VLDB 2026 Research / reviewers in the wild / expert
Naghmeh Karimi
dblp:67/471
· DBLP profile ↗
77ranked-venue papers
15as first author
44since 2021 · last 2026
0000-0002-5825-6637ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 62 · 15 first-author · 29 since 2021Software engineering, systems software and programming languages · 11 · 3 first-author · 7 since 2021Computer networks · 7 · 7 since 2021Security and privacy · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HEED: A Highly Efficient Electromagnetic Fault Detection SchemeabstractElectroMagnetic Fault Injection (EMFI) is a hard-ware attack technique that uses EM perturbations to deliberately induce faults in integrated circuits for attack purposes. In this paper, we propose to use a Digital Sensor (DS) based on a Time-to-Digital Converter (TDC) to detect such EMFI attacks. A TDC uses a delay line to sense variations in a device’s core voltage at the rate of its clock. Thus, it can detect EMFI attacks involving voltage and clock signal perturbations. The sensor output is expressed as a digital index, FN, which captures EMFI-induced delay variations. We evaluated the sensor’s effectiveness on real silicon using an FPGA test vehicle through extensive experiments. The results demonstrate that a single sensor can efficiently detect 100% of faults injected into an AES crypto-accelerator while ensuring wide circuit area coverage, with a highly negligible 1% false alarms rate thanks to the proposed differential fault detection methodology. To ascertain the sensor’s robustness, experiments were conducted under various thermal and noise conditions. Beyond fault detection, the sensor provides insight into the EMFI mechanism. The observed behavior is consistent with a timing constraint violation fault model. Roukoz Nabhan, Mohammad Ebrahimabadi, Jean-Luc Danger, Jean-Max Dutertre, Sylvain Guilley, Naghmeh Karimi, Raphael Viera 0001, Iyad Zaarour |
DATE | 6 |
| 2026 | Glitch Propagation through Flip-Flops Endangers Masking Schemes: Why Time Separation Is RequiredabstractGlitches are hardware-level hazards that are capable of compromising secure implementations. Even dominant protections against side-channel attacks must demonstrate immunity in the potential presence of glitches. In this paper, we study two hardware masking schemes rationales, namely Ishai-Shai-Wagner (ISW) and its Enhanced version (E-ISW), as well as Domain-Oriented Masking (DOM). While other glitch-aware masking schemes have been proposed, our focus is specifically on the differences between E-ISW and DOM. Those two styles rely respectively on combinational and on sequential separation of shares. It is known that sequential separation, realized through pipelining stages, does impact the latency of the hardware masking scheme. Additionally, in this paper, we show another drawback: pipelining does not provide full independence between manipulated shares. Indeed, we show that pipelining elements (DFFs in practice) can propagate upstream activity downstream. This results in first-order leakage in real-world systems, especially when parasitic effects are considered. In this respect, we show that DOM is leaking at first-order, and that this leakage increases with both the complexity of the netlist (in terms of number of DOM gadgets) and with the extent to which the operational environment can be worsened by an attacker (e.g., lowering the voltage to increase the leakage). These findings provide valuable insights for advancing secure hardware design. Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Sofiane Takarabt, Sylvain Guilley, Naghmeh Karimi |
DATE | 5 |
| 2026 | Signal Rise-Fall Time Based Fingerprinting in CAN Networks
Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi |
ICC | 4 |
| 2026 | Late Breaking Results - A Systematic Vulnerability Analysis of MRAM-Based Compute-in-Memory against Side-Channel Attacks
Hossein Pourmehrani, Yashas Krishnamohan, Sumukh Prashant Bhanushali, Saurabh Dhiman, Rajendra Bishnoi, Arindam Sanyal, Farshad Firouzi, Naghmeh Karimi |
VTS | 8 |
| 2026 | ROCKET: Runtime Operating-Condition Aware KEy Refreshing Technique for Resisting Side-Channel Analysis Attacks
Hasin Ishraq Reefat, Hossein Pourmehrani, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
VTS | 5 |
| 2026 | Assessment of Security Risks and Defenses in Chiplet Systems
Hasin Ishraq Reefat, Hossein Pourmehrani, Junie Um, Sylvain Guilley, Naghmeh Karimi |
VTS | 5 |
| 2026 | PHANTOM: Power Hammering Attack and Countermeasure on Multi-Tenant ReRAM Compute-in-Memory AcceleratorsabstractThe increasing demand for efficient and low-power deep neural network (DNN) inference has advanced the adoption of ReRAM-based compute-in-memory (CiM) accelerators, which perform computations directly within memory to reduce energy consumption and enhance throughput. However, such architectures are vulnerable to security threats, especially in a multi-tenant environment where multiple users share the same physical resources. This paper introduces a new attack model for multi-tenant ReRAM-based CiM, power hammering, that exploits the temperature sensitivity of ReRAM cells, inducing local temperature increases that lead to conductance drift and ultimately result in erroneous inference outcomes. This serves as a denial-of-service (DoS) attack, where malicious co-tenants degrade inferencing accuracy and system reliability for legitimate users in a shared environment, ultimately undermining trust and causing potential losses to the service provider. Additionally, we propose a novel strategy to counter this security vulnerability. In this technique, we focus on selectively protecting important weights with error compensation hardware. These important weights are treated as faults, and their computation is offloaded to compensation hardware. Simulation results confirm the effectiveness of the proposed method in ensuring accurate classification results even under adversarial conditions, thereby enabling secure multi-tenant inference on ReRAM-based CiM accelerators. Ashish Reddy Bommana, Rajendra Bishnoi, Naghmeh Karimi, Farshad Firouzi, Krishnendu Chakrabarty |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Multi-Sensor Data Fusion for Enhanced Detection of Laser Fault Injection Attacks in Cryptographic Hardware: Practical ResultsabstractThough considered secure the cryptographic hardware can be compromised by fault injection attack, especially laser illumination due to its precision in targeting specific areas and its fine temporal control. To address this threat, this paper presents a low-cost detection scheme that utilizes Time-to-Digital Converters (TDCs) to sense the IR drops induced by laser illumination. To achieve a high detection rate while minimizing false alarms, the proposed approach incorporates multiple sensors, with as few as two sensors demonstrated in the study. The effectiveness of the scheme is validated using a real laser setup to illuminate a targeted AES module implemented on an AMD/Xilinx Artix-7 FPGA. Mohammad Ebrahimabadi, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi |
DATE | 6 |
| 2025 | TARN: Trust Aware Routing to Enhance Security in 3D Network-on-ChipsabstractThe growing complexity and performance demands of modern computing systems resulted in a shift from traditional System-on-Chip (SoC) designs to Network-on-Chip (NoC) architectures, and further to three-dimensional Network-on-Chip (3D NoC) solutions. Despite their performance and power efficiency, the increased complexity and inter-layer communication of 3D NoCs can create opportunities for adversaries who opt to prevent reliable communications between embedded nodes by inserting hardware Trojans in such nodes. The hardware Trojans, introduced through untrusted third-party Intellectual Property (IP) blocks, can severely compromise 3D NoCs by tampering with data integrity, misrouting packets, or dropping them; thus triggering denial-of-service attacks. Detecting such behaviors is particularly difficult due to their infrequent activation. Thereby it is of utmost importance to take the trustworthiness of the embedded nodes into account when routing the packets in the NoCs. Accordingly, this paper proposes a trust-aware routing scheme, so-called TARN, to significantly reduce the rate of packet loss that can occur due to malicious behaviors of one or more nodes (or interconnects). Our distributed trust-aware path selection protocol bypasses malicious IPs and securely routes packets to their destination. Furthermore, we introduce a low-overhead mechanism for delegating trust scores to neighboring routers, thereby enhancing network efficiency. Experimental results demonstrate significant improvements in packet loss while imposing low performance and energy overhead. Hasin Ishraq Reefat, Alec Aversa, Ioannis Savidis, Naghmeh Karimi |
DATE | 4 |
| 2025 | BISSEL: Built-In Self Security via Embedded Sensors for Reproducible Side-Channel Leakage Assessment
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ETS | 5 |
| 2025 | Avoiding Malicious Nodes of a 3-D NoC with Security-Aware Priority-Based Routing
Alec Aversa, Hasin Ishraq Reefat, Naghmeh Karimi, Ioannis Savidis |
ACM Great Lakes Symposium on VLSI | 3 |
| 2025 | FAMOUS: Fault Attack Mitigation via Exploiting Invariances in Deep Neural NetworksabstractImplementing Deep Neural Networks (DNNs) in hardware is essential due to rising Power-Performance-Area (PPA) demands and the limitations of GPUs in meeting them. However, such accelerators are vulnerable to Fault Injection Attacks (FIAs), such as those induced by laser illumination or Rowhammer. FAMOUS protects against FIAs by exploiting invariances in DNNs—particularly permutation invariance—by dynamically swapping convolutional channels and linear layer connections during runtime. This misleads attackers aiming to corrupt critical weights that significantly impact model output. We evaluate FAMOUS on transformer models (ViT-tiny and ViT-small) across multiple datasets. Even with 100 faults injected into essential weights, accuracy drops are minimal (≈4.7 and 0.02 points on ImageNet-1k), compared to severe drops (59 and 70 points) without protection. CNNs also benefit from FAMOUS, though to a lesser extent. Javad Bahrami, Parsa Nooralinejad, Hamed Pirsiavash, Naghmeh Karimi |
ITC | 4 |
| 2025 | TIGER: TrIaGing KEy Refreshing Frequency via Digital Sensors
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Javad Bahrami, Hossein Pourmehrani, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
SECRYPT | 8 |
