EDBT 2026 Demo / reviewers in the wild / expert
Andrew Ferraiuolo
dblp:123/7057
· DBLP profile ↗
11ranked-venue papers
6as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 4 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-authorSecurity and privacy · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
7 papers |
Hardware security and side channels · 85% Systems and software security · 15% | |
| Computer architecture, parallel and distributed computing, and storage systems
7 papers |
Memory systems · 47% Processor architecture and microarchitecture · 35% Storage systems · 10% | |
| Software engineering, system software, and programming languages
5 papers |
Program verification · 52% Programming languages and type systems · 26% Concurrent programming · 17% |
Topics — the 25 heaviest of 28, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › side-channel countermeasures
timing attack resistance |
0.4 | 2 | 2016 | Lattice priority scheduling: Low-overhead timing-channel protection for a shared memory controller · HPCA 2016 Timing channel protection for a shared memory controller · HPCA 2014 |
Memory systems
memory controller |
0.4 | 2 | 2016 | Lattice priority scheduling: Low-overhead timing-channel protection for a shared memory controller · HPCA 2016 Timing channel protection for a shared memory controller · HPCA 2014 |
Hardware security and side channels › hardware attacks
side-channel and fault attacks |
0.3 | 1 | 2018 | HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018 |
Hardware security and side channels › side-channel attack
timing side channel |
0.3 | 1 | 2018 | HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018 |
Processor architecture and microarchitecture › hardware-assisted security
secure processor architecture |
0.3 | 1 | 2018 | HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018 |
Systems and software security › information flow control
information flow type system |
0.3 | 1 | 2017 | Secure Information Flow Verification with Mutable Dependent Types · DAC 2017 |
Hardware security and side channels › trusted execution environments
secure enclaves |
0.3 | 1 | 2017 | Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017 |
Hardware security and side channels
trusted execution environments |
0.3 | 1 | 2017 | Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017 |
Program verification › system verification
hardware-software verification |
0.3 | 1 | 2017 | Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017 |
Program verification › security property verification
information flow verification |
0.3 | 1 | 2017 | Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis · ASPLOS 2017 |
Hardware security and side channels › cache side channel
cache timing side channel |
0.2 | 1 | 2016 | SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016 |
Hardware security and side channels
side-channel attack |
0.2 | 1 | 2016 | SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016 |
Memory systems
cache |
0.2 | 1 | 2016 | SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016 |
Memory systems › cache management
cache partitioning |
0.2 | 1 | 2016 | SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016 |
Concurrent programming › concurrency bug detection
data race detection |
0.2 | 1 | 2014 | Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014 |
Storage systems
metadata management |
0.2 | 1 | 2014 | Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014 |
Processor architecture and microarchitecture › debugging support
race detection hardware |
0.2 | 1 | 2014 | Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014 |
Programming languages and type systems › type systems › security type systems
information-flow type systems |
0.1 | 1 | 2018 | HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018 |
Programming languages and type systems › type systems
security type systems |
0.1 | 1 | 2018 | HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018 |
Systems and software security
secure system design |
0.1 | 1 | 2017 | Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017 |
Programming languages and type systems › type theory
dependent types |
0.1 | 1 | 2017 | Secure Information Flow Verification with Mutable Dependent Types · DAC 2017 |
Processor architecture and microarchitecture
chip multiprocessor |
0.1 | 1 | 2017 | Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis · ASPLOS 2017 |
Electronic design automation › hardware verification and test
hardware verification |
0.1 | 1 | 2017 | Secure Information Flow Verification with Mutable Dependent Types · DAC 2017 |
Processor architecture and microarchitecture › hardware-assisted security
trustzone |
0.1 | 1 | 2017 | Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis · ASPLOS 2017 |
Program analysis
dynamic analysis |
0.1 | 1 | 2014 | Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014 |
Methods — techniques the papers use, named apart from their topics
