EDBT 2026 Demo / reviewers in the wild / expert
Ujjwal Guin
dblp:13/9680
· DBLP profile ↗
42ranked-venue papers
11as first author
21since 2021 · last 2026
0000-0002-4819-8728ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 37 · 9 first-author · 20 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unlocking Hidden Secrets: Leveraging SRAM Aging Imprints for Sensitive Data RecoveryabstractLong-term data remanence in SRAMs can pose serious security risks when ICs containing sensitive information are discarded at the end of their operational life. Sensitive information can fall into unauthorized hands if these ICs are not sanitized properly. Traditionally, data remanence has been addressed primarily in DRAM and flash memories, while SRAMs have been overlooked due to very short retention periods. Hovanes et al. [1] demonstrated that SRAMs are vulnerable to data remanence attacks, which can retrieve static data, such as firmware and keys. Their method exploits aging-induced imprints on power-up states, enabling partial recovery by comparing aged states with the originals. Although effective, this method requires maintaining records of all initial power-up states. In this paper, we propose a data recovery approach that does not require access to prior information. Our method also exploits data imprinting in SRAMs, but instead of using actual initial power-up states, we employ controlled aging to reconstruct them. Experiments on SRAM chips storing a binary image demonstrated near-complete recovery after 12 hours of controlled aging at 100◦C using 32 copies. Zakia Tamanna Tisha, Gaines Odom, Biswajit Ray, Ujjwal Guin |
DATE | 4 |
| 2026 | Mitigating Wash Trading in Incentive-Oriented Semiconductor Blockchain Frameworks
Aritri Saha, Ujjwal Guin, Vivek V. Menon |
ICBC | 2 |
| 2026 | Security Vulnerabilities of Semiconductor Memories
Pravineeth Edara, Biresh Kumar Joardar, Zakia Tamanna Tisha, Ujjwal Guin, Habib Ur Rahman, Biswajit Ray |
VTS | 4 |
| 2026 | Understanding the Security Landscape of Embedded Non-Volatile Memories: A Comprehensive SurveyabstractThe modern semiconductor industry requires memory solutions that can keep pace with the high-speed demands of high-performance computing. Embedded non-volatile memories (eNVMs) address these requirements by offering faster access to stored data at an improved computational throughput and efficiency. Furthermore, these technologies offer numerous appealing features, including limited area-energy-runtime budget and data retention capabilities. Among these, the data retention feature of eNVMs has garnered particular interest within the semiconductor community. Although this property allows eNVMs to retain data even in the absence of a continuous power supply, it also introduces some vulnerabilities, prompting security concerns. These concerns have sparked increased interest in examining the broader security implications associated with eNVM technologies. This article examines the security aspects of eNVMs by discussing the reasons for vulnerabilities in specific memories from an architectural point of view. Additionally, this article extensively reviews eNVM-based security primitives, such as physically unclonable functions and true random number generators, as well as techniques like logic obfuscation. This article also explores a broad spectrum of security threats to eNVMs, including physical attacks such as side-channel attacks, fault injection, and probing, as well as logical threats like information leakage, denial-of-service, and thermal attacks. Finally, this article presents a study of publication trends in the eNVM domain since the early 2000s, reflecting the rising momentum and research activity in this field. Zakia Tamanna Tisha, Ujjwal Guin |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2024 | Blockchain-Enabled Whitelisting Mechanisms for Enhancing Security in 3D ICsabstractThe globalization of the semiconductor supply chain has paved the way for a rapid enhancement in the research and development, and the production of electronic devices. The exponential growth in manufacturing, design, and distribution has given rise to a complex ecosystem where the risk of counterfeit or Trojan-inserted integrated circuits (ICs) becomes significant. As emerging technologies continue to reshape the landscape of the electronics supply chain, addressing the challenges and risks posed by these developments becomes increasingly crucial. The challenge of ensuring security for 2.D/3D ICs, composed of multiple chiplets manufactured globally, is exacerbated by the lack of trust among entities in the semiconductor supply chain. The chiplets that are fabricated at an untrusted location can be tampered with, resulting in the insertion of malicious circuits that may leak secret information to an adversary. This paper presents a conceptual approach that limits the communication capability of an untrusted chiplet using a whitelisting technique inspired by security measures deployed in traditional networks. We also propose to use a logger to capture any communication rule violation that occurs during die-to-die communications across different chiplets. The logger state can be further uploaded to an immutable blockchain ledger for forensics purposes if an attack is identified. Gaines Odom, Hardhik Mohanty, Ujjwal Guin, Bhaskar Krishnamachari |
ACM Great Lakes Symposium on VLSI | 3 |
| 2024 | Optimizing Supply Chain Management using Permissioned BlockchainsabstractThe semiconductor supply chain has encountered unprecedented volatility in chip demand and supply, a trend expected to persist over the next decade. Fueled by increasing demands for enhanced performance and power efficiency, the semiconductor industry has undergone a paradigm shift towards heterogeneous integration, leading to the emergence of 2.5D/3D chips. These chips integrate diverse chiplets, sourced globally, into a single chip. Current blockchain solutions in hardware supply chain management focus predominantly on enhancing resiliency for end users or system integrators, providing robust mechanisms for tracking and tracing chip movements. However, these solutions often neglect the critical needs of manufacturers at earlier stages of the supply chain. Addressing this gap, this paper proposes a novel blockchain-enabled provenance framework that equips manufacturers with early visibility into the inventory levels of chiplet distributors and system integrators. Additionally, our framework enables any downstream member to swiftly locate any available chiplets and chips registered on the chain by manufacturers. This visibility enables manufacturers to proactively respond to market shifts, thereby helping to avert supply chain disruptions. Implemented using Tendermint, our framework extends benefits to all stakeholders in the supply chain by enhancing transparency and creating incentives for manufacturers to participate on the blockchain alongside system integrators. This strategic approach not only mitigates the effects of demand volatility but also contributes as a motivation factor for blockchain adoption in hardware supply chains. Aritri Saha, Ujjwal Guin |
