Elif Bilge Kavun

dblp:00/8569 · DBLP profile ↗
← Back
22ranked-venue papers
2as first author
15since 2021 · last 2026
0000-0003-3193-8440ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 13 · 2 first-author · 11 since 2021Security and privacy · 8 · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 Lippen: a Lightweight in-Place Pointer Encryption Architecture for Pointer Integrity
Erfan Iravani, Lalit Prasad Peri, Mohannad Ismail, Charitha Tumkur Siddalingaradhya, Changwoo Min, Elif Bilge Kavun, Wenjie Xiong 0001
ISCA6
2026 TRACEFORMER: Trace-Efficient and Robust Transformer-Based Late-Fusion Side-Channel Analysis of Masked AES
Ali Alper Sakar, Elif Bilge Kavun
ISCAS2
2025 Differential Power Analysis on Low-Energy Keystream Generating Hardware: Full-State Recovery in Dizy Implementation
abstract
Lightweight cryptographic designs are increasingly being deployed in energy-constrained environments such as the Internet of Things, where efficient hardware implementations are essential. Although recent small internal state stream ciphers like DIZY offer good performance in area and energy, their physical side-channel effects have not been fully established. In this work, we present a practical Correlation Power Analysis attack targeting the resynchronization phase of the DIZY-128 keystream generator. We demonstrate full internal state recovery using fewer than 4000 traces on an FPGA implementation. Our two-phase attack first identifies candidate values for each 5bit state word based on their correlation with power traces. It then reduces these to a single hypothesis for the entire state by correlating the implied next-round state values with the measured traces. These results show how design decisions made for energy efficiency and throughput can unintentionally expose exploitable leakage. Our findings contribute to the ongoing discussion on sustainable security architectures and we argue that secure lowpower hardware must be evaluated not only for efficiency but also for concrete resilience against implementation-level attacks.
Elif Bilge Kavun
ASAP2
2025 The Fellowship of the Leak: Power Analysis of a Masked FrodoKEM Hardware Accelerator
abstract
This paper presents a novel first-order side-channel attack on a first-order masked hardware implementation of FrodoKEM—a quantum-resistant cryptographic scheme currently recommended by German, French, and Dutch agencies on track to become an ISO standard. The proposed attack bypasses the first-order masking when only applied during matrix multiplication and addition in FrodoKEM. This is achieved by using specially crafted inputs, enabling direct first-order correlations with the secret key. We experimentally demonstrate the successful recovery of rows of the secret matrix S on a Xilinx Artix-7 FPGA implementation of the design. The results show that, using correlation power analysis with crafted inputs and no more than 10,000 traces, we can break the claimed resistance with our first-order attack. These findings highlight caveats in the application of current masking techniques to post-quantum cryptographic hardware and emphasize the need for more robust countermeasures.
Giuseppe Manzoni, Aydin Aysu, Elif Bilge Kavun
ICCAD4
2025 Deus Ex LLMs: AI vs Humans in Post-Quantum Cryptographic Hardware Code Generation
abstract
Emerging Post-Quantum Cryptographic (PQC) schemes such as FALCON demand highly optimized hardware implementations to meet strict area and execution time constraints on embedded devices. Traditional hardware designs rely heavily on expert-crafted Register Transfer Level (RTL) or High Level Synthesis (HLS) code, which is time-consuming and error-prone. In this work, we explore the use of large language models (LLMs) for accelerating the development of cryptographic hardware, focusing on FALCON’s performance-critical Samplerz subroutine. We propose a design flow that iteratively leverages LLMs to generate, refine, and evaluate synthesizable C code using HLS tools. We analyze generated designs across a range of models (e.g., GPT-4, Claude, Gemini, Grok), compare them with prior hand-crafted RTL designs, and report implementation metrics including Area-Delay Product (ADP) and synthesis convergence. Alongside achieving implementations within 4% execution time and 30% area of expert-tuned code, our results demonstrate that LLMs can discover novel hardware optimizations. We finally identify key challenges in prompt engineering, numerical stability, and testbench overfitting, and provide actionable recommendations for future AI-assisted hardware design frameworks.
