Kaveh Shamsi

dblp:173/7144 · DBLP profile ↗
← Back
29ranked-venue papers
14as first author
12since 2021 · last 2026
0000-0002-9952-4597ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 27 · 12 first-author · 11 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2026 On Oracle-Guided Random Circuit Learning via Stochastic Boolean Satisfiability
abstract
Oracle-guided circuit learning (OGCL) or deobfuscation is the problem of recovering a set of secret key bits from a keyed circuit with the help of queries to a black-box functional oracle of the circuit. This problem has various applications in hardware security, such as in security analysis of obfuscation schemes, side-channel analysis, reverse engineering for trust, and Trojan detection. Boolean satisfiability (SAT)-based algorithms have been used here extensively. In this paper, we explore the adjacent problem of random circuit learning (OGRCL), which is the CL problem when the keyed circuit has an additional set of uncontrollable/unobservable random inputs with known probabilities. This can find applications in deobfuscation of probabilistic circuits, deobfuscation in the presence of noise, side-channel attacks in the presence of noise, optimal random circuit synthesis, and so on. We show for the first time that Boolean stochastic satisfiability (SSAT), which is a generalization of SAT to computing the probability of a given Boolean formula, can be used to devise generic random circuit learning procedures. We implement our proposed algorithms using modern SSAT solvers and showcase their superiority relative to a traditional black-box optimization approach on a set of benchmark circuits.
Kaveh Shamsi
DATE2
2026 Structural Reconstruction of Analog Circuits Using Graph Neural Networks and Transformers
Dipali Jain, Guangwei Zhao, Kaveh Shamsi
VTS3
2025 A Hybrid Machine Learning and Numeric Optimization Approach to Analog Circuit Deobfuscation
abstract
Oracle-guided circuit deobfuscation (or learning) is the problem of disambiguating an obfuscated (partially hidden) circuit given black-box access to it. This has applications in various hardware security areas such as analyzing the security of circuit obfuscation defense schemes, side-channel analysis, reverse engineering, and hardware Trojan detection. Generic deobfuscation of analog circuits has received less attention than the digital counterpart with existing methods relying on manual expert work to extract closed-form equations from the circuit. In this work, we move towards a significantly more automated process by using a combination of machine learning and Newton-method-based analog circuit optimization. We showcase how this hybrid scheme is superior to either standalone approach in terms of runtime and accuracy on a set of analog circuits that include amplifiers, filters, and oscillators. We achieve >98% average accuracy without any manual expert equation extraction in addition to demonstrating a superior resilience to process variation.
Dipali Jain, Guangwei Zhao, Rajesh Kumar Datta, Kaveh Shamsi
ASP-DAC4
2025 Improving Error Tolerance and Scalability in Pseudo-Boolean SAT-based Generic Side-Channel Analysis
abstract
Pseudo-Boolean Satisfiability (PBSAT) can be used to perform automated power side-channel analysis, i.e., recover secret keys from the power consumption information of a generic Boolean circuit. Here, the search for what input pattern to collect the side-channels on, and the secret value that conforms to those observations, can be formulated as a series of PBSAT calls. Since the problem is NP-hard, runtime growth can be worst-case exponential. In addition, these formal procedures tend to be more sensitive to error and noise than traditional statistical procedures. In this paper, we propose some novel techniques to improve on these two fronts. We propose a criterion that can be used to slice the circuit into parts that can be treated independently without loss of accuracy to help with scalability. We demonstrate this to provide up to two orders of magnitude improvement in runtime for comparator circuits for instance. We additionally propose various novel procedures based on pseudo-Boolean optimization, which allow for greater error tolerance as we demonstrate against various generic benchmark circuits.
