Johanna Baehr 0001

dblp:228/3809 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0002-3264-907XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 10 · 3 first-author · 8 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021
YearPublicationVenuePosition
2025 Multi-Partner Project: Reverse Engineering Methods for Trusted Chip Design (RESEC)
abstract
The RESEC (REconstruction of highly integrated SECurity devices) project addresses the growing concerns of malicious modification and IP piracy in globally distributed supply chains. The project's primary objective is to develop, verify, and optimise a complete reverse engineering process for integrated circuits manufactured in technology nodes of 40 nm and below. This paper highlights the significant contributions of RESEC in the areas of sample preparation, computer vision, and netlist analysis, thereby extending the state-of-the-art in hardware reverse engineering. The project results are expected to profoundly impact the development and physical verification of trusted chips, paving the way for future research.
Bernhard Lippmann, Johanna Baehr 0001, Alexander Hepp, Horst A. Gieser
DATE2
2024 Hardware Honeypot: Setting Sequential Reverse Engineering on a Wrong Track
abstract
Reverse engineering (RE) of finite state machines (FSMs) is a serious threat when protecting designs against RE attacks. While most recent protection techniques rely on the security of a secret key, this work presents a new approach: hardware FSM honeypots. These honeypots lead the RE tools to a wrong but, for the tools, very attractive FSM, while making the original FSM less attractive. The results show that state-of-the-art RE methods favor the highly attractive honeypot as FSM candidate or do no longer detect the correct, original FSM.
Michaela Brunner, Hye-Hyun Lee, Alexander Hepp, Johanna Baehr 0001, Georg Sigl
DDECS4
2024 Fault-Simulation-Based Flip-Flop Classification for Reverse Engineering
abstract
This work outlines a crucial step in gate-level netlist reverse engineering: classifying control and data flip-flops (FFs) to discern control logic and data paths. Existing methods rely mainly on structural characteristics, which can have disavantages. Our work introduces a novel approach that classifies FFs based on observed characteristics after fault insertion and propagation. We develop three new classification methods for block cipher implementations, emphasizing their significance in system security. However, we also explore the approach's applicability to other design types. We apply the approach on AES implementations using an automatic fault simulation framework, which shows perfect results for most classifications.
Michael Mildner, Michaela Brunner, Michael Gruber, Johanna Baehr 0001, Georg Sigl
DDECS4
2022 Golden Model-Free Hardware Trojan Detection by Classification of Netlist Module Graphs
abstract
In a world where increasingly complex integrated circuits are manufactured in supply chains across the globe, hardware Trojans are an omnipresent threat. State-of-the-art methods for Trojan detection often require a golden model of the device under test. Other methods that operate on the netlist without a golden model cannot handle complex designs and operate on Trojan-specific sets of netlist graph features. In this work, we propose a novel machine-learning-based method for hardware Trojan detection. Our method first uses a library of known malicious and benign modules in hierarchical designs to train an eXtreme Gradient Boosted Tree Classifier (XGBClassifier). For training, we generate netlist graphs of each hierarchical module and calculate feature vectors comprising structural characteristics of these graphs. After the training phase, we can analyze the synthesized hierarchical modules of an unknown design under test. The method calculates a feature vector for each module. With this feature vector, each module can be classified into either benign or malicious by the previously trained XGBClassifier. After classifying all modules, we derive a classification for all standard cells in the design under test. This technique allows the identification of hardware Trojan cells in a design and highlights regions of interest to direct further reverse engineering efforts. Experiments show that this approach performs with >97 % Sensitivity and Specificity across available and newly generated hardware Trojan benchmarks and can be applied to more complex designs than previous netlist-based methods while maintaining similar computational complexity.
Alexander Hepp, Johanna Baehr 0001, Georg Sigl
DATE2
2022 Physical and Functional Reverse Engineering Challenges for Advanced Semiconductor Solutions
abstract
Motivated by the threats of malicious modification and piracy arising from worldwide distributed supply chains, the goal of RESEC is the creation, verification, and optimization of a complete reverse engineering process for integrated circuits manufactured in technology nodes of 40nm and below. Building upon the presentation of individual reverse engineering process stages, this paper connects analysis efforts and yields with their impact on hardware security, demonstrated on a design with implemented experimental hardware Trojans. We outline the interim stage of our research activities and present our future targets linking chip design and physical verification processes.
