage for the self-destructive behavior is easily altered by resizing only two transistors. Further, this self-destructive behavior extends to registers which are built out of latches. Andrew Cannon, Tasnuva Farheen, Shahin Tajik, Domenic Forte |
ICCAD | 5 |
| 2023 | Laser Fault Injection Vulnerability Assessment and Mitigation with Case Study on PG-TVD Logic CellsabstractPhysical attacks on secure devices can leak sensitive data and have significant consequences for individuals, companies, and governments. Today, much research is centered around understanding hardware weaknesses and vulnerabilities and, in turn, designing countermeasures to increase system security. One such countermeasure is the implementation of the camouflaging gate called PG-TVD (pass gate-based threshold voltage defined), which ensures protection against reverse engineering and sidechannel attacks. However, proper investigation is needed to determine if the countermeasure opens the door to other powerful attacks, such as laser fault injection (LFI) attacks. Identifying the vulnerability against this attack requires a proper assessment. As the first attempt to understand laser sensitivity in PG-TVD, we develop a workflow for assessing a circuit layout's sensitivity to LFI. We use this workflow to analyze the PG-TVD, giving the laser-sensitive areas. A deeper understanding of how to protect devices can be gained from this assessment to keep sensitive data secure. From the information obtained by our workflow, we also propose, design, and simulate a mitigation scheme that mitigates the laser sensitivity in PG-TVD logic cells by approximately 83%. Ryan Holzhausen, Tasnuva Farheen, Morgan Thomas, Nima Maghari, Domenic Forte |
ITC | 5 |
| 2023 | A Fast Object Detection-Based Framework for Via Modeling on PCB X-Ray CT ImagesabstractFor successful printed circuit board (PCB) reverse engineering (RE), the resulting device must retain the physical characteristics and functionality of the original. Although the applications of RE are within the discretion of the executing party, establishing a viable, non-destructive framework for analysis is vital for any stakeholder in the PCB industry. A widely regarded approach in PCB RE uses non-destructive x-ray computed tomography (CT) to produce three-dimensional volumes with several slices of data corresponding to multi-layered PCBs. However, the noise sources specific to x-ray CT and variability from designers hampers the thorough acquisition of features necessary for successful RE. This article investigates a deep learning approach as a successor to the current state-of-the-art for detecting vias on PCB x-ray CT images; vias are a key building block of PCB designs. During RE, vias offer an understanding of the PCB’s electrical connections across multiple layers. Our method is an improvement on an earlier iteration which demonstrates significantly faster runtime with quality of results comparable to or better than the current state-of-the-art, unsupervised iterative Hough-based method. Compared with the Hough-based method, the current framework is 4.5 times faster for the discrete image scenario and 24.1 times faster for the volumetric image scenario. The upgrades to the prior deep learning version include faster feature-based detection for real-world usability and adaptive post-processing methods to improve the quality of detections. David Selasi Koblah, Ulbert Botero, Sean P. Costello, Olivia P. Dizon-Paradis, Fatemeh Ganji, Damon L. Woodard, Domenic Forte |
ACM J. Emerg. Technol. Comput. Syst. | 7 |
| 2023 | iPROBE: Internal Shielding Approach for Protecting Against Front-Side and Back-Side Probing AttacksabstractFocused ion beam (FIB) has emerged as one of the most prevalent integrated circuit (IC) editing techniques in the past decade, greatly assisting post-silicon debugging and failure analysis. However, the confidentiality of security assets on electronic devices is gravely threatened by FIB-based probing attacks because of the FIB’s fine-grained milling and deposition capabilities on silicon die. Although numerous solutions, such as active shields and analog sensors have been proposed, they either incur prohibitively high overhead or suffer from low reliability, failing to provide protection against such threats in a feasible manner. In this article, we propose a FIB-aware framework, iPROBE, as a set of computer-aided design (CAD) utilities to quantify the threats of FIB attacks on the target layout from both front-side and back-side at the pre-silicon stage. The subsequent shield nets/layer place-and-route are completely automated by iPROBE to minimize the quantified FIB vulnerability metric, so-called exposed area (EA), allowing users to achieve the optimal security level at a cost of minimal performance degradation, extra design efforts, and time consumption. Our experimental results show that the EA of security-critical nets, i.e., vulnerable regions inside the physical layout, to front-side and back-side probing attacks can be fully eliminated at low FIB aspect ratios with only 3% timing and area overhead. Moreover, we validate the results through the FIB experiments on a fabricated test chip covering both baseline and iPROBE-protected AES implementations at 65nm technology node, further demonstrating the effectiveness of iPROBE. Minyan Gao, M. Sazadur Rahman, Nitin Varshney, Mark Tehranipoor, Domenic Forte |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2023 | Enhanced PATRON: Fault Injection and Power-aware FSM Encoding Through Linear ProgrammingabstractSince finite state machines (FSMs) regulate the control flow in circuits, a computing system’s security might be breached by attacking the FSM. Physical attacks are especially worrisome because they can bypass software countermeasures. For example, an attacker can gain illegal access to the sensitive states of an FSM through fault injection, leading to privilege escalation and/or information leakage. Laser fault injection (LFI) provides one of the most effective attack vectors by enabling adversaries to precisely overturn single flip-flops states. Although conventional error correction/detection methodologies have been employed to improve FSM resiliency, their substantial overhead makes them unattractive to circuit designers. In our prior work, a novel decision diagram-based FSM encoding scheme called PATRON was proposed to resist LFI according to attack parameters, e.g., number of simultaneous faults. Although PATRON bested traditional encodings keeping overhead minimum, it provided numerous candidates for FSM designs requiring exhaustive and manual effort to select one optimum candidate. In this article, we automatically select an optimum candidate by enhancing PATRON using linear programming (LP). First, we exploit the proportionality between dynamic power dissipation and switching activity in digital CMOS circuits. Thus, our LP objective minimizes the number of FSM bit switches per transition, for comparatively lower switching activity and hence total power consumption. Second, additional LP constraints along with incorporating the original PATRON rules, systematically enforce bidirectionality to at least two state elements per FSM transition. This bestows protection against different types of fault injection, which we capture with a new unidirectional metric. Enhanced PATRON (EP) achieves superior security at lower power consumption in average compared to PATRON, error-coding, and traditional FSM encoding on five popular benchmarks. Muhtadi Choudhury, Minyan Gao, Avinash L. Varna, Elad Peer, Domenic Forte |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2023 | A Survey and Perspective on Artificial Intelligence for Security-Aware Electronic Design AutomationabstractArtificial intelligence (AI) and machine learning (ML) techniques have been increasingly used in several fields to improve performance and the level of automation. In recent years, this use has exponentially increased due to the advancement of high-performance computing and the ever increasing size of data. One of such fields is that of hardware design—specifically the design of digital and analog integrated circuits, where AI/ ML techniques have been extensively used to address ever-increasing design complexity, aggressive time to market, and the growing number of ubiquitous interconnected devices. However, the security concerns and issues related to integrated circuit design have been highly overlooked. In this article, we summarize the state-of-the-art in AI/ML for circuit design/optimization, security and engineering challenges, research in security-aware computer-aided design/electronic design automation, and future research directions and needs for using AI/ML for security-aware circuit design. David Selasi Koblah, Rabin Yu Acharya, Daniel E. Capecci, Olivia P. Dizon-Paradis, Shahin Tajik, Fatemeh Ganji, Damon L. Woodard, Domenic Forte |
ACM Trans. Design Autom. Electr. Syst. | 8 |
| 2023 | A Twofold Clock and Voltage-Based Detection Method for Laser Logic State Imaging AttackabstractPowerful side-channel analysis (SCA) attacks based on failure analysis (FA) techniques can bypass conventional countermeasures on integrated circuits (ICs) and, therefore, break the entire system’s security. Laser logic state imaging (LLSI) from the IC backside is an example of such attacks, making the contactless probing of static on-die signals possible. Several countermeasures have been proposed to prevent optical probing attacks, such as LLSI. However, these schemes are designed according to the laser properties and its impact on transistors, and hence, they have complex fabrication steps and large area overhead. As a result, they are difficult to verify and implement. In this article, we propose a twofold detection self-timed sensor, which is the first attempt, to our knowledge, for an easy-to-implement circuit-based countermeasure to thwart LLSI attacks. To perform LLSI, the attacker needs to freeze the clock at a point of interest and modulate the voltage supply line at a known frequency to leak the state of transistors through laser light reflections. With these two attack requirements in mind, we design, simulate, and implement clock- and voltage-based sensors that can detect LLSI attacks with very high confidence. Tasnuva Farheen, Shahin Tajik, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2022 | ASHES 2022 - 6th Workshop on Attacks and Solutions in Hardware SecurityabstractThe workshop on "Attacks and Solutions in HardwarE Security (ASHES)" welcomes any theoretical and practical works on hardware security, including attacks, solutions, countermeasures, proofs, classification, formalization, and implementations. Besides mainstream research, ASHES puts some focus on new and emerging scenarios: This includes the Internet of Things (IoT), nuclear weapons inspections, arms control, consumer and infrastructure security, or supply chain security, among others. ASHES also welcomes dedicated works on special purpose hardware, such as lightweight, low-cost, and energy-efficient devices, or non-electronic security systems. The workshop hosts four different paper categories: Apart from regular and short papers, this includes works that systematize and structure a certain (sub-)area (so-called "Systematization of Knowledge" (SoK) papers), and so-termed "Wild-and-Crazy" (WaC) papers, which distribute seminal ideas at an early conceptual stage. This summary gives a brief overview of the sixth edition of the workshop, which took place virtually on November 11, 2022 in Los Angeles, California, USA, as a post-conference satellite workshop of ACM CCS. Chip-Hong Chang, Domenic Forte, Debdeep Mukhopadhyay, Ulrich Rührmair |
CCS | 2 |
| 2022 | Garbled EDA: Privacy Preserving Electronic Design AutomationabstractThe complexity of modern integrated circuits (ICs) necessitates collaboration between multiple distrusting parties, including third-party intellectual property (3PIP) vendors, design houses, CAD/EDA tool vendors, and foundries, which jeopardizes confidentiality and integrity of each party's IP. IP protection standards and the existing techniques proposed by researchers are ad hoc and vulnerable to numerous structural, functional, and/or side-channel attacks. Our framework, Garbled EDA, proposes an alternative direction through formulating the problem in a secure multi-party computation setting, where the privacy of IPs, CAD tools, and process design kits (PDKs) is maintained. As a proof-of-concept, Garbled EDA is evaluated in the context of simulation, where multiple IP description formats (Verilog, C, S) are supported. Our results demonstrate a reasonable logical-resource cost and negligible memory overhead. To further reduce the overhead, we present another efficient implementation methodology, feasible when the resource utilization is a bottleneck, but the communication between two parties is not restricted. Interestingly, this implementation is private and secure even in the presence of malicious adversaries attempting to, e.g., gain access to PDKs or in-house IPs of the CAD tool providers. Steffi Roy, Fatemeh Ganji, Domenic Forte |
ICCAD | 4 |
| 2022 | TAMED: Transitional Approaches for LFI Resilient State Machine EncodingabstractFinite state machines (FSMs) control the behavior of sequential circuits, including access to privileged states and sensitive information. Laser-based fault injection (LFI) is a precise method where an adversary breaks the chip security by altering the values of individual flip-flops (FFs) with a laser beam. To understand LFI, different laser models, e.g., bit flip, bit set, and bit reset, have been developed. Existing countermeasures can improve FSM resiliency, but either generate multiple LFI resilient encodings applicable only to certain models, or are too conservative, thus incurring significant overhead. In this paper, we introduce the transition-based encoding CAD framework (TAMED), which offers greater flexibility by precisely generating a single optimized FSM encoding that is resilient to multiple LFI models. Predicated on linear programming, TAMED introduces Transitional Vulnerability Metrics that can quantify susceptibility of FSMs based on the bit flip model and the set-reset models. TAMED is demonstrated on 5 benchmarks and outperforms other FSM encoding schemes in terms of security and overhead. Muhtadi Choudhury, Minyan Gao, Shahin Tajik, Domenic Forte |
ITC | 4 |
| 2022 | REFICS: A Step Towards Linking Vision with Hardware AssuranceabstractHardware assurance is a key process in ensuring the integrity, security and functionality of a hardware device. Its heavy reliance on images, especially on Scanning Electron Microscopy images, makes it an excellent candidate for the vision community. The goal of this paper is to provide a pathway for inter-community collaboration by introducing the existing challenges for hardware assurance on integrated circuits in the context of computer vision and support further development using a large-scale dataset with 800,000 images. A detailed benchmark of existing vision approaches in hardware assurance on the dataset is also included for quantitative insights into the problem. Ronald Wilson, Hangwei Lu, Mengdi Zhu, Domenic Forte, Damon L. Woodard |
WACV | 4 |
