Mohammad Ebrahimabadi

dblp:282/4651 · DBLP profile ↗
← Back
23ranked-venue papers
6as first author
22since 2021 · last 2026
0000-0001-6831-8339ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 10 · 2 first-author · 9 since 2021Computer networks · 7 · 2 first-author · 7 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 5 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 HEED: A Highly Efficient Electromagnetic Fault Detection Scheme
abstract
ElectroMagnetic Fault Injection (EMFI) is a hard-ware attack technique that uses EM perturbations to deliberately induce faults in integrated circuits for attack purposes. In this paper, we propose to use a Digital Sensor (DS) based on a Time-to-Digital Converter (TDC) to detect such EMFI attacks. A TDC uses a delay line to sense variations in a device’s core voltage at the rate of its clock. Thus, it can detect EMFI attacks involving voltage and clock signal perturbations. The sensor output is expressed as a digital index, FN, which captures EMFI-induced delay variations. We evaluated the sensor’s effectiveness on real silicon using an FPGA test vehicle through extensive experiments. The results demonstrate that a single sensor can efficiently detect 100% of faults injected into an AES crypto-accelerator while ensuring wide circuit area coverage, with a highly negligible 1% false alarms rate thanks to the proposed differential fault detection methodology. To ascertain the sensor’s robustness, experiments were conducted under various thermal and noise conditions. Beyond fault detection, the sensor provides insight into the EMFI mechanism. The observed behavior is consistent with a timing constraint violation fault model.
Roukoz Nabhan, Mohammad Ebrahimabadi, Jean-Luc Danger, Jean-Max Dutertre, Sylvain Guilley, Naghmeh Karimi, Raphael Viera 0001, Iyad Zaarour
DATE2
2026 Glitch Propagation through Flip-Flops Endangers Masking Schemes: Why Time Separation Is Required
abstract
Glitches are hardware-level hazards that are capable of compromising secure implementations. Even dominant protections against side-channel attacks must demonstrate immunity in the potential presence of glitches. In this paper, we study two hardware masking schemes rationales, namely Ishai-Shai-Wagner (ISW) and its Enhanced version (E-ISW), as well as Domain-Oriented Masking (DOM). While other glitch-aware masking schemes have been proposed, our focus is specifically on the differences between E-ISW and DOM. Those two styles rely respectively on combinational and on sequential separation of shares. It is known that sequential separation, realized through pipelining stages, does impact the latency of the hardware masking scheme. Additionally, in this paper, we show another drawback: pipelining does not provide full independence between manipulated shares. Indeed, we show that pipelining elements (DFFs in practice) can propagate upstream activity downstream. This results in first-order leakage in real-world systems, especially when parasitic effects are considered. In this respect, we show that DOM is leaking at first-order, and that this leakage increases with both the complexity of the netlist (in terms of number of DOM gadgets) and with the extent to which the operational environment can be worsened by an attacker (e.g., lowering the voltage to increase the leakage). These findings provide valuable insights for advancing secure hardware design.
Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Sofiane Takarabt, Sylvain Guilley, Naghmeh Karimi
DATE2
2026 Signal Rise-Fall Time Based Fingerprinting in CAN Networks
Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi
ICC2
2025 Multi-Sensor Data Fusion for Enhanced Detection of Laser Fault Injection Attacks in Cryptographic Hardware: Practical Results
abstract
Though considered secure the cryptographic hardware can be compromised by fault injection attack, especially laser illumination due to its precision in targeting specific areas and its fine temporal control. To address this threat, this paper presents a low-cost detection scheme that utilizes Time-to-Digital Converters (TDCs) to sense the IR drops induced by laser illumination. To achieve a high detection rate while minimizing false alarms, the proposed approach incorporates multiple sensors, with as few as two sensors demonstrated in the study. The effectiveness of the scheme is validated using a real laser setup to illuminate a targeted AES module implemented on an AMD/Xilinx Artix-7 FPGA.