| 2025 | CBM-TI: Code-Based Masking against Glitches by Hybridization with Threshold ImplementationabstractCode-Based Masking (CBM) has been introduced to enhance high-order Boolean masking by increasing its resistance order via further decorrelating the coordinates of each symbol involved in the computation. Additionally, CBM enables cost amortization and fault detection. Notably, as demonstrated at CHES 2024, CBM facilitates the computation of provably masked operations under the Strong Non-Interference (SNI) security assumption with quasi-linear complexity. On the other hand, Threshold Implementation (TI) serves as an extension of Boolean masking, armoring it against combinational hazards. In this article, we show that merits of CBM and TI can be combined, paving the way to more secure hardware (high-order) masked implementations. We demonstrate CBM-TI, which is proven secure as well under SNI assumption and security when glitches worsen the leakage model.The security of CBM-TI is studied in a n-share setting, where n = 3 (minimal random splitting order required for TI). We analyzed CBM-TI in simulation and in real hardware (FPGA) to validate its security property. Leveraging high-order T-test leakage detection tool, we show that CBM-TI is endowed with higher-order security. Namely, TI leaks at order d = 3, whereas CBM-TI does not. We study several CBM-TI variants and show that the smallest leaking order of CBM-TI can be tuned to be as high as 7. This represents a significant progress over TI as each marginally improved order translates into exponentially more traces to attack the implementation. Hasin Ishraq Reefat, Hossein Pourmehrani, Wei Cheng 0003, Claude Carlet, Abderrahman Daif, Cédric Tavernier, Sylvain Guilley, Naghmeh Karimi |
VTS | 8 |
| 2025 | LiSB: Lightweight Secure Boot and Attestation Scheme for IoT and Edge DevicesabstractWith the increasing popularity of small computing devices and applications of IoT, the need for platform integrity grows both in scale and scope. In particular, the detection of successful attempts to inject a malicious software module or modify an existing one is of utmost importance. This paper promotes LiSB, a novel approach for validating software/firmware integrity and ensuring secure boot-up for resource-constrained embedded devices. LiSB is lightweight, yet very robust. A hardware primitive is used as a Root-of-Trust to support the confidentiality of generated digests and the security of the attestation protocol. Specifically, LiSB employs Physically Unclonable Functions (PUFs) to make the digest device-specific without storing any secrets in the device memory. The performance and robustness of LiSB are validated using a prototype implementation on an FPGA. The results demonstrate that LiSB outperforms recently-published and prominent commercial attestation schemes like TPM, and consumes 25 times less power than SHA-256, which serves as the core component of most existing attestation schemes. The security properties of LiSB are formally analyzed. Mohamed F. Younis, Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Emily Pozniak, Tamim I. Sookoor, Naghmeh Karimi |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Digital Twin Integrity Protection in Distributed Control SystemsabstractThe notion of Cyber-Physical Systems (CPS) reflects real-time control applications that are realized through distributed coordination among multiple modules. Such coordination is founded on frequent exchange of status and sensor data among the various modules so that actuation decisions are made autonomously. The formation of digital twins has emerged as an effective methodology where data-driven models are employed to enable effective decision making. Hence, the accuracy of these models become very critical for system stability; no wonder data forgery is a major threat for CPS where an attacker strives to inject faulty data to degrade the digital twin of one or multiple modules. Such an attack could be taking the form of impersonating a component, or manipulating/replaying status update packets. This paper proposes an effective scheme for mitigating such a threat by employing hardware-based fingerprinting primitives, namely, Physically Unclonable Functions (PUFs). The proposed PUF-based Integrity protection of digital Twins (PIT) scheme, ensures the authenticity of data sources, and the freshness and integrity of the shared status. PIT is validated using analysis and prototype implementation on an FPGA. Mohammad Ebrahimabadi, Javad Bahrami, Mohamed F. Younis, Naghmeh Karimi |
CCNC | 4 |
| 2024 | Securing ISW Masking Scheme Against GlitchesabstractIshai-Sahai-Wagner (ISW) masking scheme has been proposed in literature to protect cryptographic circuitries against side-channel analysis attacks. Although provably secure from a theoretical standpoint, its hardware implementation may not be secure as such security proof holds true if the gates are only evaluated after all of their inputs are available, yet such requirement is not met in hardware as the gates are evaluated as soon as any single input of them is changed. This paper provides a repair for ISW to address its security concern and prevent the key recovery. Our method is based on inserting artificial delays and/or “refreshing” on some sensitive paths to ensure that the underlying combinational gates are evaluated in the order expected by the ISW rationale. We verify the security of our proposed structure by leakage detection. Our solution is called E-ISW standing for Enhanced-ISW. Sofiane Takarabt, Javad Bahrami, Mohammad Ebrahimabadi, Sylvain Guilley, Naghmeh Karimi |
DATE | 5 |
| 2024 | SUMIT: Secure Unicast and Multicast Communication in Internet of Mobile ThingsabstractAn Internet of Mobile Things (IoMT) refers to an internetworked group of pervasive devices that coordinate their motion and task execution through frequent status and data exchange. An IoMT could be serving critical applications such as military reconnaissance, security surveillance, etc., and hence the authenticity, integrity and confidentiality of the transmitted data must be ensured. Yet, achieving the security goals is challenging due to the dynamic nature of the network topology, the constrained computational and communication resources, and the variety of packet traffic patterns among the nodes. This paper proposes an effective solution that leverages lightweight hardware primitives, specifically, Physical Unclonable Functions (PUFs), to support secure communication in the network. The employed PUFs are used to generate peer-to-peer encryption keys to protect the data traffic among nodes and to the command center, while coping with the dynamic change of the network topology. Our solution efficiently supports both unicast and multicast communications. The proposed solution is validated through analysis and prototype implementation on an FPGA. Hasin Ishraq Reefat, Mohammad Ebrahimabadi, Mohamed F. Younis, Mona Alkanhal, Naghmeh Karimi |
GLOBECOM | 5 |
| 2024 | Digital Twin Based Topology Fingerprinting for Detecting False Data Injection Attacks in Cyber-Physical SystemsabstractA Cyber-Physical System (CPS) employs intercon-nected sensing and actuation modules and applies distributed control strategies. With the major advances in communication technology, the CPS design methodology is getting broadly adopted, including in safety and mission-critical applications. The incorporation of digital twins within a CPS facilitates localized decision-making by the individual control modules within the system in a timely manner without risking stability and performance. However, cyberattacks could be detrimental when false data is injected to degrade the accuracy of the underlying digital twins so that a CPS module takes non-optimal or even risky action that causes application failure. This paper proposes a novel approach for detecting such an attack scenario through a combination of a predictive data model and a topology fingerprinting scheme. Specifically, we employ a recurrent neural network (RNN) to predict the next state (data) for the individual modules and use it to reason about the periodic updates provided by these modules. Then, we apply a data-driven fingerprinting scheme that characterizes the inter-module interaction to infer and classify anomalies based on the module-provided data. The validation results using a dataset of a smart power grid application demonstrate the effectiveness of our approach. Javad Bahrami, Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi |
ICC | 4 |
| 2024 | FAT-RABBIT: Fault-Aware Training towards Robustness AgainstBit-flip Based Attacks in Deep Neural NetworksabstractMachine learning and in particular deep learning is used in a broad range of crucial applications. Implementing such models in custom hardware can be highly beneficial thanks to their low power and computation latency compared to GPUs. However, an error in their output can lead to disastrous outcomes. An adversary may force misclassification in the model’s outcome by inducing a number of bit-flips in the targeted locations; thus declining the accuracy. To fill the gap, this paper presents FAT-RABBIT, a cost-effective mechanism designed to mitigate such threats by training the model such that there would be few weights that can be highly impactful in the outcome; thus reducing the sensitivity of the model to the fault injection attacks. Moreover, to increase robustness against bit-wise large perturbations, we propose an optimization scheme so-called M-SAM. We then augment FAT-RABBIT with the M-SAM optimizer to further bolster model accuracy against bit-flipping fault attacks. Notably, these approaches incur no additional hardware overhead. Our experimental results demonstrate the robustness of FAT-RABBIT and its augmented version, called Augmented FAT-RABBIT, against such attacks. Hossein Pourmehrani, Javad Bahrami, Parsa Nooralinejad, Hamed Pirsiavash, Naghmeh Karimi |
ITC | 5 |
| 2024 | PETIT: PUF-enabled trust evaluation framework for IoT networks
Suhee Sanjana Mehjabin, Mohamed F. Younis, Ali Tekeoglu, Mohammad Ebrahimabadi, Tamim I. Sookoor, Naghmeh Karimi |
Comput. Networks | 6 |
| 2024 | Multi-modal Pre-silicon Evaluation of Hardware Masking StylesabstractAbstract Protecting sensitive logic functions in ASICs requires side-channel countermeasures. Many gate-level masking styles have been published, each with pros and cons. Some styles such as RSM, GLUT, and ISW are compact but can feature 1st-order leakage. Some other styles, such as TI, DOM, and HPC are secure at the 1st-order but incur significant overheads in terms of performance. Another requirement is that security shall be ensured even when the device is aged. Pre-silicon security evaluation is now a normatively approved method to characterize the expected resiliency against attacks ahead of time. However, in this regard, there is still a fragmentation in terms of leakage models, Points of Interest (PoI) selection, attack order, and distinguishers. Accordingly, in this paper we focus on such factors as they affect the success of side-channel analysis attacks and assess the resiliency of the state-of-the-art masking styles in various corners. Moreover, we investigate the impact of device aging as another factor and analyze its influence on the success of side-channel attacks targeting the state-of-the-art masking schemes. This pragmatic evaluation enables risk estimation in a complex PPA (Power, Performance, and Area) and security plane while also considering aging impacts into account. For instance, we explore the trade-off between low-cost secure styles attackable at 1st-order vs high-cost protection attackable only at 2nd-order. Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Wei Cheng 0003, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
J. Electron. Test. | 6 |