Dipali Jain, Kaveh Shamsi
ITC3
2024 On Hardware Trojan Detection using Oracle-Guided Circuit Learning
abstract
Hardware Trojans, i.e. malicious circuitry inserted into a design by an untrusted foundry or designer, pose a threat to the fabless semiconductor industry. The detection of hardware Trojans has been the subject of numerous studies over the years. In this paper, we discuss a novel approach to Trojan detection: using the framework of oracle-guided circuit learning (OGCL) or deobfuscation, which has traditionally been used for assessing the security of circuit obfuscation schemes. We show how arbitrary functional Trojan detection can polynomially be reduced to OGCL, yielding a more formal and versatile framework than traditional heuristic techniques. This formulation can also be used to locate Trojans and can be easily extended to side-channel or hybrid detection by using non-functional OGCL. The main challenge with this approach is its worst-case-exponential space complexity when using baseline Boolean satisfiability (SAT)-based circuit deobfuscation. To this end, we propose some novel techniques based on AllSAT, cube generalization, and quantified Boolean Formula (QBF) solving. We present a set of experiments on benchmark circuits to showcase the validity and performance of our framework.
Rajesh Kumar Datta, Guangwei Zhao, Dipali Jain, Kaveh Shamsi
ACM Great Lakes Symposium on VLSI4
2024 Towards Machine-Learning-based Oracle-Guided Analog Circuit Deobfuscation
abstract
Oracle-guided circuit deobfuscation/learning is the problem of recovering unknowns from a circuit by making input-output queries to it and it has various applications in the hardware security domain: in assessing the security of obfuscation schemes, side-channel analysis, and reverse engineering. Unlike the digital case, the generic analog version of the problem has received less attention with existing approaches requiring manual instance-specific labor. In this paper, we present a novel automated approach to this end: using machine learning models trained on synthetic data to predict unknown values from query data. We evaluate our framework approach in a proof-of-concept implementation against a set of hand-crafted diverse analog circuits from simple resistive networks to complex op-amp circuits, using a variety of machine learning models from linear models to decision trees, and (graph) neural networks. Our experiments show prediction error rates of less than 5% on these circuit sets. We explore additional questions such as the impact of uncertainty sampling, topological information, out-of-training range data, and parameter (process) variation.
Dipali Jain, Guangwei Zhao, Rajesh Kumar Datta, Kaveh Shamsi
ITC4
2023 TIPLock: Key-Compressed Logic Locking using Through-Input-Programmable Lookup-Tables
abstract
Herein we explore using logic elements that can be programmed through their inputs for logic locking. For this purpose, we design a novel through-input-programmable (TIP) lookup-table (LUT) element and develop algorithms to find cuts in the circuit that can be mapped to such elements while maintaining programmability. Our proposed TIPLock flow achieves area savings of 50–70% compared to the traditional approach of using a key-vector-long scan-chain.
Kaveh Shamsi, Rajesh Kumar Datta
DATE1
2023 Enhancing Solver-based Generic Side-Channel Analysis with Machine Learning
abstract
Generic side-channel attacks, unlike traditional CPA/DPA which are specialized to individual cryptographic circuits, can take in an arbitrary circuit or its power model and try to learn user-designated secrets from its side-channel traces. In this paper, we explore the use of machine learning in the context of such generic attacks. We discuss and demonstrate the challenges of using end-to-end (trace-to-key) learning on generic circuits with larger key sizes. We instead propose a couple of ways to use machine learning to assist recent pseudo-Boolean solver-based generic attacks and report their effectiveness on FPGA power traces.
Kaveh Shamsi, Guangwei Zhao
ACM Great Lakes Symposium on VLSI1
2022 An Oracle-Less Machine-Learning Attack against Lookup-Table-based Logic Locking
abstract
Replacing cuts in a circuit with configurable lookup-tables (LUTs) that are securely programmed post-fabrication is a logic locking technique that can be used to hide the complete design from an untrusted foundry. In this paper, we study the security of basic LUT-based locking against a set of oracle-less attacks, i.e. attacks that do not have access to a functional oracle of the original circuit. Specifically we perform cut graph/truth-table prediction using deep and graph neural networks with various data encoding strategies. Overall we observe that naive LUT-based locking with small cuts with 2 or 3 inputs may be vulnerable to oracle-less approximation whereas such attacks become less feasible for higher cut sizes. We open source our software for this attack.