security-typed hardware description language · 1.0RISC-V · 1.0type checking · 0.9security type system · 0.9mutable dependent types · 0.9information flow analysis · 0.9formal verification · 0.6simulation · 0.5dynamic cache partitioning · 0.5vector clock algorithm · 0.4selective meta-data storage · 0.4per-domain queueing · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow SecurityabstractThis paper presents HyperFlow, a processor that enforces secure information flow, including control over timing channels. The design and implementation of HyperFlow offer security assurance because it is implemented using a security-typed hardware description language that enforces secure information flow. Unlike prior processors that aim to enforce simple information-flow policies such as noninterference, HyperFlow allows complex information flow policies that can be configured at run time. Its fine-grained, decentralized information flow mechanisms allow controlled communication among mutually distrusting processes and system calls into different security domains. We address the significant challenges in designing such a processor architecture with contributions in both the hardware architecture and the security type system. The paper discusses the architecture decisions that make the processor secure and describes ChiselFlow, a new secure hardware description language supporting lightweight information-flow enforcement. The HyperFlow architecture is prototyped on a full-featured processor that offers a complete RISC-V instruction set, and is shown to add moderate overhead to area and performance. Andrew Ferraiuolo, Mark Zhao, Andrew C. Myers, G. Edward Suh |
CCS | 1 |
| 2017 | Verification of a Practical Hardware Security Architecture Through Static Information Flow AnalysisabstractHardware-based mechanisms for software isolation are becoming increasingly popular, but implementing these mechanisms correctly has proved difficult, undermining the root of security. This work introduces an effective way to formally verify important properties of such hardware security mechanisms. In our approach, hardware is developed using a lightweight security-typed hardware description language (HDL) that performs static information flow analysis. We show the practicality of our approach by implementing and verifying a simplified but realistic multi-core prototype of the ARM TrustZone architecture. To make the security-typed HDL expressive enough to verify a realistic processor, we develop new type system features. Our experiments suggest that information flow analysis is efficient, and programmer effort is modest. We also show that information flow constraints are an effective way to detect hardware vulnerabilities, including several found in commercial processors. Andrew Ferraiuolo, Danfeng Zhang, Andrew C. Myers, G. Edward Suh |
ASPLOS | 1 |
| 2017 | Secure Information Flow Verification with Mutable Dependent TypesabstractThis paper presents a novel secure hardware description language (HDL) that uses an information flow type system to ensure that hardware is secure at design time. The novelty of this HDL lies in its ability to securely share hardware modules and storage elements across multiple security levels. Unlike previous secure HDLs, the new HDL enables secure sharing at a fine granularity and without implicitly adding hardware for security enforcement; this is important because the implicitly added hardware can break functionality and harm efficiency. The new HDL enables practical hardware designs that are secure, correct, and efficient. We demonstrate the practicality of the new HDL by using it to design and type-check a synthesizable pipelined processor implementation that support protection rings and instructions that change modes. Andrew Ferraiuolo, Weizhe Hua, Andrew C. Myers, G. Edward Suh |
DAC | 1 |
| 2017 | Komodo: Using verification to disentangle secure-enclave hardware from softwareabstractIntel SGX promises powerful security: an arbitrary number of user-mode enclaves protected against physical attacks and privileged software adversaries. However, to achieve this, Intel extended the x86 architecture with an isolation mechanism approaching the complexity of an OS microkernel, implemented by an inscrutable mix of silicon and microcode. While hardware-based security can offer performance and features that are difficult or impossible to achieve in pure software, hardware-only solutions are difficult to update, either to patch security flaws or introduce new features. Andrew Ferraiuolo, Andrew Baumann, Chris Hawblitzel, Bryan Parno |
SOSP | 1 |
| 2016 | SecDCP: secure dynamic cache partitioning for efficient timing channel protectionabstractIn today's multicore processors, the last-level cache is often shared by multiple concurrently running processes to make efficient use of hardware resources. However, previous studies have shown that a shared cache is vulnerable to timing channel attacks that leak confidential information from one process to another. Static cache partitioning can eliminate the cache timing channels but incurs significant performance overhead. In this paper, we propose Secure Dynamic Cache Partitioning (SecDCP), a partitioning technique that defeats cache timing channel attacks. The SecDCP scheme changes the size of cache partitions at run time for better performance while preventing insecure information leakage between processes. For cache-sensitive multiprogram workloads, our experimental results show that SecDCP improves performance by up to 43% and by an average of 12.5% over static cache partitioning. Yao Wang 0008, Andrew Ferraiuolo, Danfeng Zhang, Andrew C. Myers, G. Edward Suh |
DAC | 2 |