| 2024 | DELFINES: Detecting Laser Fault Injection Attacks via Digital SensorsabstractLaser Fault Injection Attacks (LFIA) are a major concern in physical security of electronic circuits as they allow an attacker to inject a fault with a very high spatial accuracy. They are also often considered by information technology security evaluation facilities (ITSEFs) to deliver security certification, as Common Criteria, of embedded systems. Time or spatial redundancy can be foreseen as protection methods but they are costly and do not ensure immunity against multiple laser injections. The detection would be efficient if the detecting sensors meet enough density and sensitivity to cover the functional blocks being protected. Most sensors rely on analog and specific technology. In this article, we propose a method to detect LFIAs via a fully digital sensor based on a time to digital converter (TDC) and show its efficacy in detecting such faults in various conditions related to the current induced by the laser, the characteristics of the power grid network (PGN) of the circuit and the environmental variables (voltage, temperature). The simulation results obtained using a 45nm Nangate technology confirms the high efficiency of the proposed scheme in detecting LFIAs in a large range of such conditions. Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Raphael Viera 0001, Sylvain Guilley, Jean-Luc Danger, Jean-Max Dutertre, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2024 | On the Resiliency of Protected Masked S-Boxes Against Template Attack in the Presence of Temperature and Aging MisalignmentsabstractProfiling side-channel analysis (SCA) attacks have received a lot of attention in the recent years. To perpetrate these attacks, the adversary creates a profile of a sensitive device at her disposal, and uses it to model a target device with a similar implementation to extract its key. Template attacks are recognized to be the most powerful profiling attacks when the measurement noise is Gaussian. To tackle SCA attacks, different countermeasures have been proposed in the literature, among which masking schemes have received the utmost attention. By adding randomness to the circuit, masking schemes prevent the adversary from relating the power consumption to the evaluated data, thus making the attack more difficult. In this article, we study the protection provided by several masking schemes against template attacks. More precisely, we investigate how the success of the template attack is changed when there is a misalignment between the target and profiling devices in terms of temperature and process variations. As another innovative analysis angle, we extensively study the impact of device aging on the template attack and demonstrate quantitatively how aging misalignments in side-channel traces, between the profiling and the target devices, do hinder the attack. The main objective of this study is to get accurate and numerous results allowing the designer to compare different implementations of masking and accordingly choose one which corresponds to the best compromise among complexity, security, and sensitivity to temperature and aging. We target the S-Box module of the unprotected PRESENT cipher along with its five masking variants including global lookup table (GLUT), rotating S-Box masking (referred to as RSM-LOG hereafter), RSM with read-only memory (RSM-ROM), Ishai-Sahai–Wagner masking (ISW), and threshold implementation (TI). The unprotected circuit gets impacted by such aging misalignments with$\approx 12.5$% increase in the number of traces needed to reach 80% success rate (SR) in the course of 20 weeks of aging at 105 °C. Such increase is 23.3%, 37.19%, and 38.24% for ISW, GLUT, and RSM-LOG, respectively. For RSM-ROM such increase is 193.37% for ten weeks of aging. Interestingly, TI is not much affected by aging in this regard. Md Toufiq Hasan Anik, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2023 | Aging-Induced Failure Prognosis via Digital SensorsabstractAggressive scaling continues to push technology into smaller feature sizes and results in more complex systems in a single chip. With such scaling, various robustness concerns have come into account among which the change of circuits' properties during their lifetime, so-called device aging, has received a lot of attention. Due to aging, the electrical behavior of transistors deviates from its original intended one resulting in degrading the chip's performance, and ultimately the chip fails to provide correct outputs. Thereby, prognosis of circuit performance degradation during the runtime, before the chip actually fails is highly crucial in increasing the reliability of chips. Accordingly in this paper, we develop a machine-learning based framework that, leveraging the outcome of embedded time-to-digital-convertors (so-called "digital sensors''), predicts aging-induced degradation. This information can be used to prevent chip failures via deploying Dynamic Voltage and Frequency Scaling (DVFS). Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ACM Great Lakes Symposium on VLSI | 5 |
| 2023 | International Mutual Recognition: A Description of Trust Services in US, UK, EU and JP and the Testbed "Hakoniwa"abstractWith the proliferation of digital transactions, trust is becoming increasingly important, as exemplified by the World Economic Forum’s Data Free Flow with Trust. Digital signatures are utilized to establish trust to prevent spoofing and unauthorized modification of transmitted digital data. However, the extent of trust is limited by jurisdictions, trusted lists and bridge certificate authorities, and does not have international coverage. For this reason, mutual recognition is needed, i.e. trust relationships established across countries. Establishing mutual recognition is complex and time-demanding due to the legislations, systems, and technologies involved. In parallel, electronic signatures consist of complex systems and structures and, thus, focusing on the technical requirements and solutions can enhance mutual recognition processes. The purpose of our approach is to develop a testbed that can verify technical aspects of mutual recognition. This paper describes the concept of the testbed “Hakoniwa” which includes analyzing the requirements, simulating and testing mutual recognition trust services across US, UK, EU and JP. Satoshi Kai, Takao Kondo, Naghmeh Karimi, Konstantinos Mersinas, Marc Sel, Roberto Yus, Satoru Tezuka |
SECRYPT | 3 |
| 2023 | Special Session: Security Verification & Testing for SR-Latch TRNGsabstractSecure chips implement cryptographic algorithms and protocols to ensure self-protection (e.g., firmware authenticity) as well as user data protection (e.g., encrypted data storage). In turn, cryptography needs to defer to incorruptible sources of entropy to implement their functions according to their mandatory usage guidance. Typically, keys, nonces, initialization vectors, tweaks, etc. shall not be guessed by attackers. In practice, True Random Number Generators (TRNGs) are in charge of producing such sensitive elements.Fully aware of the central role of TRNGs in the proper implementation of security in chips, stakeholders have been formalizing the requirements recently. The methods to strengthen such requirements are manifold. In this paper, we discuss and apply three of them by targeting the Set-Reset Latch TRNG which is an alternative to Ring-Oscillator (RO) TRNGs as it provides faster throughputs. The first method concerns the confidence in the TRNG being random enough. It explores how the TRNG properties can be reliably predicted by simulation, compared to real silicon experiments. The second aspect dealt with in this paper is the assessment of the TRNG properties over time, i.e., considering the impact of aging in the TRNG properties. Such knowledge is important as secure chips are expected to be in service for a long period, and it would be detrimental to the service they render if the quality of the entropy they deliver would be declining over time. Eventually, the third aspect of this paper is the timely detection of unforeseen failures or malevolent attacks. The mitigation lies in leveraging "health tests" launched prior to using random numbers.This paper focuses on a particular type of TRNG that is not prone to biasing by attackers: it is the so-called Set-Reset Latch (SR-latch) TRNG and exploits a race condition in an arbitration gate. Such kind of TRNG is of great practical interest as an alternative design compared to the mainstream "Ring Oscillator" TRNG, and it is also very amenable to analyses by various sorts of simulations aiming at properly characterizing its security in various operational environments. Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
VTS | 5 |
| 2022 | Robust and Efficient Data Security Solution for Pervasive Data Sharing in IoTabstractPervasive sensing is shaping up modern societies and opening the door for many unconventional applications. Instead of the contemporary access model where sensor data is disseminated to a single user, multi-access scenarios are becoming more prevalent, which raises the issue of how to authenticate users, how to ensure access authorization, and how to prevent information leakage. To address these issues, this paper presents a novel lightweight protocol that promotes a data-driven methodology. The idea is to employ hardware primitives to support authentication of legit data recipients and to factor in the previously shared data samples in generating encryption keys. Our protocol in essence generates encryption keys that vary per packet and in an implicitly synchronized manner between the data source and each recipient. The generated key is also a function of the hardware primitive and thus effectively prevents data access to unauthorized recipients. We analyze the resilience of our protocol to impersonation and message replay, and hardware primitive modeling attacks. The security properties of our solution is validated using the AVISPA toolset and its performance is compared to the asymmetric cryptography approaches. Wassila Lalouani, Mohamed F. Younis, Mohammad Ebrahimabadi, Naghmeh Karimi |
CCNC | 4 |
| 2022 | Leakage Power Analysis in Different S-Box Masking Protection SchemesabstractInternet-of- Things (IoT) devices are natural targets for side-channel attacks. Still, side-channel leakage can be com-plex: its modeling can be assisted by statistical tools. Projection of the leakage into an orthonormal basis allows to understand its structure, typically linear (1st-order leakage) or non-linear (sometimes referred to as glitches). In order to ensure cryptosystems protection, several masking methods have been published. Unfortunately, they follow different strategies; thus it is hard to compare them. Namely, ISW is constructive, GLUT is systematic, RSM is a low-entropy version of GLUT, RSM-ROM is a further optimization aiming at balancing the leakage further, and TI aims at avoiding, by design, the leakage arising from the glitches. In practice, no study has compared these styles on an equal basis. Accordingly, in this paper, we present a consistent methodology relying on a Walsh-Hadamard transform in this respect. We consider different masked implementations of substitution boxes of PRESENT algorithm, as this function is the most leaking in symmetric cryptography. We show that ISW is the most secure among the considered masking implementations. For sure, it takes strong advantage of the knowledge of the PRESENT substitution box equation. Tabulated masking schemes appear as providing a lesser amount of security compared to unprotected counterparts. The leakage is assessed over time, i.e., considering device aging which contributes to mitigate the leakage differently according to the masking style. Javad Bahrami, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
