VLDB 2026 Research / reviewers in the wild / expert
Anjum Riaz
dblp:321/5778
· DBLP profile ↗
12ranked-venue papers
3as first author
12since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 12 · 3 first-author · 12 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Compatibility Graph Assisted Automatic Hardware Trojan Insertion FrameworkabstractHardware Trojans (HTs) pose substantial security threats to Integrated Circuits (ICs), compromising their integrity, confidentiality, and functionality. Various HT detection methods have been developed to mitigate these risks. However, the limited availability of comprehensive HT benchmarks necessitates designers to create their own for evaluation purposes. Moreover, the existing benchmarks exhibit several deficiencies, including a restricted range of trigger nodes, susceptibility to detection through random patterns, lengthy HT instance creation and validation process, and a limited number of HT instances per circuit. To address these limitations, we propose a Compatibility Graph assisted automatic Hardware Trojan insertion framework for HT benchmark generation. Given a netlist, this framework generates a design incorporating single or multiple HT instances according to user-defined properties. It allows various configurations of HTs, such as a large number of trigger nodes, low activation probability and large number of unique HT instances. The experimental results demonstrate that the generated HT benchmarks exhibit exceptional resistance to state-of-the-art HT detection schemes. Additionally, the proposed framework achieves an average improvement of 37815.7x and 989.4x over the insertion times of the Random and Reinforcement Learning based HT insertion frameworks, respectively. Gaurav Kumar 0001, Ashfaq Hussain Shaik, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
DATE | 3 |
| 2025 | On Securing SSN Architecture using Test Vector EncryptionabstractAs System-on-Chip (SoC) architecture becomes increasingly complex, the need for secure and efficient testing methodologies have grown. Recently, the Streaming Scan Network (SSN) was introduced as a testing infrastructure to address the limitations of conventional scan-based architectures in handling complex SoCs. However, SSN architecture presents significant security risks if access control mechanisms are not implemented. Malicious users could exploit the SSN to extract sensitive information from the SoC, posing a serious threat to system security. To address these vulnerabilities, this paper proposes a secure SSN architecture that employs test vector encryption and test response masking. Further, test authorization key is needed to access the test responses. The proposed solution secures the SSN while keeping the functionality intact and additionally reduces the area overhead compared to existing schemes. Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
ISCAS | 1 |
| 2025 | A New Hardware Trojan Attack on Scan-obfuscated Logic-locked CircuitsabstractLogic locking has emerged as a crucial defense mechanism for securing ICs against threats such as IP theft, counterfeiting, and Hardware Trojans (HTs). However, advanced attacks like Boolean Satisfiability (SAT) attack have exposed vulnerabilities by exploiting scan-unlocked oracle to retrieve secret keys. To mitigate this risk, scan obfuscation techniques were introduced to secure scan access and enhance protection against SAT attack. However, ScanSAT attack has been shown to bypass these defenses, successfully retrieving secret keys even from scan-obfuscated circuits. Recently, a test authentication scheme combined with scan obfuscation has been proposed as a countermeasure against ScanSAT attack.This work presents an attack that employs a stealthy HT to subvert the security provided by the test authentication scheme. Our analysis demonstrates that the inserted Trojan not only facilitates the execution of the ScanSAT attack but also eludes detection by the state-of-the-art Hardware Trojan detection techniques. These results highlight critical vulnerabilities in current IC security measures, emphasizing the need for resilient defenses against increasingly sophisticated attacks. Anjum Riaz, Gaurav Kumar 0001, Yamuna Prasad, Satyadev Ahlawat, Virendra Singh |
ISCAS | 1 |
| 2024 | On Evaluating Test Response Obfuscation and Encryption CountermeasuresabstractThe scan design is a widely accepted technique employed to enhance the testability of VLSI designs. However, it introduces exploitable side channels that allow attackers to illicitly access confidential information within crypto-cores. To address this concern, several countermeasures have been proposed. Among these countermeasures, two specific types include obfuscation and encryption of the test response at the Scan-Out (SO) port, rendering the test response inaccessible for analysis by potential attackers. This paper proposes a scan attack that effectively retrieves the AES encryption key, even in the presence of both obfuscation and encryption countermeasures. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