Ethan Cornett, Rahul Magesh, Sharath Pendyala, Elif Bilge Kavun, Aydin Aysu
VLSI-SoC4
2025 Achieving Error-Free Lightweight Authentication With DRAM-Based Physical Unclonable Functions
abstract
In this article, we introduce a novel approach to achieving lightweight device authentication through the use of a low-complexity Convolutional Neural Network (CNN). In our work, we improve the False Authentication Rate (FAR) by transforming the standard CNN into a Bayesian CNN (BCNN or BNN). This transformation enables the use of probabilistic modelling techniques, increasing the model’s robustness and its confidence in authentication decisions. Regardless of the model used, clients authenticate with a retention-based Dynamic Random Access Memory Physical Unclonable Function (DRAM PUF) response. Our approach integrates the low computational complexity of the CNN with the intrinsic security characteristics of the DRAM PUF, offering a robust solution for lightweight and secure device authentication.
Nico Mexis, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001, Elif Bilge Kavun, Sara Tehranipoor, Tolga Arul
IEEE Trans. Circuits Syst. I Regul. Pap.4
2024 Secure Data-Binding in FPGA-based Hardware Architectures utilizing PUFs
abstract
In this work, a novel FPGA-based data-binding architecture incorporating PUFs and a user-specific encryption key to protect the confidentiality of data on external non-volatile memories is presented. By utilizing an intrinsic PUF derived from the same memory, the confidential data is additionally bound to the device. This feature proves valuable in cases where software is restricted to be executed exclusively on specific hardware or privacy-critical data is not allowed to be decrypted elsewhere. To improve the resistance against hardware attacks, a novel method to randomly select memory cells utilized for PUF measurements is presented. The FPGA-based design presented in this work allows for low latency as well as small area utilization, offers high adaptability to diverse hardware and software platforms, and is accessible from bare-metal programs to full Linux kernels. Moreover, a detailed performance and security evaluation is conducted on five boards. A single read or write operation can be executed in 0.58 μs when utilizing the lightweight PRINCE cipher on an AMD Zync 7000 MPSoC. Furthermore, the entire architecture occupies only about 10% of the FPGA's available space on a resource-constrained AMD PYNQ-Z2. Ultimately, the implementation is demonstrated by storing confidential user data on new generations of network base stations equipped with FPGAs.
Florian Frank 0004, Felix Klement, Purushothaman Palani, Elif Bilge Kavun, Wenjie Xiong 0001, Tolga Arul, Stefan Katzenbeisser 0001
AsiaCCS6
2023 A Modular Open-Source Cryptographic Co-Processor for Internet of Things
abstract
The security of computer systems can be increased effectively by using cryptographic co-processors to encapsulate secrets and speed-up the computationally intensive cryptographic functions. This can be especially advantageous for Internet of Things devices, as they usually have to be very efficient in cost, space and timing. However, these devices are also at greater risk of becoming targets of hardware attacks, as they handle sensitive data and are physically exposed to a nearly unrestricted population of users. This paper describes a modular cryptographic co-processor, allowing it to be applied in different scenarios and easily adjusted to concrete system specifications. The co-processor design is also open-source and freely available for anyone to further applications and modifications. It implements the basic cryptographic functions of symmetric encryption, hashing and a pseudo random number generation, with an interface to a true random number generator. In addition, the co-processor offers additional interfaces for key generation. A specific realization is presented in detail, compared to existing solutions, and its resilience against various attacks is discussed.
Dina Hesse, Mael Gay, Ilia Polian, Elif Bilge Kavun, Owen Millwood, Witali Bartsch
DSD4
2023 Spatial Correlation in Weak Physical Unclonable Functions: A Comprehensive Overview
abstract
Physical Unclonable Functions (PUFs) are increasingly used in the process of securing applications. For this purpose, it is crucial that the PUF satisfies all the required properties adequately, including Unpredictability. An important aspect of Unpredictability is Randomness, which includes being free of spatial correlation effects. However, most methods for assessing randomness are not capable of detecting correlation, such that this aspect is often ignored. This work summarises the current literature to shed more light on the topic of analysing spatial correlation in weak PUFs, and evaluates the various methods proposed in the literature for detecting such effects. Additionally, the spatial correlation of a Dynamic Random Access Memory (DRAM) decay-based PUF implemented on the DRAM of a Raspberry Pi board, as well as that of a Carbon-NanoTube-based PUF (CNT-PUF), are examined, using, for the first time in the context of PUFs, not only other well-known metrics proposed in the relevant literature, but also the Getis-Ord G metric. Finally, a mitigation technique against attacks based on spatial auto-correlation is proposed and its effective application to PUF responses is discussed.
