VLDB 2026 Research / reviewers in the wild / expert
Georg Sigl
dblp:89/4621
· DBLP profile ↗
83ranked-venue papers
2as first author
33since 2021 · last 2026
0000-0003-3152-941XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 56 · 2 first-author · 26 since 2021Security and privacy · 26 · 7 since 2021Software engineering, systems software and programming languages · 15 · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-Partner Project: Advancing European Semiconductor and Chiplet Innovation Through the Bavarian Chip Design CenterabstractEurope’s semiconductor industry relies heavily on Asian and US manufacturers. The EU Chips Act seeks to strengthen Europe’s capabilities across the semiconductor value chain. Aligned with this goal, the Bavarian Chip Design Center (BCDC) supports local chip design, manufacturing, and talent development, with a focus on RISC-V computing and heterogeneous integration. Within BCDC, the Technical University of Munich and Fraunhofer are developing a chiplet-based architecture optimized for low-power edge AI. The system integrates two chiplets, combining a security-enhanced RISC-V core and AI accelerators, connected via a chiplet-optimized serial interface that supports encrypted data. The chiplets are mounted on a custom interposer with low-capacitance wires for efficient data transmission. System-and component-level development is currently ongoing, with a tapeout in 22 nm FD-SOI planned for 2027. The overall goal is to deliver a proof of concept for a small-scale energy-efficient chiplet system that demonstrates Bavaria’s and Europe’s capability to drive innovation in novel chip design fields. Hussam Amrouch, Jehaan Joseph, Michael Schirmer, Johannes Geier, Ulf Schlichtmann, Michael Meidinger, Thomas Wild, Andreas Herkersdorf, Jens Nöpel, Georg Sigl, Carsten Trinitis, Aswathy Nedumpalli Sankaranarayanan, Martin Schulz 0001, Andreas Korb, Konrad Hohentanner |
DATE | 10 |
| 2026 | An Efficient Secure Boot Mechanism Leveraging DICE as a Use CaseabstractSecure boot ensures that only verified code is executed at boot time. It typically relies on asymmetric cryptography, which may pose boot time challenges for time-critical devices. We, therefore, propose an efficient secure boot (ESB) mechanism that extends the asymmetric cryptography-based approach with symmetric cryptography to reduce boot time. To demonstrate the practicality, an extended Device Identifier Composition Engine (DICE) architecture is leveraged as a use case. The evaluation results on an ARM-based MCU show that the proposed mechanism reduces boot time for regular boots while introducing a slightly higher overhead only during the initial boot phase. Utku Budak, Malek Safieh, Yigit Arda Ozen, Fabrizio De Santis, Georg Sigl |
DATE | 5 |
| 2026 | Multi-Partner Project: A Holistic and Open-Source Approach to Efficient, Secure and Reliable AI Hardware Deployment in DI-EDAIabstractArtificial Intelligence (AI) has demonstrated strong capabilities across various domains over the past decade. Edge and specifically mission-critical applications, such as automotive and aerospace, require both high performance and efficiency without compromises in security and reliability. This stems from tightly constrained power consumption, failures that can have catastrophic consequences and devices that may be physically accessible to malicious actors. AI algorithm deployment to hardware also presents significant barriers, requiring specialized knowledge and expensive development tools. The DI-EDAI project aims to offer a holistic approach for connecting high-level AI algorithms with hardware implementations while tackling the aforementioned issues. Unlike other approaches that address individual aspects of the AI deployment flow, we investigate solutions across multiple layers of the design stack. Through our work we develop efficient hardware, map AI algorithms to hardware while simultaneously ensuring security and reliability. Furthermore, we leverage AI-techniques to assist with Electronic Design Automation (EDA) workflows for design optimization, verification and implementation. Our open source approach aims to reduce entry barriers, promote transparency and education, and spark innovation. This paper presents the current state of the DI-EDAI project at midterm, highlighting our latest contributions, identifying limitations in existing state-of-the-art approaches, and outlining ongoing work to address these gaps. Georgios Sotiropoulos, Felix Frombach, Julian Höfer, Tanja Harbaum, Jürgen Becker 0001, Henrik Iver Thorøe, Vincent Meyers, Mehdi Baradaran Tahoori, Zeynep Demirdag, Mohammed Bakr Sikal, Hassan Nassar, Heba Khdr, Jörg Henkel, Christopher Wolters, Philipp van Kempen, Johannes Geier, Ulf Schlichtmann, Batuhan Sesli, Muhammad Sabih, Jakob Wittmann, Frank Hannig, Jürgen Teich, Lukas Steiner, Norbert Wehn, Mohamed Shelkamy Ali, Philipp Schmitz, Wolfgang Kunz, Stefan Koegler, Georg Sigl |
DATE | 29 |
| 2026 | Influence of Parallelism in Vector-Multiplication Units on Correlation Power AnalysisabstractThe use of Neural Networks (NNs) in edge devices is increasing, introducing new security challenges related to the confidentiality of NNs. As edge devices often offer physical access, attacks targeting the hardware, such as Side-Channel Analysis (SCA), must be considered. To enhance the performance of NN inference, hardware accelerators are commonly employed. This work investigates the influence of parallel processing within such accelerators on correlation-based side-channel attacks that exploit power consumption. The focus is on neurons that are part of the same fully-connected layer, which run parallel and simultaneously process the same input value. The theoretical impact of concurrent Multiply-and-Accumulate (MAC) operations on overall power consumption is evaluated, as well as the success rate of Correlation Power Analysis (CPA). Based on the observed behavior, equations are derived that describe how the correlation decreases with increasing levels of parallelism. The applicability of these equations is validated using a vector-multiplication unit implemented on a Field Programmable Gate Array (FPGA). The theoretical boundary for successful CPA is found to be 15 parallel Processing Elements (PEs), while practical results show this limit is reduced to 8 PEs due to noise and Signal-to-Noise Ratio (SNR) reduction. Manuel Brosch, Matthias Probst, Stefan Koegler, Georg Sigl |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2025 | Special Session - Hardware-Software Co-Design for Machine Learning Systems Made Open-SourceabstractChip technologies are crucial for the digital transformation of industry and society. Machine Learning (ML) and Artificial Intelligence (AI) are increasingly shaping both daily life and industrial applications, with AI hardware playing a vital role in enabling efficient and scalable ML deployment. However, significant challenges remain in bridging the gap between ML algorithm development and hardware implementation, particularly for edge ML applications where efficiency, power constraints, and adaptability are critical. In such resource-constrained environments, hardware-software co-design becomes essential to achieve the necessary trade-offs between performance, energy efficiency, and system responsiveness. One of the key bottlenecks in ML hardware development is the lack of seamless integration between ML toolchains and electronic design automation (EDA) tools for hardware synthesis and mapping. Current solutions often require extensive manual optimization and costly proprietary software, limiting accessibility and innovation. Open-source tools can play a transformative role in democratizing ML hardware design, fostering collaboration, and addressing the growing shortage of skilled professionals. This paper covers key aspects of hardware-software co-design for ML systems, such as ML algorithms, hardware design, compiler technologies and system security, with a focus on open-source solutions. We highlight the critical need for open-source toolchains that connect ML model development with hardware synthesis and optimization and present solutions for custom hardware, as well as FPGA accelerators. Mehdi Baradaran Tahoori, Vincent Meyers, Mahboobe Sadeghipourrudsari, Huashuangyang Xu, Jürgen Becker 0001, Tanja Harbaum, Felix Frombach, Julian Höfer, Georgios Sotiropoulos, Jörg Henkel, Zeynep Demirdag, Heba Khdr, Hassan Nassar, Ulf Schlichtmann, Johannes Geier, Philipp van Kempen, Georg Sigl, Stefan Koegler, Matthias Probst, Jürgen Teich, Frank Hannig, Muhammad Sabih, Batuhan Sesli, Norbert Wehn, Lukas Steiner, Wolfgang Kunz, Mohamed Shelkamy Ali |
CODES+ISSS | 17 |
| 2025 | Multi-Partner Project: Open-Source Design Tools for Co-Development of AI Algorithms and AI Chips: (Initial Stage)abstractChip technologies are crucial for the digital transformation of industry and society. Artificial Intelligence (AI) is playing an increasingly important role in both our daily lives and in industry. The development of advanced AI chip designs, essential for the successful deployment of AI, is of critical importance for innovation and competitiveness. However, challenges arise from the complexity of hardware development, expensive access to state-of-the-art design tools, and a global shortage of hardware experts. In addition to cost optimization, computational power, and energy consumption, security and trustworthiness are becoming increasingly important. This project aims to address these challenges in AI chip design by enabling efficient hardware development. We are developing a seamless transition between software-based AI model development and optimization, and efficient hardware implementation, while considering security, trustworthiness, and energy efficiency. An open-source approach plays a key role, facilitating access for small and medium-sized enterprises (SMEs) and expanding the community involved in AI chip design to help mitigate the shortage of skilled professionals. Mehdi Baradaran Tahoori, Jürgen Becker 0001, Jörg Henkel, Wolfgang Kunz, Ulf Schlichtmann, Georg Sigl, Jürgen Teich, Norbert Wehn |
DATE | 6 |
| 2025 | Fault Detection in the Control- and Data-Path of Neural NetworksabstractMachine learning and neural networks experience growing usage in resource-constrained devices. However, moving neural networks to small devices also brings new requirements regarding the reliability and security of the networks and their hardware. In many areas, such as autonomous driving, the device must detect possible errors during execution to ensure safe functionality. Moreover, an adversary can gain physical access to the device, opening the door for hardware attacks like fault injections that target misclassification or parameter retrieval. This work proposes a fault detection mechanism for software implementations of neural networks running on a microcontroller to increase the reliability and security of the neural network. Our technique uses AN-codes, a type of error-detecting code, to detect errors in calculations within the neural network without any implications on the accuracy of protected networks. In addition, signature checking ensures the integrity of the control flow. Simulations and real-world testing show that our mechanism successfully detects faults in all possible locations in the neural network’s program code. Despite the robustness of our fault detection mechanism, it has an overhead in code size of only about 10%, independent of the implemented network. The memory usage increases by at most 232 bytes independently of the neural network size, ensuring that the mechanism is not overly burdensome for the memory. Matthias Probst, Manuel Brosch, Augustin Ewald, Michael Gruber, Georg Sigl |
FDTC | 5 |