| 2022 | EigenCircuit: Divergent Synthetic Benchmark Generation for Hardware Security Using PCA and Linear ProgrammingabstractBenchmarks are the standards by which technologies can be evaluated and fairly compared. In the field of digital circuits, benchmarks were critical for the development of CAD and FPGA tools decades ago. Hardware security is an emerging field of research where new techniques of security and vulnerability of hardware designs are being proposed in higher volume each year. Using decade-old VLSI/CAD-oriented benchmarks for analyzing the techniques has many issues as these benchmarks were not developed for security research. Additionally, the rise of statistical analysis or machine learning (ML) to model vulnerabilities and solve security issues demands a very large set of samples for training purposes. Since the number of available VLSI/CAD benchmarks is limited, such volume can only be obtained through synthetic benchmark generation tools. To accommodate both of these needs, the first hardware security-oriented synthetic circuit benchmark generation framework is developed in this article. With the use of principal component analysis (PCA) and linear optimization tool, the benchmarks generated by the proposed framework are “divergent,” that is having maximum variation in structures from each other. By accommodating user inputs for desired features, the framework offers customization for generating richer and more challenging benchmarks for data-driven hardware security. With thorough experimentation, we demonstrate our framework’s scalability, the structural and functional variations in the generated benchmarks, and the advantage of structurally variant synthetic benchmarks in hardware security applications. Sarah Amir, Domenic Forte |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | RASCv2: Enabling Remote Access to Side-Channels for Mission Critical and IoT SystemsabstractThe Internet of Things (IoT) and smart devices are currently being deployed in systems such as autonomous vehicles and medical monitoring devices. The introduction of IoT devices into these systems enables network connectivity for data transfer, cloud support, and more, but can also lead to malware injection. Since many IoT devices operate in remote environments, it is also difficult to protect them from physical tampering. Conventional protection approaches rely on software. However, these can be circumvented by the moving target nature of malware or through hardware attacks. Alternatively, insertion of the internal monitoring circuits into IoT chips requires a design trade-off, balancing the requirements of the monitoring circuit and the main circuit. A very promising approach to detecting anomalous behavior in the IoT and other embedded systems is side-channel analysis. To date, however, this can be performed only before deployment due to the cost and size of side-channel setups (e.g., and oscilloscopes, probes) or by internal performance counters. Here, we introduce an external monitoring printed circuit board (PCB) named RASC to provide r emote a ccess to s ide- c hannels. RASC reduces the complete side-channel analysis system into two small PCBs (2 \( \times \) 2 cm), providing the ability to monitor power and electromagnetic (EM) traces of the target device. Additionally, RASC can transmit data and/or alerts of anomalous activities detected to a remote host through Bluetooth. To demonstrate RASCs capabilities, we extract keys from encryption modules such as AES implemented on Arduino and FPGA boards. To illustrate RASC’s defensive capabilities, we also use it to perform malware detection. RASC’s success in power analysis is comparable to an oscilloscope/probe setup but is lightweight and two orders of magnitude cheaper. Yunkai Bai, Andrew Stern, Jungmin Park, Mark Tehranipoor, Domenic Forte |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2021 | PATRON: A Pragmatic Approach for Encoding Laser Fault Injection Resistant FSMsabstractSince Finite State Machines (FSMs) regulate the overall operations in majority of the digital systems, the security of an entire system can be jeopardized if the FSM is vulnerable to physical attacks. By injecting faults into an FSM, an attacker can attain unauthorized access to sensitive states, resulting in information leakage and privilege escalation. One of the powerful fault injection techniques is laser-based fault injection (LFI), which enables an adversary to alter states of individual flip-flops. While standard error correction/detection techniques have been used to protect the FSMs from such fault attacks, their significant overhead makes them unattractive to designers. To keep the overhead minimal, we propose a novel FSM encoding scheme based on decision diagrams that utilizes don't-care states of the FSM. We demonstrate that PATRON outperforms conventional encoding schemes in terms of both security and scalability for popular benchmarks. Finally, we introduce a vulnerability metric to aid the security analysis, which precisely manifests the susceptibility of FSM designs. Muhtadi Choudhury, Domenic Forte, Shahin Tajik |
DATE | 2 |
| 2021 | Hardware Trust and Assurance through Reverse Engineering: A Tutorial and Outlook from Image Analysis and Machine Learning PerspectivesabstractIn the context of hardware trust and assurance, reverse engineering has been often considered as an illegal action. Generally speaking, reverse engineering aims to retrieve information from a product, i.e., integrated circuits (ICs) and printed circuit boards (PCBs) in hardware security-related scenarios, in the hope of understanding the functionality of the device and determining its constituent components. Hence, it can raise serious issues concerning Intellectual Property (IP) infringement, the (in)effectiveness of security-related measures, and even new opportunities for injecting hardware Trojans. Ironically, reverse engineering can enable IP owners to verify and validate the design. Nevertheless, this cannot be achieved without overcoming numerous obstacles that limit successful outcomes of the reverse engineering process. This article surveys these challenges from two complementary perspectives: image processing and machine learning. These two fields of study form a firm basis for the enhancement of efficiency and accuracy of reverse engineering processes for both PCBs and ICs. In summary, therefore, this article presents a roadmap indicating clearly the actions to be taken to fulfill hardware trust and assurance objectives. Ulbert Botero, Ronald Wilson, Hangwei Lu, M. Tanjidur Rahman, Mukhil A. Mallaiyan, Fatemeh Ganji, Navid Asadizanjani, Mark Tehranipoor, Damon L. Woodard, Domenic Forte |
ACM J. Emerg. Technol. Comput. Syst. | 10 |
| 2021 | Introduction to the Special Issue on Emerging Challenges and Solutions in Hardware Securityabstractintroduction Introduction to the Special Issue on Emerging Challenges and Solutions in Hardware Security Share on Editors: Domenic Forte View Profile , Debdeep Mukhopadhyay View Profile , Ilia Polian View Profile , Yunsi Fei View Profile , Rosario Cammarota View Profile Authors Info & Claims ACM Journal on Emerging Technologies in Computing SystemsVolume 17Issue 3July 2021 Article No.: 29pp 1–4https://doi.org/10.1145/3464326Online:30 June 2021Publication History 0citation108DownloadsMetricsTotal Citations0Total Downloads108Last 12 Months108Last 6 weeks4 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Domenic Forte, Debdeep Mukhopadhyay, Ilia Polian, Yunsi Fei, Rosario Cammarota |
ACM J. Emerg. Technol. Comput. Syst. | 1 |
| 2021 | A Metal-Via Resistance Based Physically Unclonable Function With Backend Incremental ADCabstractThis paper presents a novel physically unclonable function (PUF) for security authentication. Instead of using the variation of transistors or PDK provided passive components as entropy source, the parasitic resistance created between metal and via layers is used as the static entropy source. A symmetric bridge configuration consisted with the parasitic resistance creates the necessary voltage difference for comparison. An accurate backend incremental analog-to-digital converter (IADC) is implemented to convert the voltage difference into a digitized value. The operation of the IADC allows to achieve a good native instability. Two different types of layout structures are implemented to create the necessary parasitic resistance and compared. Fabricated in a 65nm process, the prototype PUF achieves a native instability and bit error rate of less than 1.45% and 0.12% with 5000 repeated evaluations. The proposed design shows 0.58%/0.1V and 0.53%/10°C bit error across the voltage and temperature range of 0.9 to 1.4V and 0°C to 85°C, respectively without any stabilization techniques. The distance ratio between intra-die and inter-die Hamming Distance is above$305\times $. Beomsoo Park, Domenic Forte, Mark Tehranipoor, Nima Maghari |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2021 | An Analysis of Enrollment and Query Attacks on Hierarchical Bloom Filter-Based Biometric SystemsabstractA Hierarchical Bloom Filter (HBF) -based biometric framework was recently proposed to provide compact storage, noise tolerance, and fast query processing for resource-constrained environments, e.g., Internet of things (IoT). While security and privacy were also touted as features of the HBF, it was not thoroughly evaluated. Compared to the classical BFs, the HBF uses a threshold parameter to make robust authentication decisions when the HBF encounters noise in the biometric input which one would think might lead to security issues. In this paper, the attack vectors that could compromise the HBF security by increasing the false positive authentication of non-members and by leaking soft information about enrolled members are explored. With quantitative analyses, HBF-based biometric system security under these well-defined attack vectors is evaluated and it is concluded that the framework is more difficult to attack than the classical Bloom Filter. Further, experimental results show that soft biometric information is also kept private. Sumaiya Shomaji, Pallabi Ghosh, Fatemeh Ganji, Damon L. Woodard, Domenic Forte |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Security Assessment of Dynamically Obfuscated Scan Chain Against Oracle-guided AttacksabstractLogic locking has emerged as a promising solution to protect integrated circuits against piracy and tampering. However, the security provided by existing logic locking techniques is often thwarted by Boolean satisfiability (SAT)-based oracle-guided attacks. Criteria for successful SAT attacks on locked circuits include: (i) the circuit under attack is fully combinational, or (ii) the attacker has scan chain access. To address the threat posed by SAT-based attacks, we adopt the dynamically obfuscated scan chain (DOSC) architecture and illustrate its resiliency against the SAT attacks when inserted into the scan chain of an obfuscated design. We demonstrate, both mathematically and experimentally, that DOSC exponentially increases the resiliency against key extraction by SAT attack and its variants. Our results show that the mathematical estimation of attack complexity correlates to the experimental results with an accuracy of 95% or better. Along with the formal proof, we model DOSC architecture to its equivalent combinational circuit and perform SAT attack to evaluate its resiliency empirically. Our experiments demonstrate that SAT attack on DOSC-inserted benchmark circuits timeout at minimal test time overhead, and while DOSC requires less than 1% area and power overhead. M. Sazadur Rahman, Adib Nahiyan, Fahim Rahman, Saverio Fazzari, Kenneth Plaks, Farimah Farahmandi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 7 |
| 2020 | Pitfalls in Machine Learning-based Adversary Modeling for Hardware SystemsabstractThe concept of the adversary model has been widely applied in the context of cryptography. When designing a cryptographic scheme or protocol, the adversary model plays a crucial role in the formalization of the capabilities and limitations of potential attackers. These models further enable the designer to verify the security of the scheme or protocol under investigation. Although being well established for conventional cryptanalysis attacks, adversary models associated with attackers enjoying the advantages of machine learning techniques have not yet been developed thoroughly. In particular, when it comes to composed hardware, often being security-critical, the lack of such models has become increasingly noticeable in the face of advanced, machine learning-enabled attacks. This paper aims at exploring the adversary models from the machine learning perspective. In this regard, we provide examples of machine learning-based attacks against hardware primitives, e.g., obfuscation schemes and hardware root-of-trust, claimed to be infeasible. We demonstrate that this assumption becomes however invalid as inaccurate adversary models have been considered in the literature. Fatemeh Ganji, Sarah Amir, Shahin Tajik, Domenic Forte, Jean-Pierre Seifert |
DATE | 4 |
| 2020 | Adaptable and Divergent Synthetic Benchmark Generation for Hardware SecurityabstractBenchmarking can drive the development of technologies by facilitating standardization of features for comparison of different methods. While hardware security has seen an exponential growth in innovation throughout the last decade, the lack of sufficient benchmarks for data-driven analysis is prominent. Researchers must currently rely on decades-old VLSI benchmarks, which in most cases were not designed with security evaluation in mind. Considering the present day computational power, these benchmarks lack in both quality and quantity for usage in hardware security topics such as obfuscation and hardware Trojans. Many advanced techniques, like statistical analysis and machine learning, require a large number of samples in order to sufficiently examine the feature space. In an attempt to resolve this issue, we have developed the first synthetic benchmark generation process flow. This paper describes our novel technique that utilizes linear optimization to generate an endless number of synthetic combinational benchmarks that are adaptable to user input constraints and divergent in quantifiable structural features from input reference benchmarks. Thus, our framework offers customization for generating richer and more challenging benchmarks for data-driven hardware security. Through experimentation, we verify that our benchmarks offers more structural variation than the current benchmark suites. Sarah Amir, Domenic Forte |
ICCAD | 2 |
| 2020 | Low-Cost Remarked Counterfeit IC Detection using LDO RegulatorsabstractRemarked and recycled counterfeit integrated circuits (ICs) form a vast majority (≈80-90%) of the total number of counterfeit IC instances. Although different types of test strategies have been developed for recycled IC detection, techniques that detect remarked ICs are limited. In this paper, we develop a method to detect false remarking of commercial grade chips into industrial/automotive grade by distinguishing power supply rejection ratio (PSRR) of commercial and automotive grade low drop-out (LDO) regulators from four different vendors. In this process, we use supervised and unsupervised machine learning (ML) methods on PSRR measurements. Our results show a best-case accuracy of 90% for both commercial and industrial LDOs with supervised ML. On the other hand, unsupervised ML can detect commercial and industrial LDOs with a best-case accuracy of 75% for both types. Sreeja Chowdhury, Fatemeh Ganji, Domenic Forte |