Kaveh Shamsi, Guangwei Zhao
ACM Great Lakes Symposium on VLSI1
2022 Graph Neural Network based Netlist Operator Detection under Circuit Rewriting
abstract
Recently graph neural networks (GNN) have shown promise in detecting operators (multiplication, addition, comparison, etc.) and their boundaries in gate-level digital circuit netlists. Unlike formal approaches such as NPN Boolean matching, GNN-based methods are structural and statistical. This means that making structural changes to the circuit while maintaining its functionality may negatively impact their accuracy. In this paper, we explore this question. We show that indeed the prediction accuracy of GNN-based operator detection does fall following simple circuit rewriting. This means that custom rewrites may be a way to hamper operator detection in applications such as logic obfuscation where such undetectability is a security goal. We then present ways to improve the accuracy of prediction under such transforms by combining functional/semi-canonical information into the training and evaluation of the ML model.
Guangwei Zhao, Kaveh Shamsi
ACM Great Lakes Symposium on VLSI2
2021 Circuit Deobfuscation from Power Side-Channels using Pseudo-Boolean SAT
abstract
The problem of inferring the value of internal nets in a circuit from its power side-channels has been the topic of extensive research over the past two decades, with several frameworks developed mostly focusing on cryptographic hardware. In this paper, we focus on the problem of breaking logic locking, a technique in which an original circuit is made ambiguous by inserting unknown “key” bits into it, via power side-channels. We present a pair of attack algorithms we term PowerSAT attacks, which take in arbitrary keyed circuits and resolve key information by interacting adaptively with a side-channel “oracle”. They are based on the query-by-disagreement scheme used in functional SAT attacks against locking but utilize Psuedo-Boolean constraints to allow for reasoning about hamming-weight power models. We present a software implementation of the attacks along with techniques for speeding them up. We present simulation and FPGA-based experiments as well. Notably, we demonstrate the extraction of a 32-bit key from a comparator circuit with a$2^{31}$functional query complexity, in$\sim 64$chosen power side-channel queries using the PowerSAT attack, where traditional CPA fails given 1000 random traces. We release a binary of our implementation along with the FPGA$+\mathbf{scope}\ \mathbf{HDL}/\mathbf{setup}$used for the experiments.
Kaveh Shamsi, Yier Jin
ICCAD1
2021 In Praise of Exact-Functional-Secrecy in Circuit Locking
abstract
Many logic locking schemes have been proposed and subsequently broken in recent years most notably by oracle-guided SAT-solver-based attacks. This has in part been due to a lack of formal definitions of security. Recent work has however taken the first steps towards this by defining some notions of security. One such notion, exact-functional-secrecy (EFS) is satisfied as soon as the attacker is not able to learn the precise functionality of the original circuit. This is less stringent than the approximate-functional-secrecy (AFS) notion of security which captures approximation-resiliency. This paper focuses on EFS. We present first a novel SAT-based attack that can automatically divide the deobfuscation of a locked circuit into two different processes: a) deobfuscating high-activity/entropy nets which contribute to AFS and are best handled by a few queries and heavy SAT-solving, and b) deobfuscating low-activity nets which require many useless queries in search of a few rare informative queries. The attack, called the rare-fast-querying (RFQ) SAT attack, guarantees key-correctness for logic outside of low-activity cones, and is not exclusive to a specific low-activity locking scheme. We show how the RFQ attack can under some conditions, avoid exponential querying altogether. Given the insight from this attack, we then present a deeper look into EFS and discuss simple techniques to achieve always-exponential EFS with bearable overhead. We show how one can take advantage of the abundance of comparator logic at the RT-level of control-oriented designs to achieve EFS with even less overhead via absorbing existing structures.
