VLDB 2026 Research / reviewers in the wild / expert
Kshitij Raj
dblp:289/0517
· DBLP profile ↗
8ranked-venue papers
1as first author
8since 2021 · last 2026
0000-0001-9160-5838ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 1 first-author · 8 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SENTRY: Protecting System-on-Chip Designs against Supply-Chain AttacksabstractSystem-on-chip security architecture is a critical, complex, and time-consuming activity, consuming months of effort. Furthermore, the architectural design can include subtle errors that compromise the security of the entire system. In this article, we develop a security engine infrastructure, SEnTry , for systematically creating security architectures for protecting SoC designs against a variety of security subversions. SEnTry provides a plug-and-play, configurable subsystem composed of custom IPs that can be integrated into the platform to derive different security primitives. We develop an instance of SEnTry for supply-chain attacks. We discuss the spectrum of challenges involved in developing a unified architecture for systematic protection against the variety of attacks involved and the SEnTry approach to addressing them. We provide several case studies to demonstrate SEnTry design and perform extensive experiments to evaluate its overhead on multiple ASIC technologies. Our experiments suggest that SEnTry incurs minimal overhead in area and power consumption. Kshitij Raj, Atri Chatterjee, Patanjali SLPSK, Swarup Bhunia, Sandip Ray |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2026 | Right-Sized Security: Configurable Security Engine for Supply-Chain Integrity in Resource-Constrained System-on-Chip DesignsabstractModern system-on-chip (SoC) designs are increasingly vulnerable to supply chain threats such as counterfeiting, overproduction, and reverse engineering, leading to financial losses, intellectual property (IP) theft, and compromised system integrity. Existing security engines, while effective in principle, typically rely on microcontroller-based architectures that incur significant area and power overhead, making them impractical for resource-constrained devices. In this article, we present a minimally configured security engine (MCSE), a lightweight, modular, configurable security engine designed to address the most critical supply-chain threats with minimal resource consumption. We introduce the notion ofminimum security, a baseline set of protection features necessary to secure SoCs under strict area and power constraints, and demonstrate how MCSE can be tailored to meet diverse system requirements. We validate our architecture through implementation on multiple ASIC technology nodes, showing favorable tradeoffs between security capability, area, and power. Our results establish MCSE as a compelling solution for integrating supply chain protection into low-power and area-sensitive SoC designs. Tambiara Tabassum, Emmanuel Elias, Kshitij Raj, Atri Chatterjee, Swarup Bhunia, Sandip Ray |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2024 | System-on-Chip Information Flow Validation Under Asynchronous ResetsabstractModern System-on-Chip (SoC) designs comprise hundreds of individual IP blocks, each with its custom implementation of reset signals in most cases. The asynchronous nature of these resets while crossing different reset domains makes the SoC prone to various vulnerabilities if not implemented and validated thoroughly. A key aspect in validating system functionality is to ensure the functionality under reset is verified. Traditional simulation-based validation techniques often become a bottleneck in complex SoC designs due to the large control path of these designs. We propose SoCCAR, a SoC validation framework that addresses this problem. SoCCAR leverages control flow graphs (CFG) of the design to extract the control flow associated with property violations caused by reset domain crossings due to asynchronous resets. SoCCAR efficiently tracks the chain of events leading to the payload without suffering from state space explosion, a common challenge in complex designs. We test the efficacy of SoCCAR in detecting such vulnerabilities by developing multiple SoC benchmarks, each embedded with custom vulnerability originating from reset implementations across different domains. These vulnerabilities reflect practical design complexity and correspond to security violations encountered in practice as a result of multiple asynchronous resets. SoCCAR successfully detected all violations with minimal computation overhead and runtime, making it a viable approach for detecting such violations in complex SoC designs. Samit Shahnawaz Miftah, Kshitij Raj, Sandip Ray, Kanad Basu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2023 | SeVNoC: Security Validation of System-on-Chip Designs With NoC FabricsabstractModern System-on-Chip (SoC) designs include a variety of Network-on-Chip (NoC) fabrics to implement coordination and communication of integrated hardware intellectual property (IP) blocks. An important class of security vulnerabilities involves a rogue hardware IP interfering with this communication to compromise the integrity of the system. Such interference includes message mutation, misdirection, delivery prevention, or IP masquerading, among others. In this article, we