| 2025 | Side-Channel Analysis of Integrate-and-Fire Neurons Within Spiking Neural NetworksabstractSpiking neural networks gain increasing attention in constraint edge devices due to event-based low-power operation and little resource usage. Such edge devices often allow physical access, opening the door for Side-Channel Analysis. In this work, we introduce a novel robust attack strategy on the neuron level to retrieve the trained parameters of an implemented spiking neural network. Utilizing horizontal correlation power analysis, we demonstrate how to recover the weights and thresholds of a feed-forward spiking neural network implementation. We verify our methodology with real-world measurements of localized electromagnetic emanations of an FPGA design. Additionally, we propose countermeasures against the introduced novel attack approach. We evaluate shuffling and masking as countermeasures to protect the implementation against our proposed attack and demonstrate their effectiveness and limitations. Matthias Probst, Manuel Brosch, Georg Sigl |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2025 | Performance and Communication Cost of Hardware Accelerators for Hashing in Post-Quantum CryptographyabstractSPHINCS+ is a signature scheme included in the first NIST post-quantum standard that bases its security on the underlying hash primitive. As most of the runtime of SPHINCS+ is caused by the evaluation of several hash- and pseudo-random functions, offloading this computation to dedicated hardware accelerators is a natural step. In this work, we evaluate different architectures for hardware acceleration of such a hash primitive with respect to its use-case and evaluate them in the context of SPHINCS+. We attach hardware accelerators for different hash primitives (SHAKE256 and Ascon-Xof for both full and round-reduced versions) to CPU interfaces having different transfer speeds. We show that for most use-cases, data transfer determines the overall performance if accelerators are equipped with FIFOs and that reducing the number of rounds in the permutation does not necessarily lead to significant performance improvements when using hardware acceleration. This work extends on a conference paper accepted at COSADE’24, first published in [ 19 ], and written by the same authors, where different architectures for hardware accelerators of hash functions are benchmarked and evaluated for SPHINCS+ as a case study. In this article, we provide results for additional parameter sets for SPHINCS+ and improve the performance of one of the accelerators by adding an additional RISC-V instruction for faster absorption. We then extend the performance benchmark by including the algorithms CRYSTALS-Kyber, CRYSTALS-Dilithium, and Falcon. Finally, we provide a power/energy comparison for the accelerators. Patrick Karl, Jonas Schupp, Georg Sigl |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2024 | ScanCamouflage: Obfuscating Scan Chains with Camouflaged Sequential and Logic GatesabstractScan chain is a commonly used technique in testing integrated circuits as it provides observability and controllability of the internal states of circuits. However, its presence can make circuits vulnerable to attacks and potentially result in confidential internal data leakage. In this paper, we propose a novel technique for obfuscating scan chains using camouflaged flip-flops, which are designed with the same layout as the original flip-flops but have the actual functionality of a buffer. Furthermore, we employ camouflaged logic gates interconnected in special configurations to increase the difficulty of SAT attack. Experimental results demonstrate that circuits with only a small number of flip-flops can already be protected by the proposed technique while incurring only a minimal area overhead. Tarik Ibrahimpasic, Grace Li Zhang, Michaela Brunner, Georg Sigl, Bing Li 0005, Ulf Schlichtmann |
DATE | 4 |
| 2024 | EMDRIVE Architecture: Embedded Distributed Computing and Diagnostics from Sensor to EdgeabstractFuture automotive architectures are expected to transition from a network-centric to a domain-centered architecture featuring central compute units. Powerful domain controllers or smart sensors alleviate the load on these central units and communication systems. These controllers execute tasks with varying criticalities on heterogeneous multicore processors, and are ideally capable of dynamically balancing the computing load between the central unit and sensors. Here, Artificial Intelligence (AI) capabilities playa crucial role, as it is in high demand for such an automotive architecture. However, AI still requires specialized accelerators to improve their computation performance. Task-oriented distributed computing with criticalities up to ASIL-D necessitates the development and utilization of specialized methodologies, such as safety, through the isolation and abstraction of low-level hardware concepts. Meanwhile, online monitoring and diagnostics become vital features to detect errors during operation. The EMDRIVE architecture includes methods, components, and strategies to enhance the performance, safety, and security of such distributed computing platforms. The nationally funded EMDRIVE project connects its twelve partners from academia and industry and is currently in its intermediate stage. Patrick Schmidt 0003, Iuliia Topko, Matthias Stammler, Tanja Harbaum, Jürgen Becker 0001, Rico Berner, Omar Ahmed, Jakub Jagielski, Thomas Seidler, Markus Abel, Marius Kreutzer, Maximilian Kirschner, Victor Pazmino Betancourt, Robin Sehm, Lukas Groth, Andrija Neskovic, Rolf Meyer, Saleh Mulhem, Mladen Berekovic, Matthias Probst, Manuel Brosch, Georg Sigl, Thomas Wild, Matthias Ernst, Andreas Herkersdorf, Florian Aigner, Stefan Hommes, Sebastian Lauer, Maximilian Seidler, Thomas Raste, Gasper Skvarc Bozic, Ibai Irigoyen Ceberio, Albrecht Mayer |
DATE | 22 |
| 2024 | Hardware Honeypot: Setting Sequential Reverse Engineering on a Wrong TrackabstractReverse engineering (RE) of finite state machines (FSMs) is a serious threat when protecting designs against RE attacks. While most recent protection techniques rely on the security of a secret key, this work presents a new approach: hardware FSM honeypots. These honeypots lead the RE tools to a wrong but, for the tools, very attractive FSM, while making the original FSM less attractive. The results show that state-of-the-art RE methods favor the highly attractive honeypot as FSM candidate or do no longer detect the correct, original FSM. Michaela Brunner, Hye-Hyun Lee, Alexander Hepp, Johanna Baehr 0001, Georg Sigl |
DDECS | 5 |
| 2024 | Fault-Simulation-Based Flip-Flop Classification for Reverse EngineeringabstractThis work outlines a crucial step in gate-level netlist reverse engineering: classifying control and data flip-flops (FFs) to discern control logic and data paths. Existing methods rely mainly on structural characteristics, which can have disavantages. Our work introduces a novel approach that classifies FFs based on observed characteristics after fault insertion and propagation. We develop three new classification methods for block cipher implementations, emphasizing their significance in system security. However, we also explore the approach's applicability to other design types. We apply the approach on AES implementations using an automatic fault simulation framework, which shows perfect results for most classifications. Michael Mildner, Michaela Brunner, Michael Gruber, Johanna Baehr 0001, Georg Sigl |
DDECS | 5 |
| 2024 | Switch-Glitch : Location of Fault Injection Sweet Spots by Electro-Magnetic EmanationabstractWhile several approaches exist to locate spatial coordinates on a chip that are susceptible to Side-Channel Analysis (SCA), e.g., Test Vector Leakage Assessment (TVLA), so far, an equivalent for localized Electro-Magnetic (EM) based Fault Injection Analysis (FIA) is missing. This work analyzes the spatial relationship between EM emanation and Electro-Magnetic Fault Injection (EMFI) susceptibility and effect. Our experiments are based on a two-step approach where we first capture a heatmap based on a single trace per location, which is then used to find promising spatial EMFI positions. We chose an STM32F303 microcontroller, which shows that the injection locations that result in data modification are almost entirely contained within areas of high Signal-to-Noise Ratio (SNR). An EMFI based attack can be accelerated up significantly using this relationship. Matthias Probst, Michael Gruber, Manuel Brosch, Tim Music, Georg Sigl |
FDTC | 5 |
| 2024 | Post-Quantum Signatures on RISC-V with Hardware AccelerationabstractCRYSTALS-Dilithium and Falcon are digital signature algorithms based on cryptographic lattices, which are considered secure even if large-scale quantum computers will be able to break conventional public-key cryptography. Both schemes have been selected for standardization in the NIST Post-Quantum competition. In this work, we present a RISC-V HW/SW codesign that aims to combine the advantages of software and hardware implementations, i.e., flexibility and performance. It shows the use of flexible hardware accelerators, which have been previously used for Public-Key Encryption (PKE) and Key-Encapsulation Mechanism (KEM), for Post-Quantum signatures. It is optimized for Dilithium as a generic signature scheme but also accelerates applications that require fast verification of Falcon’s compact signatures. We provide a comparison with previous works showing that for Dilithium and Falcon, cycle counts are significantly reduced, such that our design is faster than previous software implementations or other HW/SW codesigns. In addition to that, we present a compact Globalfoundries 22nm ASIC design that runs at 800 MHz. By using hardware acceleration, energy consumption for Dilithium is reduced by up to 92.2%, and up to 67.5% for Falcon’s signature verification. Patrick Karl, Jonas Schupp, Tim Fritzmann, Georg Sigl |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2024 | A Masked Hardware Accelerator for Feed-Forward Neural Networks With Fixed-Point ArithmeticabstractNeural network (NN) execution on resource-constrained edge devices is increasing. Commonly, hardware accelerators are introduced in small devices to support the execution of NNs. However, an attacker can often gain physical access to edge devices. Therefore, side-channel attacks are a potential threat to obtain valuable information about the NN. In order to keep the network secret and protect it from extraction, countermeasures are required. In this article, we propose a masked hardware accelerator for feed-forward NNs that utilizes fixed-point arithmetic and is protected against side-channel analysis (SCA). We use an existing arithmetic masking scheme and improve it to prevent incorrect results. Moreover, we transfer the scheme to the hardware layer by utilizing the glitch-extended probing model and demonstrate the security of the individual modules. To exhibit the effectiveness of the masked design, we implement it on an FPGA and measure the power consumption. The results show that with two million measurements, no secret information is leaked by means of a$t$-test. In addition, we compare our accelerator with the masked software implementation and other hardware designs. The comparison indicates that our accelerator is up to 38 times faster than software and improves the throughput by a factor of about 4.1 compared to other masked hardware accelerators. Manuel Brosch, Matthias Probst, Matthias Glaser, Georg Sigl |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2023 | FPGANeedle: Precise Remote Fault Attacks from FPGA to CPUabstractFPGA as general-purpose accelerators can greatly improve system efficiency and performance in cloud and edge devices alike. However, they have recently become the focus of remote attacks, such as fault and side-channel attacks from one to another user of a part of the FPGA fabric. In this work, we consider system-on-chip platforms, where an FPGA and an embedded processor core are located on the same die. We show that the embedded processor core is vulnerable to voltage drops generated by the FPGA logic. Our experiments demonstrate the possibility of compromising the data transfer from external DDR memory to the processor cache hierarchy. Furthermore, we were also able to fault and skip instructions executed on an ARM Cortex-A9 core. The FPGA based fault injection is shown precise enough to recover the secret key of an AES T-tables implementation found in the mbedTLS library. Mathieu Gross, Jonas Krautter, Dennis Gnad, Michael Gruber, Georg Sigl, Mehdi Baradaran Tahoori |
