EDBT 2026 Demo / reviewers in the wild / expert
Zhangqing He
dblp:157/2913
· DBLP profile ↗
13ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0001-7170-2446ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 1 first-author · 7 since 2021Security and privacy · 3 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Chip-PCB Hybrid Strong PUF for Physical Attack Protection of IoT Devices
Zhangqing He, Meilin Wan |
IEEE Internet Things J. | 1 |
| 2026 | An IO-Efficient SC PUF Used for Protecting Chips From PCB-Level AttacksabstractThis paper proposes a chip–PCB hybrid switched-capacitor (SC) physical unclonable function (PUF) to detect PCB-level attacks using only two, or even a single, sense IO. An on-chip capacitor array is employed to compensate for and balance the capacitances between the two sense IOs (or between one sense IO and one on-chip capacitor). The sense IOs then form a sense SC circuit, while two on-chip capacitors constitute a reference SC circuit to which a small threshold capacitor is further introduced. An unchanged relationship between the output voltages of the sense and reference SC circuits under variation of the threshold capacitor in the reference SC circuit indicates that the capacitance mismatch between the two sense IOs (or between a sense IO and an on-chip capacitor) exceeds a predefined threshold. This reflects a significant change in the capacitance of the sense IO, potentially caused by PCB-level desoldering, resoldering, or probing attacks. Furthermore, the two capacitors in the reference SC circuit are partitioned into multiple sub-capacitors to form multiple sub-reference SC circuits. Together with the sense SC circuit, these structures constitute multiple SC PUF units that generate PUF keys strongly correlated with the parasitic capacitance of the sense IOs. The proposed anti–PCB-level attack scheme is fabricated in a 180nm CMOS process for silicon verification. Measurement results demonstrate that the SC PUF output keys effectively reflect IO capacitance variations caused by PCB-level attacks, thereby providing reliable protection for the chip against such attacks. Ming Zhang 0035, Zhen Zhang 0047, Zhangqing He, Meilin Wan |
IEEE Trans. Circuits Syst. I Regul. Pap. | 5 |
| 2026 | A Digital Compatible Offset Canceled Latch-Styled Sense Amplifier Used for PUF SensingabstractThe latch-styled sense amplifier (LSSA) is widely used to amplify the micro-output voltage of a physical unclonable function (PUF) due to its compact size and low cost. However, the offset in LSSA is large, and current methods for offset cancellation struggle to eliminate the offset caused by mismatches of the two input NMOS and two PMOS transistors while maintaining compatibility with both resistive and capacitive inputs. To address this issue, we store the offset introduced by the transistors in the two output capacitors and use two additional input capacitors to isolate the influence of the input signals’ DC voltage. Moreover, all circuits in the offset-canceled (OC) LSSA are constructed using MOS transistors with the minimum allowable length, allowing for the proposed OC LSSA to be easily realized using advanced FinFET processes and integrated into the chip through digital design flow. The proposed OC LSSA is integrated in a switched-capacitor (SC) PUF and fabricated using the 7 nm FinFET process, as well as the 28 nm and 180 nm standard CMOS processes. Test results verify the effectiveness of the offset cancellation method for the LSSA. The bit error rate (BER) across all working environments of the SC PUF using 7 nm, 28 nm, and 180 nm processes decreases from 21.98%, 14.10%, and 7.19% to 7.81%, 4.86%, and 1.88%, respectively, after applying the proposed offset cancellation LSSA to amplify its output voltage. Zhen Zhang 0047, Ming Zhang 0035, Zhangqing He, Meilin Wan |
IEEE Trans. Circuits Syst. I Regul. Pap. | 4 |
| 2026 | A High-Precision Reference-Free Relaxation Oscillator With Supply-Tracking Switching ThresholdabstractConventional relaxation oscillators typically rely on reference circuits to generate switching threshold voltages or charging currents, resulting in increased chip area and power consumption. This article presents a high-precision relaxation oscillator that eliminates the need for reference circuits. A holding capacitor is charged through a timing resistor, and the switching threshold voltage is directly derived from the power supply using a resistor divider. Since both the charging speed and the switching threshold voltage scale with$V_{\!D\!D}$, their dependencies cancel each other out, resulting in an oscillation period determined solely by the time constant of the holding capacitor and timing resistor. Moreover, the tracking behavior of the switching threshold with respect to$V_{\!D\!D}$further reduces the sensitivity of the comparator delay to supply voltage variations. A dual-path charge–discharge scheme is also employed to eliminate frequency deviations caused by digital logic delays and capacitor discharge time. Fabricated in a 110-nm CMOS process, the oscillator operates at 24.5 MHz with an active area of 0.026 mm2. Measurement results indicate a power consumption of$160~\mu $W and a maximum frequency error of 1.88% across a temperature range from −55 °C to 125 °C, corresponding to a temperature coefficient of 140 ppm/°C. When$V_{\!D\!D}$increases from 3.0 to 3.6 V, the output frequency variation is 0.4%. Chuanhang Shao, Zhen Zhang 0047, Jichao Sui, Ming Zhang 0035, Zhangqing He, Meilin Wan |