DATE | 5 |
| 2022 | Collusion-resistant PUF-based Distributed Device Authentication Protocol for Internet of ThingsabstractThe scale, unattended-operation and ad-hoc nature of an Internet-of-Things (IoT) make the network vulnerable to device impersonation, message replay, and Sybil attacks by either external actors or compromised nodes. This paper opts to tackle such vulnerability and presents a novel and effective solution for mutual authentication of IoT nodes. The proposed solution calls for embedding a Physically Unclonable Function (PUF) on each device, and employs a lightweight protocol for validating the identity of the individual devices based on querying the PUF. To authenticate a “prover” node, a verifier node will send a challenge bit-stream to the prover, where the latter provides the response of its PUF to such a challenge to be matched by what the verifier expects. To prevent the PUF of a prover from being modeled by an eavesdropper or a collusive set of compromised verifiers, the proposed protocol makes the response to a challenge dependent on the verifier. In addition, our protocol combines such an identity-based response generation with a simple Elliptic curve to thwart any attempts by a compromised verifier to reverse engineer the response generation process. The robustness of our PUF-based IoT Device Authentication (PIDA) protocol, is validated using data collected from an FPGA-based implementation. Wassila Lalouani, Mohamed F. Younis, Mohammad Ebrahimabadi, Naghmeh Karimi |
GLOBECOM | 4 |
| 2022 | SWeeT: Security Protocol for Wearables Embedded Devices' Data TransmissionabstractMotivated by the quest for decreased healthcare costs and further fueled by the COVID pandemic, wearable devices have gained major attention in recent years. Yet, their secure usage and patients’ privacy continue to be concerning. To address these issues, the paper presents SWeeT, a novel lightweight protocol for allowing flexible and secure access to the collected data by multiple caregivers while sustaining the patient’s privacy. Particularly, SWeeT deploys Physically Unclonabale Functions (PUFs) to generate encryption keys to safeguard the patients’ data during transmission. The computation overhead is significantly reduced by applying very simple encryption operations while enabling frequent change of the keys to sustain robustness. SWeeT is shown to counter impersonation, Sybil, man-in-the-middle, and forgery attacks. SweeT is validated through experiments using implementation on an Artix7 FPGA and through formal security analysis. Mohammad Ebrahimabadi, Mohamed F. Younis, Wassila Lalouani, Abdulaziz Alshaeri, Naghmeh Karimi |
HealthCom | 5 |
| 2022 | On the Practicality of Relying on Simulations in Different Abstraction Levels for Pre-silicon Side-Channel AnalysisabstractInternational audience Javad Bahrami, Mohammad Ebrahimabadi, Sofiane Takarabt, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
SECRYPT | 6 |
| 2022 | Special Session: On the Reliability of Conventional and Quantum Neural Network HardwareabstractNeural Networks (NNs) are being extensively used in critical applications such as aerospace, healthcare, autonomous driving, and military, to name a few. Limited precision of the underlying hardware platforms, permanent and transient faults injected unintentionally as well as maliciously, and voltage/temperature fluctuations can potentially result in malfunctions in NNs with consequences ranging from substantial reduction in the network accuracy to jeopardizing the correct prediction of the network in worst cases. To alleviate such reliability concerns, this paper discusses the state-of-the-art reliability enhancement schemes that can be tailored for deep learning accelerators. We will discuss the errors associated with the hardware implementation of Deep-Learning (DL) algorithms along with their corresponding countermeasures. An in-field self-test methodology with a high test coverage is introduced, and an accurate high-level framework, so-called FIdelity, is proposed that enables the designers to evaluate DL accelerators in presence of such errors. Then, a state-of-the-art robustness-preserving training algorithm based on the Hessian Regularization is introduced. This algorithm alleviates the perturbations during inference time with negligible degradation in the accuracy of the network. Finally, Quantum Neural Networks (QNNs) and the methods to make them resilient against a variety of vulnerabilities such as fault injection, spatial and temporal variations in Qubits, and noise in QNNs are discussed. Mehdi Sadi, Yi He 0010, Yanjing Li, Mahabubul Alam, Satwik Kundu, Swaroop Ghosh, Javad Bahrami, Naghmeh Karimi |
VTS | 8 |
| 2022 | Cross-PUF Attacks: Targeting FPGA Implementation of Arbiter-PUFs
Trevor Kroeger, Wei Cheng 0003, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
J. Electron. Test. | 5 |
| 2022 | A PUF-Based Modeling-Attack Resilient Authentication Protocol for IoT DevicesabstractPhysical unclonable functions (PUFs) offer a promising solution for the authentication of Internet of Things (IoT) devices as they provide unique fingerprints for the underlying devices through their challenge–response pairs. However, PUFs have been shown to be vulnerable to modeling attacks. In this article, we propose a novel protocol to thwart such vulnerability by limiting the adversary’s ability to intercept the whole challenge bits exchanged with IoT nodes. We split the challenge bits over multiple messages and engage one or multiple helper nodes in the dissemination process. We further study the implications of various parts of the challenge patterns on the modeling attack and propose extensions of our protocol that exploit bits scrambling and padding to ameliorate the attack resiliency. The experimental results extracted from a 16-bit and a 64-bit arbiter-PUF implemented on FPGA demonstrate the effectiveness of the proposed methods in boosting the robustness of IoT authentication. Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi |
IEEE Internet Things J. | 3 |
| 2022 | Countering Modeling Attacks in PUF-based IoT Security SolutionsabstractHardware fingerprinting has emerged as a viable option for safeguarding IoT devices from cyberattacks. Such a fingerprint is used to not only authenticate the interconnected devices but also to derive cryptographic keys for ensuring data integrity and confidentiality. A Physically Unclonable Function (PUF) is deemed as an effective fingerprinting mechanism for resource-constrained IoT devices since it is simple to implement and imposes little overhead. A PUF design is realized based on the unintentional variations of microelectronics manufacturing processes. When queried with input bits (challenge), a PUF outputs a response that depends on such variations and this uniquely identifies the device. However, machine learning techniques constitute a threat where intercepted challenge-response pairs (CRPs) could be used to model the PUF and predict its output. This paper proposes an adversarial machine learning based methodology to counter such a threat. An effective label flipping approach is proposed where the attacker's model is poisoned by providing wrong CRPs. We employ an adaptive poisoning strategy that factors in potentially leaked information, i.e., the intercepted CRPs, and introduces randomness in the poisoning pattern to prevent exclusion of these wrong CRPs as outliers. The server and client use a lightweight procedure to coordinate and predict poisoned CRP exchanges. Specifically, we employ the same pseudo random number generator at communicating parties to ensure synchronization and consensus between them, and to vary the poisoning pattern over time. Our approach has been validated using datasets generated via a PUF implementation on an FPGA. The results have confirmed the effectiveness of our approach in defeating prominent PUF modeling attack techniques in the literature. Wassila Lalouani, Mohamed F. Younis, Mohammad Ebrahimabadi, Naghmeh Karimi |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2022 | Aging Effects on Template Attacks Launched on Dual-Rail Protected ChipsabstractProfiling side-channel attacks in which an adversary creates a “profile” of a sensitive device and uses such a profile to model a target device with similar implementation has received the lion’s share of attention in the recent years. In particular, template attacks are known to be the most powerful profiling side-channel attacks from an information theoretic point of view. When launching such an attack, the adversary first builds a model based on the leakage of the profiling (training) device in his disposal, which is then exploited in the second phase of the attack (i.e., matching) to extract the key from the target device. Discrepancies between the device used for modeling and the target device affect the attack success. The effect of process variation and temperature misalignment between the profiling and target devices in the template attack’s success has been studied extensively in the literature, while the impact of device aging on the template attack’s success is yet to be investigated thoroughly. This article moves one step forward and studies the impact of device aging, mainly bias temperature instability (BTI) and hot carrier injection (HCI), in the devices that have been protected against power analysis attacks via dual rail logics. In particular, we focus on the wave dynamic differential logic (WDDL) circuits, and via extensive transistor-level simulations, we will show how device aging misalignments between the profiling and target devices can hinder template attacks for both unprotected and WDDL protected counterparts. We mounted several attacks on the PRESENT cipher, with and without WDDL protection, at different temperatures and aging times. Our results show that the attack is more difficult if there is an aging-duration mismatch between the training and target devices, and the attack-efficiency decrease is especially significant for mismatches of few weeks. Farzad Niknia, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2022 | Assessment and Mitigation of Power Side-Channel-Based Cross-PUF Attacks on Arbiter-PUFs and Their DerivativesabstractUnintentional uncontrollable variations in the manufacturing process of integrated circuits are used to realize silicon primitives known as physical unclonable functions (PUFs). These primitives are used to create unique signatures for security purposes. Investigating the vulnerabilities of PUFs is of utmost importance to uphold their usefulness in secure applications. One such investigation includes exploring the susceptibility of PUFs to modeling attacks that aim at extracting the PUFs’ behavior. To date, these attacks have mainly focused on a single PUF instance where the targeted PUF is attacked using the model built based on the very same PUF’s challenge–response pairs or power side channel. In this article, we move one step forward and introduceCross-PUFattacks where a model is created using the power consumption of one PUF instance to attack another PUF created from the same GDSII file. Through SPICE simulations, we show that these attacks are highly effective in modeling PUF behaviors even in the presence of noise and mismatches in temperature and aging of the PUF used for modeling versus the targeted PUF. To mitigate theCross-PUFattacks, we then propose a lightweight countermeasure based on dual-rail and random initialization logic approaches called DRILL. We show that DRILL is highly effective in thwartingCross-PUFattacks. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