ISCAS | 3 |
| 2020 | A Weak Asynchronous RESet (ARES) PUF Using Start-up Characteristics of Null Conventional Logic GatesabstractPhysical unclonable functions (PUFs) are widely researched security primitive in the digital and analog domain but have yet to be explored for asynchronous circuits. In this paper, we propose novel optimization methods to design a weak Asynchronous RESet (ARES) PUF that exploits random start-up characteristics of Threshold M of N Null Conventional Logic (NCL) gates as a source of entropy. We employ two different methods to design the ARES PUF. The first includes traditional delay matching techniques using linear programming-based optimization, whereas the second one uses the genetic algorithm (GA) with delay matching as a fitness function. Both methodologies are explained with analysis and design specifications required to model NCL TH22 gates to achieve PUF characteristics. Threshold 2 of 2 (TH22) and 4 of 4 (TH44) gates are used as test cases for evaluation and comparison. Simulation results using initial delay matching techniques at 90nm and 65nm technology in HSPICE shows that the proposed ARES PUF has a uniqueness of 49.98% and reliability of 96.53% across VDD variation (±10%) and 93.39% across temperature variation (0°C-80°C). Whereas, the GA method can optimize NCL cells to form a PUF with 49% uniqueness at 65nm with an average reliability of 96.4% across VDD and 93.82% across temperature. Preliminary silicon results for proposed TH22 at TSMC 90nm technology node shows a 34% improvement in uniqueness compared to standard TH22 gate with best-case uniqueness of 53.3% and reliability of 100% respectively across repeated measurements (noise). Unlike standard TH22, standard TH44 performs better with 47.62% best-case uniqueness and 98.1% reliability1. Sreeja Chowdhury, Rabin Yu Acharya, William Boullion, Andrew Felder, Mark Howard, Jia Di, Domenic Forte |
ITC | 7 |
| 2020 | Defense-in-depth: A recipe for logic locking to prevail
M. Tanjidur Rahman, M. Sazadur Rahman, Shahin Tajik, Waleed Khalil, Farimah Farahmandi, Domenic Forte, Navid Asadizanjani, Mark Tehranipoor |
Integr. | 7 |
| 2020 | Permutation Network De-obfuscation: A Delay-based Attack and Countermeasure InvestigationabstractPermutation-based obfuscation has been proposed to protect hardware against cloning, overproduction, reverse engineering, and unauthorized operation. To prevent key extraction from memory, the key used by the obfuscation is usually stored in volatile memory. Since the key is erased after the system loses power, this scheme is often considered the best way to prevent a key from being stolen, since many attacks would require power. However, in this article, we propose a new attack where the key is determined by exploring path aging within the permutation network used for obfuscation. Both the theoretical analysis and experimental results are provided. A practical procedure to achieve the proposed attack is also discussed in the context of an attacker’s capabilities and knowledge. The proposed attack is executed in both simulation and hardware. The experimental results show the accuracy of identifying the key is over 80% and more than enough to reduce the number of brute-force combinations required by an attacker. This attack accuracy reaches 100% when the permutation network has experienced sufficient degradations. Besides the attack, we also propose a low-cost countermeasure that sweeps the permutation network configurations. Incorporating this countermeasure, the proposed attack becomes no better than brute-force guessing. Zimu Guo, Sreeja Chowdhury, Mark Tehranipoor, Domenic Forte |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2020 | Leveraging Side-Channel Information for Disassembly and SecurityabstractWith the rise of Internet of Things (IoT), devices such as smartphones, embedded medical devices, smart home appliances as well as traditional computing platforms such as personal computers and servers have been increasingly targeted with a variety of cyber attacks. Due to limited hardware resources for embedded devices and difficulty in wide-coverage and on-time software updates, software-only cyber defense techniques, such as traditional anti-virus and malware detectors, do not offer a silver-bullet solution. Hardware-based security monitoring and protection techniques, therefore, have gained significant attention. Monitoring devices using side channel leakage information, e.g. power supply variation and electromagnetic (EM) radiation, is a promising avenue that promotes multiple directions in security and trust applications. In this paper, we provide a taxonomy of hardware-based monitoring techniques against different cyber and hardware attacks, highlight the potentials and unique challenges, and display how power-based side-channel instruction-level monitoring can offer suitable solutions to prevailing embedded device security issues. Further, we delineate approaches for future research directions. Jungmin Park, Fahim Rahman, Apostol Vassilev 0001, Domenic Forte, Mark Tehranipoor |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2020 | A Physical Design Flow Against Front-Side Probing Attacks by Internal ShieldingabstractSecurity-critical applications on integrated circuits (ICs) are threatened by probing attacks that extract sensitive information assisted with focused ion beam (FIB)-based circuit edit. Existing countermeasures, such as active shield, analog shield, and t-private circuit, have proven to be inefficient and provide limited resistance against probing attacks without taking FIB capabilities into consideration. In this article, we propose an FIB-aware anti-probing physical design flow, which considers FIB capabilities and utilizes computer-aided design (CAD) tools, to automatically reduce the probing attack vulnerability of an IC's security-critical nets with minimal extra design effort. The floor-planning and routing of the design are constrained by incorporating three new steps in the conventional physical design flow, so that security-critical nets are protected by internal shield nets with low overhead. Results show that the proposed technique can reduce the vulnerable area exposed to probing on security-critical nets by 100% with all critical nets fully protected for both advanced encryption standard (AES) and data encryption standard (DES) modules. The timing, area, and power overheads are less than 3% per module, which would be negligible in a system-on-chip (SoC) design. Qihang Shi, Adib Nahiyan, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2020 | Soft-HaT: Software-Based Silicon Reprogramming for Hardware Trojan ImplementationabstractA hardware Trojan is a malicious modification to an integrated circuit (IC) made by untrusted third-party vendors, fabrication facilities, or rogue designers. Although existing hardware Trojans are designed to be stealthy, they can, in theory, be detected by post-manufacturing and acceptance tests due to their physical connections to IC logic. Manufacturing tests can potentially trigger the Trojan and propagate its payload to an output. Even if the Trojan is not triggered, the physical connections to the IC can enable detection due to additional side-channel activity (e.g., power consumption). In this article, we propose a novel hardware Trojan design, called Soft-HaT , which only becomes physically connected to other IC logic after activation by a software program. Using an electrically programmable fuse (E-fuse), the hardware can be “re-programmed” remotely. We illustrate how Soft-HaT can be used for offensive applications in system-on-chips. Examples of Soft-HaT attacks are demonstrated on an open source system-on-chip (OrpSoC) and implemented in Virtex-7 FPGA to show their efficacy in terms of stealthiness. Adib Nahiyan, Mehdi Sadi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2020 | Hidden in Plaintext: An Obfuscation-based Countermeasure against FPGA Bitstream Tampering AttacksabstractField Programmable Gate Arrays (FPGAs) have become an attractive choice for diverse applications due to their reconfigurability and unique security features. However, designs mapped to FPGAs are prone to malicious modifications or tampering of critical functions. Besides, targeted modifications have demonstrably compromised FPGA implementations of various cryptographic primitives. Existing security measures based on encryption and authentication can be bypassed using their side-channel vulnerabilities to execute bitstream tampering attacks. Furthermore, numerous resource-constrained applications are now equipped with low-end FPGAs, which may not support power-hungry cryptographic solutions. In this article, we propose a novel obfuscation-based approach to achieve strong resistance against both random and targeted pre-configuration tampering of critical functions in an FPGA design. Our solution first identifies the unique structural and functional features that separate the critical function from the rest of the design using a machine learning guided framework. The selected features are eliminated by applying appropriate obfuscation techniques, many of which take advantage of “FPGA dark silicon”—unused lookup table resources—to mask the critical functions. Furthermore, following the same obfuscation principle, a redundancy-based technique is proposed to thwart targeted, rule-based, and random tampering. We have developed a complete methodology and custom software toolflow that integrates with commercial tools. By applying the masking technique on a design containing AES, we show the effectiveness of the proposed framework in hiding the critical S-Box function. We implement the redundancy integrated solution in various cryptographic designs to analyze the overhead. To protect 16.2% critical component of a design, the proposed approach incurs an average area overhead of only 2.4% over similar redundancy-based approaches, while achieving strong security. Tamzidul Hoque, Kai Yang 0028, Robert Karam, Shahin Tajik, Domenic Forte, Mark Tehranipoor, Swarup Bhunia |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2020 | SCRIPT: A CAD Framework for Power Side-channel Vulnerability Assessment Using Information Flow Tracking and Pattern GenerationabstractPower side-channel attacks (SCAs) have been proven to be effective at extracting secret keys from hardware implementations of cryptographic algorithms. Ideally, the power side-channel leakage (PSCL) of hardware designs of a cryptographic algorithm should be evaluated as early as the pre-silicon stage (e.g., gate level). However, there has been little effort in developing computer-aided design (CAD) tools to accomplish this. In this article, we propose an automated CAD framework called SCRIPT to evaluate information leakage through side-channel analysis. SCRIPT starts by defining the underlying properties of the hardware implementation that can be exploited by side-channel attacks. It then utilizes information flow tracking (IFT) to identify registers that exhibit those properties and, therefore, leak information through the side-channel. Here, we develop an IFT-based side-channel vulnerability metric ( SCV ) that is utilized by SCRIPT for PSCL assessment. SCV is conceptually similar to the traditionally used signal-to-noise ratio (SNR) metric. However, unlike SNR, which requires thousands of traces from silicon measurements, SCRIPT utilizes formal methods to generate SCV-guided patterns/plaintexts, allowing us to derive SCV using only a few patterns (ideally as low as two) at gate level. SCV estimates PSCL vulnerability at pre-silicon stage based on the number of plaintexts required to attain a specific SCA success rate. The integration of IFT and pattern generation makes SCRIPT efficient, accurate, and generic to be applied to any hardware design. We validate the efficacy of the SCRIPT framework by demonstrating that it can effectively and accurately determine SCA success rates for different AES designs at pre-silicon stage. SCRIPT is orders of magnitude more efficient than traditional pre-silicon PSCL assessment (SNR-based), with an average evaluation time of 15 minutes; whereas, traditional PSCL assessment at pre-silicon stage would require more than a month. We also analyze the PSCL characteristic of the multiplication unit of RISC processor using SCRIPT to demonstrate SCRIPT’s applicability. Adib Nahiyan, Jungmin Park, Miao Tony He, Yousef Iskander, Farimah Farahmandi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 6 |
| 2020 | EMFORCED: EM-Based Fingerprinting Framework for Remarked and Cloned Counterfeit IC Detection Using Machine Learning ClassificationabstractElectronics supply chain vulnerabilities have broadened in scope over the past two decades. With nearly all integrated circuit (IC) design companies relinquishing their fabrication, packaging, and test facilities, they are forced to rely upon companies from around the world to produce their ICs. This dependence leaves the electronics supply chain open to counterfeiting activities. In this article, we propose an electromagnetic (EM)-based fingerprinting framework, called EMFORCED, to detect remarked and cloned counterfeit ICs. Here, we demonstrate the benefits of using naturally occurring EM side channels to identify the IC design layout without decapsulating the chip under test. Enabling only the clock, Vdd, and ground pins allows us to generate a design-specific fingerprint that is dependent upon the physical parameters of the chip under test. EMFORCED leverages the EM emissions from the clock distribution network to create a holistic, design-level, fingerprint, including both temporal information and spatial information. We utilize the fingerprint information of functionally similar 8051-series microprocessors from three vendors and perform unsupervised (principal component analysis) and supervised (linear discriminant analysis) machine learning methods on all ICs to determine their intravendor and intervendor similarities. We acquired ICs from multiple dates and lot codes along with variants acquired from the gray market and analyzed them for authenticity using physical inspection and X-ray tomography. Statistical analysis and machine learning techniques are used to demonstrate the reference-free and reference-inclusive classification methods based on EMFORCED measurements. We demonstrate the classification accuracies of 99.46% and 100% for unsupervised and supervised approaches, respectively. Andrew Stern, Ulbert Botero, Fahim Rahman, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2019 | RAM-Jam: Remote Temperature and Voltage Fault Attack on FPGAs using Memory CollisionsabstractIt has been demonstrated that with concrete hardware Trojans, a remote adversary can mount physical attacks, e.g., fault or side-channel attacks, against adjacent IP cores in an FPGA. In this work, we present a novel remote fault attack, called RAM-Jam, which exploits an existing weakness in the dual port RAMs of mainstream FPGAs. The possibility of concurrent writing of opposite logic values into these RAMs not only leads to data uncertainty but also causes transient short circuits. With a sufficient number of RAM collisions, there are severe voltage drops and excessive heat that result in timing faults as well as bit-flips in the FPGA's configuration memory. We conduct extensive experiments to evaluate the effectiveness of our fault injection technique and further present attacks against two applications, including a soft authentication scheme and the first remote fault attack against a deep neural network. Finally, we discuss potential countermeasures to prevent such attacks. Shahin Tajik, Fatemeh Ganji, Mark Tehranipoor, Domenic Forte |