ICCAD | 2 |
| 2024 | A Novel Self-referencing Approach Using Memory Power-up States for Detecting COTS SRAMsabstractThe surge in counterfeit Integrated Circuits (ICs) in the electronics supply chain, particularly those reclaimed from recycled components of old and discarded electronics, poses a significant threat to our critical infrastructures. Unfortunately, this threat persists due to the absence of effective detection techniques. In pursuing a reliable detection method, a previous study introduced the idea of identifying recycled ICs using SRAM power-up states, leveraging the inherent symmetry in the logic states of 0s and 1s in newly manufactured SRAM cells. However, in SRAMs produced with older technology nodes, the reference parameter of 50% 1s is often less prominent due to systematic design variation biasing all cells in a specific direction. To address this challenge, this paper proposes a robust self-referencing approach for detecting recycled ICs. The power-up states of an IC under test are segmented into subregions for similarity analysis of the percent of 1s within them. Our study establishes that the percent of 1s in all subregions of a newly manufactured IC is statistically more similar to each other than that in a recycled IC. Our experimental results demonstrate a substantial rise in the standard deviation of the percent of 1s for subregions in the aged SRAM, occurring after just a few days of aging. This approach aims to enhance the reliability of counterfeit IC detection, particularly in the context of older technology nodes where conventional methods may fall short. Gaines Odom, Zakia Tamanna Tisha, Ujjwal Guin |
VTS | 3 |
| 2023 | On-Demand Device Authentication using Zero-Knowledge Proofs for Smart SystemsabstractDue to the exponential growth of IoT devices across diverse applications, it has become essential to secure edge devices against various hardware attacks, such as tampering and cloning. A tampered device with a hardware Trojan can bypass the security measures implemented through the software layers. One of the primary ways to verify the authenticity of a device is by using physically unclonable functions (PUFs) as a unique device fingerprint. During authentication, the PUF response from the edge device is transferred securely and compared with the stored response. This requires a secure communication setup between the edge device and the central server. The fingerprint must also be stored on a server for response matching. However, the potential compromise of the central server will result in the leak of all secret information of the edge devices, and adversaries can exploit it to gain unauthorized access to the IoT network. In this paper, we propose an efficient, secure, and on-demand communication protocol using zero-knowledge proofs (ZKPs) that allow the prover to provide evidence of its secret without revealing that to the verifier. The edge device, acting as the prover, convinces the central server, the verifier, of the unique PUF response stored inside the device without needing the actual storage of PUF responses on the server. The non-interactive characteristic of zk-SNARK, a widely used ZKP protocol in many popular cryptocurrencies such as Zcash, offers better optimization to authentication frequency, communication bandwidth between device and server, and protection of device-specific secret, all of which contribute to constructing our proposed device authentication framework. Yadi Zhong, Joshua Hovanes, Ujjwal Guin |
ACM Great Lakes Symposium on VLSI | 3 |
| 2023 | A Comprehensive Test Pattern Generation Approach Exploiting the SAT Attack for Logic LockingabstractThe need for reducing manufacturing defect escape in today's safety-critical applications requires increased fault coverage. However, generating a test set using commercial automatic test pattern generation (ATPG) tools that lead to zero-defect escape is still an open problem. It is challenging to detect all stuck-at faults to reach 100% fault coverage. In parallel, the hardware security community has been actively involved in developing solutions for logic locking to prevent IP piracy. In logic locking, locks are inserted in different locations of the netlist to modify the original functionality. Unless the correct key is programmed into the IC, the circuit functions incorrectly. Unfortunately, the Boolean satisfiability (SAT) based attack, introduced in (Subramanyan et al. 2015), can determine the secret key efficiently, and break different logic locking schemes. In this article, we propose a novel test pattern generation approach using the powerful SAT attack on logic locking. A stuck-at fault is modeled as a locked gate with a secret key, where it can effectively deduce the satisfiable assignment with reduced backtracks under key initialization of the SAT attack. The input pattern that determines the key is a test for the stuck-at fault. We propose two different approaches for test pattern generation. First, a single stuck-at fault is targeted, and a corresponding locked circuit with one key bit is created. This approach generates one test pattern per fault. Second, we consider a group of faults and convert the circuit to its locked version with multiple key bits. The inputs obtained from the SAT attack tool are the test set for detecting this group of faults. Our approach can find test patterns for all hard-to-detect faults that were previously undetected in commercial ATPG tools. The proposed test pattern generation approach can efficiently detect redundant faults as well. We demonstrate the effectiveness of the approach on ITC’99 benchmarks. The results show that we can detect all the hard-to-detect faults and identify redundant faults and a 100% stuck fault coverage is achieved. In addition, we show that test generation time saving becomes significant for Approach 2 as multiple faults help reduce or remove conflicts. Yadi Zhong, Ujjwal Guin |
