Nimish Mishra

dblp:254/3236 · DBLP profile ↗
← Back
12ranked-venue papers
5as first author
12since 2021 · last 2025
0000-0002-8585-9425ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 8 since 2021Systems, architecture and hardware · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2025 Unified FPGA Design of Kyber and Dilithium with Provable Fault Tolerance
abstract
Efficient and secure hardware implementations of post-quantum cryptographic schemes are critical for real-world adoption. In this work, we propose a unified FPGA-based architecture for Kyber and Dilithium that combines flexibility, lightweight design, and fault tolerance. The architecture adopts a microcoded, programmable datapath supporting both schemes with minimal area overhead, enabling seamless integration of modules such as SHAKE, sampling, and coefficient rounding. To enhance resilience against propagation-based fault attacks-which exploit effective/ineffective fault behavior in public-domain computations-we embed a probabilistic verification mechanism using rejection sampling. This countermeasure transforms deterministic operations into cryptographically constrained probabilistic processes that remain efficient under normal conditions while significantly degrading under adversarial faults. The result is a robust and compact design that not only supports both a lattice-based KEM and signature scheme, but also provides the first unified fault countermeasure architecture for Kyber and Dilithium, maintaining low retry counts and minimal performance degradation in fault-free environments.
Siddhartha Chowdhury, Nimish Mishra, Sarani Bhattacharya, Debdeep Mukhopadhyay
ASAP2
2025 Ring-LWR based Commitments and ZK-PoKs with Application to Verifiable Quantum-Safe Searchable Symmetric Encryption
Debadrita Talapatra, Nimish Mishra, Debdeep Mukhopadhyay
AsiaCCS2
2025 "OOPS!": Out-Of-Band Remote Power Side-Channel Attacks on Intel SGX and TDX
abstract
Prior work shows that remote power attacks on Intel processors are possible through two Model Specific Registers (MSRs): MSR_PKG_Energy_Status and MSR_PPO_Energy_Status. In response, Intel introduced a defense: a bit in MSR IA32_MISC_PACKAGE_CTLS allows users to enable/disable “filtering” mechanism that adds additional noise to energy measurements to harden against power side-channel attacks. In this work, we demonstrate that “filtering” does not cover all possible avenues of measuring power. On Intel server-grade platforms, components like out-of-band management interface (OOB) exist which also expose telemetric information like inband energy consumption. For this, we first reverse engineer the protocol structure over which OOB communicates with in-band components. We then show how OOB allows read-only access to the Package Configuration Space (PCS) and note that energy readings through PCS are outside the scope of filtering. Using this, we establish remote power side-channels on Intel SGX and TDX operational on Intel Sapphire Rapids. We first construct a synchronization mechanism to align in-band execution with out-of-band measurements by leveraging deliberately disabled MSRs. We then use energy readings through OOB PCS to recover 2048-bit RSA keys from MbedTLS operational within in-band Intel SGX (with generic single-stepping assumption). Finally, we also leak AESNI keys from within in-band Intel TDX (without any single-step assumption). Prior to our work, the literature on side-channels has been focused on attacks leveraging in-band interfaces. Our work establishes the importance of evaluating confidential computing architectures against attack vectors that combine abilities of both in-band and out-of-band interfaces to achieve adversarial objectives (that both in-band and out-of-band interfaces cannot independently achieve).
Nimish Mishra, Kislay Arya, Sarani Bhattacharya, Paritosh Saxena, Debdeep Mukhopadhyay
DAC1
2025 TERRA: Trojan-Resilient Reverse-Firewall for Cryptographic Applications
Chandan Kumar Chaudhary, Nimish Mishra, Suvradip Chakraborty, Satrajit Ghosh, Debdeep Mukhopadhyay
ESORICS (2)2
2025 MIRAGE: Microarchitectural Footprints for Detecting Adversarial Attacks in One-Shot Inference
abstract
Adversarial attacks pose severe threats to the integrity of deep neural networks (DNNs), especially in resource-constrained systems where traditional defenses are computationally expensive. While existing defenses in the black-box setting utilize hardware characteristics of adversarial attacks (like Hardware Performance Counter or HPC measurements), these defenses often involve repeating execution of multiple target model inferences to detect the attacks.In this work, we put forth a differing perspective: while detection strategies involving multiple target model inferences appear to be successful in isolation, they have unacceptable and inhibitory requirements. Precisely, we argue that these works require cleaning the micro-architectural state of hardware like the cache and the branch predictor after each inference. This in turn leads to performance degradation of not only the adversarial attack detector, but also of the overall system at large.In this work, we put forth a novel and lightweight detection strategy, MIRAGE, using HPCs that does not require cleaning the micro-architectural state of caches or branch predictors. We train a convolutional neural network (CNN) on these signals to classify inputs as benign or adversarial in a single shot, making our approach practical for online systems, while allowing full use of hardware optimizations for performance uplifts. Experiments on CIFAR-10 and MNIST datasets reveal that our methodology not only detects adversarial samples effectively with greater than 96% accuracy, but also imposes a minimal timing overhead of 60 ms and maintains high throughput. This makes our solution well-suited for embedded and edge-AI scenarios.
Soumi Chatterjee, Debadrita Talapatra, Nimish Mishra, Aritra Hazra, Debdeep Mukhopadhyay
ICCAD3
2025 IND-CPAbf C: A New Security Notion for Conditional Decryption in Fully Homomorphic Encryption
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Nimish Mishra, Ayantika Chatterjee, Debdeep Mukhopadhyay
PQCrypto (2)3
2025 Systematic Evaluation of Randomized Cache Designs against Cache Occupancy
Anirban Chakraborty 0003, Nimish Mishra, Sayandeep Saha, Sarani Bhattacharya, Debdeep Mukhopadhyay
USENIX Security Symposium2
2024 Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault Attacks
abstract
Existing countermeasures to DVFS based fault attacks are overly restrictive because (1) they prevent benign, non-SGX processes from utilizing DVFS, and (2) rely upon a less practical threat model than that of Intel SGX. Consequently, this work proposes a new countermeasure principle to defend against DVFS based fault attacks on modern Intel systems. First, we establish that the fundamental cause of DVFS fault attacks is the ability to independently control the frequency and voltage of a processor. Using this observation, we construct a partition of frequency-voltage tuples into unsafe-safe states based on whether a tuple causes timing violations according to switching circuit theoretic principles. Our countermeasure completely prevents DVFS faults on three Intel generation CPUs: Sky Lake, Kaby Lake R, and Comet Lake. Further, it can also be deployed both as microcode or as model-specific registers at the hardware level, unlike previous countermeasures. Our countermeasure incurs a slowdown of only 0.28% on overall system performance when benchmarked against SPEC2017.
Nimish Mishra, Rahul Arvind Mool, Anirban Chakraborty 0003, Debdeep Mukhopadhyay
DAC1
2024 Faults in Our Bus: Novel Bus Fault Attack to Break ARM TrustZone
Nimish Mishra, Anirban Chakraborty 0003, Debdeep Mukhopadhyay
NDSS1
2024 Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel Processors
Anirban Chakraborty 0003, Nimish Mishra, Debdeep Mukhopadhyay
USENIX Security Symposium2
2022 Time's a Thief of Memory - Breaking Multi-tenant Isolation in TrustZones Through Timing Based Bidirectional Covert Channels
Nimish Mishra, Anirban Chakraborty 0003, Urbi Chatterjee, Debdeep Mukhopadhyay
CARDIS1
2021 A comprehensive review on collision-resistant hash functions on lattices
Nimish Mishra, SK Hafizul Islam, Sherali Zeadally
J. Inf. Secur. Appl.1