Jeyavijayan Rajendran

dblp:79/9006 · also J. V. Rajendran 0001, Jeyavijayan (JV) Rajendran · DBLP profile ↗
← Back
94ranked-venue papers
21as first author
33since 2021 · last 2026
0000-0003-3687-3746ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 73 · 18 first-author · 19 since 2021Security and privacy · 17 · 1 first-author · 13 since 2021Software engineering, systems software and programming languages · 10 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorComputer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FUZZItizer: Hardware Sanitizer-Assisted Fuzzing for Automated SoC Vulnerability Detection
Rahul Kande, Mohamadreza Rostami, Chen Chen 0125, Hareesh Khattri, Jason M. Fung, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
AsiaCCS7
2026 Focus Session: Advanced Hybrid Hardware Fuzzing
abstract
Modern processors are increasingly complex, with rich microarchitectural features and heterogeneous components. This complexity expands the attack surface and makes security vulnerabilities harder to detect using traditional security techniques. Hardware fuzzing has emerged as a scalable approach for uncovering insecure behaviors in modern processors. However, it often struggles to (i) explore hard-to-reach design spaces due to its randomness and (ii) locate the root causes of vulnerabilities due to design complexity.This work presents advanced hybrid hardware fuzzing techniques that combine the complementary strengths of fuzzing, formal verification, and static analysis to systematically detect and localize vulnerabilities in processors. Specifically, we investigate (i) the use of formal verification to guide fuzzing toward hard-to-reach design spaces, thereby enabling the discovery of subtle vulnerabilities, and (ii) the use of static analysis to extract and monitor timing behaviors at the register-transfer level (RTL), enabling localization of timing vulnerabilities that can arise even in functionally correct designs.Finally, we outline future research directions, including using large language models to generate expert-informed tests, leveraging prior design knowledge to enhance fuzzing effectiveness on new processors, and transferring effective strategies from white-box fuzzing to black-box fuzzing environments.
Chen Chen 0125, Stephen Muttathil, Mohamadreza Rostami, Nikhilesh Singh, Lichao Wu, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
DATE7
2026 Focus Session: What the Fuzz! Pushing Beyond Randomness in Hardware Security with Generative AI
Nikhilesh Singh, Mohamadreza Rostami, Lichao Wu, Chen Chen 0125, Stephen Muttathil, Jeyavijayan Rajendran, Ahmad-Reza Sadeghi
DATE6
2026 Special Day - GUIDE: GenAI Units In Digital Design Education
abstract
GenAI Units In Digital Design Education (GUIDE) is an open courseware repository with runnable Google Colab labs and other materials. We describe the repository’s architecture and educational approach based on standardized teaching units comprising slides, short videos, runnable labs, and related papers. This organization enables consistency for both the students’ learning experience and the reuse and grading by instructors. We demonstrate GUIDE in practice with three representative units: VeriThoughts for reasoning and formal-verification-backed RTL generation, enhanced LLM-aided testbench generation, and LLMPirate for IP Piracy. We also provide details for four example course instances (GUIDE4ChipDesign, Build your ASIC, GUIDE4HardwareSecurity, and Hardware Design) that assemble GUIDE units into full semester offerings, learning outcomes, and capstone projects, all based on proven materials. For example, the GUIDE4HardwareSecurity course includes a project on LLM-aided hardware Trojan insertion that has been successfully deployed in the classroom and in Cybersecurity Games and Conference (CSAW), a student competition and academic conference for cybersecurity. We also organized an NYU Cognichip Hackathon, engaging students across 24 international teams in AI-assisted RTL design workflows. The GUIDE repository is open for contributions and available at: https://github.com/FCHXWH823/LLM4ChipDesign.
Weihua Xiao, Jason Blocklove, Matthew DeLorenzo, Johann Knechtel, Ozgur Sinanoglu, Kanad Basu, Jeyavijayan Rajendran, Siddharth Garg, Ramesh Karri
DATE7
2026 ReFuzz: Reusing Tests for Processor Fuzzing with Contextual Bandits
Chen Chen 0125, Zaiyan Xu, Mohamadreza Rostami, Dileep M. Kalathil, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
NDSS7
2025 Free and Fair Hardware: A Pathway to Copyright Infringement-Free Verilog Generation using LLMs
abstract
Limitations in Large Language Model (LLM) capabilities for hardware design tasks, such as generating functional Verilog codes, have motivated various fine-tuning optimizations utilizing curated hardware datasets from open-source repositories. However, these datasets remain limited in size and contain minimal checks on licensing for reuse, resulting in potential copyright violations by fine-tuned LLMs. Therefore, we propose an evaluation benchmark to estimate the risk of Verilog-trained LLMs to generate copyright-protected codes. To minimize this risk, we present an open-source Verilog dataset, FreeSet, containing over 220k files, along with the automated dataset curation framework utilized to provide additional guarantees of fair-use Verilog data. We then execute an LLM fine-tuning framework consisting of continual pre-training, resulting in a fine-tuned Llama model for Verilog, FreeV. Our results indicate that FreeV demonstrates the smallest risk of copyright-infringement among prior works, with only a 3% violation rate. Furthermore, experimental results demonstrate improvements in Verilog generation functionality over its baseline model, improving VerilogEval pass@10 rates by over 10%.
Sam Bush, Matthew DeLorenzo, Phat Tieu, Jeyavijayan Rajendran
DAC4
2025 SCONE: A Logic Locking Technique Utilizing SMT Solver and Circuit Encoding Scheme for Efficient Hardware IP Protection
abstract
Multiple intellectual property (IP) protections have emerged to defeat security threats in integrated circuit (IC) supply chain. Among these, logic locking is regarded as a promising IP protection for its security. A state-of-the-art work uses stripped-functionality logic locking (SFLL) technique with protected input patterns (PIPs) satisfying the distance of at least 2 (Dist2) property, or D2PIPs, for ensuring resilience against both input-output (I/O)-based and structural attacks. However, this approach has research challenges in scalability, flexibility, and security, as stated and discussed in our paper. Our paper solves these challenges by (i) utilizing a satisfiability modulo theories (SMT) solver and (ii) developing a secure circuit encoding scheme. SCONE, our secure logic locking technique, combines the two methods and meets all three challenges simultaneously. Our results show that SCONE improves scalability $\mathbf{3 5 0} \times$ on the IBEX processor (16 K gates) and remains resilient against five I/O or structural attacks. Index Terms-logic locking, encoding scheme, SMT solver.
Zhaokun Han, Daniel Xing, Kostas Amberiadis, Ankur Srivastava 0001, Jeyavijayan Rajendran
DAC5
2025 Tracing the Logic: Evaluating LLM Reasoning Paths in RTL Generation
abstract
Large reasoning models (LRMs) have recently demonstrated strong improvements in complex problem-solving by leveraging inference-time reasoning strategies. In hardware design, these approaches have been applied to Verilog generation, enabling models to produce more functional designs compared to conventional LLMs. However, while the effectiveness of reasoning-augmented models has been established, the intermediate reasoning traces themselves remain underexplored. This work presents the first systematic framework for evaluating reasoning traces in Verilog generation. We analyze state-of-the-art reasoning-trained models using a suite of text-based, semantic, and structural metrics that quantify redundancy, coherence, and alignment between reasoning tokens and final Verilog outputs. Our evaluation highlights both the advantages and inefficiencies of current reasoning approaches: while extended reasoning can support functional correctness, it often introduces significant redundancy and inference overhead. These findings point toward the need for more concise, purposeful reasoning strategies. By characterizing the quality of reasoning traces, this work provides new insights and directions for optimizing reasoning structures in LLM-assisted hardware design.
Matthew DeLorenzo, Kevin Tieu, Jeyavijayan Rajendran
ICCD3
2025 LLMPirate: LLMs for Black-box Hardware IP Piracy
Vasudev Gohil, Matthew DeLorenzo, Veera Vishwa Achuta Sai Venkat Nallam, Joey See, Jeyavijayan Rajendran
NDSS5
2025 GenHuzz: An Efficient Generative Hardware Fuzzer
Lichao Wu, Mohamadreza Rostami, Huimin Li 0004, Jeyavijayan Rajendran, Ahmad-Reza Sadeghi
USENIX Security Symposium4
2024 ModSRAM: Algorithm-Hardware Co-Design for Large Number Modular Multiplication in SRAM
abstract
Elliptic curve cryptography (ECC) is widely used in security applications such as public key cryptography (PKC) and zero-knowledge proofs (ZKP). ECC is composed of modular arithmetic, where modular multiplication takes most of the processing time. Computational complexity and memory constraints of ECC limit the performance. Therefore, hardware acceleration on ECC is an active field of research. Processing-in-memory (PIM) is a promising approach to tackle this problem. In this work, we design ModSRAM, the first 8T SRAM PIM architecture to compute large-number modular multiplication efficiently. In addition, we propose R4CSA-LUT, a new algorithm that reduces the cycles for an interleaved algorithm and eliminates carry propagation for addition based on look-up tables (LUT). ModSRAM is co-designed with R4CSA-LUT to support modular multiplication and data reuse in memory with 52% cycle reduction compared to prior works with only 32% area overhead.
Jonathan Hao-Cheng Ku, Junyao Zhang 0003, Haoxuan Shan, Saichand Samudrala, Jiawen Wu 0006, Qilin Zheng, Ziru Li, Jeyavijayan Rajendran, Yiran Chen 0001
DAC8
2024 Lost and Found in Speculation: Hybrid Speculative Vulnerability Detection
abstract
Microarchitectural attacks represent a challenging and persistent threat to modern processors, exploiting inherent design vulnerabilities in processors to leak sensitive information or compromise systems. Of particular concern is the susceptibility of Speculative Execution, a fundamental part of performance enhancement, to such attacks. We introduce Specure, a novel pre-silicon verification method composing hardware fuzzing with Information Flow Tracking (IFT) to address speculative execution leakages. Integrating IFT enables two significant and non-trivial enhancements over the existing fuzzing approaches: i) automatic detection of microarchitectural information leakages vulnerabilities without golden model and ii) a novel Leakage Path coverage metric for efficient vulnerability detection. Specure identifies previously overlooked speculative execution vulnerabilities on the RISC-V BOOM processor and explores the vulnerability search space 6.45× faster than existing fuzzing techniques. Moreover, Specure detected known vulnerabilities 20× faster.
Mohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen 0125, Pouya Mahmoody, Jeyavijayan Rajendran, Ahmad-Reza Sadeghi
DAC6
2024 MABFuzz: Multi-Armed Bandit Algorithms for Fuzzing Processors
abstract
As the complexities of processors keep increasing, the task of effectively verifying their integrity and security becomes ever more daunting. The intricate web of instructions, microarchitectural features, and interdependencies woven into modern processors pose a formidable challenge for even the most diligent verification and security engineers. To tackle this growing concern, recently, researchers have developed fuzzing techniques explicitly tailored for hardware processors. However, a prevailing issue with these hardware fuzzers is their heavy reliance on static strategies to make decisions in their algorithms. To address this problem, we develop a novel dynamic and adaptive decision-making framework, MABFuzz, that uses multi-armed bandit (MAB) algorithms to fuzz processors. MABFuzz is agnostic to, and hence, applicable to, any existing hardware fuzzer. In the process of designing MABFuzz, we encounter challenges related to the compatibility of MAB algorithms with fuzzers and maximizing their efficacy for fuzzing. We overcome these challenges by modifying the fuzzing process and tailoring MAB algorithms to accommodate special requirements for hardware fuzzing. We integrate three widely used MAB algorithms in a state-of-the-art hardware fuzzer and evaluate them on three popular RISC-V-based processors. Experimental results demonstrate the ability of MABFuzz to cover a broader spectrum of processors' intricate landscapes and doing so with remarkable efficiency. In particular, MABFuzz achieves an average speedup of 53.72× in detecting vulnerabilities and an average speedup of 3.11× in achieving coverage compared to a state-of-the-art technique.
Vasudev Gohil, Rahul Kande, Chen Chen 0125, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
DATE5
2024 Beyond Random Inputs: A Novel ML-Based Hardware Fuzzing
abstract
Modern computing systems heavily rely on hardware as the root of trust. However, their increasing complexity has given rise to security-critical vulnerabilities that cross-layer attacks can exploit. Traditional hardware vulnerability detection methods, such as random regression and formal verification, have limitations. Random regression, while scalable, is slow in exploring hardware, and formal verification techniques are often concerned with manual effort and state explosions. Hardware fuzzing has emerged as an effective approach to exploring and detecting security vulnerabilities in large-scale designs like modern processors. They outperform traditional methods regarding coverage, scalability, and efficiency. However, state-of-the-art fuzzers struggle to achieve comprehensive coverage of intri-cate hardware designs within a practical timeframe, often falling short of a 70 % coverage threshold. To address this challenge, we propose a novel ML-based hardware fuzzer, ChatFuzz. Our approach leverages large language models (LLMs) to understand processor language and generate data/control flow entangled yet random machine code sequences. Reinforcement learning (RL) is integrated to guide the input generation process by rewarding the inputs using code coverage metrics. Utilizing the open-source RISC-V-based RocketCore and BOOM cores as our testbed, ChatFuzz achieves 75% condition coverage in RocketCore in just 52 minutes. This contrasts with state-of-the-art fuzzers, which demand a 30-hour timeframe for comparable condition coverage. Notably, our fuzzer can reach a 79.14% con-dition coverage rate in RocketCore by conducting approximately 199k test cases. In the case of BOOM, ChatFuzz accomplishes a remarkable 97.02% condition coverage in 49 minutes. Our analysis identified all detected bugs by The Huzz, including two new bugs in the RocketCore and discrepancies from the RISC-VISA Simulator.
Mohamadreza Rostami, Marco Chilese, Shaza Zeitouni, Rahul Kande, Jeyavijayan Rajendran, Ahmad-Reza Sadeghi
DATE5
2024 WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in Processors
Pallavi Borkar, Chen Chen 0125, Mohamadreza Rostami, Nikhilesh Singh, Rahul Kande, Ahmad-Reza Sadeghi, Chester Rebeiro, Jeyavijayan Rajendran
USENIX Security Symposium8
2024 AttackGNN: Red-Teaming GNNs in Hardware Security Using Reinforcement Learning
Vasudev Gohil, Satwik Patnaik, Dileep M. Kalathil, Jeyavijayan Rajendran
USENIX Security Symposium4
2024 LLMs for Hardware Security: Boon or Bane?
abstract
Large language models (LLMs) have emerged as transformative tools within the hardware design and verification lifecycle, offering numerous capabilities in accelerating design processes. Recent research has showcased the efficacy of LLMs in translating design specifications into source code through hardware description languages. Researchers are also using LLMs to generate test cases and write assertion rules to bolster the detection of hardware vulnerabilities. Thus, the semiconductor industry is swiftly integrating LLMs into its design workflows. However, this adoption is not without its challenges.While LLMs offer remarkable benefits, they concurrently introduce security concerns that demand a thorough examination. These concerns manifest as potential vulnerabilities indirectly introduced into the designs while generating the design code, or by directly equipping the attackers with novel avenues for exploitation. In this paper, we discuss the emerging security implications due to the capabilities introduced by LLMs in the context of hardware design verification, evaluate the capabilities of existing security detection and mitigation techniques, and highlight the possible future security attacks that use LLMs.
Rahul Kande, Vasudev Gohil, Matthew DeLorenzo, Chen Chen 0125, Jeyavijayan Rajendran
VTS5
2024 Enhancing Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Dependent Industrial Infrastructures
abstract
A robust approach for cybersecurity of industrial control systems (ICSs) that utilize programmable logic controllers (PLCs) to control critical industrial processes is demonstrated in this paper. For example, industrial water/chemical tank-based system, the liquid level sensor measurement output data may be compromised or manipulated by attackers, this can cause tank overflow, unregulated, or even malfunction. We proposed a general-purpose method called Dynamic Watermarking (DW) to secure ICSs. The basic idea of DW is that it adds a private random signal watermark on the control signal from the controller, then this watermark signal propagates through the plant and adequately converted then comes back to the attack detector. The attack detector at the actuator side can detect Man-in-the-middle (MiTM) or Masquerade attack on the cascading system in real time. The proposed method is experimentally tested and validated with several cyber-attack scenarios on a laboratory scale water tank level control system controlled by an Allen-Bradley Micro820 PLC.
Peng-Hao Huang, P. R. Kumar 0001, Jeyavijayan Rajendran, Prasad N. Enjeti
IEEE Internet Things J.4
2024 DETERRENT: Detecting Trojans Using Reinforcement Learning
abstract
The globalized nature of the integrated circuits supply chain has given rise to several security problems. The insertion of malicious components, called hardware Trojans, is one such serious problem. Since Trojans are activated only under extremely rare trigger conditions and the search space is exponentially large, detecting them is arduous. Researchers have attempted to detect Trojans by querying the design-under-test using appropriate test patterns and monitoring its logical or side-channel response. However, techniques in both these categories lack either in terms of detection accuracy or scalability for larger designs. In this work, we investigate why existing techniques fall short and use our findings to propose a new reinforcement learning (RL) framework for detecting Trojans. We carefully design two RL agents (one for each category) that navigate the exponential search space of the test patterns and return minimal sets of patterns that are most likely to detect Trojans. We overcome challenges related to scalability and efficacy through appropriate solutions. Experimental results on a variety of benchmarks demonstrate the scalability and efficacy of our RL agents, which reduce the number of test patterns significantly$(169.68\times $and$34.73\times $on average overall and$27.59\times $and$3.72\times $on average over large benchmarks) while maintaining or improving the Trojan-detection success rate compared to the state-of-the-art techniques.
Vasudev Gohil, Satwik Patnaik, Dileep M. Kalathil, Jeyavijayan Rajendran
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2024 STATION: State Encoding-Based Attack-Resilient Sequential Obfuscation
abstract
The unauthorized duplication of design intellectual property (IP) and illegal overproduction of integrated circuits (ICs) are hardware security threats plaguing the security of the globalized IC supply chain. Researchers have developed various countermeasures such as logic locking, layout camouflaging, and split manufacturing to overcome the security threat of IP piracy and unauthorized overproduction. Logic locking is a holistic solution among all countermeasures since it safeguards the design IP against untrusted entities, such as untrusted foundries, test facilities, or end-users throughout the globalized IC supply chain. There are well-known logic locking techniques for combinational circuits with well-established security properties; however, their sequential counterparts remain vulnerable. Since most practical designs are inherently sequential, it is essential to develop secure obfuscation techniques to protect sequential designs. This paper proposes a sequential obfuscation technique, STATION, building on the principles of finite state machine encoding schemes. STATION is resilient against various attacks on sequential obfuscation–input-output (I/O) query attacks and structural attacks, including the ones targeting sequential obfuscation–which have broken all state-of-the-art sequential obfuscation techniques. STATION achieves good resilience and desired security against various I/O and structural attacks, which we ascertain by launching 9 different attacks on all tested circuits. Moreover, STATION ensures tolerable overheads in power, performance, and area, such as 8.75%, 1.22%, and 5.63% on the largest tested circuit, containing 102 inputs, 7 outputs, 6.1×104 gates, 7 flip flops, 100 states, and 3.0×103 transitions.
Zhaokun Han, Aneesh Dixit, Satwik Patnaik, Jeyavijayan Rajendran
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2024 (Security) Assertions by Large Language Models
abstract
The security of computer systems typically relies on a hardware root of trust. As vulnerabilities in hardware can have severe implications on a system, there is a need for techniques to support security verification activities. Assertion-based verification is a popular verification technique that involves capturing design intent in a set of assertions that can be used in formal verification or testing-based checking. However, writing security-centric assertions is a challenging task. In this work, we investigate the use of emerging large language models (LLMs) for code generation in hardware assertion generation for security, where primarily natural language prompts, such as those one would see as code comments in assertion files, are used to produce SystemVerilog assertions. We focus our attention on a popular LLM and characterize its ability to write assertions out of the box, given varying levels of detail in the prompt. We design an evaluation framework that generates a variety of prompts, and we create a benchmark suite comprising real-world hardware designs and corresponding golden reference assertions that we want to generate with the LLM.