IOLTS | 2 |
| 2023 | On Enhancing the Security of Streaming Scan Network ArchitectureabstractTest data volume and test time have become a major concern in the testing of complex System on Chips (SoCs). This is due to the fact that the complexity, as well as the number of cores, keeps increasing while the physical size of SoCs remains relatively constant. Consequently, there is limited space available for additional IO pins for scan purposes, which restricts the ability to test multiple cores in parallel. Moreover, testing multiple cores concurrently with different scan chain lengths further increases the test data volume and test time due to the padding. To mitigate the above problems, a new testing architecture called a Streaming Scan Network (SSN) has been recently developed. It is a bus-based architecture that enables the testing of multiple cores with reduced test data volume and test time. However, the SSN-based architecture lacks essential security features, rendering it susceptible to various security threats, including unauthorized user access, as well as data sniffing and alteration attacks. In this paper, a simple, lightweight, inherently secure solution is proposed to counteract the above security threats. The proposed approach involves leveraging IJTAG static registers to incorporate security features into the SSN architecture. The proposed solution keeps the SSN functionality intact and incurs a minimal area overhead as compared to the existing solutions. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
ATS | 2 |
| 2023 | On Evaluating the Security of Dynamic Scan Obfuscation SchemeabstractScan design is the most commonly used technique to ensure high test coverage in contemporary chips. However, attackers may use it as a trapdoor to gain access to the chip internals. Thus, it affects the overall chip security. Several techniques have been proposed to protect sensitive data from hackers. Recently, a countermeasure has been proposed that obfuscates the scan data using a test key. This scheme looks simple and effective against all the existing scan-based attacks. However, a detailed analysis of the scheme reveals that it is vulnerable to scan-based side-channel attacks. In this paper, it is shown that the test key could be retrieved successfully, and hence the security provided by this scheme is rendered ineffective. To address this vulnerability, a countermeasure is also proposed. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
IOLTS | 2 |
| 2023 | On Protecting IJTAG using an Inherently Secure SIBabstractModern VLSI circuits feature various embedded instruments that support non-functional features, e.g., test/debug, diagnosis, post silicon validation, in-field maintenance, etc. The IEEE Std. 1687 (IJTAG) facilitates efficient access to these on-chip instruments using a special scan cell known as Segment Insertion Bit (SIB). Concomitantly, it provides a covert channel for potential intruders to gain unauthorized access to these embedded instruments and thus extract confidential data such as FPGA firmware, secret keys, etc. Thus, it is quite imperative to restrict access to embedded instruments. Various techniques are present in the literature for enhancing the security of IJTAG network. However, securing the test infrastructure at the cost of complex hardware resources is not always a feasible solution.In this paper, a new mechanism to secure the IJTAG network which is based on a new Inherently Secure SIB (ISSIB) is proposed. The proposed technique makes use of an LFSR that is formed using the update cell of the ISSIBs. The proposed scheme is simple to implement, highly scalable and provides high level of security against unauthorized access. In addition to that, the proposed scheme preserves the conventional IJTAG features and has negligible area overhead. Anjum Riaz, Gaurav Kumar 0001, Yamuna Prasad, Satyadev Ahlawat |
VLSI-SoC | 1 |
| 2022 | A New Access Protocol for Elevating the Security of IJTAG NetworkabstractThe modern-day SoCs have various instruments and proprietary data embedded on chip for test, diagnosis, post-silicon debug, in-field health monitoring, authentication, counterfeit detection, etc. The testing infrastructure such as IEEE Std. 1687 (IJTAG) is incorporated into the ICs for flexible access to these on-chip instruments. However, this standard can be illegitimately used by malicious users for instigating side-channel attacks. In order to improve the security of the IJTAG network, a secure access protocol based on Chip ID, access software and Locking SIB (LSIB) has been proposed. Although this protocol elevates the security of the IJTAG network, in recent works, it has been shown that the secure access protocol is vulnerable to machine learning attack and differential analysis attack. In this work, a new secure access protocol is proposed which is built over the existing secure access protocol. The proposed protocol uses multiple templates which are selected randomly for embedding the key bits. It is shown that the proposed protocol can mitigate the efficacy of machine learning attack and differential analysis attack significantly. Moreover, it is simple to implement and incurs a marginal overhead in terms of area. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