Kaveh Shamsi, Yier Jin
IEEE Trans. Inf. Forensics Secur.1
2019 KC2: Key-Condition Crunching for Fast Sequential Circuit Deobfuscation
abstract
Logic locking and IC camouflaging are two promising techniques for thwarting an array of supply chain threats. Logic locking can hide the design from the foundry as well as end-users and IC camouflaging can thwart IC reverse engineering by end-users. Oracle-guided SAT-based deobfuscation attacks against these schemes have made it more and more difficult to securely implement them with low overhead. Almost all of the literature on SAT attacks is focused on combinational circuits. A recent first implementation of oracle-guided attacks on sequential circuits showed a drastic increase in deobfuscation time versus combinational circuits. In this paper we show that integrating the sequential SAT-attack with incremental bounded-model-checking, and dynamic simplification of key-conditions (Key-Condition Crunching or KC2), we are able to reduce the runtime of sequential SAT-attacks by two orders of magnitude across benchmark circuits, significantly reducing the gap between sequential and combinational deobfuscation. These techniques are applicable to combinational deobfuscation as well and thus represent a generic improvement to deobfuscation procedures and help better understand the complexity of deobfuscation for designing secure locking/camouflaging schemes.
Kaveh Shamsi, Meng Li 0004, David Z. Pan, Yier Jin
DATE1
2019 IcySAT: Improved SAT-based Attacks on Cyclic Locked Circuits
abstract
“Cyclic” circuit locking/camouflaging is a recently proposed direction in logic obfuscation for thwarting foundry and end-user reverse engineering. As opposed to traditional schemes, these techniques create cycles in the obfuscated circuit in a way that confuses the attacker but does not disrupt the combinational nature of the circuit. While these schemes can thwart the baseline SAT-based attack, the CycSAT attack was proposed recently to break these schemes through a preprocessing step that builds a Boolean condition to avoid cyclic solutions/keys during the attack. However, follow-up work has suggested that extracting these conditions requires enumerating all cycles in the circuit, or that instead of relying on these conditions preemptively, cyclic solutions must be banned individually on the fly. In this paper we present new algorithms for performing SAT-based attacks on cyclic circuits. We first propose an algorithm that can produce non-cyclic conditions in polynomial time with respect to the size of the circuit, avoiding the potentially exponential runtime of explicit key-banning or cycle enumeration. We then take a deeper look at the problem, discussing some of the fundamental limitations of extracting precise non-cyclic conditions and propose a more complex but complete procedure for cyclic deobfuscation. We evaluate our attacks on densely cyclic obfuscated benchmark circuits.
Kaveh Shamsi, David Z. Pan, Yier Jin
ICCAD1
2019 On-Chip Analog Trojan Detection Framework for Microprocessor Trustworthiness
abstract
With the globalization of semiconductor industry, hardware security issues have been gaining increasing attention. Among all hardware security threats, the insertion of hardware Trojans is one of the main concerns. Meanwhile, many current Trojan detection solutions follow the assumption that the hardware Trojan itself should be composed of digital logic. This assumption is invalidated by recently proposed analog Trojans which are extremely small and can detect rare events. This paper proposes a runtime hardware Trojan detection method which is geared toward detecting such advanced Trojans. The principle of this method is to guard a set of concerned signals, and initiate a hardware interrupt request when abnormal toggling events occur in these guarded signals. To prove the effectiveness of this method, we design a processor based on ARMv7-A&R ISA, and insert an analog Trojan into the processor. We fabricated the design in an SMIC 130-nm process and demonstrate the effectiveness of the proposed methodology.
Yumin Hou, Hu He 0001, Kaveh Shamsi, Yier Jin, Huaqiang Wu
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2019 Provably Secure Camouflaging Strategy for IC Protection
abstract
The advancing of reverse engineering techniques has complicated the efforts in intellectual property protection. Proactive methods have been developed recently, among which layout-level integrated circuit camouflaging is the leading example. However, existing camouflaging methods are rarely supported by provably secure criteria, which further leads to an over-estimation of the security level when countering latest de-camouflaging attacks, e.g., the SAT-based attack. In this paper, a quantitative security criterion is proposed for de-camouflaging complexity measurements and formally analyzed through the demonstration of the equivalence between the existing de-camouflaging strategy and the active learning scheme. Supported by the new security criterion, two camouflaging techniques are proposed, including the low-overhead camouflaging cell generation strategy and the AND-tree camouflaging strategy, to help achieve exponentially increasing security levels at the cost of linearly increasing performance overhead on the circuit under protection. A provably secure camouflaging framework is then developed combining these two techniques. The experimental results using the security criterion show that camouflaged circuits with the proposed framework are of high resilience against different attack schemes with only negligible performance overhead.
