VLDB 2026 Research / reviewers in the wild / expert
Fahim Rahman
dblp:173/7175
· DBLP profile ↗
34ranked-venue papers
1as first author
23since 2021 · last 2025
0000-0001-9388-0112ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 32 · 1 first-author · 21 since 2021Software engineering, systems software and programming languages · 6 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | POCA: First Power-on Chip Authentication and Key Exchange for Secure Provisioning in System-on-Chip
Md Sami Ul Islam Sami, Amit Mazumder Shuvo, Fahim Rahman, Adam Cron, Dale R. Donchin, Mike Borza, Farimah Farahmandi, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2025 | Re-Pen: Reinforcement Learning-Enforced Penetration Testing for SoC Security VerificationabstractDue to the increasingly complex interaction between the tightly integrated components, reuse of various untrustworthy third-party IPs (3PIPs), and security-unaware design practices, there have been a rising number of reports of system-on-chip (SoC) hardware (HW) vulnerabilities that compromise the security of critical assets. SoC security verification, therefore, is an indispensable part of the verification effort. The existing hardware verification methodologies either presuppose white-box knowledge or scale poorly with increasing design complexity. Hardware penetration testing (pentest) is an emerging gray-box security verification methodology at the register-transfer level (RTL) that is applicable across a wide variety of threat models and addresses many shortcomings of the existing methodologies. In this work, we propose Re-Pen, a novel hardware pentest framework that requires minimal gray-box information from the design specification to achieve significantly better security vulnerability (SV) detection performance than state-of-the-art pentest techniques. At the core of this framework lies a mutation engine that combines the strengths of reinforcement learning (RL) and binary particle swarm optimization (BPSO) in its test pattern mutation strategy to generate intelligent test patterns without manual supervision. This framework significantly reduces the requirement for detailed, manual, expertise-driven adaptations specific to the SoC under test. Through extensive experiments conducted on multiple SoCs, we demonstrate that Re-Pen can reduce vulnerability detection time by up to$3\times $and achieve a markedly improved consistency compared with the state of the art. Furthermore, Re-Pen was able to detect native security bugs in an open-source SoC. It successfully identified a scenario where, despite a functionally correct hardware implementation, a mistake in the architectural specification allowed privilege escalation from the software layer. Hasan Al Shaikh, Shuvagata Saha, Kimia Zamiri Azar, Farimah Farahmandi, Mark Tehranipoor, Fahim Rahman |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2024 | Advanced Techniques in Channel Estimation, Precoding, and Detection for Massive MIMO Systems in 5G and BeyondabstractThis research explores the latest advancements in channel estimation, precoding, and detection techniques within massive multiple-input multiple-output (MIMO) systems, which are crucial for the evolution of fifth-generation (5G) and beyond. As global data traffic surges, traditional methodologies face significant limitations, necessitating innovative approaches to enhance performance. This paper critically examines how these advanced techniques effectively address challenges such as increased spectral efficiency and reduced latency while significantly improving overall signal processing efficiency. This work presents practical applications of these methodologies, showcasing a detailed analysis of novel signal detection algorithms designed to maximize system performance in real-world scenarios. By leveraging state-of-the-art signal processing frameworks, it is demonstrated how these techniques enhance detection accuracy and optimize resource allocation, ensuring robust communication in dense user environments. Ultimately, this study underscores the transformative potential of massive MIMO in revolutionizing wireless communications. The findings offer critical insights and practical guidelines that contribute to advancing telecommunications infrastructure, equipping stakeholders to meet the dynamic demands of next-generation wireless networks. This research aims to inspire further exploration and development in this rapidly evolving field, establishing massive MIMO as a cornerstone of future connectivity solutions. Khawla Alnajjar, Sam Ansari, Abdulla Alhammadi, Ali Almahal, Fahim Rahman, Abdulla Alsuwaidi, Khalifa Alzarooni, Soliman A. Mahmoud, Abir Jaafar Hussain |
DeSE | 5 |
| 2024 | SeeMLess: Security Evaluation of Logic Locking using Machine Learning oriented EstimationabstractAlthough logic locking has been widely known as a promising countermeasure against intellectual property (IP) piracy and overproduction risks, it has been challenged by different attack breeds over the years. Attacks on logic locking, either algorithmic or structural, have been always known as a time-consuming resource-intensive effort. For instance, the Boolean satisfiability (SAT) attack might take weeks to be completed. In this paper, we introduce SeeMLess, a first-of-its-kind ML framework for the security evaluation of logic locking, design and locking agnostic. SeeMLess leverages feature sets computed from different aspects, graph-based, functional, propositional, etc. to accurately estimate the attack time with no attacks running. Our experimental results, on a case study over the SAT attack, show the trained model on a dataset of 5K+ designs locked by various techniques, where SeeMLess achieves <?TeX $\sim 95\%$?> Math 1 accuracy in predicting the time of the attack, offering valuable insights into the locking mechanism effectiveness pre-implementation. Bulbul Ahmed, M. Sazadur Rahman, Kimia Zamiri Azar, Farimah Farahmandi, Fahim Rahman, Mark Tehranipoor |
ACM Great Lakes Symposium on VLSI | 5 |
