VLDB 2026 Research / reviewers in the wild / expert
Debdeep Mukhopadhyay
dblp:85/3079
· DBLP profile ↗
180ranked-venue papers
7as first author
72since 2021 · last 2026
0000-0002-6499-8346ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 102 · 7 first-author · 35 since 2021Security and privacy · 71 · 33 since 2021Software engineering, systems software and programming languages · 14 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Related-Key Cryptanalysis of FUTURE - The Full Round Distinguishing Attack
Amit Jana, Smita Das, Ayantika Chatterjee, Debdeep Mukhopadhyay, Yu Sasaki 0001 |
ACNS (3) | 4 |
| 2026 | X-CHAIN: Enhancing Electronic Supply Chain Security with 3D X-Ray Inspection and Blockchain Integration
Shuvodip Maitra, Tishya Sarma Sarkar, Chandan Kumar Chaudhary, Abhishek Chakraborty 0001, Debdeep Mukhopadhyay |
ACNS (2) | 5 |
| 2026 | DEEP-LENS: Deep-Learning Powered Layout Extraction and Novel Segmentation for IC Assurance and SecurityabstractEnsuring the physical integrity of Integrated Circuits (ICs) at the microscopic level is essential for defending against threats like Hardware Trojans and counterfeiting in the electronics supply chain. This study presents enhanced segmentation and layout modification detection capability using electron microscopy images of a delayered IC. We have developed DEEP-LENS, a robust segmentation method combining Conditional Pixel Diffusion with a Dual Residual Shifted Window U-Net architecture. This approach effectively extracts layout features, such as standard cells, from noisy SEM images. DEEP-LENS achieved impressive performance metrics, including an Intersection over Union (IoU) of 0.908, a Mean Pixel Accuracy (mPA) of 0.955, and a Dice score of 0.952 on the test dataset. IoU measures mask overlap; mPA assesses class-wise pixel accuracy; and the Dice score emphasizes true positives, enhancing sensitivity to small segmentation errors. Additionally, it detected polygon modifications with over 91% accuracy compared to the original layout designs. Shuvodip Maitra, Abhishek Chakraborty 0001, Debdeep Mukhopadhyay |
DATE | 3 |
| 2026 | Efficient and Post-quantum Conjunctive Dynamic SSE with Strong Privacy Guarantees
Bibhas Chandra Das, Nilanjan Datta, Avijit Dutta, Avishek Majumder 0002, Debdeep Mukhopadhyay, Sikhar Patranabis, Subhabrata Samajder, Laltu Sardar |
PKC (4) | 5 |
| 2025 | Unified FPGA Design of Kyber and Dilithium with Provable Fault ToleranceabstractEfficient and secure hardware implementations of post-quantum cryptographic schemes are critical for real-world adoption. In this work, we propose a unified FPGA-based architecture for Kyber and Dilithium that combines flexibility, lightweight design, and fault tolerance. The architecture adopts a microcoded, programmable datapath supporting both schemes with minimal area overhead, enabling seamless integration of modules such as SHAKE, sampling, and coefficient rounding. To enhance resilience against propagation-based fault attacks-which exploit effective/ineffective fault behavior in public-domain computations-we embed a probabilistic verification mechanism using rejection sampling. This countermeasure transforms deterministic operations into cryptographically constrained probabilistic processes that remain efficient under normal conditions while significantly degrading under adversarial faults. The result is a robust and compact design that not only supports both a lattice-based KEM and signature scheme, but also provides the first unified fault countermeasure architecture for Kyber and Dilithium, maintaining low retry counts and minimal performance degradation in fault-free environments. Siddhartha Chowdhury, Nimish Mishra, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ASAP | 4 |
| 2025 | Pay What You Spend! Privacy-Aware Real-Time Pricing with High Precision IEEE 754 Floating Point Division
Soumyadyuti Ghosh, Harishma Boyapally, Ajith Suresh, Arpita Patra, Soumyajit Dey, Debdeep Mukhopadhyay |
AsiaCCS | 6 |
| 2025 | An Efficient Circuit Synthesis Framework for TFHE via Convex Sub-graph Optimization
Ayantika Chatterjee, Anupam Chattopadhyay, Debdeep Mukhopadhyay |
AsiaCCS | 4 |
| 2025 | Ring-LWR based Commitments and ZK-PoKs with Application to Verifiable Quantum-Safe Searchable Symmetric Encryption
Debadrita Talapatra, Nimish Mishra, Debdeep Mukhopadhyay |
AsiaCCS | 3 |
| 2025 | WiperSentinel: HPC Based Wiper Detection with Enhanced AutoEncoder
Shiva Agarwal, Suvadeep Hajra, Ayantika Chatterjee, Debdeep Mukhopadhyay |
CANS | 4 |
| 2025 | "OOPS!": Out-Of-Band Remote Power Side-Channel Attacks on Intel SGX and TDXabstractPrior work shows that remote power attacks on Intel processors are possible through two Model Specific Registers (MSRs): MSR_PKG_Energy_Status and MSR_PPO_Energy_Status. In response, Intel introduced a defense: a bit in MSR IA32_MISC_PACKAGE_CTLS allows users to enable/disable “filtering” mechanism that adds additional noise to energy measurements to harden against power side-channel attacks. In this work, we demonstrate that “filtering” does not cover all possible avenues of measuring power. On Intel server-grade platforms, components like out-of-band management interface (OOB) exist which also expose telemetric information like inband energy consumption. For this, we first reverse engineer the protocol structure over which OOB communicates with in-band components. We then show how OOB allows read-only access to the Package Configuration Space (PCS) and note that energy readings through PCS are outside the scope of filtering. Using this, we establish remote power side-channels on Intel SGX and TDX operational on Intel Sapphire Rapids. We first construct a synchronization mechanism to align in-band execution with out-of-band measurements by leveraging deliberately disabled MSRs. We then use energy readings through OOB PCS to recover 2048-bit RSA keys from MbedTLS operational within in-band Intel SGX (with generic single-stepping assumption). Finally, we also leak AESNI keys from within in-band Intel TDX (without any single-step assumption). Prior to our work, the literature on side-channels has been focused on attacks leveraging in-band interfaces. Our work establishes the importance of evaluating confidential computing architectures against attack vectors that combine abilities of both in-band and out-of-band interfaces to achieve adversarial objectives (that both in-band and out-of-band interfaces cannot independently achieve). Nimish Mishra, Kislay Arya, Sarani Bhattacharya, Paritosh Saxena, Debdeep Mukhopadhyay |
DAC | 5 |
| 2025 | TERRA: Trojan-Resilient Reverse-Firewall for Cryptographic Applications
Chandan Kumar Chaudhary, Nimish Mishra, Suvradip Chakraborty, Satrajit Ghosh, Debdeep Mukhopadhyay |
ESORICS (2) | 5 |
| 2025 | MIRAGE: Microarchitectural Footprints for Detecting Adversarial Attacks in One-Shot InferenceabstractAdversarial attacks pose severe threats to the integrity of deep neural networks (DNNs), especially in resource-constrained systems where traditional defenses are computationally expensive. While existing defenses in the black-box setting utilize hardware characteristics of adversarial attacks (like Hardware Performance Counter or HPC measurements), these defenses often involve repeating execution of multiple target model inferences to detect the attacks.In this work, we put forth a differing perspective: while detection strategies involving multiple target model inferences appear to be successful in isolation, they have unacceptable and inhibitory requirements. Precisely, we argue that these works require cleaning the micro-architectural state of hardware like the cache and the branch predictor after each inference. This in turn leads to performance degradation of not only the adversarial attack detector, but also of the overall system at large.In this work, we put forth a novel and lightweight detection strategy, MIRAGE, using HPCs that does not require cleaning the micro-architectural state of caches or branch predictors. We train a convolutional neural network (CNN) on these signals to classify inputs as benign or adversarial in a single shot, making our approach practical for online systems, while allowing full use of hardware optimizations for performance uplifts. Experiments on CIFAR-10 and MNIST datasets reveal that our methodology not only detects adversarial samples effectively with greater than 96% accuracy, but also imposes a minimal timing overhead of 60 ms and maintains high throughput. This makes our solution well-suited for embedded and edge-AI scenarios. Soumi Chatterjee, Debadrita Talapatra, Nimish Mishra, Aritra Hazra, Debdeep Mukhopadhyay |
ICCAD | 5 |
| 2025 | "Energon": Unveiling Transformers from GPU Power and Thermal Side-ChannelsabstractTransformers have become the backbone of many Machine Learning (ML) applications, including language translation, summarization, and computer vision. As these models are increasingly deployed in shared Graphics Processing Unit (GPU) environments via Machine Learning as a Service (MLaaS), concerns around their security grow. In particular, the risk of side-channel attacks that reveal architectural details without physical access remains under-explored, despite the high value of the proprietary models they target. This work to the best of our knowledge is the first to investigate GPU power and thermal fluctuations as side-channels and further exploit them to extract information from pre-trained transformer models. The proposed analysis shows how these side channels can be exploited at user-privilege to reveal critical architectural details such as encoder/decoder layer and attention head for both language and vision transformers. We demonstrate the practical impact by evaluating multiple language and vision pre-trained transformers which are publicly available. Through extensive experimental evaluations, we demonstrate that the attack model achieves a high accuracy of over 89% on average for model family identification and 100% for hyperparameter classification, in both single-process as well as noisy multi-process scenarios. Moreover, by leveraging the extracted architectural information, we demonstrate highly effective black-box transfer adversarial attacks with an average success rate exceeding 93%, underscoring the security risks posed by GPU side-channel leakage in deployed transformer models. Arunava Chaudhuri, Shubhi Shukla 0001, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ICCAD | 4 |
| 2025 | TREX-F: TRustability of Electronics using X-ray based FingerprintingabstractThe present-day electronic supply chain is infested with adversaries who threaten the integrity of electronic circuit boards and components. A major intent of such adversaries is to manufacture counterfeit printed circuit boards (PCBs). They infiltrate the supply chain with these forged PCBs, which closely mimic the original designs, albeit jeopardizing the business cycle of electronic design. In this work, we aim to restrict the circulation of tampered and counterfeit boards in the supply chain by leveraging the inherent physical deformities of authentic PCBs, which are difficult to replicate. Such anomalies include solder defects, material deposition, and microscopic irregularities unique to each PCB. These anomalies, though imperceivable to the human eye, can be captured at a specific angle under an X-ray microscope when imaged at appropriate orientations. Our proposed framework, TREX-F, comprises an image-based authentication protocol that defines unique fingerprints of each PCB by extracting such anomalies and converting them into quick-response and data-matrix codes. We construct device-specific templates from the X-ray computed tomography slices of the PCB samples by utilizing a combination of computer vision techniques, including Canny edge detection, contour detection, principal component analysis, and scale-invariant feature transform. As a case study, we validate our framework on Arduino UNO, Raspberry Pi 4 model B, and STM32F407G boards. TREX-F enables a sustainable electronics supply chain ecosystem, wherein end users can directly verify the authenticity of the procured PCBs with an average accuracy of ≥95% across all boards, and an average false acceptance rate (FAR) of 0.1 Tishya Sarma Sarkar, Shuvodip Maitra, Abhishek Chakraborty 0001, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ICCAD | 5 |
| 2025 | Be a Goldfish: Forgetting Bad Conditioning in Sparse Linear Regression via Variational AutoencodersabstractVariational Autoencoders (VAEs), a class of latent-variable generative models, have seen extensive use in high-fidelity synthesis tasks, yet their loss landscape remains poorly understood. Prior theoretical works on VAE loss analysis have focused on their latent-space representational capabilities, both in the optimal and limiting cases. Although these insights have guided better VAE designs, they also often restrict VAEs to problem settings where classical algorithms, such as Principal Component Analysis (PCA), can trivially guarantee globally optimal solutions. In this work, we push the boundaries of our understanding of VAEs beyond these traditional regimes to tackle NP-hard sparse inverse problems, for which no classical algorithms exist. Specifically, we examine the nontrivial Sparse Linear Regression (SLR) problem of recovering optimal sparse inputs in the presence of an ill-conditioned design matrix having correlated features. We provably show that, under a linear encoder-decoder architecture incorporating the product of the SLR design matrix with a trainable, sparsity-promoting diagonal matrix, any minimum of VAE loss is guaranteed to be an optimal solution. This property is especially useful for identifying (a) a preconditioning factor that reduces the eigenvalue spread, and (b) the corresponding optimal sparse representation. Lastly, our empirical analysis with different types of design matrices validates these findings and even demonstrates a higher recovery rate at low sparsity where traditional algorithms fail. Overall, this work highlights the flexible nature of the VAE loss, which can be adapted to efficiently solve computationally hard problems under specific constraints. Kuheli Pratihar, Debdeep Mukhopadhyay |
ICML | 2 |
| 2025 | IND-CPAbf C: A New Security Notion for Conditional Decryption in Fully Homomorphic Encryption
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Nimish Mishra, Ayantika Chatterjee, Debdeep Mukhopadhyay |
PQCrypto (2) | 5 |
| 2025 | Systematic Evaluation of Randomized Cache Designs against Cache Occupancy
Anirban Chakraborty 0003, Nimish Mishra, Sayandeep Saha, Sarani Bhattacharya, Debdeep Mukhopadhyay |
USENIX Security Symposium | 5 |
| 2025 | Guardian of the Ensembles: Introducing Pairwise Adversarially Robust Loss for Resisting Adversarial Attacks in DNN EnsemblesabstractAdversarial attacks rely on transferability, where an adversarial example (AE) crafted on a surrogate classifier tends to mislead a target classifier. Recent ensemble methods demonstrate that AEs are less likely to mislead multiple classifiers in an ensemble. This paper proposes a new ensemble training using a Pairwise Adversarially Robust Loss (PARL) that by construction produces an ensemble of classifiers with diverse decision boundaries. PARL utilizes outputs and gradients of each layer with respect to network parameters in every classifier within the ensemble simultaneously. PARL is demonstrated to achieve higher robustness against black-box transfer attacks than previous ensemble methods as well as adversarial training without adversely affecting clean example accuracy. Extensive experiments using standard Resnet20, WideResnet28-10 classifiers demonstrate the robustness of PARL against state-of-the-art adversarial attacks. While maintaining similar clean accuracy and lesser training time, the proposed architecture has a 24.8% increase in robust accuracy (∊= 0.07) from the state-of-the art method. Code is available at: https://github.com/shubhishukla10/PARL Shubhi Shukla 0001, Subhadeep Dalui, Manaar Alam, Shubhajit Datta, Arijit Mondal, Debdeep Mukhopadhyay, P. P. Chakrabarti 0001 |
WACV | 6 |
| 2025 | $\mathtt{PARLE}$PARLE-$\mathtt{G}$G: Provable Automated Representation and Analysis Framework for Learnability Evaluation of Generic PUF CompositionsabstractBesides enormous research efforts in the design of Physically Unclonable Functions (PUFs), its vulnerabilities are still being exploited using machine learning (ML) based model-building attacks. Due to inherent complicacy in exploring and manually converging to a strong PUF composition, the challenge of building ML-attack resistant PUFs continues. Hence, it becomes imperative to develop an automated framework that can formally assess the learnability of different PUF constructions and compositions to guide the designer to explore resilient PUFs. In this work, we present an automated analysis framework (PARLE-G), to formally represent and evaluate the Probably Approximately Correct (PAC) learnability of PUF constructions and their compositions. A high-level specification language PUF-G has been developed to structurally represent any PUF composition comprising a specified set of primitive components and composition operations. The tool takes a PUF design represented in PUF-G language as input and returns its PAC learnability result, identifying a suitable PAC learning algorithm and the PAC model parameters based on the input PUF design. PUF designs proven to be learnable by PARLE-G are segregated into different classes based on the asymptotic complexity of their learnability bounds. Such automated analysis helps a designer to make informed design choices, thereby strengthening a PUF construction from the architectural level. Durba Chatterjee, Aritra Hazra, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 3 |
| 2025 | Differentially Private Real-Time Pricing Control for Smart GridsabstractSmart meters provide fine-grained power usage profiles of consumers to various utility providers, thus facilitating multiple grid functionalities such as load monitoring, Real-Time Pricing (RTP), demand response, and so on. However, information leakage from such usage profiles reveals consumers’ private day-to-day life patterns and their home presence/absence, as the state-of-the-art metering strategies lack adequate security and privacy measures. Since Smart grid communication infrastructure supports low bandwidth, it prohibits the usage of computation-intensive cryptographic solutions. Among different privacy-preserving smart meter streaming methods, data manipulation techniques can easily be implemented in smart meters and do not require installing any storage devices or alternative energy sources. For this purpose, Differential Privacy (DP) is widely adopted in the literature due to its solid mathematical foundation. However, the effect of such manipulations on the RTP control is worth exploring since pricing signals operate in a closed-loop between consumers and utilities. This brings up the privacy-utility tradeoff problem between the user’s achieved privacy and the performance of the pricing loop of Smart grids, an area where the characterization between privacy and pricing control performance is not yet established. We analytically highlight such privacy-utility tradeoff in the closed-loop RTP systems in terms of achieved privacy and the overall generation scheduling errors. We utilize the notion of \(w\) -event privacy and present a RTP aware DP scheme that promises strong user privacy and guarantees pricing signal stabilization irrespective of the privacy level of the DP mechanism. Finally, we show the efficiency and robustness of our scheme by performing extensive experimental validation on MATLAB and, subsequently, on an in-house smart meter test bed. Soumyadyuti Ghosh, Suman Maiti, Debdeep Mukhopadhyay, Soumyajit Dey |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2025 | A Severe Vulnerability and an Effective Defense Against DFA on AsconabstractDifferential Fault Attack ( DFA ) is a powerful cryptanalytic technique for recovering cryptographic keys by exploiting computational faults. At Indocrypt 2024, the first DFA on Ascon was introduced using a bit-flip fault model to recover a 64-bit key, followed by a bit-set fault model to extract another 64-bit key. However, this attack lacked practical validation. In this work, we revisit their approach and extend it by generalizing the attack to a more practical and widely accepted random fault model. Given that Ascon is implemented using bit-sliced techniques, we validate our attack through real-world experiments on a ChipWhisperer Lite platform using clock glitching. We demonstrate that the structure of Ascon inherently transforms random register faults into single-bit differences within the S-box operation, making it susceptible to DFA . We evaluate our attack under both nonce-misuse and nonce-respecting scenarios. In the nonce-misuse setting, we recover the first 64-bit key with only 50 random register faults and estimate the fault requirements for key recovery in the nonce-respecting case. Additionally, we identify a structural weakness in the Ascon tag selection process that increases its susceptibility to difference-based fault attacks. To counter this vulnerability, we propose an immediate countermeasure to strengthen its resistance against DFA . Smita Das, Amit Jana, Debdeep Mukhopadhyay |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2025 | PLAnCo: Provable Learnability Analysis of Generic APUF Compositions Using Finite Automata Models
Soumi Chatterjee, Durba Chatterjee, Aritra Hazra, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | "Hello? Is There Anybody in There?" Leakage Assessment of Differential Privacy Mechanisms in Smart Metering Infrastructure
Soumyadyuti Ghosh, Manaar Alam, Soumyajit Dey, Debdeep Mukhopadhyay |
ACNS (3) | 4 |
| 2024 | Efficient Quantum-Safe Distributed PRF and Applications: Playing DiSE in a Quantum World
Sayani Sinha, Sikhar Patranabis, Debdeep Mukhopadhyay |
ACNS (2) | 3 |
| 2024 | Tokenised Multi-client Provisioning for Dynamic Searchable Encryption with Forward and Backward PrivacyabstractSearchable Symmetric Encryption (SSE) has opened up an attractive avenue for privacy-preserved processing of outsourced data on the untrusted cloud infrastructure. SSE aims to support efficient Boolean query processing with optimal storage and search overhead over large real databases. However, current constructions in the literature lack the support for multi-client search and dynamic updates to the encrypted databases, which are essential requirements for the widespread deployment of SSE on real cloud infrastructures. Trivially extending a state-of-the-art single client dynamic construction, such as ODXT (Patranabis et al., NDSS'21), incurs significant leakage that renders such extension insecure in practice. Currently, no SSE construction in the literature offers efficient multi-client query processing and search with dynamic updates over large real databases while maintaining a benign leakage profile. Arnab Bag, Sikhar Patranabis, Debdeep Mukhopadhyay |
AsiaCCS | 3 |
| 2024 | On the Security of Privacy-Preserving Machine Learning Against Model Stealing Attacks
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Ayantika Chatterjee, Debdeep Mukhopadhyay |
CANS (2) | 4 |
| 2024 | Plug Your Volt: Protecting Intel Processors against Dynamic Voltage Frequency Scaling based Fault AttacksabstractExisting countermeasures to DVFS based fault attacks are overly restrictive because (1) they prevent benign, non-SGX processes from utilizing DVFS, and (2) rely upon a less practical threat model than that of Intel SGX. Consequently, this work proposes a new countermeasure principle to defend against DVFS based fault attacks on modern Intel systems. First, we establish that the fundamental cause of DVFS fault attacks is the ability to independently control the frequency and voltage of a processor. Using this observation, we construct a partition of frequency-voltage tuples into unsafe-safe states based on whether a tuple causes timing violations according to switching circuit theoretic principles. Our countermeasure completely prevents DVFS faults on three Intel generation CPUs: Sky Lake, Kaby Lake R, and Comet Lake. Further, it can also be deployed both as microcode or as model-specific registers at the hardware level, unlike previous countermeasures. Our countermeasure incurs a slowdown of only 0.28% on overall system performance when benchmarked against SPEC2017. Nimish Mishra, Rahul Arvind Mool, Anirban Chakraborty 0003, Debdeep Mukhopadhyay |
DAC | 4 |
| 2024 | "Ask and Thou Shall Receive": Reaction-Based Full Key Recovery Attacks on FHE
Bhuvnesh Chaturvedi, Anirban Chakraborty 0003, Ayantika Chatterjee, Debdeep Mukhopadhyay |
ESORICS (4) | 4 |
