EDBT 2026 Demo / reviewers in the wild / expert
Ckristian Duran
dblp:191/7585
· DBLP profile ↗
7ranked-venue papers
3as first author
5since 2021 · last 2024
0000-0003-3746-8320ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Unified OTP and PUF Exploiting Post-Program Current on Standard CMOS TechnologyabstractRoot-of-Trust (RoT) uses the hardware primitives to provide security in the integrated electronic systems, preventing attacks against the vital information of the system. The typical hardware primitives are used to generate random numbers and store the system's keys. However, the implementation of these primitives achieves challenges in the system due to the physical phenomena used to obtain the entropy for the random number. On the other hand, the non-volatile memories request special technologies with additional processes and layers. This work presents an implementation of a One-Time Program (OTP) memory using an Anti-Fuse (AF) methodology in 180nm standard CMOS technology. In addition, a Physical Unclonable Function (PUF) is unified, exploiting the post-program current generated in the OTP bit cell. A 128-bit OTP array and high-voltage driver are implemented without any special process and layer, occupying 68000μm2. On the other hand, the PUF implementation achieves 49.02% of uniformity, 49.52% of uniqueness, and 99.88% of reliability in the worst case with Process, Voltage, and Temperature (PVT) variations. In addition, the PUF reports a 2651F2/bit normalized area. The OTP memory application needs 6.7-V to program the AF bit cell. Ronaldo Serrano, Ckristian Duran, Marco Sarmiento, Khai-Duy Nguyen, Tetsuya Iizuka, Trong-Thuc Hoang, Cong-Kha Pham |
ISCAS | 2 |
| 2023 | In-NVRAM Unified PUF and TRNG Based on Standard CMOS TechnologyabstractHardware security primitives provide Root-of-Trust (RoT) procedures for booting, authentication, and key generation processes in secure integrated systems. The RoT requires True Random Number Generators (TRNGs), Physical Unclonable Functions (PUFs), and non-volatile memories for essential key generation and identity authentication. However, these implementations introduce challenges due to the physical phenomena used in each primitive, requiring complex calibration or special technologies with additional masks. In addition, the integration of separated implementations in a single system-on-a-chip increases the area overhead. This work describes a unified PUF-TRNG in a Non-Volatile Random Access Memory (NVRAM) implementation in 180-nm CMOS technology. The PUF and TRNG primitives are based on the NVRAM metastability in the sense amplifier. The TRNG passes the statistical and entropy tests provided by NIST SP800-22 and SP800-90B, respectively. In addition, the normalized minimum entropy of the TRNG is 0.987 in the worst case with PVT (Process, Voltage, and Temperature) variations. The PUF uniformity, uniqueness and reliability are 49.85%, 48.12% and 99.58%, respectively at nominal conditions. Moreover, the PUF reach$\mathbf{6735} F^{2}/\mathbf{bit}$normalized area11F2= (area)/(minimum feature size of the process)2. The NVRAM needs 8.5V for the programming and erasing modes. Finally, the unified implementation occupies$\mathbf{43155}\mu m^{2}$with$\mathbf{1332}kF^{2}$of normalized area. Ronaldo Serrano, Marco Sarmiento, Ckristian Duran, Tuan-Kiet Dang, Trong-Thuc Hoang, Cong-Kha Pham |
ISCAS | 3 |
| 2021 | System-on-Chip Implementation of Trusted Execution Environment with Heterogeneous ArchitectureabstractThis poster presents a Trusted Execution Environment (TEE) hardware implementation based on a heterogeneous architecture. The TEE verifies the integrity of software applications based on a chain of trust with the initial authentication. The chain-of-trust is implemented in software, using TEE hardware crypto-processors. The initial authentication is called the Root-of-Trust (RoT), and the isolated 32-bit system handles it. On the peripheral bus, there are several cryptography accelerators implemented such as SHA- 3, ED25519, AES, and a True Random Number Generator (TRNG). The TRNG module has not only the public channel over the peripheral bus but also a special private channel just for the isolated core. The proposed system was implemented in a 5mm x 5mm die by the 180-nm ROHM process library. Trong-Thuc Hoang, Ckristian Duran, Ronaldo Serrano, Marco Sarmiento, Khai-Duy Nguyen, Akira Tsukamoto, Kuniyasu Suzaki, Cong-Kha Pham |
HCS | 2 |