ASP-DAC | 5 |
| 2023 | Counterfeit Detection by Semiconductor Process Technology InspectionabstractWith world-wide distributed semiconductor supply chains and a scarcity of microelectronic products, counterfeit devices are gaining momentum. Sourcing products from trusted providers are the theoretical remedy, yet practice shows the reality. Forged electronics are entering the supply chain at a high rate and pose a threat to safety, reliability, and security. Academia and industry have established various pre- or post-production measures to effectively address this issue partially. Yet, several inadequately covered aspects of the field require improvements. First, this work introduces a rating scheme to enable the effective comparison between anti-counterfeiting methods. Recently published methods are compared using this scheme. Second, a novel, generic, generally applicable prover-verifier attestation framework for post-production anti-counterfeiting methods is established. Third, the work implements a new anti-counterfeit method. By introducing technological individual features, the method incorporates technology intrinsic features of the front-end semiconductor manufacturing process as technology distinctive characteristic. Profile parameters are extracted through pattern recognition and statistical methods which are compared to the expected technologies through distance metrics, allowing an assertion of device authenticity. Finally, the versatility of the method is experimentally validated through real samples. Overall, an accuracy of 100% is reported for seven samples which are checked for authenticity. Matthias Ludwig 0005, Ann-Christin Bette, Bernhard Lippmann, Georg Sigl |
ETS | 4 |
| 2022 | Counteract Side-Channel Analysis of Neural Networks by ShufflingabstractMachine learning is becoming an essential part in almost every electronic device. Implementations of neural networks are mostly targeted towards computational performance or memory footprint. Nevertheless, security is also an important part in order to keep the network secret and protect the intellectual property associated to the network. Especially, since neural network implementations are demonstrated to be vulnerable to side-channel analysis, powerful and computational cheap countermeasures are in demand. In this work, we apply a shuffling countermeasure to a microcontroller implementation of a neural network to prevent side-channel analysis. The countermeasure is effective while the computational overhead is low. We investigate the extensions necessary for our countermeasure, and how shuffling increases the effort for an attack in theory. In addition, we demonstrate the increase in effort for an attacker through experiments on real side-channel measurements. Based on the mechanism of shuffling and our experimental results, we conclude that an attack on a commonly used neural network with shuffling is no longer feasible in a reasonable amount of time. Manuel Brosch, Matthias Probst, Georg Sigl |
DATE | 3 |
| 2022 | Golden Model-Free Hardware Trojan Detection by Classification of Netlist Module GraphsabstractIn a world where increasingly complex integrated circuits are manufactured in supply chains across the globe, hardware Trojans are an omnipresent threat. State-of-the-art methods for Trojan detection often require a golden model of the device under test. Other methods that operate on the netlist without a golden model cannot handle complex designs and operate on Trojan-specific sets of netlist graph features. In this work, we propose a novel machine-learning-based method for hardware Trojan detection. Our method first uses a library of known malicious and benign modules in hierarchical designs to train an eXtreme Gradient Boosted Tree Classifier (XGBClassifier). For training, we generate netlist graphs of each hierarchical module and calculate feature vectors comprising structural characteristics of these graphs. After the training phase, we can analyze the synthesized hierarchical modules of an unknown design under test. The method calculates a feature vector for each module. With this feature vector, each module can be classified into either benign or malicious by the previously trained XGBClassifier. After classifying all modules, we derive a classification for all standard cells in the design under test. This technique allows the identification of hardware Trojan cells in a design and highlights regions of interest to direct further reverse engineering efforts. Experiments show that this approach performs with >97 % Sensitivity and Specificity across available and newly generated hardware Trojan benchmarks and can be applied to more complex designs than previous netlist-based methods while maintaining similar computational complexity. Alexander Hepp, Johanna Baehr 0001, Georg Sigl |
DATE | 3 |
| 2022 | Hardware Accelerated FrodoKEM on RISC-VabstractFrodoKEM is an alternative finalist in the currently running standardization process for post-quantum secure cryptography, initiated by the National Institute of Standards and Technology (NIST). It is based on the well studied plain Learning With Errors (LWE) problem, leading to a high confidence in security. Its conservative design approach, however, makes it less performant when compared to other lattice-based candidates. In this work, we assemble a RISC-V based HW/SW codesign of FrodoKEM to speed up its computation. Our design supports all three parameter sets of the NIST submission. Compared to plain SW implementations on RISC-V, our accelerated design achieves speedup factors of up to 8.13. Patrick Karl, Tim Fritzmann, Georg Sigl |
DDECS | 3 |
| 2022 | Open Source Hardware Design and Hardware Reverse Engineering: A Security AnalysisabstractMajor industry-led initiatives such as RISC-V and OpenTitan strive for verified, customizable and standardized products, based on a combination of Open Source Hardware (OSHW) and custom intellectual property (IP), to be used in safety and security-critical systems. The protection of these products against reverse-engineering-based threats such as IP Theft and IP Piracy, Hardware Trojan (HT) insertion, and physical attacks is of equal importance as for closed source designs. OSHW generates novel threats to the security of a design and the protection of IP. This paper discusses to what extent OSHW reduces the difficulty of attacking a product. An analysis of the reverse engineering process shows that OSHW lowers the effort to retrieve broad knowledge about a product and decreases the success of related countermeasures. In a case study on a RISC-V core and an AES design, the red team uses knowledge about OSHW to circumvent logic locking protection and successfully identify the functionality and the used locking key. The paper concludes with an outlook on the secure protection of OSHW. Johanna Baehr 0001, Alexander Hepp, Michaela Brunner, Maja Malenko, Georg Sigl |
DSD | 5 |
| 2022 | A Pragmatic Methodology for Blind Hardware Trojan Insertion in Finalized LayoutsabstractA potential vulnerability for integrated circuits (ICs) is the insertion of hardware trojans (HTs) during manufacturing. Understanding the practicability of such an attack can lead to appropriate measures for mitigating it. In this paper, we demonstrate a pragmatic framework for analyzing HT susceptibility of finalized layouts. Our framework is representative of a fabrication-time attack, where the adversary is assumed to have access only to a layout representation of the circuit. The framework inserts trojans into tapeoutready layouts utilizing an Engineering Change Order (ECO) flow. The attacked security nodes are blindly searched utilizing reverse-engineering techniques. For our experimental investigation, we utilized three crypto-cores (AES-128, SHA-256, and RSA) and a microcontroller (RISC-V) as targets. We explored 96 combinations of triggers, payloads and targets for our framework. Our findings demonstrate that even in high-density designs, the covert insertion of sophisticated trojans is possible. All this while maintaining the original target logic, with minimal impact on power and performance. Furthermore, from our exploration, we conclude that it is too naive to only utilize placement resources as a metric for HT vulnerability. This work highlights that the HT insertion success is a complex function of the placement, routing resources, the position of the attacked nodes, and further design-specific characteristics. As a result, our framework goes beyond just an attack, we present the most advanced analysis tool to assess the vulnerability of HT insertion into finalized layouts. Alexander Hepp, Tiago D. Perez, Samuel Nascimento Pagliarini, Georg Sigl |
ICCAD | 4 |
| 2022 | A Power Side-Channel Attack on the Reed-Muller Reed-Solomon Version of the HQC Cryptosystem
Thomas Schamberger, Lukas Holzbaur, Julian Renner, Antonia Wachter-Zeh, Georg Sigl |
PQCrypto | 5 |
| 2022 | Toward a Human-Readable State Machine ExtractionabstractThe target of sequential reverse engineering is to extract the state machine of a design. Sequential reverse engineering of a gate-level netlist consists of the identification of so-called state flip-flops (sFFs), as well as the extraction of the state machine. The second step can be solved with an exact approach if the correct sFFs and the correct reset state are provided. For the first step, several more or less heuristic approaches exist. This work investigates sequential reverse engineering with the objective of a human-readable state machine extraction. A human-readable state machine reflects the original state machine and is not overloaded by additional design information. For this purpose, the work derives a systematic categorization of sFF sets, based on properties of single sFFs and their sets. These properties are determined by analyzing the degrees of freedom in describing state machines as the well-known Moore and Mealy machines. Based on the systematic categorization, this work presents an sFF set definition for a human-readable state machine, categorizes existing sFF identification strategies, and develops four post-processing methods. The results show that post-processing predominantly improves the outcome of several existing sFF identification algorithms. Michaela Brunner, Alexander Hepp, Johanna Baehr 0001, Georg Sigl |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2022 | Enhancing the Security of FPGA-SoCs via the Usage of ARM TrustZone and a Hybrid-TPMabstractIsolated execution is a concept commonly used for increasing the security of a computer system. In the embedded world, ARM TrustZone technology enables this goal and is currently used on mobile devices for applications such as secure payment or biometric authentication. In this work, we investigate the security benefits achievable through the usage of ARM TrustZone on FPGA-SoCs. We first adapt Microsoft’s implementation of a firmware Trusted Platform Module (fTPM) running inside ARM TrustZone for the Zynq UltraScale+ platform. This adaptation consists in integrating hardware accelerators available on the device to fTPM’s implementation and to enhance fTPM with an entropy source derived from on-chip SRAM start-up patterns. With our approach, we transform a software implementation of a TPM into a hybrid hardware/software design that could address some of the security drawbacks of the original implementation while keeping its flexibility. To demonstrate the security gains obtained via the usage of ARM TrustZone and our hybrid-TPM on FPGA-SoCs, we propose a framework that combines them for enabling a secure remote bitstream loading. The approach consists in preventing the insecure usages of a bitstream reconfiguration interface that are made possible by the manufacturer and to integrate the interface inside a Trusted Execution Environment. Mathieu Gross, Konrad Hohentanner, Stefan Wiehler, Georg Sigl |