Nico Mexis, Tolga Arul, Nikolaos A. Anagnostopoulos, Florian Frank 0004, Simon Böttger, Martin Hartmann, Sascha Hermann, Elif Bilge Kavun, Stefan Katzenbeisser 0001
DSD8
2023 A Generic Obfuscation Framework for Preventing ML-Attacks on Strong-PUFs through Exploitation of DRAM-PUFs
abstract
Considering the limited power and computational resources available, designing sufficiently secure systems for low-power devices is a difficult problem to tackle. With the ubiquitous adoption of the Internet of Things (IoT) not appearing to be slowing any time soon, resource-constrained security is more important than ever. Physical Unclonable Functions (PUFs) have gained momentum in recent years for their potential to enable strong security through the generation of unique identifiers based on entropy derived from unique manufacturing variations. Strong-PUFs, which are desirable for authentication protocols, have often been shown to be insecure to Machine Learning Modelling Attacks (ML-MA). Recently, some schemes have been proposed to enhance security against ML-MA through post-processing of the PUF; however, often, security is not sufficiently upheld, the scheme requires too large an additional overhead or key data must be insecurely stored in Non-Volatile Memory. In this work, we propose a generic framework for securing Strong-PUFs against ML-MA through obfuscation of challenge and response data by exploiting a DRAM-PUF to supplement a One-Way Function (OWF) which can be implemented using the available resources on an FPGA platform. Our proposed scheme enables reconfigurability, strong security and one-wayness. We conduct ML-MA using various classifiers to thoroughly evaluate the performance of our scheme across multiple 16-bit and 32-bit Arbiter-PUF (APUF) variants, showing our scheme reduces model accuracy to around 50% for each PUF (random guessing) and evaluate the properties of the final responses, demonstrating that ideal uniformity and uniqueness are maintained. Even though we demonstrate our proposal through a DRAM-PUF, our scheme can be extended to work with memory-based PUFs in general.
Owen Millwood, Meltem Kurt, Aryan Mohammadi Pasikhani, Jack Miskelly, Prosanta Gope, Elif Bilge Kavun
EuroS&P6
2023 Invited Paper: A Scalable Hardware/Software Co-Design Approach for Efficient Polynomial Multiplication
abstract
Polynomial multiplication is a fundamental operation in security and cryptography applications. However, traditional polynomial multiplication algorithms suffer from high computational complexity and memory bandwidth requirements, limiting their scalability and efficiency. In this work, we propose a new approach that leverages hardware acceleration and software optimization techniques to achieve high performance and scalability while minimizing memory requirements. Our approach uses custom lightweight hardware instructions to perform the computationally intensive parts of the multiplication, while the software manages data movement and communication between the hardware and main memory. We demonstrate the effectiveness of our approach on TMVP-based polynomial multiplication algorithm. The proposed design can be easily customized to target different hardware platforms and polynomial sizes, making it a promising solution for a wide range of applications.
Lóránt Meszlényi, Elif Bilge Kavun, Irem Keskinkurt Paksoy, Avesha Khalid, Tolga Yalçin
ICCAD2
2023 Design Rationale for Symbiotically Secure Key Management Systems in IoT and Beyond
abstract
The overwhelmingly widespread use of Internet of Things (IoT) in different application domains brought not only benefits, but, alas, security concerns as a result of the increased attack surface and vectors. One of the most critical mechanisms in IoT infrastructure is key management. This paper reflects on the problems and challenges of existing key management systems, starting with the discussion of a recent real-world attack. We identify and elaborate on the drawbacks of security primitives based purely on physical variations and - after highlighting the problems of such systems - continue on to deduce an effective and cost-efficient key management solution for IoT systems extending the symbiotic security approach in a previous work. The symbiotic architecture combines software, firmware, and hardware resources for secure IoT while avoiding the traditional scheme of static key storage and generating entropy for key material on-the-fly via a combination of a Physical Unclonable Function (PUF) and pseudo-random bits pre-populated in firmware.