| 2024 | SAP: Silicon Authentication Platform for System-on-Chip Supply Chain VulnerabilitiesabstractThe increasing complexity of system-on-chip (SoC) designs, prompted by the integration of additional functionalities, has led to a reliance on global sources in the SoC supply chain. This reliance introduces security concerns, including intellectual property (IP) theft, unauthorized usage, counterfeiting, and overproduction of integrated circuits (ICs). While various design-for-trust measures have been explored in academic research, such as watermarking, IC metering, IC camouflaging, and hardware obfuscation, there is currently no holistic approach within the SoC framework to support these measures. Secure provisioning of security assets within the chip is also critical for these measures, requiring the establishment of secure communication channels and the authentication of the chip by authorized entities. Existing root-of-trust mechanisms primarily target software-level threats during in-field operations but fall short of adequately addressing supply chain threats and ensuring secure asset provisioning. This paper introduces the Silicon Authentication Platform (SAP) security IP, specifically designed to address security vulnerabilities within the SoC supply chain. SAP is tailored to authenticate SoC dies within untrusted environments, ensuring secure provisioning of security assets and chip authentication during in-field operations. This hardware-based, plug-and-play IP facilitates lightweight integration into SoC designs, establishing a secure perimeter around its assets to protect them from potential leakage. In addition, a comprehensive security analysis showcasing SAP's resilience against contemporary attack scenarios, with minimal impact on performance and area overhead, is also provided in this paper. Md Sami Ul Islam Sami, Jingbo Zhou 0002, Sujan Kumar Saha, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ISPASS | 4 |
| 2024 | Heterogeneous Integration Supply Chain Integrity Through Blockchain and CHSMabstractOver the past few decades, electronics have become commonplace in government, commercial, and social domains. These devices have developed rapidly, as seen in the prevalent use of system-on-chips rather than separate integrated circuits on a single circuit board. As the semiconductor community begins conversations over the end of Moore’s law, an approach to further increase both functionality per area and yield using segregated functionality dies on a common interposer die, labeled a System in Package (SiP), is gaining attention. Thus, the chiplet and SiP space has grown to meet this demand, creating a new packaging paradigm, advanced packaging, and a new supply chain. This new distributed supply chain with multiple chiplet developers and foundries has augmented counterfeit vulnerabilities. Chiplets are currently available on an open market, and their origin and authenticity consequently are difficult to ascertain. With this lack of control over the stages of the supply chain, counterfeit threats manifest at the chiplet, interposer, and SiP levels. In this article, we identify counterfeit threats in the SiP domain, and we propose a mitigating framework utilizing blockchain for the effective traceability of SiPs to establish provenance. Our framework utilizes the Chiplet Hardware Security Module to authenticate a SiP throughout its life. To accomplish this, we leverage SiP information including electronic chip identification of chiplets, combating die and IC recycling sensor information, documentation, test patterns and/or electrical measurements, grade, and part number of the SiP. We detail the structure of the blockchain and establish protocols for both enrolling trusted information into the blockchain network and authenticating the SiP. Our framework mitigates SiP counterfeit threats including recycled, remarked, cloned, overproduced interposer, forged documentation, and substituted chiplet while detecting of out-of-spec and defective SiPs. Paul E. Calzada, Md Sami Ul Islam Sami, Kimia Zamiri Azar, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2023 | SHarPen: SoC Security Verification by Hardware Penetration TestabstractAs modern SoC architectures incorporate many complex/heterogeneous intellectual properties (IPs), the protection of security assets has become imperative, and the number of vulnerabilities revealed is rising due to the increased number of attacks. Over the last few years, penetration testing (PT) has become an increasingly effective means of detecting software (SW) vulnerabilities. As of yet, no such technique has been applied to the detection of hardware vulnerabilities. This paper proposes a PT framework, SHarPen, for detecting hardware vulnerabilities, which facilitates the development of a SoC-level security verification framework. SHarPen proposes a formalism for performing gray-box hardware (HW) penetration testing instead of relying on coverage-based testing and provides an automation for mapping hardware vulnerabilities to logical/mathematical cost functions. SHarPen supports both simulation and FPGA-based prototyping, allowing us to automate security testing at different stages of the design process with high capabilities for identifying vulnerabilities in the targeted SoC. Hasan Al Shaikh, Arash Vafaei, Mridha Md Mashahedur Rahman, Kimia Zamiri Azar, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ASP-DAC | 5 |
| 2023 | EvoLUTe: Evaluation of Look-Up-Table-based Fine-Grained IP RedactionabstractRecent studies on intellectual property (IP) protection techniques demonstrate that engaging embedded reconfigurable components (e.g., eFPGA redaction) would be a promising approach to concealing the functional and structural information of the security-critical design. However, detailed investigation reveals that such techniques suffer from almost prohibited overhead in terms of area, power, delay, and testability. In this paper, we introduce EvoLUTe, a distinct and significantly more fine-grained redaction methodology using smaller reconfigurable components (such as look-up-tables (LUTs)). In EvoLUTe, we examine both eFPGA-based and LUT-based design spaces, demonstrating that a novel cone-based and fine-grained universal function modeling approach using LUTs is capable of providing the same degree of resiliency at a much lower area/power/delay and testability costs. Rui Guo 0010, M. Sazadur Rahman, Hadi Mardani Kamali, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
DATE | 4 |