| 2024 | FHEDA: Efficient Circuit Synthesis with Reduced Bootstrapping for Torus FHEabstractFully Homomorphic Encryption (FHE) schemes are widely used cryptographic primitives for performing arbitrary computations on encrypted data. However, FHE incorporates a computationally intensive mechanism called bootstrapping, that resets the noise in the ciphertext to a lower level allowing the computation on circuits of arbitrary depth. This process can take significant time, ranging from several minutes to hours. To address the above issue, in this work, we propose an Electronic Design Automation (EDA) framework$\mathsf{FHEDA}$that generates efficient Boolean representations of circuits compatible with the Torus-FHE (ASIACRYPT 2020) scheme. To the best of our knowledge, this is the first work in the EDA domain of FHE. We integrate logic synthesis and gate optimization techniques into our$\mathsf{FHEDA}$framework for reducing the total number of bootstrapping operations in a Boolean circuit, which leads to a significant (up to 50%) reduction in homomorphic computation time. Our$\mathsf{FHEDA}$is built upon the observation that in Torus-FHE two consecutive Boolean gate evaluations over fresh encryptions require only one bootstrapping instead of two, based on appropriate parameter choices. By integrating this observation with logic replacement techniques into$\mathsf{FHEDA}$, we could reduce the total number of bootstrapping operations along with the circuit depth. This eventually reduces the homomorphic evaluation time of Boolean circuits. In order to verify the efficacy of our approach, we assess the performance of the proposed EDA flow on a diverse set of representative benchmarks including privacy-preserving machine learning and different symmetric key block ciphers. Smita Das, Anirban Chakraborty 0003, Rajat Sadhukhan, Ayantika Chatterjee, Debdeep Mukhopadhyay |
EuroS&P | 6 |
| 2024 | Breaching the Gap: Modelling SRAM-PUFs via Side-Channel SignaturesabstractCryptographic systems employing SRAM-based Physically Unclonable Functions (SRAM-PUFs) rely on the assumption that modelling the internal PUF state is practically infeasible. This work investigates the modelling prowess of an adversary with access to side-channel information collected from similar, albeit not identical, devices to develop templates for leakages. To the best of our knowledge, this is the first work to show the modelling vulnerability of SRAM-PUFs to side-channel leakages by utilizing the correlation between power, electromagnetic signatures obtained from similar devices with identical patterns in their PUF responses. To evaluate the effectiveness of our attack, we perform extensive experiments on ATmega328P and demonstrate a maximum accuracy of 98.45% in the Hamming Weight ( <?TeX $\mathsf {HW}$?> Math 2 ) prediction of the PUF responses and <?TeX $96.91\%$?> Math 3 for the exact PUF response over 50 target devices. Our attack’s feasibility also extends to newer technology nodes, as validated on the 32-bit ARM Cortex M0+. Additionally, we augment the well-known helper data induced min-entropy loss to factor in the effect of side-channels and show that the residual entropy per byte of SRAM-PUF reduces significantly due to <?TeX $\mathsf {HW}$?> Math 4 leakage. Lastly, we propose an in-situ masking countermeasure using SRAM metastable cells, that effectively randomizes the side-channel signatures and reduces the <?TeX $\mathsf {HW}$?> Math 5 prediction accuracy to <?TeX $< 30\%$?> Math 6 . Kuheli Pratihar, Soumi Chatterjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
ACM Great Lakes Symposium on VLSI | 4 |
| 2024 | µLAM: A LLM-Powered Assistant for Real-Time Micro-architectural Attack Detection and MitigationabstractThe rise of microarchitectural attacks has necessitated robust detection and mitigation strategies to secure computing systems. Traditional tools, such as static and dynamic code analyzers and attack detectors, often fall short due to their reliance on predefined patterns and heuristics that lack the flexibility to adapt to new or evolving attack vectors. In this paper, we introduce for the first time a microarchitecture security assistant, built on OpenAI's GPT-3.5, which we refer to as μLAM. This assistant surpasses conventional tools by not only identifying vulnerable code segments but also providing context-aware mitigations, tailored to specific system specifications and existing security measures. Additionally, μLAM leverages real-time data from dynamic Hardware Performance Counters (HPCs) and system specifications to detect ongoing attacks, offering a level of adaptability and responsiveness that static and dynamic analyzers cannot match. Upasana Mandal, Shubhi Shukla 0001, Ayushi Rastogi, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ICCAD | 5 |
| 2024 | Faults in Our Bus: Novel Bus Fault Attack to Break ARM TrustZone
Nimish Mishra, Anirban Chakraborty 0003, Debdeep Mukhopadhyay |
NDSS | 3 |
| 2024 | Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel Processors
Anirban Chakraborty 0003, Nimish Mishra, Debdeep Mukhopadhyay |
USENIX Security Symposium | 3 |
| 2024 | VALIANT: An EDA Flow for Side-Channel Leakage Evaluation and Tailored ProtectionabstractPower side-channels give rise to several potent attack vectors for leaking information in digital circuits. While a plethora of (mathematically robust) solutions exist to tackle such side-channels, their deployment through existing VLSI design-flows remains an important engineering issue. Besides, most existing solutions result in significant hardware overhead hindering their practical usage for resource-constrained settings, such as Internet-of-Things (IoT) or embedded devices. In this paper, we address both of these issues through an integrated electronic design automation (EDA) tool-flow operating on gate-level designs. Based on an interesting observation that not every net in a design is equally susceptible to side-channel leakage, we devise a generic testing mechanism and lightweight albeit customizable protection strategy for a given trace count. We first analytically establish the observation based on certain physical properties of VLSI circuits and also validate it on ISCAS benchmark circuits. Next, we present a tool calledVALIANT, which can identify the leaking nets for a given number of traces from the gate-level netlist of a cipher.VALIANTworks alongside state-of-the-art design automation tools and, therefore, can be directly incorporated in existing design flows. After identifying the leaky subset of nets in a design, we propose a lightweight variant of an existing masking scheme to eliminate the leakage concerning a given trace count. The main feature of our protection scheme is that it takes into account subset of nets are not “leaky” and optimizes the usage of randomness and extra gates according to this information to minimize the overhead. Experimental evaluation over state-of-the-art lightweight S-Boxes and the GIFT block cipher establishes the efficacy of the proposed idea for generating lightweight protected solutions in an automated manner. Rajat Sadhukhan, Sayandeep Saha, Sudipta Paria, Swarup Bhunia, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 5 |
| 2024 | Enhancing SRAM-Based PUF Reliability Through Machine Learning-Aided Calibration TechniquesabstractStatic random access memory (SRAM)-based physically unclonable functions (PUFs) utilize unpredictable start-up values (SUVs) for key generation, making them widely adopted in cryptographic systems. This unpredictability in SUVs is accompanied by device noise that escalates with process-voltage–temperature (PVT) variations, resulting in significant deviations from the golden response collected at ambient conditions, thereby increasing the bit-error-rate (BER) of the PUF responses. To reduce this high-$(\geq 15\%)$BER, either an involved error correcting code (ECC) circuitry with significant overhead is required, or more helper information needs to be generated at varying operating conditions, resulting in increased information leakage. We address this issue by proposing the first reported application of machine learning to recalibrate the responses by predicting the golden responses of the SRAM-based PUF (SRAM-PUF) at different operating conditions with high accuracy. Our recalibration technique is based on a novel collective decision that involves observing the neighborhood cells of the SRAM-PUF, as opposed to the traditional single-cell approach. By leveraging a memory map exhibiting a high correlation in ambient reliability amongst neighboring cells, we indirectly use the physical co-location of SRAM cells to assist neighborhood error prediction. It leads to efficient post-processing for SRAM-PUFs by using helper data generated at ambient conditions only while employing a fixed ECC designed for the same. Subsequently, to justify our claims and validate the efficacy of our proposed methodology, we demonstrate extensive experimentation results over multiple SRAM-PUF instances implemented on the Arduino UNO (an 8-bit microcontroller unit) and its scaled-up version, the Arduino Zero (a 32-bit microcontroller unit) boards, by varying supply voltages from 3.8 to 6.2 V and 7 to 12 V, respectively, and temperature from −25° to 70° C in both cases. Our observations show a vast drop in BER from 17.02% to$\approx 1\%$. Although worst-case conditions with both voltage and temperature variations at play resulted in a BER of 20%, using our proposed approach reduces it to$\approx 1{\text {-}} 2\%$, in turn demonstrating the high efficacy of our scheme. Kuheli Pratihar, Soumi Chatterjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2024 | Latent RAGE: Randomness Assessment Using Generative Entropy ModelsabstractNIST’s recent review of the widely employed special publication (SP) 800–22 randomness testing suite has underscored several shortcomings, particularly the absence of entropy source modeling and the necessity for large sequence lengths. Motivated by this revelation, we explore low-dimensional modeling of the entropy source in random number generators (RNGs) using a variational autoencoder (VAE). This low-dimensional modeling enables the separation between strong and weak entropy sources by magnifying the deterministic effects in the latter, which are otherwise difficult to detect with conventional testing. Bits from weak-entropy RNGs with bias, correlation, or deterministic patterns are more likely to lie on a low-dimensional manifold within a high-dimensional space, in contrast to strong-entropy RNGs, such as true RNGs (TRNGs) and pseudo-RNGs (PRNGs) with uniformly distributed bits. We exploit this insight to employ a generative AI-based noninterference test (GeNI) for the first time, achieving implementation-agnostic low-dimensional modeling of all types of entropy sources. GeNI’s generative aspect uses VAEs to produce synthetic bitstreams from the latent representation of RNGs, which are subjected to a deep learning (DL)-based noninterference (NI) test evaluating the masking ability of the synthetic bitstreams. The core principle of the NI test is that if the bitstream exhibits high-quality randomness, the masked data from the two sources should be indistinguishable. GeNI facilitates a comparative analysis of low-dimensional entropy source representations across various RNGs, adeptly identifying the artificial randomness in specious RNGs with deterministic patterns that otherwise passes all NIST SP800-22 tests. Notably, GeNI achieves this with$10\times $lower-sequence lengths and$16.5\times $faster execution time compared to the NIST test suite. Kuheli Pratihar, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2024 | Systematically Quantifying Cryptanalytic Nonlinearities in Strong PUFsabstractPhysically Unclonable Functions (PUFs) with large challenge space (also called Strong PUFs) are promoted for usage in authentications and various other cryptographic and security applications. In order to qualify for these cryptographic applications, the Boolean functions realized by PUFs need to possess a high nonlinearity (NL). However, with a large challenge space (usually$\geq 64$bits), measuring NL by classical techniques like the Walsh transformation is computationally infeasible. In this paper, we propose the usage of a heuristic-based measure called the non-homomorphicity test which estimates the cryptographic NL of Boolean functions with high accuracy in spite of not needing access to the entire challenge-response set. We also combine our analysis with a technique used in linear cryptanalysis, called Piling-up lemma, to measure the NL of popular PUF compositions. As a demonstration to justify the soundness of the metric, we perform extensive experimentation by first estimating the NL of constituent Arbiter/Bistable Ring PUFs using the non-homomorphicity test, and then applying them to quantify the same for their XOR compositions namely XOR Arbiter PUFs and XOR Bistable Ring PUF. Our findings show that the metric explains the impact of various parameter choices of these PUF compositions on the NL obtained and thus promises to be used as an important objective criterion for future efforts to evaluate PUF designs. While the framework is not representative of the machine learning robustness of PUFs, it can be a useful complementary tool to analyze the cryptanalytic strengths of PUF primitives. Durba Chatterjee, Kuheli Pratihar, Aritra Hazra, Ulrich Rührmair, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | On the Instability of Softmax Attention-Based Deep Learning Models in Side-Channel AnalysisabstractIn side-channel analysis (SCA), Points-of-Interest (PoIs), i.e., the informative sample points remain sparsely scattered across the whole side-channel trace. Several works in the SCA literature have demonstrated that the attack efficacy could be significantly improved by combining information from the sparsely occurring PoIs. In Deep Learning (DL), a common approach for combining the information from the sparsely occurring PoIs is softmax attention. This work studies the training instability of the softmax attention-based CNN models on long traces. We show that the softmax attention-based CNN model incurs an unstable training problem when applied to longer traces (e.g., traces having a length greater than$10K$sample points). We also explore the use of batch normalization and multi-head softmax attention to make the CNN models stable. Our results show that the use of a large number of batch normalization layers and/or multi-head softmax attention (replacing the vanilla softmax attention) can make the models significantly more stable, resulting in better attack efficacy. Moreover, we found our models to achieve similar or better results (up to 85% reduction in the minimum number of the required traces to reach the guessing entropy 1) than the state-of-the-art results on several synchronized and desynchronized datasets. Finally, by plotting the loss surface of the DL models, we demonstrate that using multi-head softmax attention instead of vanilla softmax attention in the CNN models can make the loss surface significantly smoother. Suvadeep Hajra, Manaar Alam, Sayandeep Saha, Stjepan Picek, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | ExploreFault: Identifying Exploitable Fault Models in Block Ciphers with Reinforcement LearningabstractExploitable fault models for block ciphers are typically cipher-specific, and their identification is essential for evaluating and certifying fault attack-protected implementations. However, identifying exploitable fault models has been a complex manual process. In this work, we utilize reinforcement learning (RL) to identify exploitable fault models generically and automatically. In contrast to the several weeks/months of tedious analyses required from experts, our RL-based approach identifies exploitable fault models for protected/unprotected AES and GIFT ciphers within 12 hours. Notably, in addition to all existing fault models, we identify/discover a novel fault model for GIFT, illustrating the power and promise of our approach in exploring new attack avenues. Sayandeep Saha, Vasudev Gohil, Satwik Patnaik, Debdeep Mukhopadhyay, Jeyavijayan Rajendran |
DAC | 5 |
| 2023 | Conjunctive Searchable Symmetric Encryption from Hard LatticesabstractSearchable Symmetric Encryption (SSE) supports efficient keyword searches over encrypted outsourced document collections while minimizing information leakage. All practically efficient SSE schemes supporting conjunctive queries rely crucially on quantum-broken cryptographic assumptions (such as discrete-log hard groups) to achieve compact storage and fast query processing. On the other hand, quantum-safe SSE schemes based on purely symmetric-key cryptoprimitives either do not support conjunctive searches, or are practically inefficient. In particular, there exists no quantum-safe yet practically efficient conjunctive SSE scheme from lattice-based hardness assumptions.We solve this open question by proposing Oblivious Post-Quantum Secure Cross Tags (OQXT) – the first lattice-based practically efficient and highly scalable conjunctive SSE scheme. The technical centerpiece of OQXT is a novel oblivious cross-tag generation protocol with provable security guarantees derived from lattice-based hardness assumptions. We prove the post-quantum simulation security of OQXT with respect to a rigorously defined and thoroughly analyzed leakage profile. We then present a prototype implementation of OQXT and experimentally validate its practical efficiency and scalability over extremely large real-world databases. Our experiments show that OQXT has competitive end-to-end search latency when compared with the best (quantum-broken) conjunctive SSE schemes. Debadrita Talapatra, Sikhar Patranabis, Debdeep Mukhopadhyay |
EuroS&P | 3 |
| 2023 | Are Randomized Caches Truly Random? Formal Analysis of Randomized-Partitioned CachesabstractCache based side-channel attacks exploit the fact that an adversary can setup the shared cache memory (the last level cache in modern systems) into a known state and detect any microarchitectural state changes made by the victim on the cache. Different mitigation techniques have been proposed in the literature that aims to mitigate these attacks by randomizing the address to cache location mappings. The security guarantees in these schemes are based on the degree of difficulty for an attacker to reliably determine the cache lines accessed by the victim within practical time settings. However, prior attacks have shown that newer and more improved algorithms can be envisaged that discover conflicting sets in the secured randomized caches. In this work, we first categorize different types of cache designs into four broad classes based on the extent of non-determinism and randomness of allocating an address in those caches. We then develop a mathematical framework to formally analyse the security implications of the randomized and partitioned cache designs in terms of collision probability, self-collision probability and size of the eviction set required to perform a successful eviction-based attack. We further empirically demonstrate set associative eviction on recently proposed randomization schemes called Mirage and Scattercache. Next, we propose two algorithms to generate efficient eviction set on these schemes and analytically evaluate the efficacy of our algorithms against the one proposed in the literature. Finally, we argue that mere randomization using a cryptographic primitive as used in popular schemes like Scattercache, CEASER-S, Mirage etc. does not provide the required randomness. Although the randomized-partitioned caches provide some resilience against eviction-set generation techniques, they are still vulnerable to eviction-based attacks. Anirban Chakraborty 0003, Sarani Bhattacharya, Sayandeep Saha, Debdeep Mukhopadhyay |
HPCA | 4 |
| 2023 | Learn from Your Faults: Leakage Assessment in Fault Attacks Using Deep Learning
Sayandeep Saha, Manaar Alam, Arnab Bag, Debdeep Mukhopadhyay, Pallab Dasgupta |
J. Cryptol. | 4 |
| 2023 | TWo-IN-one-SSE: Fast, Scalable and Storage-Efficient Searchable Symmetric Encryption for Conjunctive and Disjunctive Boolean QueriesabstractSearchable Symmetric Encryption (SSE) supports efficient yet secure query processing over outsourced symmetrically encrypted databases without the need for decryption. A longstanding open question has been the following: can we design a fast, scalable, linear storage and low-leakage SSE scheme that efficiently supports arbitrary Boolean queries over encrypted databases? In this paper, we present the design, analysis and prototype implementation of the first SSE scheme that efficiently supports conjunctive, disjunctive and more general Boolean queries (in both the conjunctive and disjunctive normal forms) while scaling smoothly to extremely large encrypted databases, and while incurring linear storage overheads and supporting extremely fast query processing in practice. We quantify the leakage of our proposal via a rigorous cryptographic analysis and argue that it achieves security against a well-known class of leakage-abuse and volume analysis attacks. Finally, we demonstrate the storage-efficiency and scalability of our proposed scheme by presenting experimental results of a prototype implementation of our scheme over large real-world databases. Arnab Bag, Debadrita Talapatra, Ayushi Rastogi, Sikhar Patranabis, Debdeep Mukhopadhyay |
Proc. Priv. Enhancing Technol. | 5 |
| 2023 | Birds of the Same Feather Flock Together: A Dual-Mode Circuit Candidate for Strong PUF-TRNG FunctionalitiesabstractPhysically Unclonable Functions (PUFs) and True Random Number Generators (TRNGs) are two highly useful hardware primitives to build up the root-of-trust for embedded devices in Internet-of-Things and Cyber-Physical System applications. These applications demand the primitives be lightweight, yet flexible. However, PUFs are designed to offerrepetitive and instance-specificrandomness, whereas TRNGs are expected to beinvariablyrandom. A challenging but thought-provoking problem from a hardware designer's perspective would be to design a circuit that serves the purpose of both PUF and TRNG depending on the exact requirement of the application. Here, we present a dual-mode PUF-TRNG design that utilises two different hardware-intrinsic properties, i.e., oscillatory metastability of Transition Effect Ring Oscillator (TERO) cell and propagation delay of a buffer within the cell to achieve this goal. A 48.62% reduction in area is accomplished due to the integration in comparison to separate instances of standalone PUFs/ TRNG designs, built from Programmable Delay Line (PDL) based Arbiter PUFs (APUFs) and TERO-TRNG. Our final design has a hardware footprint of 618 Look-Up Tables (LUTs) and 447 Flip-Flops (FFs). Furthermore, experimental analysis of the state-of-the-art modelling attacks, reliability attacks on the proposed PUF design shows a prediction accuracy of 55.37% and 50.14% respectively for 5.2M Challenge Response Pairs (CRPs). Additionally, the TRNG passes evaluation through National Institute of Standards and Technology (NIST) Special Publication (SP) 800-22 and German Federal Office for Information Security (BSI) Application Notes and Interpretation of the Scheme (AIS)-31 tests. Kuheli Pratihar, Urbi Chatterjee, Manaar Alam, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 5 |
