Tao Zhang 0108

dblp:15/4777-108 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0001-6922-5652ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 4 first-author · 5 since 2021
YearPublicationVenuePosition
2024 FLAT: Layout-Aware and Security Property-Assisted Timing Fault-Injection Attack Assessment
abstract
The ease and inexpensive setup of injecting timing faults in a hardware design make it vulnerable to adversaries, resulting in confidentiality or integrity violations. The state-of-the-art fault-injection attack assessment frameworks do not consider significant timing variations during layout generation from a gate-level design when assessing security threats of timing faults. Additionally, existing mitigation methods focus on higher design abstractions (e.g., register transfer level (RTL) and gate level), resulting in substantial area, power consumption, and latency overhead. To address these limitations, we propose our layout-aware and security property-assisted timing fault-injection attack assessment (FLAT) framework that automatically assesses the feasibility of injecting controlled timing faults into the layout of a design using clock glitches and quantifies its vulnerability concerning security properties. If the design is vulnerable, FLAT modifies the layout to tune the fan-in path delays of the security-critical registers as local countermeasures. Unlike system-wide mitigation approaches, these countermeasures incur minimal overheads at an IP or system-on-chip (SoC) design regarding power, performance, and area while ensuring security against timing faults. To demonstrate the effectiveness of FLAT, we perform security assessments on the postlayout designs of various benchmarks e.g., advanced encryption standard (AES), rivest-shamir-adleman (RSA), and floating-point unit (FPU) by targeting major fault injection attack vectors and deploying local countermeasures. These assessments indicate that the FLAT framework adeptly evaluates each design’s susceptibility to timing faults and implements the countermeasures to mitigate this susceptibility to the desired level.
Amit Mazumder Shuvo, Tao Zhang 0108, Farimah Farahmandi, Mark Tehranipoor
IEEE Trans. Very Large Scale Integr. Syst.2
2024 SiPGuard: Run-Time System-in-Package Security Monitoring via Power Noise Variation
abstract
As Moore’s law comes to a crawl, advanced package and integration techniques become increasingly crucial by allowing for the combination of fabricated silicon dies, so-called chiplet, to constitute system-in-package (SiP) achieving a much better yield and time-to-market. However, due to inherent security concerns within the convoluted semiconductor supply chain and in-field environment, hostile attacks targeting software and hardware applications can present a formidable challenge to ensuring the security of SiP. Even worse, the immanent black-box nature of product chiplets renders most conventional security inspection and testing solutions less useful. Therefore, we present our SiPGuard in this article to enable the security monitoring capability during run time to noninvasively track the application-level behaviors of target chiplets and detect any deviations potentially induced by underlying malicious intrusions. The security monitoring mechanism utilizes information-bearing system-level power noise variation and machine learning (ML) techniques. Specifically, we utilize a trusted field-programmable gate array (FPGA) chiplet as our trust anchor to implement the lightweight power sensor and on-chip ML inference engine for near-sensor analysis. We prototype our solution on a 2.5-D chiplet-based FPGA device and demonstrate the effectiveness against threats at software/hardware levels by identifying the consequent power anomalies of malicious activities.
Tao Zhang 0108, Md Latifur Rahman, Hadi Mardani Kamali, Kimia Zamiri Azar, Farimah Farahmandi
IEEE Trans. Very Large Scale Integr. Syst.1
2024 TrustGuard: Standalone FPGA-Based Security Monitoring Through Power Side-Channel
abstract
The Internet-of-Thing (IoT) era inspires a surge of networked embedded devices in the real world. However, cyber-attacks such as malware intrusions pose severe concerns about the security of the entire IoT space by hijacking the devices, altering the application’s execution, and/or causing a denial of services. Traditional operating-system-level and built-in hardware detection solutions either induce drastic performance degradation or incur high overhead to the system, failing to provide protection in a timely and affordable fashion. On the other hand, external side-channel-based security monitoring becomes an attractive scheme for addressing the dilemma because the observable physical properties of a running electronic device, such as power consumption and electromagnetic (EM) emanations, can deliver a good amount of information for the underlying operations. In this article, we present TrustGuard, a standalone security monitoring framework integrating both power side-channel capturing and machine learning (ML)-based malware detection capabilities on the same field-programmable gate array (FPGA) fabric. We eliminate the need for dedicated sampling equipment like an oscilloscope with an ON-chip configurable sensor FPGA analog-to-digital converter (ADC) and enable agile prototyping of ML accelerator for attack detection through the high-level synthesis (HLS) technique. We deploy the outcome hardware sensor and security monitor on the Xilinx ZCU104 platform to target the prevalent BeagleBone Black (BBB) board by profiling the behaviors of uncompromised benchmark applications and discovering the anomalies introduced by the attack vectors, including malware infections, code injection, and code reuse. The experimental results demonstrate the performance and effectiveness of TrustGuard by achieving more than 90% malware detection accuracy.
Tao Zhang 0108, Mark Tehranipoor, Farimah Farahmandi
IEEE Trans. Very Large Scale Integr. Syst.1
2023 BitFREE: On Significant Speedup and Security Applications of FPGA Bitstream Format Reverse Engineering
abstract
FPGAs have been widely deployed in critical applications ranging from consumer electronics to spacecraft while the mainstream vendors refuse to disclose the details of their configuration bitstream format for security considerations but obstruct benign applications at the same time. Despite several bitstream reverse engineering solutions being proposed to reconstruct the bitstream formats, the state-of-the-art techniques typically require at least days to partially retrieve the architecture-specific bitstream format for a single (small) FPGA model. In this paper, we propose our BitFREE methodology which targets the most market-dominating Xilinx devices to reverse engineer the majority of bitstream formats of all models in different FPGA families at the time in the order of minutes by utilizing the correlation between FPGA architecture and the configuration memory map to decompose the configuration frames into more fine-grained segments for intelligent parallel analysis instead of directly analyzing entire bitstreams serially like other works. We demonstrate the high accuracy of BitFREE by recovering the information precisely from bitstreams of covered FPGA models. Also, we introduce two security applications of BitFREE, i.e., routing-level bitstream tampering and malicious ring oscillator circuitry detection, to shed light on the broad usage of bitstream reverse engineering in the hardware security domain.
Tao Zhang 0108, Mark Tehranipoor, Farimah Farahmandi
ETS1
2021 PSC-TG: RTL Power Side-Channel Leakage Assessment with Test Pattern Generation
abstract
Power side-channel attacks (SCAs) exploit leakage from cryptographic implementations to recover secrets in a non-invasive manner. Existing power side-channel assessment techniques mostly focus on post-silicon stages, suffering from the extremely low flexibility in changing designs to address identified leakages. In this paper, we propose a framework called PSC-TG which supports side-channel leakage assessment at the earliest stage of design cycle, i.e., RTL, allowing the maximum flexibility for countermeasure deployment. The assessment starts with RTL information flow tracking to identify the most sensitive variables according to pre-defined SCA-aware properties. Then, formal assertions are generated based on these variables and the presumed attack model to derive the corresponding test patterns. Next, the sidechannel vulnerability (SCV) metric is calculated using the estimated power with as low as two patterns to quantify the first-order sidechannel leakage. Besides, PSC-TG can give pass/fail indication for masked implementations at higher orders with t-test. We experimentally evaluate the leakage of multiple non-protected benchmarks at RTL, and validate with gate-level and FPGA results. Also, the t-test results of the masked Simon implementation are consistent with the post-silicon findings.
Tao Zhang 0108, Jungmin Park, Mark Tehranipoor, Farimah Farahmandi
DAC1