Dina Mahmoud

dblp:241/0934 · also Dina G. Mahmoud · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
2since 2021 · last 2022
0000-0003-0720-1342ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2022 FPGA-to-CPU Undervolting Attacks
abstract
FPGAs are proving useful and attractive for many applications, thanks to their hardware reconfigurability, low power, and high-degree of parallelism. As a result, modern embedded systems are often based on systems-on-chip (SoCs), where CPUs and FPGAs share the same die. In this paper, we demonstrate the first undervolting attack in which the FPGA acts as an aggressor while the CPU, residing on the same SoC, is the victim. We show that an adversary can use the FPGA fabric to create a significant supply voltage drop which, in turn, faults the software computation performed by the CPU. Additionally, we show that an attacker can, with an even higher success rate, execute a denial-of-service attack, without any modification of the underlying hardware or the power distribution network. Our work exposes a new electrical-level attack surface, created by tight integration of CPUs and FPGAs in modern SoCs, and incites future research on countermeasures.
Dina Mahmoud, Samah Hussein, Vincent Lenders, Mirjana Stojilovic
DATE1
2021 Shared FPGAs and the Holy Grail: Protections against Side-Channel and Fault Attacks
abstract
In this paper, we survey recently proposed methods for protecting against side-channel and fault attacks in shared FPGAs. These methods are quite versatile, targeting FPGA compilation flow, real-time timing-fault detection, on-chip active fences, automated bitstream verification, etc. Despite their versatility, they are mostly designed to counteract a specific class of attacks. To understand how to address the problem of security in shared FPGAs in a comprehensive way, we discuss their individual strengths and weaknesses, in an attempt to identify research directions necessitating further investigation.
Ognjen Glamocanin, Dina Mahmoud, Francesco Regazzoni 0001, Mirjana Stojilovic
DATE2
2020 X-Attack: Remote Activation of Satisfiability Don't-Care Hardware Trojans on Shared FPGAs
abstract
Albeit very appealing, FPGA multitenancy in the cloud computing environment is currently on hold due to a number of recently discovered vulnerabilities to side-channel attacks and covert communication. In this work, we successfully demonstrate a new attack scenario on shared FPGAs: we show that an FPGA tenant can activate a dormant hardware Trojan without any physical or logical connection to the private Trojan-infected FPGA circuit. Our victim contains a so-called satisfiability don't-care Trojan, activated by a pair of don't-care signals, which never reach the combined trigger condition under normal operation. However, once a malicious FPGA user starts to induce considerable fluctuations in the on-chip signal delays—and, consequently, the timing faults-these harmless don't-care signals take unexpected values which trigger the Trojan. Our attack model eliminates the assumption on physical access to or manipulation of the victim design. Contrary to existing fault and side-channel attacks that target unprotected cryptographic circuits, our new attack is shown effective even against provably well-protected cryptographic circuits. Besides demonstrating the attack by successfully leaking the entire cryptographic key from one unprotected and one masked AES S-box implementation, we present an efficient and lightweight countermeasure.
Dina Mahmoud, Wei Hu 0008, Mirjana Stojilovic
FPL1
2020 Work-in-Progress: Triple Event Upset Tolerant Area-Efficient FPGA-Based System for Space Applications And Nuclear Plants
abstract
This paper focuses on FPGA-based systems in the context of space applications and nuclear plants which are extremely harsh environments. In such environments, the probability of occurrence of Multiple Event Upsets (MEUs) is not negligible. Conventional fault-tolerant architectures (such as Triple Modular Redundancy) will NOT be able to handle Triple Event Upsets (TEUs) for example. A fault-tolerant architecture with only six identical modules is developed in this paper even though, intuitively, at least seven modules are required for a system to recover from a TEU. It is proven that the proposed architecture can fully recover from any sequence of Single, Double or Triple Event Upsets by using Dynamic Partial Reconfiguration. If a hard fault affects one of the modules, the architecture will lose some of its fault tolerance but may be able to continue operating correctly depending on the nature of the next fault.
Beatrice Shokry, Dina Mahmoud, Hassanein H. Amer, Maha Shatta, Gehad I. Alkady, Ramez M. Daoud, Ihab Adly, Manar N. Shaker, Tarek K. Refaat
WFCS2
2019 Timing Violation Induced Faults in Multi-Tenant FPGAs
abstract
FPGAs have made their way into the cloud, allowing users to gain remote access to the state-of-the-art reconfigurable fabric and implement their custom accelerators. Since FPGAs are large enough to accommodate multiple independent designs, the multi-tenant user scenario may soon be prevalent in cloud computing environments. However, shared use of an FPGA raises security concerns. Recently discovered hardware Trojans for use in multi-tenant FPGA settings target denial-of-service attacks, power side-channel attacks, and crosstalk side-channel attacks. In this work, we present an attack method for causing timing-constraints violation in the multi-tenant FPGA setting. This type of attack is very dangerous as the consequences of timing faults are temporary errors, which are often impossible to notice. We demonstrate the attack on a set of self-timed true random number generators (STRNGs), frequently used in cryptographic applications. When the attack is launched, the STRNG outputs become biased and fail randomness tests. However, after the attack, STRNGs recover and continue generating random bits.
Dina Mahmoud, Mirjana Stojilovic
DATE1
2019 Intelligent Battery-Aware Energy Management System for Electric Vehicles
abstract
This paper proposes a system for intelligent energy management in electric vehicles. This system incorporates parameters relating to driving style of the car, trip information and battery states. The driving cycle classification subsystem is implemented in different scenarios, and the results of power, performance and utilization are reported. Finally, a performability analysis, utilizing the implementation scenarios for increasing the system reliability, is presented.
Dina Mahmoud, Omar A. Elkhouly, Muhammad Azzazy, Gehad I. Alkady, Ihab Adly, Ramez M. Daoud, Hassanein H. Amer, Hany M. Elsayed, Mark Guirguis, Mohamed Gamal Abdelshafi
ETFA1