| 2023 | SoCFuzzer: SoC Vulnerability Detection using Cost Function enabled Fuzz TestingabstractThe modern System-on-Chips (SoCs), with numerous complex and heterogeneous intellectual properties (IPs), and the inclusion of highly-sensitive assets, become the target of malicious attacks. However, security verification of these SoCs remains behind compared to the advances in functional verification, mostly because it is difficult to formally define the accurate threat model(s). Few recent studies have investigated the possibility of engaging fuzz testing for hardware-oriented vulnerability detection. However, they suffer from several limitations, i.e., lack of cross-layer co-verification, the need for expert knowledge, and the inability to capture detailed hardware interactions. In this paper, we propose SoCFuzzer, an automated SoC verification assisted by fuzz testing for detecting SoC security vulnerabilities. Unlike the previous HW-oriented fuzz testing studies, which mostly rely on traditional (code) coverage-based metrics, in SoCFuzzer, we develop (i) generic evaluation metrics for fuzzing the hardware domain, and (ii) security-oriented cost function. This relieves designers of making correlations between coverage metrics, test data, and possible vulnerabilities. The SoCFuzzer cost functions are defined high level, allowing us to follow the gray-box model, which requires less detailed and interactive information from the design-under-test. Our experiments on an open-source RISCV based SoC show the efficiency of these metrics and cost functions on fuzzing for generating cornerstone inputs to trigger the vulnerability conditions with faster convergence. Muhammad Monir Hossain, Arash Vafaei, Kimia Zamiri Azar, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
DATE | 4 |
| 2023 | RTLock: IP Protection using Scan-Aware Logic Locking at RTLabstractConventional logic locking techniques mainly focus on gate-level netlists to combat IP piracy and IC overproduction. However, this is generally not sufficient for protecting semantics and behaviors of the design. Further, these techniques are even more objectionable when the IC supply chain is at risk of insider threats. This paper proposes RTLock, a robust logic locking framework at the RTL abstraction. RTLock provides a detailed formal analysis of the design specs at the RTL that determines the locking candidate points w.r.t. attacks resiliency (SAT/BMC), locking key size, and overhead. RTLock incorporates (partial) DFT infrastructure (scan chain) at the RTL, enabled with a scan locking mechanism. It allows us to push all the necessary security-driven actions to the highest abstraction level, thus making the flow EDA tool agnostic. Additionally, RTLock demonstrates why RTL-based locking must be coupled with encryption and management protocols (e.g., IEEE P1735), to be effective against insider threats. Our experimental results show that, vs. other techniques, RTLock protects the design against broader threats at low overhead and without compromising testability. Md Rafid Muttaki, Shyvagata Saha, Hadi Mardani Kamali, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
DATE | 4 |
| 2023 | PSC-Watermark: Power Side Channel Based IP Watermarking Using Clock GatesabstractWith the ever-increasing re-use of intellectual property (IP) cores in modern system-on-chips (SoCs), it is crucial to prevent security risks such as IP piracy and overuse. Considering that IP watermarking is a potential solution to the copyright protection of IP cores, this paper proposes PSC-Watermark as a power side-channel-based IP authentication methodology using clock gates. PSC-Watermark embeds a power signature with very minimal modification to the IP core. It is done by reusing the existing clock gates to modify the dynamic power consumption inside the IP (in an SoC) based on an applied challenge, and it generates a unique power trace that works as a signature of the IP. Our experimental results show that this power signature can be robustly/effectively verified, even with the interferences emanating from the rest of the functional cores in complex SoCs. We evaluate our technique on several benchmarks of varying size (i.e., MIPS, openMSP430, or1200) in the presence of multiple non-watermarked cores operating in parallel and obtain > 90% confidence rate in proving the ownership of each watermarked IP core. Furthermore, the IP cores are watermarked in a subtle and obfuscated way with < 4% overhead, which makes the proposed technique hard to detect, remove or modify. Upoma Das, M. Sazadur Rahman, N. Nalla Anandakumar, Kimia Zamiri Azar, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
ETS | 5 |
| 2023 | TaintFuzzer: SoC Security Verification using Taint Inference-enabled FuzzingabstractModern System-on-Chip (SoC) designs containing sensitive information have become targets of malicious attacks. Unfortunately, current verification practices still undermine the importance of SoCs security verification due to extreme time-to-market constraints, lack of autonomous methodologies, and low coverage. This results in SoC designs moving forward to production with security holes, making them insecure and exploitable by adversaries. Traditional taint analysis and formal approaches are losing applicability to industrial applications due to labor-intensive, slow, and scalability issues. Some approaches apply fuzz testing for hardware vulnerability detection using state-of-the-art software fuzzers, also utilizing information flow tracking for better coverage. However, these approaches prove to be inefficient and cannot be applied to SoCs integrated with third-party IPs (3PIP) for several reasons: laborious white-box-based taint analysis, inconsiderate cross-layer co-verification, and lacking hardware-centric input mutations. This paper proposes Taintuzzer, a fuzzing-driven automated SoC security verification framework leveraging taint inference (feasible in gray-box verification) for detecting SoC security vulnerabilities. Unlike previous studies relying on traditional (code) coverage-related metrics, in TaintFuzzer, we develop (i) schemes for generating smart seeds, (ii) a security-oriented cost function, and (iii) run-time feedback for the mutation engine to choose the appropriate strategies to mutate stimuli targeting SoC modules. TaintFuzzer is powered by FPGA emulation of SoC, making it extremely fast and scalable, especially for cross-layer co-verification. TaintFuzzer's cost function and feedback enable dynamic tuning of mutation strategies to generate hardware-centric inputs. Our experiments with RISC-V-based SoC demonstrate the TaintFuzzer's effectiveness in detecting both known and unknown vulnerabilities in significantlv less time. Muhammad Monir Hossain, Nusrat Farzana, Kimia Zamiri Azar, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ICCAD | 4 |
