EDBT 2026 Demo / reviewers in the wild / expert
Shahin Tajik
dblp:139/7378
· DBLP profile ↗
37ranked-venue papers
6as first author
22since 2021 · last 2026
0000-0003-3752-2358ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 24 · 2 first-author · 17 since 2021Security and privacy · 13 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Chypnosis: Undervolting-based Static Side-channel AttacksabstractStatic side-channel analysis attacks, which rely on a stopped clock to extract sensitive information, pose a growing threat to embedded systems' security. To protect against such attacks, several proposed defenses aim to detect unexpected variations in the clock signal and clear sensitive states. In this work, we present \emph{Chypnosis}, an undervolting attack technique that indirectly stops the target circuit clock, while retaining stored data. Crucially, Chypnosis also blocks the state clearing stage of prior defenses, allowing recovery of secret information even in their presence. However, basic undervolting is not sufficient in the presence of voltage sensors designed to handle fault injection via voltage tampering. To overcome such defenses, we observe that rapidly dropping the supply voltage can disable the response mechanism of voltage sensor systems. We implement Chypnosis on various FPGAs, demonstrating the successful bypass of their sensors, both in the form of soft and hard IPs. To highlight the real-world applicability of Chypnosis, we show that the alert handler of the OpenTitan root-of-trust, responsible for providing hardware responses to threats, can be bypassed. Furthermore, we demonstrate that by combining Chypnosis with static side-channel analysis techniques, namely laser logic state imaging (LLSI) and impedance analysis (IA), we can extract sensitive information from a side-channel protected cryptographic module used in OpenTitan, even in the presence of established clock and voltage sensors. Finally, we propose and implement an improvement to an established FPGA-compatible clock detection countermeasure, and we validate its resilience against Chypnosis. Kyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robbie Dumitru, Yuval Yarom, Shahin Tajik |
SP | 6 |
| 2026 | Impedance Side-Channel Analysis of ASICs: An investigation of measurement factorsabstractAbstract A substantial body of research has been conducted on the subject of physical side-channel analysis attacks and the measures that can be employed to counteract them. These attacks typically exploit the impact of computation or storage on current consumption or voltage drop on a chip, which is an unavoidable consequence of the underlying physical processes. This data-dependent influence can be exploited through analytical techniques such as power or electromagnetic analysis. Recently, a novel target for side-channel analysis adversaries has emerged, based on the data dependency between the chip’s power delivery network impedance and the temporarily stored content in registers. There are two principal reasons why information leakage through the Impedance Side Channel (IMSC) compromises the security of the implementations. First, this method can target the secret even outside the time window, provided that the sensitive data is stored somewhere in the circuit; and second, the simultaneous and independent probing of particular registers challenges the t-probing security model used in masking proofs, a primary side-channel countermeasure. It is crucial to highlight that the interdependence between the die impedance and the temporarily stored data in registers is revealed through scattering parameter analysis. Consequently, the precise measurement of data-dependent impedance, or equivalently, the Scattering (S)- parameter, is essential for its use as a side-channel, which is our focus in this study. In this study, we examine the impact of environmental factors on the IMSC, which are controlled by a classical side-channel adversary. Such factors include temperature and supply voltage. Due to the similarity between the measurement procedures of IMSC and Static Power Side- Channel Analysis (SPSCA), we further provide a fair comparison of these two side-channels in terms of their exploitability and ease of measurement. Most of the previously published studies on the IMSC have been conducted using Field Programmable Gate Arrays (FPGAs). This provides a high level of control over the placement of design components, which can, in turn, affect analysis results. In this work, we use a dedicated Application-Specific Integrated Circuit (ASIC) chip fabricated in 28nm Complementary Metal-Oxide-Semiconductor (CMOS) technology to conduct our study in a more realistic setting. We demonstrated the significant impact of the aforementioned environmental factors on the exploitability of such a side channel. In conclusion, an IMSC adversary can influence the device to leak more information by regulating its operational environment. Bijan Fadaeinia, Shahin Tajik, Amir Moradi 0001 |
J. Electron. Test. | 2 |
| 2025 | Garblet: Multi-party Computation for Protecting Chiplet-based SystemsabstractThe introduction of shared computation architectures assembled from heterogeneous chiplets introduces new security threats. Due to the shared logical and physical resources, an untrusted chiplet can act maliciously to surreptitiously probe the data communication between chiplets or sense the computation shared between them. This paper presents Garblet, the first framework to leverage the flexibility offered by chiplet technology and Garbled Circuits (GC)-based MPC to enable efficient, secure computation even in the presence of potentially compromised chiplets. Our approach integrates a customized hardware Oblivious Transfer (OT) module and an optimized evaluator engine into chiplet-based platforms. This configuration distributes the tasks of garbling and evaluating circuits across two chiplets, reducing communication costs and enhancing computation speed. We implement this framework on an AMD/Xilinx UltraScale+ multichip module and demonstrate its effectiveness using benchmark functions. Additionally, we introduce a novel circuit decomposition technique that allows for parallel processing across multiple chiplets to improve computational efficiency further. Our results highlight the potential of chiplet systems for accelerating GC (e.g., the time complexity of garbled AES is 0.0226ms) in order to guarantee the security and privacy of the computation on chiplets. Shahin Tajik, Fatemeh Ganji |
VTS | 2 |