IEEE Trans. Very Large Scale Integr. Syst. | 7 |
| 2025 | Negative Input Protection Design of Power SwitchabstractA design method is presented to protect the power switch from negative voltage at the input power supply due to the connecting or disconnecting the power line. To ensure proper power supply acquisition under positive input conditions and isolation under negative input conditions, a negative input isolation circuit is first used for the non-power circuit. Then, two protective NMOS transistors are used to pull the gate and substrate of the power NMOS transistor to the negative VIN to prevent leakage current in the power NMOS transistor. At the same time, two simple switches which conduct under positive VIN and cutoff under negative VIN are used to effectively turn off the two protective NMOS transistors, preventing them from affecting the normal multi-mode operation of the power switch during positive VIN. This circuit does not require an additional positive voltage power supply and does not introduce voltage drop, providing negative protection for all devices and circuits between VIN and GND as well as between VIN and VOUT. The proposed power switch is implemented using a 180 nm BCD process, and the test results show that the power switch can effectively mitigate −5 V negative voltage at the input power supply. Meilin Wan, Yingchen Ma, Zhen Zhang 0047, Ming Zhang 0035, Zhangqing He |
IEEE Trans. Circuits Syst. I Regul. Pap. | 7 |
| 2024 | APLDP: Adaptive personalized local differential privacy data collection in mobile crowdsensing
Haina Song, Hua Shen 0006, Nan Zhao 0006, Zhangqing He, Minghu Wu, Wei Xiong 0004, Mingwu Zhang |
Comput. Secur. | 4 |
| 2024 | A 32-Bit Ripple-Ling Hybrid Carry AdderabstractThe low-order bits of the Ling adder are not on the critical path, eliminating the need for a carry lookahead method to calculate their output sums. In this paper, we propose a hybrid carry adder that combines high-order Ling and low-order ripple techniques. The low 11 bits of the adder utilize a ripple-carry structure, while the high 21 bits employ a Ling-based parallel prefix structure. This approach simplifies the low-order sum circuit without compromising the critical path length of the adder. Furthermore, new intermediate variables are introduced to facilitate Shannon expansion and enable efficient implementation of the output sum. This ensures that the control signal of the output MUX maintains a delay consistent with its input signal. The output sum circuit is further custom designed using reusable logic circuits. The proposed adder is verified using the conventional 180 nm and 28 nm processes, as well as the advanced 14 nm FinFET process, with the layout area as 4557.5$\mu $m$^{\mathbf{2}}$, 193.2$\mu $m$^{\mathbf{2}}$, and 73.8$\mu $m$^{\mathbf{2}}$, respectively. Testing results show that the maximum delay is 0.83 ns, 0.312 ns, and 0.183 ns respectively for the adder using 180 nm, 28 nm, and 14 nm processes respectively. The proposed adder provides an area optimization of approximately 10%$\sim$30% and optimizations of 10% in power and speed compared to the conventional Ling adder. Ning Shang 0003, Ruikang Liu, Zhangqing He, Meilin Wan |
IEEE Trans. Circuits Syst. I Regul. Pap. | 6 |
| 2024 | Enhancing the Reliability of SC PUF Through Optimal Capacitor ConfigurationabstractSwitched-capacitor (SC) PUF has been used in the protection of security chips from invasive attacks due to their capacitive sensitivity. However, non-volatile memory cells are often used to bypass the unstable SC PUF units, which then become insensitive to outside attacks, creating a vulnerability that can be exploited by probing or Focus Ion Beam (FIB) attacks, thereby posing a potential security risk if these units are used to cover sensitive areas of the security chip. This paper proposes a method to increase stability while maintaining anti-invasive-attack capabilities by utilizing the configurability of the four capacitors in each SC PUF unit, and selecting the configuration that provides a larger mismatch of capacitor ratios, resulting in a larger output voltage mismatch. By doing so, the variation of offset for the latch-styled sense amplifier (LSSA) is suppressed, and the stability of the SC PUF is significantly increased. Additionally, changing the polarity of the LSSA’s inputs to match its offset also increases the effective input voltage of the LSSA. The proposed SC PUF using optimal capacitor configuration is fabricated using a 12 nm FinFET CMOS process. Test results demonstrate that the bit error rate of the SC PUF is reduced from about 17% to about 1.5%, and most of the SC PUF units can serve as anti-invasive-attack shields of the security chip. Yingchen Ma, Ming Zhang 0035, Zhangqing He, Meilin Wan |
IEEE Trans. Circuits Syst. I Regul. Pap. | 5 |