IEEE Trans. Very Large Scale Integr. Syst. | 5 |
| 2021 | On the Impact of Aging on Power Analysis Attacks Targeting Power-Equalized Cryptographic CircuitsabstractSide-channel analysis attacks exploit the physical characteristics of cryptographic chip implementations to extract their embedded secret keys. In particular, Power Analysis (PA) attacks make use of the dependency of the power consumption on the data being processed by the cryptographic devices. To tackle the vulnerability of cryptographic circuits against PA attack, various countermeasures have been proposed in literature and adapted by industries, among which a branch of hiding schemes opt to equalize the power consumption of the chip regardless of the processed data. Although these countermeasures are supposed to reduce the information leakage of cryptographic chips, they fail to consider the impact of aging occurs during the device lifetime. Due to aging, the specifications of transistors, and in particular their threshold-voltage, deviate from their fabrication-time specification, leading to a change of circuit's delay and power consumption over time. In this paper, we show that the aging-induced impacts result in imbalances in the equalized power consumption achieved by hiding countermeasures. This makes such protected cryptographic chips vulnerable to PA attacks when aged. The experimental results extracted through the aging simulation of the PRESENT cipher protected by Sense Amplifier Based Logic (SABL), one of the well-known hiding countermeasures, show that the achieved protection may not last during the circuit lifetime. Md Toufiq Hasan Anik, Bijan Fadaeinia, Amir Moradi 0001, Naghmeh Karimi |
ASP-DAC | 4 |
| 2021 | Learning Assisted Side Channel Delay Test for Detection of Recycled ICsabstractWith the outsourcing of design flow, ensuring the security and trustworthiness of integrated circuits has become more challenging. Among the security threats, IC counterfeiting and recycled ICs have received a lot of attention due to their inferior quality, and in turn, their negative impact on the reliability and security of the underlying devices. Detecting recycled ICs is challenging due to the effect of process variations and process drift occurring during the chip fabrication. Moreover, relying on a golden chip as a basis for comparison is not always feasible. Accordingly, this paper presents a recycled IC detection scheme based on delay side-channel testing. The proposed method relies on the features extracted during the design flow and the sample delays extracted from the target chip to build a Neural Network model using which the target chip can be truly identified as new or recycled. The proposed method classifies the timing paths of the target chip into two groups based on their vulnerability to aging using the information collected from the design and detects the recycled ICs based on the deviation of the delay of these two sets from each other. Ashkan Vakil, Farzad Niknia, Ali Mirzaeian, Avesta Sasan, Naghmeh Karimi |
ASP-DAC | 5 |
| 2021 | Making Obfuscated PUFs Secure Against Power Side-Channel Based Modeling AttacksabstractTo enhance the security of digital circuits, there is often a desire to dynamically generate, rather than statically store, random values used for identification and authentication purposes. Physically Unclonable Functions (PUFs) provide the means to realize this feature in an efficient and reliable way by utilizing commonly overlooked process variations that unintentionally occur during the manufacturing of integrated circuits (ICs) due to the imperfection of fabrication process. When given a challenge, PUFs produce a unique response. However, PUFs have been found to be vulnerable to modeling attacks where by using a set of collected challenge response pairs (CRPs) and training a machine learning model, the response can be predicted for unseen challenges. To combat this vulnerability, researchers have proposed techniques such as Challenge Obfuscation. However, as shown in this paper, this technique can be compromised via modeling the PUF's power side-channel. We first show the vulnerability of a state-of-the-art Challenge Obfuscated PUF (CO-PUF) against power analysis attacks by presenting our attack results on the targeted CO-PUF. Then we propose two countermeasures, as well as their hybrid version, that when applied to the CO-PUFs make them resilient against power side-channel based modeling attacks. We also provide some insights on the proper design metrics required to be taken when implementing these mitigations. Our simulation results show the high success of our attack in compromising the original Challenge Obfuscated PUFs (success rate > 98%) as well as the significant improvement on resilience of the obfuscated PUFs against power side-channel based modeling when equipped with our countermeasures. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
DATE | 5 |
| 2021 | Hardware Assisted Smart Grid AuthenticationabstractA Cyber-Physical System (CPS) refers to the interconnection of control (actuation), computational nodes and sensors, in order to manage physical processes. In recent years, the CPS design methodology has been adopted in several large-scale infrastructures such as smart power grids. Given the application criticality, sustaining the security of these systems is of utmost importance. One of the major security goals is to protect CPS against impersonation, where an adversary intends to manipulate the system state by sending erroneous data that appears to be reported by one of the system nodes, e.g. PMUs of a power grid. This paper proposes a novel hardware-assisted authentication scheme to counter such a threat, by exploiting imperfections that occur in the manufacturing process of integrated circuits. In essence, the proposed scheme associates a fingerprint for each system node so that the authenticity of the data source could be verified. In addition, the paper tackles the threat of message replay where the adversary re-transmits a legitimate message so that the system factors in outdated rather than fresh sensor measurements. This paper thwarts such a replay attack by leveraging the synchronized clocks across the CPS nodes, e.g., based on GPS; the idea is to employ a combination of time-stamp signatures and hardware fingerprints. Our proposed schemes can also detect and prevent data forgery, and Sybil attacks. The viability and performance of the proposed schemes are validated through analysis and prototype implementation. Mohammad Ebrahimabadi, Mohamed F. Younis, Naghmeh Karimi |
ICC | 3 |
| 2021 | Reducing Aging Impacts in Digital Sensors via Run-Time Calibration
Md Toufiq Hasan Anik, Mohammad Ebrahimabadi, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
J. Electron. Test. | 5 |
| 2021 | Detecting Failures and Attacks via Digital SensorsabstractDetection of abnormal behaviors is essential in complex and/or strategic systems requiring a high level of safety and security. Sensing environmental conditions to ensure that the device is not operating out-of-specifications is highly useful in detecting anomalies caused by failures or malevolent actions. In this regard, digital sensors (DSs) are particularly attractive as they are portable and can be easily calibrated. In contrast to analog sensors, DSs have an interesting property that considers the operating environmental conditions as a whole, i.e., they are sensitive to temperature, voltage, and process altogether, without precise knowledge about each. This property endows DSs with fewer false positives compared to analog sensors. This article studies a low-cost DS, discusses its presilicon architecture and post-silicon calibration such that it detects system failures accurately in the designer's preferable range of operating conditions. The impact of aging in this sensor is studied extensively. Tradeoffs between false positive and undetection rates are discussed. As an example, we target the substitution box (S-Box) of the PRESENT cipher assuming that it can be the target of fault injection attacks launched via abruptly changing the operating temperature and voltage. We show that such malfunction can be accurately detected by our DS, i.e., with a very negligible percentage of false and missed alarms (<; 1% totally). The results show that the number of false alarms raises with aging (while the rate is highly negligible), whereas the number of missed alarms remains at a reasonable low rate. Md Toufiq Hasan Anik, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2020 | Effect of Aging on PUF Modeling Attacks based on Power Side-Channel ObservationsabstractThanks to the imperfections in manufacturing process, Physically Unclonable Functions (PUFs) produce their unique outputs for given input signals (challenges) fed to identical circuitry designs. PUFs are often used as hardware primitives to provide security, e.g., for key generation or authentication purposes. However, they can be vulnerable to modeling attacks that predict the output for an unknown challenge, based on a set of known challenge/response pairs (CRPs). In addition, an attacker may benefit from power side-channels to break a PUFs' security. Although such attacks have been extensively discussed in literature, the effect of device aging on the efficacy of these attacks is still an open question. Accordingly, in this paper, we focus on the impact of aging on Arbiter-PUFs and one of its modeling-resistant counterparts, the Voltage Transfer Characteristic (VTC) PUF. We present the results of our SPICE simulations used to perform modeling attack via Machine Learning (ML) schemes on the devices aged from 0 to 20 weeks. We show that aging has a significant impact on modeling attacks. Indeed, when the training dataset for ML attack is extracted at a different age than the evaluation dataset, the attack is greatly hindered despite being performed on the same device. We show that the ML attack via power traces is particularly efficient to recover the responses of the anti-modeling VTC PUF, yet aging still contributes to enhance its security. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
DATE | 5 |
| 2020 | PUF Enrollment and Life Cycle Management: Solutions and Perspectives for the Test CommunityabstractPhysically Unclonable Functions (PUFs) allow to extract unique fingerprints from silicon chips. The applications are numerous: chip identification, chip master key extraction, authentication protocol, unique seeding, etc. However, secure usage of PUF requires some precautions. This paper reviews industrial concerns associated with PUF operation, including those occurring before and after market. Namely, starting from PUF “secure” specifications, aligned with state-of-the-art standards, we explore innovative techniques to handle enrollment and subsequent PUF queries, in nominal as well as in adversarial environment. Amir Ali Pour, Vincent Beroulle, Bertrand Cambou, Jean-Luc Danger, Giorgio Di Natale, David Hély, Sylvain Guilley, Naghmeh Karimi |