Bernhard Lippmann, Ann-Christin Bette, Matthias Ludwig 0005, Johannes Mutter, Johanna Baehr 0001, Alexander Hepp, Horst A. Gieser, Nicola Kovac, Tobias Zweifel, Martin Rasche, Oliver Kellermann
DATE5
2022 Hardware Obfuscation of Digital FIR Filters
abstract
A finite impulse response (FIR) filter is a ubiquitous block in digital signal processing applications. Its characteristics are determined by its coefficients, which are the intellectual property (IP) for its designer. However, in a hardware efficient realization, its coefficients become vulnerable to reverse engineering. This paper presents a filter design technique that can protect this IP, taking into account hardware complexity and ensuring that the filter behaves as specified only when a secret key is provided. To do so, coefficients are hidden among decoys, which are selected beyond possible values of coefficients using three alternative methods. As an attack scenario, an adversary at an untrusted foundry is considered. A reverse engineering technique is developed to find the chosen decoy selection method and explore the potential leakage of coefficients through decoys. An oracle-less attack is also used to find the secret key. Experimental results show that the proposed technique can lead to filter designs with competitive hardware complexity and higher resiliency to attacks with respect to previously proposed methods.
Levent Aksoy, Alexander Hepp, Johanna Baehr 0001, Samuel Nascimento Pagliarini
DDECS3
2022 Open Source Hardware Design and Hardware Reverse Engineering: A Security Analysis
abstract
Major industry-led initiatives such as RISC-V and OpenTitan strive for verified, customizable and standardized products, based on a combination of Open Source Hardware (OSHW) and custom intellectual property (IP), to be used in safety and security-critical systems. The protection of these products against reverse-engineering-based threats such as IP Theft and IP Piracy, Hardware Trojan (HT) insertion, and physical attacks is of equal importance as for closed source designs. OSHW generates novel threats to the security of a design and the protection of IP. This paper discusses to what extent OSHW reduces the difficulty of attacking a product. An analysis of the reverse engineering process shows that OSHW lowers the effort to retrieve broad knowledge about a product and decreases the success of related countermeasures. In a case study on a RISC-V core and an AES design, the red team uses knowledge about OSHW to circumvent logic locking protection and successfully identify the functionality and the used locking key. The paper concludes with an outlook on the secure protection of OSHW.
Johanna Baehr 0001, Alexander Hepp, Michaela Brunner, Maja Malenko, Georg Sigl
DSD1
2022 Toward a Human-Readable State Machine Extraction
abstract
The target of sequential reverse engineering is to extract the state machine of a design. Sequential reverse engineering of a gate-level netlist consists of the identification of so-called state flip-flops (sFFs), as well as the extraction of the state machine. The second step can be solved with an exact approach if the correct sFFs and the correct reset state are provided. For the first step, several more or less heuristic approaches exist. This work investigates sequential reverse engineering with the objective of a human-readable state machine extraction. A human-readable state machine reflects the original state machine and is not overloaded by additional design information. For this purpose, the work derives a systematic categorization of sFF sets, based on properties of single sFFs and their sets. These properties are determined by analyzing the degrees of freedom in describing state machines as the well-known Moore and Mealy machines. Based on the systematic categorization, this work presents an sFF set definition for a human-readable state machine, categorizes existing sFF identification strategies, and develops four post-processing methods. The results show that post-processing predominantly improves the outcome of several existing sFF identification algorithms.
Michaela Brunner, Alexander Hepp, Johanna Baehr 0001, Georg Sigl
ACM Trans. Design Autom. Electr. Syst.3
2020 Machine learning and structural characteristics for reverse engineering
Johanna Baehr 0001, Alessandro Bernardini, Georg Sigl, Ulf Schlichtmann
Integr.1
2019 Machine learning and structural characteristics for reverse engineering
abstract
In the past years, much of the research into hardware reverse engineering has focused on the abstraction of gate level netlists to a human readable form. However, none of the proposed methods consider a realistic reverse engineering scenario, where the netlist is physically extracted from a chip. This paper analyzes how errors caused by this extraction and the later partitioning of the netlist affect the ability to identify the functionality. Current formal verification based methods, which compare against a golden model, are incapable of dealing with such erroneous netlists. Two new methods are proposed, which focus on the idea that structural similarity implies functional similarity. The first approach uses fuzzy structural similarity matching to compare the structural characteristics of an unknown design against designs in a golden model library using machine learning. The second approach proposes a method for inexact graph matching using fuzzy graph isomorphisms, based on the functionalities of gates used within the design. For realistic error percentages, both approaches are able to match more than 90% of designs correctly. This is an important first step for hardware reverse engineering methods beyond formal verification based equivalence matching.
Johanna Baehr 0001, Alessandro Bernardini, Georg Sigl, Ulf Schlichtmann
ASP-DAC1