Rahul Kande, Hammond A. Pearce, Benjamin Tan 0001, Brendan Dolan-Gavitt, Shailja Thakur, Ramesh Karri, Jeyavijayan Rajendran
IEEE Trans. Inf. Forensics Secur.7
2023 ExploreFault: Identifying Exploitable Fault Models in Block Ciphers with Reinforcement Learning
abstract
Exploitable fault models for block ciphers are typically cipher-specific, and their identification is essential for evaluating and certifying fault attack-protected implementations. However, identifying exploitable fault models has been a complex manual process. In this work, we utilize reinforcement learning (RL) to identify exploitable fault models generically and automatically. In contrast to the several weeks/months of tedious analyses required from experts, our RL-based approach identifies exploitable fault models for protected/unprotected AES and GIFT ciphers within 12 hours. Notably, in addition to all existing fault models, we identify/discover a novel fault model for GIFT, illustrating the power and promise of our approach in exploring new attack avenues.
Sayandeep Saha, Vasudev Gohil, Satwik Patnaik, Debdeep Mukhopadhyay, Jeyavijayan Rajendran
DAC6
2023 PSOFuzz: Fuzzing Processors with Particle Swarm Optimization
abstract
Hardware security vulnerabilities in computing systems compromise the security defenses of not only the hardware but also the software running on it. Recent research has shown that hardware fuzzing is a promising technique to efficiently detect such vulnerabilities in large-scale designs such as modern processors. However, the current fuzzing techniques do not adjust their strategies dynamically toward faster and higher design space exploration, resulting in slow vulnerability detection, evident through their low design coverage. To address this problem, we propose PSOFuzz, which uses particle swarm optimization (PSO) to schedule the mutation operators and to generate initial input programs dynamically with the objective of detecting vulnerabilities quickly. Unlike traditional PSO, which finds a single optimal solution, we use a modified PSO that dynamically computes the optimal solution for selecting mutation operators required to explore new design regions in hardware. We also address the challenge of inefficient initial seed generation by employing PSO-based seed generation. Including these optimizations, our final formulation outperforms fuzzers without PSO. Experiments show that PSOFuzz achieves up to 15.25× speedup for vulnerability detection and up to 2.22× speedup for coverage compared to the state-of-the-art simulation-based hardware fuzzer.
Chen Chen 0125, Vasudev Gohil, Rahul Kande, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
ICCAD5
2023 HyPFuzz: Formal-Assisted Processor Fuzzing
Chen Chen 0125, Rahul Kande, Nathan Nguyen, Flemming Andersen, Aakash Tyagi, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
USENIX Security Symposium7
2023 FuncTeller: How Well Does eFPGA Hide Functionality?
Zhaokun Han, Mohammed Shayan, Aneesh Dixit, Mustafa M. Shihab, Yiorgos Makris, Jeyavijayan Rajendran
USENIX Security Symposium6
2022 ATTRITION: Attacking Static Hardware Trojan Detection Techniques Using Reinforcement Learning
abstract
Stealthy hardware Trojans (HTs) inserted during the fabrication of integrated circuits can bypass the security of critical infrastructures. Although researchers have proposed many techniques to detect HTs, several critical limitations exist, including: (i) a low success rate of HT detection, (ii) high algorithmic complexity, and (iii) a large number of test patterns. Furthermore, as we show in this work the most pertinent drawback of prior (including state-of-the-art) detection techniques stems from an incorrect evaluation methodology, i.e., they assume that an adversary inserts HTs randomly. Such inappropriate adversarial assumptions enable detection techniques to claim high HT detection accuracy, leading to a "false sense of security." To the best of our knowledge, despite more than a decade of research on detecting HTs inserted during fabrication, there have been no concerted efforts to perform a systematic evaluation of HT detection techniques.
Vasudev Gohil, Satwik Patnaik, Jeyavijayan Rajendran
CCS4
2022 Trusting the trust anchor: towards detecting cross-layer vulnerabilities with hardware fuzzing
abstract
The rise in the development of complex and application-specific commercial and open-source hardware and the shrinking verification time are causing numerous hardware-security vulnerabilities. Traditional verification techniques are limited in both scalability and completeness. Research in this direction is hindered due to the lack of robust testing benchmarks. In this paper, in collaboration with our industry partners, we built an ecosystem mimicking the hardware-development cycle where we inject bugs inspired by real-world vulnerabilities into RISC-V SoC design and organized an open-to-all bug-hunting competition. We equipped the participating researchers with industry-standard static and dynamic verification tools in a ready-to-use environment. The findings from our competition shed light on the strengths and weaknesses of the existing verification tools and highlight the potential for future research in developing new vulnerability detection techniques.
Chen Chen 0125, Rahul Kande, Pouya Mahmoody, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
DAC5
2022 DETERRENT: detecting trojans using reinforcement learning
abstract
Insertion of hardware Trojans (HTs) in integrated circuits is a pernicious threat. Since HTs are activated under rare trigger conditions, detecting them using random logic simulations is infeasible. In this work, we design a reinforcement learning (RL) agent that circumvents the exponential search space and returns a minimal set of patterns that is most likely to detect HTs. Experimental results on a variety of benchmarks demonstrate the efficacy and scalability of our RL agent, which obtains a significant reduction (169×) in the number of test patterns required while maintaining or improving coverage (95.75%) compared to the state-of-the-art techniques.
Vasudev Gohil, Satwik Patnaik, Dileep M. Kalathil, Jeyavijayan Rajendran
DAC5
2022 Hardware IP Protection against Confidentiality Attacks and Evolving Role of CAD Tool
abstract
With growing use of hardware intellectual property (IP) based integrated circuits (IC) design and increasing reliance on a globalized supply chain, the threats to confidentiality of hardware IPs have emerged as major security concerns to the IP producers and owners. These threats are diverse, including reverse engineering (RE), piracy, cloning, and extraction of design secrets, and span different phases of electronics life cycle. The academic research community and the semiconductor industry have made significant efforts over the past decade on developing effective methodologies and CAD tools targeted to protect hardware IPs against these threats. These solutions include watermarking, logic locking, obfuscation, camouflaging, split manufacturing, and hardware redaction. This paper focuses on key topics on confidentiality of hardware IPs encompassing the major threats, protection approaches, security analysis, and metrics. It discusses the strengths and limitations of the major solutions in protecting hardware IPs against the confidentiality attacks, and future directions to address the limitations in the modern supply chain ecosystem.
Swarup Bhunia, Amitabh Das, Saverio Fazzari, Vivian Kammler, David Kehlet, Jeyavijayan Rajendran, Ankur Srivastava 0001
ICCAD6
2022 TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities
Rahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig, Ahmad-Reza Sadeghi, Aakash Tyagi, Jeyavijayan Rajendran
USENIX Security Symposium7
2021 Organizing The World's Largest Hardware Security Competition: Challenges, Opportunities, and Lessons Learned
abstract
The recent trend of providing fast and flexible hardware platforms as-a-service coupled with the advancements in hardware design tools have significantly reduced the effort of designing new hardware. Additionally, with the advent of open-source Instruction Set Architectures (ISAs) such as OpenRISC and RISC-V, we witness the rise of a wide variety of open-source and commercial processor cores and System-On-Chip (SoC) designs in a short time.
Ahmad-Reza Sadeghi, Jeyavijayan Rajendran, Rahul Kande
ACM Great Lakes Symposium on VLSI2
2021 Does logic locking work with EDA tools?
Zhaokun Han, Muhammad Yasin, Jeyavijayan Rajendran
USENIX Security Symposium3
2021 Games, Dollars, Splits: A Game-Theoretic Analysis of Split Manufacturing
abstract
Split manufacturing has been proposed as a defense to prevent threats like intellectual property (IP) piracy and illegal overproduction of integrated circuits (ICs). Over the last few years, researchers have developed a plethora of attack and defense techniques, creating a cat-and-mouse game between defending designers and attacking foundries. In this paper, we take an orthogonal approach to this ongoing research in split manufacturing; rather than developing an attack or a defense technique, we propose a means to analyze different attack and defense techniques. To that end, we develop a game-theoretic framework that helps researchers evaluate their new and existing attack and defense techniques. We model two attack scenarios using two different types of games and obtain the optimal defense strategies. We perform extensive simulations with our proposed framework, using nine different attacks and a class of placement and routing-based defense techniques on various benchmarks to gain deeper insights into split manufacturing. For instance, our framework indicates that the optimal defense techniques in the two attack scenarios are the same. Moreover, larger benchmarks are secure by naïve split manufacturing and do not require any additional defense technique under our cost model and considered attacks. We also uncover a counter-intuitive finding—an attacker using the network-flow attack should not use all the hints; instead, she should use only a subset.
Vasudev Gohil, Mark Tressler, Kevin Sipple, Satwik Patnaik, Jeyavijayan Rajendran
IEEE Trans. Inf. Forensics Secur.5
2020 Multi-Objective Strategies for Stripped-Functionality Logic Locking
abstract
Logic locking acts as powerful countermeasure against piracy and reverse engineering attacks on the Integrated circuit (IC) supply chain. Stripped functionality logic locking (SFLL) represents the state-of-the-art in logic locking. SFLL delivers high resilience against certain attacks; however, it can protect only a small fraction of the design. Moreover, it fails to achieve a high corruption rate at the circuit outputs. In this paper, we explore strategies for deploying SFLL in a way that optimizes both corruption rate and resilience while protecting a large fraction of the design. The proposed joint optimization framework leverages the principles of VLSI testing to meet desired objectives cost-effectively.
Zhaokun Han, Muhammad Yasin, Jeyavijayan Rajendran
ISCAS3
2020 Schmitt Trigger-Based Key Provisioning for Locking Analog/RF Integrated Circuits
abstract
Analog/RF performance locking techniques insert configurable components to obfuscate the biasing or the design parameters of the secured analog block. The locked circuit meets the specifications only under a specific configuration decided by the correct common key, shared by all chip instances of the same design. Key provisioning enables the design of distinct user keys for individual chip instances. This area has received little research attention, and a naive approach yields large area overhead when increasing the key size. We propose a new approach based on a Schmitt trigger (ST) circuit with configurable hysteresis. The proposed key provisioning is compatible with existing analog locking techniques and has a constant area overhead regardless of key size. This approach is tested with three analog/RF circuits to demonstrate its area scalability and effectiveness on security.