IEEE Trans. Computers | 2 |
| 2023 | Complexity Analysis of the SAT Attack on Logic LockingabstractDue to the adoption of horizontal business models following the globalization of semiconductor manufacturing, the overproduction of integrated circuits (ICs) and the piracy of intellectual properties (IPs) can lead to significant damage to the integrity of the semiconductor supply chain. Logic locking emerges as a primary design-for-security measure to counter these threats, where ICs become fully functional only when unlocked with a secret key. However, Boolean satisfiability (SAT)-based attacks have rendered most locking schemes ineffective. This gives rise to numerous defenses and new locking methods to achieve SAT resiliency. This article provides a unique perspective on the SAT attack efficiency based on conjunctive normal form (CNF) stored in SAT solver. First, we show how the attack learns new relations between keys in every iteration using distinguishing input patterns and the corresponding oracle responses. The input-output pairs result in new CNF clauses of unknown keys to be appended to the SAT solver, which leads to an exponential reduction in incorrect key values. Second, we demonstrate that the SAT attack can break any locking scheme within linear iteration complexity of key size. Moreover, we show how key constraints on point functions affect the SAT attack complexity. We explain why proper key constraint on AntiSAT reduces the complexity effectively to constant 1. The same constraint helps the breaking of CAS-Lock down to linear iteration complexity. Our analysis provides a new perspective on the capabilities of SAT attack against multiplier benchmark c6288, and we provide new directions to achieve SAT resiliency. Yadi Zhong, Ujjwal Guin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | CamSkyGate: camouflaged skyrmion gates for protecting ICsabstractMagnetic skyrmion has the potential to become one of the candidates for emerging technologies due to its ultra-high integration density and ultra-low energy. Skyrmion is a magnetic pattern created by transverse current injection in the ferromagnetic (FM) layer. A skyrmion can be generated by localized spin-polarized current and behaves like a stable pseudoparticle. Different logic gates have been proposed, where the presence or absence of a single skyrmion is represented as binary logic 1 or logic 0, respectively. In this paper, we propose novel camouflaged logic gate designs to prevent an adversary from extracting the original netlist. The proposal uses differential doping to block the propagation of the skyrmions to realize the camouflaged gates. To the best of our knowledge, we are the first to propose camouflaged skyrmion gates to prevent an adversary from performing reverse engineering. We demonstrate the functionality of different camouflaged gates using the mumax3 micromagnetic simulator. We have also evaluated the security of the proposed camouflaged designs using SAT attacks. We show that the same security from the traditional CMOS-based camouflaged circuits can be retained. Yuqiao Zhang, Chunli Tang, Ujjwal Guin |
DAC | 4 |
| 2022 | Fault-Injection Based Chosen-Plaintext Attacks on Multicycle AES ImplementationsabstractHardware implementations of cryptographic algorithms offer significantly higher throughput on both encryption and decryption than their software counterparts. Advanced Encryption Standard (AES) is a widely used symmetric block cipher for data encryption. The most commonly used architecture for AES hardware implementations is the multicycle design, where each round uses the same hardware resource multiple times to increase area efficiency. In this paper, we successfully decouple the interdependency of multiple key bytes from the AES encryption. Thus, we solve each key byte separately with an overall attack complexity in O(28). Moreover, we uniquely determine each key byte through a chosen set of three plaintext-ciphertext pairs. We propose two novel chosen-plaintext attacks on multicycle AES implementations. Both attacks can eliminate the key diffusion from the MixColumns and Key Schedule modules. The first attack takes advantage of vulnerable AES implementations where an adversary can observe the output of each round. The second attack is based on fault injection, where a single fault on the completion-indicator register is sufficient to launch the attack. Because no faults are injected in the internal computations of AES, the current fault detection mechanisms are bypassed as no intermediate result has been altered. Lastly, we explore the theoretical aspect for the inherent property of our attacks. Yadi Zhong, Ujjwal Guin |
ACM Great Lakes Symposium on VLSI | 2 |
| 2022 | Fault Modeling and Test Generation for Technology-Specific Defects of Skyrmion Logic CircuitsabstractThis paper advances the recent results on testing skyrmion logic circuits, which recently gained popularity as an emerging technology. A skyrmion circuit differs significantly from the existing CMOS circuit in physical structure and operation mechanisms. The previous work identified 19 defect types and modeled them as either a stuck-at fault, no-fault causing no error, or a technology-specific defect requiring special consideration. The previous work was limited to those defects that map onto single stuck-at faults. The present work addresses the class of technology-specific defects that were not discussed before. Our defect mapping onto an analyzable fault model uses extensions of fault equivalence and fault dominance principles. We model the defects as transition faults whose test generation is supported in the logic-level EDA systems. All such defects require two-pattern tests, except one defect, missing annihilation notch of OR gate, that needs three patterns. These require test generation for constrained stuck-at fault, generally available in EDA systems. The reported results show that majority of the defects of skyrmionbased circuits can be detected using the proposed test generation approach; few exceptions are defects that map through dominance onto faults rendered redundant due to the circuit structure. Ujjwal Guin, Vishwani D. Agrawal |