| 2023 | CAPEC: A Cellular Automata Guided FSM-based IP Authentication SchemeabstractThe ever-increasing propensity for intellectual property (IP) reuse has reduced the design productivity gap in the supply chain. As a consequence, protecting IPs has become more difficult since IP vendors now make their IPs more flexible so that they can be reused in other designs for greater profits. This has made IP piracy and infringement easier than ever. IP watermarking can detect IP piracy and infringement and it has been an active research topic for the past decade. Various watermarking techniques have been discussed in the literature that embed circuitry into IP to provide proof of ownership. But, in most RT-level watermarking methods, the watermarking circuit is separate from IP functionality and can be easily identified and tampered with. In this paper, we propose CAPEC, a Cellular Automata (CA) guided watermarking technique that embeds watermarking circuits into the don’t care states of the FSM. The watermarking function is a set of configurable CA rules tightly coupled with the functional states of the FSM. CAPEC generates a signature in a challenge-response-based protocol, is resistant to identification, tampering, and removal attacks, and has minimal overhead. We also analyze and evaluate the efficiency of the technique and its resilience to different attacks for varying challenge size and CA rules. After watermarking different benchmarks, the watermark overhead was found to be negligible and formal verification proved no changes to the functional circuit. Mridha Md Mashahedur Rahman, M. Sazadur Rahman, Rasheed Kibria, Mike Borza, Bandy Reddy, Adam Cron, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
VTS | 7 |
| 2022 | O'clock: lock the clock via clock-gating for SoC IP protectionabstractExisting logic locking techniques can prevent IP piracy or tampering. However, they often come at the expense of high overhead and are gradually becoming vulnerable to emerging deobfuscation attacks. To protect SoC IPs, we propose O'Clock, a fully-automated clock-gating-based approach that 'locks the clock' to protect IPs in complex SoCs. O'Clock obstructs data/control flows and makes the underlying logic dysfunctional for incorrect keys by manipulating the activity factor of the clock tree. O'Clock has minimal changes to the original design and no change to the IC design flow. Our experimental results show its high resiliency against state-of-the-art de-obfuscation attacks (e.g., oracle-guided SAT, unrolling-/BMC-based SAT, removal, and oracle-less machine learning-based attacks) at negligible power, performance, and area (PPA) overhead. M. Sazadur Rahman, Rui Guo 0010, Hadi Mardani Kamali, Fahim Rahman, Farimah Farahmandi, Mohamed Abdel-Moneum, Mark Tehranipoor |
DAC | 4 |
| 2022 | ACED-IT: Assuring Confidential Electronic Design Against Insider Threats in a Zero-Trust EnvironmentabstractThe electronics supply chain has adapted into a global process over the past two decades to support the cost of process optimization. As the semiconductor industry has transitioned from a vertical to the horizontal business model, the perceived vulnerability of integrated circuit (IC) design, and fabrication has grown dramatically. Design intellectual property (IP) is the defining characteristic of most fabless design houses and integrated device manufacturers (IDMs) within the supply chain, and as such, holds significant value for market competitiveness, and in some cases, national security. Malicious insiders threaten the confidentiality of this proprietary technology. To prevent IP piracy, we redefine the modern threat landscape by considering nearly every individual in the IC design and fabrication process untrusted. Therefore, we propose a novel framework to assure confidential electronic design against insider threats, termed ACED-IT, that enables maintaining the confidentiality of the design when it traverses through different design stages (e.g., RTL/Gate-level to GDSII). ACED-IT integrates encryption, logic locking, novel temporary-inserted logic elements (TILEs), access controls, and action logging, to protect the design IP from insider threats originating from any entity in the process. ACED-IT is compatible with the current industry development flow and provides all engineers with the tools to complete their roles. The proposed ACED-IT framework is demonstrated across various benchmarks and analyzed for security. Benchmarks processed using ACED-IT incurred negligible overhead across parameters such as power, area, timing, and test coverage after functional recovery, and provided a brute force attack complexity to recover the original design exceeding that of AES-256. Andrew Stern, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2022 | SoFI: Security Property-Driven Vulnerability Assessments of ICs Against Fault-Injection AttacksabstractFault-injection attacks have become a major concern for hardware designs, primarily due to their powerful capability in tampering with critical locations in a device to cause violation of its integrity, confidentiality, and availability. Researchers have proposed a number of physical and architectural countermeasures against fault-injection attacks; however, these techniques usually come with large overhead and design efforts making them difficult to use in practice. In addition, the current electronic design automation (EDA) tools are not fully equipped to support vulnerability assessment against fault-injection attacks at the design-time for secure hardware development. To perform a design-time (i.e., presilicon) evaluation of such attacks, a designer should be aware of various security vulnerabilities and must perform a tedious manual design review, which is time-consuming and hard to ensure effectiveness. Therefore, it is very important to develop an automatic assessment framework to identify the most security-critical locations in a design to fault-injection attacks and place emphasis on protecting those locations. In this article, we propose an automated framework for fault-injection vulnerability assessment of designs at gate-level, while considering the design-specific security properties (SPs) using novel models and metrics. The proposed framework identifies the faults that can violate the SPs of the design. As a result, applying local countermeasures will be more effective and the protection overhead will be reduced significantly. Our experimental results on the SP of AES, RSA, and SHA implementations show that the security threat from fault-injection attacks can be significantly mitigated by protecting the identified critical locations, which are less than 0.6% of the design. Henian Li, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2021 | Invited: End-to-End Secure SoC Lifecycle ManagementabstractThe pursuit of manufacturing cost reduction reshaped the conventional system-on-chip (SoC) design and manufacturing flow into the horizontal business model. In this model, the design house loses control of the design during the manufacturing process. Therefore, this shift has introduced potential vulnerabilities at each stage of the flow and provides adversaries ample opportunities to cause piracy, security, and trust concerns. Further, SoCs deployed in IoT, smart, and mission-critical devices contain sensitive assets to perform security-critical applications, requiring an on-chip security engine (SE) to ensure protecting assets and secure operation throughout the lifecycle. In this paper, we present an end-to-end secure SoC lifecycle management flow that establishes trust at each stage of the manufacturing process, prevents potential security threats, provides secure provisioning schemes, and protects the chip from in-field and supply chain vulnerabilities. Md Sami Ul Islam Sami, Fahim Rahman, Farimah Farahmandi, Adam Cron, Mike Borza, Mark Tehranipoor |