Adriana C. Sanabria-Borbon, Nithyashankari Gummidipoondi Jayasankaran, Sir Yee Lee, Edgar Sánchez-Sinencio, Jiang Hu 0001, Jeyavijayan Rajendran
ITC6
2020 Keynote: A Disquisition on Logic Locking
abstract
The fabless business model has given rise to many security threats, including piracy of intellectual property (IP), overproduction, counterfeiting, reverse engineering (RE), and hardware Trojans (HT). Such threats severely undermine the benefits of the fabless model. Among the countermeasures developed to thwart piracy and RE attacks, logic locking has emerged as a promising and versatile solution that is being adopted by both academia and industry. The idea behind logic locking is to lock the design using a “keying” mechanism; only the rightful owner has control over the locked design. Therefore, the design remains nonfunctional without the knowledge of the key. In this article, we survey the evolution of logic locking over the last decade. We introduce various “cat-and-mouse” games involved in logic locking along with its novel applications-including, processor pipelines, graphics processing units (GPUs), and analog circuits. We aim this article to be a primer for researchers interested in developing new logic-locking techniques and employing logic locking in different application domains.
Abhishek Chakraborty 0001, Nithyashankari Gummidipoondi Jayasankaran, Yuntao Liu 0001, Jeyavijayan Rajendran, Ozgur Sinanoglu, Ankur Srivastava 0001, Yang Xie 0001, Muhammad Yasin, Michael Zuzak
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2020 Thwarting Replication Attack Against Memristor-Based Neuromorphic Computing System
abstract
Neuromorphic architectures are widely used in many applications for advanced data processing and often implement proprietary algorithms. However, in an adversarial scenario, such systems may face elaborate security attacks including learning attack. In this article, we prevent an attacker with physical access from learning the proprietary algorithm implemented by the neuromorphic hardware. For this purpose, we leverage the obsolescence effect in memristors to judiciously reduce the accuracy of outputs for any unauthorized user. For a legitimate user, we regulate the obsolescence effect, thereby maintaining the accuracy of outputs in a suitable range. We extensively examine the feasibility of our proposed method with four datasets. We experiment under different settings, such as activation functions and constraints such as process variations, and estimate the calibration overhead. The security versus cost and performance versus resistance range tradeoffs for different applications are also analyzed. We then prove that the defense is still valid even if the attacker has the prior knowledge of the defense mechanism. Overall, our methodology is compatible with mainstream classification applications, memristor devices, and security and performance constraints.
Chaofei Yang, Beiye Liu, Hai Li 0001, Yiran Chen 0001, Mark Barnell, Qing Wu 0002, Wujie Wen, Jeyavijayan Rajendran
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.8
2020 Breaking Analog Locking Techniques
abstract
Similar to digital circuits, analog circuits are also susceptible to supply-chain attacks. There are several analog locking techniques proposed to combat these supply-chain attacks. However, there exists no elaborate evaluation procedure to estimate the resilience offered by these techniques. Evaluating analog defenses requires the usage of non-Boolean variables, such as bias current and gain. Hence, in this work, we evaluate the resilience of the analog-only locks and analog and mixed-signal (AMS) locks using satisfiability modulo theories (SMTs). We demonstrate our attack on five analog locking techniques and three AMS locking techniques. The attack is demonstrated on commonly used circuits, such as bandpass filter (BPF), low-noise amplifier (LNA), and low-dropout (LDO) voltage regulator. Attack results on analog-only locks show that the attacker, knowing the required bias current or voltage range, can determine the key. Likewise, knowing the protected input patterns (PIPs), the attacker can determine the key to unlock the AMS locks. We then extend our attack to break the existing analog camouflaging technique.
Nithyashankari Gummidipoondi Jayasankaran, Adriana C. Sanabria-Borbon, Amr Abuellil, Edgar Sánchez-Sinencio, Jiang Hu 0001, Jeyavijayan Rajendran
IEEE Trans. Very Large Scale Integr. Syst.6
2019 Layout recognition attacks on split manufacturing
abstract
One technique to prevent attacks from an untrusted foundry is split manufacturing, where only a part of the layout is sent to the untrusted high-end foundry, and the rest is manufactured at a trusted low-end foundry. The untrusted foundry has front-end-of-line (FEOL) layout and the original circuit netlist and attempts to identify critical components on the layout for Trojan insertion. Although defense methods for this scenario have been developed, the corresponding attack technique is not well explored. For instance, Boolean satisfiability (SAT) based bijective mapping attack is mentioned without detailed research. Hence, the defense methods are mostly evaluated with the k-security metric without actual attacks. We provide the first systematic study, to the best of our knowledge, on attack techniques in this scenario. Besides of implementing SAT-based bijective mapping attack, we develop a new attack technique based on structural pattern matching. Experimental comparison with bijective mapping attack shows that the new attack technique achieves about the same success rate with much faster speed for cases without the k-security defense, and has a much better success rate at the same runtime for cases with k-security defense. The results offer an alternative and practical interpretation for k-security in split manufacturing.
Lang Feng 0001, Jeyavijayan Rajendran, Jiang Hu 0001
ASP-DAC3
2019 SFLL-HLS: Stripped-Functionality Logic Locking Meets High-Level Synthesis
abstract
Logic locking has emerged as a promising countermeasure against piracy and reverse engineering attacks on integrated circuits. The state-of-the-art logic locking techniques, more specifically stripped-functionality logic locking (SFLL), offer provable security guarantees against many attacks. However, these techniques focus on protecting individual modules or even parts of a module, failing to deliver system-wide security. This paper sheds light on integrating logic locking with high-level synthesis (HLS) in an attempt to deliver system-wide security. We demonstrate the integration of SFLL with LegUp HLS tool for an image processing application.
Muhammad Yasin, Chongzhi Zhao, Jeyavijayan Rajendran
ICCAD3
2019 Red Teaming a Multi-Colored Bluetooth Bulb
abstract
Given the proliferation of Internet-of-Things (IoT) devices, their security has become an important concern due to the nature of their usage. In this work, we demonstrate several ways of exfiltrating data in a Bluetooth-enabled electric bulb. We have developed four different ways of exfiltrating data and analyzed them for generality, throughput, efficiency, and stealthiness.
Ryan Vrecenar, Michael Hall, Joshua Zshiesche, Mahesh Naidu, Jeyavijayan Rajendran, Stavros Kalafatis
ICCD5
2019 Breaking Analog Locking Techniques via Satisfiability Modulo Theories
abstract
Similar to digital circuits, analog circuits are also susceptible to supply-chain attacks, such as intellectual property (IP) piracy, counterfeiting, and overproduction. Hence, analog locking techniques have been proposed to combat supply-chain attacks. However, there exists no evaluation procedure to estimate the resilience offered by these defense techniques. Evaluating analog defense techniques requires the usage of non-Boolean variables, such as bias current, bias voltage, and gain. However, it cannot be handled by the Boolean satisfiability (SAT) attack. In this work, we propose an evaluation technique based on satisfiability modulo theories (SMT). We demonstrate our attack on four state-of-the-art analog locking techniques using commonly used circuits, such as bandpass filter (BPF), LC oscillator, quadrature oscillator, and class-D amplifiers. Our results show that the attacker, knowing the required bias current values, can determine the key in polynomial time. We also show that even if he/she has only partial information about the bias currents, the search space can be reduced from exponential to a polynomial number of keys. We then extend our attack to break existing analog camouflaging techniques.
Nithyashankari Gummidipoondi Jayasankaran, Adriana C. Sanabria-Borbon, Amr Abuellil, Edgar Sánchez-Sinencio, Jiang Hu 0001, Jeyavijayan Rajendran
ITC6
2019 HardFails: Insights into Software-Exploitable Hardware Bugs
Ghada Dessouky, David Gens, Patrick Haney, Garrett Persyn, Arun K. Kanuparthi, Hareesh Khattri, Jason M. Fung, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
USENIX Security Symposium9
2019 Special Session: Countering IP Security threats in Supply chain
abstract
The continuing decrease in feature size of integrated circuits, and the increase of the complexity and cost of design and fabrication has led to outsourcing the design and fabrication of integrated circuits to third parties across the globe, and in turn has introduced several security vulnerabilities. The adversaries in the supply chain can pirate integrated circuits, overproduce these circuits, perform reverse engineering, and/or insert hardware Trojans in these circuits. Developing countermeasures against such security threats is highly crucial. Accordingly, this paper first develops a learning-based trust verification framework to detect hardware Trojans. To tackle Trojan insertion, IP piracy and overproduction, logic locking schemes and in particular stripped functionality logic locking is discussed and its resiliency against the state-of-the-art attacks is investigated.
Hassan Salmani, Tamzidul Hoque, Swarup Bhunia, Muhammad Yasin, Jeyavijayan Rajendran, Naghmeh Karimi
VTS5
2018 Towards provably-secure performance locking
abstract
Locking the functionality of an integrated circuit (IC) thwarts attacks such as intellectual property (IP) piracy, hardware Trojans, overbuilding, and counterfeiting. Although functional locking has been extensively investigated, locking the performance of an IC has been little explored. In this paper, we develop provably-secure performance locking, where only on applying the correct key the IC shows superior performance; for an incorrect key, the performance of the IC degrades significantly. This leads to a new business model, where the companies can design a single IC capable of different performances for different users. We develop mathematical definitions of security and theoretically, and experimentally prove the security against the state-of-the-art-attacks. We implemented performance locking on a FabScalar microprocessor, achieving a degradation in instructions per clock cycle (IPC) of up to 77% on applying an incorrect key, with an overhead of 0.6%, 0.2%, and 0% for area, power, and delay, respectively.
Monir Zaman, Abhrajit Sengupta, Danqing Liu, Ozgur Sinanoglu, Yiorgos Makris, Jeyavijayan Rajendran
DATE6
2018 Towards provably-secure analog and mixed-signal locking against overproduction
abstract
Similar to digital circuits, analog and mixed-signal (AMS) circuits are also susceptible to supply-chain attacks such as piracy, overproduction, and Trojan insertion. However, unlike digital circuits, supply-chain security of AMS circuits is less explored. In this work, we propose to perform "logic locking" on digital section of the AMS circuits. The idea is to make the analog design intentionally suffer from the effects of process variations, which impede the operation of the circuit. Only on applying the correct key, the effect of process variations are mitigated, and the analog circuit performs as desired. We provide the theoretical guarantees of the security of the circuit, and along with simulation results for the band-pass filter, low-noise amplifier, and low-dropout regulator, we also show experimental results of our technique on a band-pass filter.
Nithyashankari Gummidipoondi Jayasankaran, Adriana C. Sanabria-Borbon, Edgar Sánchez-Sinencio, Jiang Hu 0001, Jeyavijayan Rajendran
ICCAD5
2018 Special session: Recent developments in hardware security
abstract
In this session, we explore some of the recent challenges facing hardware security: (i) Challenges in the implementation of post-quantum crypto algorithms, (ii) Impact of aging on security, and (ii) Security challenges in machine learning.