| 2023 | CAMiSE: Content Addressable Memory-Integrated Searchable EncryptionabstractSearchable symmetric encryption (SSE) is a special class of encryption schemes for computing directly over encrypted data. SSE aims to be significantly more efficient as compared to other solutions, such as fully homomorphic encryption (FHE), while leaking only minimal information to the adversary. SSE is particularly efficient and scalable for Boolean queries over large encrypted relational databases outsourced to third-party cloud service providers. However, practical implementations of SSE often suffer from performance bottlenecks due to randomised memory accesses for reads/writes and computation-intensive cryptographic operations. As a result, a gap exists today between theoretically efficient SSE algorithms and practically efficient SSE systems for real-world databases. In this paper, we address this longstanding open question that has otherwise hindered the widespread deployment of SSE over real cloud computing platforms. We proposeCAMiSE–a fully associative memory-integrated framework for designing SSE systems with fast query processing over extremely large databases. We show a novel usage of custom-designed Content Addressable Memory (CAM), together with robust data access policies, to bridge the memory wall in traditional SSE implementations by minimising storage-access latencies due to randomised look-up operations during searches. Coupled with dedicated hardware accelerators for cryptographic operations,CAMiSEachieves extremely fast and scalable query processing over encrypted relational databases. We prototype multiple well-known SSE algorithms and SSE data structures within our proposedCAMiSEframework. Our experiments show that these implementations achieve around$5\times $to$7\times $speed-up over traditional software-based implementations while scaling smoothly to extensive real-world databases with millions of records. Arnab Bag, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2023 | CAD Support for Security and Robustness Analysis of Safety-critical Automotive SoftwareabstractModern vehicles contain a multitude of electronic control units that implement software features controlling most of the operational, entertainment, connectivity, and safety aspects of the vehicle. However, with security requirements often being an afterthought in automotive software development, incorporation of such software features with intra- and inter-vehicular connectivity requirements often opens up new attack surfaces. Demonstrations of such security vulnerabilities in past reports and literature bring in the necessity to formally analyze how secure automotive control systems really are against adversarial attacks. Modern vehicles often incorporate onboard monitoring systems that test the sanctity of data samples communicated among controllers and detect possible attack/noise insertion scenarios. The performance of such monitors against security threats also needs to be verified. In this work, we outline a rigorous methodology for estimating the vulnerability of automotive CPSs. We provide a computer-aided design framework that considers the model-based representation of safety-critical automotive controllers and monitoring systems working in a closed loop with vehicle dynamics and verifies their safety and robustness w.r.t. false data injection attacks. Symbolically exploring all possible combinations of attack points of the input automotive CPS, the proposed framework tries to find out which sensor and/or actuation signal is vulnerable by generating stealthy and successful attacks using a formal method-based counter-example guided abstract refinement process. We also validate the efficacy of the proposed framework using a case study performed in an industry-scale simulator. Ipsita Koley, Soumyajit Dey, Debdeep Mukhopadhyay, Sachin Kumar Singh, Lavanya Lokesh, Shantaram Vishwanath Ghotgalkar |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2023 | PReFeR : Physically Related Function based Remote Attestation ProtocolabstractRemote attestation is a request-response based security service that permits a trusted entity (verifier) to check the current state of an untrusted remote device (prover). The verifier initiates the attestation process by sending an attestation challenge to the prover; the prover responds with its current state, which establishes its trustworthiness. Physically Unclonable Function (PUF) offers an attractive choice for hybrid attestation schemes owing to its low overhead security guarantees. However, this comes with the limitation of secure storage of the PUF model or large challenge-response database on the verifier end. To address these issues, in this work, we propose a hybrid attestation framework, named PReFeR , that leverages a new class of hardware primitive known as Physically Related Function (PReF) to remotely attest low-end devices without the requirement of secure storage or heavy cryptographic operations. It comprises a static attestation scheme that validates the memory state of the remote device prior to code execution, followed by a dynamic run-time attestation scheme that asserts the correct code execution by evaluating the content of special registers present in embedded systems, known as hardware performance counters (HPC). The use of HPCs in the dynamic attestation scheme mitigates the popular class of attack known as the time-of-check-time-of-use (TOCTOU) attack, which has broken several state-of-the-art hybrid attestation schemes. We demonstrate our protocol and present our experimental results using a prototype implementation on Digilent Cora Z7 board, a low-cost embedded platform, specially designed for IoT applications. Anupam Mondal, Shreya Gangopadhyay, Durba Chatterjee, Harishma Boyapally, Debdeep Mukhopadhyay |
ACM Trans. Embed. Comput. Syst. | 5 |
| 2023 | Commitments via Physically Related FunctionsabstractCommitment schemes are one of the basic building blocks to construct secure protocols for multi party computation. Many recent works are exploring hardware primitives like physically unclonable functions to build keyless cryptographic protocols, with minimal assumptions. The asymmetric nature and non-invertibility property of PUFs are widely exploited to build oblivious transfer protocols that are extended to build bit-commitment schemes. However, these schemes require the physical transfer of the PUF device between the interacting parties. In this work, we introduce a new class of hardware-based primitives called physically related functions that enable hardware circuits to securely communicate with each other over insecure channels. We propose a bit-commitment protocol based on this hardware primitive without needing any physical transfer. Our scheme is statistically hiding and computationally binding, requiring only one round of communication while being practically deployable. We explore the security properties of physically related functions, under which we prove the security of our scheme. We experimentally show that it is impossible to break the security of the scheme with more than negligible probability. Harishma Boyapally, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Time's a Thief of Memory - Breaking Multi-tenant Isolation in TrustZones Through Timing Based Bidirectional Covert Channels
Nimish Mishra, Anirban Chakraborty 0003, Urbi Chatterjee, Debdeep Mukhopadhyay |
CARDIS | 4 |
| 2022 | Work-in-Progress: CAMiSE: Content Addressable Memory-integrated Searchable EncryptionabstractSearchable symmetric encryption (SSE) aims to support efficient query-execution directly over encrypted databases. Practical implementations of SSE suffer from performance bottlenecks due to randomised memory accesses and computation-intensive cryptographic operations. We propose CAMISE – a fully associative memory-integrated framework for designing SSE systems with fast query processing over large databases. We show a novel usage of custom-designed Content Addressable Memory (CAM) to minimise storage-access latencies during query execution in SSE systems. We prototype a well-known SSE scheme, namely Oblivious Cross Tags (OXT), within this framework. Our implementation achieves 5x-7x speed-up over traditional software-based implementations while scaling smoothly to real-world databases with millions of records. Arnab Bag, Sikhar Patranabis, Debdeep Mukhopadhyay |
CASES | 3 |
| 2022 | ASHES 2022 - 6th Workshop on Attacks and Solutions in Hardware SecurityabstractThe workshop on "Attacks and Solutions in HardwarE Security (ASHES)" welcomes any theoretical and practical works on hardware security, including attacks, solutions, countermeasures, proofs, classification, formalization, and implementations. Besides mainstream research, ASHES puts some focus on new and emerging scenarios: This includes the Internet of Things (IoT), nuclear weapons inspections, arms control, consumer and infrastructure security, or supply chain security, among others. ASHES also welcomes dedicated works on special purpose hardware, such as lightweight, low-cost, and energy-efficient devices, or non-electronic security systems. The workshop hosts four different paper categories: Apart from regular and short papers, this includes works that systematize and structure a certain (sub-)area (so-called "Systematization of Knowledge" (SoK) papers), and so-termed "Wild-and-Crazy" (WaC) papers, which distribute seminal ideas at an early conceptual stage. This summary gives a brief overview of the sixth edition of the workshop, which took place virtually on November 11, 2022 in Los Angeles, California, USA, as a post-conference satellite workshop of ACM CCS. Chip-Hong Chang, Domenic Forte, Debdeep Mukhopadhyay, Ulrich Rührmair |
CCS | 3 |
| 2022 | Timed speculative attacks exploiting store-to-load forwarding bypassing cache-based countermeasuresabstractIn this paper, we propose a novel class of speculative attacks, called Timed Speculative Attacks (TSA), that does not depend on the state changes in the cache memory. Instead, it makes use of the timing differences that occur due to store-to-load forwarding. We propose two attack strategies - Fill-and-Forward utilizing correctly speculated loads, and Fill-and-Misdirect using mis-speculated load instructions. While Fill-and-Forward exploits the shared store buffers in a multi-threaded CPU core, the Fill-and-Misdirect approach exploits the influence of rolled back mis-speculated loads on subsequent instructions. As case studies, we demonstrate a covert channel using Fill-and-Forward and key recovery attacks on OpenSSL AES and Romulus-N Authenticated Encryption with Associated Data scheme using Fill-and-Misdirect approach. Finally, we show that TSA is able to subvert popular cache-based countermeasures for transient attacks. Anirban Chakraborty 0003, Nikhilesh Singh, Sarani Bhattacharya, Chester Rebeiro, Debdeep Mukhopadhyay |
DAC | 5 |
| 2022 | DIP Learning on CAS-Lock: Using Distinguishing Input Patterns for Attacking Logic LockingabstractThe globalization of the integrated circuit (IC) manufacturing industry has lured the adversary to come up with numerous malicious activities in the IC supply chain. Logic locking has risen to prominence as a proactive defense strategy against such threats. CAS-Lock (proposed in CHES'20), is an advanced logic locking technique that harnesses the concept of single-point function in providing SAT-attack resiliency. It is claimed to be powerful and efficient enough in mitigating existing state-of-the-art attacks against logic locking techniques. Despite the security robustness of CAS-Lock as claimed by the authors, we expose a serious vulnerability and by exploiting the same we devise a novel attack algorithm against CAS-Lock. The proposed attack can not only reveal the correct key but also the exact AND/OR structure of the implemented CAS-Lock design along with all the key gates utilized in both the blocks of CAS-Lock. It simply relies on the externally observable Distinguishing Input Patterns (DIPs) pertaining to a carefully chosen key simulation of the locked design without the requirement of structural analysis of any kind of the locked netlist. Our attack is successful against various AND/OR cascaded-chain configurations of CAS-Lock and reports 100% success rate in recovering the correct key. It has an attack complexity of$\mathcal{O}(m)$, where$m$denotes the number of DIPs obtained for an incorrect key simulation. Akashdeep Saha, Urbi Chatterjee, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
DATE | 3 |
| 2022 | Is the Whole lesser than its Parts? Breaking an Aggregation based Privacy aware Metering AlgorithmabstractSmart metering is a mechanism through which fine-grained electricity usage data of consumers is collected periodically in a smart grid. However, a growing concern in this regard is that the leakage of consumers' consumption data may reveal their daily life patterns as the state-of-the-art metering strategies lack adequate security and privacy measures. Many proposed solutions have demonstrated how the aggregated metering information can be transformed to obscure individual consumption patterns without affecting the intended semantics of smart grid operations. In this paper, we expose a complete break of such an existing privacy preserving metering scheme [10] by determining individual consumption patterns efficiently, thus compromising its privacy guarantees. The underlying methodol-ogy of this scheme allows us to - i) retrieve the lower bounds of the privacy parameters and ii) establish a relationship between the privacy preserved output readings and the initial input readings. Subsequently, we present a rigorous experimental validation of our proposed attacking methodology using real-life dataset to highlight its efficacy. In summary, the present paper queries: Is the Whole lesser than its Parts? for such privacy aware metering algorithms which attempt to reduce the information leakage of aggregated consumption patterns of the individuals. Soumyadyuti Ghosh, Urbi Chatterjee, Soumyajit Dey, Debdeep Mukhopadhyay |
DSD | 4 |
| 2022 | AntiSIFA-CAD: A Framework to Thwart SIFA at the Layout LevelabstractFault Attacks (FA) have gained a lot of attention from both industry and academia due to their practicality, and wide applicability to different domains of computing. In the context of symmetric-key cryptography, designing countermeasures against FA is still an open problem. Recently proposed attacks such as Statistical Ineffective Fault Analysis (SIFA) has shown that merely adding redundancy or infection-based countermeasure to detect the fault doesn't work and a proper combination of masking and error correction/detection is required. In this work, we show that masking which is mathematically established as a good countermeasure against a certain class of SIFA faults, in practice may fall short if low-level details during physical design layout development are not taken care of. We initiate this study by demonstrating a successful SIFA attack on a post placed-and-routed masked crypto design for ASIC platform. Eventually, we propose a fully automated approach along with a proper choice of placement constraints which can be realized easily for any commercial CAD tools to successfully get rid of this vulnerability during the physical layout development process. Our experimental validation of our tool flow over masked implementation on PRESENT cipher establishes our claim. Rajat Sadhukhan, Sayandeep Saha, Debdeep Mukhopadhyay |
ICCAD | 3 |
| 2022 | Innovation Practices Track: Security in Test and Test for SecurityabstractVLSI testing is essential to guarantee the correct functionality of the chip design. The recent advances in hardware security have posed new challenges for testing. In this IP session, we discuss the security in test and test for security through three talks. First, we give a brief overview of the security vulnerabilities and countermeasures in scan chain design, followed by a detailed discussion of a new configurable partial scan design approach. Second, we present the challenges in testing the security of design at various design stages and propose a strategy to identify potential security vulnerabilities in early design stages. Finally, we consider physical unclonable function (PUF) and develop an adaptive framework based on machine learning for the test and error correction of PUF designs. Gang Qu 0001, Benjamin Tan 0001, Kuheli Pratihar, Debdeep Mukhopadhyay, Ramesh Karri |
VTS | 4 |
| 2022 | NN-Lock: A Lightweight Authorization to Prevent IP Threats of Deep Learning ModelsabstractThe prevalent usage and unparalleled recent success of Deep Neural Network (DNN) applications have raised the concern of protecting their Intellectual Property (IP) rights in different business models to prevent the theft of trade secrets. In this article, we propose a lightweight, generic, key-based DNN IP protection methodology, NN-Lock , to defend against unauthorized usage of stolen DNN models. NN-Lock utilizes SBox, a cryptographic primitive, with good security properties to encrypt each parameter of a trained DNN model with the secret keys derived from a master key through a key-scheduling algorithm. The method ensures that only an authorized user with a correct master key can accurately use the locked DNN model. Evaluation results of NN-Lock on a Google Coral edge device for various DNN architectures on several datasets show that for an incorrect master key, the accuracy of a locked model is that of a random classifier. The dense network of encrypted parameters makes the method robust against the model fine-tuning attack and a novel approximation attack using the Genetic Algorithm, which achieves reasonable success against another recent IP protection scheme called HPNN Chakraborty et al. 2020 . The security evaluation of NN-Lock against other families of attacks demonstrates its soundness in practical scenarios. NN-Lock does not modify any internal structure of a DNN model, making it scalable for all of the existing DNN implementations without adversely affecting their performance. Manaar Alam, Sayandeep Saha, Debdeep Mukhopadhyay, Sandip Kundu |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2022 | FlexiPair: An Automated Programmable Framework for Pairing CryptosystemsabstractPairing cryptosystems are extremely powerful mathematical tools for developing cryptographic protocols that can provide end-to-end security for applications like Internet-of-Things (IoT), cloud services and cyber-physical systems (CPS). However, these applications require the implementations to be light-weight but still real-time, with the additional feature of being flexible. The flexibility can come from different choices of underlying algorithms along with suitable parameter choices. A software implementation offers better flexibility but lacks in timing performance, whereas custom hardware delivers better performance but has poor flexibility. Furthermore, the designs over small characteristic curves are now insecure against recent attacks. Existing designs do not address the drawback of less flexibility and huge resource consumption collectively. In this article, we present a micro-program controlled hardware design which has the least resource consumption among the similar existing designs on FPGA that offer such programmability and flexibility. This redundant number arithmetic-based architecture consumes only 2506 slices on Xilinx Virtex-7 FPGA. It can be migrated to other device families or updated for different algorithms without data-path or control-path modification. To enhance the flexibility, we developed a custom assembly-like finite state machine (FSM) description, called Prism, and necessary tool to generate the micro-program states. To illustrate the functionality of Prism, we present designs for Tate and Optimal-Ate pairing with the micro-program states generated using this tool. Arnab Bag, Debapriya Basu Roy, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 4 |
| 2022 | Exploring Bitslicing Architectures for Enabling FHE-Assisted Machine LearningabstractHomomorphic encryption (HE) is the ultimate tool for performing secure computations even in untrusted environments. Application of HE for deep learning (DL) inference is an active area of research, given the fact that DL models are often deployed in untrusted environments (e.g., third-party servers) yet inferring on private data. However, existing HE libraries [somewhat (SWHE), leveled (LHE) or fully homomorphic (FHE)] suffer from extensive computational and memory overhead. Few performance optimized high-speed homomorphic libraries are either suffering from certain approximation issues leading to decryption errors or proven to be insecure according to recent published attacks. In this article, we propose architectural tricks to achieve performance speedup for encrypted DL inference developed with exact HE schemes without any approximation or decryption error in homomorphic computations. The main idea is to apply quantization and suitable data packing in the form of bitslicing to reduce the costly noise handling operation, Bootstrapping while achieving a functionally correct and highly parallel DL pipeline with a moderate memory footprint. Experimental evaluation on the MNIST dataset shows a significant ( $37\times$ ) speedup over the nonbitsliced versions of the same architecture. Low memory bandwidths (700 MB) of our design pipelines further highlight their promise toward scaling over larger gamut of Edge-AI analytics use cases. Soumik Sinha, Sayandeep Saha, Manaar Alam, Varun Agarwal, Ayantika Chatterjee, Anoop Mishra, Deepak Khazanchi, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 8 |
| 2022 | Safe is the New Smart: PUF-Based Authentication for Load Modification-Resistant Smart MetersabstractIn the energy sector, IoT manifests in the form of next-generation power grids that provide enhanced electrical stability, efficient power distribution, and utilization. The primary feature of a Smart Grid is the presence of an advanced bi-directional communication network between the Smart meters at the consumer end and the servers at the Utility Operators. Smart meters are broadly vulnerable to attacks on communication and physical systems. We propose a secure and operationally asymmetric mutual authentication and key-exchange protocol for secure communication. Our protocol balances security and efficiency, delegates complex cryptographic operations to the resource-equipped servers, and carefully manages the workload on the resource-constrained Smart meter nodes using unconventional lightweight primitives such as Physically Unclonable Functions. We prove the security of the protocol using well-established cryptographic assumptions. We implement the proposed scheme end-to-end in a Smart meter prototype using commercial-off-the-shelf products, a Utility server, and a credential generator as the trusted third party. Additionally, we demonstrate a physics-based attack named load modification attack on the Smart meter to demonstrate that merely securing the communication channel using authentication does not secure the meter, but requires further protections to ensure the correctness of the reported consumption. Hence, we propose a countermeasure to such an attack that goes side-by-side with our protocol implementation. Harishma Boyapally, Paulson Mathew, Sikhar Patranabis, Urbi Chatterjee, Umang Agarwal, Manu Maheshwari, Soumyajit Dey, Debdeep Mukhopadhyay |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2022 | Physically Related Functions: Exploiting Related Inputs of PUFs for Authenticated-Key ExchangeabstractThis paper initiates the study of “Cryptophasia in Hardware” – a phenomenon that allows hardware circuits/devices with no pre-established secret keys to securely exchange secret information over insecure communication networks. The study of cryptophasia is motivated by the need to establish secure communication channels between lightweight resource-constrained devices incapable of securely storing cryptographic keys and/or executing resource-intensive cryptographic protocols. In this paper, we introduce a novel concept calledPhysically Related Functions(PReFs) that can exchange secret information in a secure and authenticated manner over insecure networks. This function can be visualized as an abstraction of Strong Physically Unclonable Functions (PUFs). Strong PUFs have the limitation in communicating between two identical devices, an issue that we address in the definition of PReFs. We describe a formal framework for analyzing the functional and security requirements of PReFs. In this framework, we present a lightweight (in terms of computation cost) yet provably secure authenticated key-exchange protocol that relies only on PReFs and makes no additional assumptions (such as secure storage of cryptographic keys). Finally, we present a proof-of-concept realization of PReFs in hardware over Digilent Cora Z7 – a low-cost development platform (consisting of an ARM Cortex processor and a Xilinx FPGA) that is particularly suitable for real-world IoT applications involving resource-constrained devices. We validate that our realization of PReFs satisfies all the properties warranted by our formal framework. We further demonstrate the efficacy of our proposed protocol by analyzing its performance (in terms of computational and communication latency) over the Digilent Cora Z7 platform. Durba Chatterjee, Harishma Boyapally, Sikhar Patranabis, Urbi Chatterjee, Aritra Hazra, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2021 | Divided We Stand, United We Fall: Security Analysis of Some SCA+SIFA Countermeasures Against SCA-Enhanced Fault Template Attacks
Sayandeep Saha, Arnab Bag, Dirmanto Jap, Debdeep Mukhopadhyay, Shivam Bhasin |
ASIACRYPT (2) | 4 |
| 2021 | SACReD: An Attack Framework on SAC Resistant Delay-PUFs leveraging Bias and Reliability FactorsabstractThe S-PUF and Sn-PUF designs (proposed in IN-DOCRYPT2019) are one of the contemporary composite strong PUF candidates of the Delay-PUF family that exhibit two distinguishing and notable attributes – (i) it is one of the few PUF constructions which is guided by theoretical analysis of the Strict Avalanche Criteria (SAC) property and not by ad-hoc choices; and (ii) though its construction is quite similar to XOR PUFs, it has very good reliability property unlike the former design due to the introduction of Maiorana-McFarland (M-M) Bent Function. These make Sn-PUF to be a very good candidate for strong PUF proposals and an interesting target from the point of view of attackers. In this work, we testify that a novel reliability based machine learning attack can be launched in this architecture against the original authors’ claim. Though it is challenging to launch a classical or reliability based ML attack directly, we leverage the bias introduced by the AND operation in the M-M bent function due to its non-linearity property. Our proposed novel attack framework, SACReD, is able to break $S_{8}, S_{10}$ and $S_{12}-$PUF designs, which were originally assumed to be secure, by taking only 400K Challenge-Response Pairs. Durba Chatterjee, Urbi Chatterjee, Debdeep Mukhopadhyay, Aritra Hazra |
DAC | 3 |