ETS | 8 |
| 2020 | Failure and Attack Detection by Digital SensorsabstractTimely notification of abnormal behaviors is essential in strategic systems requiring a high level of safety and security. Sensing environmental conditions to ensure that the device is not operating out-of-specifications is highly useful in detecting anomalies caused by failures or malevolent actions. Digital sensors consider the operating environmental conditions as a whole, i.e. they are sensitive to temperature, voltage and process altogether, without precise knowledge about each. This paper proposes a low-cost digital sensor that can detect system failures accurately in the designer's preferable range of operating conditions. Our experimental results show the high accuracy of this sensor in detecting circuits failure which occurred due to change of the operating temperature and supply voltage. Md Toufiq Hasan Anik, Rachit Saini, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ETS | 5 |
| 2020 | On-Chip Voltage and Temperature Digital Sensor for Security, Reliability, and PortabilityabstractThe integrated circuits can be exposed to various stresses during run-time due to unexpected environmental conditions or attacks. Ensuring that a circuit is not working out-of-specification via sensing its operating conditions, e.g., temperature and voltage, is highly useful in detecting anomalies. Analog sensors have been used to monitor the operating conditions for a long time, however, weaknesses including lack of portability to thin technology nodes, costly & complex calibration process, and low attack resistance make such sensors inefficient. Digital sensors, via considering the temperature and voltage effects altogether instead of treating each separately, have been demonstrated as a qualified replacement. In this paper, we develop an integrated framework for continuous monitoring of the operating voltage and temperature of each chip. The framework includes an embedded on-chip sensor circuitry along with a Neural Network model that quantifies the temperature and voltage values via processing the data collected by this sensor. The experimental results confirm the high accuracy of the proposed framework in tracking on-chip voltage and temperature variations, i.e., with the average error of 0.014V in a range of 0.65V to 1.4V, and the average error of 3.9°C in a range of -10°C to 150°C, respectively. Md Toufiq Hasan Anik, Mohammad Ebrahimabadi, Hamed Pirsiavash, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi |
ICCD | 6 |
| 2020 | Cross-PUF Attacks on Arbiter-PUFs through their Power Side-ChannelabstractThe silicon primitives known as Physically Unclonable Functions (PUFs) are used for various security purposes including key generation, device authentication, etc. Due to the imperfections in manufacturing process, PUFs produce their unique outputs (responses) for given input signals (challenges) fed to identical circuitry designs. Although PUFs are deployed to preserve security and are assumed to be unclonable, their functionality may still be compromised by modeling attacks. However, such attacks only target one single PUF aiming at reversing its behavior (based on a subset of its challenge-response pairs), and are not useful for attacking other PUFs. Moreover a subset of the target PUF's response has to be known by the attacker. This paper moves one step forward and investigates the possibility of Cross-PUF attacks in which a particular PUF's power fingerprints can be used to break another PUF's security. In these Cross-PUF attacks, the attacker has at his disposal a reference PUF, and uses its power side-channel to train a machine learning model which can be deployed to attack other identical PUFs. The experimental results show the high success of the proposed attacks even in presence of noise and temperature differences between the target PUF and the one used to train the model. We target arbiter-PUFs but we deduce that the findings extend to all its derivatives, e.g., XOR-PUFs and Feed-Forward-PUFs. Trevor Kroeger, Wei Cheng 0003, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi |
ITC | 5 |
| 2020 | DFSSD: Deep Faults and Shallow State Duality, A Provably Strong Obfuscation Solution for Circuits with Restricted Access to Scan ChainabstractIn this paper, we introduce DFSSD, a novel logic locking solution for sequential and FSM circuits with a restricted (locked) access to the scan chain. DFSSD combines two techniques for obfuscation: (1) Deep Faults, and (2) Shallow State Duality. Both techniques are specifically designed to resist against sequential SAT attacks based on bounded model checking. The shallow state duality prevents a sequential SAT attack from taking a shortcut for early termination without running an exhaustive unbounded model checker to assess if the attack could be terminated. The deep fault, on the other hand, provides a designer with a technique for building deep, yet key recoverable faults that could not be discovered by sequential SAT (and bounded model checker based) attacks in a reasonable time. Shervin Roshanisefat, Hadi Mardani Kamali, Kimia Zamiri Azar, Sai Manoj Pudukotai Dinakarrao, Naghmeh Karimi, Houman Homayoun, Avesta Sasan |
VTS | 5 |
| 2019 | Special Session: Countering IP Security threats in Supply chainabstractThe continuing decrease in feature size of integrated circuits, and the increase of the complexity and cost of design and fabrication has led to outsourcing the design and fabrication of integrated circuits to third parties across the globe, and in turn has introduced several security vulnerabilities. The adversaries in the supply chain can pirate integrated circuits, overproduce these circuits, perform reverse engineering, and/or insert hardware Trojans in these circuits. Developing countermeasures against such security threats is highly crucial. Accordingly, this paper first develops a learning-based trust verification framework to detect hardware Trojans. To tackle Trojan insertion, IP piracy and overproduction, logic locking schemes and in particular stripped functionality logic locking is discussed and its resiliency against the state-of-the-art attacks is investigated. Hassan Salmani, Tamzidul Hoque, Swarup Bhunia, Muhammad Yasin, Jeyavijayan Rajendran, Naghmeh Karimi |
VTS | 6 |
| 2018 | Device aging: A reliability and security concernabstractDevice aging is an important concern in nanoscale designs. Due to aging the electrical behavior of transistors embedded in an integrated circuit deviates from original intended one. This leads to performance degradation in the underlying device, and the ultimate device failure. This effect is exacerbated in emerging technologies. To be able to tailor effective aging mitigation schemes and improve the reliability of devices realized in cutting edge technologies, there is a need to accurately study the effect of aging in high performance industrial applications. According, this paper targets a high performance SRAM memory realized in 14nm FinFET technology and depicts how aging degrades the individual components of this memory as well as the interaction between them. Aging mitigation is critical not only from device reliability point of view but also regarding device security perspectives. It is essential to assure the security of the sensitive tasks performed by the security-sensitive circuits and to guarantee the security of information stored within these devices in the presence of aging. Accordingly in this paper, we also focus on aging-related security concerns and present the cases in which aging need to considered to preserve security. Daniel Kraak, Mottaqiallah Taouil, Said Hamdioui, Pieter Weckx, Francky Catthoor, Abhijit Chatterjee, Adit D. Singh, Hans-Joachim Wunderlich, Naghmeh Karimi |
ETS | 9 |
| 2018 | Impact of Aging on Template AttacksabstractTemplate attack is the most powerful side-channel attack from an information theoretic point of view. This attack is launched in two phases. In the first phase (training) the attacker uses a training device to estimate leakage models for targeted intermediate computations, which are then exploited in the second phase (matching) to extract secret information from the target device. Process variation and discrepancy of operating conditions (e.g., temperature) between training and matching phases adversely affect the success probability of the attack. Attack-success degradation is exacerbated when device aging comes into account. Due to aging, electrical specifications of transistors change over time. Thereby, if the training and target devices have experienced different usage time, the attack will be more difficult. Aging alignment between training and target devices is difficult as aging degradation is highly affected by operating conditions and technological variations. This paper investigates the effect of aging on the success rate of template attacks. In particular, we focus on NBTI and HCI aging mechanisms. We mount several attacks on the PRESENT cipher at different temperatures and aging times. Our results show that the attack is more difficult if there is an aging-duration mismatch between the training and target devices. Naghmeh Karimi, Sylvain Guilley, Jean-Luc Danger |
ACM Great Lakes Symposium on VLSI | 1 |
| 2018 | On the Effect of Aging in Detecting Hardware Trojan Horses with Template AnalysisabstractWith the outsourcing of design flow, ensuring the security and trustworthiness of integrated circuits has become more challenging. Potential malicious modification of circuits, so-called Hardware Trojans Horses (HTH), has emerged as a major security threat. When triggered, the HTH delivers its payload resulting in denial of service, decreasing the device performance, or leaking sensitive information. Deploying VLSI testing schemes to detect HTH may fail in most cases as HTH are designed such that they are rarely activated. Side-channel analysis schemes have a higher detection coverage. The template analysis is the most powerful side-channel tool from an information theoretic point of view. In this paper, we focus on the template analysis used for detecting HTH in cryptographic devices, and study the effect of device aging on the success of these HTH detection schemes. Due to aging, electrical specifications of transistors, and in turn the power signatures used by template schemes change over time. We focus on Negative-Bias Temperature Instability and Hot-Carrier Injection aging mechanisms. We use the PRESENT cipher as a target, and mount several template attacks at different aging times on target devices and a genuine device used as reference. We deduce the authenticity of the target devices based on the attack success rates obtained by template analysis. Our results show that aging makes template-based HTH detection easier as it needs less traces in old devices compared to the new one (137 traces for a 20-week old device versus 195 traces for a new one). Naghmeh Karimi, Jean-Luc Danger, Sylvain Guilley |
IOLTS | 1 |
| 2018 | Special session: Recent developments in hardware securityabstractIn this session, we explore some of the recent challenges facing hardware security: (i) Challenges in the implementation of post-quantum crypto algorithms, (ii) Impact of aging on security, and (ii) Security challenges in machine learning. Rosario Cammarota, Naghmeh Karimi, Siddharth Garg, Jeyavijayan Rajendran |