Meng Li 0004, Kaveh Shamsi, Travis Meade, Zheng Zhao 0003, Bei Yu 0001, Yier Jin, David Z. Pan
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2019 On the Approximation Resiliency of Logic Locking and IC Camouflaging Schemes
abstract
The SAT-based attacks are extremely successful in deobfuscating the traditional combinational logic locking and IC camouflaging schemes. While several SAT-resilient protection schemes that increase the minimum query count of the attack have been proposed recently, none of them satisfy the output corruptibility (error) criteria. Therefore, most of them were combined with high corruptibility schemes to achieve both corruptibility and high query count. These “compound” schemes are successful since existing SAT attacks are agnostic to the corruptibility of the protection scheme. In this paper, we propose an approximate SAT-based attack framework which focuses on the iterative convergence of an attack toward a better solution. This helps our attack reduce a compound scheme to a standalone SAT-resilient scheme. In addition, we relate the problem of minimum query count to a well-known graph problem, and we propose a novel technique to increase the corruptibility of SAT-resilient protection schemes in a controllable manner. This creates protection schemes that have both high query count and corruptibility. Furthermore, due to the approximation resiliency property of these schemes, approximate attacks provide no advantage over exact attacks when attacking them.
Kaveh Shamsi, Travis Meade, Meng Li 0004, David Z. Pan, Yier Jin
IEEE Trans. Inf. Forensics Secur.1
2019 IP Protection and Supply Chain Security through Logic Obfuscation: A Systematic Overview
abstract
The globalization of the semiconductor supply chain introduces ever-increasing security and privacy risks. Two major concerns are IP theft through reverse engineering and malicious modification of the design. The latter concern in part relies on successful reverse engineering of the design as well. IC camouflaging and logic locking are two of the techniques under research that can thwart reverse engineering by end-users or foundries. However, developing low overhead locking/camouflaging schemes that can resist the ever-evolving state-of-the-art attacks has been a challenge for several years. This article provides a comprehensive review of the state of the art with respect to locking/camouflaging techniques. We start by defining a systematic threat model for these techniques and discuss how various real-world scenarios relate to each threat model. We then discuss the evolution of generic algorithmic attacks under each threat model eventually leading to the strongest existing attacks. The article then systematizes defences and along the way discusses attacks that are more specific to certain kinds of locking/camouflaging. The article then concludes by discussing open problems and future directions.
Kaveh Shamsi, Meng Li 0004, Kenneth Plaks, Saverio Fazzari, David Z. Pan, Yier Jin
ACM Trans. Design Autom. Electr. Syst.1
2018 Cross-Lock: Dense Layout-Level Interconnect Locking using Cross-bar Architectures
abstract
Logic locking is an attractive defense against a series of hardware security threats. However, oracle guided attacks based on advanced Boolean reasoning engines such as SAT, ATPG and model-checking have made it difficult to securely lock chips with low overhead. While the majority of existing locking schemes focus on gate-level locking, in this paper we present a layout-inclusive interconnect locking scheme based on cross-bars of metal-to-metal programmable-via devices. We demonstrate how this enables configuring a large obfuscation key with a small number of physical key wires contributing to zero to little substrate area overhead. Dense interconnect locking based on these circuit level primitives shows orders of magnitude better SAT attack resiliency compared to an XOR/XNOR gate-insertion locking with the same key length which has a much higher overhead.
Kaveh Shamsi, Meng Li 0004, David Z. Pan, Yier Jin
ACM Great Lakes Symposium on VLSI1
2018 TimingSAT: Decamouflaging Timing-based Logic Obfuscation
abstract
In order to counter advanced reverse engineering techniques, various integrated circuit (IC) camouflaging methods are proposed to protect hardware intellectual property (IP) proactively. For example, a timing-based camouflaging strategy is developed recently representing a new class of parametric camouflaging strategies. Unlike traditional IC camouflaging techniques that directly hide the circuit functionality, the new parametric strategies obfuscate the circuit timing schemes, which in turn protects the circuit functionality and invalidates all the existing attacks. In this paper, we propose a SAT attack, named TimingSAT, to analyze the security of such timing-based camouflaging strategies. We demonstrate that with a proper transformation of the camouflaged netlist, traditional SAT attacks are still effective to decamouflage the new protection methods. The correctness of the resolved circuit functionality is formally proved. While a direct implementation of TimingSAT suffers from poor scalability, we propose a simplification procedure to significantly enhance the attack efficiency without sacrificing the correctness of the decamouflaged netlist. The efficiency and effectiveness of TimingSAT is validated with extensive experimental results.