FDTC | 5 |
| 2019 | Recycled Analog and Mixed Signal Chip Detection at Zero Cost Using LDO DegradationabstractCounterfeit electronics impact the global economy and pose life-threatening risks to critical systems and infrastructure. Analog/mixed-signal (AMS) chips are the most widely reported counterfeit chip type, but existing countermeasures are impractical for detecting them. In this paper, we propose a method to detect recycled AMS counterfeits that exploits degradation of power supply rejection ratio (PSRR) in low drop out (LDO) regulators. Our zero cost approach does not require information about the component's design. Moreover, due to the ubiquity of LDOs, it may apply to active and legacy AMS system on chips (SoCs). To evaluate the feasibility and effectiveness of our method, we use an automated test setup to collect PSRR data from commercial off-the-shelf LDOs before and after aging. Machine learning algorithms ranging from unsupervised to supervised are applied to differentiate between aged (i.e., synthetically recycled) and new LDOs. Silicon results confirm that semi-supervised and supervised algorithms are effective even with LDOs used less than 10 days (for 65nm technology node). Sreeja Chowdhury, Fatemeh Ganji, Troy Briant, Nima Maghari, Domenic Forte |
ITC | 5 |
| 2019 | IEEE International Symposium on Hardware Oriented Security and Trust (HOST): Past, Present, and FutureabstractHardware plays an integral role in system security with many emerging vulnerabilities and defense mechanisms targeting hardware. The IEEE International Symposium on Hardware Oriented Security and Trust (HOST) aims to facilitate the rapid growth of hardware-based security research and development. Since 2008, HOST has provided an environment to present cutting-edge developments in hardware security and trust. With the recent expansion of its scope to include all areas of overlap between hardware and security, HOST has become a premier event in the field of cybersecurity, and is one of the few to bridge the gap between computer security, mircoelectronics, and electronic design automation (EDA) communities. Domenic Forte, Swarup Bhunia, Ramesh Karri, James F. Plusquellic, Mark Tehranipoor |
ITC | 1 |
| 2019 | Quality Obfuscation for Error-Tolerant and Adaptive Hardware IP ProtectionabstractAhstract-Various attacks on hardware intellectual properties (IPs) have been successful in obtaining design information that can be used to reverse engineer a system, create counterfeits, or insert hardware Trojans. Key-based hardware obfuscation is an attractive solution that helps prevent such attacks. In this paper, for the first time, we propose a key error tolerant obfuscation approach that achieves graceful degradation in output Quality of Service (QoS) as the bit error rate (BER) in obfuscation key increases. The approach, which we refer to it as, “Quality Obfuscation”, is applicable to a large variety of IPs, including digital signal processing (DSP) and approximating computing IPs, which are resilient to output QoS degradation. We present a complete obfuscation framework that can be adapted to any error tolerance rate. To demonstrate its robustness, we obfuscate several common DSP IP blocks and observe the performance under various percentages of bit-flips in the key. We show that our approach provides controllability of system quality, as well as the strong protection at low overhead, e.g., average 15% area and 5.9% power overhead to tolerate 10% BER. Abdulrahman Alaql, Tamzidul Hoque, Domenic Forte, Swarup Bhunia |
VTS | 3 |
| 2019 | Security-Aware FSM Design Flow for Identifying and Mitigating Vulnerabilities to Fault AttacksabstractThe security of a system-on-chip (SoC) can be compromised by exploiting the vulnerabilities of the finite state machines (FSMs) in the SoC controller modules through fault injection attacks. These vulnerabilities may be unintentionally introduced by traditional FSM design practices or by CAD tools during synthesis. In this paper, we first analyze how the vulnerabilities in an FSM can be exploited by fault injection attacks. Then, we propose a security-aware FSM design flow for ASIC designs to mitigate them and prevent fault attacks on FSM. Our proposed FSM design flow starts with a security-aware encoding scheme which makes the FSM resilient against fault attacks. However, the vulnerabilities introduced by the CAD tools cannot be addressed by encoding schemes alone. To analyze for such vulnerabilities, we develop a novel technique named analyzing vulnerabilities in FSM. If any vulnerability exists, we propose a secure FSM architecture to address the issue. In this paper, we mainly focus on setup-time violation-based fault attacks which pose a serious threat on FSMs; though our proposed flow works for advanced laser-based fault attacks as well. We compare our proposed secure FSM design flow with traditional FSM design practices in terms of cost, performance, and security. We show that our FSM design flow ensures security while having a negligible impact on cost and performance. Adib Nahiyan, Farimah Farahmandi, Prabhat Mishra 0001, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2019 | Obfuscated Built-In Self-Authentication With Secure and Efficient Wire-LiftingabstractHardware Trojan insertion and intellectual property (IP) theft are two major concerns when dealing with untrusted foundries. Most existing mitigation techniques are limited in protecting against both vulnerabilities. Split manufacturing is designed to stop IP piracy and integrated circuit (IC) cloning, but it fails at preventing untargeted hardware Trojan insertion and incurs significant overheads when high level of security is demanded. Built-in self-authentication (BISA) is a low-cost technique for preventing and detecting hardware Trojan insertion, but is vulnerable to IP piracy, IC cloning, or redesign attacks, especially on original circuitry. In this paper, we propose an obfuscated BISA technique that combines and optimizes both the techniques so that they complement and improve security against both vulnerabilities, while at the same time minimizing design overheads to the extent that the proposed method does not incur prohibitive cost for designs of industrial-level sophistication. Our evaluation on advanced encryption standard and data encryption standard cores shows that the proposed technique can reach security levels more than two times higher, satisfying all existing layout-based security metrics, while reducing overheads from hundreds of percents to less than 13% in power, 5% in delay, and zero percent in area, as compared to best reported performance in existing techniques. Qihang Shi, Mark Tehranipoor, Domenic Forte |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2019 | Electronics Supply Chain Integrity Enabled by BlockchainabstractElectronic systems are ubiquitous today, playing an irreplaceable role in our personal lives as well as in critical infrastructures such as power grid, satellite communication, and public transportation. In the past few decades, the security of software running on these systems has received significant attention. However, hardware has been assumed to be trustworthy and reliable "by default" without really analyzing the vulnerabilities in the electronics supply chain. With the rapid globalization of the semiconductor industry, it has become challenging to ensure the integrity and security of hardware. In this paper, we discuss the integrity concerns associated with a globalized electronics supply chain. More specifically, we divide the supply chain into six distinct entities: IP owner/foundry (OCM), distributor, assembler, integrator, end user, and electronics recycler, and analyze the vulnerabilities and threats associated with each stage. To address the concerns of the supply chain integrity, we propose a blockchain-based certificate authority framework that can be used to manage critical chip information such as electronic chip identification (ECID), chip grade, transaction time, etc. The decentralized nature of the proposed framework can mitigate most threats of the electronics supply chain, such as recycling, remarking, cloning, and overproduction. Xiaolin Xu 0001, Fahim Rahman, Bicky Shakya, Apostol Vassilev 0001, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2019 | Recycled FPGA Detection Using Exhaustive LUT Path Delay Characterization and Voltage ScalingabstractField-programmable gate arrays (FPGAs) have been extensively used because of their lower nonrecurring engineering and design costs, instant availability and reduced visibility of failure, high performance, and power benefits. Reports indicate that previously used or recycled FPGAs are infiltrating the electronics’ supply chain and making the security and reliability of the critical systems and networks vulnerable. Current recycled integrated circuit (IC) detection procedures include parametric, functional, and burn-in tests that require golden or reference data. Besides, they are time consuming, require expensive equipment, and do not focus on FPGAs. In this article, we propose two recycled FPGA detection methods based on supervised and unsupervised machine learning algorithms. We develop a sophisticated ring oscillator (RO) design to exploit the degradation of lookup tables (LUTs) and use them in the proposed methods. In the supervised method, a one-class classifier is trained with RO frequencies, kurtosis, and skewness data obtained from unused FPGAs, which differentiates unused and aged FPGAs. The unsupervised method uses $k$ -means clustering and Silhouette value analysis to detect suspect recycled components with very little (if any) golden information. In addition, we introduce a voltage scaling-assisted RO frequency measurement technique that improves the classification. The proposed methods are examined for Spartan-3A and Spartan-6 FPGAs, and the result shows that both methods are effective in detecting recycled FPGAs, which experience accelerated aging for at least 12 h equivalent to 70 days in real-time age. Mark Tehranipoor, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2019 | Probing Assessment Framework and Evaluation of Antiprobing SolutionsabstractProbing attacks against integrated circuits has become a serious concern, especially for security-critical applications. With the help of modern circuit editing tools, an attacker could remove layers of materials and expose wires carrying sensitive on-chip assets, such as cryptographic keys and proprietary firmware, for probing. Most of the existing protection methods use an active shield that provides tamper-evident covers at the top-most metal layers to the circuitry below. However, they lack formal proofs of their effectiveness as some active shields have already been circumvented by hackers. In this paper, we investigate the problem of protection against front-side probing attacks and propose a framework to assess a design's vulnerabilities against probing attacks. Metrics are developed to evaluate the resilience of designs to bypass an attack and reroute the attack, the two common techniques used to compromise an antiprobing mechanism. Exemplary assets from a system-on-chip layout are used to evaluate the proposed flow. The results show that long net and high layer wires are vulnerable to a probing attack equipped with high aspect ratio focused ion beam. Meanwhile, nets that occupy small area on the chip are probably compromised through rerouting shield wires. On the other hand, the multilayer internal orthogonal shield performs the best among common shield structures. Qihang Shi, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2018 | Power-based side-channel instruction-level disassemblerabstractModern embedded computing devices are vulnerable against malware and software piracy due to insufficient security scrutiny and the complications of continuous patching. To detect malicious activity as well as protecting the integrity of executable software, it is necessary to monitor the operation of such devices. In this paper, we propose a disassembler based on power-based side-channel to analyze the real-time operation of embedded systems at instruction-level granularity. The proposed disassembler obtains templates from an original device (e.g., IoT home security system, smart thermostat, etc.) and utilizes machine learning algorithms to uniquely identify instructions executed on the device. The feature selection using Kullback-Leibler (KL) divergence and the dimensional reduction using PCA in the time-frequency domain are proposed to increase the identification accuracy. Moreover, a hierarchical classification framework is proposed to reduce the computational complexity associated with large instruction sets. In addition, covariate shifts caused by different environmental measurements and device-to-device variations are minimized by our covariate shift adaptation technique. We implement this disassembler on an AVR 8-bit microcontroller. Experimental results demonstrate that our proposed disassembler can recognize test instructions including register names with a success rate no lower than 99.03% with quadratic discriminant analysis (QDA). Jungmin Park, Xiaolin Xu 0001, Yier Jin, Domenic Forte, Mark Tehranipoor |
DAC | 4 |
| 2018 | EMFORCED: EM-based Fingerprinting Framework for Counterfeit Detection with Demonstration on Remarked and Cloned ICsabstractToday’s globalized electronics supply chain is prone to counterfeit chip proliferation. Existing techniques to detect counterfeit integrated circuits (ICs) are limited by relatively high cost, lengthy inspection time, destructive nature, and restriction to a pre-packaging environment. We propose a novel method of counterfeit IC detection which takes advantage of design-specific electromagnetic (EM) fingerprints generated by simulating on-chip clock distribution networks. Through exploitation of the chip’s physical characteristics, our technique can help detect foundry of origin. We validate our approach on 8051 microcontrollers from three different vendors and utilize principal component analysis to distinguish the acquisitions by vendor. Our results show that near-field EM measurements combined with unsupervised machine learning provide ≈ 99% accuracy in counterfeit detection through design-specific fingerprint classification. Andrew Stern, Ulbert Botero, Bicky Shakya, Haoting Shen, Domenic Forte, Mark Tehranipoor |
ITC | 5 |