| 2021 | Shortest Path to Secured Hardware: Domain Oriented Masking with High-Level-SynthesisabstractImplementing hardware secure against side-channel attacks (SCA) demands significant time and expertise in hardware design. In this paper, we propose a simple and fast approach for synthesizing masked block cipher hardware from a C-code exploiting High-Level-Synthesis (HLS), which allows a very short design time. Compared to previous approaches, our proposal provides a systematic and general flow based on state-of-the-art Domain-Oriented Masking (DOM). We also present a fast security-validation flow for the synthesized circuits at the early design stages using commercial-off-the-shelf CAD tools. Efficacy of the proposed design-flow has been established over a set of representative benchmarks including a masked S-Box and a lightweight block-cipher. Rajat Sadhukhan, Sayandeep Saha, Debdeep Mukhopadhyay |
DAC | 3 |
| 2021 | Forward and Backward Private Conjunctive Searchable Symmetric Encryption
Sikhar Patranabis, Debdeep Mukhopadhyay |
NDSS | 2 |
| 2021 | Formal Analysis of Physically Unclonable FunctionsabstractIn this research work, we aim to formalize the analysis of Physically Unclonable Functions (PUF) constructions. First, we present a testability analysis scheme that leverages the correlation spectra properties of Boolean functions to assess the quality of a collection of PUF instances of the same make by comparing its correlation spectra with that of a collection of known good PUF instances. Further, in the research, we propose a CAD framework that automatically assesses the learnability of a PUF construction in the PAC Learning model. To represent a PUF design, we propose a formal PUF representation language capable of representing any PUF construction or composition upfront. Next, we present a non-linearity assisted reliability based ML attack on a contemporary PUF construction, named Sn-PUF. We leverage the non-linearity of the Bent function to launch a reliability-based ML attack, that is able to break upto S12-PUF. Durba Chatterjee, Debdeep Mukhopadhyay, Aritra Hazra |
VLSI-SoC | 2 |
| 2021 | Design and Analysis of Logic Locking TechniquesabstractThe skyrocketing cost of integrated circuit (IC) manufacturing has forced the majority of enterprises to shift to fabless operation. IC design is often outsourced to foreign fabrication laboratories to reduce time and cost However, as a flip-side, it has introduced various hardware security concerns at different stages in the supply chain, namely, IP piracy, illegal overproduction, design counterfeiting, etc. Logic locking has risen to prominence as a proactive defense strategy against such threats. The basic idea of logic locking is to obscure the actual design to an adversary by integrating additional key-based logic into the original design. The authors in [1] have proposed an obfuscation scheme using a class of non-group additive cellular automata (CA) called $D1 * CA$ and $D1 * CA_{dual}$ to obfuscate each state-transition of an FSM. We propose a novel attack (named ORACALL) to extract the secret key used to obfuscate each FSM state-transition. We further propose a novel logic locking technique [2] which harnesses the security of block ciphers. It is found to be secure against known existing attacks. Akashdeep Saha, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
VLSI-SoC | 2 |
| 2021 | Victims Can Be Saviors: A Machine Learning-based Detection for Micro-Architectural Side-Channel AttacksabstractMicro-architectural side-channel attacks are major threats to the most mathematically sophisticated encryption algorithms. In spite of the fact that there exist several defense techniques, the overhead of implementing the countermeasures remains a matter of concern. A promising strategy is to develop online detection and prevention methods for these attacks. Though some recent studies have devised online prevention mechanisms for some categories of these attacks, still other classes remain undetected. Moreover, to detect these side-channel attacks with minimal False Positives is a challenging effort because of the similarity of their behavior with computationally intensive applications. This article presents a generalized machine learning--based multi-layer detection technique that targets these micro-architectural side-channel attacks, while not restricting its attention only on a single category of attacks. The proposed mechanism gathers low-level system information by profiling performance counter events using Linux perf tool and then applies machine learning techniques to analyze the data. A novel approach using time-series analysis of the data is implemented to find out the correlation of the execution trace of the attack process with the secret key of encryption, which helps in dealing with False-Positives and unknown attacks. This article also provides a detailed theoretical analysis of the detection mechanism of the proposed model along with its security analysis. The experimental results show that the proposed method is superior to the state-of-the-art reported techniques with high detection accuracy, low False Positives, and low implementation overhead while being able to detect before the completion of the attack. Manaar Alam, Sarani Bhattacharya, Debdeep Mukhopadhyay |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2021 | Introduction to the Special Issue on Emerging Challenges and Solutions in Hardware Securityabstractintroduction Introduction to the Special Issue on Emerging Challenges and Solutions in Hardware Security Share on Editors: Domenic Forte View Profile , Debdeep Mukhopadhyay View Profile , Ilia Polian View Profile , Yunsi Fei View Profile , Rosario Cammarota View Profile Authors Info & Claims ACM Journal on Emerging Technologies in Computing SystemsVolume 17Issue 3July 2021 Article No.: 29pp 1–4https://doi.org/10.1145/3464326Online:30 June 2021Publication History 0citation108DownloadsMetricsTotal Citations0Total Downloads108Last 12 Months108Last 6 weeks4 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Domenic Forte, Debdeep Mukhopadhyay, Ilia Polian, Yunsi Fei, Rosario Cammarota |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2021 | A Formal Analysis of Prefetching in Profiled Cache-Timing Attacks on Block Ciphers
Chester Rebeiro, Debdeep Mukhopadhyay |
J. Cryptol. | 2 |
| 2021 | ORACALL: An Oracle-Based Attack on Cellular Automata Guided Logic LockingabstractIn logic locking, the finite-state machine (FSM) embedded in a sequential circuit is often chosen to be obfuscated. Such an obfuscation scheme using a class of nongroup additive cellular automata (CA) called$D1 * CA$and$D1 * CA_{\mathrm{ dual}}$to obfuscate each state transition of an FSM has been proposed previously. Since$D1 * CA$and$D1 * CA_{\mathrm{ dual}}$provide high testability even in the absence of scan-based design-for-testability techniques, they conceal the sequential elements, thus thwarting several existing scan-chain attacks. In this article, we introduce a novel attack to extract the secret key used to obfuscate each state transition of the FSM, by utilizing the information leaked by the leftmost CA cell, which is obtained via an oracle query to the obfuscated circuit. The proposed attack has two variants: 1) when the combinational circuit of theInterrupt Logicis not logic encrypted and 2) when theInterrupt Logicis logic encrypted with a$k$-bit key. The first attack variant has a complexity of$\mathcal {O}(n \cdot m)$, where$n$denotes the number of transitions in the FSM, and$m$denotes the maximum transition cycle length of the underlying$D1 * CA$. The second attack variant has a complexity of$\mathcal {O}(n\cdot q_{\mathrm{ max}})$, where$q_{\mathrm{ max}}$denotes the maximum number of oracle queries (equal to the number of primary inputs involved in that state transition), followed by a SAT-attack to extract the$k$-bit key of the correspondingInterrupt Logic. The experimental evaluation of the attack on CA-based obfuscated benchmark circuits establishes the effectiveness of our proposed attack. Akashdeep Saha, Hrivu Banerjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2021 | 3PAA: A Private PUF Protocol for Anonymous AuthenticationabstractAnonymous authentication (AA) schemes are used by an application provider to grant services to its n users for pre-defined k times after they have authenticated themselves anonymously. These privacy-preserving cryptographic schemes are essentially based on the secret key that is embedded in a trusted platform module (TPM). In this work, we propose a private physically unclonable function (PUF) based scheme that overcomes the shortcomings of prior attempts to incorporate PUF for AA schemes. Traditional PUF based authentication protocols have their limitations as they only work based on challenge-response pairs (CRPs) exposed to the verifier, thus violating the principle of anonymity. Here, we ensure that even if the PUF instance is private to the user, it can be used for authentication to the application provider. Besides, no raw CRPs need to be stored in a secure database, thus making it more difficult for an adversary to launch model-building attacks on the deployed PUFs. We reduce the execution time from O(n) to O(1) and storage overhead from O(nk) to O(n) compared to state-of-the-art AA protocols and also dispense the necessity of maintaining a revocation list for the compromised keys. In addition, we provide security proofs of the protocol under Elliptic Curve Diffie-Hellman assumption and decisional uniqueness assumption of a PUF. A prototype of the protocol has been implemented on a Z-Turn board integrated with dual-core ARM CortexA9 processor and Artix-7 FPGA. The resource footprint and performance characterization results show that the proposed scheme is suitable for implementation on resource-constrained platforms. Urbi Chatterjee, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | LoPher: SAT-Hardened Logic Embedding on Block CiphersabstractBlock ciphers are widely regarded as concrete realizations of pseudorandom permutations with established security features. However, their applicability outside the domain of encryption has not been explored so far. In this paper, we open up, for the first time, an entirely novel application of them to logic hiding. We show that a combinational circuit can always be embedded within a block cipher having a bit-permutation based diffusion layer, preserving the cipher structure and security properties. The functionality of the embedded circuit becomes transparent only on the application of a secret key, whereas a wrong key will cause behaviour that is uncorrelated to that of the circuit. As an immediate application, we propose a combinational logic-locking scheme. The proposed locking scheme is also found to be robust against the state-of-the-art (SAT-assisted and other) attacks on logic locks. Akashdeep Saha, Sayandeep Saha, Siddhartha Chowdhury, Debdeep Mukhopadhyay, Bhargab B. Bhattacharya |
DAC | 4 |
| 2020 | ExplFrame: Exploiting Page Frame Cache for Fault Analysis of Block CiphersabstractPage Frame Cache (PFC) is a purely software cache, present in modern Linux based operating systems (OS), which stores the page frames that were recently released by the processes running on a particular CPU. In this paper, we show that the page frame cache can be maliciously exploited by an adversary to steer the pages of a victim process to some pre-decided attacker-chosen locations in the memory. We practically demonstrate an end-to-end attack, ExplFrame, where an attacker having only user-level privilege is able to force a victim process's memory pages to vulnerable locations in DRAM and deterministically conduct Rowhammer to induce faults. As a case study, we induce single bit faults in the T-tables on OpenSSL (v1.1.1) AES using our proposed attack ExplFrame. We also propose an improvised fault analysis technique which can exploit any Rowhammer-induced bit-flips in the AES T-tables. Anirban Chakraborty 0003, Sarani Bhattacharya, Sayandeep Saha, Debdeep Mukhopadhyay |
DATE | 4 |
| 2020 | Towards Secure Composition of Integrated Circuits and Electronic Systems: On the Role of EDAabstractModern electronic systems become evermore complex, yet remain modular, with integrated circuits (ICs) acting as versatile hardware components at their heart. Electronic design automation (EDA) for ICs has focused traditionally on power, performance, and area. However, given the rise of hardware-centric security threats, we believe that EDA must also adopt related notions like secure by design and secure composition of hardware. Despite various promising studies, we argue that some aspects still require more efforts, for example: effective means for compilation of assumptions and constraints for security schemes, all the way from the system level down to the "bare metal"; modeling, evaluation, and consideration of security-relevant metrics; or automated and holistic synthesis of various countermeasures, without inducing negative cross-effects.In this paper, we first introduce hardware security for the EDA community. Next we review prior (academic) art for EDA-driven security evaluation and implementation of countermeasures. We then discuss strategies and challenges for advancing research and development toward secure composition of circuits and systems. Johann Knechtel, Elif Bilge Kavun, Francesco Regazzoni 0001, Annelie Heuser, Anupam Chattopadhyay, Debdeep Mukhopadhyay, Soumyajit Dey, Yunsi Fei, Yaacov Belenky, Itamar Levi, Tim Güneysu, Patrick Schaumont, Ilia Polian |
DATE | 6 |
| 2020 | Formal Synthesis of Monitoring and Detection Systems for Secure CPS ImplementationsabstractWe consider the problem of securing a given control loop implementation of a cyber-physical system (CPS) in the presence of Man-in-the-Middle attacks on data exchange between plant and controller over a compromised network. To this end, there exists various detection schemes which provide mathemat¬ical guarantees against such attacks for the theoretical control model. However, such guarantees may not hold for the actual control software implementation. In this article, we propose a formal approach towards synthesizing attack detectors with varying thresholds which can prevent performance degrading stealthy attacks while minimizing false alarms. Ipsita Koley, Saurav Kumar Ghosh, Soumyajit Dey, Debdeep Mukhopadhyay, Amogh Kashyap K. N., Sachin Kumar Singh, Lavanya Lokesh, Jithin Nalu Purakkal, Nishant Sinha 0003 |
DATE | 4 |
| 2020 | Fault Template Attacks on Block Ciphers Exploiting Fault Propagation
Sayandeep Saha, Arnab Bag, Debapriya Basu Roy, Sikhar Patranabis, Debdeep Mukhopadhyay |
EUROCRYPT (1) | 5 |
| 2020 | PUF-G: A CAD Framework for Automated Assessment of Provable Learnability from Formal PUF RepresentationsabstractPhysically Unclonable Functions (PUFs) are widely adopted in various lightweight authenticating devices due to their unique fingerprints - providing uniform, unpredictable and reliable nature of responses. However, with the growth of machine learning (ML) attacks in recent times, it is imperative that the PUFs need to be resilient to such modeling attacks as well. Consequently, analyzing the learnability of PUFs has initiated a new branch of study leading to establishing provable guarantees (and PAC-learnability) of various PUF designs. However, these derivations are often carried out manually while implementing the design and thereby cannot automatically adjust the changes in PUF designs or its various compositions. In this paper, for the first time, we present an automated framework, called PUF-G, to reason about the PAC-learnability of PUF designs from an architectural level. To enable this, we propose a formal PUF representation language by which any architectural PUF design and its compositions can be specified upfront. This PUF specification can be automatically analyzed through a CAD framework by translating the same to an interim model and then deriving the PAC-learnability bounds from the model. Such a tool will help the designer to explore various compositional architectures of PUFs and its resilience to ML attacks automatically before converging on a strong PUF design for implementation. We also show the efficacy of our proposed framework over a wide range of PUF architectures while automatically deriving their learnability guarantees. As a matter of independent interest, the framework presents the first reported proofs to show that Interpose-PUF (newly proposed), MUX-PUF, FF-APUF, FF-XOR APUF and DA-PUF, are all PAC-learnable. Durba Chatterjee, Debdeep Mukhopadhyay, Aritra Hazra |
ICCAD | 2 |
| 2020 | Faultless to a Fault? The Case of Threshold Implementations of Crypto-systems vs Fault Template AttacksabstractThe propagation of faults in hardware devices for a Boolean circuit leaves a distinct fault template which can be used as a signature to launch a new class of attacks called Fault Template Attacks (FTA). In this paper we present a systematic methodology to develop fault templates of Boolean circuits using awell known concept in design verification, namely positive Davio's decomposition. We use this improved template called FTA* to attack a popular defence against side channel analysis called Threshold Implementations (TI), which are based on computations using non-complete shares of the secret data to hide it. The paper tries to explore whether such shares can be still combined to reveal the secret quantities by inflicting carefully crafted faults in the registers storing the shares and observing the fault propagation templates. In particular, we show as a case study that a TI-protected S-Box of the PRESENT block cipher can be circumvented by considering Double Event Upset (DEU) faults in single registers storing targeted shared bits as suggested by the derived fault templates. This shows that the TI crypto-circuits are not naturally faultless to faults and needs further explorations to thwart such powerful attack vectors. Debdeep Mukhopadhyay |
ICCAD | 1 |
| 2020 | A Minimalistic Perspective on Koblitz Curve Scalar Multiplication for FPGA PlatformsabstractKoblitz Curves offer excellent optimization opportunities for characteristic-2 Elliptic Curve Cryptosystems (ECC). However, porting such choices onto a lightweight and cost-effective FPGA platform is a major challenge. The underlying characteristic-2 algebra is not aligned with the on-chip components like DSP multipliers, which if not utilized leads to large LUT counts of the designs. In this work, we develop several techniques to propose a minimal instruction set, centered around ADDN (Add and Branch if less than zero) based OISC (One-Instruction-Set-Computing) coupled with a lightweight comba characteristic-2 finite field multiplier to ensure the aggressive utilization of the FPGA resources. The paper develops an ADDN based scalar multiplier for Koblitz curves which has a minimal footprint on the LUTs, leveraging methods for utilizing the underlying DSP blocks in FPGAs for performing GF(2) operations, in conjunction with proposed reduced variants of the ADDN instruction to perform the computations. The architecture uses FPGA resources like BRAMs, DSPs effectively to have a minimal requirement for FPGA LUTs, thus leaving room for other peripheral designs to be hosted in a single FPGA. The same design can be configured to realize scalar multiplications by two popular strategies, namely due to Solinas and Montgomery, to demonstrate the modular nature of the design. The minimalistic design style leads to a resource-constrained architecture performing scalar multiplication in less than 1000 slices, needing less than 0.5 ms on a cost-effective Artix-7 FPGA. The design has been compared with reported literature to highlight the area efficiency of the design, however ensuring a competitive AT (area-time) product. Siddhartha Chowdhury, Debapriya Basu Roy, Debdeep Mukhopadhyay |
VLSI-SOC | 3 |
| 2020 | Design Automation for Side Channel Resistant Lightweight CryptographyabstractThe scaling of devices in loT era has opened doors to broad range of privacy and security concerns making it vulnerable to various side channel attacks (SCA) and differential fault attacks (DFA). The generic EDA flows provide powerful solutions for simulation, verification, power, performance and area (PPA) optimizations. But these flows are not enabled to detect side channel leakages or provide countermeasures or handle huge search space under both lightweightedness and security dimension paradigm. So, we propose to augment classical EDA flow with security aware notion addressing the challenges wrt primitive design, SCA and DFA thereby helping crypto-designers to reduce overall design cycle-time and early detection of security flaws in lightweight design and provide countermeasure. Rajat Sadhukhan, Debdeep Mukhopadhyay |
VLSI-SOC | 2 |
| 2020 | Neural Network-based Inherently Fault-tolerant Hardware Cryptographic Primitives without Explicit Redundancy ChecksabstractFault injection-based cryptanalysis is one of the most powerful practical threats to modern cryptographic primitives. Popular countermeasures to such fault-based attacks generally use some form of redundant computation to detect and react/correct the injected faults. However, such countermeasures are shown to be vulnerable to selective fault injections. In this article, we aim to develop a cryptographic primitive that is fault tolerant by its construction and does not require to compute the same value multiple times. We utilize the effectiveness of Neural Networks (NNs), which show “some degree” of robustness by functioning correctly even after the occurrence of faults in any of its parameters. We also propose a novel strategy that enhances the fault tolerance of the implementation to “high degree” (close to 100%) by incorporating selective constraints in the NN parameters during the training phase. We evaluated the performance of revised NN considering both software and FPGA implementations for standard cryptographic primitives like 8×8 AES SBox and 4×4 PRESENT SBox. The results show that the fault tolerance of such implementations can be significantly increased with the proposed methodology. Such NN-based cryptographic primitives will provide inherent resistance against fault injections without requiring any redundancy countermeasures. Manaar Alam, Arnab Bag, Debapriya Basu Roy, Dirmanto Jap, Jakub Breier, Shivam Bhasin, Debdeep Mukhopadhyay |
ACM J. Emerg. Technol. Comput. Syst. | 7 |
| 2020 | Branch Prediction Attack on Blinded Scalar MultiplicationabstractIn recent years, performance counters have been used as a side channel source to monitor branch mispredictions, in order to attack cryptographic algorithms. However, the literature considers blinding techniques as effective countermeasures against such attacks. In this article, we present the first template attack on the branch predictor. We target blinded scalar multiplications with a side-channel attack that uses branch misprediction traces. Since an accurate model of the branch predictor is a crucial element of our attack, we first reverse-engineer the branch predictor. Our attack proceeds with a first online acquisition step, followed by an offline template attack with a template building phase and a template matching phase. During the template matching phase, we use a strategy we call Deduce & Remove, to first infer the candidate values from templates based on a model of the branch predictor, and subsequently eliminate erroneous observations. This last step uses the properties of the target blinding technique to remove wrong guesses and thus naturally provides error correction in key retrieval. In the later part of this article, we demonstrate a template attack on Curve1174 where the double-and-add always algorithm implementation is free from conditional branching on the secret scalar. In that case, we target the data-dependent branching based on the modular reduction operations of long integer multiplications. Such implementations still exist in open source software and can be vulnerable, even if top level safeguards like blinding are used. We provide experimental results on scalar splitting, scalar randomization, and point blinding to show that the secret scalar can be correctly recovered with high confidence. Finally, we conclude with recommendations on countermeasures to thwart such attacks. Sarani Bhattacharya, Clémentine Maurice, Shivam Bhasin, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 4 |
| 2020 | LAMBDA: Lightweight Assessment of Malware for emBeddeD ArchitecturesabstractSecurity is a critical aspect in many of the latest embedded and IoT systems. Malware is one of the severe threats of security for such devices. There have been enormous efforts in malware detection and analysis; however, occurrences of newer varieties of malicious codes prove that it is an extremely difficult problem given the nature of these surreptitious codes. In this article, instead of addressing a general solution, we aim at malware detection for platforms that have more than one core for performance enhancement. We investigate the utility of multiple cores from the point of view of security, where one of the cores operate as a watchdog. We define a notion of a new metric called LAMBDA (Lightweight Assessment of Malware for emBeddeD Architectures), denoted by λ, indicating a conceptual boundary between the programs which are allowed to run on a given platform, with the codes that are suspected as malwares. The metric λ is computed using carefully chosen monitors or features, which are tuples of high-level programs representing OS resources, along with low-level hardware performance counters. In comparison to heavy-weight machine learning techniques, we use an online hypothesis testing, in the form of t -test, to classify a given program-under-test. For applications where security is of prime concern, we propose an additional step based on multivariate analysis to classify the unknown programs that are closer to the threshold with a high degree of confidence. We present experimental results focusing on an ARM-based platform which validate that the proposed approach provides a lightweight, accurate assessment of malware codes for embedded platforms. In addition to it, we also present a security analysis to show the difficulty of a mimicry attack attempting to bypass LAMBDA. Sai Praveen Kadiyala, Manaar Alam, Yash Shrivastava, Sikhar Patranabis, Muhamed Fauzi Bin Abbas, Arnab Kumar Biswas, Debdeep Mukhopadhyay, Thambipillai Srikanthan |
