Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Andrew Ferraiuolo

dblp:123/7057 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 4 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-authorSecurity and privacy · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
7 papers
Hardware security and side channels · 85% Systems and software security · 15%
Computer architecture, parallel and distributed computing, and storage systems
7 papers
Memory systems · 47% Processor architecture and microarchitecture · 35% Storage systems · 10%
Software engineering, system software, and programming languages
5 papers
Program verification · 52% Programming languages and type systems · 26% Concurrent programming · 17%

Topics — the 25 heaviest of 28, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › side-channel countermeasures
timing attack resistance
0.422016
Lattice priority scheduling: Low-overhead timing-channel protection for a shared memory controller · HPCA 2016
Timing channel protection for a shared memory controller · HPCA 2014
Memory systems
memory controller
0.422016
Lattice priority scheduling: Low-overhead timing-channel protection for a shared memory controller · HPCA 2016
Timing channel protection for a shared memory controller · HPCA 2014
Hardware security and side channels › hardware attacks
side-channel and fault attacks
0.312018
HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018
Hardware security and side channels › side-channel attack
timing side channel
0.312018
HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018
Processor architecture and microarchitecture › hardware-assisted security
secure processor architecture
0.312018
HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018
Systems and software security › information flow control
information flow type system
0.312017
Secure Information Flow Verification with Mutable Dependent Types · DAC 2017
Hardware security and side channels › trusted execution environments
secure enclaves
0.312017
Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017
Hardware security and side channels
trusted execution environments
0.312017
Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017
Program verification › system verification
hardware-software verification
0.312017
Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017
Program verification › security property verification
information flow verification
0.312017
Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis · ASPLOS 2017
Hardware security and side channels › cache side channel
cache timing side channel
0.212016
SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016
Hardware security and side channels
side-channel attack
0.212016
SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016
Memory systems
cache
0.212016
SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016
Memory systems › cache management
cache partitioning
0.212016
SecDCP: secure dynamic cache partitioning for efficient timing channel protection · DAC 2016
Concurrent programming › concurrency bug detection
data race detection
0.212014
Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014
Storage systems
metadata management
0.212014
Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014
Processor architecture and microarchitecture › debugging support
race detection hardware
0.212014
Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014
Programming languages and type systems › type systems › security type systems
information-flow type systems
0.112018
HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018
Programming languages and type systems › type systems
security type systems
0.112018
HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security · CCS 2018
Systems and software security
secure system design
0.112017
Komodo: Using verification to disentangle secure-enclave hardware from software · SOSP 2017
Programming languages and type systems › type theory
dependent types
0.112017
Secure Information Flow Verification with Mutable Dependent Types · DAC 2017
Processor architecture and microarchitecture
chip multiprocessor
0.112017
Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis · ASPLOS 2017
Electronic design automation › hardware verification and test
hardware verification
0.112017
Secure Information Flow Verification with Mutable Dependent Types · DAC 2017
Processor architecture and microarchitecture › hardware-assisted security
trustzone
0.112017
Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis · ASPLOS 2017
Program analysis
dynamic analysis
0.112014
Low-overhead and high coverage run-time race detection through selective meta-data management · HPCA 2014

Methods — techniques the papers use, named apart from their topics

security-typed hardware description language · 1.0RISC-V · 1.0type checking · 0.9security type system · 0.9mutable dependent types · 0.9information flow analysis · 0.9formal verification · 0.6simulation · 0.5dynamic cache partitioning · 0.5vector clock algorithm · 0.4selective meta-data storage · 0.4per-domain queueing · 0.2
YearPublicationVenuePosition
2018 HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow Security
abstract
This paper presents HyperFlow, a processor that enforces secure information flow, including control over timing channels. The design and implementation of HyperFlow offer security assurance because it is implemented using a security-typed hardware description language that enforces secure information flow. Unlike prior processors that aim to enforce simple information-flow policies such as noninterference, HyperFlow allows complex information flow policies that can be configured at run time. Its fine-grained, decentralized information flow mechanisms allow controlled communication among mutually distrusting processes and system calls into different security domains. We address the significant challenges in designing such a processor architecture with contributions in both the hardware architecture and the security type system. The paper discusses the architecture decisions that make the processor secure and describes ChiselFlow, a new secure hardware description language supporting lightweight information-flow enforcement. The HyperFlow architecture is prototyped on a full-featured processor that offers a complete RISC-V instruction set, and is shown to add moderate overhead to area and performance.