ACM Trans. Reconfigurable Technol. Syst. | 4 |
| 2022 | ROPAD: Enhancing the Digital Ring Oscillator Probing Attempt Detector for Protecting Irregular Data BusesabstractMicroprobing is applied to intercept data from on-chip signals, such as data passing through a data bus. Hence, it allows for extracting a full dump of this data, e.g., the firmware of a microcontroller, cryptographic key material, or any other type of passing data on the physical metal lines and/or the physical cells of the data bus connected to the metal lines. It is categorized as an invasive and physical attack vector against which software measures are insufficient for protection. As a countermeasure detecting microprobing attacks and enabling appropriate protection mechanisms, we propose a new probing detector for an industrial sub-40-nm advanced process node. It is based on ring oscillators (ROs), which are formed from the data bus lines. The oscillation frequency, caused by the capacity of bus lines, is measured and compared to detect any attached microprobes. The concept is optimized for detection of placed microprobes on both regular and irregular data buses or on any other pair of lines. For this purpose, a statistics-driven decision is made to distinguish probed from not probed lines. To improve the concept for high capacitance irregular lines, a hybrid design and test time calibration is proposed and analyzed, which shows the applicability of the concept under irregular bus lines, local variations, and jittery conditions. The results show that the approach results in low false positive (FP) and false negative (FN) rate at lower overhead comparing with alternative approaches. Seyed Hamidreza Moghadas, Michael Pehl, Georg Sigl |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2021 | Tapeout of a RISC-V crypto chip with hardware trojans: a case-study on trojan design and pre-silicon detectabilityabstractThis paper presents design and integration of four hardware Trojans (HTs) into a post-quantum-crypto-enhanced RISC-V micro-controller, which was taped-out in September 2020. We cover multiple HTs ranging from a simple denial-of-service HT to a side-channel HT transmitting arbitrary information to external observers. For each HT, we give estimations of the detectability by the microcontroller-integration team using design tools or by simulation. We conclude that some HTs are easily detected by design-tool warnings. Other powerful HTs, modifying software control flow, cause little disturbance, but require covert executable code modifications. With this work, we strengthen awareness for HT risks and present a realistic testing device for HT detection tools. Alexander Hepp, Georg Sigl |
CF | 2 |
| 2021 | The Cost of OSCORE and EDHOC for Constrained DevicesabstractMany modern IoT applications rely on the Constrained Application Protocol (CoAP). Recently, the Internet Engineering Task Force (IETF) proposed two novel protocols for securing it. These are: 1) Object Security for Constrained RESTful Environments (OSCORE) providing authenticated encryption for the CoAP’s payload data and 2) Ephemeral Diffie-Hellman Over COSE (EDHOC) providing the symmetric session keys required for OSCORE. In this paper, we present the design of four firmware libraries for these protocols which are especially targeted for constrained microcontrollers and their detailed evaluation. More precisely, we present the design of μOSCORE and μEDHOC libraries for regular microcontrollers and μOSCORE-TEE and μEDHOC-TEE libraries for microcontrollers with a Trusted Execution Environment (TEE), such as microcontrollers featuring ARM TrustZone-M. Our firmware design for the latter class of devices concerns the fact that attackers may exploit common software vulnerabilities, e.g., buffer overflows in the protocol logic, OS or application to compromise the protocol security. We present an evaluation of our implementations in terms of RAM/FLASH requirements and execution speed on a broad range of microcontrollers. Our implementations are available as open-source software. Stefan Hristozov, Manuel Huber 0001, Jaro Fietz, Marco Liess, Georg Sigl |
CODASPY | 6 |
| 2021 | Algebraic Fault Analysis of Subterranean 2.0abstractAlgebraic Fault Analysis (AFA) is based on the principles of algebraic cryptanalysis in conjunction with fault analysis. One of the main benefits of AFA is the ability to use off the shelf solving tools like SAT solvers to conduct fault analysis in an automated fashion. In this work we show how the principles of AFA can be applied to the authenticated encryption scheme Subterranean 2.0, a second round candidate of the ongoing NIST-LWC competition. In order to find the optimal parameters for a fault injection we investigated the fault model’s influence on the solving time. The optimal fault parameters turned out as a single bitflip fault in conjunction with a known but randomly chosen fault location, where the fault is applied just one cycle before the tag generation. We verify the efficiency of our attack by means of simulation. Conducting our proposed attack with optimal fault parameters requires only five fault injections to recover the secret key of Subterranean 2.0 in less than four seconds. Michael Gruber, Patrick Karl, Georg Sigl |
FDTC | 3 |
| 2021 | Beyond Cache Attacks: Exploiting the Bus-based Communication Structure for Powerful On-Chip Microarchitectural AttacksabstractSystem-on-Chips (SoCs) are a key enabling technology for the Internet-of-Things (IoT), a hyper-connected world where on- and inter-chip communication is ubiquitous. SoCs usually integrate cryptographic hardware cores for confidentiality and authentication services. However, these components are prone to implementation attacks. During the operation of a cryptographic core, the secret key may passively be inferred through cache observations. Access-driven attacks exploiting these observations are therefore a vital threat to SoCs operating in IoT environments. Previous works have shown the feasibility of these attacks in the SoC context. Yet, the SoC communication structure can be used to further improve access-based cache attacks. The communication attacks are not as well-understood as other micro-architectural attacks. It is important to raise the awareness of SoC designers of such a threat. To this end, we present four contributions. First, we demonstrate an improved Prime+Probe attack on four different AES-128 implementations (original transformation tables, T 0 -Only, T 2KB , and S-Box). As a novelty, this attack exploits the collisions of the bus-based SoC communication to further increase its efficiency. Second, we explore the impact of preloading on the efficiency of our communication-optimized attack. Third, we integrate three countermeasures ( shuffling , mini-tables , and Time-Division Multiple Access (TDMA) bus arbitration ) and evaluate their impact on the attack. Although shuffling and mini-tables countermeasures were proposed in previous work, their application as countermeasures against the bus-based attack was not studied before. In addition, TDMA as a countermeasure for bus-based attacks is an original contribution of this work. Fourth, we further discuss the implications of our work in the SoC design and its perspective with the new cryptographic primitives proposed in the ongoing National Institute of Standard and Technology Lightweight Cryptography competition. The results show that our improved communication-optimized attack is efficient, speeding up full key recovery by up to 400 times when compared to the traditional Prime+Probe technique. Moreover, the protection techniques are feasible and effectively mitigate the proposed improved attack. Martha Johanna Sepúlveda, Mathieu Gross, Andreas Zankl, Georg Sigl |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2021 | DOMREP-An Orthogonal Countermeasure for Arbitrary Order Side-Channel and Fault Attack ProtectionabstractProtection against physical attacks is a major requirement for cryptographic implementations on devices which can be accessed by attackers. Side-channel and fault injection attacks are the most common types of physical attacks. In this work we present a novel generic solution for simultaneous protection against side-channel and fault attacks with arbitrary order. We combine domain oriented masking and repetition codes in an orthogonal way and call this approach DOMREP. The resistance against side-channel attacks and fault attacks can be scaled independently of each other, for the protection against higher-order side-channel analysis and the injection of multiple faults including SIFA. We develop the generic concept of orthogonal protection, and implement the DOMREP concept on GIMLI, a round two NIST LWC competition candidate, on a Xilinx Artix-7 FPGA. Our implementation of GIMLI is verified to be resistant against univariate first-order side-channel attacks by TVLA. The resistance against SIFA is verified by means of fault emulation of single as well as multiple bit faults. Our implementation of GIMLI achieves the expected security level according to these measurements. We also provide numbers for the area overhead for our protected implementation of GIMLI. Michael Gruber, Matthias Probst, Patrick Karl, Thomas Schamberger, Lars Tebelmann, Michael Tempelmeier, Georg Sigl |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2021 | Finding the Needle in the Haystack: Metrics for Best Trace Selection in Unsupervised Side-Channel Attacks on Blinded RSAabstractFor asymmetric ciphers, such as RSA and ECC, side-channel attacks on the underlying exponentiation are mitigated by countermeasures like constant-time implementation and blinding. This restricts an attacker to a single side-channel trace for an attack as a different representation of the private key is used for each exponentiation. In this work, we propose an unsupervised machine learning framework for side-channel attacks on asymmetric cryptography that analyzes leakage in multiple side-channel traces, identifying the best trace for key retrieval. We apply Principal Component Analysis (PCA) preprocessing followed by a classification step that assigns segments of traces to elementary operations of the Square and Multiply exponentiation of RSA. In order to estimate the attack complexity for each trace in terms of key enumeration effort, we introduce two new metrics: The Entropy-based Cost Function (EBCF) is used to select a trace for the attack as well as bits which have to be brute-forced if not all bits can be determined correctly from this single trace. To reduce brute-force complexity further, we introduce Illegal Sequence Detection (ISD) to remove brute-force candidates which do not fit to the Square-and-Multiply scheme. We first provide a proof of concept for 320-bit key length traces and, moving towards a more realistic scenario, retrieve the key from a 1024-bit RSA implementation protected by message and exponent blinding. We are able to select the trace with the least remaining brute-force complexity from 1000 power measurements of the signature generation with randomized inputs and blinding values on a 32-bit ARM Cortex-M4 microcontroller. Alexander Kulow, Thomas Schamberger, Lars Tebelmann, Georg Sigl |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | Timing Resilience for Efficient and Secure CircuitsabstractIn this paper, we will cover several techniques that can enhance the resilience of timing of digital circuits. Using post-silicon tuning components, the clock arrival times at flip-flops can be modified after manufacturing to balance delays between flip-flops. The actual delay properties of flip-flops will be examined to exploit the natural flexibility of such components. Wave-pipelining paths spanning several flip-flop stages can be integrated into a synchronous design to improve the circuit performance and to reduce area. In addition, with this technique, it cannot be taken for granted anymore that all the combinational paths in a circuit work with respect to one clock period. Therefore, a netlist alone does not represent all the design information. This feature enables the potential to embed wave-pipelining paths into a circuit to increase the complexity of reverse engineering. In order to replicate a design, attackers therefore have to identify the locations of the wave-pipelining paths, in addition to the netlist extracted from reverse engineering. Therefore, the security of the circuit against counterfeiting can be improved. Grace Li Zhang, Michaela Brunner, Bing Li 0005, Georg Sigl, Ulf Schlichtmann |