ACM Trans. Embed. Comput. Syst. | 7 |
| 2020 | A Framework to Counter Statistical Ineffective Fault Analysis of Block Ciphers Using Domain Transformation and Error CorrectionabstractRight from its introduction, fault attacks (FA) have been established to be one of the most practical threats to both public key and symmetric key based cryptosystems. Statistical Ineffective Fault Analysis (SIFA) is a recently proposed class of fault attacks introduced at CHES 2018. The fascinating feature of this attack is that it exploits the correct ciphertexts obtained during a fault injection campaign, instead of the faulty ciphertexts. SIFA has been shown to bypass almost all of the existing fault attack countermeasures even when they are combined with masking schemes for side-channel resistance. The goal of this work is to propose a countermeasure framework for SIFA. It has been observed that a randomized domain transformation of the intermediate computation combined with bit-level error correction can prevent SIFA attacks. The domain transformation (Transform) can be realized by standard masking schemes. In fact, we prove that if biased faults are injected at the state register of a block cipher at a certain target round, then masking is sufficient for SIFA protection, until all the shares for a specific bit are corrupted. However, masking alone cannot prevent SIFA if the faults are injected at certain specific locations inside the S-Boxes. To address this issue, we incorporate a bit-level error-correction mechanism (Encode). An instantiation of this Transform-and-Encode (TaE) framework, called AntiSIFA, has been proposed and realized for the block cipher PRESENT as a proof-of-concept. Practical evaluation of the countermeasure implementation in both hardware and software ensures our theoretical claims regarding SIFA security, as well as protection against Side-Channel-Attacks (SCA). Sayandeep Saha, Dirmanto Jap, Debapriya Basu Roy, Avik Chakraborty, Shivam Bhasin, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2020 | Machine Learning Assisted PUF Calibration for Trustworthy Proof of Sensor Data in IoTabstractRemote integrity verification plays a paramount role in resource-constraint devices owing to emerging applications such as Internet-of-Things (IoT), smart homes, e-health, and so on. The concept of Virtual Proof of Reality (VPoR) proposed by Rührmair et al. in 2015 has come up with a Sense-Prove-Validate framework for integrity checking of abundant data generated from billions of connected sensors. It leverages the unreliability factor of Physically Unclonable Functions (PUFs) with respect to ambient parameter variations such as temperature, supply voltages, and so on, and claims to prove the authenticity of the sensor data without using any explicit keys. The state-of-the-art authenticated sensing protocols majorly lack in limited authentications and huge storage overhead. These protocols also assume that the behaviour of the PUF instances varies unpredictably for different levels of ambient factors, which in turn makes them hard to go beyond the theoretical concept. We address these issues in this work 1 and propose a Machine Learning (ML) assisted PUF calibration scheme to predict the Challenge-Response Pair (CRP) behaviour of a PUF instance in a specific environment, given the CRP behaviour in a pivot environment. Here, we present a new class of authenticated sensing protocols where we leverage the beneficence of ML techniques to validate the authenticity and integrity of sensor data over ambient factor variations. The scheme also reduces the storage complexity of the verifier from O ( p * K * l * ( c + r )) to O ( p * l *( c + r )), where p is the number of PUF instances deployed in the framework, l is the number of challenge-response pairs used for authentication, c is the bit lengths of the challenge, r is the response bits of the PUF, and K is the number of levels of ambient factor variations. The scheme alleviates the issue of limited authentication as well, whereby every CRP is used only once for authentication and then deleted from the database. To validate the proposed protocol through actual experiments on FPGA, we propose 5-4 Double Arbiter PUF, which is an extension of Double Arbiter PUFs (DAPUFs) as this design is more suited for FPGA, and implement it on Xilinx Artix-7 FPGAs. We characterise the proposed PUF instance from −20° C to 80° C and use Random Forest --based ML technique to generate a soft model of the PUF instance. This model is further used by the verifier to authenticate the actual PUF circuit. According to the FPGA-based validation, the proposed protocol with DAPUF can be effectively used to authenticate sensor devices across wide variations of temperature values. Urbi Chatterjee, Soumi Chatterjee, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2019 | A 0.16pJ/bit recurrent neural network based PUF for enhanced machine learning attack resistanceabstractPhysically Unclonable Function (PUF) circuits are finding wide-spread use due to increasing adoption of IoT devices. However, the existing strong PUFs such as Arbiter PUFs (APUF) and its compositions are susceptible to machine learning (ML) attacks because the challenge-response pairs have a linear relationship. In this paper, we present a Recurrent-Neural-Network PUF (RNN-PUF) which uses a combination of feedback and XOR function to significantly improve resistance to ML attack, without significant reduction in the reliability. ML attack is also partly reduced by using a shared comparator with offset-cancellation to remove bias and save power. From simulation results, we obtain ML attack accuracy of 62% for different ML algorithms, while reliability stays above 93%. This represents a 33.5% improvement in our Figure-of-Merit. Power consumption is estimated to be 12.3μW with energy/bit of ≈ 0.16pJ. Nimesh Shah, Manaar Alam, Durga Prasad Sahoo, Debdeep Mukhopadhyay, Arindam Basu |
ASP-DAC | 4 |
| 2019 | Deep Learning Based Diagnostics for Rowhammer Protection of DRAM ChipsabstractModern day DRAM chips have been shown to have a reliability issue which can lead to erratic bit flips, a phenomenon which is called Rowhammer. Although current DRAM modules come with in-built countermeasures, recent attacks have shown they are still vulnerable. The Rowhammer vulnerability has been used in conjunction with other side-channels to lead to devastating attacks. In this work, we take a novel approach by training a deep learning model based on several successful and unsuccessful attempts to conduct Rowhammer. The objective of the model is to analyze the access patterns of the DRAM by reverse engineering the physical address to pinpoint exact DRAM location and in turn use them for early prediction of a potential Rowhammer flip. We showed that our approach could detect a probable Rowhammer attempt with considerably high accuracy and even before the completion of the attack. In a more general context, this work shows that suitable combinations of deep learning and reverse engineering of physical address space can help to enhance both the reliability and security of systems. Anirban Chakraborty 0003, Manaar Alam, Debdeep Mukhopadhyay |
ATS | 3 |
| 2019 | In-situ Extraction of Randomness from Computer Architecture Through Hardware Performance Counters
Manaar Alam, Astikey Singh, Sarani Bhattacharya, Kuheli Pratihar, Debdeep Mukhopadhyay |
CARDIS | 5 |
| 2019 | How Secure are Deep Learning Algorithms from Side-Channel based Reverse Engineering?abstractDeep Learning has become a de-facto paradigm for various prediction problems including many privacy-preserving applications, where the privacy of data is a serious concern. There have been efforts to analyze and exploit information leakages from DNN to compromise data privacy. In this paper, we provide an evaluation strategy for such information leakages through DNN by considering a case study on CNN classifier. The approach utilizes low-level hardware information provided by Hardware Performance Counters and hypothesis testing during the execution of a CNN to produce alarms if there exists any information leakage on actual input. Manaar Alam, Debdeep Mukhopadhyay |
DAC | 2 |
| 2019 | United We Stand: A Threshold Signature Scheme for Identifying Outliers in PLCsabstractThis work proposes a scheme to detect, isolate and mitigate malicious disruption of electro-mechanical processes in legacy PLCs where each PLC works as a finite state machine (FSM) and goes through predefined states depending on the control flow of the programs and input-output mechanism. The scheme generates a group-signature for a particular state combining the signature shares from each of these PLCs using (k,l)-threshold signature scheme. If some of them are affected by the malicious code, signature can be verified by k out of l uncorrupted PLCs and can be used to detect the corrupted PLCs and the compromised state. We use OpenPLC software to simulate Legacy PLC system on Raspberry Pi and show I/O pin configuration attack on digital and pulse width modulation (PWM) pins. We describe the protocol using a small prototype of five instances of legacy PLCs simultaneously running on OpenPLC software. We show that when our proposed protocol is deployed, the aforementioned attacks get successfully detected and the controller takes corrective measures. This work has been developed as a part of the problem statement given in the Cyber Security Awareness Week-2017 competition. Urbi Chatterjee, Pranesh Santikellur, Rajat Sadhukhan, Vidya Govindan, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
DAC | 5 |
| 2019 | ALAFA: Automatic Leakage Assessment for Fault Attack CountermeasuresabstractAssessment of the security provided by a fault attack countermeasure is challenging, given that a protected cipher may leak the key if the countermeasure is not designed correctly. This paper proposes, for the first time, a statistical framework to detect information leakage in fault attack countermeasures. Based on the concept of non-interference, we formalize the leakage for fault attacks and provide a t-test based methodology for leakage assessment. One major strength of the proposed framework is that leakage can be detected without the complete knowledge of the countermeasure algorithm, solely by observing the faulty ciphertext distributions. Experimental evaluation over a representative set of countermeasures establishes the efficacy of the proposed methodology. Sayandeep Saha, S. Nishok Kumar, Sikhar Patranabis, Debdeep Mukhopadhyay, Pallab Dasgupta |
DAC | 4 |
| 2019 | Count Your Toggles: a New Leakage Model for Pre-Silicon Power Analysis of Crypto Designs
Rajat Sadhukhan, Paulson Mathew, Debapriya Basu Roy, Debdeep Mukhopadhyay |
J. Electron. Test. | 4 |
| 2019 | SCADFA: Combined SCA+DFA Attacks on Block Ciphers with Practical ValidationsabstractWe present the first practically realizable side-channel assisted fault attack on any block-ciphers having bit-permutation with optimal diffusion, that can retrieve the round key efficiently using random nibble faults. The attack demonstrates how side-channel leakage can allow the adversary to precisely determine the fault mask resulting from a nibble fault injection instance. We first demonstrate the viability of such attack model via side-channel analysis experiments on top of a laser-based fault injection setup, targeting a PRESENT-80 and GIFT-128 (two popular block-ciphers based on bit-permutation having optimal diffusion) implementation on an ATmega328P microcontroller. Subsequently, we present a differential fault analysis (DFA) exploiting the knowledge of the output fault mask in the target round to recover multiple last round keys nibbles independently and in parallel. We show that the combined attack can recover the last round key of PRESENT-80 and GIFT-128 with 4 random nibble fault injections in the best case. In the average case, the number of random nibble faults required for PRESENT-80 and GIFT-128 are 9-18 and 6-9 respectively. Sikhar Patranabis, Nilanjan Datta, Dirmanto Jap, Jakub Breier, Shivam Bhasin, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 6 |
| 2019 | CC Meets FIPS: A Hybrid Test Methodology for First Order Side Channel AnalysisabstractCommon Criteria (CC) and FIPS 140-3 are two popular side channel testing methodologies. Test Vector Leakage Assessment Methodology (TVLA), a potential candidate for FIPS, can detect the presence of side-channel information in leakage measurements. However, TVLA results cannot be used to quantify side-channel vulnerability and it is an open problem to derive its relationship with side channel attack success rate (SR), i.e., a common metric for CC. In this paper, we extend the TVLA testing beyond its current scope. Precisely, we derive a concrete relationship between TVLA and signal to noise ratio (SNR). The linking of the two metrics allows direct computation of success rate (SR) from TVLA for given choice of intermediate variable and leakage model and thus unify these popular side channel detection and evaluation metrics. An end-to-end methodology is proposed, which can be easily automated, to derive attack SR starting from TVLA testing. The methodology works under both univariate and multivariate setting and is capable of quantifying any first order leakage. Detailed experiments have been provided using both simulated traces and real traces on SAKURA-GW platform. Additionally, the proposed methodology is benchmarked against previously published attacks on DPA contest v4.0 traces, followed by extension to jitter based countermeasure. The result shows that the proposed methodology provides a quick estimate of SR without performing actual attacks, thus bridging the gap between CC and FIPS. Debapriya Basu Roy, Shivam Bhasin, Sylvain Guilley, Annelie Heuser, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 6 |
| 2019 | Building PUF Based Authentication and Key Exchange Protocol for IoT Without Explicit CRPs in Verifier DatabaseabstractPhysically Unclonable Functions (PUFs) promise to be a critical hardware primitive to provide unique identities to billions of connected devices in Internet of Things (IoTs). In traditional authentication protocols a user presents a set of credentials with an accompanying proof such as password or digital certificate. However, IoTs need more evolved methods as these classical techniques suffer from the pressing problems of password dependency and inability to bind access requests to the “things” from which they originate. Additionally, the protocols need to be lightweight and heterogeneous. Although PUFs seem promising to develop such mechanism, it puts forward an open problem of how to develop such mechanism without needing to store the secret challenge-response pair (CRP) explicitly at the verifier end. In this paper, we develop an authentication and key exchange protocol by combining the ideas of Identity based Encryption (IBE), PUFs and Key-ed Hash Function to show that this combination can help to do away with this requirement. The security of the protocol is proved formally under the Session Key Security and the Universal Composability Framework. A prototype of the protocol has been implemented to realize a secured video surveillance camera using a combination of an Intel Edison board, with a Digilent Nexys-4 FPGA board consisting of an Artix-7 FPGA, together serving as the IoT node. We show, though the stand-alone video camera can be subjected to man-in-the-middle attack via IP-spoofing using standard network penetration tools, the camera augmented with the proposed protocol resists such attacks and it suits aptly in an IoT infrastructure making the protocol deployable for the industry. Urbi Chatterjee, Vidya Govindan, Rajat Sadhukhan, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty, Debashis Mahata, Mukesh M. Prabhu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2019 | Combining PUF with RLUTs: A Two-party Pay-per-device IP Licensing Scheme on FPGAsabstractWith the popularity of modern FPGAs, the business of FPGA specific intellectual properties (IP) is expanding rapidly. This also brings in the concern of IP protection. FPGA vendors are making serious efforts toward IP protection, leading to standardization schemes like IEEE P1735. However, efficient techniques to prevent unauthorized overuse of IP still remain an open question. In this article, we propose a two-party IP protection scheme combining the re-configurable look-up table primitive of modern FPGAs with physically unclonable functions (PUF). The proposed scheme works with the assumption that the FPGA vendor provides the assurance of confidentiality and integrity of the developed IP. The proposed scheme is considerably lightweight compared to existing schemes, prevents overuse, and does not involve FPGA vendors or trusted third parties for IP licensing. The validation of the proposed scheme is done on MCNC’91 benchmark and third-party IPs like AES and lightweight MIPS processors. Debapriya Basu Roy, Shivam Bhasin, Ivica Nikolic, Debdeep Mukhopadhyay |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2019 | Automatic Characterization of Exploitable Faults: A Machine Learning ApproachabstractCharacterizing the fault space of a cipher to filter out a set of faults potentially exploitable for fault attacks (FA), is a problem with immense practical value. A quantitative knowledge of the exploitable fault space is desirable in several applications, such as security evaluation, cipher construction and implementation, design, testing of countermeasures, and so on. In this paper, we investigate this problem in the context of block ciphers. The formidable size of the fault space of a block cipher mandates the use of an automation strategy to solve this problem, which should be able to characterize each individual fault instance quickly. On the other hand, the automation strategy is expected to be applicable to most of the block cipher constructions. Existing techniques for automated fault attacks do not satisfy both of these goals simultaneously, and hence are not directly applicable in the context of exploitable fault characterization. In this paper, we present a supervised machine learning assisted automated framework, which successfully addresses both of the criteria mentioned. The key idea is to extrapolate the knowledge of some existing FAs on a cipher to rapidly figure out new attack instances. Experimental validation of this idea on two state-of-the-art block ciphers - PRESENT and LED - establishes that our approach is able to provide fairly good accuracy in identifying exploitable fault instances at a reasonable cost. Utilizing this observation, we propose a statistical framework for exploitable fault space characterization, which can provide an estimate of the success rate of an attacker corresponding to the given fault model and fault location. The framework also returns test vectors leading toward successful attacks. As a potential application, the effect of different S-Boxes on the fault space of a cipher is evaluated utilizing the framework. Sayandeep Saha, Dirmanto Jap, Sikhar Patranabis, Debdeep Mukhopadhyay, Shivam Bhasin, Pallab Dasgupta |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Guest Editorial Special Section on Security Challenges and Solutions With Emerging Computing TechnologiesabstractMultiple emerging computing technologies based on, e.g., graphene, spintronics, resistive RAM, quantum computing, and others are being developed to enhance the capabilities of logic devices and circuits. The rapid growth in these technologies is synchronized with the decline of Moore’s law, thus promises to herald the era of Beyond CMOS technologies with a significant improvement in energy efficiency, reliability, performance, and manufacturability. These devices enable very different computing paradigms, e.g., neuromorphic computing, non-Boolean computing, and in-memory computing, thus making these platforms an interesting playground for circuit and application-developers alike. Anupam Chattopadhyay, Swaroop Ghosh, Wayne P. Burleson, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2019 | Guest Editorial: Special Section on Autonomous Intelligence for Security and Privacy AnalyticsabstractWe interact with a wide variety of computing systems in our daily life. These computing systems are often connected through a network to provide a wide array of services. Depending on our specific circumstances, our interactions can be with embedded and cyber-physical systems (CPSs) or Internet-of-Things (IoT) devices. While these devices vary in terms of form factors, hardware–software integration, and energy constraints, they have one commonality—security and privacy are the primary design considerations. These systems collect and analyze sensitive data, which may include our personal, financial, as well as health information on a regular basis. As a result, the existing academic and industrial efforts have focused on designing systems with security and privacy in mind. Given the complexity of these systems and the diversity of the potential attacks, machine learning (ML) has become an attractive solution for security and privacy analytics. Prabhat Mishra 0001, Debdeep Mukhopadhyay, Swarup Bhunia |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2019 | High-Speed Implementation of ECC Scalar Multiplication in GF(p) for Generic Montgomery CurvesabstractElliptic curve-based cryptography (ECC) has become the automatic choice for public key cryptography due to its lightweightness compared to Rivest-Shamir-Adleman (RSA). The most important operation in ECC is elliptic curve scalar multiplication, and its efficient implementation has gathered significant attention in the research community. Fast implementation of ECC scalar multiplication is often desired for speed-critical applications such as runtime authentication in automated cars, web server certification, and so on. Such fast architectures are achieved by implementing ECC scalar multiplication in fields with pseudo-Mersenne prime or Solinas prime. In this paper, we aim to implement a fast implementation of ECC scalar multiplication for any generic Montgomery curve in Galois Field in p [GF(p)] without having the constraint of using any specialized modulus. We will show that the proposed ECC scalar multiplication architecture is as fast as scalar multiplication in special curves like Curve25519, albeit with little area overhead. The proposed architecture can be modified to support ECC scalar multiplication in both Montgomery and short Weierstrass curves. Debapriya Basu Roy, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2019 | Power Efficiency of S-Boxes: From a Machine-Learning-Based Tool to a Deterministic ModelabstractDesigning cryptographically good and power-efficient 4 × 4 S-boxes is a challenging problem in the era of lightweight cryptography. Although the optimal cryptographic properties are easy to determine, verifying the power efficiency of an S-box is nontrivial. The conventional approach of determining the power consumption using commercially available CAD tools is highly time-consuming, which becomes formidable while dealing with a large pool of S-boxes. This mandates the development of automation that should quickly characterize the power efficiency from the Boolean function representation of an S-box. In this paper, we present a supervised machine-learning-assisted automated framework to resolve the problem for 4 × 4 S-boxes, which turns out to be 14 times faster than the traditional approach. The key idea is to extrapolate the knowledge of literal counts, AND-OR-NOT gate counts in the sum-of-products (SOP) form of the underlying Boolean functions to predict the dynamic power efficiency. We demonstrate the effectiveness of our framework by reporting on a set of power-efficient (involutive) optimal S-boxes from a large set of S-boxes. We also develop a deterministic model using results obtained from supervised learning to predict the dynamic power of an S-box that can be used in an evolutionary algorithm to generate cryptographically good and low-power S-boxes. Rajat Sadhukhan, Nilanjan Datta, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2018 | Hardware Acceleration of Searchable EncryptionabstractSearchable symmetric encryption (SSE) allows a client to outsource the storage of her data to an (untrusted) server in a private manner, while maintaining the ability to selectively search over it. A key feature of all existing SSE schemes is the tradeoff between security (in terms of the information leakage to the server) and efficiency (in terms of the operational and storage overhead on the server and client sides). The premise of this work is that SSE schemes typically offer scope for massively parallel implementations with improved efficiency without compromising security. Based on this idea, we propose a highly scalable framework for parallelized SSE implementations using hardware-based crypto-accelerators, interfaced with a software-based control unit and a memory controller unit. We choose field programmable gate arrays (FPGAs) as the platform for the crypto-accelerators due to their flexibility, reconfigurability, low time-to-market and low maintenance overheads. As a case study, we illustrate how the recently proposed SSE scheme of Lai et al. (CCS'18) may be implemented as per our framework, and the benefits thereof, including shorter preprocessing time and reduced query-response latency as compared to a software implementation. Arnab Bag, Sikhar Patranabis, L. Tribhuvan, Debdeep Mukhopadhyay |