| 2021 | AES Sbox Acceleration Schemes for Low-Cost SoCsabstractCurrent solutions for low-cost and secure systems have ended up trading effective encryption schemes for lighter encryption schemes to ensure longevity in battery-powered applications. Here we demonstrate the potential to apply an effective and lighter encryption scheme, such as AES-256, in a low-cost battery-powered systems-on-chip (SoC) without demanding excessive energy. We accelerated AES-256 with a custom instruction along with an enhanced memory access scheme. Measurement results from a fabricated SoC featuring a RISC-V based 32-bit processor indicate a 900 fold improvement of AES-256 computing energy efficiency compared to pure-software implementations. The memory access improves the energy by 3 times an standard push-pull hardware implementation. Ckristian Duran, Elkim Roa |
ISCAS | 1 |
| 2021 | Routing-Aware Standard Cell Placement Algorithm Applying Boolean SatisfiabilityabstractAutomatic standard cell layout generation employs algorithms for transistor folding, placing, and routing. Reported standard transistor placement algorithms neglect to consider, in advance, the full netlist and the routing to generate clean layouts. Here, we introduce a placement algorithm with an optimization for complete routing and pre-layout algorithm awareness. The algorithm applies pseudo-boolean satisfiability to determine the minimum-width transistors in the cell. Placement optimization provides route-awareness to circumvent routing congestion according to pins location. The proposed algorithm is implemented in a full automatic standard cell generation procedure, fulfilling a commercial 180nm technology node design rules. Final generated layouts are 30% more routable than the base SAT formulations, enabling 100% routing in complex cells. Ckristian Duran, Elkim Roa |
ISCAS | 1 |
| 2020 | Simulation and Formal: The Best of Both Domains for Instruction Set Verification of RISC-V Based ProcessorsabstractThe instruction set architecture (ISA) specifies a contract between hardware and software; it covers all possible operations that have to be performed by a processor, regardless of the implemented architecture. Verifying the instruction execution against a golden execution model following the ISA is becoming a common practice to verify processors. Despite many potential applications, existing verification frameworks require an extensive test set to cover most of the processor states. In this paper, we suggest a verification scheme combining two different domains, simulation- and formal-verification, establishing a methodology for exclusive error detection. The first approach drives automatic program generation using genetic algorithms to maximize coverage of the test and the contrast against an instruction set simulator. The second is a formal verification approach, where an interface carries specific processor states according to the ISA specification. By combining these two, we present a reliable way to perform more accurate instruction verification by increasing processor state coverage and formal assertions to detect different kinds of errors. Compared to extensive torture test sets, this approach reaches a more significant number of internal states by taking advantage of the exercised abstractions. Among remarkable results to highlight, the proposed approach detected a RISC-V ISA specification gap revealing ambiguity from two different verification perspectives. Ckristian Duran, Hanssel Morales, Annachiara Ruospo, Ernesto Sánchez 0001, Elkim Roa |
ISCAS | 1 |
| 2020 | Cryptographic Accelerators for Trusted Execution Environment in RISC-V ProcessorsabstractThe trusted execution environment protects data by taking advantage of memory isolation schemes. Most of the software implementations on security enclaves offer a framework that can be implemented on any processor architecture. Assuming that privilege escalation is not possible through software means, the only way to access protected data is over authentication over a driver in kernel mode. However, the use of hardware back-doors cannot prevent processor execution in more privileged modes. Implementation of kernel-mode allows the reading of sensitive data over the protected regions of memory. In this work, a proposal of crypto-accelerator is described. The peripheral bus in the proposed architecture features a write-only secure memory. That means the cryptography operations on the software level can not read the sensitive data from that secure memory. This approach suppresses any cache coherence manipulator and fault execution-related attacks against reading sensitive data. The peripheral can be useful to accelerate the cryptography operations, and store securely intermediate calculations as well as storing secure keys. The time of execution compared to the software counterpart can be reduced down to 2.5 decades, and the throughput is risen to 3 decades, reaching speeds of 30MB/s for large chunks of data. The total area represents 10.7% of the total area of a dual-core RISC-V processor with RV64IMAFC extensions and TileLink buses. Trong-Thuc Hoang, Ckristian Duran, Akira Tsukamoto, Kuniyasu Suzaki, Cong-Kha Pham |
ISCAS | 2 |