ASP-DAC | 4 |
| 2020 | A Power Side-Channel Attack on the CCA2-Secure HQC KEM
Thomas Schamberger, Julian Renner, Georg Sigl, Antonia Wachter-Zeh |
CARDIS | 3 |
| 2020 | Extending the RISC-V Instruction Set for Hardware Acceleration of the Post-Quantum Scheme LACabstractThe increasing effort in the development of quantum computers represents a high risk for communication systems due to their capability of breaking currently used public-key cryptography. LAC is a lattice-based public-key encryption scheme resistant to traditional and quantum attacks. It is characterized by small key sizes and low arithmetic complexity. Recent publications have shown practical post-quantum solutions through co-design techniques. However, for LAC only software implementations were explored. In this work, we propose an efficient, flexible and time-protected HW/SW co-design architecture for LAC. We present two contributions. First, we develop and integrate hardware accelerators for three LAC performance bottlenecks: the generation of polynomials, polynomial multiplication and error correction. The accelerators were designed to support all post-quantum security levels from 128 to 256-bits. Second, we develop tailored instruction set extensions for LAC on RISC-V and integrate the HW accelerators directly into a RISC-V core. The results show that our architecture for LAC with constant-time error correction improves the performance by a factor of 7.66 for LAC-128, 14.42 for LAC-192, and 13.36 for LAC-256, when compared to the unprotected reference implementation running on RISC-V. The increased performance comes at a cost of an increased resource consumption (32,617 LUTs, 11,019 registers, and two DSP slices). Tim Fritzmann, Georg Sigl, Martha Johanna Sepúlveda |
DATE | 2 |
| 2020 | Efficient Hardware/Software Co-Design for Post-Quantum Crypto Algorithm SIKE on ARM and RISC-V based MicrocontrollersabstractPost-quantum cryptography has emerged as a very attractive research topic due to the recent advancements in the development of quantum computers. Among the different available post-quantum public-key algorithms, Supersingular Isogeny Key-Encapsulation (SIKE) has posed a unique design challenge due to its resource intensive arithmetic but is characterized by small key sizes. Existing implementations of SIKE either focus on dedicated accelerators on FPGA platforms or on assembly optimized software implementations on ARM. A full FPGA implementation, though offering low latency and high performance, suffers from the disadvantage of having a large area footprint and a low flexibility. On the other hand, a pure software implementation has lower performance compared to FPGA implementations. In this paper, we propose hardware/software co-design methodologies for SIKE and integrate a redundant number based finite field accelerator into two microcontroller platforms based on ARM and RISC-V. The result shows that our implementation on ARM Cortex-A9 enhanced with a field accelerator offers significant speedup in terms of clock cycles when compared to standalone software implementations on ARM32 and ARM64. Moreover, to show how the communication overhead between processor and accelerator can be mitigated, we integrated the finite field accelerator directly into the core of a RISC-V processor. To the best of our knowledge, this is the first design that applies hardware/software co-design methodologies to implement SIKE on ARM and RISC-V platforms. Our proposed design requires 65500 K clock cycles to execute SIKEp434 on an ARM Cortex-A9 processor. On RISC-V, our proposed design requires only 36900 K clock cycles. Debapriya Basu Roy, Tim Fritzmann, Georg Sigl |
ICCAD | 3 |
| 2020 | Secure and user-friendly over-the-air firmware distribution in a portable faraday cageabstractSetting up a large-scale wireless sensor networks (WSNs) is challenging, as firmware must be distributed and trust between sensor nodes and a backend needs to be established. To perform this task efficiently, we propose an approach named Box, which utilizes an intelligent Faraday Cage (FC). The FC acquires firmware images and secret keys from a backend, patches the firmware with the keys and deploys those customized images over-the-air (OTA) to sensor nodes placed in the FC. Electromagnetic (EM) shielding protects this exchange against passive attackers. We place few demands on the sensor node, not requiring additional hardware components or firmware customized by the manufacturer. We describe this novel workflow, implement the Box and a backend system and demonstrate the feasibility of our approach by batch-deploying firmware to multiple commercial off-the-shelf (COTS) sensor nodes. We conduct a user-study with 31 participants with diverse backgrounds and find, that our approach is both faster and more user-friendly than firmware distribution over a wired connection. Martin Striegel, Johann Heyszl, Florian Jakobsmeier, Yacov Matveev, Georg Sigl |
WISEC | 5 |
| 2020 | Machine learning and structural characteristics for reverse engineering
Johanna Baehr 0001, Alessandro Bernardini, Georg Sigl, Ulf Schlichtmann |
Integr. | 3 |
| 2020 | TimingCamouflage+: Netlist Security Enhancement With Unconventional TimingabstractWith recent advances in reverse engineering, attackers can reconstruct a netlist to counterfeit chips by opening the die and scanning all layers of authentic chips. This relatively easy counterfeiting is made possible by the use of the standard simple clocking scheme, where all combinational blocks function within one clock period, so that a netlist of combinational logic gates and flip-flops is sufficient to duplicate a design. In this article, we propose to invalidate the assumption that a netlist completely represents the function of a circuit with unconventional timing. With the introduced wave-pipelining (WP) paths, attackers have to capture gate and interconnect delays during reverse engineering, or to test a huge number of combinational paths to identify the WP paths. To hinder the test-based attack, we construct false paths with WP to increase the counterfeiting challenge. The experimental results confirm that WP true paths and false paths can be constructed in benchmark circuits successfully with only a negligible cost, thus thwarting the potential attack techniques. Grace Li Zhang, Bing Li 0005, Meng Li 0004, Bei Yu 0001, David Z. Pan, Michaela Brunner, Georg Sigl, Ulf Schlichtmann |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2019 | Machine learning and structural characteristics for reverse engineeringabstractIn the past years, much of the research into hardware reverse engineering has focused on the abstraction of gate level netlists to a human readable form. However, none of the proposed methods consider a realistic reverse engineering scenario, where the netlist is physically extracted from a chip. This paper analyzes how errors caused by this extraction and the later partitioning of the netlist affect the ability to identify the functionality. Current formal verification based methods, which compare against a golden model, are incapable of dealing with such erroneous netlists. Two new methods are proposed, which focus on the idea that structural similarity implies functional similarity. The first approach uses fuzzy structural similarity matching to compare the structural characteristics of an unknown design against designs in a golden model library using machine learning. The second approach proposes a method for inexact graph matching using fuzzy graph isomorphisms, based on the functionalities of gates used within the design. For realistic error percentages, both approaches are able to match more than 90% of designs correctly. This is an important first step for hardware reverse engineering methods beyond formal verification based equivalence matching. Johanna Baehr 0001, Alessandro Bernardini, Georg Sigl, Ulf Schlichtmann |
ASP-DAC | 3 |
| 2019 | EyeSec: A Retrofittable Augmented Reality Tool for Troubleshooting Wireless Sensor Networks in the Field
Martin Striegel, Carsten Rolfes, Johann Heyszl, Fabian Helfert, Maximilian Hornung, Georg Sigl |
EWSN | 6 |
| 2019 | A Calibratable Detector for Invasive AttacksabstractMicroprobing is commonly used by adversaries to extract firmware or cryptographic keys from microcontrollers. We introduce the calibratable lightweight invasive attack detector (CaLIAD) to detect microprobing attacks. The CaLIAD measures timing imbalances between lines that are caused by the capacitive load of a probe. Compared to protection mechanisms from industry, it does not require an additional protection layer such as meshes do; in contrast to bus encryption, it does not introduce delay cycles. Compared to state-of-the-art low area probing detectors, it can be calibrated and, thus, allows compensating manufacturing variations as well as small layout imbalances. This capability allows us to significantly reduce the detection margin compared to the prior art while maintaining the low rate of false positives. We can finally show that capacitive loads of 23 fF or less can be detected, depending on how the CaLIAD is used. This includes all state-of-the-art commercial microprobes we are aware of. Michael Weiner 0004, Wolfgang Wieser, Emili Lupon, Georg Sigl, Salvador Manich |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2018 | High-Resolution EM Attacks Against Leakage-Resilient PRFs Explained - And an Improved Construction
Florian Unterstein, Johann Heyszl, Fabrizio De Santis, Robert Specht, Georg Sigl |
CT-RSA | 5 |