VTS | 2 |
| 2022 | A Systematic Bit Selection Method for Robust SRAM PUFs
Adit D. Singh, Ujjwal Guin |
J. Electron. Test. | 3 |
| 2022 | AFIA: ATPG-Guided Fault Injection Attack on Secure Logic Locking
Yadi Zhong, Ayush Jain 0002, M. Tanjidur Rahman, Navid Asadizanjani, Jiafeng Xie, Ujjwal Guin |
J. Electron. Test. | 6 |
| 2022 | Test and Yield Loss Reduction of AI and Deep Learning AcceleratorsabstractWith data-driven analytics becoming mainstream, the global demand for dedicated artificial intelligence (AI) and deep learning accelerator chips is soaring. These accelerators, designed with densely packed processing elements (PE), are especially vulnerable to the manufacturing defects and functional faults common in the advanced semiconductor process nodes resulting in significant yield loss. In this work, we demonstrate an application-driven methodology of binning the AI accelerator chips, and yield loss reduction by correlating the circuit faults in the PEs of the accelerator with the desired accuracy of the target AI workload. We exploit the inherent fault tolerance features of trained deep learning models and a strategy of selective deactivation of faulty PEs to develop the presented yield loss reduction and test methodology. An analytical relationship is derived between fault location, fault rate, and the AI task’s accuracy for deciding if the accelerator chip can pass the final yield test. A yield-loss reduction-aware fault isolation, ATPG, and test flow are presented for the multiply and accumulate units of the PEs. Results obtained with widely used AI/deep learning benchmarks demonstrate that the accelerators can sustain 5% fault rate in PE arrays while suffering from less than 1% accuracy loss, thus enabling product binning and yield loss reduction of these chips. Mehdi Sadi, Ujjwal Guin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2021 | Survey of Recent Developments for Hardware Trojan DetectionabstractThe outsourcing of the design and manufacturing of Integrated Circuits (ICs) poses a severe threat to our critical infrastructures as an adversary can exploit them by bypassing the security features by activating a hardware Trojan. These malicious modifications in the design introduced at an untrusted fabrication site can virtually leak any secret information from a secure system to an adversary. This paper discusses all three different hardware Trojan models, such as combinational, sequential, and analog Trojans. We provide a survey of the recent advancements in Trojan detection techniques classified based on their applicability to different Trojans types. We describe a practical approach recently developed using the characterization of Electro-Optical Frequency Mapping (EOFM) images of the chip to detect a hardware Trojan by identifying malicious state elements. This survey also presents open problems with Trojan detection and suggests future research directions in hardware Trojan detection. Ayush Jain 0002, Ujjwal Guin |
ISCAS | 3 |
| 2021 | Special Session: Reliability Analysis for AI/ML HardwareabstractArtificial intelligence (AI) and Machine Learning (ML) are becoming pervasive in today's applications, such as autonomous vehicles, healthcare, aerospace, cybersecurity, and many critical applications. Ensuring the reliability and robustness of the underlying AI/ML hardware becomes our paramount importance. In this paper, we explore and evaluate the reliability of different AI/ML hardware. The first section outlines the reliability issues in a commercial systolic array-based ML accelerator in the presence of faults engendering from device-level non-idealities in the DRAM. Next, we quantified the impact of circuit-level faults in the MSB and LSB logic cones of the Multiply and Accumulate (MAC) block of the AI accelerator on the AI/ML accuracy. Finally, we present two key reliability issues- circuit aging and endurance in emerging neuromorphic hardware platforms and present our system-level approach to mitigate them. Shamik Kundu, Kanad Basu, Mehdi Sadi, Twisha Titirsha, Shihao Song, Anup Das 0001, Ujjwal Guin |
VTS | 7 |
| 2021 | Defect Characterization and Testing of Skyrmion-Based Logic CircuitsabstractMagnetic skyrmion is an emerging digital technology that provides ultra-high integration density and requires ultralow energy. Skyrmion is a magnetic pattern behaving like a stable pseudoparticle, created by a transverse current injection in ferromagnetic thin film. The state of a logic signal is represented by the presence (logic-1) or absence (logic-0) of a single skyrmion. Patterns on ferromagnetic and metal films form interconnects, called nanotracks, through which electric currents move skyrmions. Because skyrmion-based logic gates (e.g., AND, OR, inverter, and fanout) operate through skyrmion-to-skyrmion interaction, their logic circuit implementation and manufacturing defects differ from those of CMOS circuits. We examine breaks and bridges in nanotrack interconnects, and 19 technology-specific defects in skyrmion gate structures. Simulator MuMax3is used to exhaustively simulate all circuit elements. The results help map each defect onto a fault, modeled in an equivalent logic circuit. A break in a nanotrack interconnect maps onto a single stuck-at fault. Experiments on benchmark circuits demonstrate that tests for all nanotrack breaks can be found using the available ATPG and simulation tools. Others are classified as technology-specific defects. For example, a bridge between two nanotracks results in simultaneous AND and OR functions on respective nanotracks. A variety of technology-dependent faults are identified for future research. Ujjwal Guin, Vishwani D. Agrawal |
VTS | 2 |
| 2021 | Estimating Operational Age of an Integrated Circuit
Prattay Chowdhury, Ujjwal Guin, Adit D. Singh, Vishwani D. Agrawal |
J. Electron. Test. | 2 |