CCS | 4 |
| 2018 | POSTER: Authenticated Key-Exchange Protocol for Heterogeneous CPSabstractThe widespread advent of Cyber-Physical Systems~(CPS), intertwined with the Internet of Things~(IoT), allows billions of resource-constrained embedded devices to be connected at the same time. While this significantly enhances the scope for productivity, it also throws up security issues which, unless addressed, could lead to catastrophic consequences. The biggest challenge in an IoT network is to ensure inter-device authentication and secure key-exchange, while taking into account the heterogeneous nature of the participating devices in terms of processing capacity and memory bandwidth. In this paper, we propose a secure and operationally asymmetric authenticated key-exchange protocol targeting oT networks and CPS. Our protocol balances security and efficiency, delegates complex cryptographic operations to the resource-equipped servers, and carefully manages the workload on the resource- constrained nodes via the use of unconventional lightweight primitives such as Physically Unclonable Functions (PUFs). The security of our protocol is based on well-established cryptographic assumptions. Harishma Boyapally, Sikhar Patranabis, Urbi Chatterjee, Debdeep Mukhopadhyay |
AsiaCCS | 4 |
| 2018 | Result Pattern Hiding Searchable Encryption for Conjunctive QueriesabstractThe recently proposed Oblivious Cross-Tags (OXT) protocol (CRYPTO 2013) has broken new ground in designing efficient searchable symmetric encryption (SSE) protocol with support for conjunctive keyword search in a single-writer single-reader framework. While the OXT protocol offers high performance by adopting a number of specialised data-structures, it also trades-off security by leaking 'partial' database information to the server. Recent attacks have exploited similar partial information leakage to breach database confidentiality. Consequently, it is an open problem to design SSE protocols that plug such leakages while retaining similar efficiency. In this paper, we propose a new SSE protocol, called Hidden Cross-Tags (HXT), that removes 'Keyword Pair Result Pattern' (KPRP) leakage for conjunctive keyword search. We avoid this leakage by adopting two additional cryptographic primitives - Hidden Vector Encryption (HVE) and probabilistic (Bloom filter) indexing into the HXT protocol. We propose a 'lightweight' HVE scheme that only uses efficient symmetric-key building blocks, and entirely avoids elliptic curve-based operations. At the same time, it affords selective simulation-security against an unbounded number of secret-key queries. Adopting this efficient HVE scheme, the overall practical storage and computational overheads of HXT over OXT are relatively small (no more than 10% for two keywords query, and 21% for six keywords query), while providing a higher level of security. Shangqi Lai, Sikhar Patranabis, Amin Sakzad, Joseph K. Liu, Debdeep Mukhopadhyay, Ron Steinfeld, Shifeng Sun 0001, Dongxi Liu, Cong Zuo 0001 |
CCS | 5 |
| 2018 | Trustworthy proofs for sensor data using FPGA based physically unclonable functionsabstractThe Internet of Things (IoT) is envisaged to consist of billions of connected devices coupled with sensors which generate huge volumes of data enabling control-and-command in this paradigm. However, integrity of this data is of utmost concern, and is promisingly addressed leveraging the inherent unreliability of Physically Unclonable Functions (PUFs) w.r.t. ambient parameter variations, using the concept of Virtual Proofs (VPs). Advantage of these protocols is that they do not use explicit keys and aim at proving the authenticity of the sensor. Since the existing PUF-based protocols do not use the sensor data as a part of challenge (i.e. input) to PUFs, there is no guarantee of uniqueness of PUF's challenge-response behavior over multiple levels of ambient parameters. Few of these protocols needs to sequential search in the challenge-response database. To alleviate these issues, we develop a new class of authenticated sensing protocols where the sensor data is combined with the external challenge by utilizing the Strict Avalanche Criterion of the PUF. We validate the proposed protocol through actual experiments on FPGA using Double Arbiter PUFs (DAPUFs), which are implemented with superior uniformity, uniqueness, and reliability on Xilinx Artix-7 FPGAs. According to the FPGA-based validation, the proposed protocol with DAPUF can be effectively used to authenticate wide variations of temperature from -20°C to 80°C. Urbi Chatterjee, Durga Prasad Sahoo, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
DATE | 3 |
| 2018 | DFARPA: Differential fault attack resistant physical design automationabstractDifferential Fault Analysis (DFA), aided by sophisticated mathematical analysis techniques for ciphers and precise fault injection methodologies, has become a potent threat to cryptographic implementations. In this paper, we propose, to the best of the our knowledge, the first “DFA-aware” physical design automation methodology, that effectively mitigates the threat posed by DFA. We first develop a novel floorplan heuristic, which resists the simultaneous corruption of cipher states necessary for successful fault attack, by exploiting the fact that most fault injections are localized in practice. Our technique results in the computational complexity of the fault attack to shoot up to exhaustive search levels, making them practically infeasible. In the second part of the work, we develop a routing mechanism, which tackles more precise and costly fault injection techniques, like laser and electromagnetic guns. We propose a routing technique by integrating a specially designed ring oscillator based sensor circuit around the potential fault attack targets without incurring any performance overhead. We demonstrate the effectiveness of our technique by applying it on state of the art ciphers. Mustafa Khairallah, Rajat Sadhukhan, Radhamanjari Samanta, Jakub Breier, Shivam Bhasin, Rajat Subhra Chakraborty, Anupam Chattopadhyay, Debdeep Mukhopadhyay |
DATE | 8 |
| 2018 | Efficient Secure k-Nearest Neighbours over Encrypted Data
Manish Kesarwani, Akshar Kaul, Prasad Naldurg, Sikhar Patranabis, Sameep Mehta, Debdeep Mukhopadhyay |
EDBT | 7 |
| 2018 | Breaking Redundancy-Based Countermeasures with Random Faults and Power Side ChannelabstractRedundancy based countermeasures against fault attacks are a popular choice in security-critical commercial products, owing to its high fault coverage and applications to safety/reliability. In this paper, we propose a combined attack on such countermeasures. The attack assumes a random byte/nibble fault model with existence of side-channel leakage of the final comparison, and no knowledge of the faulty ciphertext. Unlike the previously proposed biased/multiple fault attack, we just need to corrupt one computation branch. Both analytical and experimental evaluation of this attack strategy is presented on software implementations of two state-of-the-art block ciphers, AES and PRESENT, on an ATmega328P microcontroller, via side-channel measurements and a laser-based fault injection. Moreover, this work establishes that even without the knowledge of the faulty ciphertexts, one can still perform differential fault analysis attacks, given the availability of side-channel information. Sayandeep Saha, Dirmanto Jap, Jakub Breier, Shivam Bhasin, Debdeep Mukhopadhyay, Pallab Dasgupta |
FDTC | 5 |
| 2018 | Revisiting FPGA Implementation of Montgomery Multiplier in Redundant Number System for Efficient ECC Application in GF(p)abstractThe fast implementations of ECC in GF(p) are generally implemented using specialized prime field, and henceforth, they are dependent on the structure of the prime. But, these implementations cannot be ported to generic curves which do not support such prime structures. Such generic curves are often used in various crypto-applications like pairing and post-quantum secure supersingular isogeny based key exchange. In those cases, modular multiplication is executed through Montgomery multiplier which is slower compared to modular multiplication using specialized primes. This work aims to reduce the speed gap between Montgomery multiplication and modular multiplication in specialized prime field by presenting an efficient implementation of Montgomery multiplier on FPGA using the redundant number system. Debdeep Mukhopadhyay, Debapriya Basu Roy |
FPL | 1 |
| 2018 | A Multiplexer-Based Arbiter PUF Composition with Enhanced Reliability and SecurityabstractArbiter Physically Unclonable Functions (APUFs), while being relatively lightweight, are extremely vulnerable to modeling attacks. Hence, various compositions of APUFs such as XOR APUF and Lightweight Secure PUF have been proposed to be secure alternatives. Previous research has demonstrated that PUF compositions have two major challenges to overcome: vulnerability against modeling and statistical attacks, and lack of reliability. In this paper, we introduce a multiplexer-based composition of APUFs, denoted as MPUF, to simultaneously overcome these challenges. In addition to the basic MPUF design, we propose two MPUF variants namely cMPUF and rMPUF to improve the robustness against cryptanalysis and reliability-based modeling attack, respectively. An rMPUF demonstrates enhanced robustness against the reliability-based modeling attack, while even the well-known XOR APUF, otherwise robust to machine learning based modeling attacks, has been modeled using the same technique with linear data and time complexities. The rMPUF can provide a good trade-off between security and hardware overhead while maintaining a significantly higher reliability level than any practical XOR APUF instance. Moreover, MPUF variants are the first APUF compositions, to the best of our knowledge, that can achieve Strict Avalanche Criterion without using any additional input network (or hardware) for challenge transformation. Finally, we validate our theoretical findings using Matlab-based simulations of MPUFs. Durga Prasad Sahoo, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty, Phuong Ha Nguyen |
IEEE Trans. Computers | 2 |
| 2018 | Utilizing Performance Counters for Compromising Public Key CiphersabstractHardware performance counters (HPCs) are useful artifacts for evaluating the performance of software implementations. Recently, HPCs have been made more convenient to use without requiring explicit kernel patches or superuser privileges. However, in this article, we highlight that the information revealed by HPCs can be also exploited to attack standard implementations of public key algorithms. In particular, we analyze the vulnerability due to the event branch miss leaked via the HPCs during execution of the target ciphers. We present an iterative attack that targets the key bits of 1,024-bit RSA and 256-bit ECC, whereas in the offline phase, the system’s underlying branch predictor is approximated by a theoretical predictor in the literature. Subsimulations are performed corresponding to each bit guess to classify the message space into distinct partitions based on the event branch misprediction and the target key bit value. In the online phase, branch mispredictions obtained from the hardware performance monitors on the target system reveal the secret key bits. We also theoretically prove that the probability of success of the attack is equivalent to the accurate modeling of the theoretical predictor to the underlying system predictor. In addition, we propose an improved version of the attack that requires fewer branch misprediction traces from the HPCs to recover the secret. Experimentations using both attack strategies have been provided on Intel Core 2 Duo, Core i3, and Core i5 platforms for 1,024-bit implementation of RSA and 256-bit scalar multiplication over the secp 256 r 1 curve followed by results on the effect of change of parameters on the success rate. The attack can successfully reveal the exponent bits and thus seeks attention to model secure branch predictors such that it inherently prevents information leakage. Sarani Bhattacharya, Debdeep Mukhopadhyay |
ACM Trans. Priv. Secur. | 2 |
| 2017 | Side Channel Evaluation of PUF-Based Pseudorandom PermutationabstractPUF-PRFs are Pseudorandom Functions (PRFs) constructed using Physically Unclonable Functions (PUFs) as a hardware building block to provide the random input-output mapping. Since PUF-PRFs inherit all the principal properties of PUFs such as memory-leakage resilience, unclonablity, tampering-resistance, pseudo-randomness, and provable security, PUF-PRFs hold great promise as an extremely useful cryptographic hardware primitive. In this paper, we evaluate the security of PUF-PRFs against Side Channel Attacks. Two different attacks based on analysis of power side channel are developed, and demonstrated through the experiments on Xilinx FPGAs. In addition, we reduce the complexity of Correlation Power Analysis (CPA) to recover n-bit secret, from O(2 2n) to O(3n 2n). Based on our experimental results, we conclude that the security of PUF-PRFs, when subjected to side channel attacks, depends on not only the security of the used PUFs, but also the PUF-PRF architecture. Durga Prasad Sahoo, Phuong Ha Nguyen, Debapriya Basu Roy, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
DSD | 4 |
| 2017 | A Practical Fault Attack on ARX-Like Ciphers with a Case Study on ChaCha20abstractThis paper presents the first practical fault attack on the ChaCha family of addition-rotation-XOR (ARX)-based stream ciphers. ChaCha has recently been deployed for speeding up and strengthening HTTPS connections for Google Chrome on Android devices. In this paper, we propose differential fault analysis attacks on ChaCha without resorting to nonce misuse. We use the instruction skip and instruction replacement fault models, which are popularly mounted on microcontroller-based cryptographic implementations. We corroborate the attack propositions via practical fault injection experiments using a laser-based setup targeting an Atmel AVR 8-bit microcontroller-based implementation of ChaCha. Each of the proposed attacks can be repeated with 100% accuracy in our fault injection setup, and can recover the entire 256 bit secret key using 5-8 fault injections on an average. S. V. Dilip Kumar, Sikhar Patranabis, Jakub Breier, Debdeep Mukhopadhyay, Shivam Bhasin, Anupam Chattopadhyay, Anubhab Baksi |
FDTC | 4 |
| 2017 | One Plus One is More than Two: A Practical Combination of Power and Fault Analysis Attacks on PRESENT and PRESENT-Like Block CiphersabstractWe present the first practically realizable sidechannel assisted fault attack on PRESENT, that can retrieve the last round key efficiently using single nibble faults. The attack demonstrates how side-channel leakage can allow the adversary to precisely determine the fault mask resulting from a nibble fault injection instance. We first demonstrate the viability of such an attack model via side-channel analysis experiments on top of a laser-based fault injection setup, targeting a PRESENT-80 implementation on an ATmega328P microcontroller. Subsequently, we present a differential fault analysis (DFA) exploiting the knowledge of the output fault mask in the target round to recover multiple last round key nibbles independently and in parallel. Both analytically and through experimental evidence, we show that the combined attack can recover the last round key of PRESENT with 4 random nibble fault injections in the best case, and around 7- 8 nibble fault injections in the average case. Our attack sheds light on a hitherto unexplored vulnerability of PRESENT and PRESENT-like block ciphers that use bit-permutations instead of maximum distance separable (MDS) layers for diffusion. Sikhar Patranabis, Jakub Breier, Debdeep Mukhopadhyay, Shivam Bhasin |
FDTC | 3 |
| 2017 | Redefining the transparency order
Kaushik Chakraborty 0001, Sumanta Sarkar, Subhamoy Maitra, Bodhisatwa Mazumdar, Debdeep Mukhopadhyay, Emmanuel Prouff |
Des. Codes Cryptogr. | 5 |
| 2017 | Construction of Rotation Symmetric S-Boxes with High Nonlinearity and Improved DPA ResistivityabstractIn this paper, we provide an n × n bijective rotation symmetric S-box (RSSB) construction with improved resistance to differential power analysis (DPA) using rotation-symmetric Boolean functions (RSBFs). The RSSB class is generated from an instance of a proposed RSSB construction and then iteratively applying a simulated annealing algorithm in the respective neighborhood of the RSSB followed by a hill climbing algorithm to obtain a good tradeoff of cryptographic properties. The constructed 8 × 8 RSSBs have a nonlinearity of 102 and transparency order value 7.709 whereas the Rijndael S-box has a higher transparency order of 7.86. The evaluation of security metric called guessing entropy on the constructed RSSBs shows that a side-channel adversary requires more effort to exploit information leakage from the simulated power traces. In comparison to Rijndael S-box, the correlation based DPA on RSSBs which when incorporated in AES-128, shows requirement of significantly more power traces when implemented on Xilinx Virtex-5 FPGA device on SASEBO-GII development board. While the distributed memory and block memory implementations of the Rijndael S-box required 500 and 2,000 power traces to extract the last round key, our proposed RSSBs required 2,000 and 12,000 power traces respectively. Bodhisatwa Mazumdar, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 2 |
| 2017 | Provably Secure Key-Aggregate Cryptosystems with Broadcast Aggregate Keys for Online Data Sharing on the CloudabstractOnline data sharing for increased productivity and efficiency is one of the primary requirements today for any organization. The advent of cloud computing has pushed the limits of sharing across geographical boundaries, and has enabled a multitude of users to contribute and collaborate on shared data. However, protecting online data is critical to the success of the cloud, which leads to the requirement of efficient and secure cryptographic schemes for the same. Data owners would ideally want to store their data/files online in an encrypted manner, and delegate decryption rights for some of these to users, while retaining the power to revoke access at any point of time. An efficient solution in this regard would be one that allows users to decrypt multiple classes of data using a single key of constant size that can be efficiently broadcast to multiple users. Chu et al. proposed a key aggregate cryptosystem (KAC) in 2014 to address this problem, albeit without formal proofs of security. In this paper, we propose CPA and CCA secure KAC constructions that are efficiently implementable using elliptic curves and are suitable for implementation on cloud based data sharing environments. We lay special focus on how the standalone KAC scheme can be efficiently combined with broadcast encryption to cater to m data users and m' data owners while reducing the reducing the secure channel requirement from O(mm') in the standalone case to O(m + m'). Sikhar Patranabis, Yash Shrivastava, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 3 |
| 2017 | A Combined Power and Fault Analysis Attack on Protected Grain Family of Stream CiphersabstractDifferential fault analysis of stream ciphers, such as Grain (Grain v1 and Grain-128) has been an active area of research. Several countermeasures to thwart such analysis have been also proposed in the related cryptographic literature. In this paper, we demonstrate a novel combination of power and fault analysis strategies to devise attacks against such protected implementations of Grain stream cipher. We considered clock glitch induced faults occurring in practice to construct our fault model. In addition, we developed a generic power analysis attack technique against the Grain family of stream ciphers assuming that the cipher implementation can be resynchronized multiple times with a fixed secret key and any randomly generated initialization vector. Subsequently, we combine our proposed power analysis strategy with the notion of the practically occurring faults to mount attacks on various fault attack countermeasures. In order to validate our proposed power analysis attack, we report the results of power trace classifications of a Grain v1 implementation on SASEBO-GII board. The captured power traces were analyzed using least squares support vector machine learning algorithm-based multiclass classifiers to segregate the power traces into the respective Hamming distance (HD) classes. To extract power samples with high information about HD classes, signal-to-noise ratio (SNR) metric was chosen for feature selection. The experimental results of power trace classifications of test set showed success rate as high as 92.5% when the seven largest SNR sample instants over a clock cycle were chosen as features along with a suitable kernel hyperparameter combination. Abhishek Chakraborty 0001, Bodhisatwa Mazumdar, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2017 | A PUF-Based Secure Communication Protocol for IoTabstractSecurity features are of paramount importance for the Internet of Things (IoT), and implementations are challenging given the resource-constrained IoT setup. We have developed a lightweight identity-based cryptosystem suitable for IoT to enable secure authentication and message exchange among the devices. Our scheme employs a Physically Unclonable Function (PUF) to generate the public identity of each device, which is used as the public key for each device for message encryption. We have provided formal proofs of security in the Session Key Security and Universally Composable Framework of the proposed protocol, which demonstrates the resilience of the scheme against passive and active attacks. We have demonstrated the setup required for the protocol implementation and shown that the proposed protocol implementation incurs low hardware and software overhead. Urbi Chatterjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2017 | Fault Space Transformation: A Generic Approach to Counter Differential Fault Analysis and Differential Fault Intensity Analysis on AES-Like Block CiphersabstractClassical fault attacks, such as differential fault analysis(DFA) as well as biased fault attacks, such as the differential fault intensity analysis (DFIA), have been a major threat to cryptosystems in recent times. DFA uses pairs of fault-free and faulty ciphertexts to recover the secret key. DFIA, on the other hand, combines principles of side-channel analysis and fault attacks to try and extract the key using faulty ciphertexts only. Till date, no effective countermeasure that can thwart both DFA- as well as DFIA-based attacks has been reported in the literature to the best of our knowledge. In particular, traditional redundancy-based countermeasures that assume uniform fault distributions are found to be vulnerable against the DFIA due to its use of biased fault models. In this paper, we propose a novel generic countermeasure strategy that combines the principles of redundancy with that of fault space transformation to achieve security against both DFA- and DFIA-based attacks on AES-like block ciphers. As a case study, we have applied our proposed technique to obtain temporal and spatial redundancy-based countermeasures for AES-128, and have evaluated their security against both DFA and DFIA via practical experiments on a SASEBO-GII board. Results show that our proposed countermeasure makes it practically infeasible to obtain a single instance of successful fault injection, even in the presence of biased fault models. Sikhar Patranabis, Abhishek Chakraborty 0001, Debdeep Mukhopadhyay, P. P. Chakrabarti 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Security Analysis of Arbiter PUF and Its Lightweight Compositions Under Predictability TestabstractUnpredictability is an important security property of Physically Unclonable Function (PUF) in the context of statistical attacks, where the correlation between challenge-response pairs is explicitly exploited. In the existing literature on PUFs, the Hamming Distance Test, denoted by HDT( t ), was proposed to evaluate the unpredictability of PUFs, which is a simplified case of the Propagation Criterion test PC( t ). The objective of these test schemes is to estimate the output transition probability when there are t or fewer than t bits flips, and ideally this probability value should be 0.5. In this work, we show that aforementioned two test schemes are not enough to ensure the unpredictability of a PUF design. We propose a new test, which is denoted as HDT( e , t ). This test scheme is a fine-tuned version of the previous schemes, as it considers the flipping bit pattern vector e along with parameter t . As a contribution, we provide a comprehensive discussion and analytic interpretation of HDT( t ), PC( t ), and HDT( e , t ) test schemes for Arbiter PUF (APUF), Exclusive-OR (XOR) PUF, and Lightweight Secure PUF (LSPUF). Our analysis establishes that HDT( e , t ) test is more general in comparison with HDT( t ) and PC( t ) tests. In addition, we demonstrate a few scenarios where the adversary can exploit the information obtained from the analysis of HDT( e , t ) properties of APUF, XOR PUF, and LSPUF to develop statistical attacks on them, if the ideal value of HDT( e , t ) = 0.5 is not achieved for a given PUF. We validate our theoretical observations using the simulated and Field Programmable Gate Array (FPGA) implemented APUF, XOR PUF, and LSPUF designs. Phuong Ha Nguyen, Durga Prasad Sahoo, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2016 | Curious Case of Rowhammer: Flipping Secret Exponent Bits Using Timing Analysis