Mohammad Ebrahimabadi, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi
DATE1
2025 TIGER: TrIaGing KEy Refreshing Frequency via Digital Sensors
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Javad Bahrami, Hossein Pourmehrani, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
SECRYPT3
2025 LiSB: Lightweight Secure Boot and Attestation Scheme for IoT and Edge Devices
abstract
With the increasing popularity of small computing devices and applications of IoT, the need for platform integrity grows both in scale and scope. In particular, the detection of successful attempts to inject a malicious software module or modify an existing one is of utmost importance. This paper promotes LiSB, a novel approach for validating software/firmware integrity and ensuring secure boot-up for resource-constrained embedded devices. LiSB is lightweight, yet very robust. A hardware primitive is used as a Root-of-Trust to support the confidentiality of generated digests and the security of the attestation protocol. Specifically, LiSB employs Physically Unclonable Functions (PUFs) to make the digest device-specific without storing any secrets in the device memory. The performance and robustness of LiSB are validated using a prototype implementation on an FPGA. The results demonstrate that LiSB outperforms recently-published and prominent commercial attestation schemes like TPM, and consumes 25 times less power than SHA-256, which serves as the core component of most existing attestation schemes. The security properties of LiSB are formally analyzed.
Mohamed F. Younis, Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Emily Pozniak, Tamim I. Sookoor, Naghmeh Karimi
IEEE Trans. Inf. Forensics Secur.2
2024 Digital Twin Integrity Protection in Distributed Control Systems
abstract
The notion of Cyber-Physical Systems (CPS) reflects real-time control applications that are realized through distributed coordination among multiple modules. Such coordination is founded on frequent exchange of status and sensor data among the various modules so that actuation decisions are made autonomously. The formation of digital twins has emerged as an effective methodology where data-driven models are employed to enable effective decision making. Hence, the accuracy of these models become very critical for system stability; no wonder data forgery is a major threat for CPS where an attacker strives to inject faulty data to degrade the digital twin of one or multiple modules. Such an attack could be taking the form of impersonating a component, or manipulating/replaying status update packets. This paper proposes an effective scheme for mitigating such a threat by employing hardware-based fingerprinting primitives, namely, Physically Unclonable Functions (PUFs). The proposed PUF-based Integrity protection of digital Twins (PIT) scheme, ensures the authenticity of data sources, and the freshness and integrity of the shared status. PIT is validated using analysis and prototype implementation on an FPGA.
Mohammad Ebrahimabadi, Javad Bahrami, Mohamed F. Younis, Naghmeh Karimi
CCNC1
2024 Securing ISW Masking Scheme Against Glitches
abstract
Ishai-Sahai-Wagner (ISW) masking scheme has been proposed in literature to protect cryptographic circuitries against side-channel analysis attacks. Although provably secure from a theoretical standpoint, its hardware implementation may not be secure as such security proof holds true if the gates are only evaluated after all of their inputs are available, yet such requirement is not met in hardware as the gates are evaluated as soon as any single input of them is changed. This paper provides a repair for ISW to address its security concern and prevent the key recovery. Our method is based on inserting artificial delays and/or “refreshing” on some sensitive paths to ensure that the underlying combinational gates are evaluated in the order expected by the ISW rationale. We verify the security of our proposed structure by leakage detection. Our solution is called E-ISW standing for Enhanced-ISW.