Witali Bartsch, Prosanta Gope, Elif Bilge Kavun, Owen Millwood, Andriy Panchenko 0001, Aryan Mohammadi Pasikhani, Ilia Polian
ICISSP3
2023 PUF-Phenotype: A Robust and Noise-Resilient Approach to Aid Group-Based Authentication With DRAM-PUFs Using Machine Learning
abstract
As the demand for highly secure and dependable lightweight systems increases in the modern world, Physically Unclonable Functions (PUFs) continue to promise a lightweight alternative to high-cost encryption techniques and secure key storage. While the security features promised by PUFs are highly attractive for secure system designers, they have been shown to be vulnerable to various sophisticated attacks - most notably Machine Learning (ML) based modelling attacks (ML-MA) which attempt to digitally clone the PUF behaviour and thus undermine their security. More recent ML-MA have even exploited publicly known helper data required for PUF error correction in order to predict PUF responses without requiring knowledge of response data. In response to this, research is beginning to emerge regarding the authentication of PUF devices with the assistance of ML as opposed to traditional PUF techniques of storage and comparison of pre-known Challenge-Response pairs (CRPs). In this article, we propose a classification system using ML based on a novel ‘PUF-Phenotype’ concept to accurately identify the origin and determine the validity of noisy memory-derived (DRAM) PUF responses as an alternative to helper data-reliant denoising techniques. To our best knowledge, we are thefirstto perform classification over multiple devices per model to enable a group-based PUF authentication scheme. We achieve up to 98% classification accuracy using a modified deep convolutional neural network (CNN) for feature extraction in conjunction with several well-established classifiers. We also experimentally verified the performance of our model on a Raspberry Pi device to determine the suitability of deploying our proposed model in a resource-constrained environment.
Owen Millwood, Jack Miskelly, Bohao Yang, Prosanta Gope, Elif Bilge Kavun, Chenghua Lin 0002
IEEE Trans. Inf. Forensics Secur.5
2022 Evaluating Cryptographic Extensions On A RISC-V Simulation Environment
abstract
Due to the security requirement in the widely-deployed embedded applications, lightweight cryptographic ci-phers have been offered and used in resource-constrained devices in the last decades. In addition to the intrinsic low-cost properties of these ciphers, implementation-and architecture-specific techniques can make the implementation of these ciphers even more efficient. In this paper, we propose a simulation environment for the open-source RISC-V Instruction Set Architecture (ISA) implementing the base RISC-V ISA as well as the “bit manipulation” instruction set extension (ISE), which facilitates the imple-mentation of (lightweight) symmetric cryptography algorithms on resource-constrained devices efficiently. For demonstration pur-poses, we implement the lightweight block ciphers LEA, SIMON, and SPECK on our simulator and evaluate the performance of these ciphers on RISC-V architecture implemented with and without bit manipulation instructions. We define the performance of the lightweight ciphers as the total number of clock cycles required to encrypt one block of plaintext successfully. The performance of lightweight ciphers gives us an insight on how the performance of a cipher can be improved by using specific bit manipulation instructions. Our results show an average 38 % improvement in the total number of clock cycles required to run lightweight ciphers while using bit manipulation instructions.
Parangat Sud, Shekoufeh Neisarian, Elif Bilge Kavun
DSD3
2022 A Power Reduction Technique Based on Linear Transformations for Block Ciphers
abstract
In this paper, we present a novel method for power reduction based on linear transforms for realization of cryptographic block ciphers on hardware platforms. The proposed technique is applicable to both substitution-permutation and Feistel networks, which are widely-used design choices for block ciphers. In our method, an isomorphic transform and its inverse is applied within every round of the target cipher, while the inputs and outputs are also transformed in order to have the same behavior as the original cipher. Hence, our method does not lead to any change of the cryptographic properties of the original cipher. We showcase our method on certain lightweight block ciphers, including the ISO-standard PRESENT, in order to achieve even lower power consumption figures compared to the original designs. Using our proposed technique, we reach power reductions of up to 20%. In some cases, the method can also lead to area reduction in addition to power reduction, which is surprising because the selected lightweight ciphers were already optimized for low area.