| 2025 | Sense and React: Self-Destructive Polymorphic Mechanism Against Voltage Tampered Active Physical AttacksabstractSecrets such as cryptographic keys and obfuscation keys are used in modern computing systems to protect the sensitive and private information as well as intellectual property (IP). During typical operations, they are stored in volatile memories, e.g., registers and SRAMs, which are vulnerable to active physical attacks whereby environmental parameters such as temperature, system clock, and supply voltage, are manipulated to extract information. A common way to protect assets against such attacks are sensors that detect active physical attacks and trigger the destruction of secrets. Often, this requires several thousand clock cycles to accomplish. On top of that, the detection and destruction mechanisms are implemented as separate circuitry, which can be identified and disabled by an attacker. In this article, active physical attacks based on supply voltage manipulation are considered. Storage elements, specifically latches and registers, are designed to change their behavior with supply voltage manipulation and automatically destroy their stored data in an integrated sense and response countermeasure. The ability of an electronic circuit to change its behavior under different environmental conditions is known as polymorphism and such circuits are called polymorphic circuits. In the proposed designs, a genetic algorithm (GA) is used to optimize polymorphic gates designed using two separate approaches, namely, multithreshold null convention logic (MTNCL) and voltage-controlled polymorphism termed in this article as Non-MTNCL. These polymorphic gates are used to design polymorphic latches and registers and both approaches are compared using power, performance, area overhead, reliability criteria, and application in cryptographic benchmarks. It is observed that while the GA-optimized MTNCL-based implementation has 75% less area overhead, the GA-optimized Non-MTNCL implementation is 14% more reliable according to simulation results. Apart from the simulations, proof-of-concept is further provided with an FPGA implementation. Andrew Cannon, Luis de la Mata, Rabin Yu Acharya, Tasnuva Farheen, Shahin Tajik, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2024 | FaultyGarble: Fault Attack on Secure Multiparty Neural Network InferenceabstractThe success of deep learning across a variety of applications, including inference on edge devices, has led to increased concerns about the privacy of users’ data and deep learning models. Secure multiparty computation allows parties to remedy this concern, resulting in a growth in the number of such proposals and improvements in their efficiency. The majority of secure inference protocols relying on multiparty computation assume that the client does not deviate from the protocol and passively attempts to extract information. Yet clients, driven by different incentives, can act maliciously to actively deviate from the protocol and disclose the deep learning model owner’s private information. Interestingly, faults are well understood in multiparty computation-related literature, although fault attacks have not been explored. Our paper introduces the very first fault attack against secure inference implementations relying on garbled circuits as a prime example of multiparty computation schemes. In this regard, laser fault injection coupled with a model-extraction attack is successfully mounted against existing solutions that have been assumed to be secure against active attacks. Notably, the number of queries required for the attack is equal to that of the best model-extraction attack mounted against the secure inference engines under the semi-honest scenario. Dev Mehta 0001, Kyle Mitard, Shahin Tajik, Fatemeh Ganji |
FDTC | 4 |
| 2024 | Amnesiac Memory: A Self-Destructive Polymorphic Mechanism Against Cold Boot Data Remanence AttackabstractVolatile memories, like registers and SRAM, are integral parts of any CPU or system-on-chip (SoC). They store a variety of on-chip sensitive assets, such as cryptographic keys, intermediate cipher computations, passwords, obfuscation keys, and hardware security primitive outputs. Although such data should be erased as soon as the power is off, it can be susceptible to cold boot attacks. Cold boot attack is based on remanence effect of memories, which says that memory contents do not disappear immediately after power is cut; they fade gradually over time, which can be significantly prolonged at low temperatures. This effect can be exploited by rebooting a running machine and reading what is left in memory. This paper proposes a self-destructive latch extending to amnesiac register, protecting sensitive data when temperature goes to freezing conditions. Our proposed latch senses the temperature drop required during such attacks and reacts instantaneously by entering a forbidden data state, erasing registers stored data. The design uses a NULL convention logic (NCL)-based polymorphic NOR/NAND gate, which changes its functionality with temperature. Our results show that latch and register are stable across process variation, corresponding to attack with 99% and 80% confidence. Even for the 20% where data is not destroyed, in 9.5% of cases data flips its state, making reliable extraction difficult for an attacker. The polymorphic mechanism is straightforward to implement due to its easy implementation, and temperature threshold for self-destructive behavior is easily programmed using only one gate voltage. Tasnuva Farheen, Andrew Cannon, Jia Di, Shahin Tajik, Domenic Forte |
ACM Great Lakes Symposium on VLSI | 5 |