| 2021 | TAAL: Tampering Attack on Any Key-based Logic Locked CircuitsabstractDue to the globalization of semiconductor manufacturing and test processes, the system-on-a-chip (SoC) designers no longer design the complete SoC and manufacture chips on their own. This outsourcing of the design and manufacturing of Integrated Circuits (ICs) has resulted in several threats, such as overproduction of ICs, sale of out-of-specification/rejected ICs, and piracy of Intellectual Properties (IPs). Logic locking has emerged as a promising defense strategy against these threats. However, various attacks about the extraction of secret keys have undermined the security of logic locking techniques. Over the years, researchers have proposed different techniques to prevent existing attacks. In this article, we propose a novel attack that can break any logic locking techniques that rely on the stored secret key. This proposed TAAL attack is based on implanting a hardware Trojan in the netlist, which leaks the secret key to an adversary once activated. As an untrusted foundry can extract the netlist of a design from the layout/mask information, it is feasible to implement such a hardware Trojan. All three proposed types of TAAL attacks can be used for extracting secret keys. We have introduced the models for both the combinational and sequential hardware Trojans that evade manufacturing tests. An adversary only needs to choose one hardware Trojan out of a large set of all possible Trojans to launch the TAAL attack. Ayush Jain 0002, Ujjwal Guin |
ACM Trans. Design Autom. Electr. Syst. | 3 |
| 2020 | A Novel Tampering Attack on AES Cores with Hardware TrojansabstractThe implementation of cryptographic primitives in integrated circuits (ICs) continues to increase over the years due to the recent advancement of semiconductor manufacturing and reduction of cost per transistors. The hardware implementation makes cryptographic operations faster and more energy-efficient. However, various hardware attacks have been proposed aiming to extract the secret key in order to undermine the security of these primitives. In this paper, we focus on the widely used advanced encryption standard (AES) block cipher and demonstrate its vulnerability against tampering attack. Our proposed attack relies on implanting a hardware Trojan in the netlist by an untrusted foundry, which can design and implement such a Trojan as it has access to the design layout and mask information. The hardware Trojan's activation modifies a particular round's input data by preventing the effect of all previous rounds' key-dependent computation. We propose to use a sequential hardware Trojan to deliver the payload at the input of an internal round for achieving this modification of data. All the internal subkeys, and finally, the secret key can be computed from the observed ciphertext once the Trojan is activated. We implement our proposed tampering attack with a sequential hardware Trojan inserted into a 128-bit AES design from OpenCores benchmark suite and report the area overhead to demonstrate the feasibility of the proposed tampering attack. Ayush Jain 0002, Ujjwal Guin |
ITC-Asia | 2 |
| 2020 | Special Session: Novel Attacks on Logic-LockingabstractThe outsourcing of the design and manufacturing of integrated circuits (IC) involves various untrusted entities, which can pose many security threats such as overproduction of ICs, sale of out-of-specification/rejected ICs, and piracy of Intellectual Properties (IPs). As a result, various design-for-trust techniques have been developed. Logic locking has recently gained significant interest from the research community due to its capability to provide defense against the threats from untrusted manufacturing. In logic locking, the original circuit is locked using a secret key to make it into a key-dependent circuit. However, various attacks on the extraction of secret keys associated with locking have undermined the security of logic locking techniques. Even after a decade of research, the security of logic locking is still under risk as none of the countermeasures can simultaneously provide resiliency against different attacks, such as tampering, probing, and oracle or oracle-less attacks. This paper presents an overview of novel attacks on logic locking apart from SAT-based analysis. We will present three different techniques to break a secure lock, and they are hardware Trojan based attacks, optical probing based attacks, and the ATPG oriented attacks. Ayush Jain 0002, Ujjwal Guin, M. Tanjidur Rahman, Navid Asadizanjani, Danielle Duvalsaint, R. D. (Shawn) Blanton |
VTS | 2 |
| 2020 | A Zero-Cost Detection Approach for Recycled ICs using Scan ArchitectureabstractThe recycling of used integrated circuits (ICs) has raised serious problems in ensuring the integrity of today’s globalized semiconductor supply chain. This poses a serious threat to critical infrastructure due to potentially shorter lifetime, lower reliability, and poorer performance from these counterfeit new chips. Recently, we have proposed a highly effective approach for detecting such chips by exploiting the power-up state of on-chip SRAMs. Due to the symmetry of the memory array layout, an equal number of cells power-up to the 0 and 1 logic states in a new unused SRAM; this ratio gets skewed in time due to uneven NBTI aging from normal usage in the field. Although this solution is very effective in detecting recycled ICs, its applicability is somewhat limited as a large number older designs do not have large on-chip memories. In this paper, we propose an alternate approach based on the initial power-up state of scan flip-flops, which are present in virtually every digital circuit. Since the flip-flops, unlike SRAM cells, are generally not perfectly symmetrical in layout, an equal number of scan cells will not power-up to 0 or 1 logic states in most designs. Consequently, a stable time zero reference of 50% logic 0s and 1s cannot be used for determining the subsequent usage of a chip. To overcome this key limitation, we propose a novel solution in this paper that reliably identifies used ICs from testing the part alone, without the need for any additional reference data or even the netlist of the circuit. Through scan testing of the IC, we first identify a significant number of asymmetrically stressed flip-flops in the design, divided into two groups. One group of flip-flops is selected such that it mostly experiences the 1 logic state during functional operation, while the other group mostly experiences the 0 state. The resulting differential stress during operation causes growing disparity over time in the number of 0s (and 1s) observed in these two groups at power-up. When new and unaged, these two groups behave similarly, with similar percentage of 1s (or 0s). However, over time the differential stress makes these counts diverge. We show that this changing count can be a measure of operational aging. Our simulation results show that it is possible to reliably detect used ICs after as little as three months of operation. Ujjwal Guin, Adit D. Singh |