Andrew Ferraiuolo, Mark Zhao, Andrew C. Myers, G. Edward Suh
CCS1
2017 Verification of a Practical Hardware Security Architecture Through Static Information Flow Analysis
abstract
Hardware-based mechanisms for software isolation are becoming increasingly popular, but implementing these mechanisms correctly has proved difficult, undermining the root of security. This work introduces an effective way to formally verify important properties of such hardware security mechanisms. In our approach, hardware is developed using a lightweight security-typed hardware description language (HDL) that performs static information flow analysis. We show the practicality of our approach by implementing and verifying a simplified but realistic multi-core prototype of the ARM TrustZone architecture. To make the security-typed HDL expressive enough to verify a realistic processor, we develop new type system features. Our experiments suggest that information flow analysis is efficient, and programmer effort is modest. We also show that information flow constraints are an effective way to detect hardware vulnerabilities, including several found in commercial processors.
Andrew Ferraiuolo, Danfeng Zhang, Andrew C. Myers, G. Edward Suh
ASPLOS1
2017 Secure Information Flow Verification with Mutable Dependent Types
abstract
This paper presents a novel secure hardware description language (HDL) that uses an information flow type system to ensure that hardware is secure at design time. The novelty of this HDL lies in its ability to securely share hardware modules and storage elements across multiple security levels. Unlike previous secure HDLs, the new HDL enables secure sharing at a fine granularity and without implicitly adding hardware for security enforcement; this is important because the implicitly added hardware can break functionality and harm efficiency. The new HDL enables practical hardware designs that are secure, correct, and efficient. We demonstrate the practicality of the new HDL by using it to design and type-check a synthesizable pipelined processor implementation that support protection rings and instructions that change modes.
Andrew Ferraiuolo, Weizhe Hua, Andrew C. Myers, G. Edward Suh
DAC1
2017 Komodo: Using verification to disentangle secure-enclave hardware from software
abstract
Intel SGX promises powerful security: an arbitrary number of user-mode enclaves protected against physical attacks and privileged software adversaries. However, to achieve this, Intel extended the x86 architecture with an isolation mechanism approaching the complexity of an OS microkernel, implemented by an inscrutable mix of silicon and microcode. While hardware-based security can offer performance and features that are difficult or impossible to achieve in pure software, hardware-only solutions are difficult to update, either to patch security flaws or introduce new features.
Andrew Ferraiuolo, Andrew Baumann, Chris Hawblitzel, Bryan Parno
SOSP1
2016 SecDCP: secure dynamic cache partitioning for efficient timing channel protection
abstract
In today's multicore processors, the last-level cache is often shared by multiple concurrently running processes to make efficient use of hardware resources. However, previous studies have shown that a shared cache is vulnerable to timing channel attacks that leak confidential information from one process to another. Static cache partitioning can eliminate the cache timing channels but incurs significant performance overhead. In this paper, we propose Secure Dynamic Cache Partitioning (SecDCP), a partitioning technique that defeats cache timing channel attacks. The SecDCP scheme changes the size of cache partitions at run time for better performance while preventing insecure information leakage between processes. For cache-sensitive multiprogram workloads, our experimental results show that SecDCP improves performance by up to 43% and by an average of 12.5% over static cache partitioning.
Yao Wang 0008, Andrew Ferraiuolo, Danfeng Zhang, Andrew C. Myers, G. Edward Suh
DAC2
2016 Lattice priority scheduling: Low-overhead timing-channel protection for a shared memory controller
abstract
Computer hardware is increasingly shared by distrusting parties in platforms such as commercial clouds and web servers. Though hardware sharing is critical for performance and efficiency, this sharing creates timing-channel vulnerabilities in hardware components such as memory controllers and shared memory. Past work on timing-channel protection for memory controllers assumes all parties are mutually distrusting and require timing-channel protection. This assumption limits the capability of the memory controller to allocate resources effectively, and causes severe performance penalties. Further, the assumption that all entities are mutually distrusting is often a poor fit for the security needs of real systems. Often, some entities do not require timing-channel protection or trust others with information. We propose lattice priority scheduling (LPS), a secure memory scheduling algorithm that improves performance by more precisely meeting the target system's security requirements, expressed as a lattice policy. We evaluate LPS in a simulated 8-core microprocessor. Compared to prior solutions [34], lattice priority scheduling improves system throughput by over 30% on average and by up to 84% for some workloads.