| 2024 | RandOhm: Mitigating Impedance Side-channel Attacks using Randomized Circuit ConfigurationsabstractPhysical side-channel attacks can compromise the security of integrated circuits. Most physical side-channel attacks (e.g., power or electromagnetic) exploit the dynamic behavior of a chip, typically manifesting as changes in current consumption or voltage fluctuations where algorithmic countermeasures, such as masking, can effectively mitigate them. However, as demonstrated recently, these mitigation techniques are not entirely effective against backscattered side-channel attacks such as impedance analysis. In the case of an impedance attack, an adversary exploits the data-dependent impedance variations of the chip's power delivery network (PDN) to extract secret information. In this work, we introduce RandOhm, which exploits a moving target defense (MTD) strategy based on the partial reconfiguration (PR) feature of mainstream FPGAs and programmable SoCs to defend against impedance side-channel attacks. We demonstrate that the information leakage through the PDN's impedance could be significantly reduced via runtime reconfiguration of the secret-sensitive parts of the circuitry. Hence, by constantly randomizing the placement and routing of the circuit, one can decorrelate the data-dependent computation from the impedance value. Moreover, in contrast to existing PR-based countermeasures, RandOhm deploys open-source bitstream manipulation tools on programmable SoCs to speed up the randomization and provide real-time protection. To validate our claims, we apply RandOhm to AES ciphers realized on 28-nm FPGAs. We analyze the resiliency of our approach by performing non-profiled and profiled impedance analysis attacks and investigate the overhead of our mitigation in terms of delay and performance. Saleh Khalaj Monfared, Domenic Forte, Shahin Tajik |
ICCAD | 3 |
| 2024 | LaserEscape: Detecting and Mitigating Optical Probing AttacksabstractThe security of integrated circuits (ICs) can be broken by sophisticated physical attacks relying on failure analysis methods. Optical probing is one of the most prominent examples of such attacks, which can be accomplished in a matter of days, even with limited knowledge of the IC under attack. Unfortunately, few countermeasures are proposed in the literature, and none have been fabricated and tested in practice. These countermeasures usually require changing the standard cell libraries and, thus, are incompatible with digital and programmable platforms, such as field programmable gate arrays (FPGAs). In this work, we shift our attention from preventing the attack to detecting and responding to it. We introduce LaserEscape, the first fully digital and FPGA-compatible countermeasure to detect and mitigate optical probing attacks. LaserEscape incorporates digital delay-based sensors to reliably detect the physical alteration of the fabric caused by laser beam irradiations in real time. Furthermore, as a response to the attack, LaserEscape deploys real-time hiding approaches using randomized hardware reconfigurability. It realizes 1) moving target defense (MTD) to physically move the sensitive circuity under attack out of the probing field of focus to protect secret keys and 2) polymorphism to logically obfuscate the functionality of the targeted circuit to counter function extraction and reverse engineering attempts. We demonstrate the effectiveness and resiliency of our approach by performing optical probing attacks on protected and unprotected designs on a 28-nm FPGA. Our results show that optical probing attacks can be reliably detected and mitigated without interrupting the chip's operation. Saleh Khalaj Monfared, Kyle Mitard, Andrew Cannon, Domenic Forte, Shahin Tajik |
ICCAD | 5 |
| 2024 | Evaluating Vulnerability of Chiplet-Based Systems to Contactless Probing TechniquesabstractDriven by a need for ever-increasing chip performance, a growing number of semiconductor companies are opting for all-inclusive System-on-Chip (SoC) architectures. Increasingly, the solution adopted to minimize the impact of silicon defects on manufacturing yield of larger dies has been to split a design into multiple smaller dies called chiplets, which are then brought together on a silicon interposer. Advanced 2.5D and 3D packaging techniques that enable this kind of integration also promise increased power efficiency and opportunities for heterogeneous integration.However, despite their advantages, chiplets are not without issues. Disaggregating a design into multiple separate dies introduces new security threats, including the possibility of tampering with and probing exposed data lines. In this paper we evaluate the exposure of chiplets to probing by applying laser contactless probing techniques to a chiplet-based AMD/Xilinx VU9P FPGA. First, we identify and map interposer wire drivers, and show that probing them is easier compared to probing internal nodes. Lastly, we demonstrate that delay-based sensors, which can be used to protect against physical probes, are insufficient to protect against laser probing. Aleksa Deric, Kyle Mitard, Shahin Tajik, Daniel E. Holcomb |
ITC | 3 |
| 2023 | LeakyOhm: Secret Bits Extraction using Impedance AnalysisabstractThe threats of physical side-channel attacks and their countermeasures have been widely researched. Most physical side-channel attacks rely on the unavoidable influence of computation or storage on current consumption or voltage drop on a chip. Such data-dependent influence can be exploited by, for instance, power or electromagnetic analysis. In this work, we introduce a novel non-invasive physical side-channel attack, which exploits the data-dependent changes in the impedance of the chip. Our attack relies on the fact that the temporarily stored contents in registers alter the physical characteristics of the circuit, which results in changes in the die's impedance. To sense such impedance variations, we deploy a well-known RF/microwave method called scattering parameter analysis, in which we inject sine wave signals with high frequencies into the system's power distribution network (PDN) and measure the echo of the signals. We demonstrate that according to the content bits and physical location of a register, the reflected signal is modulated differently at various frequency points enabling the simultaneous and independent probing of individual registers. Such side-channel leakage challenges the t-probing security model assumption used in masking, which is a prominent side-channel countermeasure. To validate our claims, we mount non-profiled and profiled impedance analysis attacks on hardware implementations of unprotected and high-order masked AES. We show that in the case of the profiled attack, only a single trace is required to recover the secret key. Finally, we discuss how a specific class of hiding countermeasures might be effective against impedance leakage. Saleh Khalaj Monfared, Tahoura Mosavirik, Shahin Tajik |
CCS | 3 |