| 2018 | UCR: An Unclonable Environmentally Sensitive Chipless RFID Tag For Protecting Supply ChainabstractChipless Radio Frequency Identification (RFID) tags that do not include an integrated circuit (IC) in the transponder are more appropriate for supply-chain management of low-cost commodities and have been gaining extensive attention due to their relatively lower price. However, existing chipless RFID tags consume considerable tag area and manufacturing time/cost because of complex fabrication process (e.g., requiring removing or shorting some resonators on the tag substrate to encode data). Worse still, their identifiers (IDs) are deterministic, clonable, and small in terms of bitwidth. To address these shortcomings and help preserve the cold chain for commodities (e.g., vaccines, pharmaceuticals, etc.) sensitive to temperature, we develop a novel unclonable environmentally sensitive chipless RFID (UCR) tag that intrinsically generates a unique ID from both manufacturing variations and ambient temperature variation. A UCR tag consists of two parts: (i) a certain number of concentric ring slot resonators integrated on a certain laminate (e.g., TACONIC TLX-0), whose resonance frequencies rely on geometric parameters of slot resonators and dielectric constant of substrate material that are sensitive to manufacturing variations, and (ii) a stand-alone circular ring slot resonator integrated on a particular substrate (e.g., grease) that will be melted at a high temperature, whose resonance frequency relies on geometric parameters of slot resonator, dielectric constant of substrate material, and ambient temperature. UCR tags have the capability to track commodities and their temperatures in the supply chain. The area of UCR tag is comparable to regular quick response (QR) code. Experimental results based on UCR tag prototypes have verified their uniqueness and reliability. Kun Yang 0012, Ulbert Botero, Haoting Shen, Damon L. Woodard, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2018 | ReSC: An RFID-Enabled Solution for Defending IoT Supply ChainabstractThe Internet of Things (IoT), an emerging global network of uniquely identifiable embedded computing devices within the existing Internet infrastructure, is transforming how we live and work by increasing the connectedness of people and things on a scale that was once unimaginable. In addition to facilitated information and service exchange between connected objects, enhanced computing power and analytic capabilities of individual objects, and increased interaction between objects and their environments, the IoT also raises new security and privacy challenges. Hardware trust across the IoT supply chain is the foundation of IoT security and privacy. Two major supply chain issues—disappearance/theft of authentic IoT devices and appearance of inauthentic ones—have to be addressed to secure the IoT supply chain and lay the foundation for further security and privacy-defensive measures. Comprehensive solutions that enable IoT device authentication and traceability across the entire supply chain (i.e., during distribution and after being provisioned) need to be established. Existing hardware, software, and network protection methods, however, do not address IoT supply chain issues. To mitigate this shortcoming, we propose an RFID-enabled solution called ReSC that aims at defending the IoT supply chain. By incorporating three techniques—one-to-one mapping between RFID tag identity and control chip identity; unique tag trace, which records tag provenance and history information; and neighborhood attestation of IoT devices—ReSC is resistant to split attacks (i.e., separating tag from product, swapping tags), counterfeit injection, product theft throughout the entire supply chain, device recycling, and illegal network service access (e.g., Internet, cable TV, online games, remote firmware updates). Simulations, theoretical analysis, and experimental results based on a printed circuit board (PCB) prototype demonstrate the effectiveness of ReSC. Finally, we evaluate the security of our proposed scheme against various attacks. Kun Yang 0012, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2018 | Hardware-Enabled Pharmaceutical Supply Chain SecurityabstractThe pharmaceutical supply chain is the pathway through which prescription and over-the-counter (OTC) drugs are delivered from manufacturing sites to patients. Technological innovations, price fluctuations of raw materials, as well as tax, regulatory, and market demands are driving change and making the pharmaceutical supply chain more complex. Traditional supply chain management methods struggle to protect the pharmaceutical supply chain, maintain its integrity, enhance customer confidence, and aid regulators in tracking medicines. To develop effective measures that secure the pharmaceutical supply chain, it is important that the community is aware of the state-of-the-art capabilities available to the supply chain owners and participants. In this article, we will be presenting a survey of existing hardware-enabled pharmaceutical supply chain security schemes and their limitations. We also highlight the current challenges and point out future research directions. This survey should be of interest to government agencies, pharmaceutical companies, hospitals and pharmacies, and all others involved in the provenance and authenticity of medicines and the integrity of the pharmaceutical supply chain. Kun Yang 0012, Haoting Shen, Domenic Forte, Swarup Bhunia, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2018 | SCARe: An SRAM-Based Countermeasure Against IC RecyclingabstractWith the rapid growth of the electronics market, counterfeiting of integrated circuits (ICs), in particular IC recycling, has become a serious issue in recent years. Recycled ICs are those harvested from old systems and resold in the supply chain as new. Such ICs exhibit lower performance and shorter lifetime and, as a result, pose threats to the security and reliability of electronic systems. In this paper, we propose a recycled IC detection framework called static random-access memory (SRAM)-based countermeasure against IC recycling (SCARe) to detect the aging of SRAM cells. Our framework can be applied to both standalone SRAM chips and system on chips with embedded SRAM. For each SRAM under detection, statistical analysis is conducted to differentiate the recycled and new ICs. To mimic the practical aging scenario, 16 commodity SRAM chips from three different manufacturers and different technology nodes (e.g., 90, 110, and 130 nm) are stressed under high-temperature and supply-voltage conditions for different periods of time. The experimental results from new and aged SRAM chips, which represents recycled ICs, demonstrate that our proposed technology can achieve extremely high-detection success rate (no lower than 96.5%). The minimal in-field usage, which can be detected by SCARe, is 7 h. Zimu Guo, Xiaolin Xu 0001, Md Tauhidur Rahman 0001, Mark Tehranipoor, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 5 |
| 2018 | Bimodal Oscillation as a Mechanism for Autonomous Majority Voting in PUFs
Xiaolin Xu 0001, Shahrzad Keshavarz, Domenic Forte, Mark Tehranipoor, Daniel E. Holcomb |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2017 | Security vulnerability analysis of design-for-test exploits for asset protection in SoCsabstractSoCs implementing security modules should be both testable and secure. Oversights in a design's test structure could expose internal modules creating security vulnerabilities during test. In this paper, for the first time, we propose a novel automated security vulnerability analysis framework to identify violations of confidentiality, integrity, and availability policies caused by test structures and designer oversights during SoC integration. Results demonstrate existing information leakage vulnerabilities in implementations of various encryption algorithms and secure microprocessors. These can be exploited to obtain secret keys, control finite state machines, or gain unauthorized access to memory read/write functions. Gustavo K. Contreras, Adib Nahiyan, Swarup Bhunia, Domenic Forte, Mark Tehranipoor |
ASP-DAC | 4 |
| 2017 | Standardizing Bad Cryptographic Practice: A Teardown of the IEEE Standard for Protecting Electronic-design Intellectual PropertyabstractWe provide an analysis of IEEE standard P1735, which describes methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP. We find a surprising number of cryptographic mistakes in the standard. In the most egregious cases, these mistakes enable attack vectors that allow us to recover the entire underlying plaintext IP. Some of these attack vectors are well-known, e.g. padding-oracle attacks. Others are new, and are made possible by the need to support the typical uses of the underlying IP; in particular, the need for commercial system-on-chip (SoC) tools to synthesize multiple pieces of IP into a fully specified chip design and to provide syntax errors. We exploit these mistakes in a variety of ways, leveraging a commercial SoC tool as a black-box oracle. Animesh Chhotaray, Adib Nahiyan, Thomas Shrimpton, Domenic Forte, Mark Tehranipoor |
CCS | 4 |
| 2017 | Novel Bypass Attack and BDD-based Tradeoff Analysis Against All Known Logic Locking Attacks
Xiaolin Xu 0001, Bicky Shakya, Mark Tehranipoor, Domenic Forte |
CHES | 4 |
| 2017 | FFD: A Framework for Fake Flash DetectionabstractCounterfeit electronics have become a big concern in the globalized semiconductor industry where chips might be recycled, remarked, cloned or overproduced. In this work, we advance the state-of-the-art counterfeit detection of flash memory, which is widely used in electronic systems. Fake memories may be used in critical systems, such as missiles, military aircrafts and helicopters, thus diminishing their reliability. In addition, there are countless stories of fake flash drives in the general consumer market. We propose a comprehensive framework called FFD to detect fake flash memories (i.e., recycled, remarked and cloned parts). FFD is validated with 200,000 commercial flash memory pages. Experimental results show that our framework performs well in: 1) nearly 100% detection accuracy of flash with as little as 5% usage, 2) estimating the flash memory usage with high resolution (≤ 5% of its maximal endurance). Another contribution of this work is a chip ID generation technique that can generate unique flash fingerprints with greater than 99.3% reliability. Zimu Guo, Xiaolin Xu 0001, Mark Tehranipoor, Domenic Forte |
DAC | 4 |
| 2017 | Comparative Analysis of Hardware Obfuscation for IP ProtectionabstractIn the era of globalized Integrated Circuit (IC) design and manufacturing flow, a rising issue to the silicon industry is various attacks on hardware intellectual property (IP). As a measure to ensure security along the supply chain against IP piracy, tampering and reverse engineering, hardware obfuscation is considered a reliable defense mechanism. Sequential and combinational obfuscations are the primary classes of obfuscation, and multiple methods have been proposed in each type in recent years. This paper presents an overview of obfuscation techniques and a qualitative comparison of the two major types. Sarah Amir, Bicky Shakya, Domenic Forte, Mark Tehranipoor, Swarup Bhunia |
ACM Great Lakes Symposium on VLSI | 3 |
| 2017 | Securing Split Manufactured ICs with Wire Lifting Obfuscated Built-In Self-AuthenticationabstractHardware Trojan insertion and intellectual property (IP) theft are two major concerns when dealing with untrusted foundries. Most existing mitigation techniques are limited in protecting against both vulnerabilities. Split manufacturing is designed to stop IP piracy and IC cloning, but it fails at preventing untargeted hardware Trojan insertion and incurs significant overheads when high level of security is demanded. Built-in self-authentication (BISA) is a low cost technique for preventing and detecting hardware Trojan insertion, but is vulnerable to IP piracy, IC cloning or redesign attacks, especially on original circuitry. In this paper, we propose an obfuscated built-in self-authentication (OBISA) technique that combines and optimizes both technique so that they complement and improve security against both vulnerabilities. Performance of the proposed OBISA technique is presented with experimental implementation on same benchmark circuits as used in the existing wire lifting technique. The security performance is evaluated with the most popular split manufacturing security metrics. Qihang Shi, Kan Xiao, Domenic Forte, Mark Tehranipoor |
ACM Great Lakes Symposium on VLSI | 3 |
| 2017 | Human recognition from photoplethysmography (PPG) based on non-fiducial featuresabstractPhotoplethysmography (PPG) signals have unique identity properties for human recognition, and are becoming easier to capture by emerging IoT sensors. Existing research on PPG-based biometric systems rely on fiducial methods that extract landmarks from the PPG signal as features. This paper investigates non-fiducial methods that operating in a holistic manner that is less sensitive to noise in landmarks. We compare PPG-based human verification of 42 subjects with fiducial and non-fiducial methods (specifically, discrete wavelet transform) and classification using a neural network and support vector machine. The experimental results demonstrate higher test recognition rates for wavelet transform feature extraction. We further improve our results by selecting a subset of features via the genetic algorithm. Nima Karimian, Zimu Guo, Mark Tehranipoor, Domenic Forte |
ICASSP | 4 |
| 2017 | On the vulnerability of ECG verification to online presentation attacksabstractElectrocardiogram (ECG) has long been regarded as a biometric modality which is impractical to copy, clone, or spoof. However, it was recently shown that an ECG signal can be replayed from arbitrary waveform generators, computer sound cards, or off-the-shelf audio players. In this paper, we develop a novel presentation attack where a short template of the victim's ECG is captured by an attacker and used to map the attacker's ECG into the victim's, which can then be provided to the sensor using one of the above sources. Our approach involves exploiting ECG models, characterizing the differences between ECG signals, and developing mapping functions that transform any ECG into one that closely matches an authentic user's ECG. Our proposed approach, which can operate online or on-the-fly, is compared with a more ideal offline scenario where the attacker has more time and resources. In our experiments, the offline approach achieves average success rates of 97.43% and 94.17% for non-fiducial and fiducial based ECG authentication. In the online scenario, the performance is de-graded by 5.65% for non-fiducial based authentication, but is nearly unaffected for fiducial authentication. Nima Karimian, Damon L. Woodard, Domenic Forte |
IJCB | 3 |
| 2017 | Hardware trojan detection through information flow security verificationabstractSemiconductor design houses are increasingly becoming dependent on third party vendors to procure intellectual property (IP) and meet time-to-market constraints. However, these third party IPs cannot be trusted as hardware Trojans can be maliciously inserted into them by untrusted vendors. While different approaches have been proposed to detect Trojans in third party IPs, their limitations have not been extensively studied. In this paper, we analyze the limitations of the state-of-the-art Trojan detection techniques and demonstrate with experimental results how to defeat these detection mechanisms. We then propose a Trojan detection framework based on information flow security (IFS) verification. Our framework detects violation of IFS policies caused by Trojans without the need of white-box knowledge of the IP. We experimentally validate the efficacy of our proposed technique by accurately identifying Trojans in the trust-hub benchmarks. We also demonstrate that our technique does not share the limitations of the previously proposed Trojan detection techniques. Adib Nahiyan, Mehdi Sadi, Rahul Vittal, Gustavo K. Contreras, Domenic Forte, Mark Tehranipoor |