| 2018 | A measurement system for capacitive PUF-based security enclosuresabstractBattery-backed security enclosures that are permanently monitored for penetration and tampering are common solutions for providing physical integrity to multi-chip embedded systems. This paper presents a well-tailored measurement system for a batteryless PUF-based capacitive enclosure. The key is derived from the PUF and encrypts the underlying system. We present a system concept for combined enclosure integrity verification and PUF evaluation. The system performs differential capacitive measurements inside the enclosure by applying stimulus signals with a 180° phase shift that isolate the local variation in the femtofarad range. The analog circuitry and corresponding digital signal processing chain perform precise PUF digitization, using a microcontroller-based digital lock-in amplifier. The system's measurement range is approximately ±73 fF, the conversion time per PUF node is less than 0.6 ms, and the raw data shows a measurement noise of 0.3 fF. This is the base for a high-entropy key generation while enabling a short system startup time. The system is scalable to the enclosure size and has been experimentally verified to extract information from 128 PUF nodes, using a system prototype. The results show that our concept forms a cornerstone of a novel batteryless PUF-based security enclosure. Johannes Obermaier, Vincent Immler, Matthias Hiller, Georg Sigl |
DAC | 4 |
| 2018 | Towards the formal verification of security properties of a Network-on-Chip routerabstractVulnerabilities and design flaws in Network-on-Chip (NoC) routers can be exploited in order to spy, modify and constraint the sensitive communication inside the Multi-Processors Systems-on-Chip (MPSoCs). Although previous works address the NoC threat, finding secure and efficient solutions to verify the security is still a challenge. In this work, we propose for the first time a method to formally verify the correctness and the security properties of a NoC router in order to provide the proper communication functionality and to avoid NoC attacks. We present a generalized verification flow that proves a wide set of implementation-independent security-related properties to hold. We employ unbounded model checking techniques to account for the highly-sequential behaviour of the NoC systems. The evaluation results demonstrate the feasibility of our approach by presenting verification results of six different NoC routing architectures demonstrating the vulnerabilities of each design. Martha Johanna Sepúlveda, Damian Aboul-Hassan, Georg Sigl, Bernd Becker 0001, Matthias Sauer 0002 |
ETS | 3 |
| 2018 | Locked out by Latch-up? An Empirical Study on Laser Fault Injection into Arm Cortex-M ProcessorsabstractLaser-based fault injection (LFI) is considered as one of the most powerful tools for active attacks against integrated circuits. However, only few empirical results are published for LFI into modern low-power microcontrollers with current process technologies. To fill this gap, we investigate LFI in four Cortex-M microcontrollers from different manufacturers: ST Microelectronics, NXP and Infineon. We note that those controllers differ from the ones used in high-security smartcard devices but argue that they are possibly built in similar process technologies making our results relevant for security evaluations. We were able to successfully inject precise faults into either the SRAM or the register file in all tested devices. We report our settings and fault maps in order to facilitate further fault attack investigations on these microcontrollers. As another contribution, we would like to emphasize the significant difficulties we encountered in some measurements due to the occurrence of latch-up effects. In many cases, the latch-up behavior of the integrated circuit prevented successful fault injections. This observation is largely underrepresented in scientific publications, which leads to an overestimation of the effectiveness of laser-based fault injection attacks under realistic circumstances. Bodo Selmke, Kilian Zinnecker, Philipp Koppermann, Katja Miller, Johann Heyszl, Georg Sigl |
FDTC | 6 |
| 2018 | DATA - Differential Address Trace Analysis: Finding Address-based Side-Channels in Binaries
Samuel Weiser, Andreas Zankl, Raphael Spreitzer, Katja Miller, Stefan Mangard, Georg Sigl |
USENIX Security Symposium | 6 |
| 2018 | The Low Area Probing Detector as a Countermeasure Against Invasive AttacksabstractMicroprobing allows intercepting data from on-chip wires as well as injecting faults into data or control lines. This makes it a commonly used attack technique against security-related semiconductors, such as smart card controllers. We present the low area probing detector (LAPD) as an efficient approach to detect microprobing. It compares delay differences between symmetric lines such as bus lines to detect timing asymmetries introduced by the capacitive load of a probe. Compared with state-of-the-art microprobing countermeasures from industry, such as shields or bus encryption, the area overhead is minimal and no delays are introduced; in contrast to probing detection schemes from academia, such as the probe attempt detector, no analog circuitry is needed. We show the Monte Carlo simulation results of mismatch variations as well as process, voltage, and temperature corners on a 65-nm technology and present a simple reliability optimization. Eventually, we show that the detection of state-of-the-art commercial microprobes is possible even under extreme conditions and the margin with respect to false positives is sufficient. Michael Weiner 0004, Salvador Manich, Rosa Rodríguez-Montañés, Georg Sigl |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2017 | How to Break Secure Boot on FPGA SoCs Through Malicious Hardware
Nisha Jacob, Johann Heyszl, Andreas Zankl, Carsten Rolfes, Georg Sigl |
CHES | 5 |
| 2017 | Towards post-quantum security for IoT endpoints with NTRUabstractThe NTRU cryptosystem is one of the main alternatives for practical implementations of post-quantum, public-key cryptography. In this work, we analyze the feasibility of employing the NTRU encryption scheme, NTRUEncrypt, in resource constrained devices such as those used for Internet-of-Things endpoints. We present an analysis of NTRUEncrypt's advantages over other cryptosystems for use in such devices. We describe four different NTRUEncrypt implementations on an ARM Cortex M0-based microcontroller, compare their results, and show that NTRUEncrypt is suitable for use in battery-operated devices. We present performance and memory footprint figures for different security parameters, as well as energy consumption in a resource constrained microcontroller to backup these claims. Furthermore, to the best of our knowledge, in this work we present the first time-independent implementation of NTRUEncrypt. Oscar M. Guillen, Thomas Pöppelmann, Jose Maria Bermudo Mera, Elena Fuentes Bongenaar, Georg Sigl, Martha Johanna Sepúlveda |
DATE | 5 |
| 2017 | Compromising FPGA SoCs using malicious hardware blocksabstractModern FPGA System-on-Chips (SoCs) combine high performance application processors with reconfigurable hardware. This allows to enhance complex software systems with reconfigurable hardware accelerators. Unfortunately, even when state-of-the-art software security mechanisms are implemented, this combination creates new security threats. Attacks on the software are now possible through the reconfigurable hardware as these cores share resources with the processor and may contain unwanted functionality. In this paper, we discuss software protection mechanisms offered in conventional SoCs and how they can be circumvented by malicious hardware blocks. As a concrete example, we show how the malicious functionality within an IP core accesses and replaces critical memory sections. We refer to this type of attacks as hardware-assisted attacks against running software systems. We carry-out a proof-of-concept on the Xilinx Zynq device which runs a Linux OS and a software application that verifies system updates. The malicious IP core replaces the public key used to verify system updates, thus, allowing an attacker to maliciously update the FPGA SoC. Additionally, we propose a countermeasure that can be applied against such threats in the form of a security wrapper for hardware modules. Nisha Jacob, Carsten Rolfes, Andreas Zankl, Johann Heyszl, Georg Sigl |
DATE | 5 |
| 2017 | ChaCha20-Poly1305 authenticated encryption for high-speed embedded IoT applicationsabstractThe ChaCha20 stream cipher and the Poly1305 authenticator are cryptographic algorithms designed by Daniel J. Bernstein with the aim of ensuring high-security margins, while achieving high performance on a broad range of software platforms. In response to the concerns raised about the reliability of the existing IETF/TLS cipher suite, its performance on software platforms, and the ease to realize secure implementations thereof, the IETF has recently published the RFC7905 and RFC7539 to promote the use and standardization of the ChaCha20 stream cipher and Poly1305 authenticator in the TLS protocol. Most interestingly, the RFC7539 specifies how to combine together the ChaCha20 stream cipher and Poly1305 authenticator to construct an Authenticated Encryption with Associated Data (AEAD) scheme to provide confidentiality, integrity, and authenticity of data. In this work, we present compact, constant-time, and fast implementations of the ChaCha20 stream cipher, Poly1305-ChaCha20 authenticator, and ChaCha20-Poly1305 AEAD scheme for ARM Cortex-M4 processors, aimed at evaluating the suitability of such algorithms for high-speed and lightweight IoT applications, e.g. to deploy fast and secure TLS connections between IoT nodes and remote cloud servers, when AES hardware acceleration capabilities are not available. Fabrizio De Santis, Andreas Schauer, Georg Sigl |
DATE | 3 |
| 2017 | Pushing the limits further: Sub-atomic AESabstractWhile throughput has for a long time been the main focus of optimisation, the need for compact and lightweight implementations of cryptographic primitives is on the rise again. Along with development of new tailored primitives and standards, the search for small implementations of the Advanced Encryption Standard has gained momentum again. This culminated in the recent publication of the AtomicAES architecture by Banik et al., who reported a design size of just over 2000 GE. In this work we design a new 8-bit serial architecture from scratch that enables us to push the area requirement for a fully featured AES primitive further down by more than 10% of the theoretical gap left by AtomicAES for optimisation. Moreover our architecture provides full functionality for encryption and decryption including keyschedule. Markus S. Wamser, Georg Sigl |
VLSI-SoC | 2 |
| 2016 | Squeezing Polynomial Masking in Tower Fields - A Higher-Order Masked AES S-Box
Fabrizio De Santis, Tobias Bauer, Georg Sigl |
CARDIS | 3 |
| 2016 | Automated Detection of Instruction Cache Leaks in Modular Exponentiation Software
Andreas Zankl, Johann Heyszl, Georg Sigl |
CARDIS | 3 |
| 2016 | Practical evaluation of code injection in encrypted firmware updates
Oscar M. Guillen, Dawin Schmidt, Georg Sigl |
DATE | 3 |
| 2016 | Fast and Reliable PUF Response Evaluation from Unsettled Bistable RingsabstractBistable ring (BR) based strong PUFs are promising candidates for lightweight authentication applications. It has been observed that a good '0'/'1'-balance of their responses correlates with longer settling times. This is problematic, since the state-of-the-art evaluation method requires the BR to be settled in order to generate a reliable PUF response. We show that settling times can easily extend beyond 100 milli seconds for 70 percent of the responses in the TBR PUF, which is a BR-based PUF with good '0'/'1'-balance characteristics. Hence, it is practically impossible to wait for all BRs to settle, which results in a reliability penalty. In order to solve this problem, we present three new methods, which allow the evaluation of unsettled BRs with increased reliability compared to the state-of-the-art method. We were able to achieve evaluation times down to 1 micro second and improve response reliability from 80 percent to up to 98.5 percent. This enables the fast and reliable use of BR-based PUFs in strong PUFs applications. Robert Hesselbarth, Georg Sigl |
DSD | 2 |