DAC | 2 |
| 2021 | BOFT: Exploitable Buffer Overflow Detection by Information Flow TrackingabstractBuffer overflow is one of the most critical software vulnerabilities with numerous functional and security impacts on memory boundaries and program calls. An exploitable buffer overflow, which can be directly or indirectly triggered through external user domain inputs, is of a greater concern because it can be misused during run-time for adversarial intention. Although some existing tools offer buffer overflow detection to certain extents, there are major limitations, such as, poor detection coverage and ad-hoc/manual verification efforts due to inadequate predefined executions for static analysis and substantially large input subspace for dynamic verification. In this paper, to provide program verification in static time with high detection coverage, we propose an automated framework for Exploitable Buffer Overflow Detection by Information Flow Tracking (BOFT). We achieve this goal following three steps - first, BOFT analyzes the usage of arrays, pointers, and vulnerable application programming interface (APIs) in the program code and automatically inserts assertions required for buffer overflow detection. Second, BOFT instruments the program with taints for direct and indirect information flow tracking using an extensive set of formal expressions. Finally, it symbolically analyzes the instrumented code for maximum coverage and provides the list of exploitable buffer overflow vulnerabilities. BOFT is evaluated on standard benchmarks from SAMATE Juliet Test Suite (NIST) with a successful detection of ~94.87% (minimum) of exploitable buffer overflows with zero false positives. Muhammad Monir Hossain, Farimah Farahmandi, Mark Tehranipoor, Fahim Rahman |
DATE | 4 |
| 2021 | RHAT: Efficient RowHammer-Aware Test for Modern DRAM ModulesabstractIn recent times, the family of rowhammer attacks have posed major security threats. Assessing the rowhammer vulnerability of DRAM modules during post-manufacturing test as well as system development and in-field deployment is a crucial step towards detecting and mitigating it. Detection of rowhammer vulnerable cells is quite challenging due to random physical factors and memory constructions, and very exhaustive leading to time and cost overhead. In this paper, we propose an efficient test framework, called RHAT, to address this concern. RHAT can be employed for both manufacturing test and in-field (deployment) test. It first develops a non-invasive approach to efficiently reverse engineer the address scrambling on DRAM. It then identifies critical vulnerability features by spatial correlation analysis of memory cells. Finally, it offers a fast test algorithm to detect rowhammer-vulnerable cells using smaller representative memory array based on the correlation analysis. We implemented and validated RHAT on DIMM samples from three different DRAM vendors showing significant correlation with satisfactory test coverage and time. Mohammad Farmani, Mark Tehranipoor, Fahim Rahman |
ETS | 3 |
| 2021 | AutoMap: Automated Mapping of Security Properties Between Different Levels of Abstraction in Design FlowabstractThe security of system-on-chip (SoC) designs is threatened by many vulnerabilities introduced by untrusted third-party IPs, and designers and CAD tools' lack of awareness of security requirements. Ensuring the security of an SoC has become highly challenging due to the diverse threat models, high design complexity, and lack of effective security-aware verification solutions. Moreover, new security vulnerabilities are introduced during the design transformation from higher to lower abstraction levels. As a result, security verification becomes a major bottleneck that should be performed at every level of design abstraction. Reducing the verification effort by mapping the security properties at different design stages could be an efficient solution to lower the total verification time if the new vulnerabilities introduced at different abstraction levels are addressed properly. To address this challenge, we introduce AutoMap that, in addition to the mapping, extends and expands the security properties to identify new vulnerabilities introduced when the design moves from higher-to lower-level abstraction. Starting at the higher abstraction level with a defined set of security properties for the target threat models, AutoMap automatically maps the properties to the lower levels of abstraction to reduce the verification effort. Furthermore, it extends and expands the properties to cover new vulnerabilities introduced by design transformations and updates to the lower abstraction level. We demonstrate AutoMap's efficacy by applying it to AES, RSA, and SHA256 at C++, RTL, and gate-level. We show that AutoMap effectively facilitates the detection of security vulnerabilities from different sources during the design transformation. Bulbul Ahmed, Fahim Rahman, Nick Hooten, Farimah Farahmandi, Mark Tehranipoor |
ICCAD | 2 |