ITC | 5 |
| 2017 | SMA: A System-Level Mutual Authentication for Protecting Electronic Hardware and FirmwareabstractDue to the enhanced capability of adversaries, electronic systems are now increasingly vulnerable to counterfeiting and piracy. The majority of counterfeit systems today are of cloned type, which have been on the rise in the recent years. Ensuring the security of such systems is of great concern as an adversary can create a backdoor or insert a malware to bypass security modules. The reliability of such systems could also be questionable as the components used in these systems may be counterfeit and/or of inferior quality. It is of prime importance to develop solutions that can prevent an adversary from creating these non-authentic systems. In this paper, we present a novel system-level mutual authentication approach for both the hardware and firmware. The hardware authenticates the firmware by verifying the checksum during the power-up. On the other hand, firmware verifies the identity of the hardware and cannot produce correct results unless it receives a unique hardware fingerprint, which we call as system ID. We propose two secure protocols, TIDP and TIDS, to construct the system ID and authenticate the system by using this unique ID. We show that our approach is resistant to various known attacks. Ujjwal Guin, Swarup Bhunia, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Obfuscation-Based Protection Framework against Printed Circuit Boards Unauthorized Operation and Reverse EngineeringabstractPrinted circuit boards (PCBs) are a basic necessity for all modern electronic systems but are becoming increasingly vulnerable to cloning, overproduction, tampering, and unauthorized operation. Most efforts to prevent such attacks have only focused on the chip level, leaving a void for PCBs and higher levels of abstraction. In this article, we propose the first ever obfuscation-based framework for the protection of PCBs. Central to our approach is a permutation block that hides the inter-chip connections between chips on the PCB and is controlled by a key. If the correct key is applied, then the correct connections between chips are made. Otherwise, the connections are incorrectly permuted, and the PCB/system fails to operate. We propose a permutation network added to the PCB based on a Benes network that can easily be implemented in a complex programmable logic device or field-programmable gate arrays. Based on this implementation, we analyze the security of our approach with respect to (i) brute-force attempts to reverse engineer the PCB, (ii) brute-force attempts at guessing the correct key, and (iii) physical and logistic attacks by a range of adversaries. Performance evaluation results on 12 reference designs show that brute force generally requires prohibitive time to break the obfuscation. We also provide detailed requirements for countermeasures that prevent reverse engineering, unauthorized operation, and so on, for different classes of attackers. Zimu Guo, Jia Di, Mark Tehranipoor, Domenic Forte |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2017 | CDTA: A Comprehensive Solution for Counterfeit Detection, Traceability, and Authentication in the IoT Supply ChainabstractThe Internet of Things (IoT) is transforming the way we live and work by increasing the connectedness of people and things on a scale that was once unimaginable. However, the vulnerabilities in the IoT supply chain have raised serious concerns about the security and trustworthiness of IoT devices and components within them. Testing for device provenance, detection of counterfeit integrated circuits (ICs) and systems, and traceability of IoT devices are challenging issues to address. In this article, we develop a novel radio-frequency identification (RFID)-based system suitable for counterfeit detection, traceability, and authentication in the IoT supply chain called CDTA . CDTA is composed of different types of on-chip sensors and in-system structures that collect necessary information to detect multiple counterfeit IC types (recycled, cloned, etc.), track and trace IoT devices, and verify the overall system authenticity. Central to CDTA is an RFID tag employed as storage and a channel to read the information from different types of chips on the printed circuit board (PCB) in both power-on and power-off scenarios. CDTA sensor data can also be sent to the remote server for authentication via an encrypted Ethernet channel when the IoT device is deployed in the field. A novel board ID generator is implemented by combining outputs of physical unclonable functions (PUFs) embedded in the RFID tag and different chips on the PCB. A light-weight RFID protocol is proposed to enable mutual authentication between RFID readers and tags. We also implement a secure interchip communication on the PCB. Simulations and experimental results using Spartan 3E FPGAs demonstrate the effectiveness of this system. The efficiency of the radio-frequency (RF) communication has also been verified via a PCB prototype with a printed slot antenna. Kun Yang 0012, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2017 | Security Beyond CMOS: Fundamentals, Applications, and RoadmapabstractHardware-oriented security and trust has traditionally relied on the dominant CMOS technology to develop security primitives and provide protection against different attacks and vulnerabilities. With CMOS nearly reaching its fundamental scaling limit and the shortcomings of current solutions, researchers are now looking to exploit emerging nanoelectronic devices for various security applications. In this paper, we discuss the unique features of three emerging nanoelectronic technologies, namely, phase-change memory, grapheme, and carbon nanotubes, and analyze how these features can aid in hardware security and trust. In addition, we present challenges and future research directions about how to effectively integrate emerging nanoscale devices into hardware security. We emphasize that an interdisciplinary initiative is needed for emerging technologies to reach their full potential in security and trust applications. Fahim Rahman, Bicky Shakya, Xiaolin Xu 0001, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2017 | Poly-Si-Based Physical Unclonable FunctionsabstractPhysically unclonable functions (PUFs) were introduced over a decade ago for a variety of security applications. Silicon PUFs exploit uncontrollable random variations from manufacturing to generate unique and random signatures/ responses. However, such sources of randomness may become limited during standard CMOS manufacturing as processes continue to mature especially with the advances in design for manufacturability. Recently, poly-Si is proposed to improve PUF quality by offering considerable random variations at the materials level, which is from randomly distributed grain boundaries and trapped charges in poly-Si. In this paper, we develop a poly-Si field-effect transistor (FET) model to study the properties of poly-Si-based PUFs under different supply voltages (VDD) and temperatures (T). Simulation results obtained from ring oscillator and arbiter PUFs show that compared with conventional CMOS-based PUFs, the reliability of poly-Si-based PUFs can be improved from around 90% to 98% and the PUF devices are robust against varying VDDand T. Haoting Shen, Fahim Rahman, Bicky Shakya, Xiaolin Xu 0001, Mark Tehranipoor, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2016 | AVFSM: a framework for identifying and mitigating vulnerabilities in FSMsabstractA finite state machine (FSM) is responsible for controlling the overall functionality of most digital systems and, therefore, the security of the whole system can be compromised if there are vulnerabilities in the FSM. These vulnerabilities can be created by improper designs or by the synthesis tool which introduces additional don't-care states and transitions during the optimization and synthesis process. An attacker can utilize these vulnerabilities to perform fault injection attacks or insert malicious hardware modifications (Trojan) to gain unauthorized access to some specific states. To our knowledge, no systematic approaches have been proposed to analyze these vulnerabilities in FSM. In this paper, we develop a framework named Analyzing Vulnerabilities in FSM (AVFSM) which extracts the state transition graph (including the don't-care states and transitions) from a gate-level netlist using a novel Automatic Test Pattern Generation (ATPG) based approach and quantifies the vulnerabilities of the design to fault injection and hardware Trojan insertion. We demonstrate the applicability of the AVFSM framework by analyzing the vulnerabilities in the FSM of AES and RSA encryption module. We also propose a low-cost mitigation technique to make FSM more secure against these attacks. Adib Nahiyan, Kan Xiao, Kun Yang 0012, Yier Jin, Domenic Forte, Mark Tehranipoor |
DAC | 5 |
| 2016 | Tracking Data Flow at Gate-Level through Structural CheckingabstractThe rapid growth of Internet-of-things and other electronic devices make a huge impact on how and where data travel. The confidential data (e.g., personal data, financial information) that travel through unreliable channels can be exposed to attackers. In hardware, the confidential data such as secret cipher keys are facing the same issue. This problem is even more serious when the IP is from a 3rd party and contains scan-chains. Thus, data flow tracking is important to analyze possible leakage channels in fighting against such hardware security threats. This paper introduces a method for tracking data flow and detecting potential hardware Trojans in gate-level soft IPs using assets and Structural Checking tool. Thao Le 0001, Jia Di, Mark Tehranipoor, Domenic Forte, Lei Wang 0003 |
ACM Great Lakes Symposium on VLSI | 4 |
| 2016 | Chip editor: leveraging circuit edit for logic obfuscation and trusted fabricationabstractThe globalization of the semiconductor foundry business poses grave risks in terms of intellectual property (IP) protection, especially for critical applications. Over the past few years, several techniques have been proposed that allow manufacturing of ICs at untrusted foundries by obfuscating and/or locking, albeit at high design overhead, low security guarantees and high cost. In this paper, for the first time, we utilize well-known, low-cost circuit edit techniques, which enable a designer to modify a circuit post-fabrication on a chip-by-chip basis. In the proposed design flow, obfuscated ICs are fabricated and tested at untrusted foundries, and post-fabrication focused ion beam (FIB) circuit edit techniques are utilized to revert the circuit back to its intended functionality at a trusted design house. In order to obfuscate the structural logic of the design, several possible gate-level techniques such as wire swapping and gate insertion are proposed. At the same time, the tradeoffs between layout-level modifications to aid circuit edit and the strength of obfuscation provided by the proposed approach are also assessed. Gate-level simulation results show that the chip-editor flow provides a strong level of design obfuscation and makes it infeasible for the untrusted foundry to retrieve the original design from the obfuscated layout it receives and the resultant netlist it can extract. Bicky Shakya, Navid Asadizanjani, Domenic Forte, Mark Tehranipoor |
ICCAD | 3 |
| 2016 | Hardware security meets biometrics for the age of IoTabstractThe Internet of Things (IoT) is a concept that involves connecting endpoint devices and physical objects to the Internet. While IoT is envisioned to dramatically increase convenience in our daily lives, it could also result in catastrophic economic and safety issues. Considering the applications envisioned for IoT (smart cities, homes, retail, etc.), security must be handled with great care and should start from the bottom up (i.e., from the hardware level). As a good deal of IoT devices require interaction between devices and humans, biometrics provide an interesting opportunity for improving both the convenience and security in IoT applications. In this paper, we consider the potential benefits and challenges associated with incorporating biometrics into IoT. We combine novel biometrics, such as ECG and PPG, and system-level obfuscation approaches to prevent reverse engineering, tampering and unauthorized access of IoT devices and other electronic systems. Our preliminary results are promising and motivate future work in this area. Zimu Guo, Nima Karimian, Mark Tehranipoor, Domenic Forte |
ISCAS | 4 |
| 2016 | Recycled FPGA detection using exhaustive LUT path delay characterizationabstractField programmable gate arrays (FPGAs) have been extensively used because of their lower non-recurring engineering and design costs, instant availability and reduced visibility of failure, high performance and power benefits. Reports indicate that counterfeit FPGAs are infiltrating the IC supply chain, most of which are recycled type (previously used). Counterfeit components pose a significant threat to the government and industrial sectors of the economy because they undermine the security and reliability of the critical systems and networks. Recycled FPGA detection procedures include parametric test, functional test, and burn-in test that requires golden data and/or parts specifications from original component manufacturers. In this work, a sophisticated ring oscillator design method is used to exploit all the possible paths in look-up tables (LUTs). A recycled FPGA is likely to have fully used, partially used, and unused LUTs. The proposed mapping targets all paths of LUTs and forms a frequency array. A support vector machine is trained with frequency array from unused FPGAs, which differentiates between unused and aged FPGAs. An unsupervised method based on k-means clustering is also proposed to classify recycled components without golden information. Simulation and silicon results demonstrate high rates of success using the proposed methods. Mark Tehranipoor, Domenic Forte |
ITC | 3 |