| 2023 | Counterfeit Chip Detection using Scattering Parameter AnalysisabstractThe increase in the number of counterfeit and recycled microelectronic chips in recent years has created significant security and safety concerns in various applications. Hence, detecting such counterfeit chips in electronic systems is critical before deployment in the field. Unfortunately, the conventional verification tools using physical inspection and side-channel methods are costly, unscalable, error-prone, and often incompatible with legacy systems. This paper introduces a generic non-invasive and low-cost counterfeit chip detection based on characterizing the impedance of the system’s power delivery network (PDN). Our method relies on the fact that the impedance of the counterfeit and recycled chips differs from the genuine ones. To sense such impedance variations confidently, we deploy scattering parameters, frequently used for impedance characterization of RF/microwave circuits. Our proposed approach can directly be applied to soldered chips on the system’s PCB and does not require any modifications on the legacy systems. To validate our claims, we perform extensive measurements on genuine and aged samples from two families of STMicroelectronics chips to assess the effectiveness of the proposed approach. Maryam Saadat-Safa, Tahoura Mosavirik, Shahin Tajik |
DDECS | 3 |
| 2023 | Protection Against Physical Attacks Through Self-Destructive Polymorphic LatchabstractOn-chip assets, such as cryptographic keys, intermediate cipher computations, obfuscation keys, and hardware security primitive outputs, are usually stored in volatile memories, e.g., registers and SRAMs. Such volatile memories could be read out using active physical attacks, such laser-assisted side-channels. One way to protect assets stored in volatile memories can be the employment of sensors that detect active physical attacks and trigger complete zeroization of sensitive data. However, hundreds or thousands of clock cycles are often needed to accomplish this. Further, the sensing and self-destruction mechanisms are decoupled from the sensitive circuitry and can be disabled separately by an adversary. Moreover, defensive actions (e.g., zeroization) may be disabled by bringing the CPU/SoC into an inoperable condition, while registers may still hold their data, making them susceptible. This paper proposes a self-destructive latch to protect sensitive data from active side-channel attacks, which require supply voltage manipulations. Our proposed latch senses supply voltage interference required during such attacks, and reacts instantaneously by entering a forbidden data state, erasing its stored data. The design uses a NULL convention logic (NCL)-based polymorphic NOR/NAND gate, which changes its functionality with supply voltage. Our results show that the latch is stable across temperature and process variation reacting to attacks with 91% confidence. Even for the 9% where data is not destroyed, in 3.33 % of cases data flips its state which makes reliable extraction difficult for an attacker. The polymorphic latch is straightforward to implement due to its NCL implementation and the voltage for the self-destructive behavior is easily altered by resizing only two transistors. Further, this self-destructive behavior extends to registers which are built out of latches. Andrew Cannon, Tasnuva Farheen, Shahin Tajik, Domenic Forte |
ICCAD | 4 |
| 2023 | A Survey and Perspective on Artificial Intelligence for Security-Aware Electronic Design AutomationabstractArtificial intelligence (AI) and machine learning (ML) techniques have been increasingly used in several fields to improve performance and the level of automation. In recent years, this use has exponentially increased due to the advancement of high-performance computing and the ever increasing size of data. One of such fields is that of hardware design—specifically the design of digital and analog integrated circuits, where AI/ ML techniques have been extensively used to address ever-increasing design complexity, aggressive time to market, and the growing number of ubiquitous interconnected devices. However, the security concerns and issues related to integrated circuit design have been highly overlooked. In this article, we summarize the state-of-the-art in AI/ML for circuit design/optimization, security and engineering challenges, research in security-aware computer-aided design/electronic design automation, and future research directions and needs for using AI/ML for security-aware circuit design. David Selasi Koblah, Rabin Yu Acharya, Daniel E. Capecci, Olivia P. Dizon-Paradis, Shahin Tajik, Fatemeh Ganji, Damon L. Woodard, Domenic Forte |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2023 | A Twofold Clock and Voltage-Based Detection Method for Laser Logic State Imaging AttackabstractPowerful side-channel analysis (SCA) attacks based on failure analysis (FA) techniques can bypass conventional countermeasures on integrated circuits (ICs) and, therefore, break the entire system’s security. Laser logic state imaging (LLSI) from the IC backside is an example of such attacks, making the contactless probing of static on-die signals possible. Several countermeasures have been proposed to prevent optical probing attacks, such as LLSI. However, these schemes are designed according to the laser properties and its impact on transistors, and hence, they have complex fabrication steps and large area overhead. As a result, they are difficult to verify and implement. In this article, we propose a twofold detection self-timed sensor, which is the first attempt, to our knowledge, for an easy-to-implement circuit-based countermeasure to thwart LLSI attacks. To perform LLSI, the attacker needs to freeze the clock at a point of interest and modulate the voltage supply line at a known frequency to leak the state of transistors through laser light reflections. With these two attack requirements in mind, we design, simulate, and implement clock- and voltage-based sensors that can detect LLSI attacks with very high confidence. Tasnuva Farheen, Shahin Tajik, Domenic Forte |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2022 | Toward Optical Probing Resistant Circuits: A Comparison of Logic Styles and Circuit Design TechniquesabstractLaser-assisted side-channel analysis techniques, such as optical probing (OP), have been shown to pose a severe threat to secure hardware. While several countermeasures have been proposed in the literature, they can either be bypassed by an attacker or require a modification in the transistor's fabrication process, which is costly and complex. In this work, firstly, we propose a formulation for the caliber of reflected light from OP. Secondly, we propose circuit design techniques and logic styles to alleviate OP attacks based on our formulation. Finally, we compare several logic families and circuit design techniques in terms of performance and OP security merits. In this regard, we perform simulations to compare the optical beam interaction between the different logic gates. By utilizing our proposed circuit design techniques and dual-rail logic (DRL), the signal-to-noise ratio (SNR) of the reflected light from OP is reduced significantly. Sajjad Parvin, Thilo Krachenfels, Shahin Tajik, Jean-Pierre Seifert, Frank Sill, Rolf Drechsler |