| 2021 | LL-ATPG: Logic-Locking Aware Test Using Valet Keys in an Untrusted EnvironmentabstractThe ever-increasing cost and complexity of cutting-edge manufacturing and test processes have migrated the semiconductor industry towards a globalized business model. With many untrusted entities involved in the supply chain located across the globe, original intellectual property (IP) owners face threats such as IP theft/piracy, tampering, counterfeiting, reverse engineering, and overproduction. Logic locking has emerged as a promising solution to protect integrated circuits (ICs) against supply chain vulnerabilities. It inserts key gates to corrupt circuit functionality for incorrect key inputs. A logic-locked chip test can be performed either before or after chip activation (becoming unlocked) by loading the unlocking key into the on-chip tamperproof memory. However, both pre-activation and post-activation tests suffer from lower test coverage, higher test cost, and critical security vulnerabilities. To address the shortcomings, we propose LL-ATPG, a logic-locking aware test method that applies a set of valet (dummy) keys based on a target test coverage to perform manufacturing test in an untrusted environment. LL-ATPG achieves high test coverage and minimizes test time overhead when testing the logic-locked chip before activation without sharing the unlocking key. We perform security analysis of LL-ATPG and experimentally demonstrate that sharing the valet keys with the untrusted foundry does not create additional vulnerability for the underlying locking method. M. Sazadur Rahman, Henian Li, Rui Guo 0010, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
ITC | 4 |
| 2021 | SAIF: Automated Asset Identification for Security Verification at the Register Transfer LevelabstractWith the increasing complexity, modern system-onchip (SoC) designs are becoming more susceptible to security attacks and require comprehensive security assurance. However, establishing a comprehensive assurance for security often involves knowledge of relevant security assets. Since modern SoCs contain myriad confidential assets, the identification of security assets is not straightforward. The number and types of assets change due to numerous embedded hardware blocks within the SoC and their complex interactions. Some security assets are easily identifiable because of their distinct characteristics and unique definitions, while others remain in the blind-spot during design and verification and can be utilized as potential attack surfaces to violate confidentiality, integrity, and availability of the SoC. Therefore, it is essential to automatically identify security assets in an SoC at pre-silicon design stages to protect them and prevent potential attacks. In this paper, we propose an automated CAD framework called SAF to identify an SoC's security assets at the register transfer level (RTL) through comprehensive vulnerability analysis under different threat models. Moreover, we develop and incorporate metrics with SAF to quantitatively assess multiple vulnerabilities for the identified security assets. We demonstrate the effectiveness of SAF on MSP430 micro-controller and CEP SoC benchmarks. Our experimental results show that SAF can successfully and automatically identify an SoC's most vulnerable underlying security assets for protection. Nusrat Farzana, Avinash Ayalasomayajula, Fahim Rahman, Farimah Farahmandi, Mark Tehranipoor |
VTS | 3 |
| 2021 | Security Assessment of Dynamically Obfuscated Scan Chain Against Oracle-guided AttacksabstractLogic locking has emerged as a promising solution to protect integrated circuits against piracy and tampering. However, the security provided by existing logic locking techniques is often thwarted by Boolean satisfiability (SAT)-based oracle-guided attacks. Criteria for successful SAT attacks on locked circuits include: (i) the circuit under attack is fully combinational, or (ii) the attacker has scan chain access. To address the threat posed by SAT-based attacks, we adopt the dynamically obfuscated scan chain (DOSC) architecture and illustrate its resiliency against the SAT attacks when inserted into the scan chain of an obfuscated design. We demonstrate, both mathematically and experimentally, that DOSC exponentially increases the resiliency against key extraction by SAT attack and its variants. Our results show that the mathematical estimation of attack complexity correlates to the experimental results with an accuracy of 95% or better. Along with the formal proof, we model DOSC architecture to its equivalent combinational circuit and perform SAT attack to evaluate its resiliency empirically. Our experiments demonstrate that SAT attack on DOSC-inserted benchmark circuits timeout at minimal test time overhead, and while DOSC requires less than 1% area and power overhead. M. Sazadur Rahman, Adib Nahiyan, Fahim Rahman, Saverio Fazzari, Kenneth Plaks, Farimah Farahmandi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2020 | SeRFI: Secure Remote FPGA Initialization in an Untrusted EnvironmentabstractThe bitstream inside a Field-Programmable Gate Array (FPGA) is often protected using an encryption key, acting as a root of trust and stored inside the FPGA, to defend against bitstream piracy, tampering, overproduction, and static-time reverse engineering. For cost savings and faster production, trusted system designers often rely on an untrusted system assembler to program the encryption key into the FPGA, focusing only the end-user-stage threats. However, providing the secret encryption key to an untrusted entity introduces additional threats, since access to this key can compromise the entire root of trust and breach the encrypted bitstream enabling a multitude of attacks including Trojan insertion, piracy and overproduction. To address this issue, we propose the Secure Remote FPGA Initialization (SeRFI) protocol to transmit the encryption key securely from a trusted system designer into an FPGA in physical possession of an untrusted system assembler. Our protocol eliminates direct key sharing with the untrusted system assembler as well as prevents against adversarial intention of extracting the encryption key during the programming phase where the assembler has physical access to the FPGA. Adam Duncan, Adib Nahiyan, Fahim Rahman, Grant Skipper, D. Martin Swany, Andrew Lukefahr, Farimah Farahmandi, Mark Tehranipoor |
VTS | 3 |