Rosario Cammarota, Naghmeh Karimi, Siddharth Garg, Jeyavijayan Rajendran
VTS4
2018 The Cat and Mouse in Split Manufacturing
Jiang Hu 0001, Guofeng Li, Jeyavijayan Rajendran
IEEE Trans. Very Large Scale Integr. Syst.5
2017 Routing perturbation for enhanced security in split manufacturing
abstract
Split manufacturing can mitigate security vulnerabilities at untrusted foundries by exposing only partial designs. Even so, attackers can make educated guess according to design conventions and thereby recover entire chip designs. In this work, a routing perturbation-based defense method is proposed such that such attacks become very difficult while wirelength/timing overhead is restricted to be very small. Experimental results on benchmark circuits confirm the effectiveness of the proposed techniques. The new techniques also significantly outperform the latest previous work.
Jiang Hu 0001, Jeyavijayan Rajendran
ASP-DAC4
2017 Security analysis of Anti-SAT
abstract
Logic encryption protects integrated circuits (ICs) against intellectual property (IP) piracy and overbuilding attacks by encrypting the IC with a key. A Boolean satisfiability (SAT) based attack breaks all existing logic encryption technique within few hours. Recently, a defense mechanism known as Anti-SAT was presented that protects against SAT attack, by rendering the SAT-attack effort exponential in terms of the number of key gates. In this paper, we highlight the vulnerabilities of Anti-SAT and propose signal probability skew (SPS) attack against Anti-SAT block. SPS attack leverages the structural traces in Anti-SAT block to identify and isolate Anti-SAT block. The attack is 100% successful on all variants of Anti-SAT block. SPS attack is scalable to large circuits, as it breaks circuits with up to 22K gates within two minutes.
Muhammad Yasin, Bodhisatwa Mazumdar, Ozgur Sinanoglu, Jeyavijayan Rajendran
ASP-DAC4
2017 Provably-Secure Logic Locking: From Theory To Practice
abstract
Logic locking has been conceived as a promising proactive defense strategy against intellectual property (IP) piracy, counterfeiting, hardware Trojans, reverse engineering, and overbuilding attacks. Yet, various attacks that use a working chip as an oracle have been launched on logic locking to successfully retrieve its secret key, undermining the defense of all existing locking techniques. In this paper, we propose stripped-functionality logic locking (SFLL), which strips some of the functionality of the design and hides it in the form of a secret key(s), thereby rendering on-chip implementation functionally different from the original one. When loaded onto an on-chip memory, the secret keys restore the original functionality of the design. Through security-aware synthesis that creates a controllable mismatch between the reverse-engineered netlist and original design, SFLL provides a quantifiable and provable resilience trade-off between all known and anticipated attacks. We demonstrate the application of SFLL to large designs (>100K gates) using a computer-aided design (CAD) framework that ensures attaining the desired security level at minimal implementation cost, 8%, 5%, and 0.5% for area, power, and delay, respectively. In addition to theoretical proofs and simulation confirmation of SFLL's security, we also report results from the silicon implementation of SFLL on an ARM Cortex-M0 microprocessor in 65nm technology.
Muhammad Yasin, Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Mohammed Ashraf, Jeyavijayan Rajendran, Ozgur Sinanoglu
CCS5
2017 What to Lock?: Functional and Parametric Locking
abstract
Logic locking is an intellectual property (IP) protection technique that prevents IP piracy, reverse engineering and overbuilding attacks by the untrusted foundry or end-users. Existing logic locking techniques are all based on locking the functionality; the design/chip is nonfunctional unless the secret key has been loaded. Existing techniques are vulnerable to various attacks, such as sensitization, key-pruning, and signal skew analysis enabled removal attacks. In this paper, we propose a tenacious and traceless logic locking technique, TTlock, that locks functionality and provably withstands all known attacks, such as SAT-based, sensitization, removal, etc. TTLock protects a secret input pattern; the output of a logic cone is flipped for that pattern, where this flip is restored only when the correct key is applied. Experimental results confirm our theoretical expectations that the computational complexity of attacks launched on TTLock grows exponentially with increasing key-size, while the area, power, and delay overhead increases only linearly. In this paper, we also coin ``parametric locking," where the design/chip behaves as per its specifications (performance, power, reliability, etc.) only with the secret key in place, and an incorrect key downgrades its parametric characteristics. We discuss objectives and challenges in parametric locking.
Muhammad Yasin, Abhrajit Sengupta, Benjamin Carrión Schäfer, Yiorgos Makris, Ozgur Sinanoglu, Jeyavijayan Rajendran
ACM Great Lakes Symposium on VLSI6
2017 Making split fabrication synergistically secure and manufacturable
abstract
Split fabrication is a promising approach to security against attacks by untrusted foundries. While existing split fabrication methods consider the overhead of conventional objectives such as wirelength and timing, they mostly neglect manufacturability - an unavoidable challenge in nanometer technologies. Observing that security and manufacturability can be addressed in a synergistic manner, this work introduces routing techniques that can simultaneously improve both security and manufacturability in terms of either Chemical Mechanical Planarization (CMP) uniformity or Self-Aligned Double Patterning (SADP) compliance. The effectiveness of these techniques is confirmed by experiments on benchmark circuits.
Lang Feng 0001, Jiang Hu 0001, Wai-Kei Mak, Jeyavijayan Rajendran
ICCAD5
2017 Making split fabrication synergistically secure and manufacturable
abstract
Split fabrication is a promising approach to security against attacks by untrusted foundries. While existing split fabrication methods consider the overhead of conventional objectives such as wirelength and timing, they mostly neglect manufacturability - an unavoidable challenge in nanometer technologies. Observing that security and manufacturability can be addressed in a synergistic manner, this work introduces routing techniques that can simultaneously improve both security and manufacturability in terms of either Chemical Mechanical Planarization (CMP) uniformity or Self-Aligned Double Patterning (SADP) compliance. The effectiveness of these techniques is confirmed by experiments on benchmark circuits.
Lang Feng 0001, Jiang Hu 0001, Wai-Kei Mak, Jeyavijayan Rajendran
ICCAD5
2017 Front-end-of-line attacks in split manufacturing
abstract
By splitting the manufacturing of integrated circuits into back-end-of-line (BEOL) and front-end-of-line (FEOL) at different foundries, the vulnerabilities to attacks by a untrusted foundry is considerably alleviated. Most previous works focus on the scenario of only BEOL attacks at untrusted FEOL foundries. In this work, we study a largely unexplored scenario, where FEOL attacks are launched by an untrusted BEOL foundry. A geometric pattern match attack and a machine learningbased attack technique are investigated. Defense techniques against the FEOL attacks are also discussed. The effectiveness of these techniques is demonstrated by experiments on benchmark circuits.
Tri Cao, Jiang Hu 0001, Jeyavijayan Rajendran
ICCAD4
2017 An overview of hardware intellectual property protection
abstract
Over the last fifteen years, a plethora of techniques has been developed to protect the hardware from piracy attacks from different sets of attackers in the supply chain — untrusted foundry, untrusted user, untrusted testing facility, or a combination thereof. This article explains their threat model(s), capabilities, and limitations. It also highlights several approaches that are developed to incorporate these techniques in conventional logic designs. Finally, the article explains provably-secure IP protection techniques and outline the challenges involved in making those technique practical.
Jeyavijayan Rajendran
ISCAS1
2017 DFS covert channels on multi-core platforms
abstract
Covert channels provide a secret communication medium between two malicious processes to exfiltrate information stealthily that violates the security policy of a system. In this paper, we demonstrate a new covert timing channel attack that exploits the CPU operating frequencies with different power governors in real system environment. In particular, we establish how two colluding processes-a trojan and a spy can modulate the CPU frequency to create a powerful, high-capacity and robust covert channel. We implement this covert channel both in a single threaded and simultaneous multi-threading (SMT) environment and show the feasibility of such a communication. Our experiments on Intel Xeon server platform demonstrate dynamic frequency scaling covert channels that can achieve up to 20 bits/second.
Murugappan Alagappan, Jeyavijayan Rajendran, Milos Doroslovacki, Guru Venkataramani
VLSI-SoC2
2017 Innovative practices session 3C hardware security
abstract
Start of the above-titled section of the conference proceedings record.
Jeyavijayan Rajendran, Peilin Song, Suriyaprakash Natarajan
VTS1
2017 Testing the Trustworthiness of IC Testing: An Oracle-Less Attack on IC Camouflaging
abstract
Test of integrated circuits (ICs) is essential to ensure their quality; the test is meant to prevent defective and out-of-spec ICs from entering into the supply chain. The test is conducted by comparing the observed IC output with the expected test responses for a set of test patterns; the test patterns are generated using automatic test pattern generation algorithms. Existing test-pattern generation algorithms aim to achieve higher fault coverage at lower test costs. In an attempt to reduce the size of test data, these algorithms reveal the maximum information about the internal circuit structure. This is realized through sensitizing the internal nets to the outputs as much as possible, unintentionally leaking the secrets embedded in the circuit as well. In this paper, we present HackTest, an attack that extracts secret information generated in the test data, even if the test data do not explicitly contain the secret. HackTest can break the existing intellectual property protection techniques, such as camouflaging, within 2 min for our benchmarks using only the camouflaged layout and the test data. HackTest applies to all existing camouflaged gate-selection techniques and is successful even in the presence of the state-of-the-art test infrastructure, i.e., test data compression circuits. Our attack necessitates that the IC test data generation algorithms can be reinforced with security.
Muhammad Yasin, Ozgur Sinanoglu, Jeyavijayan Rajendran
IEEE Trans. Inf. Forensics Secur.3
2016 The cat and mouse in split manufacturing
abstract
Split manufacturing of integrated circuits eliminates vulnerabilities introduced by an untrusted foundry by manufacturing only a part of design at an untrusted high-end foundry and the remaining part at a trusted low-end foundry. Most researchers have focused on attack and defenses for hierarchical designs and/or use a relatively high-end trusted foundry, leading to high cost. We propose an attack and defense for split manufacturing for industry-standard/relevant flattened designs. Our attack uses network-flow model and outperforms previous attacks. We also develop a defense technique using placement perturbation, while considering overhead. The effectiveness of our techniques is demonstrated on benchmark circuits.