propose a scalable RTL-level SoC validation scheme, SeVNoC, for the systematic detection of security violations in inter-IP communications for SoC designs with NoC fabrics. Given a target security property to be validated, SeVNoC entails extraction of the control-flow graph of the relevant SoC, which is analyzed through a security property-based model comparison, without incurring state-space explosion. Our experiments on full-scale realistic SoC designs with multiple IPs and NoC architecture indicate that SeVNoC detects security violations in NoC communications with near-perfect accuracy, within only a few minutes. Kshitij Raj, Sandip Ray, Kanad Basu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | SoCCom: Automated Synthesis of System-on-Chip ArchitecturesabstractWe present CAD framework and EDA tool,$\mathrm{S{\scriptstyle O}CC{\scriptstyle OM}}$, for automated synthesis of optimized SoC architectures. We delineate a disciplined and streamlined methodology to enable automated IP integration and design optimization.$\mathrm{S{\scriptstyle O}CC{\scriptstyle OM}}$supports generation of a wide variety of optimized SoCs by: 1) automating the entire process of intellectual property (IP) standardization and integration; 2) allowing configurable assembly of complex, scalable systems with application-specific subsystems; and 3) enabling optimization and evaluation of generated designs based on area and power constraints. Applications of$\mathrm{S{\scriptstyle O}CC{\scriptstyle OM}}$include development of heterogeneous, domain-specific SoCs, rapid register-transfer level (RTL) prototyping of wide-varieties of SoC benchmarks, and many others. Atul Prasad Deb Nath, Kshitij Raj, Swarup Bhunia, Sandip Ray |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2021 | SoCCAR: Detecting System-on-Chip Security Violations Under Asynchronous ResetsabstractModern SoC designs include several reset domains that enable asynchronous partial resets while obviating complete system boot. Unfortunately, asynchronous resets can introduce security vulnerabilities that are difficult to detect through traditional validation. In this paper, we address this problem through a new security validation framework, SoCCCAR, that accounts for asynchronous resets. The framework involves (1) efficient extraction of reset-controlled events while avoiding combinatorial explosion, and (2) concolic testing for systematic exploration of the extracted design space. Our experiments demonstrate that SoCCAR can achieve almost perfect detection accuracy and verification time of a few seconds on realistic SoC designs. Kshitij Raj, Atul Prasad Deb Nath, Kanad Basu, Sandip Ray |
DAC | 2 |
| 2021 | CASTLE: Architecting Assured System-on-Chip Firmware IntegrityabstractModern System-on-Chip (SoC) designs include a large number of embedded microcontrollers that execute custom firmware. Firmware provides the flexibility of updating security features, i.e., it enables patching or in-field update, in response to an emerging security threat, bug, or changing requirements. Unfortunately, current firmware update mechanisms are complex, manual, and error-prone. In this paper we present CASTLE, an architectural framework to enable systematic and assured updates to SoC firmware. The main workhorse of CASTLE is a centralized, dedicated IP in the SoC that is responsible for receiving, authenticating, and installing a patch. The architecture works with off-chip firmware validation flows, e.g., cloud-based service for validating a proposed patch, and identifying compatibility constraints on other resident firmware in the SoC. The result is a comprehensive infrastructure that works seamlessly across architectures, vendors, and service providers, while meeting deployment and usability requirements. We demonstrate the application of proposed framework in addressing functional and security flaws of existing firmware patching mechanisms including firmware incompatibility, inadequate authentication, and time-of-check vs. time-of-use (TOCTOU) constraints. Sandip Ray, Atul Prasad Deb Nath, Kshitij Raj, Swarup Bhunia |
DATE | 3 |
| 2021 | The Curious Case of Trusted IC Provisioning in Untrusted Testing FacilitiesabstractAsset provisioning is a crucial step in present-day IC manufacturing process. The nature of on-chip assets can range from crypto keys, IC configurations, and manufacturer firmware to target specific security specifications, policies, and chip debugging information. Given the criticality of the assets, a major part of IC security research is targeted towards the development of their protection mechanisms, especially in post-fabrication deployment phase. However, in this work our curious observation is that a series of novel attack surfaces can stem from asset provisioning at untrusted testing sites and colluding foundries which are not covered by existing threat models and defense schemes. To that end, we study the state-of-the-art protection mechanisms adopted for secure IC provisioning at untrusted testing facilities and highlight their security vulnerabilities. In particular, we show the inadequacy of existing authentication and design obfuscation-based defense mechanisms during asset provisioning through a secure root of trust. Sandip Ray, Atul Prasad Deb Nath, Kshitij Raj, Swarup Bhunia |
ACM Great Lakes Symposium on VLSI | 3 |