ASP-DAC | 3 |
| 2022 | TAMED: Transitional Approaches for LFI Resilient State Machine EncodingabstractFinite state machines (FSMs) control the behavior of sequential circuits, including access to privileged states and sensitive information. Laser-based fault injection (LFI) is a precise method where an adversary breaks the chip security by altering the values of individual flip-flops (FFs) with a laser beam. To understand LFI, different laser models, e.g., bit flip, bit set, and bit reset, have been developed. Existing countermeasures can improve FSM resiliency, but either generate multiple LFI resilient encodings applicable only to certain models, or are too conservative, thus incurring significant overhead. In this paper, we introduce the transition-based encoding CAD framework (TAMED), which offers greater flexibility by precisely generating a single optimized FSM encoding that is resilient to multiple LFI models. Predicated on linear programming, TAMED introduces Transitional Vulnerability Metrics that can quantify susceptibility of FSMs based on the bit flip model and the set-reset models. TAMED is demonstrated on 5 benchmarks and outperforms other FSM encoding schemes in terms of security and overhead. Muhtadi Choudhury, Minyan Gao, Shahin Tajik, Domenic Forte |
ITC | 3 |
| 2022 | ScatterVerif: Verification of Electronic Boards Using Reflection Response of Power Distribution NetworkabstractThe globalization of electronic systems’ fabrication has made some of our most critical systems vulnerable to supply chain attacks. Implanting spy chips on the printed circuit boards (PCBs) or replacing genuine components with counterfeit/recycled ones are examples of such attacks. Unfortunately, conventional attack detection schemes for PCBs are ad hoc, costly, unscalable, and error prone. This work introduces a holistic physical verification framework for PCBs, called ScatterVerif , based on the characterization of the PCBs’ power distribution network. First, we demonstrate how scattering parameters, frequently used for impedance characterization of RF circuits, can characterize the entire PCB with a single measurement. Second, we present how a class of machine learning algorithms, namely the Gaussian mixture model, can be applied to the measurements to automatically classify/cluster the genuine and tampered/counterfeit PCBs. We show that these attacks affect the overall impedance of a PCB differently in various frequency ranges, hence the conventional impedance measurements using a constant-frequency electrical stimulus might leave the attack undetected. We conduct extensive experiments on counterfeit and tampered devices and demonstrate that these attacks can be detected with high confidence. Finally, we show that the acquired data from the power distribution network characterization can also be deployed for fingerprinting genuine PCBs. Tahoura Mosavirik, Fatemeh Ganji, Patrick Schaumont, Shahin Tajik |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2021 | PATRON: A Pragmatic Approach for Encoding Laser Fault Injection Resistant FSMsabstractSince Finite State Machines (FSMs) regulate the overall operations in majority of the digital systems, the security of an entire system can be jeopardized if the FSM is vulnerable to physical attacks. By injecting faults into an FSM, an attacker can attain unauthorized access to sensitive states, resulting in information leakage and privilege escalation. One of the powerful fault injection techniques is laser-based fault injection (LFI), which enables an adversary to alter states of individual flip-flops. While standard error correction/detection techniques have been used to protect the FSMs from such fault attacks, their significant overhead makes them unattractive to designers. To keep the overhead minimal, we propose a novel FSM encoding scheme based on decision diagrams that utilizes don't-care states of the FSM. We demonstrate that PATRON outperforms conventional encoding schemes in terms of both security and scalability for popular benchmarks. Finally, we introduce a vulnerability metric to aid the security analysis, which precisely manifests the susceptibility of FSM designs. Muhtadi Choudhury, Domenic Forte, Shahin Tajik |
DATE | 3 |
| 2021 | Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelabstractDue to its sound theoretical basis and practical efficiency, masking has become the most prominent countermeasure to protect cryptographic implementations against physical side-channel attacks (SCAs). The core idea of masking is to randomly split every sensitive intermediate variable during computation into at least t+1 shares, where t denotes the maximum number of shares that are allowed to be observed by an adversary without learning any sensitive information. In other words, it is assumed that the adversary is bounded either by the possessed number of probes (e.g., microprobe needles) or by the order of statistical analyses while conducting higher-order SCA attacks (e.g., differential power analysis). Such bounded models are employed to prove the SCA security of the corresponding implementations. Consequently, it is believed that given a sufficiently large number of shares, the vast majority of known SCA attacks are mitigated.In this work, we present a novel laser-assisted SCA technique, called Laser Logic State Imaging (LLSI), which offers an unlimited number of contactless probes, and therefore, violates the probing security model assumption. This technique enables us to take snapshots of hardware implementations, i.e., extract the logical state of all registers at any arbitrary clock cycle with a single measurement. To validate this, we mount our attack on masked AES hardware implementations and practically demonstrate the extraction of the full-length key in two different scenarios. First, we assume that the location of the registers (key and/or state) is known, and hence, their content can be directly read by a single snapshot. Second, we consider an implementation with unknown register locations, where we make use of multiple snapshots and a SAT solver to reveal the secrets. Thilo Krachenfels, Fatemeh Ganji, Amir Moradi 0001, Shahin Tajik, Jean-Pierre Seifert |
SP | 4 |
| 2021 | Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel Attacks
Thilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre Seifert |
USENIX Security Symposium | 3 |
| 2021 | Special Session: Physical Attacks through the Chip Backside: Threats, Challenges, and OpportunitiesabstractThis paper reviews the evolution of a powerful class of physical attacks against integrated circuits (ICs), developed initially for performing failure analysis (FA) from the IC backside. Over the last two decades, several publications have demonstrated the effectiveness of these techniques in bypassing the IC protection schemes and extracting the stored assets inside secure ICs. In this work, we take a fresh look at such hardware attacks from three different perspectives. First, we will discuss the potential threat of the attacks against modern technologies and demystify a set of wrong beliefs about the attacks' complexity. Second, we review some technical challenges of such attacks from a law enforcement agency's perspective for unraveling crimes and preventing further crimes by criminals involved. Finally, we give an insight into the future development of FA tools and the opportunities for designing effective countermeasures against attacks through the chip backside. Elham Amini, Kai Bartels, Christian Boit, Marius Eggert, Norbert Herfurth, Tuba Kiyan, Thilo Krachenfels, Jean-Pierre Seifert, Shahin Tajik |
VTS | 9 |
| 2021 | CONCEALING-Gate: Optical Contactless Probing Resilient DesignabstractOptical probing, though developed as silicon debugging tools from the chip backside, has shown its capability of extracting secret data, such as cryptographic keys and user identifications, from modern system-on-chip devices. Existing optical probing countermeasures are based on detecting any device modification attempt or abrupt change in operating conditions during asset extraction. These countermeasures usually require additional fabrication steps and cause area and power overheads. In this article, we propose a novel low-overhead design methodology to prevent optical probing. It leverages additional operational logic gates, termed as “CONCEALING-Gates,” inserted as neighbor gates of the logic gates connected to the nets carrying asset signals. The switching activity of the asset carrying logic is camouflaged with the switching activity of the concealing-gate. The input signal and placement in the layout of the concealing-gates must be selected in such a way that they remain equally effective in preventing different variants of optical probing, i.e., electro-optical frequency mapping and Electro-optical probing. The methodology is suitable for the existing ASIC/FPGA design flow and fabrication process, since designing new standard logic cells is not required. We have performed a comprehensive security evaluation of the concealing-gates using a security metric developed based on the parameters that are crucial for optical probing. The attack resiliency of the logic cells, protected by concealing-gates, is evaluated using an empirical study-based simulation methodology and experimental validation. Our analysis has shown that in the presence of concealing-gates, logic cells achieve high resiliency against optical contactless probing techniques. M. Tanjidur Rahman, Nusrat Farzana, Dhwani Mehta, Shahin Tajik, Mark Tehranipoor, Navid Asadizanjani |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2020 | Pitfalls in Machine Learning-based Adversary Modeling for Hardware SystemsabstractThe concept of the adversary model has been widely applied in the context of cryptography. When designing a cryptographic scheme or protocol, the adversary model plays a crucial role in the formalization of the capabilities and limitations of potential attackers. These models further enable the designer to verify the security of the scheme or protocol under investigation. Although being well established for conventional cryptanalysis attacks, adversary models associated with attackers enjoying the advantages of machine learning techniques have not yet been developed thoroughly. In particular, when it comes to composed hardware, often being security-critical, the lack of such models has become increasingly noticeable in the face of advanced, machine learning-enabled attacks. This paper aims at exploring the adversary models from the machine learning perspective. In this regard, we provide examples of machine learning-based attacks against hardware primitives, e.g., obfuscation schemes and hardware root-of-trust, claimed to be infeasible. We demonstrate that this assumption becomes however invalid as inaccurate adversary models have been considered in the literature. Fatemeh Ganji, Sarah Amir, Shahin Tajik, Domenic Forte, Jean-Pierre Seifert |
DATE | 3 |
| 2020 | SPARTA: A Laser Probing Approach for Trojan DetectionabstractIntegrated circuits (ICs) fabricated at untrusted foundries are vulnerable to hardware Trojan insertion. Trojans can be inserted into design files by modifying existing functionality or inserting additional circuitry into unused areas. Checking for the existence of Trojans either requires design-level modification or a complex test process. Unfortunately, the detection confidence using existing techniques is low, while they require a significant increase in verification effort, making them inapplicable to complex circuits due to aggressive time-to-market constraints. On the other hand, for a high confidence detection of Trojans, an exhaustive inspection may be required using destructive reverse-engineering techniques. However, such methods are quite expensive, render the device unusable, and are very time-consuming. In this work, we propose SPARTA, a non-destructive laser probing approach for Trojan detection, which detects sequential hardware Trojans by comparing clock activity within a fabricated IC with the original clock tree created in the design phase. SPARTA does not require any golden samples, but rather the golden design. SPARTA is based upon creating a 2-dimensional frequency map of the backside silicon using electro-optical frequency mapping (EOFM), which exposes the activity of clocked elements in the IC. The measurements are then compared with the expected sequential activity based on the original clock tree identified in the IC to detect all additions, subtractions, or modifications to sequential elements with sub-micron spatial resolution and its efficiency is demonstrated on a 28nm device. Andrew Stern, Dhwani Mehta, Shahin Tajik, Farimah Farahmandi, Mark Tehranipoor |
ITC | 3 |
| 2020 | Defense-in-depth: A recipe for logic locking to prevail