| 2020 | Leveraging Side-Channel Information for Disassembly and SecurityabstractWith the rise of Internet of Things (IoT), devices such as smartphones, embedded medical devices, smart home appliances as well as traditional computing platforms such as personal computers and servers have been increasingly targeted with a variety of cyber attacks. Due to limited hardware resources for embedded devices and difficulty in wide-coverage and on-time software updates, software-only cyber defense techniques, such as traditional anti-virus and malware detectors, do not offer a silver-bullet solution. Hardware-based security monitoring and protection techniques, therefore, have gained significant attention. Monitoring devices using side channel leakage information, e.g. power supply variation and electromagnetic (EM) radiation, is a promising avenue that promotes multiple directions in security and trust applications. In this paper, we provide a taxonomy of hardware-based monitoring techniques against different cyber and hardware attacks, highlight the potentials and unique challenges, and display how power-based side-channel instruction-level monitoring can offer suitable solutions to prevailing embedded device security issues. Further, we delineate approaches for future research directions. Jungmin Park, Fahim Rahman, Apostol Vassilev 0001, Domenic Forte, Mark Tehranipoor |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2020 | EMFORCED: EM-Based Fingerprinting Framework for Remarked and Cloned Counterfeit IC Detection Using Machine Learning ClassificationabstractElectronics supply chain vulnerabilities have broadened in scope over the past two decades. With nearly all integrated circuit (IC) design companies relinquishing their fabrication, packaging, and test facilities, they are forced to rely upon companies from around the world to produce their ICs. This dependence leaves the electronics supply chain open to counterfeiting activities. In this article, we propose an electromagnetic (EM)-based fingerprinting framework, called EMFORCED, to detect remarked and cloned counterfeit ICs. Here, we demonstrate the benefits of using naturally occurring EM side channels to identify the IC design layout without decapsulating the chip under test. Enabling only the clock, Vdd, and ground pins allows us to generate a design-specific fingerprint that is dependent upon the physical parameters of the chip under test. EMFORCED leverages the EM emissions from the clock distribution network to create a holistic, design-level, fingerprint, including both temporal information and spatial information. We utilize the fingerprint information of functionally similar 8051-series microprocessors from three vendors and perform unsupervised (principal component analysis) and supervised (linear discriminant analysis) machine learning methods on all ICs to determine their intravendor and intervendor similarities. We acquired ICs from multiple dates and lot codes along with variants acquired from the gray market and analyzed them for authenticity using physical inspection and X-ray tomography. Statistical analysis and machine learning techniques are used to demonstrate the reference-free and reference-inclusive classification methods based on EMFORCED measurements. We demonstrate the classification accuracies of 99.46% and 100% for unsupervised and supervised approaches, respectively. Andrew Stern, Ulbert Botero, Fahim Rahman, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2020 | Interconnect-Based PUF With Signature Uniqueness EnhancementabstractPhysical unclonable function (PUF) is an important security primitive, which generates unique signatures as fingerprints for each chip. This article first presents a novel interconnect-based PUF (iPUF). The proposed iPUF utilizes the manufacturing process variability of interconnect lines to introduce crosstalk variations for generating PUF signatures. By leveraging the variations of passive interconnects, iPUF minimizes the usage of active CMOS components, providing an increased resiliency against environmental variations and aging. Initiated by a linear feedback shift register (LFSR), iPUF sequentially generates 1-bit signature at each clock cycle, making it more efficient compared with ring-oscillator PUF. Second, two schemes for signature uniqueness enhancement of sequential PUFs are proposed. The self-masking scheme windows the sequential signature with an m-bit mask trained by the PUF's own initial sequential signature. Meanwhile, the bit-filtering scheme screens the randomness of each bit within the sequential signature by exploiting several sub-iPUFs and selects the bits with high randomness. To verify the performance of iPUF, Monte Carlo simulations of 500 samples, with variations following industrial data, are conducted in different operating corners. The uniqueness of the given sample set approaches 48.63% with a 10-bit mask. With ±10% supply voltage, 0 °C-100 °C temperature variations, as well as one year of unaccelerated aging, iPUF's reliability values, are as high as 96.09%, 99.06%, and 99.63%, respectively. For verification, 50 dies of iPUF chips are manufactured with a 55-nm technology node. Silicon results demonstrate that iPUF generates 1024-bit signatures with satisfied uniqueness (48.03%) while exhibiting good reliability (90.07%) under 120-mV voltage variations. Finally, iPUF's robustness against various attacks is also proven. Liting Yu, Xiaoxiao Wang 0001, Fahim Rahman, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2019 | FPGA Bitstream Security: A Day in the LifeabstractSecurity concerns for field-programmable gate array (FPGA) applications and hardware are evolving as FPGA designs grow in complexity, involve sophisticated intellectual properties (IPs), and pass through more entities in the design and implementation flow. FPGAs are now routinely found integrated into system-on-chip (SoC) platforms, cloud-based shared computing resources, and in commercial and government systems. The IPs included in FPGAs are sourced from multiple origins and passed through numerous entities (such as design house, system integrator, and users) through the lifecycle. This paper thoroughly examines the interaction of these entities from the perspective of the bitstream file responsible for the actual hardware configuration of the FPGA. Five stages of the bitstream lifecycle are introduced to analyze this interaction: 1) bitstream-generation, 2) bitstream-at-rest, 3) bitstream-loading, 4) bitstream-running, and 5) bitstream-end-of-life. Potential threats and vulnerabilities are discussed at each stage, and both vendor-offered and academic countermeasures are highlighted for a robust and comprehensive security assurance. Adam Duncan, Fahim Rahman, Andrew Lukefahr, Farimah Farahmandi, Mark Tehranipoor |
ITC | 2 |
| 2019 | SoC Security Verification using Property CheckingabstractSecurity of a system-on-chip (SoC) can be weakened by exploiting the inherent and potential vulnerabilities of the intellectual property (IP) cores used to implement the design as well as the interaction among the IPs. These vulnerabilities not only increase the security verification effort but also can increase design complexity and time-to-market. If the design and verification engineers are equipped with a comprehensive set of security properties at the early stage of a design process, SoC security validation effort can be greatly reduced. In this paper, we propose a property-driven approach to design a secure SoC. Our goal is to develop a comprehensive set of reusable and architecture-agnostic properties acting as security-aware design rules and guidelines. Moreover, we develop metrics from these properties to facilitate quantitative security assessment. Finally, we present design examples to demonstrate the efficacy of our approach under different threat models. Nusrat Farzana, Fahim Rahman, Mark Tehranipoor, Farimah Farahmandi |