| 2016 | X25519 Hardware Implementation for Low-Latency ApplicationsabstractIn the world of "Internet of Things" (IoT), millions of interconnected smart devices have to share information in a fast and secure way. In order to ensure the success and widespread adoption of IoT applications, cryptographic services must be provided to ensure secure communications and avoid skepticism about new emerging technologies. Due to its short key sizes, elliptic curve cryptography is typically deployed on resource-constrained devices in order to enable public-key cryptographic services, i.e. secure key exchanges between smart devices. In the past few years, there has been a growing interest in Curve25519 due to its elegant design aimed at both high-security and high-performance, making it one of the most promising candidates to secure IoT applications. In fact, beside providing appropriate security levels, most IoT applications must adhere to strict latency requirements and provide guarantee to process information in a tiny fraction of time. Until now Curve25519 hardware implementations were mainly optimized for high-throughput applications, while no special care was given to low-latency designs. In this work, we close this gap and provide a Curve25519 hardware design targeting low-latency applications. Our implementation takes only 13,639 cycles for a variable-base Curve25519 scalar multiplication and can be operated up to 115 MHz on Xilinx Zynq 7030 FPGA devices. This allows to compute a session key in less than 120 μs, which outperforms known FPGA-based Curve25519 implementations by a factor of 2.8, yet requiring 24 % less area resources. Philipp Koppermann, Fabrizio De Santis, Johann Heyszl, Georg Sigl |
DSD | 4 |
| 2016 | Towards Efficient Evaluation of a Time-Driven Cache Attack on Modern Processors
Andreas Zankl, Katja Miller, Johann Heyszl, Georg Sigl |
ESORICS (2) | 4 |
| 2016 | Attack on a DFA Protected AES by Simultaneous Laser Fault InjectionsabstractThis paper demonstrates a Fault Attack on anAES core protected by an infection type countermeasure. The redundant AES is implemented on a Xilinx Spartan-6FPGA, with a feature size of 45 nm. By injecting exactlythe same fault in both state registers of the redundant implementation using lasers, we are able to annul the protection added by the countermeasure and thus perform a successful Differential Fault Analysis. This requires a high precision double laser setup in order to hit two different locations on the chip at the same point intime. With a priori knowledge about the location of bothstate registers, we were able to generate applicable faultyciphertexts within minutes. Our results show that forapplications demanding a high level of security, relyingon a duplication of hardware is not sufficient. Bodo Selmke, Johann Heyszl, Georg Sigl |
FDTC | 3 |
| 2016 | Enhancing Fault Emulation of Transient Faults by Separating Combinational and Sequential Fault PropagationabstractWe present a fault emulation environment capable of injecting single and multiple transient faults in sequential as well as combinational logic. It is used to perform fault injection campaigns during design verification of security circuits such as smart cards. In order to reduce the unacceptable hardware overhead of fault emulation for combinational faults, we split the problem of combinational fault modeling into two steps: 1) Fault injection in combinational cells and propagation into sequential cells, processed by a software approach, and 2) fast FPGA-based fault emulation of faults in sequential logic. We used the presented tool to emulate single and multiple faults in two different designs used for security applications. We analyzed how faults propagate from combinational to sequential logic, discuss the resulting consequences for developers of security circuits and fault analysis environments and derive performance optimizations. We demonstrate the performance of our method with varying tests and varying fault multiplicities. Interestingly, we found that the presented method outperforms conventional standalone FPGA-based approaches, while it requires 45% less logic elements on the FPGA. Ralph Nyberg, Johann Heyszl, Dietmar Heinz, Georg Sigl |
ACM Great Lakes Symposium on VLSI | 4 |
| 2016 | A flexible framework for mobile device forensics based on cold boot attacksabstractMobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits the remanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory.In this paper, we present a novel framework for cold boot-based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than three kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach on the Samsung Galaxy S4 and Nexus 5 mobile devices along with an extensive evaluation. First, we compare our framework to a traditional memory dump-based analysis. In the next step, we show the potential of our framework by acquiring sensitive user data. Manuel Huber 0001, Benjamin Taubmann, Sascha Wessel, Hans P. Reiser, Georg Sigl |
EURASIP J. Inf. Secur. | 5 |
| 2016 | Cherry-Picking Reliable PUF Bits With Differential Sequence CodingabstractSilicon physical unclonable functions (PUFs) produce a sequence of response bits from chip-unique manufacturing variations. Since the response bits are physically derived, there is noise present. To generate bit-exact cryptographic keys, error correction algorithms are used. The error correction is typically split into small processing blocks to reduce implementation complexity. The reliability of PUF responses varies from bit to bit, but there has been very little work so far that mathematically analyzes the effect of the block size on the reliability of PUF response sequences. We use the information theoretical concept of typicality to show that the probability of drawing an unreliable sequence decreases exponentially with the block size. We present differential sequence coding that scales efficiently across larger block sizes without having the super-linear increase in decoding complexity of prior approaches. It scans the entire PUF response sequentially and then only operates on one single, maximally reliable, block to generate the cryptographic key. Our sample FPGA implementation with a convolutional code is designed for a popular SRAM PUF scenario. It generates a 128-bit key for an average input bit error probability of 15% with an output bit error probability of 6.14 · 10-9and only uses 974 PUF bits and 1, 108 helper data bits. There are 36% less PUF bits and 71% less helper data bits than the best previous individual results in both criteria without increasing the implementation size of the key generation module noticeably. Matthias Hiller, Meng-Day (Mandel) Yu, Georg Sigl |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | A Lightweight Framework for Cold Boot Based Forensics on Mobile DevicesabstractMobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits theremanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory. In this paper, we present a novel framework for cold boot based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than five kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach by comparing it to a traditional memory dump based analysis using the Samsung Galaxy S4 mobile device. Benjamin Taubmann, Manuel Huber 0001, Sascha Wessel, Lukas Heim, Hans P. Reiser, Georg Sigl |
ARES | 6 |
| 2015 | seTPM: Towards Flexible Trusted Computing on Mobile Devices Based on GlobalPlatform Secure Elements
Sergej Proskurin, Georg Sigl |
CARDIS | 3 |
| 2015 | Precise Laser Fault Injections into 90 nm and 45 nm SRAM-cells
Bodo Selmke, Stefan Brummer, Johann Heyszl, Georg Sigl |
CARDIS | 4 |
| 2015 | A Petite and Power Saving Design for the AES S-BoxabstractThe S-Box operation in the Advanced Encryption Standard has a long history of research in tailored and optimised hardware designs. While Canright's design based on tower-field decomposition has long been a benchmark design for low area, designs based on linear-feedback structures achieve lower area and power consumption at the price of additional clock cycles. We combine both approaches to get a design with ~80% lower switching power than Canright using 4% less gates. While our design needs 7 additional clock cycles, it runs at up to 4.8 times higher clock speeds. Our design adds an additional attractive choice along the line of power-speed-tradeoffs while keeping area minimal, offering designers more choices for implementing the AES S-Box. Markus S. Wamser, Lukas Holzbaur, Georg Sigl |
DSD | 3 |
| 2014 | Increasing the efficiency of syndrome coding for PUFs with helper data compressionabstractPhysical Unclonable Functions (PUFs) provide secure cryptographic keys for resource constrained embedded systems without secure storage. A PUF measures internal manufacturing variations to create a unique, but noisy secret inside a device. Syndrome coding schemes create and store helper data about the structure of a specific PUF to correct errors within subsequent PUF measurements and generate a reliable key. This helper data can contain redundancy. We analyze existing schemes and show that data compression can be applied to decrease the size of the helper data of existing implementations. We introduce compressed Differential Sequence Coding (DSC), which is the most efficient syndrome coding scheme known to date for a popular reference scenario. Adding helper data compression to the DSC algorithm leads to an overall decrease of 68% in helper data size compared to other algorithms in a reference scenario. This is achieved without increasing the number of PUF bits and a minimal increase in logic size. Matthias Hiller, Georg Sigl |
DATE | 2 |
| 2014 | Seesaw: An Area-Optimized FPGA Viterbi Decoder for PUFsabstractPhysical Unclonable Functions PUFs are popular security primitives to provide cryptographic keys on FPGAs. However, PUFs require error correction to create reliable cryptographic keys. This work presents a highly optimized Viterbi decoder, adapted to the constraints of PUFs on FPGAs, primarily area but also low power. Our Seesaw architecture contains two block RAMs that are connected through a custom low-area data path. As main result, alternating data access patterns reduce the complexity of the data handling in the Viterbi decoder. Instead of translating through the entire trellis, we introduce a method that only operates on the last state. The new access pattern permits to store the intermediate results in block RAM and leads to a compact overall footprint with low register count. Synthesis results for one legacy and one state-of-the art FPGA, and a comparison to state-of-the-art implementations demonstrate the efficiency of our new Seesaw architecture. Our decoder requires only 65 FPGA slices and 2 block RAMs to carry out the entire Viterbi decoding for a popular (2, 1, [7]) convolutional code. Matthias Hiller, Leandro Rodrigues Lima, Georg Sigl |
DSD | 3 |
| 2014 | Closing the Gap between Speed and Configurability of Multi-bit Fault Emulation Environments for Security and Safety-Critical DesignsabstractSteadily decreasing transistor sizes and new multi beam laser attacks lead to an increasing amount of multi-bit fault occurrences, e.g. during fault attacks against cryptographic implementations. Therefore, multi-bit fault injection becomes more important during security and safety verification. Fault injection techniques which are applicable during the development cycle of a device are based on either software implementations, e.g. formal methods and simulations, or fault emulation environments in hardware. So far, simulations provide the best configurability whereas fault emulation environments provide the best performance in terms of run time. This contribution presents an FPGA-based emulation environment that combines the advantages of both simulation-based and emulation-based environments. To the best of our knowledge, we are the first to achieve this. Permanent and transient multi-bit faults are configurable at run time where the selection of a fault model, the configuration of the injection time and fault duration is supported without the need for re-synthesizing the design. We propose three measures for performance optimization allowing us to support all the fault configuration capabilities at run time without performance penalty. Our experimental results show that the presented emulation environment reaches the theoretical optimal performance for a wide range of fault configurations using our proposed optimizations. Ralph Nyberg, Jürgen Nolles, Johann Heyszl, Dirk Rabe, Georg Sigl |