| 2016 | Lattice priority scheduling: Low-overhead timing-channel protection for a shared memory controllerabstractComputer hardware is increasingly shared by distrusting parties in platforms such as commercial clouds and web servers. Though hardware sharing is critical for performance and efficiency, this sharing creates timing-channel vulnerabilities in hardware components such as memory controllers and shared memory. Past work on timing-channel protection for memory controllers assumes all parties are mutually distrusting and require timing-channel protection. This assumption limits the capability of the memory controller to allocate resources effectively, and causes severe performance penalties. Further, the assumption that all entities are mutually distrusting is often a poor fit for the security needs of real systems. Often, some entities do not require timing-channel protection or trust others with information. We propose lattice priority scheduling (LPS), a secure memory scheduling algorithm that improves performance by more precisely meeting the target system's security requirements, expressed as a lattice policy. We evaluate LPS in a simulated 8-core microprocessor. Compared to prior solutions [34], lattice priority scheduling improves system throughput by over 30% on average and by up to 84% for some workloads. Andrew Ferraiuolo, Yao Wang 0008, Danfeng Zhang, Andrew C. Myers, G. Edward Suh |
HPCA | 1 |
| 2015 | Detecting Hardware Trojans using On-chip Sensors in an ASIC Design
Shane Kelly, Xuehui Zhang, Mark Tehranipoor, Andrew Ferraiuolo |
J. Electron. Test. | 4 |
| 2014 | Low-overhead and high coverage run-time race detection through selective meta-data managementabstractThis paper presents an efficient hardware architecture that enables run-time data race detection with high coverage and minimal performance overhead. Run-time race detectors often rely on the happens-before vector clock algorithm for accuracy, yet suffer from either non-negligible performance overhead or low detection coverage due to a large amount of meta-data. Based on the observation that most of data races happen between close-by accesses, we introduce an optimization to selectively store meta-data only for recently shared memory locations and decouple meta-data storage from regular data storage such as caches. Experiments show that the proposed scheme enables run-time race detection with a minimal impact on performance (4.8% overhead on average) with very high detection coverage (over 99%). Furthermore, this architecture only adds a small amount of on-chip resources for race detection: a 13-KB buffer per core and a 1-bit tag per data cache block. Ruirui C. Huang, Erik Halberg, Andrew Ferraiuolo, G. Edward Suh |
HPCA | 3 |
| 2014 | Timing channel protection for a shared memory controllerabstractThis paper proposes a new memory controller design that enables secure sharing of main memory among mutually mistrusting parties by eliminating memory timing channels. This study demonstrates that shared memory controllers are vulnerable to both side channel and covert channel attacks that exploit memory interference as timing channels. To address this vulnerability, we identify the sources of interference in a conventional memory controller design, and propose a protection scheme to eliminate the interference across security domains through two main changes: (i) a per security domain based queueing structure, and (ii) static allocation of time slots in the scheduling algorithm. Multi-programmed workloads comprised of SPEC2006 benchmarks were used to evaluate the protection scheme. The results show that the proposed scheme completely eliminates the timing channels in the shared memory with small hardware and performance overheads. Yao Wang 0008, Andrew Ferraiuolo, G. Edward Suh |
HPCA | 2 |
| 2013 | Detection of trojans using a combined ring oscillator network and off-chip transient power analysisabstractVerifying the trustworthiness of Integrated Circuits (ICs) is of utmost importance, as hardware Trojans may destroy ICs bound for critical applications. A novel methodology combining on-chip structure with external current measurements is proposed to verify whether or not an IC is Trojan free. This method considers Trojans' impact on neighboring cells and on the entire IC's power consumption, and effectively localizes the measurement of dynamic power. To achieve this, we develop a new on-chip ring oscillator network structure distributed across the entire chip and place each ring oscillator's components in different rows of a standard-cell design. By developing novel statistical data analysis, the effect of process variations on the ICs' transient power will be separated from the effect of Trojans. Simulation results using 90nm technology and experimental results on Xilinx Spartan-6 FPGAs demonstrate the efficiency of our proposed method. Xuehui Zhang, Andrew Ferraiuolo, Mark Tehranipoor |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2012 | Experimental analysis of a ring oscillator network for hardware Trojan detection in a 90nm ASICabstractThe modern integrated circuit (IC) manufacturing process has exposed chip designers to hardware Trojans which threaten circuits bound for critical applications. This paper details the implementation and analysis of a novel ring oscillator network technique for Trojan detection in an application specific integrated circuit (ASIC). The ring oscillator network serves as a power supply monitor by detecting fluctuations in characteristic frequencies due to malicious modifications (i.e. hardware Trojans) in the circuit under authentication. The ring oscillator network was implemented and fabricated in 40 IBM 90nm ASICs with controlled hardware Trojans. This work analyzes the impact of Trojans with varied partial activity, area, and location on the proposed ring oscillator structure and demonstrates that stealthy Trojans can be efficiently detected with this technique even while obfuscated by process variations, background noise, and environment noise. Andrew Ferraiuolo, Xuehui Zhang, Mark Tehranipoor |
ICCAD | 1 |