Meng Li 0004, Kaveh Shamsi, Yier Jin, David Z. Pan
ITC2
2017 Cyclic Obfuscation for Creating SAT-Unresolvable Circuits
abstract
Logic locking and IC camouflaging are proactive circuit obfuscation methods that if proven secure can thwart hardware attacks such as reverse engineering and IP theft. However, the security of both these schemes is called into question by recent SAT based attacks. While a number of methods have been proposed in literature that exponentially increase the running time of such attacks, they are vulnerable to "findand-remove" attacks, and only slightly hide the circuit functionality. In this paper, we present a novel approach towards creating SAT attack resiliency based on creating densely cyclic obfuscated circuit topologies by adding dummy paths to the circuit. Our methodology is applicable to both IC camouflaging and logic locking. We demonstrate that cyclic logic locking creates SAT resilient circuits with 40% less area and 20% less delay compared to an insecure XOR/XNOR-obfuscation with the same key length. Furthermore, we show that cyclic IC camouflaging can be implemented at the layout level with no substrate area overhead and little delay and power overhead with respect to the original circuit.
Kaveh Shamsi, Meng Li 0004, Travis Meade, Zheng Zhao 0003, David Z. Pan, Yier Jin
ACM Great Lakes Symposium on VLSI1
2017 Circuit Obfuscation and Oracle-guided Attacks: Who can Prevail?
abstract
This paper provides a systematization of knowledge in the domain of integrated circuit protection through obfuscation with a focus on the recent Boolean satisfiability (SAT) attacks. The study systematically combines real-world IC reverse engineering reports, experimental results using the most recent oracle-guided attacks, and concepts in machine-learning and cryptography to draw a map of the state-of-the-art of IC obfuscation and future challenges and opportunities.
Kaveh Shamsi, Meng Li 0004, Travis Meade, Zheng Zhao 0003, David Z. Pan, Yier Jin
ACM Great Lakes Symposium on VLSI1
2016 Leverage Emerging Technologies For DPA-Resilient Block Cipher Design
Yu Bi, Kaveh Shamsi, Jiann-Shiun Yuan, François-Xavier Standaert, Yier Jin
DATE2
2016 Enhancing Hardware Security with Emerging Transistor Technologies
abstract
We consider how the I-V characteristics of emerging transistors (particularly those sponsored by STARnet) might be employed to enhance hardware security. An emphasis of this work is to move beyond hardware implementations of physically unclonable functions (PUFs) and random num- ber generators (RNGs). We highlight how new devices (i) may enable more sophisticated logic obfuscation for IP protection, (ii) could help to prevent fault injection attacks, (iii) prevent differential power analysis in lightweight cryptographic systems, etc.
Yu Bi, Xiaobo Sharon Hu, Yier Jin, Michael T. Niemier, Kaveh Shamsi, Xunzhao Yin
ACM Great Lakes Symposium on VLSI5
2016 Provably secure camouflaging strategy for IC protection
abstract
The advancing of reverse engineering techniques has complicated the efforts in intellectual property protection. Proactive methods have been developed recently, among which layout-level IC camouflaging is the leading example. However, existing camouflaging methods are rarely supported by provably secure criteria, which further leads to over-estimation of the security level when countering the latest de-camouflaging attacks, e.g., the SAT-based attack. In this paper, a quantitative security criterion is proposed for de-camouflaging complexity measurements and formally analyzed through the demonstration of the equivalence between the existing de-camouflaging strategy and the active learning scheme. Supported by the new security criterion, two novel camouflaging techniques are proposed, the low-overhead camouflaging cell library and the AND-tree structure, to help achieve exponentially increasing security levels at the cost of linearly increasing performance overhead on the circuit under protection. A provably secure camouflaging framework is then developed by combining these two techniques. Experimental results using the security criterion show that the camouflaged circuits with the proposed framework are of high resilience against the SAT-based attack with negligible performance overhead.