Sarani Bhattacharya, Debdeep Mukhopadhyay |
CHES | 2 |
| 2016 | Remote Dynamic Clock Reconfiguration Based Attacks on Internet of Things ApplicationsabstractMany Internet of Things (IoT) applications can potentially benefit from the remote Dynamic Partial Reconfiguration (DPR) capabilities of modern Field Programmable Gate Arrays (FPGAs). Such capabilities enable changes in the circuit mapped on the FPGA, for modification or enhancement of functionality offered by the FPGA without taking it offline, via remote communications over a network. However, the use of remote DPR can result in security threats with catastrophic consequences. In this paper, we design two Hardware Trojan Horse attacks that exploit the remote DPR capability of the FPGA, on an encryption circuit and a true random number generator circuit, respectively. In particular, these attacks target the clock signal management circuitry on the FPGA to disrupt functionality. We substantiate the threat by demonstrating successful remote attacks via transfer of malicious bitstreams to a Virtex-5 FPGA, thereby embedding the HTH. Finally, we propose plausible countermeasures to prevent such attacks. Anju P. Johnson, Sikhar Patranabis, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
DSD | 4 |
| 2016 | Testability Based Metric for Hardware Trojan Vulnerability AssessmentabstractCurrent approaches for Hardware Trojan detection have varying degrees of computational and/or design overheads. In this paper, we develop a CAD methodology for a-priori estimation of Trojan vulnerability of a given circuit at the early stages of the design flow. We develop a security metric to estimate the testability of a circuit for HTHs, thus assessing its relative vulnerability. Our methodology overcomes several shortcomings of previously proposed testability metrics in the context of their applicability to the HTH detection problem in particular. We utilize the proposed metric to estimate the Trojan vulnerability of gate-level ISCAS benchmark circuits. The metric values show excellent correlation with the testability results obtained from previously proposed Trojan targeted ATPG techniques. Sayandeep Saha, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
DSD | 3 |
| 2016 | Fault Tolerant Implementations of Delay-Based Physically Unclonable Functions on FPGAabstractRecent literature has demonstrated that the security of Physically Unclonable Function (PUF) circuits might be adversely affected by the introduction of faults. In this paper, we propose novel and efficient architectures for a variety of widely used delay-based PUFs which are robust against high precision laser fault attacks proposed by Tajik et al. in FDTC-2015. The proposed architectures can be used to detect run-time modifications in the PUF design due to fault injection. In addition, we propose fault recovery techniques based on either logical reconfiguration or dynamic partial reconfiguration of the PUF design. We validate the robustness of our proposed fault tolerant delay-based PUF designs on Xilinx Artix-7 FPGA platform. Durga Prasad Sahoo, Sikhar Patranabis, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
FDTC | 3 |
| 2016 | Shuffling across rounds: A lightweight strategy to counter side-channel attacksabstractSide-channel attacks are a potent threat to the security of devices implementing cryptographic algorithms. Designing lightweight countermeasures against side-channel analysis that can run on resource constrained devices is a major challenge. One such lightweight countermeasure is shuffling, in which the designer randomly permutes the order of execution of potentially vulnerable operations. State of the art shuffling countermeasures advocate shuffling a set of independent operations in a single round of a cryptographic algorithm, but are often found to be insufficient as standalone countermeasures. In this paper, we propose a two-round version of the shuffling countermeasure, and test its security when applied to a serialized implementation of AES-128 using Test Vector Leakage Assessment (TVLA). Our results show that the required number of traces to break AES-128 implemented using our proposed countermeasure is significantly larger than the implementations using simple one-round shuffling. Furthermore, the new shuffling method has significantly lower overhead of around 1.3 times, as compared to other side-channel countermeasures such as masking that have an overhead of approximately two times. Sikhar Patranabis, Debapriya Basu Roy, Praveen Kumar Vadnala, Debdeep Mukhopadhyay, Santosh Ghosh |
ICCD | 4 |
| 2016 | SmashClean: A hardware level mitigation to stack smashing attacks in OpenRISCabstractBuffer overflow and stack smashing have been one of the most popular software based vulnerabilities in literature. There have been multiple works which have used these vulnerabilities to induce powerful attacks to trigger malicious code snippets or to achieve privilege escalation. In this work, we attempt to implement hardware level security enforcement to mitigate such attacks on OpenRISC architecture. We have analyzed the given exploits [5] in detail and have identified two major vulnerabilities in the exploit codes: memory corruption by non-secure memcpy() and return address modification by buffer overflow. We have individually addressed each of these exploits and have proposed a combination of compiler and hardware level modification to prevent them. The advantage of having hardware level protection against these attacks provides reliable security against the popular software level countermeasures. Manaar Alam, Debapriya Basu Roy, Sarani Bhattacharya, Vidya Govindan, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
MEMOCODE | 6 |
| 2016 | Template attack on SPA and FA resistant implementation of Montgomery ladderabstractHardware implementations of the well‐known Rivest–Shamir–Adleman (RSA) algorithm have been shown to be vulnerable to power and fault analysis (FA) attacks. To implement protected designs of RSA‐Chinese remainder theorem in embedded devices, like smart cards or RFIDs, the one needs to find solutions which require less computations as well as incurs low storage overheads. One such efficient scheme was proposed by Joye et al . in CHES'02 and it was claimed to be secure against both simple power analysis (SPA) and FA attacks. In this study, the authors demonstrate a template attack (TA) against Joye's countermeasure and show that the scheme can be broken with a low number of power traces. In addition, the authors report the experimental results of the proposed attack against an implementation of Joye's scheme on a Xilinx Microblaze soft‐core processor of SASEBO‐W standard side‐channel analysis board. The authors used least squares support vector machine (LS‐SVM) based binary classifiers to analyse the collected power traces. The authors also describe the potential threat posed by cache timing attacks on Joye's ladder in presence of a concurrently running spy process and outline a probable countermeasure to the posed attacks. Abhishek Chakraborty 0001, Sarani Bhattacharya, Tanu Hari Dixit, Chester Rebeiro, Debdeep Mukhopadhyay |
IET Inf. Secur. | 5 |
| 2016 | Theory and Application of Delay Constraints in Arbiter PUFabstractPhysically Unclonable Function (PUF) circuits are often vulnerable to mathematical model-building attacks . We theoretically quantify the advantage provided to an adversary by any training dataset expansion technique along the lines of security analysis of cryptographic hash functions. We present an algorithm to enumerate certain sets of delay constraints for the widely studied Arbiter PUF (APUF) circuit, then demonstrate how these delay constraints can be utilized to expand the set of known Challenge--Response Pairs (CRPs), thus facilitating model-building attacks. We provide experimental results for Field Programmable Gate Array (FPGA)--based APUF to establish the effectiveness of the proposed attack. Urbi Chatterjee, Rajat Subhra Chakraborty, Hitesh Kapoor, Debdeep Mukhopadhyay |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2015 | Who Watches the Watchmen?: Utilizing Performance Monitors for Compromising Keys of RSA on Intel Platforms
Sarani Bhattacharya, Debdeep Mukhopadhyay |
CHES | 2 |
| 2015 | Improved Test Pattern Generation for Hardware Trojan Detection Using Genetic Algorithm and Boolean Satisfiability
Sayandeep Saha, Rajat Subhra Chakraborty, Srinivasa Shashank Nuthakki, Anshul, Debdeep Mukhopadhyay |
CHES | 5 |
| 2015 | Improved practical differential fault analysis of grain-128
Prakash Dey, Abhishek Chakraborty 0001, Avishek Adhikari, Debdeep Mukhopadhyay |
DATE | 4 |
| 2015 | Efficient attacks on robust ring oscillator PUF with enhanced challenge-response set
Phuong Ha Nguyen, Durga Prasad Sahoo, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
DATE | 4 |
| 2015 | Towards Ideal Arbiter PUF Design on Xilinx FPGA: A Practitioner's PerspectiveabstractDespite the perceived lightweight and structural regularity of Arbiter PUF (APUF), high quality (bias-free) large APUF implementation on FPGA has traditionally proved to be challenging. Currently, the most widely accepted design approach for FPGA-based APUF implementation is the Programmable Delay Line (PDL) based APUF. In this work, we describe a scalable design methodology to implement close-to-ideal APUF on Xilinx FPGA using the standard Xilinx CAD tool flow. The main insight is to exploit the Hard Macro feature of the Xilinx design flow to design bias-free symmetric delay paths. We have demonstrated the effectiveness and superiority of our design to previously proposed PDL-based PUFs through implementation and characterization results. Durga Prasad Sahoo, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay |
DSD | 3 |
| 2015 | From theory to practice of private circuit: A cautionary noteabstractPrivate circuits, from their publication, have been really popular among the researchers. They also form the basis for provable masking schemes. There are several works which try to improve the results of bit-level private circuits based on 2-input gates for the combinational logic. However, strangely, no practical side-channel analysis of private circuits has been presented so far, which is the focus of the present paper. In this paper, we have tried to identify the `ambush' or hidden dangers in the implementation of private circuits, which can compromise its security in practical scenarios. We have implemented block cipher SIMON with private circuit and have performed side-channel analysis on it. The result shows that, in practice, there is significant amount of information leakage which can be exploited by adversaries. Some leakage comes from practical optimization applied by standard CAD tools, if they restructure the netlists. But even with immutable netlists, we identify leakage caused by a kind of glitch known as early evaluation. Lastly, we demonstrate how to translate theoretically secure private circuit to practically secure private circuit with added overhead, by clocking every combinational gate. Leakage detection tests are applied to attest the security of considered variants of private circuits. Debapriya Basu Roy, Shivam Bhasin, Sylvain Guilley, Jean-Luc Danger, Debdeep Mukhopadhyay |
ICCD | 5 |
| 2015 | ECC on Your Fingertips: A Single Instruction Approach for Lightweight ECC Design in GF(p)
Debapriya Basu Roy, Poulami Das 0003, Debdeep Mukhopadhyay |
SAC | 3 |
| 2015 | Micro-Architectural Analysis of Time-Driven Cache Attacks: Quest for the Ideal ImplementationabstractTime-driven attacks on the data cache are a lethal form of cryptanalytic attacks for block-ciphers implemented with look-up tables. The difference of means (DOM) observed in the execution time of a block cipher is often used as a distinguisher to glean information about the secret key. The root cause for the distinguisher to work has long been attributed to the number of cache-misses that occur during the encryption. In this paper, we show that micro-architectural acceleration features in cache memories that are used to reduce miss-penalty (such as pipelining, parallelism, out-of-order, and non-blocking memory accesses) contribute significantly to the leakage. We develop a framework to analyze the DOM distinguisher considering architectural as well as micro-architectural acceleration components in the cache memory. Our findings, which are experimentally verified, show that the two contributing leakage factors (namely the number of cache misses and the micro-architectural acceleration features) affect the DOM in opposite directions. One leakage source results in a positive DOM while the other causes a negative DOM. This opposing characteristic of the leakages makes it feasible to implement block ciphers in a way such that the two leakages cancel each other, thus leading to implementations with higher resistance against time-driven cache-attacks. Chester Rebeiro, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 2 |
| 2015 | Reaching the Limit of Nonprofiling DPAabstractMany profiling differential power analysis (DPA) attacks estimate the multivariate probability distribution using a profiling step, and thus, can optimally combine the leakages of multiple sample points. Though there exist several approaches like filtering or principal component analysis for combining the leakages of multiple sample points in nonprofiling DPA, their optimality has been rarely studied. We study the issue of optimally combining the leakages of multiple sample points in nonprofiling DPA attacks using a linear function. In this paper, we introduce a multivariate leakage model based on some observations obtained by profiling the power traces of Advanced Encryption Standard (AES) encryption on Virtex-5 field programmable gate array (FPGA) device. Then, we use the introduced multivariate leakage model to propose optimal combining functions for nonprofiling DPA. The theoretical claims are supported by experimental evidence. We have also discussed different sides of the proposed combining functions in various practical scenarios. Suvadeep Hajra, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2015 | A Case of Lightweight PUF Constructions: Cryptanalysis and Machine Learning AttacksabstractDue to their unique physical properties, physically unclonable functions (PUF) have been proposed widely as versatile cryptographic primitives. It is desirable that silicon PUF circuits should be lightweight, i.e., have low-hardware resource requirements. However, it is also of primary importance that such demands of low hardware overhead should not compromise the security aspects of PUF circuits. In this paper, we develop two different mathematical attacks on previously proposed lightweight PUF circuits, namely composite PUF and the multibit output lightweight secure PUF (LSPUF). We show that independence of various components of composite PUF can be used to develop divide and conquer attacks which can be used to determine the responses to unknown challenges. We reduce the complexity of the attack using a machine learning-based modeling analysis. In addition, we elucidate a special property of the output network of LSPUF to show how such feature can be leveraged by an adversary to perform an intelligent model building attack. The theoretical inferences are validated through experimental results. More specifically, proposed attacks on composite PUF are validated using the challenge-response pairs (CRPs) from its field programmable gate array (FPGA) implementation, and attack on LSPUF is validated using the CRPs of both simulated and FPGA implemented LSPUF. Durga Prasad Sahoo, Phuong Ha Nguyen, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2014 | Destroying Fault Invariant with Randomization - A Countermeasure for AES Against Differential Fault Attacks
Harshal Tupsamudre, Shikha Bisht, Debdeep Mukhopadhyay |
CHES | 3 |
| 2014 | Tile Before Multiplication: An Efficient Strategy to Optimize DSP Multiplier for Accelerating Prime Field ECC for NIST CurvesabstractHigh speed DSP blocks present in the modern FPGAs can be used to implement prime field multiplication to accelerate Elliptic Curve scalar multiplication in prime fields. However, compared to logic slices, DSP blocks are scarce resources, hence its usage needs to be optimized. The asymmetric 25 × 18 signed multipliers in FPGAs open a new paradigm for multiplier design, where operand decomposition becomes equivalent to a tiling problem. Previous literature has reported that for asymmetric multiplier, it is possible to generate a tiling (known as non-standard tiling) which requires less number of DSP blocks compared to standard tiling, generated by school book algorithm. In this paper, we propose a generic technique for such tiling generation and generate this tiling for field multiplication in NIST specified curves. We compare our technique with standard school book algorithm to highlight the improvement. The acceleration in ECC scalar multiplication due to the optimized field multiplier is experimentally validated for P-256. The impact of this accelerated scalar multiplication is shown for the key encapsulation algorithm PSEC-KEM (Provably Secure Key Encapsulation Mechanism). Debapriya Basu Roy, Debdeep Mukhopadhyay, Masami Izumi, Junko Takahashi |
DAC | 2 |
| 2014 | Circuits and Synthesis Mechanism for Hardware Design to Counter Power Analysis AttacksabstractExecution of cryptographic algorithm in hardware or software usually leaves power/current traces that are dependent on the data being processed. Power analysis attacks (PAAs) have been found to be extremely effective on such systems to derive the cryptographic secrets from these traces. Therefore, countering PAAs is of great importance. In this work, a Binary Decision Diagram (BDD) based dual-rail logic circuit scheme has been developed to counter PAAs. This circuit scheme features novel pre-charge generation, voltage scaling with leakage power minimization and early propagation effect resistance mechanism. A simple synthesis algorithm for mapping given Boolean functions to such BDD based circuits is also presented. The synthesized circuits feature low power circuitry and extremely low peak power variation. Experimental results for elementary gates such as AND, OR, NOT, XOR, NAND, NOR and the Lucifer and the Present S-boxes highlight the advantages of circuits based on this scheme with respect to peak power variance, average power and average current when compared with two other techniques - DP-BDD and SDMLp. Resistance of our S-box implementations to strong differential power analysis and correlation power analysis attacks have also been experimentally demonstrated. All results have been obtained using 65nm technology. Partha De, Kunal Banerjee 0001, Chittaranjan A. Mandal, Debdeep Mukhopadhyay |
DSD | 4 |
| 2014 | Differential Fault Analysis on the Families of SIMON and SPECK CiphersabstractIn 2013, the US National Security Agency proposed two new families of lightweight block ciphers: SIMON and SPECK. Currently, linear and differential cryptanalytic results for SIMON are available in the literature but no fault attacks have been reported so far on these two cipher families. In this paper, we show that these families of ciphers are vulnerable to differential fault attacks. Specifically, we demonstrate two fault attacks on SIMON and one fault attack on SPECK. The first attack on SIMON assumes a bit-flip fault model and recovers the n-bit last round key of SIMON using n/2 bit faults. The second attack on SIMON uses a more practical, random byte fault model and requires n/8 faults on average to retrieve the last round key. The attack presented on SPECK also assumes a bit-flip fault model and recovers the n-bit last round key of SPECK using n/3 bit faults on average. Harshal Tupsamudre, Shikha Bisht, Debdeep Mukhopadhyay |
FDTC | 3 |
| 2013 | Multivariate Leakage Model for Improving Non-profiling DPA on Noisy Power Traces
Suvadeep Hajra, Debdeep Mukhopadhyay |
Inscrypt | 2 |
| 2013 | Role of power grid in side channel attack and power-grid-aware secure designabstractSide-channel attack (SCA) is a method in which an attacker aims at extracting secret information from crypto chips by analyzing physical parameters (e.g. power). SCA has emerged as a serious threat to many mathematically unbreakable cryptography systems. From an attacker's point of view, the difficulty of mounting SCA largely depends on Signal-to-Noise Ratio (SNR) of the side-channel information. It has been shown that SNR primarily depends on algorithmic and circuit-level implementation, measurement noise, as well as device thermal noise. However, to the best of our knowledge, there has not been any study on the effect of power delivery network (PDN) on SCA resistance. We note that the PDN plays a significant role in SNR of measured supply current. Furthermore, SCA resistance strongly depends on the operating frequency due to RLC structure of a power grid. In this paper, we analyze the effect of power grid on SCA and provide quantitative results to demonstrate the frequency-dependent SCA resistance due to PDN-induced noise. This property can potentially be exploited by an attacker to facilitate the attack by operating a device at favorable frequency points. On the other hand, from a designer's perspective, one can explore countermeasures to secure the device at all operating frequencies while minimizing the design overhead. Based on this observation, we propose a frequency-dependent noise-injection based compensation technique to efficiently protect against SCA. Simulation results using realistic PDN model as well as experimental measurements using FPGA test board validate the observations on role of PDN in SCA and the efficacy of the proposed compensation approach. Xinmu Wang, Wen Yueh, Debapriya Basu Roy, Seetharam Narasimhan, Yu Zheng 0011, Saibal Mukhopadhyay, Debdeep Mukhopadhyay, Swarup Bhunia |
DAC | 7 |
| 2013 | Designing DPA Resistant Circuits Using BDD Architecture and Bottom Pre-charge LogicabstractDifferential power analysis (DPA) attacks are the most powerful side channel attacks against cryptographic systems. In this work, a reduced ordered binary decision diagram (ROBDD) based dual rail circuit for a basic DPA resistant cell has been designed. The specialty of this cell is that the overall input current of the cell is invariant to the input combinations of data bits applied to the cell. For the first time, bottom pre-charge logic is used in the design of such a cell. The ROBDD based design minimizes both area and early propagation effect. A number of logic functions including AND, OR, XOR, NOT, NAND, NOR and also an adder, all based on the basic cell, have then been designed in a hierarchical manner. Experimental results demonstrate DPA resistance of the circuits (for example an adder) developed using this cell, outperforming other competing design with respect to peak power variance. Partha De, Kunal Banerjee 0001, Chittaranjan A. Mandal, Debdeep Mukhopadhyay |
DSD | 4 |