Jiang Hu 0001, Jeyavijayan Rajendran
DAC4
2016 Activation of logic encrypted chips: Pre-test or post-test?
Muhammad Yasin, Samah Mohamed Saeed, Jeyavijayan Rajendran, Ozgur Sinanoglu
DATE3
2016 Security of neuromorphic computing: thwarting learning attacks using memristor's obsolescence effect
abstract
Neuromorphic architectures are widely used in many applications for advanced data processing, and often implements proprietary algorithms. In this work, we prevent an attacker with physical access from learning the proprietary algorithm implemented by the neuromorphic hardware. For this purpose, we leverage the obsolescence effect in memristors to judiciously reduce the accuracy of outputs for any unauthorized user. For a legitimate user, we regulate the obsolescence effect, thereby controlling the accuracy of outputs. We also analyze the security vs. cost trade-offs for different applications. Our methodology is compatible with mainstream classification applications, memristor devices, and security and performance constraints.
Chaofei Yang, Beiye Liu, Hai Li 0001, Yiran Chen 0001, Wujie Wen, Mark Barnell, Qing Wu 0002, Jeyavijayan Rajendran
ICCAD8
2016 CamoPerturb: secure IC camouflaging for minterm protection
abstract
Integrated circuit (IC) camouflaging is a layout-level technique that thwarts reverse engineering attacks on ICs by introducing camouflaged cells that look alike, but can implement one of many possible Boolean functions. Existing camouflaging techniques have been broken by a recent decamouflaging attack, which uses Boolean satisfiability (SAT) techniques to compute specialized discriminating input patterns that prune the functionality search space quickly. This paper presents CamoPerturb, a countermeasure to thwart the decamouflaging attack by integrating logic perturbation with IC camouflaging. CamoPerturb, contrary to all the existing camouflaging schemes, perturbs the functionality of the given design minimally, i.e., adds/removes one minterm, rather than camouflaging the design. A separate camouflaged block CamoFix restores the perturbed minterm, recovering the functionality of the design. The perturbed minterm is the designer's secret and is incorporated into CamoFix using camouflaged cells. CamoPerturb renders the decamouflaging attack effort exponentially harder in the number of camouflaged gates while its overhead grows linearly. The paper presents formal proofs for the security of CamoPerturb along with experimental results.
Muhammad Yasin, Bodhisatwa Mazumdar, Ozgur Sinanoglu, Jeyavijayan Rajendran
ICCAD4
2016 Hardware-based attacks to compromise the cryptographic security of an election system
abstract
We present our experiences in implementing hardware-based attacks to subvert the results of an election system. The election system was outlined by the Cyber Security Awareness Week (CSAW) Embedded Security Challenge (ESC) competition in 2015, held at the New York University (NYU). The system had multiple layers of security and primarily used homomorphic encryption. The competition presented a challenge to hack the election system such that a preferred candidate wins the election. We cryptanalyzed the given election system to evaluate the effectiveness of various theoretical and practical attacks, and used a custom designed embedded system to demonstrate our attacks. The embedded system was implemented on a Nexys 4 DDR Artix-7 FPGA board. Our work, which earned the first place in the competition, demonstrates that low-cost hardware-based attacks can indeed lead to catastrophic consequences.
Mohammad-Mahdi Bidmeshki, Gaurav Rajavendra Reddy, Liwei Zhou, Jeyavijayan Rajendran, Yiorgos Makris
ICCD4
2016 Securing pressure measurements using SensorPUFs
abstract
We present a micro-electro-mechanical (MEM) relay based physical unclonable function (PUF) that is capable of sensing pressure while providing an assurance of authenticity. The unique properties of the SensorPUF arise from the pressure sensitivity of electrostatically actuated MEM relay structures. Thus, pres sure sensing is made secure by the integration of the sensor reading with the challenge-response generation circuitry. We evaluate the pressure SensorPUF design in terms of uniqueness, diffuseness, uniformity and bit-aliasing while considering the effect of pressure.
Jeyavijayan Rajendran, Jack Tang, Ramesh Karri
ISCAS1
2016 On Improving the Security of Logic Locking
abstract
Due to globalization of integrated circuit (IC) design flow, rogue elements in the supply chain can pirate ICs, overbuild ICs, and insert hardware Trojans. EPIC locks the design by randomly inserting additional gates; only a correct key makes the design to produce correct outputs. We demonstrate that an attacker can decipher the locked netlist, in a time linear to the number of keys, by sensitizing the key-bits to the output. We then develop techniques to fix this vulnerability and make an attacker's effort truly exponential in the number of inserted keys. We introduce a new security metric and a method to deliver strong logic locking.
Muhammad Yasin, Jeyavijayan Rajendran, Ozgur Sinanoglu, Ramesh Karri
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2016 Building Trustworthy Systems Using Untrusted Components: A High-Level Synthesis Approach
abstract
Trustworthiness of system-on-chip designs is undermined by malicious logic (Trojans) in third-party intellectual properties (3PIPs). In this paper, duplication, diversity, and isolation principles have been extended to detect build trustworthy systems using untrusted, potentially Trojan-infected 3PIPs. We use a diverse set of vendors to prevent collusions between the 3PIPs from the same vendor. We identify design constraints for Trojan detection to achieving detection, collusion prevention, and isolating the Trojan-infected 3PIP, and incorporate them during high-level synthesis. In addition, we develop techniques to reduce the number of vendors. The effectiveness of the proposed techniques is validated using the high-level synthesis benchmarks.
Jeyavijayan Rajendran, Ozgur Sinanoglu, Ramesh Karri
IEEE Trans. Very Large Scale Integr. Syst.1
2015 Detecting malicious modifications of data in third-party intellectual property cores
abstract
Globalization of the system-on-chip (SoC) design flow has created opportunities for rogue elements in the intellectual property (IP) vendor companies to insert malicious circuits (a.k.a. hardware Trojans) into their IPs. We propose to formally verify third party IPs (3PIPs) for unauthorized corruption of critical data such as secret key. Our approach develops properties to identify corruption of critical registers. Furthermore, we describe two attacks where computations can be performed on corrupted data without corrupting the critical register. We develop additional properties to detect such attacks. We validate our technique using Trojans in 8051 and RISC processors and AES designs from Trust-Hub.
Jeyavijayan Rajendran, Vivekananda Vedula, Ramesh Karri
DAC1
2015 Nano Meets Security: Exploring Nanoelectronic Devices for Security Applications
abstract
Information security has emerged as an important system and application metric. Classical security solutions use algorithmic mechanisms that address a small subset of emerging security requirements, often at high-energy and performance overhead. Further, emerging side-channel and physical attacks can compromise classical security solutions. Hardware security solutions overcome many of these limitations with less energy and performance overhead. Nanoelectronics-based hardware security preserves these advantages while enabling conceptually new security primitives and applications. This tutorial paper shows how one can develop hardware security primitives by exploiting the unique characteristics such as complex device and system models, bidirectional operation, and nonvolatility of emerging nanoelectronic devices. This paper then explains the security capabilities of several emerging nanoelectronic devices: memristors, resistive random-access memory, contact-resistive random-access memory, phase change memories, spin torque-transfer random-access memory, orthogonal spin transfer random access memory, graphene, carbon nanotubes, silicon nanowire field-effect transistors, and nanoelectronic mechanical switches. Further, the paper describes hardware security primitives for authentication, key generation, data encryption, device identification, digital forensics, tamper detection, and thwarting reverse engineering. Finally, the paper summarizes the outstanding challenges in using emerging nanoelectronic devices for security.
Jeyavijayan Rajendran, Ramesh Karri, James B. Wendt, Miodrag Potkonjak, Nathan R. McDonald, Garrett S. Rose, Bryant T. Wysocki
Proc. IEEE1
2015 Improving Tolerance to Variations in Memristor-Based Applications Using Parallel Memristors
abstract
Memristors are being explored for a wide variety of applications such as neuromorphic computing, memory and digital logic. However, they suffer from process variations like any other nanodevice, which in turn impacts their applicability. The effect of process variations, specifically variation in thickness, is highly non-linear on memristors; the effect is greater near the lower memristance region (near M$_{\rm on}$) than in the higher memristance region (near M$_{\rm off}$). Due to this non-linear effect, many applications do not use the lower memristance values. Consequently, the application's functionality and performance is affected. In this work, we propose a technique called parallel memristors. In this technique, instead of using a single memristor, the application uses several memristors connected in parallel. Each memristor in this parallel structure is programmed to a higher memristance value to tolerate variations. Since many memristors are connected in parallel, the effective memristance value can be near the M$_{\rm on}$value, thereby achieving high-speed operation. We evaluate the parallel memristor technique in two different applications—memristor-based threshold logic and memristor-based memory. We also perform various optimizations to tradeoff between variation tolerance, power, delay, and area.
Jeyavijayan Rajendran, Ramesh Karri, Garrett S. Rose
IEEE Trans. Computers1
2015 Fault Analysis-Based Logic Encryption
abstract
Globalization of the integrated circuit (IC) design industry is making it easy for rogue elements in the supply chain to pirate ICs, overbuild ICs, and insert hardware Trojans. Due to supply chain attacks, the IC industry is losing approximately $4 billion annually. One way to protect ICs from these attacks is to encrypt the design by inserting additional gates such that correct outputs are produced only when specific inputs are applied to these gates. The state-of-the-art logic encryption technique inserts gates randomly into the design, but does not necessarily ensure that wrong keys corrupt the outputs. Our technique ensures that wrong keys corrupt the outputs. We relate logic encryption to fault propagation analysis in IC testing and develop a fault analysis-based logic encryption technique. This technique enables a designer to controllably corrupt the outputs. Specifically, to maximize the ambiguity for an attacker, this technique targets 50% Hamming distance between the correct and wrong outputs (ideal case) when a wrong key is applied. Furthermore, this 50% Hamming distance target is achieved using a smaller number of additional gates when compared to random logic encryption.