| 2016 | A Survey on Chip to System Reverse EngineeringabstractThe reverse engineering (RE) of electronic chips and systems can be used with honest and dishonest intentions. To inhibit RE for those with dishonest intentions (e.g., piracy and counterfeiting), it is important that the community is aware of the state-of-the-art capabilities available to attackers today. In this article, we will be presenting a survey of RE and anti-RE techniques on the chip, board, and system levels. We also highlight the current challenges and limitations of anti-RE and the research needed to overcome them. This survey should be of interest to both governmental and industrial bodies whose critical systems and intellectual property (IP) require protection from foreign enemies and counterfeiters who possess advanced RE capabilities. Shahed E. Quadir, Junlin Chen, Domenic Forte, Navid Asadizanjani, Sina Shahbazmohamadi, Lei Wang 0003, John A. Chandy, Mark Tehranipoor |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2016 | On Reverse Engineering-Based Hardware Trojan DetectionabstractDue to design and fabrication outsourcing to foundries, the problem of malicious modifications to integrated circuits (ICs), also known as hardware Trojans (HTs), has attracted attention in academia as well as industry. To reduce the risks associated with Trojans, researchers have proposed different approaches to detect them. Among these approaches, test-time detection approaches have drawn the greatest attention. Many test-time approaches assume the existence of a Trojan-free (TF) chip/model also known as “golden model.” Prior works suggest using reverse engineering (RE) to identify such TF ICs for the golden model. However, they did not state how to do this efficiently. In fact, RE is a very costly process which consumes lots of time and intensive manual effort. It is also very error prone. In this paper, we propose an innovative and robust RE scheme to identify the TF ICs. We reformulate the Trojan-detection problem as clustering problem. We then adapt a widely used machine learning method, ${K}$ -means clustering, to solve our problem. Simulation results using state-of-the-art tools on several publicly available circuits show that the proposed approach can detect HTs with high accuracy rate. A comparison of this approach with our previously proposed approach [1] is also conducted. Both the limitations and application scenarios of the two methods are discussed in detail. Chongxi Bao, Domenic Forte, Ankur Srivastava 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2016 | FORTIS: A Comprehensive Solution for Establishing Forward Trust for Protecting IPs and ICsabstractWith the advent of globalization in the semiconductor industry, it is necessary to prevent unauthorized usage of third-party IPs (3PIPs), cloning and unwanted modification of 3PIPs, and unauthorized production of ICs. Due to the increasing complexity of ICs, system-on-chip (SoC) designers use various 3PIPs in their design to reduce time-to-market and development costs, which creates a trust issue between the SoC designer and the IP owners. In addition, as the ICs are fabricated around the globe, the SoC designers give fabrication contracts to offshore foundries to manufacture ICs and have little control over the fabrication process, including the total number of chips fabricated. Similarly, the 3PIP owners lack control over the number of fabricated chips and/or the usage of their IPs in an SoC. Existing research only partially addresses the problems of IP piracy and IC overproduction, and to the best of our knowledge, there is no work that considers IP overuse. In this article, we present a comprehensive solution for preventing IP piracy and IC overproduction by assuring forward trust between all entities involved in the SoC design and fabrication process. We propose a novel design flow to prevent IC overproduction and IP overuse. We use an existing logic encryption technique to obfuscate the netlist of an SoC or a 3PIP and propose a modification to enable manufacturing tests before the activation of chips which is absolutely necessary to prevent overproduction. We have used asymmetric and symmetric key encryption, in a fashion similar to Pretty Good Privacy (PGP), to transfer keys from the SoC designer or 3PIP owners to the chips. In addition, we also propose to attach an IP digest (a cryptographic hash of the entire IP) to the header of an IP to prevent modification of the IP by the SoC designers. We have shown that our approach is resistant to various attacks with the cost of minimal area overhead. Ujjwal Guin, Qihang Shi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2016 | Hardware Trojans: Lessons Learned after One Decade of ResearchabstractGiven the increasing complexity of modern electronics and the cost of fabrication, entities from around the globe have become more heavily involved in all phases of the electronics supply chain. In this environment, hardware Trojans (i.e., malicious modifications or inclusions made by untrusted third parties) pose major security concerns, especially for those integrated circuits (ICs) and systems used in critical applications and cyber infrastructure. While hardware Trojans have been explored significantly in academia over the last decade, there remains room for improvement. In this article, we examine the research on hardware Trojans from the last decade and attempt to capture the lessons learned. A comprehensive adversarial model taxonomy is introduced and used to examine the current state of the art. Then the past countermeasures and publication trends are categorized based on the adversarial model and topic. Through this analysis, we identify what has been covered and the important problems that are underinvestigated. We also identify the most critical lessons for those new to the field and suggest a roadmap for future hardware Trojan research. Kan Xiao, Domenic Forte, Yier Jin, Ramesh Karri, Swarup Bhunia, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2016 | Design of Accurate Low-Cost On-Chip Structures for Protecting Integrated Circuits Against RecyclingabstractThe recycling of electronic components has become a major industrial and governmental concern, as it could potentially impact the security and reliability of a wide variety of electronic systems. It is extremely challenging to detect a recycled integrated circuit (IC) that is already used for a very short period of time because the process variations outpace the degradation caused by aging, especially in lower technology nodes. In this paper, we propose a suite of solutions, based on lightweight negative bias temperature instability (NBTI)-aware ring oscillators (ROs), for combating die and IC recycling (CDIR) when ICs are used for a very short duration. The proposed solutions are implemented in the 90-nm technology node. The simulation results demonstrate that our newly proposed NBTI-aware multiple pair RO-based CDIRs can detect ICs used only for a few hours. Ujjwal Guin, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2015 | Investigation of obfuscation-based anti-reverse engineering for printed circuit boardsabstractPrior work has shown that printed circuit board (PCB) reverse engineering can be accomplished with inexpensive home solutions as well as state-of-the-art technologies. Once the information of how components on a PCB are connected is determined, an adversary can steal the IP, clone the design, determine points of attack on a system, etc. Existing chip-level obfuscation techniques are not applicable to board level due to the significant differences between chips and PCBs. In this paper, we propose a PCB obfuscation approach that relies on permutation blocks to hide the interconnects among the PCB's circuit components. A detailed framework is provided to implement the proposed approach and evaluate its performance. Potential attacks and countermeasures are also discussed. Results obtained from five industrial reference designs show that it is nearly impossible to break the proposed approach by brute force, even under pessimistic assumptions. Our investigation also reveals that PCBs containing a programmable component with 64 pins (or more) are well-protected by our approach, making it suitable for a large percentage of systems and applications. Zimu Guo, Mark Tehranipoor, Domenic Forte, Jia Di |
DAC | 3 |
| 2015 | Protecting Endpoint Devices in IoT Supply ChainabstractThe Internet of Things (IoT), an emerging global network of uniquely identifiable embedded computing devices within the existing Internet infrastructure, is transforming how we live and work by increasing the connectedness of people and things on a scale that was once unimaginable. In addition to increased communication efficiency between connected objects, the IoT also brings new security and privacy challenges. Comprehensive measures that enable IoT device authentication and secure access control need to be established. Existing hardware, software, and network protection methods, however, are designed against fraction of real security issues and lack the capability to trace the provenance and history information of IoT devices. To mitigate this shortcoming, we propose an RFID-enabled solution that aims at protecting endpoint devices in IoT supply chain. We take advantage of the connection between RFID tag and control chip in an IoT device to enable data transfer from tag memory to centralized database for authentication once deployed. Finally, we evaluate the security of our proposed scheme against various attacks. Kun Yang 0012, Domenic Forte, Mark Tehranipoor |
ICCAD | 2 |
| 2015 | A pair selection algorithm for robust RO-PUF against environmental variations and agingabstractPhysically Unclonable Functions (PUFs) have emerged as a promising security primitive for low-cost authentication and cryptographic key generation. However, PUF stability with respect to temporal variations still limits its utility and widespread acceptance. Previous techniques in the literature have focused on improving PUF robustness against voltage and temperature variations, but the issues associated with aging have been largely neglected. In this paper, we propose a reliable pair selection algorithm (RePa) that can generate reliable keys from an RO-PUF under aging, voltage, and temperature variations. The RePa approach selects RO pairs with both initial frequency difference and aging rate/slope in mind. The aging slope is predicted by exploiting correlation that exists between frequency variation with respect to voltage and frequency variation with respect to aging. We evaluate RePa with simulations to show that it achieves significant improvement over the current state of the art in terms of reliability and cost. The proposed approach can achieve ~ 3.0x more robust key with only ~ 2.3x more ROs required than the conventional RO-PUF pair selection for the same key size. Md Tauhidur Rahman 0001, Domenic Forte, Fahim Rahman, Mark Tehranipoor |
ICCD | 2 |
| 2015 | Performance optimization for on-chip sensors to detect recycled ICsabstractIC recycling has become a grave problem in today's globalized semiconductor industry, with potential impact to critical infrastructures. In order to mitigate this problem, various Design-for-Anti-Counterfeit (DfAC) measures have been recently proposed. In this paper, we look at DfAC strategies based on recycling sensors, most notably the ones based on a pair of ring oscillators, which rely on integrated circuit aging phenomena to detect usage of ICs in the field. We introduce a novel optimization technique that generalizes to most recycling sensors suggested so far in literature and gives manufacturers exact control over parameters that determine sensor performance, such as yield, misprediction and area overhead. A detailed analysis of various factors affecting recycling sensor performance is presented and an optimization problem is formulated and verified using simulations, in order to demonstrate the accuracy of the approach. Bicky Shakya, Ujjwal Guin, Mark Tehranipoor, Domenic Forte |
ICCD | 4 |
| 2015 | Temperature Tracking: Toward Robust Run-Time Detection of Hardware TrojansabstractThe hardware Trojan threat has motivated development of Trojan detection schemes at all stages of the integrated circuit (IC) lifecycle. While the majority of existing schemes focus on ICs at test-time, there are many unique advantages offered by post-deployment/run-time Trojan detection. However, run-time approaches have been underutilized with prior work highlighting the challenges of implementing them with limited hardware resources. In this paper, we propose three innovative low-overhead approaches for run-time Trojan detection which exploit the thermal sensors already available in many modern systems to detect deviations in power/thermal profiles caused by Trojan activation. The first one is a local sensor-based approach that uses information from thermal sensors together with hypothesis testing to make a decision. The second one is a global approach that exploits correlation between sensors and maintains track of the ICs thermal profile using a Kalman filter (KF). The third approach incorporates leakage power into the system dynamic model and apply extended KF (EKF) to track ICs thermal profile. Simulation results using state-of-the-art tools on ten publicly available Trojan benchmarks verify that all three proposed approaches can detect active Trojans quickly and with few false positives. Among three approaches, EKF is flawless in terms of the ten benchmarks tested but would require the most overhead. Chongxi Bao, Domenic Forte, Ankur Srivastava 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2014 | Advanced Analysis of Cell Stability for Reliable SRAM PUFsabstractA Physically Unclonable Function (PUF) is a structure that when issued a challenge, it produces a unique and reliable response which can be used as an identifier or a cryptographic key. SRAM PUFs create unique responses upon power up as certain SRAM cells output a '1' or '0' with high probability due to uncontrollable process variations. A current challenge in SRAM PUFs is their sensitivity to temperature and voltage variations as well as aging. By creating algorithms that isolate stable bits quickly and with minimal testing, the use of SRAM PUF should become more practical. In this paper, we explore the selection of stable bits through enrollment under different conditions (temperature, voltage, and aging) and also by exploiting previously undiscovered interactions between neighboring SRAM cells. We develop metrics that analyze the impact of each neighboring cell and each enrollment condition. Our metrics can be used to identify the best cells and conditions for stable bit selection. We have analyzed data from Spartan 3 FPGA and our metrics identify the best neighborhood size (16 stable neighbors) and best enrollment condition pair (high temperature, high voltage and low temperature). Alison Hosey, Md Tauhidur Rahman 0001, Kan Xiao, Domenic Forte, Mark Tehranipoor |
ATS | 4 |
| 2014 | Low-cost On-Chip Structures for Combating Die and IC RecyclingabstractThe recycling of electronic components has become a major concern for the industry and government as it potentially impacts the security and reliability of a wide variety of electronic systems. The sheer number of component types (analog, digital, mixed-signal) and sizes (large or small) makes it extremely challenging to find a one-size-fits-all solution to detect and prevent recycled ICs. In this paper, we propose a suite of solutions for combating die and IC recycling (CDIR). These solutions include light-weight, on-chip structures based on ring oscillators (RO-CDIR), anti-fuses (AF-CDIR) and fuses (F-CDIR). Each structure meets the unique needs and limitations of different part types and sizes providing excellent coverage of recycled parts. HSPICE simulation results using 90nm technology demonstrate the effectiveness of our proposed negative-bias temperature instability (NBTI)-aware RO-CDIR for detecting ICs used for very short period of time. Recycling of large digital ICs can effectively be detected by using AF-CDIR. Small analog and digital recycled components can be identified by testing our F-CDIR with very low cost measurement devices, e.g., a multimeter. Ujjwal Guin, Xuehui Zhang, Domenic Forte, Mark Tehranipoor |
DAC | 3 |