Sofiane Takarabt, Javad Bahrami, Mohammad Ebrahimabadi, Sylvain Guilley, Naghmeh Karimi
DATE3
2024 SUMIT: Secure Unicast and Multicast Communication in Internet of Mobile Things
abstract
An Internet of Mobile Things (IoMT) refers to an internetworked group of pervasive devices that coordinate their motion and task execution through frequent status and data exchange. An IoMT could be serving critical applications such as military reconnaissance, security surveillance, etc., and hence the authenticity, integrity and confidentiality of the transmitted data must be ensured. Yet, achieving the security goals is challenging due to the dynamic nature of the network topology, the constrained computational and communication resources, and the variety of packet traffic patterns among the nodes. This paper proposes an effective solution that leverages lightweight hardware primitives, specifically, Physical Unclonable Functions (PUFs), to support secure communication in the network. The employed PUFs are used to generate peer-to-peer encryption keys to protect the data traffic among nodes and to the command center, while coping with the dynamic change of the network topology. Our solution efficiently supports both unicast and multicast communications. The proposed solution is validated through analysis and prototype implementation on an FPGA.
Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Mohamed F. Younis, Mona Alkanhal, Naghmeh Karimi
GLOBECOM2
2024 Digital Twin Based Topology Fingerprinting for Detecting False Data Injection Attacks in Cyber-Physical Systems
abstract
A Cyber-Physical System (CPS) employs intercon-nected sensing and actuation modules and applies distributed control strategies. With the major advances in communication technology, the CPS design methodology is getting broadly adopted, including in safety and mission-critical applications. The incorporation of digital twins within a CPS facilitates localized decision-making by the individual control modules within the system in a timely manner without risking stability and performance. However, cyberattacks could be detrimental when false data is injected to degrade the accuracy of the underlying digital twins so that a CPS module takes non-optimal or even risky action that causes application failure. This paper proposes a novel approach for detecting such an attack scenario through a combination of a predictive data model and a topology fingerprinting scheme. Specifically, we employ a recurrent neural network (RNN) to predict the next state (data) for the individual modules and use it to reason about the periodic updates provided by these modules. Then, we apply a data-driven fingerprinting scheme that characterizes the inter-module interaction to infer and classify anomalies based on the module-provided data. The validation results using a dataset of a smart power grid application demonstrate the effectiveness of our approach.
Javad Bahrami, Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi
ICC2
2024 PETIT: PUF-enabled trust evaluation framework for IoT networks
Suhee Sanjana Mehjabin, Mohamed F. Younis, Ali Tekeoglu, Mohammad Ebrahimabadi, Tamim I. Sookoor, Naghmeh Karimi
Comput. Networks4
2024 DELFINES: Detecting Laser Fault Injection Attacks via Digital Sensors
abstract
Laser Fault Injection Attacks (LFIA) are a major concern in physical security of electronic circuits as they allow an attacker to inject a fault with a very high spatial accuracy. They are also often considered by information technology security evaluation facilities (ITSEFs) to deliver security certification, as Common Criteria, of embedded systems. Time or spatial redundancy can be foreseen as protection methods but they are costly and do not ensure immunity against multiple laser injections. The detection would be efficient if the detecting sensors meet enough density and sensitivity to cover the functional blocks being protected. Most sensors rely on analog and specific technology. In this article, we propose a method to detect LFIAs via a fully digital sensor based on a time to digital converter (TDC) and show its efficacy in detecting such faults in various conditions related to the current induced by the laser, the characteristics of the power grid network (PGN) of the circuit and the environmental variables (voltage, temperature). The simulation results obtained using a 45nm Nangate technology confirms the high efficiency of the proposed scheme in detecting LFIAs in a large range of such conditions.
Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2023 Special Session: Security Verification & Testing for SR-Latch TRNGs
abstract
Secure chips implement cryptographic algorithms and protocols to ensure self-protection (e.g., firmware authenticity) as well as user data protection (e.g., encrypted data storage). In turn, cryptography needs to defer to incorruptible sources of entropy to implement their functions according to their mandatory usage guidance. Typically, keys, nonces, initialization vectors, tweaks, etc. shall not be guessed by attackers. In practice, True Random Number Generators (TRNGs) are in charge of producing such sensitive elements.Fully aware of the central role of TRNGs in the proper implementation of security in chips, stakeholders have been formalizing the requirements recently. The methods to strengthen such requirements are manifold. In this paper, we discuss and apply three of them by targeting the Set-Reset Latch TRNG which is an alternative to Ring-Oscillator (RO) TRNGs as it provides faster throughputs. The first method concerns the confidence in the TRNG being random enough. It explores how the TRNG properties can be reliably predicted by simulation, compared to real silicon experiments. The second aspect dealt with in this paper is the assessment of the TRNG properties over time, i.e., considering the impact of aging in the TRNG properties. Such knowledge is important as secure chips are expected to be in service for a long period, and it would be detrimental to the service they render if the quality of the entropy they deliver would be declining over time. Eventually, the third aspect of this paper is the timely detection of unforeseen failures or malevolent attacks. The mitigation lies in leveraging "health tests" launched prior to using random numbers.This paper focuses on a particular type of TRNG that is not prone to biasing by attackers: it is the so-called Set-Reset Latch (SR-latch) TRNG and exploits a race condition in an arbitration gate. Such kind of TRNG is of great practical interest as an alternative design compared to the mainstream "Ring Oscillator" TRNG, and it is also very amenable to analyses by various sorts of simulations aiming at properly characterizing its security in various operational environments.
Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
VTS2
2022 Robust and Efficient Data Security Solution for Pervasive Data Sharing in IoT
abstract
Pervasive sensing is shaping up modern societies and opening the door for many unconventional applications. Instead of the contemporary access model where sensor data is disseminated to a single user, multi-access scenarios are becoming more prevalent, which raises the issue of how to authenticate users, how to ensure access authorization, and how to prevent information leakage. To address these issues, this paper presents a novel lightweight protocol that promotes a data-driven methodology. The idea is to employ hardware primitives to support authentication of legit data recipients and to factor in the previously shared data samples in generating encryption keys. Our protocol in essence generates encryption keys that vary per packet and in an implicitly synchronized manner between the data source and each recipient. The generated key is also a function of the hardware primitive and thus effectively prevents data access to unauthorized recipients. We analyze the resilience of our protocol to impersonation and message replay, and hardware primitive modeling attacks. The security properties of our solution is validated using the AVISPA toolset and its performance is compared to the asymmetric cryptography approaches.
Wassila Lalouani, Mohamed F. Younis, Mohammad Ebrahimabadi, Naghmeh Karimi
CCNC3
2022 Leakage Power Analysis in Different S-Box Masking Protection Schemes
abstract
Internet-of- Things (IoT) devices are natural targets for side-channel attacks. Still, side-channel leakage can be com-plex: its modeling can be assisted by statistical tools. Projection of the leakage into an orthonormal basis allows to understand its structure, typically linear (1st-order leakage) or non-linear (sometimes referred to as glitches). In order to ensure cryptosystems protection, several masking methods have been published. Unfortunately, they follow different strategies; thus it is hard to compare them. Namely, ISW is constructive, GLUT is systematic, RSM is a low-entropy version of GLUT, RSM-ROM is a further optimization aiming at balancing the leakage further, and TI aims at avoiding, by design, the leakage arising from the glitches. In practice, no study has compared these styles on an equal basis. Accordingly, in this paper, we present a consistent methodology relying on a Walsh-Hadamard transform in this respect. We consider different masked implementations of substitution boxes of PRESENT algorithm, as this function is the most leaking in symmetric cryptography. We show that ISW is the most secure among the considered masking implementations. For sure, it takes strong advantage of the knowledge of the PRESENT substitution box equation. Tabulated masking schemes appear as providing a lesser amount of security compared to unprotected counterparts. The leakage is assessed over time, i.e., considering device aging which contributes to mitigate the leakage differently according to the masking style.
Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
DATE2
2022 Collusion-resistant PUF-based Distributed Device Authentication Protocol for Internet of Things
abstract
The scale, unattended-operation and ad-hoc nature of an Internet-of-Things (IoT) make the network vulnerable to device impersonation, message replay, and Sybil attacks by either external actors or compromised nodes. This paper opts to tackle such vulnerability and presents a novel and effective solution for mutual authentication of IoT nodes. The proposed solution calls for embedding a Physically Unclonable Function (PUF) on each device, and employs a lightweight protocol for validating the identity of the individual devices based on querying the PUF. To authenticate a “prover” node, a verifier node will send a challenge bit-stream to the prover, where the latter provides the response of its PUF to such a challenge to be matched by what the verifier expects. To prevent the PUF of a prover from being modeled by an eavesdropper or a collusive set of compromised verifiers, the proposed protocol makes the response to a challenge dependent on the verifier. In addition, our protocol combines such an identity-based response generation with a simple Elliptic curve to thwart any attempts by a compromised verifier to reverse engineer the response generation process. The robustness of our PUF-based IoT Device Authentication (PIDA) protocol, is validated using data collected from an FPGA-based implementation.
Wassila Lalouani, Mohamed F. Younis, Mohammad Ebrahimabadi, Naghmeh Karimi
GLOBECOM3
2022 SWeeT: Security Protocol for Wearables Embedded Devices' Data Transmission
abstract
Motivated by the quest for decreased healthcare costs and further fueled by the COVID pandemic, wearable devices have gained major attention in recent years. Yet, their secure usage and patients’ privacy continue to be concerning. To address these issues, the paper presents SWeeT, a novel lightweight protocol for allowing flexible and secure access to the collected data by multiple caregivers while sustaining the patient’s privacy. Particularly, SWeeT deploys Physically Unclonabale Functions (PUFs) to generate encryption keys to safeguard the patients’ data during transmission. The computation overhead is significantly reduced by applying very simple encryption operations while enabling frequent change of the keys to sustain robustness. SWeeT is shown to counter impersonation, Sybil, man-in-the-middle, and forgery attacks. SweeT is validated through experiments using implementation on an Artix7 FPGA and through formal security analysis.
Mohammad Ebrahimabadi, Mohamed F. Younis, Wassila Lalouani, Abdulaziz Alshaeri, Naghmeh Karimi
HealthCom1
2022 On the Practicality of Relying on Simulations in Different Abstraction Levels for Pre-silicon Side-Channel Analysis
abstract
International audience
Javad Bahrami, Mohammad Ebrahimabadi, Sofiane Takarabt, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
SECRYPT2
2022 A PUF-Based Modeling-Attack Resilient Authentication Protocol for IoT Devices
abstract
Physical unclonable functions (PUFs) offer a promising solution for the authentication of Internet of Things (IoT) devices as they provide unique fingerprints for the underlying devices through their challenge–response pairs. However, PUFs have been shown to be vulnerable to modeling attacks. In this article, we propose a novel protocol to thwart such vulnerability by limiting the adversary’s ability to intercept the whole challenge bits exchanged with IoT nodes. We split the challenge bits over multiple messages and engage one or multiple helper nodes in the dissemination process. We further study the implications of various parts of the challenge patterns on the modeling attack and propose extensions of our protocol that exploit bits scrambling and padding to ameliorate the attack resiliency. The experimental results extracted from a 16-bit and a 64-bit arbiter-PUF implemented on FPGA demonstrate the effectiveness of the proposed methods in boosting the robustness of IoT authentication.
Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi
IEEE Internet Things J.1
2022 Countering Modeling Attacks in PUF-based IoT Security Solutions
abstract
Hardware fingerprinting has emerged as a viable option for safeguarding IoT devices from cyberattacks. Such a fingerprint is used to not only authenticate the interconnected devices but also to derive cryptographic keys for ensuring data integrity and confidentiality. A Physically Unclonable Function (PUF) is deemed as an effective fingerprinting mechanism for resource-constrained IoT devices since it is simple to implement and imposes little overhead. A PUF design is realized based on the unintentional variations of microelectronics manufacturing processes. When queried with input bits (challenge), a PUF outputs a response that depends on such variations and this uniquely identifies the device. However, machine learning techniques constitute a threat where intercepted challenge-response pairs (CRPs) could be used to model the PUF and predict its output. This paper proposes an adversarial machine learning based methodology to counter such a threat. An effective label flipping approach is proposed where the attacker's model is poisoned by providing wrong CRPs. We employ an adaptive poisoning strategy that factors in potentially leaked information, i.e., the intercepted CRPs, and introduces randomness in the poisoning pattern to prevent exclusion of these wrong CRPs as outliers. The server and client use a lightweight procedure to coordinate and predict poisoned CRP exchanges. Specifically, we employ the same pseudo random number generator at communicating parties to ensure synchronization and consensus between them, and to vary the poisoning pattern over time. Our approach has been validated using datasets generated via a PUF implementation on an FPGA. The results have confirmed the effectiveness of our approach in defeating prominent PUF modeling attack techniques in the literature.
Wassila Lalouani, Mohamed F. Younis, Mohammad Ebrahimabadi, Naghmeh Karimi
ACM J. Emerg. Technol. Comput. Syst.3
2021 Hardware Assisted Smart Grid Authentication
abstract
A Cyber-Physical System (CPS) refers to the interconnection of control (actuation), computational nodes and sensors, in order to manage physical processes. In recent years, the CPS design methodology has been adopted in several large-scale infrastructures such as smart power grids. Given the application criticality, sustaining the security of these systems is of utmost importance. One of the major security goals is to protect CPS against impersonation, where an adversary intends to manipulate the system state by sending erroneous data that appears to be reported by one of the system nodes, e.g. PMUs of a power grid. This paper proposes a novel hardware-assisted authentication scheme to counter such a threat, by exploiting imperfections that occur in the manufacturing process of integrated circuits. In essence, the proposed scheme associates a fingerprint for each system node so that the authenticity of the data source could be verified. In addition, the paper tackles the threat of message replay where the adversary re-transmits a legitimate message so that the system factors in outdated rather than fresh sensor measurements. This paper thwarts such a replay attack by leveraging the synchronized clocks across the CPS nodes, e.g., based on GPS; the idea is to employ a combination of time-stamp signatures and hardware fingerprints. Our proposed schemes can also detect and prevent data forgery, and Sybil attacks. The viability and performance of the proposed schemes are validated through analysis and prototype implementation.
Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi
ICC1
2021 Reducing Aging Impacts in Digital Sensors via Run-Time Calibration
Md Toufiq Hasan Anik, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
J. Electron. Test.2
2020 On-Chip Voltage and Temperature Digital Sensor for Security, Reliability, and Portability
abstract
The integrated circuits can be exposed to various stresses during run-time due to unexpected environmental conditions or attacks. Ensuring that a circuit is not working out-of-specification via sensing its operating conditions, e.g., temperature and voltage, is highly useful in detecting anomalies. Analog sensors have been used to monitor the operating conditions for a long time, however, weaknesses including lack of portability to thin technology nodes, costly & complex calibration process, and low attack resistance make such sensors inefficient. Digital sensors, via considering the temperature and voltage effects altogether instead of treating each separately, have been demonstrated as a qualified replacement. In this paper, we develop an integrated framework for continuous monitoring of the operating voltage and temperature of each chip. The framework includes an embedded on-chip sensor circuitry along with a Neural Network model that quantifies the temperature and voltage values via processing the data collected by this sensor. The experimental results confirm the high accuracy of the proposed framework in tracking on-chip voltage and temperature variations, i.e., with the average error of 0.014V in a range of 0.65V to 1.4V, and the average error of 3.9°C in a range of -10°C to 150°C, respectively.
Md Toufiq Hasan Anik, Mohammad Ebrahimabadi, Hamed Pirsiavash, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
ICCD2