Elif Bilge Kavun
VLSI-SoC1
2020 Towards Secure Composition of Integrated Circuits and Electronic Systems: On the Role of EDA
abstract
Modern electronic systems become evermore complex, yet remain modular, with integrated circuits (ICs) acting as versatile hardware components at their heart. Electronic design automation (EDA) for ICs has focused traditionally on power, performance, and area. However, given the rise of hardware-centric security threats, we believe that EDA must also adopt related notions like secure by design and secure composition of hardware. Despite various promising studies, we argue that some aspects still require more efforts, for example: effective means for compilation of assumptions and constraints for security schemes, all the way from the system level down to the "bare metal"; modeling, evaluation, and consideration of security-relevant metrics; or automated and holistic synthesis of various countermeasures, without inducing negative cross-effects.In this paper, we first introduce hardware security for the EDA community. Next we review prior (academic) art for EDA-driven security evaluation and implementation of countermeasures. We then discuss strategies and challenges for advancing research and development toward secure composition of circuits and systems.
Johann Knechtel, Elif Bilge Kavun, Francesco Regazzoni 0001, Annelie Heuser, Anupam Chattopadhyay, Debdeep Mukhopadhyay, Soumyajit Dey, Yunsi Fei, Yaacov Belenky, Itamar Levi, Tim Güneysu, Patrick Schaumont, Ilia Polian
DATE2
2014 Block Ciphers - Focus on the Linear Layer (feat. PRIDE)
Martin R. Albrecht, Benedikt Driessen, Elif Bilge Kavun, Gregor Leander, Christof Paar, Tolga Yalçin
CRYPTO (1)3
2013 A Non-Linear/Linear Instruction Set Extension for Lightweight Ciphers
abstract
Modern cryptography today is substantially involved with securing lightweight (and pervasive) devices. For this purpose, several lightweight cryptographic algorithms have already been proposed. Up to now, the literature has focused on hardware-efficiency while lightweight with respect to software has barely been addressed. However, a large percentage of lightweight ciphers will be implemented on embedded CPUs- without support for cryptographic operations. In parallel, many lightweight ciphers are based on operations which are hardware-friendly but quite costly in software. For instance, bit permutations that accrue essentially no costs in hardware require a non-trivial number of CPU cycles and/or lookup tables in software. Similarly, S-Boxes often require relatively large lookup tables in software. In this work, we try to address the open question of efficient cipher implementations on small CPUs by introducing a non-linear/linear instruction set extension, to which we refer to as NLU, capable of implementing on-linear operations expressed in their algebraic normal form(ANF) and linear operations expressed in binary "matrix multiply-and-add" form. The proposed NLU is targeted for embedded micro controllers and it is therefore 8-bit wide. However, its modular architecture allows it to be used in16, 32, 64 and even 4-bit CPUs. We furthermore present examples of the use of NLU in the implementation of standard cryptographic algorithms in order to demonstrate its coding advantage.
Susanne Engels, Elif Bilge Kavun, Christof Paar, Tolga Yalçin, Hristina Mihajloska
IEEE Symposium on Computer Arithmetic2
2012 PRINCE - A Low-Latency Block Cipher for Pervasive Computing Applications - Extended Abstract
Julia Borghoff, Anne Canteaut, Tim Güneysu, Elif Bilge Kavun, Miroslav Knezevic, Lars R. Knudsen, Gregor Leander, Ventzislav Nikov, Christof Paar, Christian Rechberger, Peter Rombouts, Søren S. Thomsen, Tolga Yalçin
ASIACRYPT4
2012 On the Implementation Aspects of Sponge-Based Authenticated Encryption for Pervasive Devices
Tolga Yalçin, Elif Bilge Kavun
CARDIS2
2011 Memory Encryption for Smart Cards
Baris Ege, Elif Bilge Kavun, Tolga Yalçin
CARDIS2
2010 A pipelined camellia architecture for compact hardware implementation
abstract
In this paper, we present a compact and fast pipelined implementation of the block cipher Camellia for 128-bit data and 128-bit key lengths. The implementation is suitable for both Field Programmable Gate Array (FPGA) and Application Specific Integrated Circuit (ASIC) platforms, and is targeted for low area and low power applications. To obtain a compact design, pipelining principles are exploited and platform specific optimizations are made. The design requires only 321 slices with a throughput of 32.96 Mbps based on Xilinx Spartan-S XC3S50-5 chip and 4.31K gates with a throughput of 81 Mbps based on 0.13-μm CMOS standard cell library.
Elif Bilge Kavun, Tolga Yalçin
ASAP1