| 2014 | TI-TRNG: Technology Independent True Random Number GeneratorabstractTrue random number generators (TRNGs) are needed for a variety of security applications and protocols. The quality (randomness) of TRNGs depends on sensitivity to random noise, environmental conditions, and aging. Random sources of noise improve TRNG quality. In older or more mature technologies, the random sources are limited resulting in low TRNG quality. Prior work has also shown that attackers can manipulate voltage supply and temperature to bias the TRNG output. In this paper, we propose bias detection mechanisms and a technology independent TRNG (TI-TRNG) architecture. The TI-TRNG enhances power supply noise for older technologies and uses a self-calibration mechanism that reduces bias in TRNG output due to aging and attacks. Experiment results on 130nm, 90nm, and 45nm FPGAs demonstrate the quality of random sequences from the TI-TRNG across aging and different environmental conditions. Md Tauhidur Rahman 0001, Kan Xiao, Domenic Forte, Xuhei Zhang, Zhijie Jerry Shi, Mark Tehranipoor |
DAC | 3 |
| 2014 | ARO-PUF: An aging-resistant ring oscillator PUF designabstractPhysically Unclonable Functions (PUFs) have emerged as a security block with the potential to generate chip-specific identifiers and cryptographic keys. However it has been shown that the stability of these identifiers and keys is heavily impacted by aging and environmental variations. Previous techniques have mostly focused on improving PUF robustness against supply noise and temperature but aging has been largely neglected. In this paper, we propose a new aging resistant design for the popular ring-oscillator (RO)-PUF. Simulation results demonstrate that our aging resistant RO-PUF (called ARO-PUF) can produce unique, random, and more reliable keys. Only 7.7% bits get flipped on average over 10 years operation period for an ARO-PUF due to aging where the value is 32% for a conventional RO-PUF. The ARO-PUF shows an average interchip HD of 49.67% (close to ideal value 50%) and better than the conventional RO-PUF (~45%). With lower error, ARO-PUF offers ~ 24X area reduction for a 128-bit key because of reduced ECC complexity and smaller PUF footprint. Md Tauhidur Rahman 0001, Domenic Forte, Jim Fahrny, Mark Tehranipoor |
DATE | 2 |
| 2014 | A Novel Built-In Self-Authentication Technique to Prevent Inserting Hardware TrojansabstractWith the rapid globalization of the semiconductor industry, hardware Trojans have become a significant threat to government agencies and enterprises that require secure and reliable systems for their critical applications. Because of the diversity of hardware Trojans and the randomness associated with process variations, hardware Trojan detection is a challenging problem. In this paper, we propose a novel technique, called built-in self-authentication (BISA), which can be used to make hardware Trojan insertion by untrusted Graphic Data System (GDSII) developer and untrusted foundry considerably more difficult and easier to detect. The unused spaces in the circuit layout represent the best opportunity to insert Trojans by these entities. BISA works by eliminating this spare space and filling it with functional filler cells, instead of nonfunctional filler cells. A self-testing procedure generates a digital signature that will be different if any BISA cells are changed because of hardware Trojan insertion. We demonstrate that BISA can be applied to any flat or bottom-up hierarchical design with negligible overhead in terms of area, power, and timing. Kan Xiao, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2013 | Temperature tracking: an innovative run-time approach for hardware Trojan detectionabstractThe hardware Trojan threat has motivated development of Trojan detection schemes at all stages of the integrated circuit (IC) lifecycle. While the majority of existing schemes focus on ICs at test-time, there are many unique advantages offered by post-deployment/run-time Trojan detection. However, run-time approaches have been underutilized with prior work highlighting the challenges of implementing them with limited hardware resources. In this paper, we propose innovative low-overhead approaches for run-time Trojan detection which exploit the thermal sensors already available in many modern systems to detect deviations in power/thermal profiles caused by Trojan activation. Simulation results using state-of-the-art tools on publicly available Trojan benchmarks verify that our approaches can detect active Trojans quickly and with few false positives. Domenic Forte, Chongxi Bao, Ankur Srivastava 0001 |
ICCAD | 1 |
| 2013 | Improving the Quality of Delay-Based PUFs via Optical Proximity CorrectionabstractSilicon physically unclonable functions (PUFs) are circuits that exploit modern manufacturing variations to generate unique signatures for chip authentication and cryptographic key generation. Existing research has focused on improving PUF quality at architectural or design levels, but has ignored opportunities available during fabrication, which is the source of systematic and random variation in (ICs)/PUFs. For typical ICs (where security is not a concern), optical proximity correction (OPC) is used to suppress both these types of variations. However, several prior works have shown that only systematic variations negatively impact PUF quality and random variations are beneficial for PUFs. In this paper, we propose two PUF-aware OPC cost functions: 1) P-OPC generates a PUF lithography mask that increases all variations in PUF circuitry (the opposite of state-of-the-art OPC), and 2) SVC-OPC generates mask patterns that reduce the systematic variation found in PUFs for better quality. Simulation results for ring oscillator (RO) PUFs show that the proposed techniques can improve PUF signature quality compared to current state-of-the-art OPC. Domenic Forte, Ankur Srivastava 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2013 | Energy- and Thermal-Aware Video Coding via Encoder/Decoder Workload BalancingabstractVideo coding and compression are essential components of multimedia services but are known to be computationally intensive and energy demanding. Traditional video coding paradigms, predictive and distributed video coding (PVC and DVC), result in excessive computation at either the encoder (PVC) or decoder (DVC). Several recent papers have proposed a hybrid PVC/DVC codec which shares the video coding workload between encoder and decoder. In this article, we propose a controller for such hybrid coders that considers energy and temperature to dynamically split the coding workload of a system comprised of one encoder and one decoder. We also present two heuristic algorithms for determining safe operating temperatures in the controller solution: (1) stable state thermal modeling algorithm, which focuses on long term temperatures, and (2) transient thermal modeling algorithm, which is better for short-term thermal behavior. Results show that the proposed algorithms result in more balanced energy utilization, improve overall system lifetime, and reduce operating temperatures when compared to strictly PVC and DVC systems. Domenic Forte, Ankur Srivastava 0001 |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2013 | Resource-aware architectures for adaptive particle filter based visual target trackingabstractThere are a growing number of visual tracking applications now being envisioned for mobile devices. However, since computer vision algorithms such as particle filtering have large computational demands, they can result in high energy consumption and temperatures in mobile devices. Conventional approaches for distributed target tracking with a camera node and a receiver node are either sender-based (SB) or receiver-based (RB). The SB approach uses little energy and bandwidth, but requires a sender with large computational resources. The RB approach fits applications where computational resources are completely unavailable to the sender, but requires very large energy and bandwidth. In this article, we propose three architectures for distributed particle filtering that (i) reduce particle filtering workload and (ii) allow for dynamic migration of workload between nodes participating in tracking. We also discuss an adaptive particle filtering extension that adapts particle filter computational complexity and can be applied to both the conventional and proposed architectures for improved energy efficiency. Results show that the proposed solutions require low additional overhead, improve on tracking system lifetime, balance node temperatures, maintain track of the desired target, and are more effective than conventional approaches in many scenarios. Domenic Forte, Ankur Srivastava 0001 |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2013 | Thermal-aware sensor scheduling for distributed estimationabstractA sensor network is a distributed system where sensor nodes autonomously collect local data and collaborate to solve global problems. Recent work has shown that sensor functionality varies with node temperature. Extreme temperatures can decrease node/network lifetime by leading to premature hardware failure and reducing battery capacity. Furthermore, high temperatures can increase sensor measurement noise and disrupt communication between overheated sensor nodes, thereby interfering with their ability to contribute valuable information to collaborative tasks. In the past, sensor networks only consisted of low-end devices with limited power, computational capabilities, and available bandwidth. Such devices would only experience high temperatures in harsh environments. However, sensor networks are now envisioned for applications that require higher-end devices, such as smart cameras, smart phones, and laptops. The power dissipated by such devices is much larger than low-end sensors and can create thermal emergencies in sensor hardware even in calm environments. In this article, we present unique management opportunities for distributed estimation tasks in sensor networks consisting of high-end devices prone to thermal issues. We attempt to balance both thermal- and performance-related constraints by examining trade-offs between sensor sampling rate, number of sensors, node temperature, and state estimation error. Initially, we devise a scheduling algorithm which can achieve a desired real-time performance constraint while maintaining a thermal limit on temperature assuming identical nodes in the network. Then, we extend the concept to a network consisting of heterogeneous sensor nodes. Analytical results and simulation experiments are done for state estimation with a Kalman filter for simplicity, but our main contributions should easily extend to any form of estimation with measurable error. Results show that our policies can successfully balance the trade-offs between thermal- and performance-related constraints. Note that our analyses, schemes, and results are less applicable to low-end sensors whose operation does not cause high node temperature. This work is most suited for high-performance sensors and upper-tier sensors which experience greater workloads. Domenic Forte, Ankur Srivastava 0001 |
ACM Trans. Sens. Networks | 1 |
| 2012 | On improving the uniqueness of silicon-based physically unclonable functions via optical proximity correctionabstractPhysically Unclonable Functions (PUFs) are effective for security applications because they generate unique signatures that are resistant to cloning attempts as well as physical tampering. A silicon PUF is a special circuit embedded in an IC that relies on random fabrication process variations to produce a unique signature for its native IC. While current research directions have focused on improving PUF quality at the architectural level, little work has explicitly targeted their fundamental source of randomness, the fabrication process. During IC fabrication, Optical Proximity Correction (OPC) is typically used to suppress manufacturing variations. In this paper, we recognize that this is actually counterintuitive for PUFs. We provide a novel framework which enables OPC to increase the effects of manufacturing variations within PUF circuitry and produce more randomness in PUFs for greater uniqueness and reliability. The proposed OPC techniques are validated using a population of 100 ring oscillator PUFs. Results show that our schemes provide over five times larger variation in ring oscillator delay, improve PUF uniqueness by 5%, and improve PUF reliability by as much as 70% when compared to conventional OPC. Domenic Forte, Ankur Srivastava 0001 |
DAC | 1 |
| 2011 | Adaptable architectures for distributed visual target trackingabstractThere are a growing number of visual tracking applications for mobile devices. However, the computer vision algorithms which process real-time video to track moving targets are demanding. Since a single mobile device possesses limited computational capabilities, energy, etc. to fully support target tracking, some works have investigated architectures which migrate a portion of tracking duties to another device at the cost of transmission bandwidth and energy. In this paper, we investigate the resource utilization in such architectures and present an adaptable architecture which balances tracking workload among the participating devices based on current resource availability (energy, temperature, bandwidth). Results show that the proposed solution requires low additional overhead, can improve on tracking system lifetime by reducing energy consumption, and is more effective in maintaining safe operating temperatures within participants as compared to previously investigated architecture Domenic Forte, Ankur Srivastava 0001 |
ICCD | 1 |
| 2011 | Energy-aware and quality-scalable data placement and retrieval for disks in video server environmentsabstractAs the popularity of video streaming over the Internet grows, energy consumption in video server environments which store and retrieve video data increases as well. Previous work has shown that video quality delivered to clients can be scaled in order to serve more concurrent video requests and/or reduce energy consumption of server disks. We propose a data placement strategy for such quality scaling methods which distributes video data within a disk based on its priority/importance. Results show that in doing so the disk can retrieve data with greater efficiency and serve lower quality video to more clients than previously investigated strategies. Domenic Forte, Ankur Srivastava 0001 |
ICCD | 1 |
| 2010 | Thermal-Aware Sensor Scheduling for Distributed Estimation
Domenic Forte, Ankur Srivastava 0001 |
DCOSS | 1 |
| 2010 | Energy and thermal-aware video coding via encoder/decoder workload balancingabstractEven with consistent advances in storage and transmission capacity, video coding and compression are essential components of multimedia services. Traditional video coding paradigms result in excessive computation at either the encoder or decoder. However, several recent papers have proposed a hybrid PVC/DVC (Predictive/Distributed Video Coding) codec which shares the video coding workload. In this paper, we propose a controller for such hybrid coders that considers energy and temperature to dynamically split the coding workload of a system comprised of one encoder and one decoder. Results show that the proposed controller results in more balanced energy utilization, improving overall system lifetime and reducing operating temperatures when compared to strictly PVC and DVC systems. Domenic Forte, Ankur Srivastava 0001 |
ISLPED | 1 |