VTS | 2 |
| 2018 | Impact of Aging on the Reliability of Delay PUFs
Naghmeh Karimi, Jean-Luc Danger, Sylvain Guilley |
J. Electron. Test. | 1 |
| 2017 | Impact of the switching activity on the aging of delay-PUFsabstractPhysically Unclonable Functions (PUFs) are mainly used for generating unique keys to identify electronic devices. The reliability of PUFs needs to be assured under a wide variety of environmental conditions and aging mechanisms. In this paper, we evaluate the impact of NBTI and HCI aging on two types of delay-PUFs (arbiter-PUFs and loop-PUFs). The results show that the switching activity has a limited impact on delay chains and a significant impact on the arbiter (RS latch) of the arbiter-PUF. Naghmeh Karimi, Jean-Luc Danger, Mariem Slimani, Sylvain Guilley |
ETS | 1 |
| 2015 | MAGIC: Malicious Aging in Circuits/CoresabstractThe performance of an IC degrades over its lifetime, ultimately resulting in IC failure. In this article, we present a hardware attack (called MAGIC) to maliciously accelerate NBTI aging effects in cores. In this attack, we identify the input patterns that maliciously age the pipestages of a core. We then craft a program that generates these patterns at the inputs of the targeted pipestage. We demonstrate the MAGIC-based attack on the OpenSPARC processor. Executing this program dramatically accelerates the aging process and degrades the processor’s performance by 10.92% in 1 month, bypassing existing aging mitigation and timing-error correction schemes. We also present two low-cost techniques to thwart the proposed attack. Naghmeh Karimi, Arun K. Kanuparthi, Ozgur Sinanoglu, Ramesh Karri |
ACM Trans. Archit. Code Optim. | 1 |
| 2015 | Modeling, Detection, and Diagnosis of Faults in Multilevel Memristor MemoriesabstractMemristors are an attractive option for use in future memory architectures but are prone to high defect densities due to the nondeterministic nature of nanoscale fabrication. Several works discuss memristor fault models and testing. However, none of them considers the memristor as a multilevel cell (MLC). The ability of memristors to function as an MLC allows for extremely dense, low-power memories. Using a memristor as an MLC introduces fault mechanisms that cannot occur in typical two-level memory cells. In this paper, we develop fault models for memristor-based MLC crossbars. The typical approach to testing a memory subsystem entails testing one memory cell at a time. However, this testing strategy is time consuming and does not scale for dense, memristor memories. We propose an efficient testing technique that exploits sneak-paths inherent in crossbar memories to test several memory cells simultaneously. In this paper, we integrate solutions for detecting and locating faults in memristors. We develop a power aware built-in self-test solution to detect these faults. We also propose a hybrid diagnosis scheme that uses a combination of sneak-path and March testing to reduce diagnosis time. The proposed schemes enable and leverage sneak-paths during fault detection and diagnosis modes, while disabling sneak-paths during normal operation. The proposed hybrid scheme reduces fault detection and diagnosis time by 24.69% and 28%, respectively, compared to traditional March tests. Sachhidh Kannan, Naghmeh Karimi, Ramesh Karri, Ozgur Sinanoglu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2015 | Security Vulnerabilities of Emerging Nonvolatile Main Memories and CountermeasuresabstractEmerging nonvolatile memory devices such as phase change memories and memristors are replacing SRAM and DRAM. However, nonvolatile main memories (NVMM) are susceptible to probing attacks even when powered down. This way, they may compromise sensitive data such as passwords and keys that reside in the NVMM. To eliminate this vulnerability, we propose sneak-path encryption (SPE), a hardware intrinsic encryption technique for memristor-based NVMMs. SPE is instruction set architecture independent and has minimal impact on performance. SPE exploits the physical parameters, such as sneak-paths in crossbar memories, to encrypt the data stored in a memristor-based NVMM. SPE is resilient to a number of attacks that may be performed on NVMMs. We use a cycle accurate simulator to evaluate the performance impact of SPE-based NVMM and compare against other security techniques. SPE can secure an NVMM with a ~1.3% performance overhead. Sachhidh Kannan, Naghmeh Karimi, Ozgur Sinanoglu, Ramesh Karri |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2014 | Secure Memristor-based Main MemoryabstractNon-volatile memory devices such as phase change memories and memristors are promising alternatives to SRAM and DRAM main memories as they provide higher density and improved energy efficiency. However, non-volatile main memories (NVMM) introduce security vulnerabilities. Sensitive data such as passwords and keys residing in the NVMM will persist and can be probed after power down. We propose sneak-path encryption (SPE), for memristor-based NVMM. SPE exploits the physical parameters, multilevel cell (MLC) capability and the sneak paths in crossbar memories to encrypt the data stored in memristor-based NVMM. We investigate three attacks on NVMMs and show the resilience of SPE against them. We use a cycle accurate simulator to evaluate the security and performance impact of SPE based NVMM. SPE can secure the NVMM with a latency of 16 cycles and ~1.5% performance overhead. Sachhidh Kannan, Naghmeh Karimi, Ozgur Sinanoglu |
DAC | 2 |
| 2014 | Detection, diagnosis, and repair of faults in memristor-based memoriesabstractMemristors are an attractive option for use in future memory architectures due to their non-volatility, high density and low power operation. Notwithstanding these advantages, memristors and memristor-based memories are prone to high defect densities due to the non-deterministic nature of nanoscale fabrication. The typical approach to fault detection and diagnosis in memories entails testing one memory cell at a time. This is time consuming and does not scale for the dense, memristor-based memories. In this paper, we integrate solutions for detecting and locating faults in memristors, and ensure post-silicon recovery from memristor failures. We propose a hybrid diagnosis scheme that exploits sneak-paths inherent in crossbar memories, and uses March testing to test and diagnose multiple memory cells simultaneously, thereby reducing test time. We also provide a repair mechanism that prevents faults in the memory from being activated. The proposed schemes enable and leverage sneak paths during fault detection and diagnosis modes, while still maintaining a sneak-path free crossbar during normal operation. The proposed hybrid scheme reduces fault detection and diagnosis time by ~44%, compared to traditional March tests, and repairs the faulty cell with minimal overhead. Sachhidh Kannan, Naghmeh Karimi, Ramesh Karri, Ozgur Sinanoglu |
VTS | 2 |
| 2013 | Reconciling the IC test and security dichotomyabstractMany of the design companies cannot afford owning and acquiring expensive foundries and hence, go fabless and outsource their design fabrication to foundries that are potentially untrustwrothy. This globalization of Integrated Circuit (IC) design flow has introduced security vulnerabilities. If a design is fabricated in a foundry that is outside the direct control of the (fabless) design house, reverse engineering, malicious circuit modification, and Intellectual Property (IP) piracy are possible. In this tutorial, we elaborate on these and similar hardware security threats by making connections to VLSI testing. We cover design-for-trust techniques, such as logic encryption, aging acceleration attacks, and statistical methods that help identify Trojan'ed and counterfeit ICs. Ozgur Sinanoglu, Naghmeh Karimi, Jeyavijayan Rajendran, Ramesh Karri, Yier Jin, Ke Huang 0001, Yiorgos Makris |
ETS | 2 |
| 2013 | Special session 4B: Elevator talksabstractStart of the "Special session 4B: Elevator talks" section of the conference record. Jennifer Dworak, R. D. (Shawn) Blanton, Masahiro Fujita 0004, Kazumi Hatayama, Naghmeh Karimi, Michail Maniatakos, Antonis M. Paschalis, Adit D. Singh |
VTS | 5 |
| 2013 | On the Impact of Performance Faults in Modern Microprocessors
Naghmeh Karimi, Michail Maniatakos, Chandra Tirumurti, Yiorgos Makris |
J. Electron. Test. | 1 |
| 2013 | Detection, Diagnosis, and Recovery From Clock-Domain Crossing Failures in Multiclock SoCsabstractClock-domain crossing (CDC) faults require careful post-silicon testing for multiclock circuits. Even when robust design methods based on synchronizers and design verification techniques are used, process variations can introduce subtle timing problems that affect data transfer across clock-domain boundaries for fabricated chips. We integrate solutions for detecting and locating CDC faults, and ensuring post-silicon recovery from CDC failures. In the proposed method, CDC faults are located using a CDC-fault dictionary, and their impact is masked using post-silicon clock-path tuning. To quantify the impact of process variations in the transfer of data at clock domain boundaries of multiclock circuits and to validate the proposed error-recovery method, we conducted a series of HSpice simulations using a 45-nm technology. The results demonstrate high incidence of process variation-induced violation of setup and hold time at the boundary flip-flops, even when synchronizer flip-flops are employed. The results also confirm the effectiveness of the proposed error-recovery scheme in recovering from CDC failures. Naghmeh Karimi, Krishnendu Chakrabarty |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2012 | Test generation for clock-domain crossing faults in integrated circuitsabstractClock-domain crossing (CDC) faults are a serious concern for high-speed, multi-core integrated circuits. Even when robust design methods based on synchronizers and design verification techniques are used, process variations can introduce subtle timing problems that affect data transfer across clock-domain boundaries for fabricated chips. We present a test generation technique that leverages commercial ATPG tools, but introduces additional constraints, to detect CDC faults. We also present HSpice simulation data using a 45 nm technology to quantify the occurrence of CDC faults at clock-domain boundaries. Results are presented for synthesized IWLS05 benchmarks that include multiple clock domains. The results highlight the ineffectiveness of commercial transition-delay fault ATPG and the “coverage gap” resulting from the use of ATPG methods employed in industry today. While the proposed method can detect nearly all CDC faults, TDF ATPG is found to be severely deficient for screening CDC faults. Naghmeh Karimi, Krishnendu Chakrabarty, Pallav Gupta, Srinivas Patil |
DATE | 1 |