VTS | 2 |
| 2020 | Special Session: The Recent Advance in Hardware Implementation of Post-Quantum CryptographyabstractThe recent advancement in quantum technology has initiated a new round of cryptosystem innovation, i.e., the emergence of Post-Quantum Cryptography (PQC). This new class of cryptographic schemes is intended to be mathematically resistant against any known attacks using quantum computers, but, at the same time, be fully implementable using traditional semiconductor technology. The National Institutes of Standards and Technology (NIST) has already started the PQC standardization process, and the initial pool of 69 submissions has been reduced to 26 Round 2 candidates. Echoing the pace of the PQC "revolution," this paper gives a detailed and thorough introduction to recent advances in the hardware implementation of PQC schemes, including challenges, new implementation methods, and novel hardware architectures. Specifically, we have: (i) described the challenges and rewards of implementing PQC in hardware; (ii) presented the novel methodology for the design-space exploration of PQC implementations using high-level synthesis (HLS); (iii) introduced a new underexplored PQC scheme (binary Ring-Learning-with-Errors), as well as its novel hardware implementation for possible lightweight applications. The overall content delivered by this paper could serve multiple purposes: (i) provide useful references for the potential learners and the interested public; (ii) introduce new areas and directions for potential research to the VTS community; (iii) facilitate the PQC standardization process and the exploration of related new ways of implementing cryptography in existing and emerging applications. Jiafeng Xie, Kanad Basu, Kris Gaj, Ujjwal Guin |
VTS | 4 |
| 2020 | Aging-Resilient SRAM-based True Random Number Generator for Lightweight Devices
Ujjwal Guin, Adit D. Singh |
J. Electron. Test. | 2 |
| 2020 | End-to-End Traceability of ICs in Component Supply Chain for Fighting Against RecyclingabstractThe rise of recycled integrated circuits (ICs) in the critical infrastructures causes a major concern to the government and industry because these chips exhibit lower performance and have shorter remaining useful life. The detection of these ICs becomes extremely challenging when they are in the supply chain. It is necessary to power up a chip at a distributor's site to measure different electrical parameters for verifying whether it is used before. However, this can be challenging, as many of the distributors may not be equipped with proper test infrastructures. Moreover, the reliability of authentic chips may be reduced if they have been removed from the packaging boxes for testing purposes. In this paper, we propose a robust and low-cost solution for enabling the traceability of an IC. The proposed solution builds a chain of trust among the manufacturer, distributors, and system integrator by enabling end-to-end traceability from manufacturing to system integration and provides protection against IC recycling. The proposed solution utilizes a small passive radio-frequency identification (RFID) tag, which needs to be placed on the package. Any entity in the supply chain can verify the authenticity of a chip using a commercial RFID reader. Yuqiao Zhang, Ujjwal Guin |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Special Session: Delay Fault Testing - Present and FutureabstractThis article presents a brief survey of digital delay fault testing, which lists 100+ references on fault models, simulators, ATPG, DFT, and tools. Continuing studies are needed in this maturing field for new technologies, signal integrity, process variations, faster than critical path operation, asynchronous circuits, counterfeit ICs, and hardware Trojans. This information is compiled to provide direction to students, practicing engineers, and researchers alike. Jubayer Mahmod, Spencer K. Millican, Ujjwal Guin, Vishwani D. Agrawal |
VTS | 3 |
| 2019 | Low-Cost and Secure Firmware Obfuscation Method for Protecting Electronic Systems From CloningabstractThe continuous growth of the cloning of electronic devices poses a severe threat to our critical infrastructure that uses the Internet, as cloned devices can transmit secret information and cause security concerns. Cloned devices can also be unreliable as they may be manufactured with inferior quality materials, and they may have many defects as they may not be tested properly. It is thus extremely important to protect these electronic devices from cloning. An efficient way to prevent a device being cloned is to prevent the firmware from being copied because, without the proper firmware, the device will not function like the original. In this paper, we present a novel firmware obfuscation method without encrypting the entire memory. The firmware is obfuscated by swapping a subset of instructions. The instructions to be swapped are specifically chosen so that an attacker cannot discover their location. During operation, the hardware reconstructs the original program using a physically unclonable function-generated identifier and a small memory that stores the swapped instructions. An adversary cannot make a program work completely without knowing which instructions have been swapped, as the program will execute in the wrong sequence and produce the incorrect result. Our proposed solution requires only a small overhead to reconstruct the firmware, making it practical for devices with strict resource constraints. This solution also allows remote updates of new obfuscated firmware without any modification and is practical for the rising trend of ubiquitous computing. Benjamin Cyr, Jubayer Mahmod, Ujjwal Guin |
IEEE Internet Things J. | 3 |