Jeyavijayan Rajendran, Garrett S. Rose, Youngok K. Pino, Ozgur Sinanoglu, Ramesh Karri
IEEE Trans. Computers1
2015 Belling the CAD: Toward Security-Centric Electronic System Design
abstract
In order to keep pace with the growing complexity of integrated circuits (ICs), IC and system designers are increasingly using electronic system level (ESL) design tools. ESL tool sales were around $460 million in 2011. The value of the ICs designed using these tools is at least an order of magnitude more. Concurrently, advanced IC reverse engineering techniques are being developed and used by attackers. In response, several anti-reverse engineering techniques have been proposed for integration into the IC design flow. An important class of defenses hardens the controllers that orchestrate the functionality of designs generated by ESL tools. We demonstrate an attack to recover the controller in any ESL-generated design even if the controller has been hardened using state-of-the-art controller hardening techniques. The attack analyzes the unhardened parts of the controller (i.e., the controller output logic and datapath) and reconciles this information with the architectural, controller, and timing constraints implicit in and underlying all ESL design methodologies. We then propose a countermeasure that inserts decoy connections into an ESL tool-generated design to thwart reverse engineering. We introduce a security metric to quantify the effectiveness of the developed attacks and defenses. We demonstrate the attack and defenses on designs generated by state-of-the-art ESL tools.
Jeyavijayan Rajendran, Aman Ali, Ozgur Sinanoglu, Ramesh Karri
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2014 A Red Team/Blue Team Assessment of Functional Analysis Methods for Malicious Circuit Identification
abstract
Recent advances in hardware security have led to the development of FANCI (Functional Analysis for Nearly-Unused Circuit Identification), an analysis algorithm that identifies stealthy, malicious circuits within hardware designs that can perform backdoor operations to compromise security. Evaluations of such methods using benchmarks and academically known attacks are not always equivalent to the dynamic attack scenarios that can arise in the real world. For this reason, we apply a red team/blue team approach to stress-test the abilities of the FANCI prototype.
Adam Waksman, Jeyavijayan Rajendran, Matthew Suozzo, Simha Sethumadhavan
DAC2
2014 Shielding and securing integrated circuits with sensors
abstract
An integrated circuit (IC) Supply Chain Hardware Integrity for Electronics Defense (SHIELD) is envisioned to enable advanced supply chain hardware authentication and tracing capabilities. The suggested SHIELD is expected to be a ultra-lower power, minuscule electronic component that is physically attached to the host IC. This paper focuses on two important adversarial acts on SHIELD: physical reverse engineering and physical side-channel analysis. These attacks can be launched through mechanical or optical means and they can reveal and/or modify the confidential on-chip data or enable reverse-engineering of the design. For detection of these attacks and subsequent erasing of the sensitive data, sensors, erasure devices, and the relevant control circuitry need to be added to the SHIELD. We describe the device-level operation of the optical (photodetectors) and mechanical (nano- or micro-electromechanical switches) sensors and how they can be integrated within an IC to detect physical attacks. The operation of these micro/nano-scale sensors is unreliable due to environmental, operational, and structural fluctuations and noise. We outline system-level approaches to design a reliable countermeasure against physical attacks using unreliable sensors.
Davood Shahrjerdi, Jeyavijayan Rajendran, Siddharth Garg, Farinaz Koushanfar, Ramesh Karri
ICCAD2
2014 Hot topic session 9C: Test and fault tolerance for emerging memory technologies
abstract
Ever larger on-die memory arrays for future processors in CMOS logic technology drive the need for dense and scalable embedded memory alternatives beyond SRAM and eDRAM. Recent advances in nonvolatile spin transfer torque (STT) RAM technology, which stores data by the spin orientation of a soft ferromagnetic material and shows current induced switching, have created interest for its use as embedded memory. STTRAM exhibits scalable write current, sufficient read margin and nonvolatility or persistence, all of which make it an attractive solution for last level cache, embedded cache or even main memory. In an era of on-die non-volatile storage, new defect, disturb and fault mechanisms need to be comprehended during characterization as well as manufacturing tests. The first part of the talk will introduce STTRAM and review the fundamentals of the cell design, the read and write mechanisms as well as recent advances in technology, which make it a potential successor to eDRAM, followed by how variations and thermal noise limit the material and cell design space. The second part will discuss new test models that would be required for such non-volatile storage, the necessity of large scale data collection and analysis, as well as the need for BIST and on-line testing, and conclude with challenges and opportunities in STTRAM testing that lie ahead of us.
Suriyaprakash Natarajan, Amitava Majumdar 0002, Jeyavijayan Rajendran
VTS3
2014 Regaining Trust in VLSI Design: Design-for-Trust Techniques
abstract
Designers use third-party intellectual property (IP) cores and outsource various steps in their integrated circuit (IC) design flow, including fabrication. As a result, security vulnerabilities have been emerging, forcing IC designers and end-users to reevaluate their trust in hardware. If an attacker gets hold of an unprotected design, attacks such as reverse engineering, insertion of malicious circuits, and IP piracy are possible. In this paper, we shed light on the vulnerabilities in very large scale integration (VLSI) design and fabrication flow, and survey design-for-trust (DfTr) techniques that aim at regaining trust in IC design. We elaborate on four DfTr techniques: logic encryption, split manufacturing, IC camouflaging, and Trojan activation. These techniques have been developed by reusing VLSI test principles.
Jeyavijayan Rajendran, Ozgur Sinanoglu, Ramesh Karri
Proc. IEEE1
2013 Hardware security strategies exploiting nanoelectronic circuits
abstract
Hardware security has emerged as an important field of study aimed at mitigating issues such as piracy, counterfeiting, and side channel attacks. One popular solution for such hardware security attacks are physical unclonable functions (PUF) which provide a hardware specific unique signature or identification. The uniqueness of a PUF depends on intrinsic process variations within individual integrated circuits. As process variations become more prevalent due to technology scaling into the nanometer regime, novel nanoelectronic technologies such as memristors become viable options for improved security in emerging integrated circuits. In this paper, we provide an overview of memristor based PUF structures and circuits that illustrate the potential for nanoelectronic hardware security solutions.
Garrett S. Rose, Jeyavijayan Rajendran, Nathan R. McDonald, Ramesh Karri, Miodrag Potkonjak, Bryant T. Wysocki
ASP-DAC2
2013 Security analysis of integrated circuit camouflaging
abstract
Camouflaging is a layout-level technique that hampers an attacker from reverse engineering by introducing, in one embodiment, dummy contacts into the layout. By using a mix of real and dummy contacts, one can camouflage a standard cell whose functionality can be one of many. If an attacker cannot resolve the functionality of a camouflaged gate, he/she will extract an incorrect netlist. In this paper, we analyze the feasibility of identifying the functionality of camouflaged gates. We also propose techniques to make the dummy contact-based IC camouflaging technique resilient to reverse engineering. Furthermore, we judiciously select gates to camouflage by using techniques which ensure that the outputs of the extracted netlist are controllably corrupted. The techniques leverage IC testing principles such as justification and sensitization. The proposed techniques are evaluated using ISCAS benchmark circuits and OpenSparc T1 microprocessor controllers.
Jeyavijayan Rajendran, Michael Sam, Ozgur Sinanoglu, Ramesh Karri
CCS1
2013 Is split manufacturing secure?
abstract
Split manufacturing of integrated circuits (IC) is being investigated as a way to simultaneously alleviate the cost of owning a trusted foundry and eliminate the security risks associated with outsourcing IC fabrication. In split manufacturing, a design house (with a low-end, in-house, trusted foundry) fabricates the Front End Of Line (FEOL) layers (transistors and lower metal layers) in advanced technology nodes at an untrusted high-end foundry. The Back End Of Line (BEOL) layers (higher metal layers) are then fabricated at the design house's trusted low-end foundry. Split manufacturing is considered secure (prevents reverse engineering and IC piracy) as it hides the BEOL connections from an attacker in the FEOL foundry. We show that an attacker in the FEOL foundry can exploit the heuristics used in typical floorplanning, placement, and routing tools to bypass the security afforded by straightforward split manufacturing. We developed an attack where an attacker in the FEOL foundry can connect 96% of the missing BEOL connections correctly. To overcome this security vulnerability in split manufacturing, we developed a fault analysis-based defense. This defense improves the security of split manufacturing by deceiving the FEOL attacker into making wrong connections.
Jeyavijayan Rajendran, Ozgur Sinanoglu, Ramesh Karri
DATE1
2013 Reconciling the IC test and security dichotomy
abstract
Many of the design companies cannot afford owning and acquiring expensive foundries and hence, go fabless and outsource their design fabrication to foundries that are potentially untrustwrothy. This globalization of Integrated Circuit (IC) design flow has introduced security vulnerabilities. If a design is fabricated in a foundry that is outside the direct control of the (fabless) design house, reverse engineering, malicious circuit modification, and Intellectual Property (IP) piracy are possible. In this tutorial, we elaborate on these and similar hardware security threats by making connections to VLSI testing. We cover design-for-trust techniques, such as logic encryption, aging acceleration attacks, and statistical methods that help identify Trojan'ed and counterfeit ICs.
Ozgur Sinanoglu, Naghmeh Karimi, Jeyavijayan Rajendran, Ramesh Karri, Yier Jin, Ke Huang 0001, Yiorgos Makris
ETS3
2013 Hardware security: threat models and metrics
abstract
The globalized semiconductor supply chain is vulnerable to hardware attacks including: Trojans, piracy of intellectual properties (IPs) and/or overbuilding of integrated circuits (ICs), reverse engineering, side-channels, and counterfeiting. In this paper, we explain the threat models, the state-of-the-art defenses, and the metrics used to evaluate the defenses. The threat models outlined in this paper enables one to understand the attacks. Defenses and metrics can help defenders to build stronger countermeasures and evaluate them against other protection techniques using the metrics.
Masoud Rostami, Farinaz Koushanfar, Jeyavijayan Rajendran, Ramesh Karri
ICCAD3
2013 High-level synthesis for security and trust
abstract
Trustworthiness of System-on-Chips (SoCs) is undermined by malicious logic (trojans) in third party intellectual properties (3PIPs). Concurrent Error Detection (CED) techniques can be adapted to detect malicious outputs generated by trojans. Further, by using a diverse set of 3PIP vendors and operation-to-3PIP-to-vendor allocation constraints, one can prevent collusions between 3PIPs from the same vendor. These security constraints to detect malicious outputs and to prevent collusion have been incorporated into the allocation step of high-level synthesis.
Jeyavijayan Rajendran, Ozgur Sinanoglu, Ramesh Karri
IOLTS1
2013 VLSI testing based security metric for IC camouflaging
abstract
An Integrated Circuit (IC) can be reverse engineered by imaging its layout and reconstructing the netlist. IC camouflaging is a layout-level technique that hampers imaging-based reverse engineering by using, in one embodiment, functionally different standard cells that look alike. Reverse engineering will fail if the functionality of a camouflaged gate cannot be correctly resolved. We adapt VLSI testing principles (justification and sensitization) to quantify the ability of a reverse engineer to unambiguously resolve the functionality of look-alike camouflaged gates. We evaluate the security of look-alike standard cells based IC camouflaging by applying it on the controllers in OpenSPARC T1 processor.