ATS | 2 |
| 2022 | Evaluating Security of New Locking SIB-based ArchitecturesabstractThe IEEE Std 1687 (IJT AG) provides enhanced access to the on-chip test instruments, which are included on the chip for test, post-silicon debug, in field maintenance, and diagnosis purposes. Although the on-chip instruments access provides data and features explicitly for test and debug, these features are misused by the malicious user to access sensitive data such as encryption keys, Chip-IDs, etc. Hence, it is desired to limit the access to sensitive on-chip instruments via IJT AG network. One of the various schemes proposed to mitigate the vulnerability of the IJT AG network is to use a secure access protocol, which is based on LSIB, Chip-ID, and licensed access software.In this paper, the detailed security analysis is performed on IJT AG, it is shown that the secure access protocol technique is vulnerable to differential analysis attack. It can be used to break the secure communication between the board and the licensed access software and thus, the sensitive on-chip test instruments can be accessed illegitimately. It is shown that our proposed algorithm can recover the template used for secure communication within a fraction of a second. Yogendra Sao, Anjum Riaz, Satyadev Ahlawat, Subidh Ali |
ETS | 2 |
| 2022 | On Attacking Locking SIB based IJTAG ArchitectureabstractThe IEEE 1687 standard, which is commonly used for efficient access of on-chip instruments, could be exploited by an intruder and thus needs to be secured. One of the techniques to alleviate the vulnerability of 1687 network is to use a secure access protocol that is based on licensed access software, Chip ID and locking SIB. A licensed access software is generally used to gain control of the embedded instruments and use them as per requirement. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
ACM Great Lakes Symposium on VLSI | 2 |
| 2022 | On Attacking IJTAG Architecture based on Locking SIB with Security LFSRabstractIn recent decennium, hardware security has gained a lot of attention due to different types of attacks being launched, such as IP theft, reverse engineering, counterfeiting, etc. The critical testing infrastructure incorporated into ICs is very popular among attackers to mount side-channel attacks. The IEEE standard 1687 (IJTAG) is one such testing infrastructure that is the focus of attackers these days. To secure access to the IJTAG network, various techniques based on Locking SIB (LSIB) have been proposed. One such very effective technique makes use of Security Linear Feedback Shift Register (SLFSR) along with LSIB. The SLFSR obfuscates the scan chain information from the attacker and hence makes the brute-force attack against LSIB ineffective.In this work, it is shown that the SLFSR based Locking SIB is vulnerable to side-channel attacks. A power analysis attack along with known-plaintext attack is used to determine the IJTAG network structure. First, the known-plaintext attack is used to retrieve the SLFSR design information. This information is further used along with power analysis attack to determine the exact length of the scan chain which in turn breaks the whole security scheme. Further, a countermeasure is proposed to prevent the aforementioned hybrid attack. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
IOLTS | 2 |
| 2022 | Power Analysis Attack on Locking SIB based IJTAG AchitectureabstractToday’s integrated circuits contain a large number and variety of embedded instruments that support testing, infield monitoring, post-silicon validation, etc. The IEEE Std. 1687 (IJTAG) provides efficient access to these embedded instruments by dynamically reconfiguring the IJTAG network. At the same time, it opens a backdoor for malicious users to steal sensitive information. Hence, access to embedded instruments through IJTAG must be restricted/secured. Various techniques have been proposed to prevent unauthorized access to the IJTAG network. One such very effective technique that improves the security of IJTAG network is a secure access protocol that uses licensed access software, Locking SIB (LSIB) and Chip ID. Although this technique is simple to implement and is very effective against scan attacks; however, it does not consider the power analysis attack.In this study, it is demonstrated that the security of the secure access protocol technique could be easily breached using a power analysis side-channel attack. The attack leads to unauthorized access to the embedded instruments which in turn could be used for various malicious purposes. Moreover, a countermeasure that mitigates the efficacy of power analysis attack significantly is proposed. It incurs a minimal area overhead and can be easily integrated into the existing secure access protocol. Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat |
VLSI-SoC | 2 |