ITC | 2 |
| 2019 | Electronics Supply Chain Integrity Enabled by BlockchainabstractElectronic systems are ubiquitous today, playing an irreplaceable role in our personal lives as well as in critical infrastructures such as power grid, satellite communication, and public transportation. In the past few decades, the security of software running on these systems has received significant attention. However, hardware has been assumed to be trustworthy and reliable "by default" without really analyzing the vulnerabilities in the electronics supply chain. With the rapid globalization of the semiconductor industry, it has become challenging to ensure the integrity and security of hardware. In this paper, we discuss the integrity concerns associated with a globalized electronics supply chain. More specifically, we divide the supply chain into six distinct entities: IP owner/foundry (OCM), distributor, assembler, integrator, end user, and electronics recycler, and analyze the vulnerabilities and threats associated with each stage. To address the concerns of the supply chain integrity, we propose a blockchain-based certificate authority framework that can be used to manage critical chip information such as electronic chip identification (ECID), chip grade, transaction time, etc. The decentralized nature of the proposed framework can mitigate most threats of the electronics supply chain, such as recycling, remarking, cloning, and overproduction. Xiaolin Xu 0001, Fahim Rahman, Bicky Shakya, Apostol Vassilev 0001, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2018 | Device attestation: Past, present, and futureabstractIn recent years we have seen a rise in popularity of networked devices. From traffic signals in a city's busiest intersection and energy metering appliances, to internet-connected security cameras, these embedded devices have become entrenched in everyday life. As a consequence, a need to ensure secure and reliable operation of these devices has also risen. Device attestation is a promising solution to the operational demands of embedded devices, especially those widely used in Internet of Things and Cyber-Physical System. In this paper, we summarize the basics of device attestation. We then present a summary of attestation approaches by classifying them based on their functionality and reliability guarantees they provide to networked devices. Lastly, we discuss the limitations and potential issues current mechanisms exhibit and propose new research directions. Orlando Arias, Fahim Rahman, Mark Tehranipoor, Yier Jin |
DATE | 2 |
| 2017 | Security Beyond CMOS: Fundamentals, Applications, and RoadmapabstractHardware-oriented security and trust has traditionally relied on the dominant CMOS technology to develop security primitives and provide protection against different attacks and vulnerabilities. With CMOS nearly reaching its fundamental scaling limit and the shortcomings of current solutions, researchers are now looking to exploit emerging nanoelectronic devices for various security applications. In this paper, we discuss the unique features of three emerging nanoelectronic technologies, namely, phase-change memory, grapheme, and carbon nanotubes, and analyze how these features can aid in hardware security and trust. In addition, we present challenges and future research directions about how to effectively integrate emerging nanoscale devices into hardware security. We emphasize that an interdisciplinary initiative is needed for emerging technologies to reach their full potential in security and trust applications. Fahim Rahman, Bicky Shakya, Xiaolin Xu 0001, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2017 | Poly-Si-Based Physical Unclonable FunctionsabstractPhysically unclonable functions (PUFs) were introduced over a decade ago for a variety of security applications. Silicon PUFs exploit uncontrollable random variations from manufacturing to generate unique and random signatures/ responses. However, such sources of randomness may become limited during standard CMOS manufacturing as processes continue to mature especially with the advances in design for manufacturability. Recently, poly-Si is proposed to improve PUF quality by offering considerable random variations at the materials level, which is from randomly distributed grain boundaries and trapped charges in poly-Si. In this paper, we develop a poly-Si field-effect transistor (FET) model to study the properties of poly-Si-based PUFs under different supply voltages (VDD) and temperatures (T). Simulation results obtained from ring oscillator and arbiter PUFs show that compared with conventional CMOS-based PUFs, the reliability of poly-Si-based PUFs can be improved from around 90% to 98% and the PUF devices are robust against varying VDDand T. Haoting Shen, Fahim Rahman, Bicky Shakya, Xiaolin Xu 0001, Mark Tehranipoor, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2015 | A pair selection algorithm for robust RO-PUF against environmental variations and agingabstractPhysically Unclonable Functions (PUFs) have emerged as a promising security primitive for low-cost authentication and cryptographic key generation. However, PUF stability with respect to temporal variations still limits its utility and widespread acceptance. Previous techniques in the literature have focused on improving PUF robustness against voltage and temperature variations, but the issues associated with aging have been largely neglected. In this paper, we propose a reliable pair selection algorithm (RePa) that can generate reliable keys from an RO-PUF under aging, voltage, and temperature variations. The RePa approach selects RO pairs with both initial frequency difference and aging rate/slope in mind. The aging slope is predicted by exploiting correlation that exists between frequency variation with respect to voltage and frequency variation with respect to aging. We evaluate RePa with simulations to show that it achieves significant improvement over the current state of the art in terms of reliability and cost. The proposed approach can achieve ~ 3.0x more robust key with only ~ 2.3x more ROs required than the conventional RO-PUF pair selection for the same key size. Md Tauhidur Rahman 0001, Domenic Forte, Fahim Rahman, Mark Tehranipoor |
ICCD | 3 |