Shoei Nashimoto

dblp:198/2302 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
2since 2021 · last 2025
0000-0002-7495-681XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Improving Fault Vulnerability Detection via Rehosting and Comparative Analysis of Open-Source Tools
abstract
Fault injection attacks pose a critical threat to embedded systems by intentionally inducing hardware-level disturbances that cause unintended program behavior. While software-based tools offer a fast and platform-independent approach for detecting such vulnerabilities, existing instruction set emulation (ISE)-based tools can produce misclassifications due to incomplete system emulation. Moreover, the lack of standardized benchmarks impedes fair evaluation of these tools.In this work, we address these limitations by introducing a rehosting technique that significantly improves the accuracy of ISE-based fault vulnerability detection. Our approach reconstructs memory and register states by executing the target binary in QEMU or native machine, capturing its runtime state, and importing it into the emulator. This enables accurate reproduction of system initialization, including ELF relocations, memory-mapped I/O, and architecture-specific alias regions.We conduct a comprehensive evaluation of seven open-source tools, including the state-of-the-art tool FaultFinder, using the Fault Injection and Simulation Secure Collection (FISSC) dataset and multiple fault models. Compared to the original FaultFinder, our rehosted version eliminates all false negatives related to state initialization and achieves 99%–100% recall while maintaining precision above 88%. Additionally, we construct a labeled benchmark dataset by aggregating and manually verifying the vulnerabilities detected by the tools, which reduces the manual inspection space—originally requiring full instruction coverage— by over 83%.Our findings establish a new baseline for fair and accurate evaluation of software-based fault vulnerability detection tools and demonstrate the effectiveness of rehosting in enhancing emulator fidelity.
Shoei Nashimoto
FDTC1
2024 Comparative Analysis and Implementation of Jump Address Masking for Preventing TEE Bypassing Fault Attacks
abstract
Attacks on embedded devices continue to evolve with the increasing number of applications in actual products. A trusted execution environment (TEE) enhances the security of embedded devices by isolating and protecting sensitive applications such as cryptography from malicious or vulnerable applications. However, the emergence of TEE bypass attacks using faults exposes TEEs to threats. In CHES’22, jump address masking (JAM) was proposed as a countermeasure against TEE bypass attacks, specifically targeting RISC-V. JAM prevents modifications of protected data by calculating jump addresses using the protected data, and is expected to provide promising resistance to TEE bypass attacks, for which traditional countermeasures are ineffective. However, JAM was originally proposed for bare metal applications. Therefore, its application to TEEs that operate with an OS presents technical and security challenges. This study proposes a method for applying JAM to Keystone, a major TEE framework for RISC-V, and validates its practical effectiveness and performance through a comparative evaluation with existing countermeasures such as memory encryption, random delays, and instruction duplication. Our evaluation reveals that the proposed JAM implementation is the first countermeasure that achieves complete resistance to TEE bypass attacks with an execution time overhead of approximately 340% for context switches and 1.0% across the entire program, which is acceptable compared with other countermeasures.
Shoei Nashimoto, Rei Ueno, Naofumi Homma
ARES1
2018 Sensor CON-Fusion: Defeating Kalman Filter in Signal Injection Attack
abstract
In recent years, information systems have become increasingly able to interact with the real world by using relatively cheap connected embedded devices. In such systems, sensors are crucial components because systems can observe the real world only through sensors. Recently, there have been emerging threats to sensors, which involve the injection of false information in the physical/analog domain. To counter such attacks, sensor fusion is considered a promising approach because the robustness of a measurement can be improved by combining data from redundant sensors. However, sensor fusion algorithms were not originally designed to consider security, and thus their effectiveness is unclear. For this reason, in this paper, we evaluate in detail the security of sensor fusion. Notably, we consider a sensor fusion scenario that involves measuring inclination, with a combination of an accelerometer, gyroscope, and magnetometer using Kalman filter. Based on a theoretical analysis of the algorithm, two concrete attacks that defeat the sensor fusion are proposed. The feasibility of the proposed attacks is verified by performing experiments in emulated and real environments. We also propose a countermeasure that thwarts the new attacks. Furthermore, we logically prove that the proposed countermeasure detects all possible attacks.
Shoei Nashimoto, Daisuke Suzuki, Takeshi Sugawara 0001, Kazuo Sakiyama
AsiaCCS1