Meng Li 0004, Kaveh Shamsi, Travis Meade, Zheng Zhao 0003, Bei Yu 0001, Yier Jin, David Z. Pan
ICCAD2
2016 Voting system design pitfalls: Vulnerability analysis and exploitation of a model platform
abstract
Homomorphic encryption may be seen as a substantial potential boon to voting systems. If properly used, it allows provably anonymous elections to take place. However, when poorly constructed, using weak cryptographic primitives results in highly vulnerable systems that are prone to attacks. This paper details one attack done against a model of an election system as part of a security competition, where a hardware Trojan has weakened its security. We designed a proof of concept exploit and implemented it on an FPGA, demonstrating weaknesses in the system regardless of the existence of this Trojan.
Kelvin Ly, Orlando Arias, Jacob Wurm, Khoa Hoang, Kaveh Shamsi, Yier Jin
ICCD5
2016 Security of emerging non-volatile memories: Attacks and defenses
abstract
While the non-volatile memory (NVM) has often been discussed in the context of alternatives to SRAM and RRAM for performance improvements in modern computing systems, their unique properties which lead to security applications and security vulnerabilities have also raised interests. In this paper, we provide a comparative discussion on how the usage of NVMs in the context of security in terms of mitigating some of their vulnerabilities. Further, we discuss innovative implementations of NVMs in the creation of novel hardware security primitives. Through this survey, we expect to have more non-traditional security applications of NVMs in modern designs leveraging their unique properties.
Kaveh Shamsi, Yier Jin
VTS1
2016 Emerging Technology-Based Design of Primitives for Hardware Security
abstract
Hardware security concerns such as intellectual property (IP) piracy and hardware Trojans have triggered research into circuit protection and malicious logic detection from various design perspectives. In this article, emerging technologies are investigated by leveraging their unique properties for applications in the hardware security domain. Security, for the first time, will be treated as one design metric for emerging nano-architecture. Five example circuit structures including camouflaging gates, polymorphic gates, current/voltage-based circuit protectors, and current-based XOR logic are designed to show the high efficiency of silicon nanowire FETs and graphene SymFET in applications such as circuit protection and IP piracy prevention. Simulation results indicate that highly efficient and secure circuit structures can be achieved via the use of non-CMOS devices.
Yu Bi, Kaveh Shamsi, Jiann-Shiun Yuan, Pierre-Emmanuel Gaillardon, Giovanni De Micheli, Xunzhao Yin, Xiaobo Sharon Hu, Michael T. Niemier, Yier Jin
ACM J. Emerg. Technol. Comput. Syst.2
2015 Reliable and high performance STT-MRAM architectures based on controllable-polarity devices
abstract
Source degeneration of access devices in the parallel (P)_ anti-parallel (AP) switching in Spin Transfer Torque Magnetic Random Access Memories (STT-MRAM) has ultimately been a limiting factor in the operational speed of these types of memories. In this work, new architectures for memory single-cells and arrays of cells are presented that utilize Schottky-Barrier Silicon Nanowire Field Effect Transistors with polarity control capabilities (e.g., SiNW-FETs), to substantially increase the performance of STT-MRAM, specifically Multi-Level Cell (MLC) STT-MRAM. The proposed design offers built-in reliability improvement as it omits one of the available four states in the MLC STT-MRAM memory facilitating the resistance level detection for peripheral circuitry. Our simulation results of the developed memory cell show 49.7% reductions in P-AP switching time, as well as 51.3% increases in available drive current under 1.4V supply voltage when compared to FinFET 22imi technology. With respect to memory arrays, the proposed architecture demonstrates an average write latency reduction of 37% in comparison with FinFET 22nm technology node.
Kaveh Shamsi, Yu Bi, Yier Jin, Pierre-Emmanuel Gaillardon, Michael T. Niemier, Xiaobo Sharon Hu
ICCD1