Andrew Ferraiuolo, Yao Wang 0008, Danfeng Zhang, Andrew C. Myers, G. Edward Suh
HPCA1
2015 Detecting Hardware Trojans using On-chip Sensors in an ASIC Design
Shane Kelly, Xuehui Zhang, Mark Tehranipoor, Andrew Ferraiuolo
J. Electron. Test.4
2014 Low-overhead and high coverage run-time race detection through selective meta-data management
abstract
This paper presents an efficient hardware architecture that enables run-time data race detection with high coverage and minimal performance overhead. Run-time race detectors often rely on the happens-before vector clock algorithm for accuracy, yet suffer from either non-negligible performance overhead or low detection coverage due to a large amount of meta-data. Based on the observation that most of data races happen between close-by accesses, we introduce an optimization to selectively store meta-data only for recently shared memory locations and decouple meta-data storage from regular data storage such as caches. Experiments show that the proposed scheme enables run-time race detection with a minimal impact on performance (4.8% overhead on average) with very high detection coverage (over 99%). Furthermore, this architecture only adds a small amount of on-chip resources for race detection: a 13-KB buffer per core and a 1-bit tag per data cache block.
Ruirui C. Huang, Erik Halberg, Andrew Ferraiuolo, G. Edward Suh
HPCA3
2014 Timing channel protection for a shared memory controller
abstract
This paper proposes a new memory controller design that enables secure sharing of main memory among mutually mistrusting parties by eliminating memory timing channels. This study demonstrates that shared memory controllers are vulnerable to both side channel and covert channel attacks that exploit memory interference as timing channels. To address this vulnerability, we identify the sources of interference in a conventional memory controller design, and propose a protection scheme to eliminate the interference across security domains through two main changes: (i) a per security domain based queueing structure, and (ii) static allocation of time slots in the scheduling algorithm. Multi-programmed workloads comprised of SPEC2006 benchmarks were used to evaluate the protection scheme. The results show that the proposed scheme completely eliminates the timing channels in the shared memory with small hardware and performance overheads.
Yao Wang 0008, Andrew Ferraiuolo, G. Edward Suh
HPCA2
2013 Detection of trojans using a combined ring oscillator network and off-chip transient power analysis
abstract
Verifying the trustworthiness of Integrated Circuits (ICs) is of utmost importance, as hardware Trojans may destroy ICs bound for critical applications. A novel methodology combining on-chip structure with external current measurements is proposed to verify whether or not an IC is Trojan free. This method considers Trojans' impact on neighboring cells and on the entire IC's power consumption, and effectively localizes the measurement of dynamic power. To achieve this, we develop a new on-chip ring oscillator network structure distributed across the entire chip and place each ring oscillator's components in different rows of a standard-cell design. By developing novel statistical data analysis, the effect of process variations on the ICs' transient power will be separated from the effect of Trojans. Simulation results using 90nm technology and experimental results on Xilinx Spartan-6 FPGAs demonstrate the efficiency of our proposed method.
Xuehui Zhang, Andrew Ferraiuolo, Mark Tehranipoor
ACM J. Emerg. Technol. Comput. Syst.2
2012 Experimental analysis of a ring oscillator network for hardware Trojan detection in a 90nm ASIC
abstract
The modern integrated circuit (IC) manufacturing process has exposed chip designers to hardware Trojans which threaten circuits bound for critical applications. This paper details the implementation and analysis of a novel ring oscillator network technique for Trojan detection in an application specific integrated circuit (ASIC). The ring oscillator network serves as a power supply monitor by detecting fluctuations in characteristic frequencies due to malicious modifications (i.e. hardware Trojans) in the circuit under authentication. The ring oscillator network was implemented and fabricated in 40 IBM 90nm ASICs with controlled hardware Trojans. This work analyzes the impact of Trojans with varied partial activity, area, and location on the proposed ring oscillator structure and demonstrates that stealthy Trojans can be efficiently detected with this technique even while obfuscated by process variations, background noise, and environment noise.
Andrew Ferraiuolo, Xuehui Zhang, Mark Tehranipoor
ICCAD1