DSD | 5 |
| 2013 | Clustering Algorithms for Non-profiled Single-Execution Attacks on Exponentiations
Johann Heyszl, Andreas Ibing, Stefan Mangard, Fabrizio De Santis, Georg Sigl |
CARDIS | 5 |
| 2013 | Comprehensive analysis of software countermeasures against fault attacksabstractFault tolerant software against fault attacks constitutes an important class of countermeasures for embedded systems. In this work, we implemented and systematically analyzed a comprehensive set of 19 different strategies for software countermeasures with respect to protection effectiveness as well as time and memory efficiency. We evaluated the performance and security of all implementations by fault injections into a microcontroller simulator based on an ARM Cortex-M3. Our results show that some rather simple countermeasures outperform other more sophisticated methods due to their low memory and/or performance overhead. Further, combinations of countermeasures show strong characteristics and can lead to a high fault coverage, while keeping additional resources at a minimum. The results obtained in this study provide developers of secure software for embedded systems with a solid basis to decide on the right type of fault attack countermeasure for their application. Nikolaus Theißing, Dominik Merli, Michael Smola, Frederic Stumpf, Georg Sigl |
DATE | 5 |
| 2013 | Differential scan-path: A novel solution for secure design-for-testabilityabstractIn this paper, we present a new scan-path structure for improving the security of systems including scan paths, which normally introduce a security critical information leak channel into a design. Our structure, named differential scan path (DiSP), divides the internal state of the scan path in two sections. During the shift-out operation, only subtraction of the two sections is provided. Inferring the internal state from this subtraction requires much guesswork that increases exponentially with scan path length while the resulting fault coverage is only marginally altered. Subtraction does not preserve parity, thus avoiding attacks using parity information. The structure is simple, needs little area and does not require unlocking keys. Through implementing the DiSP in an elliptic curve crypto-graphic coprocessor, we demonstrate how easily it can be integrated into existing design tools. Simulations show that test effectiveness is preserved and that the internal state is effectively hidden. Salvador Manich, Markus S. Wamser, Oscar M. Guillen, Georg Sigl |
ITC | 4 |
| 2012 | Strengths and Limitations of High-Resolution Electromagnetic Field Measurements for Side-Channel Analysis
Johann Heyszl, Dominik Merli, Benedikt Heinz, Fabrizio De Santis, Georg Sigl |
CARDIS | 5 |
| 2012 | Localized Electromagnetic Analysis of Cryptographic Implementations
Johann Heyszl, Stefan Mangard, Benedikt Heinz, Frederic Stumpf, Georg Sigl |
CT-RSA | 5 |
| 2011 | A Cost-Effective FPGA-based Fault Simulation EnvironmentabstractIn this contribution, we present an FPGA-based simulation environment for fault attacks on cryptographic hardware designs. With our methodology, we are able to simulate the effects of global fault attacks from e.g., spikes and local attacks from e.g., focused laser beams. The environment simulates transient bit-flip faults in sequential elements of a digital design. In this way it is tailored to the simulation of fault attacks on cryptographic designs. It is a tool to verify the design's behaviour in case of fault attacks and to verify implemented countermeasures. The environment is script-based for fully automated modification of the digital design and simulation. It can handle designs in VHDL as well as in Verilog language and does not require modifications to the design's source code. We used our environment in a case study and successfully tested the effectiveness of a fault detection countermeasure in an elliptic curve cryptography design. Angelika Janning, Johann Heyszl, Frederic Stumpf, Georg Sigl |
FDTC | 4 |
| 2011 | Keynote address: Design of secure systems - Where are the EDA tools?abstractSummary form only given. The design of security controllers, or more generally of microcontroller platforms implementing measures against hardware attacks, is still a very tedious handwork. Standardized and broadly available design tools as well as the necessary knowledge are rarely available and make secure hardware design a black art, known only within specialized companies building smart cards or Pay TV chips, for example. Secure hardware is, however, of increasing importance in many future embedded systems connected to cyber physical systems. Secure elements, i.e. special security chips or cores on a system on chip, are needed everywhere to protect these systems against physical attacks. Within this talk, the speaker will give some insight in the design flow of two security controller platforms and the special challenges encountered there. After summarizing the main attack scenarios for security hardware, a selection of countermeasures will be presented. These countermeasures have to be implemented and verified during various phases in the design flow. Some self-made tools and scripts have been used to achieve the result of a highly secure implementation, but there is a huge opportunity to accelerate implementation and verification steps. Furthermore, the knowledge about security could be captured inside tools and relieve designers of the task of becoming hardware security experts. The talk should motivate researchers in the EDA world to participate in the development of a new state-of-the-art design flow for secure hardware. Georg Sigl |
ICCAD | 1 |
| 1992 | Accurate net models for placement improvement by network flow methodsabstractAn efficient iterative improvement procedure for row based cell placement is described. Special emphasis is placed on the objective function used to model net lengths. It is shown that minimizing the net length estimated with the net model also minimizes the half perimeter of a rectangle enclosing all pins of a net. Contrary to the half perimeter the new objective function permits computation of costs for assigning cells to locations independently for all cells to be placed simultaneously. This provides the algorithm an important advantage compared to other iterative improvement techniques: many cells can be placed simultaneously by formulating placement as a network flow problem. The algorithm is superior to Timber-WolfSC 5.4, which minimizes the half perimeter.> Konrad Doll, Frank M. Johannes, Georg Sigl |
ICCAD | 3 |
| 1991 | Analytical Placement: A Linear or a Quadratic Objective Function?abstractArticle Analytical placement: A linear or a quadratic objective function? Share on Authors: Georg Sigl Institute of Electronic Design Automation, Department of Electrical Engineering, Technical University of Munich, D-8000 Munich 2, Germany Institute of Electronic Design Automation, Department of Electrical Engineering, Technical University of Munich, D-8000 Munich 2, GermanyView Profile , Konrad Doll Institute of Electronic Design Automation, Department of Electrical Engineering, Technical University of Munich, D-8000 Munich 2, Germany Institute of Electronic Design Automation, Department of Electrical Engineering, Technical University of Munich, D-8000 Munich 2, GermanyView Profile , Frank M. Johannes Institute of Electronic Design Automation, Department of Electrical Engineering, Technical University of Munich, D-8000 Munich 2, Germany Institute of Electronic Design Automation, Department of Electrical Engineering, Technical University of Munich, D-8000 Munich 2, GermanyView Profile Authors Info & Claims DAC '91: Proceedings of the 28th ACM/IEEE Design Automation ConferenceJune 1991 Pages 427–432https://doi.org/10.1145/127601.127707Online:01 June 1991Publication History 167citation908DownloadsMetricsTotal Citations167Total Downloads908Last 12 Months36Last 6 weeks6 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Georg Sigl, Konrad Doll, Frank M. Johannes |
DAC | 1 |
| 1991 | A New Linear Placement Algorithm for Cell GenerationabstractMany design styles used for automatic cell generation need a linear placement of their components. The authors present a novel two-phase algorithm for that task. In a first step, the net length is globally minimized by quadratic programming with an iterative weight update. Its results are as good as a minimization of the net length by linear programming but are obtained by significantly shorter CPU times. In a second step, track count, net length, and possibility of abutment between components are optimized simultaneously by means of a branch and bound algorithm applied to local subproblems. A comparison to previously published algorithms shows that the results of the proposed algorithm are superior.> Edgar Auer, Werner L. Schiele, Georg Sigl |
ICCAD | 3 |
| 1991 | GORDIAN: VLSI placement by quadratic programming and slicing optimizationabstractThe authors present a placement method for cell-based layout styles. It is composed of alternating and interacting global optimization and partitioning steps that are followed by an optimization of the area utilization. Methods using the divide-and-conquer paradigm usually lose the global view by generating smaller and smaller subproblems. In contrast, GORDIAN maintains the simultaneous treatment of all cells over all global optimization steps, thereby considering constraints that reflect the current dissection of the circuit. The global optimizations are performed by solving quadratic programming problems that possess unique global minima. Improved partitioning schemes for the stepwise refinement of the placement are introduced. The area utilization is optimized by an exhaustive slicing procedure. The placement method is applied to real-world problems, and excellent results in terms of placement quality and computation time are obtained.> Jürgen M. Kleinhans, Georg Sigl, Frank M. Johannes, Kurt Antreich |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 1988 | GORDIAN: a new global optimization/rectangle dissection method for cell placementabstractA placement method for cell-based layout styles composed of alternating and interacting global optimization and partitioning phases is presented. In contrast to other methods using the divide-and-conquer paradigm, it maintains the simultaneous treatment of all cells during optimization over all levels of partitioning. In the global optimization phases, constrained quadratic optimization problems with unique global minima are solved. Their solutions induce the assignment of cells to regions during the partitioning phases. For general-cell circuits, a highly efficient exhaustive slicing procedure is applied to small subsets of cells. The designer may choose a configuration from a menu to meet his requirements on chip area, chip aspect ratio and wire length. Placements with high area utilization are obtained within short computation times. The method has been applied to general-cell and standard-cell circuits with up to 3000 cells and nets.> Jürgen M. Kleinhans, Georg Sigl, Frank M. Johannes |
ICCAD | 2 |