| 2011 | Testing of Clock-Domain Crossing Faults in Multi-core System-on-ChipabstractManufacturing test for clock-domain crossing(CDC) defects is a major challenge for multi-core system-on chip(SoC) designs in the nanometer regime. Setup- and hold time violations in flip-flops situated on clock boundaries may lead to catastrophic failures, even when circuits are equipped with synchronizers at clock boundaries. In this work, we comprehensively study the effect of CDC faults, and propose a number of fault models to target such defects. In addition, we develop an automatic test-pattern selection method for CDC fault detection. This work is motivated by the fact that CDC faults cannot always be detected by conventional ATPG methods. The results of applying the proposed method to a number of IWLS'05 benchmarks demonstrate the effectiveness of our approach. Naghmeh Karimi, Zhiqiu Kong, Krishnendu Chakrabarty, Pallav Gupta, Srinivas Patil |
Asian Test Symposium | 1 |
| 2011 | Workload-Cognizant Concurrent Error Detection in the Scheduler of a Modern MicroprocessorabstractWe present a Concurrent Error Detection (CED) scheme for the Scheduler of a modern microprocessor. The proposed CED scheme is based on monitoring a set of invariances imposed through added hardware, violation of which signifies the occurrence of an error. The novelty of our solution stems from the workload-cognizant way in which these invariances are selected so that they leverage the application-level error masking inherent in program execution. Specifically, in order to ensure cost-effectiveness of the hardware employed to construct these invariances, we make use of information regarding the type and frequency of errors affecting the typical workload of the microprocessor. Thereby, we identify the most susceptible aspects of instruction execution and we accordingly distribute CED resources to protect them. Our approach is demonstrated on the Scheduler of an Alpha-like superscalar microprocessor with dynamic scheduling, hybrid branch prediction and out-of-order execution capabilities. Using an extensive fault-simulation infrastructure that we developed around this microprocessor, we profile the impact of Scheduler faults across a variety of different SPEC2000 benchmarks. Based on the results, we construct a CED scheme which monitors the time and location of instruction execution, the executed operation, the utilized resources, as well as the executed and retired sequence of instructions. At a hardware cost of only 32 percent of the Scheduler, the corresponding CED scheme detects over 85 percent of its faults that affect the architectural state of the microprocessor. Furthermore, over 99.5 percent of these faults are detected before they corrupt the architectural state, while the average detection latency for the remaining faults is in the order of a few clock cycles, implying that efficient recovery methods can be developed. Naghmeh Karimi, Michail Maniatakos, Abhijit Jas, Chandra Tirumurti, Yiorgos Makris |
IEEE Trans. Computers | 1 |
| 2011 | Instruction-Level Impact Analysis of Low-Level Faults in a Modern Microprocessor ControllerabstractWe investigate the correlation between low-level faults in the control logic of a modern microprocessor and their instruction-level impact on the execution of typical workload. Such information can prove immensely useful in accurately assessing and prioritizing faults with regards to their criticality, as well as commensurately allocating resources to enhance online testability and error/fault resilience through concurrent error detection/correction methods. To this end, we developed an extensive fault simulation infrastructure which allows injection of stuck-at faults and transient errors of arbitrary starting time and duration, as well as cost-effective simulation and classification of their repercussions into various instruction-level error types. As a test vehicle for our study, we employ a superscalar, dynamically-scheduled, out-of-order, Alpha-like microprocessor, on which we execute SPEC2000 integer benchmarks. Extensive fault injection campaigns in control modules of this microprocessor facilitate valuable observations regarding the distribution of low-level faults into the instruction-level error types that they cause. Experimentation with both Register Transfer (RT-) and Gate-Level faults, as well as with both stuck-at faults and transient errors, confirms the validity and corroborates the utility of these observations. Michail Maniatakos, Naghmeh Karimi, Chandra Tirumurti, Abhijit Jas, Yiorgos Makris |
IEEE Trans. Computers | 2 |
| 2009 | Impact analysis of performance faults in modern microprocessorsabstractTowards improving performance, modern microprocessors incorporate a variety of architectural features, such as branch prediction and speculative execution, which are not critical to the correctness of their operation. While faults in the corresponding hardware may not necessarily affect functional correctness, they may, nevertheless, adversely impact performance. In this paper, we investigate quantitatively the performance impact of such faults using a superscalar, dynamically-scheduled, out-of-order, Alpha-like microprocessor, on which we execute SPEC2000 integer benchmarks. We provide extensive fault simulation-based experimental results and we discuss how this information may guide the inclusion of additional hardware for performance loss recovery and yield enhancement. Naghmeh Karimi, Michail Maniatakos, Chandra Tirumurti, Abhijit Jas, Yiorgos Makris |
ICCD | 1 |
| 2009 | Instruction-Level Impact Comparison of RT- vs. Gate-Level Faults in a Modern Microprocessor ControllerabstractWe discuss the results of an extensive fault simulation study involving the control logic of a modern alpha-like microprocessor. In this comparative study, faults are injected in both the RT- and the Gate-Level description of the design and are simulated under actual workload of the microprocessor, which is executing SPEC2000 benchmarks. The objective of this study is to analyze and contrast the impact of RT- and gate-level faults on the instruction execution flow of the microprocessor. The key observation is a pronounced consistency in the type and frequency of instruction level errors (ILEs) arising due to RT- vs. gate-level faults. The motivation for this work stems from the need to understand the relative importance of low-level faults based on their instruction-level impact, in order to appropriately allocate error detection and/or correction resources. Hence, the consistency revealed through this study implies that such decisions can be made equally effective based on RT-level fault simulation results, as with their far more computationally-expensive gate-level equivalents. Michail Maniatakos, Naghmeh Karimi, Chandra Tirumurti, Abhijit Jas, Yiorgos Makris |
VTS | 2 |
| 2008 | A Novel GA-Based High-Level Synthesis Technique to Enhance RT-Level Concurrent TestingabstractThis paper presents an efficient high-level synthesis (HLS) approach to improve RT-level concurrent testing. The proposed method used for both fault detection and fault location. At first the available resources are used in their dead intervals to test active resources for fault detection, and then some changes are applied to the RT-level controller to locate the faults. The fault detection step is based on a genetic algorithm (GA) search technique. This genetic algorithm is applied to the design after high level synthesis process to explore the test map. The proposed method has been evaluated based on dependability enhancement and area/latency overhead imposed to different benchmarks after applying our algorithm. The dependability has been considered in terms of fault coverage. The experimental result shows that applying our algorithm, the associated area overhead and performance penalty are negligible while the online fault coverage improvement is considerable. Naghmeh Karimi, Soheil Aminzadeh, Saeed Safari, Zainalabedin Navabi |
IOLTS | 1 |
| 2008 | NoC Reconfiguration for Utilizing the Largest Fault-free Connected Sub-structureabstractThis paper proposes an offline test strategy for finding the largest fault-free connected sub-structure of a mesh-based NoC. Faulty switch ports are found by flooding the NoC with test packets. Then, NoC routers are reconfigured according to the degraded NoC structure to route incoming packets. Armin Alaghi, Mahshid Sedghi, Naghmeh Karimi, Zainalabedin Navabi |
ITC | 3 |
| 2008 | On the Correlation between Controller Faults and Instruction-Level Errors in Modern MicroprocessorsabstractWe investigate the correlation between register transfer-level faults in the control logic of a modern microprocessor and their instruction-level impact on the execution flow of typical programs. Such information can prove immensely useful in accurately assessing and prioritizing faults with regards to their criticality, as well as commensurately allocating resources to enhance testability, diagnosability, manufacturability and reliability. To this end, we developed an extensive infrastructure which allows injection of stuck-at faults and transient errors of arbitrary starting point and duration, as well as cost-effective simulation and classification of their repercussions into various instruction-level error types. As a test vehicle for our study, we employ a superscalar, dynamically-scheduled, out-of-order, Alpha-like microprocessor, on which we execute SPEC2000 integer benchmarks. Extensive experimentation with faults injected in control logic modules of this microprocessor reveals interesting trends and results, corroborating the utility of this simulation infrastructure and motivating its further development and application to various tasks related to robust design. Naghmeh Karimi, Michail Maniatakos, Abhijit Jas, Yiorgos Makris |
ITC | 1 |
| 2007 | RT level reliability enhancement by constructing dynamic TMRSabstractThis paper presents a novel and efficient approach for reliability enhancement at the RT level. The reliability enhancement is performed by utilizing the available resources of a design in their dead intervals. Such resources are used for constructing dynamic TMR structures that can change per clock cycle. In this method all resources participate in constructing TMR structures at least once per a system input to output flow.To evaluate the proposed fault tolerance technique we consider dependability, and area/latency overhead imposed on a circuit by applying our method. In order to evaluate dependability, faults are injected into our test circuits before and after applying our algorithm and fault coverage is measured. Experimental results show that after applying our method, fault coverage is significantly reduced indicating that the reliability of designs is improved. Naghmeh Karimi, Shahrzad Mirkhani, Zainalabedin Navabi, Fabrizio Lombardi |
ACM Great Lakes Symposium on VLSI | 1 |
| 2006 | ESTA: An Efficient Method for Reliability Enhancement of RT-Level DesignsabstractThis paper proposes a novel and efficient method for RT level online testing. Our method makes every RT-level resource online-testable, and guarantees high single stuck-at fault detection (i.e., high reliability) with low area/latency overhead. This method uses available resources in their dead intervals (the intervals during which a resource is not being used) to test active resources. The area and/or latency overhead are due to concurrent operation of active and inactive resources. This method is evaluated by fault simulating several benchmark designs before and after applying the proposed algorithm. Experimental results show that after applying our method, online fault coverage is significantly improved Naghmeh Karimi, Shahrzad Mirkhani, Zainalabedin Navabi |
ATS | 1 |