| 2021 | A New Message Expansion Structure for Full Pipeline SHA-2abstractOnce there are constant or infrequently changed bits (COIBs) in two adjacent input messages of SHA-2, the switching power of input messages data registers (IMD-REGs) used for COIBs will disappear. Meanwhile, when full pipeline SHA-2 is applied in a certain application scenario where the IMD-REGs used for COIBs can be removed, more area of full pipeline SHA-2 can be saved as the proportion of IMD-REGs in message word registers increases. This paper proposes a new message expansion structure for full pipeline SHA-2 to increase the proportion of IMD-REGs. By inserting two expanders in last part of expansion structure pipeline stages and rescheduling the expander, the consumption rate of input messages will be decreased and the proportion of IMD-REGs will be increased. Compared with normal message expansion structure, the ratio of IMD-REGs to total message word registers in the proposed structure is increased from 15.1% to 41.6% for full pipeline SHA256, and 11.2% to 32.4% for full pipeline SHA512. When COIBs exists in adjacent input messages, the power and area advantages of proposed new message expansion structure have been demonstrated by FPGA and ASIC implementations. Zhangqing He, Meilin Wan, Muwen Zhan, Ming Zhang 0035, Kuang Peng, Haoshuang Gu |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2021 | A SC PUF Standard Cell Used for Key Generation and Anti-Invasive-Attack ProtectionabstractBy using metal blocks as the protective coating, placing the sensitive signals in last but second metal (LSM), integrating a low-cost one-time programming (OTP) cell in each PUF unit, the proposed switched-capacitor (SC) PUF can both provide sensitive anti-invasive-attack protective coating and stable key for the security chip. Moreover, the circuit parameters and the layout implementation of the SC PUF unit are all compatible with other digital standard cells, which greatly facilitates the integration of SC PUF unit in the security chip by using digital design flow when its function, timing, power, and layout views are characterized using commercial timing and layout extraction tools. The anti-invasive-attack ability, stability, and digital design flow compatibility of the proposed SC PUF standard cell are verified in a security chip by using a standard 0.18- μm CMOS process. The measured bit error rate, bias, average intra-die HD, and average inter-die HD of output keys after OTP is-4, 46.72%, 0%, and 50.38% respectively. Finally, the failed probing and destruction attack attempts to the coating also verify the invasive-attack-resistant property of the proposed SC PUF standard cell. With the help of SC PUF standard cell, the whole security chip can easily obtain stable keys and sensitive anti-invasive-attack ability by using digital design flow. Zhangqing He, Meilin Wan, Jiuyang Liu, Haoshuang Gu, Xuecheng Zou |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | A Reliable Strong PUF Based on Switched-Capacitor Circuit
Zhangqing He, Meilin Wan, Chuang Bai, Kui Dai |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2016 | Array Factor Forming for Image Reconstruction of One-Dimensional Nonuniform Aperture Synthesis RadiometersabstractNonuniform aperture synthesis radiometers (NASRs) have the advantage of flexibility in practical applications. However, the main limitation of NASRs for Earth observation is the poor reconstruction quality. In this letter, the array factor of 1-D NASR is analyzed. Array factor forming (AFF) is introduced to improve the reconstruction quality of 1-D NASRs. The limitations of the AFF on array configurations are given. The NASR that meets the given limitations is called the optimizable NASR (ONASR). The numerical results and experimental results demonstrate that the AFF is able to improve the reconstruction quality of 1-D ONASRs. To assess the performance of the AFF thoroughly, the comparisons are made against the linear interpolation and the regularized G-matrix method. Meanwhile, the comparisons between the AFF-based 1-D ONASRs and the 1-D uniform ASRs are also made. The comparison results demonstrate that the AFF can obtain better reconstruction quality than the linear interpolation and the regularized G-matrix method. Additionally, the comparison results also demonstrate that the reconstruction quality of AFF-based 1-D ONASRs can approach that of 1-D uniform ASRs. Li Feng 0002, Minghu Wu, Qingxia Li, Ke Chen 0014, Zhangqing He, Jing Tong, Lingying Tu, Honggang Xie, Hailiang Lu 0001 |
IEEE Geosci. Remote. Sens. Lett. | 6 |
| 2014 | A Compact Hardware Implementation of SM3 Hash FunctionabstractWith mobile and wireless devices becoming pervasive, low-cost hardwares of security functions are being desired. A compact hardware implementation of the SM3 hash algorithm is presented in this paper. A SRAM is used to do message expansion function instead of shift registers which are used in common hardware implementations, and the values of A~H and V0~V7 registers are updated in the serial shift way when they are initialized and updated. The computation units are saved as much as possible. Compared with traditional designs, the store resources for message expansion function can be shared with other modules to reduce the cost of a system. The Synopsys' DC synthesis results show that the area of the compact SM3 is approximate 8277 GEs while its throughput can be as high as 276 Mbps. If the SRAM is shared with other modules, only 6904 GEs are required to implement the SM3 hardware module in the system. The compact architecture can be accommodated to resource-constrained systems for its advantages of low-cost and low-power. Tianyong Ao, Zhangqing He, Jinli Rao, Kui Dai, Xuecheng Zou |
TrustCom | 2 |