| 2018 | Modeling and test generation for combinational hardware TrojansabstractDue to globalization of semiconductor manufacturing, appearance of malicious circuitry known as hardware Trojan is now a recognized security threat. A Trojan may be added to the verified netlist without the knowledge of the designer or user causing unexpected malfunction or data theft when the device is in use. In this research we devise tests that would detect a Trojan in a manufactured chip. We recognize that a Trojan must escape manufacturing tests provided with the netlist by the designer. Based on the two parts of a Trojan, namely, a trigger derived as a Boolean function of any set of signals and a payload (typically, an XOR gate) inserted on a signal line, we develop a test generation model. A single-line trigger combined with a single payload line gives a set of 2K × (K - 1) Trojans in this model for a circuit with K signal lines. Tests for these are shown to be vectors that detect “conditional stuck-at” faults, for which we give a test generation algorithm using standard ATPG tools. The model allows us to define and measure a Trojan coverage metric for tests. Results show scalability of these tests, besides being more effective in detecting real Trojans than N-detect stuck-at test vectors or random vectors. Ujjwal Guin, Vishwani D. Agrawal |
VTS | 2 |
| 2018 | Robust Design-for-Security Architecture for Enabling Trust in IC Manufacturing and Test
Ujjwal Guin, Adit D. Singh |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2017 | A novel design-for-security (DFS) architecture to prevent unauthorized IC overproductionabstractDue to the prohibitive costs of semiconductor manufacturing, most system-on-chip (SoC) design companies outsource their production to offshore foundries. An untrusted foundry can manufacture and sell additional unauthorized chips for profit in violation of their contract. This overproduction can not only cause significant loss of revenue to the designer, but may also have national security implications in case of sensitive designs. Over the years, researchers have proposed different design obfuscation techniques by modifying the underlying functionality to prevent this unauthorized overproduction of chips. An untrusted foundry/assembly cannot sell chips unless they are activated. A chip works properly only when it is activated with a key, which needs to be kept secret from any adversary. However, Boolean satisfiability (SAT)-based algorithms have shown to efficiently break key based obfuscation methods. In this paper, we present a novel secure cell design for implementing design-for-security (DFS) infrastructure to prevent of leaking the key to an adversary under any circumstances. Importantly, our design does not limit the testability of the chip in any way, including post-silicon validation and debug. Ujjwal Guin, Adit D. Singh |
VTS | 1 |
| 2017 | SMA: A System-Level Mutual Authentication for Protecting Electronic Hardware and FirmwareabstractDue to the enhanced capability of adversaries, electronic systems are now increasingly vulnerable to counterfeiting and piracy. The majority of counterfeit systems today are of cloned type, which have been on the rise in the recent years. Ensuring the security of such systems is of great concern as an adversary can create a backdoor or insert a malware to bypass security modules. The reliability of such systems could also be questionable as the components used in these systems may be counterfeit and/or of inferior quality. It is of prime importance to develop solutions that can prevent an adversary from creating these non-authentic systems. In this paper, we present a novel system-level mutual authentication approach for both the hardware and firmware. The hardware authenticates the firmware by verifying the checksum during the power-up. On the other hand, firmware verifies the identity of the hardware and cannot produce correct results unless it receives a unique hardware fingerprint, which we call as system ID. We propose two secure protocols, TIDP and TIDS, to construct the system ID and authenticate the system by using this unique ID. We show that our approach is resistant to various known attacks. Ujjwal Guin, Swarup Bhunia, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | FORTIS: A Comprehensive Solution for Establishing Forward Trust for Protecting IPs and ICsabstractWith the advent of globalization in the semiconductor industry, it is necessary to prevent unauthorized usage of third-party IPs (3PIPs), cloning and unwanted modification of 3PIPs, and unauthorized production of ICs. Due to the increasing complexity of ICs, system-on-chip (SoC) designers use various 3PIPs in their design to reduce time-to-market and development costs, which creates a trust issue between the SoC designer and the IP owners. In addition, as the ICs are fabricated around the globe, the SoC designers give fabrication contracts to offshore foundries to manufacture ICs and have little control over the fabrication process, including the total number of chips fabricated. Similarly, the 3PIP owners lack control over the number of fabricated chips and/or the usage of their IPs in an SoC. Existing research only partially addresses the problems of IP piracy and IC overproduction, and to the best of our knowledge, there is no work that considers IP overuse. In this article, we present a comprehensive solution for preventing IP piracy and IC overproduction by assuring forward trust between all entities involved in the SoC design and fabrication process. We propose a novel design flow to prevent IC overproduction and IP overuse. We use an existing logic encryption technique to obfuscate the netlist of an SoC or a 3PIP and propose a modification to enable manufacturing tests before the activation of chips which is absolutely necessary to prevent overproduction. We have used asymmetric and symmetric key encryption, in a fashion similar to Pretty Good Privacy (PGP), to transfer keys from the SoC designer or 3PIP owners to the chips. In addition, we also propose to attach an IP digest (a cryptographic hash of the entire IP) to the header of an IP to prevent modification of the IP by the SoC designers. We have shown that our approach is resistant to various attacks with the cost of minimal area overhead. Ujjwal Guin, Qihang Shi, Domenic Forte, Mark Tehranipoor |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2016 | Design of Accurate Low-Cost On-Chip Structures for Protecting Integrated Circuits Against RecyclingabstractThe recycling