M. Tanjidur Rahman, M. Sazadur Rahman, Shahin Tajik, Waleed Khalil, Farimah Farahmandi, Domenic Forte, Navid Asadizanjani, Mark Tehranipoor |
Integr. | 4 |
| 2020 | Hidden in Plaintext: An Obfuscation-based Countermeasure against FPGA Bitstream Tampering AttacksabstractField Programmable Gate Arrays (FPGAs) have become an attractive choice for diverse applications due to their reconfigurability and unique security features. However, designs mapped to FPGAs are prone to malicious modifications or tampering of critical functions. Besides, targeted modifications have demonstrably compromised FPGA implementations of various cryptographic primitives. Existing security measures based on encryption and authentication can be bypassed using their side-channel vulnerabilities to execute bitstream tampering attacks. Furthermore, numerous resource-constrained applications are now equipped with low-end FPGAs, which may not support power-hungry cryptographic solutions. In this article, we propose a novel obfuscation-based approach to achieve strong resistance against both random and targeted pre-configuration tampering of critical functions in an FPGA design. Our solution first identifies the unique structural and functional features that separate the critical function from the rest of the design using a machine learning guided framework. The selected features are eliminated by applying appropriate obfuscation techniques, many of which take advantage of “FPGA dark silicon”—unused lookup table resources—to mask the critical functions. Furthermore, following the same obfuscation principle, a redundancy-based technique is proposed to thwart targeted, rule-based, and random tampering. We have developed a complete methodology and custom software toolflow that integrates with commercial tools. By applying the masking technique on a design containing AES, we show the effectiveness of the proposed framework in hiding the critical S-Box function. We implement the redundancy integrated solution in various cryptographic designs to analyze the overhead. To protect 16.2% critical component of a design, the proposed approach incurs an average area overhead of only 2.4% over similar redundancy-based approaches, while achieving strong security. Tamzidul Hoque, Kai Yang 0028, Robert Karam, Shahin Tajik, Domenic Forte, Mark Tehranipoor, Swarup Bhunia |
ACM Trans. Design Autom. Electr. Syst. | 4 |
| 2019 | RAM-Jam: Remote Temperature and Voltage Fault Attack on FPGAs using Memory CollisionsabstractIt has been demonstrated that with concrete hardware Trojans, a remote adversary can mount physical attacks, e.g., fault or side-channel attacks, against adjacent IP cores in an FPGA. In this work, we present a novel remote fault attack, called RAM-Jam, which exploits an existing weakness in the dual port RAMs of mainstream FPGAs. The possibility of concurrent writing of opposite logic values into these RAMs not only leads to data uncertainty but also causes transient short circuits. With a sufficient number of RAM collisions, there are severe voltage drops and excessive heat that result in timing faults as well as bit-flips in the FPGA's configuration memory. We conduct extensive experiments to evaluate the effectiveness of our fault injection technique and further present attacks against two applications, including a soft authentication scheme and the first remote fault attack against a deep neural network. Finally, we discuss potential countermeasures to prevent such attacks. Shahin Tajik, Fatemeh Ganji, Mark Tehranipoor, Domenic Forte |
FDTC | 2 |
| 2017 | On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAsabstractModern Integrated Circuits (ICs) employ several classes of countermeasures to mitigate physical attacks. Recently, a powerful semi-invasive attack relying on optical contactless probing has been introduced, which can assist the attacker in circumventing the integrated countermeasures and probe the secret data on a chip. This attack can be mounted using IC debug tools from the backside of the chip. The first published attack based on this technique was conducted against a proof-of-concept hardware implementation on a Field Programmable Gate Array (FPGA). Therefore, the success of optical probing techniques against a real commercial device without any knowledge of the hardware implementation is still questionable. The aim of this work is to assess the threat of optical contactless probing in a real attack scenario. To this end, we conduct an optical probing attack against the bitstream encryption feature of a common FPGA. We demonstrate that the adversary is able to extract the plaintext data containing sensitive design information and intellectual property (IP). In contrast to previous optical attacks from the IC backside, our attack does not require any device preparation or silicon polishing, which makes it a non-invasive attack. Additionally, we debunk the myth that small technology sizes are unsusceptible to optical attacks, as we use an optical resolution of about 1 um to successfully attack a 28 nm device. Based on our time measurements, an attacker needs less than 10 working days to conduct the optical analysis and reverse-engineer the security-related parts of the hardware. Finally, we propose and discuss potential countermeasures, which could make the attack more challenging. Shahin Tajik, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit |
CCS | 1 |
| 2017 | PUFMon: Security monitoring of FPGAs using physically unclonable functionsabstractMainstream FPGAs and programmable SoCs employ different countermeasures during configuration and runtime to mitigate physical attacks. However, it has been demonstrated that sophisticated active attack techniques, such as laser voltage probing, can still bypass the bitstream protections during the configuration phase. On the other hand, although the security monitoring IP cores provided by FPGA vendors can ensure the physical security during the runtime of applications, they are unable to detect such attacks during configuration. In this work, we propose a novel approach to using PUFs as physical sensors to monitor the integrity of FPGAs against active attacks. Small modifications in existing PUF architectures enable us to design a PUF-based security scheme, which can be deployed for integrity monitoring and authentication/key generation at the same time. We evaluate the effectiveness of our framework against a range of powerful attacks, such as optical probing and fault attacks. We further discuss how this scheme can be deployed during bitstream configuration in FPGAs with partial reconfiguration capability. Shahin Tajik, Julian Fietkau 0002, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit |
IOLTS | 1 |
| 2017 | Photonic Side-Channel Analysis of Arbiter PUFs
Shahin Tajik, Enrico Dietz, Sven Frohmann, Helmar Dittrich, Dmitry Nedospasov, Clemens Helfmeier, Jean-Pierre Seifert, Christian Boit, Heinz-Wilhelm Hübers |
J. Cryptol. | 1 |
| 2016 | Strong Machine Learning Attack Against PUFs with No Mathematical Model
Fatemeh Ganji, Shahin Tajik, Fabian Fäßler, Jean-Pierre Seifert |
CHES | 2 |
| 2016 | No Place to Hide: Contactless Probing of Secret Data on FPGAs
Heiko Lohrke, Shahin Tajik, Christian Boit, Jean-Pierre Seifert |
CHES | 2 |
| 2015 | Lattice Basis Reduction Attack against Physically Unclonable FunctionsabstractDue to successful modeling attacks against arbiter PUFs (Physically Unclonable Functions), the trend towards consideration of XOR arbiter PUFs has emerged. Nevertheless, it has already been demonstrated that even this new non-linear structure, with a restricted number of parallel arbiter chains, is still vulnerable to more advanced modeling attacks and side channel analyses. However, so far the security of XOR arbiter PUFs with a large number of parallel arbiter chains has not been appropriately assessed. Furthermore, as another countermeasure against modeling and physical attacks, the concept of controlled PUFs, i.e., with a limited access to challenges and responses, has also been developed. Towards a better understanding of the security of XOR arbiter PUFs, the present paper simultaneously addresses all above mentioned countermeasures by introducing a novel attack, which is a combination of a lattice basis reduction attack and a photonic side channel analysis. We present how our new attack can be successfully launched against XOR arbiter PUFs with an arbitrarily large number of parallel arbiter chains. Most interestingly, our attack does not require any access to challenges or responses. Finally, by conducting an exhaustive discussion on our experimental results, the practical feasibility of our attack scenario is proved as well. Fatemeh Ganji, Juliane Krämer, Jean-Pierre Seifert, Shahin Tajik |
CCS | 4 |
| 2015 | Laser Fault Attack on Physically Unclonable FunctionsabstractPhysically Unclonable Functions (PUFs) are introduced to remedy the shortcomings of traditional methods of secure key storage and random key generation on Integrated Circuits (ICs). Due to their effective and low-cost implementations, intrinsic PUFs are popular PUF instances employed to improve the security of different applications on reconfigurable hardware. In this work we introduce a novel laser fault injection attack on intrinsic PUFs by manipulating the configuration of logic cells in a programable logic device. We present two fault attack scenarios, where not only the effectiveness of modeling attacks can be dramatically increased, but also the entropy of the targeted PUF responses are drastically decreased. In both cases, we conduct detailed theoretical analyses by considering XOR arbiter PUFs and RO PUFs as the examples of PUF-based authenticators and PUF-based random key generators, respectively. Finally we present our experimental results based on conducting laser fault injection on real PUFs, implemented on a common complex programmable logic device manufactured in 180 nm technology. Shahin Tajik, Heiko Lohrke, Fatemeh Ganji, Jean-Pierre Seifert, Christian Boit |
FDTC | 1 |
| 2014 | Physical Characterization of Arbiter PUFs
Shahin Tajik, Enrico Dietz, Sven Frohmann, Jean-Pierre Seifert, Dmitry Nedospasov, Clemens Helfmeier, Christian Boit, Helmar Dittrich |
CHES | 1 |
| 2014 | Physical vulnerabilities of Physically Unclonable FunctionsabstractIn recent years one of the most popular areas of research in hardware security has been Physically Unclonable Functions (PUF). PUFs provide primitives for implementing tamper detection, encryption and device fingerprinting. One particularly common application is replacing Non-volatile Memory (NVM) as key storage in embedded devices like smart cards and secure microcontrollers. Though a wide array of PUF have been demonstrated in the academic literature, vendors have only begun to roll out PUFs in their end-user products. Moreover, the improvement to overall system security provided by PUFs is still the subject of much debate. This work reviews the state of the art of PUFs in general, and as a replacement for key storage in particular. We review also techniques and methodologies which make the physical response characterization and physical/digital cloning of PUFs possible. Clemens Helfmeier, Christian Boit, Dmitry Nedospasov, Shahin Tajik, Jean-Pierre Seifert |
DATE | 4 |
| 2014 | Emission Analysis of Hardware ImplementationsabstractToday, hardware implementations are the basis for many security applications, such as cryptographic ciphers. Such applications are realized using complex combinatorial logic circuits of substantial size. Therefore, understanding the gate-level implementation can be crucial for the attacker. However, Hardware Description Language (HDL) behavioral models and gate-level net list are seldom available for a particular design. Executing software directly on the device to assist in understanding the implementation is one potential solution. However, this may either be infeasible or completely impossible in practice as target devices may be incapable of executing code. Currently, few works have proposed forms of dynamic gate-level analysis of the actual hardware implementations. Moreover, current reverse-engineering techniques based on physical delayering and optical imaging cannot be applied to programmable logic. In this work we present the first dynamic emission analysis of a hardware implementation. This technique does not require any prior knowledge about the target device. Furthermore, it does not require code to be executed by the target. Hardware implementations consist of basic primitives that form the building blocks of complex hardware functions. By individually analyzing each primitive and correlating the corresponding optical images, the emission fingerprint of each primitive can be identified. As a result the hardware implementation of the device can be reconstructed. We present practical results for a common Complex Programmable Logic Device (CPLD). However, the same approach can be applied to hardware implementations in general. Shahin Tajik, Dmitry Nedospasov, Clemens Helfmeier, Jean-Pierre Seifert, Christian Boit |
DSD | 1 |