Jeyavijayan Rajendran, Ozgur Sinanoglu, Ramesh Karri
ITC1
2013 A study on the effectiveness of Trojan detection techniques using a red team blue team approach
abstract
As part of the Embedded Systems Challenge, we assess the effectiveness of Trojan detection techniques. The red team inserted different types of Trojans - combinational, sequential, reliability degrading, and performance degrading - into selected variants of a target design; the other variants are Trojan-free. The blue team has to correctly classify the Trojan-free and Trojan-infected variants. Seven different teams from six different universities performed the blue team activity using different types of Trojan-detection techniques, namely activation-based detection, and power- and delay-based side-channels.
Xuehui Zhang, Kan Xiao, Mark Tehranipoor, Jeyavijayan Rajendran, Ramesh Karri
VTS4
2012 Security analysis of logic obfuscation
abstract
Due to globalization of Integrated Circuit (IC) design flow, rogue elements in the supply chain can pirate ICs, overbuild ICs, and insert hardware trojans. EPIC [1] obfuscates the design by randomly inserting additional gates; only a correct key makes the design to produce correct outputs. We demonstrate that an attacker can decipher the obfuscated netlist, in a time linear to the number of keys, by sensitizing the key values to the output. We then develop techniques to fix this vulnerability and make obfuscation truly exponential in the number of inserted keys.
Jeyavijayan Rajendran, Youngok K. Pino, Ozgur Sinanoglu, Ramesh Karri
DAC1
2012 Logic encryption: A fault analysis perspective
abstract
The globalization of Integrated Circuit (IC) design flow is making it easy for rogue elements in the supply chain to pirate ICs, overbuild ICs, and insert hardware trojans; the IC industry is losing approximately $4 billion annually [1], [2]. One way to protect the ICs from these attacks is to encrypt the design by inserting additional gates such that correct outputs are produced only when specific inputs are applied to these gates. The state-of-the-art logic encryption technique inserts gates randomly into the design [3] and does not necessarily ensure that wrong keys corrupt the outputs. Our technique ensures that wrong keys corrupt the outputs. We relate logic encryption to fault propagation analysis in IC testing and develop a fault analysis based logic encryption technique. This technique achieves 50% Hamming distance between the correct and wrong outputs (ideal case) when a wrong key is applied. Furthermore, this 50% Hamming distance target is achieved by using a smaller number of additional gates when compared to random logic encryption.
Jeyavijayan Rajendran, Youngok K. Pino, Ozgur Sinanoglu, Ramesh Karri
DATE1
2012 Engineering crossbar based emerging memory technologies
abstract
Emerging Resistive Random Access Memories (RRAM) devices are an attractive option for future memory architectures due to their low-power and high density. However, their capacity is limited by sneak paths and the sensitivity of the sense amplifiers (SA). We develop a framework to maximize the capacity of RRAM memories by modeling the interactions between memory capacity, sneak paths, device parameters, and the sense amplifier. The framework explores the design space of the memory by considering different read/write mechanisms, sneak path elimination techniques, and multi-level storage.
Sachhidh Kannan, Jeyavijayan Rajendran, Ramesh Karri, Ozgur Sinanoglu
ICCD2
2012 Design Considerations for Multilevel CMOS/Nano Memristive Memory
abstract
With technology migration into nano and molecular scales several hybrid CMOS/nano logic and memory architectures have been proposed that aim to achieve high device density with low power consumption. The discovery of the memristor has further enabled the realization of denser nanoscale logic and memory systems by facilitating the implementation of multilevel logic. This work describes the design of such a multilevel nonvolatile memristor memory system, and the design constraints imposed in the realization of such a memory. In particular, the limitations on load, bank size, number of bits achievable per device, placed by the required noise margin for accurately reading and writing the data stored in a device are analyzed. Also analyzed are the nondisruptive read and write methodologies for the hybrid multilevel memristor memory to program and read the memristive information without corrupting it. This work showcases two write methodologies that leverage the best traits of memristors when used in either linear (low power) or nonlinear drift (fast speeds) modes. The system can therefore be tailored depending on the required performance parameters of a given application for a fast memory or a slower but very energy-efficient system. We propose for the first time, a hybrid memory that aims to incorporate the area advantage provided by the utilization of multilevel logic and nanoscale memristive devices in conjunction with CMOS for the realization of a high density nonvolatile multilevel memory.
Harika Manem, Jeyavijayan Rajendran, Garrett S. Rose
ACM J. Emerg. Technol. Comput. Syst.2
2012 Leveraging Memristive Systems in the Construction of Digital Logic Circuits
abstract
The recent emergence of the memristor has led to a great deal of research into the potential uses of the devices. Specifically, the innate reconfigurability of memristors can be exploited for applications ranging from multilevel memory, programmable logic, and neuromorphic computing, to name a few. In this work, memristors are explored for their potential use in dense programmable logic circuits. While much of the work is focused on Boolean logic, nontraditional styles including threshold logic and neuromorhpic computing are also considered. In addition to an analysis of the circuits themselves, computer-aided design (CAD) flows are presented which have been used to map digital logic functionality to dense complementary metal-oxide-semiconductor (CMOS)-memristive logic arrays. As exemplified through the circuits described here memristor-based digital logic holds great potential for high-density and energy-efficient computing.
Garrett S. Rose, Jeyavijayan Rajendran, Harika Manem, Ramesh Karri, Robinson E. Pino
Proc. IEEE2
2012 An Energy-Efficient Memristive Threshold Logic Circuit
abstract
Researchers have claimed that the memristor, the fourth fundamental circuit element, can be used for computing. In this work, we utilize memristors as weights in the realization of low-power Field Programmable Gate Arrays (FPGAs) using threshold logic which is necessary not only for low power embedded systems, but also realizing biological applications using threshold logic. Boolean functions, which are subsets of threshold functions, can be implemented using the proposed Memristive Threshold Logic (MTL) gate, whose functionality can be configured by changing the weights (memristance). A CAD framework is also developed to map the weights of a threshold gate to corresponding memristance values and synthesize logic circuits using MTL gates. Performance of the MTL gates at the circuit and logic levels is also evaluated using this CAD framework using ISCAS-85 combinational benchmarking circuits. This work also provides solutions based on device options and refreshing memristance, against drift in memristance, which can be a potential problem during operation. Comparisons with the existing CMOS look-up-table (LUT) and capacitor threshold logic (CTL) gates show that MTL gates exhibit less energy-delay product by at least 90 percent.
Jeyavijayan Rajendran, Harika Manem, Ramesh Karri, Garrett S. Rose
IEEE Trans. Computers1
2011 Blue team red team approach to hardware trust assessment
abstract
Hardware security techniques are validated using fixed in-house methods. However, the effectiveness of such techniques in the field cannot be the same as the attacks are dynamic. A red team blue team approach mimics dynamic attack scenarios and thus can be used to validate such techniques by determining the effectiveness of a defense and identifying vulnerabilities in it. By following a red team blue team approach, we validated two trojan detection techniques namely, path delay measurement and ring oscillator frequency monitoring, in the Embedded Systems Challenge (ESC) 2010. In ESC, one team performed the blue team activities and eight other teams performed red team activities. The path delay measurement technique detected all the trojans. The ESC exposed a vulnerability in the RO-based technique which was exploited by the red teams causing some trojans to be undetected. Post ESC, we developed a technique to fix this vulnerability.
Jeyavijayan Rajendran, Vinayaka Jyothi, Ramesh Karri
ICCD1
2011 Parallel memristors: Improving variation tolerance in memristive digital circuits
abstract
Memristors are employed by a wide variety of applications such as neural networks, memory and digital logic. However, the process variation effects of memristors may affect these applications. In this research, we consider the effect of process variations in the thickness of the oxide layer of memristors that are used in Memristor-based Threshold Logic (MTL) gates. As the effect of variations is less pronounced in high memristance values, a variation tolerant design without any degradation in speed is achieved by having a number of high memristance devices in parallel (redundancy factor). We propose an algorithm for the MTL gates to determine the number of memristors in parallel and the variation-minimal high memristance state. A power optimization algorithm is also proposed to map gates in a design using different libraries that have different performance characteristics. Finally, we present the power, delay performance and also the redundancy factor of memristors for various benchmark circuits.
Jeyavijayan Rajendran, Ramesh Karri, Garrett S. Rose
ISCAS1
2011 Design and analysis of ring oscillator based Design-for-Trust technique
abstract
Due to the increasing opportunities for malicious inclusions in hardware, Design-for-Trust (DFTr) is emerging as an important IC design methodology. In order to incorporate the DFTr techniques into the IC development cycle, they have to be practical in terms of their Trojan detection capabilities, hardware overhead, and test cost. We propose a non-invasive DFTr technique, which can detect Trojans in the presence of process variations and measurement errors. This technique can detect Trojans that are inserted in all or a subset of the ICs. It is applicable to both ASICs and FPGA implementations. Circuit paths in a design are reconfigured into ring oscillators (ROs) by adding a small amount of logic. Trojans are detected by observing the changes in the frequency of the ROs. An algorithm is provided to secure all the gates, while reducing the hardware overhead. We analyzed the coverage, area and test time overhead of the proposed DFTr technique. To demonstrate its effectiveness in the real world, the proposed technique had been validated by a red-team blue-team approach.
Jeyavijayan Rajendran, Vinayaka Jyothi, Ozgur Sinanoglu, Ramesh Karri
VTS1
2010 Towards a comprehensive and systematic classification of hardware Trojans
abstract
Recently, there have been reports of Trojans being inserted at the hardware level. It is necessary to understand the characteristics of these hardware Trojans to be able to develop systematic methods to detect their presence. Absent this, only ad-hoc methods can be developed. Also, developed detection methods are not being adequately tested on a comprehensive set of benchmarks. We propose a comprehensive taxonomy of hardware Trojans based on five intuitive attributes. We organized the embedded systems challenge (ESC) to compile Trojans and analysed them to validate the taxonomy.
Jeyavijayan Rajendran, Efstratios Gavas, Jorge Jimenez, Vikram Padman, Ramesh Karri
ISCAS1