of electronic components has become a major industrial and governmental concern, as it could potentially impact the security and reliability of a wide variety of electronic systems. It is extremely challenging to detect a recycled integrated circuit (IC) that is already used for a very short period of time because the process variations outpace the degradation caused by aging, especially in lower technology nodes. In this paper, we propose a suite of solutions, based on lightweight negative bias temperature instability (NBTI)-aware ring oscillators (ROs), for combating die and IC recycling (CDIR) when ICs are used for a very short duration. The proposed solutions are implemented in the 90-nm technology node. The simulation results demonstrate that our newly proposed NBTI-aware multiple pair RO-based CDIRs can detect ICs used only for a few hours. Ujjwal Guin, Domenic Forte, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2015 | Performance optimization for on-chip sensors to detect recycled ICsabstractIC recycling has become a grave problem in today's globalized semiconductor industry, with potential impact to critical infrastructures. In order to mitigate this problem, various Design-for-Anti-Counterfeit (DfAC) measures have been recently proposed. In this paper, we look at DfAC strategies based on recycling sensors, most notably the ones based on a pair of ring oscillators, which rely on integrated circuit aging phenomena to detect usage of ICs in the field. We introduce a novel optimization technique that generalizes to most recycling sensors suggested so far in literature and gives manufacturers exact control over parameters that determine sensor performance, such as yield, misprediction and area overhead. A detailed analysis of various factors affecting recycling sensor performance is presented and an optimization problem is formulated and verified using simulations, in order to demonstrate the accuracy of the approach. Bicky Shakya, Ujjwal Guin, Mark Tehranipoor, Domenic Forte |
ICCD | 2 |
| 2014 | Low-cost On-Chip Structures for Combating Die and IC RecyclingabstractThe recycling of electronic components has become a major concern for the industry and government as it potentially impacts the security and reliability of a wide variety of electronic systems. The sheer number of component types (analog, digital, mixed-signal) and sizes (large or small) makes it extremely challenging to find a one-size-fits-all solution to detect and prevent recycled ICs. In this paper, we propose a suite of solutions for combating die and IC recycling (CDIR). These solutions include light-weight, on-chip structures based on ring oscillators (RO-CDIR), anti-fuses (AF-CDIR) and fuses (F-CDIR). Each structure meets the unique needs and limitations of different part types and sizes providing excellent coverage of recycled parts. HSPICE simulation results using 90nm technology demonstrate the effectiveness of our proposed negative-bias temperature instability (NBTI)-aware RO-CDIR for detecting ICs used for very short period of time. Recycling of large digital ICs can effectively be detected by using AF-CDIR. Small analog and digital recycled components can be identified by testing our F-CDIR with very low cost measurement devices, e.g., a multimeter. Ujjwal Guin, Xuehui Zhang, Domenic Forte, Mark Tehranipoor |
DAC | 1 |
| 2014 | Counterfeit Integrated Circuits: Detection, Avoidance, and the Challenges Ahead
Ujjwal Guin, Daniel DiMase, Mark Tehranipoor |
J. Electron. Test. | 1 |
| 2014 | A Comprehensive Framework for Counterfeit Defect Coverage Analysis and Detection Assessment
Ujjwal Guin, Daniel DiMase, Mark Tehranipoor |
J. Electron. Test. | 1 |
| 2014 | Counterfeit Integrated Circuits: A Rising Threat in the Global Semiconductor Supply ChainabstractAs the electronic component supply chain grows more complex due to globalization, with parts coming from a diverse set of suppliers, counterfeit electronics have become a major challenge that calls for immediate solutions. Currently, there are a few standards and programs available that address the testing for such counterfeit parts. However, not enough research has yet addressed the detection and avoidance of all counterfeit parts-recycled, remarked, overproduced, cloned, out-of-spec/defective, and forged documentation-currently infiltrating the electronic component supply chain. Even if they work initially, all these parts may have reduced lifetime and pose reliability risks. In this tutorial, we will provide a review of some of the existing counterfeit detection and avoidance methods. We will also discuss the challenges ahead for implementing these methods, as well as the development of new detection and avoidance mechanisms. Ujjwal Guin, Ke Huang 0001, Daniel DiMase, John M. Carulli Jr., Mark Tehranipoor, Yiorgos Makris |
Proc. IEEE | 1 |
| 2013 | Functional Fmax test-time reduction using novel DFTs for circuit initializationabstractUsing functional test for Fmaxanalysis is still the only effective method used in practice in spite of the fact that the test cost associated with functional Fmaxtest remains to be a major problem. In this paper, we develop novel design-for-testability (DFT) structures to considerably reduce the cost of initializing the circuit during functional test. The proposed architectures take advantage of existing DFT structures to reduce the overall cost of hardware and have no impact on the circuit timing. Our implementations of these DFT structures for initializing ITC'99 benchmark circuit b19 demonstrate the effectiveness of these techniques in reducing test time and thus the overall test cost. Ujjwal Guin, Tapan J. Chakraborty, Mark Tehranipoor |
ICCD | 1 |
| 2011 | Design for Bit Error Rate estimation of high speed serial linksabstractHigh speed serial links, consisting of SerDes devices, require the Bit Error Rate (BER) to be at the level of 10-12or lower. The excessive test time for comparing each captured bit for error detection in the traditional BER measurement and the costly instrumentation are major drawbacks for high volume production test of SerDes devices. In this paper, we propose a design for BER estimation methodology which includes a new BER estimation method, a simple BER test system which incorporates a novel design of time-to-digital converter (TDC). Ujjwal Guin, Chen-Huan Chiang |
VTS | 1 |