| 2013 | PERMS: A Bit Permutation Instruction for Accelerating Software CryptographyabstractThis paper proposes a new bit-permutation instruction, named PERMS for accelerating software cryptography. Bit permutation is a very commonly used operation in standard cryptographic algorithms. However, modern processors are word oriented and provide little support for high-speed implementation of bit permutations. With the help of PERMS instruction, any arbitrary n bit permutation can be performed using less than log(n) number of instructions. The proposed instruction is also scalable to perform 2n bit permutation, using an n bit instruction. The comparison with the existing bit-permutation instructions shows that PERMS needs least area requirement in hardware and also provides better throughput/slice ratio than one of the best bit-permutation instruction found in literature. The instruction format of PERMS provides the scope to be added with all the modern ISAs. Further, due to the very less hardware requirement, PERMS can also be considered for resource constrained devices, like PDAs. Souvik Kolay, Sagar Khurana, Anupam Sadhukhan, Chester Rebeiro, Debdeep Mukhopadhyay |
DSD | 5 |
| 2013 | Improved Differential Fault Analysis of CLEFIAabstractCLEFIA is already shown to be vulnerable to differential fault analysis (DFA). The existing state-of-the-art DFA shows that two faults are enough to break CLEFIA-128, whereas for CLEFIA-192 and CLEFIA-256 ten faults are needed. Side-by-side it emphasizes the need for protecting last four rounds of the cipher in order to make it secure against the attack. In this paper we propose an improved DFA on CLEFIA. The analysis shows that an attack is possible even if the last four rounds of CLEFIA are protected against DFA. Further, the proposed attacks on CLEFIA-192 and CLEFIA-256 show that 8 faults are sufficient to successfully retrieve the 192 and 256-bit key respectively. The work shows improvement over the previous work. Extensive simulation results have been presented to validate the proposed attack. The simulation results show that the attack can retrieve the 128-bit secret key in around one minute of execution time whereas the attack on 192 and 256-bit key requires around one second to retrieve the secret key. Subidh Ali, Debdeep Mukhopadhyay |
FDTC | 2 |
| 2013 | On-line testing for differential fault attacks in cryptographic circuitsabstractFaults have been found to be catastrophic for the security of ciphers. Random faults inside a cipher implementation, trigger intentionally or accidentally, can be shown to reduce the key space of ciphers drastically. Even world-wide standard ciphers, like the Advanced Encryption Standard (AES) can be shown to be cryptanalyzed when the faulty ciphertexts are exposed to the outside world. Our recent findings show that fluctuations of the operating conditions of a circuit introduces circuit marginalities, which are manifested as exploitable multiple byte faults. The paper subsequently deals with a natural follow up question, how to test these faults? Can we adopt classical fault tolerance methods to detect these malicious faults? We show that while classical fault tolerance assumes uniform distribution of faults, the fault attacker introduces biased faults. On the other hand, while classical fault tolerance attempts to target all faults, most of the attacks exploit a small subspace of the entire fault space. This hiatus implies the necessity of the emergence of novel on-line methodologies for fault detection. The paper concludes with the requirement of proofs for 100% fault coverage of the attack-exploitable space, vs the simulation based approaches of classical fault tolerance. Debdeep Mukhopadhyay |
IOLTS | 1 |
| 2013 | Constrained Search for a Class of Good Bijective S-Boxes With Improved DPA ResistivityabstractThe transparency order is proposed as a parameter for the robustness of S-boxes to differential power analysis (DPA): lower transparency order implying more resistance. However, most cryptographically strong S-boxes have been found to have high transparency order. In this paper, we characterize transparency order for various classes of S-boxes by computing the upper and lower bounds of transparency order for both even and odd numbers of variables. We find high transparency order values in the class of S-boxes whose sum of autocorrelation spectra of the coordinate functions has zero value for a large number of vectors a. Also instead of propagation characteristics, autocorrelation spectra of the S-box function F are found to be stronger in deciding the transparency order. With this characterization, we performed a constrained random generation and search of a class of balanced 8 × 8 S-boxes with transparency order upper bounded by 7.8. The nonlinearity and absolute indicator values of global avalanche characteristics of the coordinate functions of the S-boxes are in the range (98, 110) and (48, 88), respectively. A correlation analysis DPA on table look-up implementation of AES Rijndael S-box revealed the last round key in 700 power traces, while it took at least 1500 power traces with S-boxes from our proposed class. Bodhisatwa Mazumdar, Debdeep Mukhopadhyay, Indranil Sengupta 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Formalizing the Effect of Feistel Cipher Structures on Differential Cache AttacksabstractThe success of a side-channel attack depends mainly on three factors, namely, the cipher algorithm, the attack platform, and the measurement noise. In this paper, we consider a class of side-channel attacks known as differential cache attacks on Feistel ciphers, and develop a theoretical framework to understand the relationship between the attack's success, the target platform, and the cipher algorithm. The framework allows a comparison of various differential cache attack forms, and is supported by case studies on the block ciphers CLEFIA and CAMELLIA. To understand the effect of noise in the attack's success, the paper uses empirical methods on standard Intel platforms in a time driven side-channel analysis scenario. Chester Rebeiro, Phuong Ha Nguyen, Debdeep Mukhopadhyay, Axel Poschmann |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2013 | Secure Dual-Core Cryptoprocessor for Pairings Over Barreto-Naehrig Curves on FPGA PlatformabstractThis paper is devoted to the design and the physical security of a parallel dual-core flexible cryptoprocessor for computing pairings over Barreto-Naehrig (BN) curves. The proposed design is specifically optimized for field-programmable gate-array (FPGA) platforms. The design explores the in-built features of an FPGA device for achieving an efficient cryptoprocessor for computing 128-bit secure pairings. The work further pinpoints the vulnerability of those pairing computations against side-channel attacks and demonstrates experimentally that power consumptions of such devices can be used to attack these ciphers. Finally, we suggest a suitable countermeasure to overcome the respective weaknesses. The proposed secure cryptoprocessor needs 1 730 000, 1 206 000, and 821 000 cycles for the computation of Tate, ate, and optimal-ate pairings, respectively. The implementation results on a Virtex-6 FPGA device shows that it consumes 23 k Slices and computes the respective pairings in 11.93, 8.32, and 5.66 ms. Santosh Ghosh, Debdeep Mukhopadhyay, Dipanwita Roy Chowdhury |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2013 | Theoretical Modeling of Elliptic Curve Scalar Multiplier on LUT-Based FPGAs for Area and SpeedabstractThis paper uses a theoretical model to approximate the delay of different characteristic two primitives used in an elliptic curve scalar multiplier architecture (ECSMA) implemented onkinput lookup table (LUT)-based field-programmable gate arrays. Approximations are used to determine the delay of the critical paths in the ECSMA. This is then used to theoretically estimate the optimal number of pipeline stages and the ideal placement of each stage in the ECSMA. This paper illustrates suitable scheduling for performing point addition and doubling in a pipelined data path of the ECSMA. Finally, detailed analyses, supported with experimental results, are provided to design the fastest scalar multiplier over generic curves. Experimental results for GF(2163) show that, when the ECSMA is suitably pipelined, the scalar multiplication can be performed in only 9.5 μs on a Xilinx Virtex V. Notably the design has an area which is significantly smaller than other reported high-speed designs, which is due to the better LUT utilization of the underlying field primitives. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2012 | Pushing the Limits of High-Speed GF(2 m ) Elliptic Curve Scalar Multiplication on FPGAs
Chester Rebeiro, Sujoy Sinha Roy, Debdeep Mukhopadhyay |
CHES | 3 |
| 2012 | Differential Fault Analysis of Twofish
Subidh Ali, Debdeep Mukhopadhyay |
Inscrypt | 2 |
| 2012 | Improved Differential Cache Attacks on SMS4
Phuong Ha Nguyen, Chester Rebeiro, Debdeep Mukhopadhyay, Huaxiong Wang |
Inscrypt | 3 |
| 2012 | A Parallel Architecture for Koblitz Curve Scalar Multiplications on FPGA PlatformsabstractElliptic curve scalar multiplication is the central operation in elliptic curve cryptography. The paper presents a parallel architecture to accelerate scalar multiplications on Koblitz curves. The scalar multiplier architecture converts the scalar into τ-NAF representation and processes the zero digits of the scalar in parallel to point additions. Since the conversion from integer to τ-NAF is a time consuming operation, the proposed architecture uses recently developed double lazy reduction algorithm for conversion of scalar. The scalar multiplier processes two consecutive τ-NAF digits in every iteration. This facilitates parallel processing of large number of consecutive zero digits during a single point addition and practically no time is spent for processing the zero digits of the scalar. The proposed techniques are incorporated in a scalar multiplier and validated on Xilinx Virtex IV FPGA. Experimental results show that our architecture in F2163 has the best performance and has the computation time comparable with the fastest known implementation, which uses window based scalar multiplication algorithm. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
DSD | 3 |
| 2012 | Generalized high speed Itoh-Tsujii multiplicative inversion architecture for FPGAs
Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
Integr. | 3 |
| 2012 | Boosting Profiled Cache Timing Attacks With A Priori AnalysisabstractThe vulnerability of cryptographic devices to side-channel attacks is of interest in the domain of information security. The success of a side-channel attack depends on the crypto-algorithm implementation, the platform being attacked, and the attack strategy. While the former two parameters are generally beyond the adversary's control, the choice of the attack strategy is solely with the adversary. However, there is no unique “best attack strategy.” The attack strategy that works best for one platform may not be the best for another. Further there is no systematic way to choose the best attack strategy from the available pool. In this paper, we analyze a category of side-channel attacks known as profiled cache-timing attacks and develop a methodology by which an adversary capable of limited number of side-channel measurements can choose the best strategy prior to the actual attack. The methodology is tested on several platforms and cipher implementations and shows that the best attacking strategy can be estimated closely, without the requirement of an exhaustive search. Chester Rebeiro, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2011 | Testability of Cryptographic Hardware and Detection of Hardware TrojansabstractCryptographic algorithms are routinely used toper form computationally intense operations over increasingly larger volumes of data, and in order to meet the high throughput requirements of the applications, are often implemented by VLSI designs. The high complexity of such implementations raises concern about their reliability. In order to improve upon the testability of sequential circuits, both at fabrication time and also in the field, Design For Testability (DFT) techniques are commonly employed. However conventional DFT methodologies for digital circuits have been found to compromise the security of the cryptographic hardware. In this tutorial we first discuss the challenges and potential attacks on cipher hardware through standard DFT techniques, and then potential solutions against them. Also, as the electronic design industry has grown globally, economic reasons dictate the widespread participation of external agents in modern design and manufacture of integrated circuits(ICs), which decreases the control that the IC design houses used to traditionally have over their own designs. This issue raises the question of ensuring Trust in an integrated circuit, and whether the IC can be certified to be free of malicious, hard-to detect circuitry, commonly referred to as Hardware Trojans. In this tutorial, we would explore the unique challenges and testing solutions to detect/prevent such malicious modifications. Debdeep Mukhopadhyay, Rajat Subhra Chakraborty |
Asian Test Symposium | 1 |
| 2011 | Differential Fault Analysis of AES-128 Key Schedule Using a Single Multi-byte Fault
Subidh Ali, Debdeep Mukhopadhyay |
CARDIS | 2 |
| 2011 | Cryptanalysis of CLEFIA Using Differential Methods with Cache Trace Patterns
Chester Rebeiro, Debdeep Mukhopadhyay |
CT-RSA | 2 |
| 2011 | Multi-level attacks: An emerging security concern for cryptographic hardwareabstractModern hardware and software implementations of cryptographic algorithms are subject to multiple sophisticated attacks, such as differential power analysis (DPA) and fault-based attacks. In addition, modern integrated circuit (IC) design and manufacturing follows a horizontal business model where different third-party vendors provide hardware, software and manufacturing services, thus making it difficult to ensure the trustworthiness of the entire process. Such business practices make the designs vulnerable to hard-to-detect malicious modifications by an adversary, termed as “Hardware Trojans”. In this paper, we show that malicious nexus between multiple parties at different stages of the design, manufacturing and deployment makes the attacks on cryptographic hardware more potent. We describe the general model of such an attack, which we refer to as Multi-level Attack, and provide an example of it on the hardware implementation of the Advanced Encryption Standard (AES) algorithm, where a hardware Trojan is embedded in the design. We then analytically show that the resultant attack poses a significantly stronger threat than that from a Trojan attack by a single adversary. We validate our theoretical analysis using power simulation results as well as hardware measurement and emulation on a FPGA platform. Subidh Ali, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay, Swarup Bhunia |
DATE | 3 |
| 2011 | Theoretical modeling of the Itoh-Tsujii Inversion algorithm for enhanced performance on k-LUT based FPGAsabstractMaximizing the performance of the Itoh-Tsujii finite field inversion algorithm (ITA) on FPGAs requires tuning of several design parameters. This is often time consuming and difficult. This paper presents a theoretical model for the ITA for any Galois field and fc-input LUT based FPGA (k >; 3). Such a model would aid a hardware designer to select the ideal design parameters quickly. The model is experimentally validated with the NIST specified fields and with 4 and 6 LUT based FPGAs. Finally, it is demonstrated that the resultant designs of the Itoh-Tsujii Inversion algorithm is most optimized among contemporary works on LUT based FPGAs. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
DATE | 3 |
| 2011 | A Differential Fault Analysis on AES Key Schedule Using Single FaultabstractLiterature on Differential Fault Analysis (DFA) on AES-128 shows that it is more difficult to attack AES when the fault is induced in the key schedule, than when it is injected in the intermediate states. Recent research shows that DFA on AES key schedule still requires two faulty cipher texts, while it requires only one faulty cipher text and a brute-force search of 28AES-128 keys when the fault is injected inside the round of AES. The present paper proposes a DFA on AES-128 key schedule which requires only one single byte fault and a brute-force search of 28keys, showing that a DFA on AES key schedule is equally dangerous as a fault analysis when the fault is injected in the intermediate state of AES. Further, the fault model of the present attack is a single byte fault. This is more realistic than the existing fault model of injecting three byte faults in a column of the AES key which has a less chance of success. To the best of our knowledge the proposed attack is the best known DFA on AES key schedule and requires minimum number of faulty cipher text. The simulated attack, running on 3GHz Intel Core 2 Duo desktop machine with 2GB RAM, takes around 35 minutes to reveal the secret key. Subidh Ali, Debdeep Mukhopadhyay |
FDTC | 2 |
| 2011 | Accelerating Itoh-Tsujii multiplicative inversion algorithm for FPGAsabstractThe Itoh-Tsujii multiplicative inversion algorithm (ITA) is the most efficient finite field inversion algorithm for hardware based implementations over extended binary fields. In this paper we propose a novel technique to reduce the computation time of the ITA by saving clock cycles without increasing the delay and area significantly. In order to compare, we have designed the architecture for the ITA in the field GF(2193). The architecture uses a configuration of a cascaded quad-root block in parallel with a 297 circuit to compute the inverse in only .53 ¼secs on a Virtex E FPGA and .14 ¼secs on a Virtex V FPGA. Experimental results are presented to support that the architecture takes least computation time compared to other reported results. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
ACM Great Lakes Symposium on VLSI | 3 |
| 2011 | Differential Fault Analysis of the Advanced Encryption Standard Using a Single Fault
Michael Tunstall, Debdeep Mukhopadhyay, Subidh Ali |
WISTP | 2 |
| 2011 | A Parallel Efficient Architecture for Large Cryptographically Robust n × k (k>n/2) MappingsabstractWe present a scalable, modular, memoryless, and reconfigurable parallel architecture to generate cryptographically robust mappings, which are useful in the construction of stream and block ciphers. It has been theoretically proved that the proposed architecture can be reconfigured to generate a large number of mappings, all of which have high nonlinearity, satisfies Strict Avalanche Criterion (SAC) and is robust against linear and differential cryptanalysis. The architecture can be also used to optimize the resiliency and algebraic degree. The architecture has been found to scale easily to handle large number of input variables, which is an important criterion in realizing nonlinear combiners for stream ciphers using Boolean functions. Debdeep Mukhopadhyay, Dipanwita Roy Chowdhury |
IEEE Trans. Computers | 1 |
| 2011 | Revisiting the Itoh-Tsujii Inversion Algorithm for FPGA PlatformsabstractThe Itoh-Tsujii multiplicative inverse algorithm (ITA) forms an integral component of several cryptographic implementations such as elliptic curve cryptography. For binary fields generated by irreducible trinomials, this paper proposes a modified ITA algorithm for efficient implementations on field-programmable gate-array (FPGA) platforms. Efficiency is obtained by the fact that the adapted ITA algorithm uses FPGA resources better and requires shorter addition chains. Evidence is furnished and supported with experimental results to show that the proposed architecture outperforms reported results. The proposed method is also shown to be scalable with respect to field sizes. Chester Rebeiro, Sujoy Sinha Roy, Sankara Reddy, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2010 | High Speed Flexible Pairing Cryptoprocessor on FPGA Platform
Santosh Ghosh, Debdeep Mukhopadhyay, Dipanwita Roy Chowdhury |
Pairing | 2 |
| 2010 | New Pseudo Near Collision Attack on Tiger
Dibyendu Mallik, Debdeep Mukhopadhyay |
SECRYPT | 2 |
| 2009 | Effect of glitches against masked AES S-box implementation and countermeasureabstractMasking of gates is one of the most popular techniques to prevent differential power analysis (DPA) of AES algorithm. It has been shown that the logic circuits used in the implementation of cryptographic algorithms leak side-channel information inspite of masking, which can be exploited, in differential power attacks. The phenomenon in CMOS circuits responsible for the leakage of masked circuits is known as glitching. Motivated by this fact, the authors analyse the effect of glitches in CMOS circuits against masked implementation of the AES S-box. The authors explicitly demonstrate that glitches do not affect always. There exists a relation between combinational path delay of the circuit and timing difference of input vectors to the circuit, which has a bearance on the amount of information leaked by the masked gates. A balanced masked S-box circuit is proposed where the inputs are synchronised by sequential components. Detailed SPICE results are shown to support the claim that the modifications indeed reduce the vulnerability of the masked AES S-box against DPA attacks. Monjur Alam, Santosh Ghosh, M. J. Mohan, Debdeep Mukhopadhyay, Dipanwita Roy Chowdhury, Indranil Sengupta 0001 |
IET Inf. Secur. | 4 |
| 2007 | Strengthening NLS Against Crossword Puzzle Attack
Debojyoti Bhattacharya, Debdeep Mukhopadhyay, Dhiman Saha, Dipanwita Roy Chowdhury |
ACISP | 2 |
| 2007 | An area optimized reconfigurable encryptor for AES-Rijndael
Monjur Alam, Sonai Ray, Debdeep Mukhopadhyay, Santosh Ghosh, Dipanwita Roy Chowdhury, Indranil Sengupta 0001 |
DATE | 3 |
| 2007 | Hierarchical Verification of Galois Field CircuitsabstractThis paper proposes a hierarchical method for the formal hardware verification of Galois field architecture circuits. The reduced ordered functional decision diagram has been explored. The proposed method has been found to lead to significant gains in time and space, depending on the resources that are available. The theoretical claims that were made have been supported by experiments. Debdeep Mukhopadhyay, Gaurav Sengar, Dipanwita Roy Chowdhury |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2007 | Secured Flipped Scan-Chain Model for Crypto-ArchitectureabstractScan chains are exploited to develop attacks on cryptographic hardware and steal intellectual properties from the chip. This paper proposes a secured strategy to test designs by inserting a certain number of inverters between randomly selected scan cells. The security of the scheme has been analyzed. Two detailed case studies of RC4 stream cipher and AES block cipher have been presented to show that the proposed strategy prevents existing scan-based attacks in the literature. The elegance of the scheme lies in its less hardware overhead. Gaurav Sengar, Debdeep Mukhopadhyay, Dipanwita Roy Chowdhury |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2006 | Design and Analysis of a Robust and Efficient Block Cipher using Cellular AutomataabstractCellular automaton (CA) has been shown to be capable of generating complex and random patterns out of simple rules. There has been constant efforts of applying CA to develop ciphers, but the attempts have not been successful. This paper describes how repeated application of simple CA transforms may be used to achieve confusion and diffusion, needed in block ciphers. The components have been evaluated for their robustness against conventional cryptanalysis and the results have been found to be comparable to standards. Finally, the parts are assembled in an unconventional way to construct a self-invertible CA based round, which is resistant against linear and differential cryptanalysis and yet can be efficiently implemented Pallavi Joshi, Debdeep Mukhopadhyay, Dipanwita Roy Chowdhury |
AINA (2) | 2 |
| 2006 | An integrated DFT solution for mixed-signal SOCsabstractThis paper introduces an efficient implementation of a test access mechanism (TAM) for mixed-signal system-on-chip (MSOC) testing. The design-for-testability (DFT) strategy has been developed to make the testing of analog cores digitally compliant. The mixed-signal cores have been accessed through specially design mechanisms (switches). A computer-aided test (CAT) tool employing the proposed algorithm has been developed. Extensive experiments have been performed on MSOC benchmarks built of ISCAS'89 circuits for digital cores and ITC'97 circuits for analog cores. Results show that the CAT tool provides a hardware-efficient integrated solution. Shibaji Banerjee, Debdeep Mukhopadhyay, C. V. G. Rao, Dipanwita Roy Chowdhury |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2005 | CryptoScan: A Secured Scan Chain ArchitectureabstractScan based testing is a powerful and popular test technique. However the scan chain can be used by an attacker to decipher the cryptogram. The present paper shows such a side-channel attack on LFSR-based stream ciphers using scan chains. The paper subsequently discusses a strategy to build the scan chains in a tree based pattern with a selfchecking compactor. It has been shown that such a structure prevents such scan based attacks but does not compromise on fault coverage. Debdeep Mukhopadhyay, Shibaji Banerjee, Dipanwita Roy Chowdhury, Bhargab B. Bhattacharya |
Asian Test Symposium | 1 |