Rajat Sadhukhan

dblp:201/6466 · DBLP profile ↗
← Back
11ranked-venue papers
7as first author
5since 2021 · last 2024
0000-0002-2922-9517ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 6 first-author · 3 since 2021Security and privacy · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 FHEDA: Efficient Circuit Synthesis with Reduced Bootstrapping for Torus FHE
abstract
Fully Homomorphic Encryption (FHE) schemes are widely used cryptographic primitives for performing arbitrary computations on encrypted data. However, FHE incorporates a computationally intensive mechanism called bootstrapping, that resets the noise in the ciphertext to a lower level allowing the computation on circuits of arbitrary depth. This process can take significant time, ranging from several minutes to hours. To address the above issue, in this work, we propose an Electronic Design Automation (EDA) framework$\mathsf{FHEDA}$that generates efficient Boolean representations of circuits compatible with the Torus-FHE (ASIACRYPT 2020) scheme. To the best of our knowledge, this is the first work in the EDA domain of FHE. We integrate logic synthesis and gate optimization techniques into our$\mathsf{FHEDA}$framework for reducing the total number of bootstrapping operations in a Boolean circuit, which leads to a significant (up to 50%) reduction in homomorphic computation time. Our$\mathsf{FHEDA}$is built upon the observation that in Torus-FHE two consecutive Boolean gate evaluations over fresh encryptions require only one bootstrapping instead of two, based on appropriate parameter choices. By integrating this observation with logic replacement techniques into$\mathsf{FHEDA}$, we could reduce the total number of bootstrapping operations along with the circuit depth. This eventually reduces the homomorphic evaluation time of Boolean circuits. In order to verify the efficacy of our approach, we assess the performance of the proposed EDA flow on a diverse set of representative benchmarks including privacy-preserving machine learning and different symmetric key block ciphers.
Smita Das, Anirban Chakraborty 0003, Rajat Sadhukhan, Ayantika Chatterjee, Debdeep Mukhopadhyay
EuroS&P4
2024 VALIANT: An EDA Flow for Side-Channel Leakage Evaluation and Tailored Protection
abstract
Power side-channels give rise to several potent attack vectors for leaking information in digital circuits. While a plethora of (mathematically robust) solutions exist to tackle such side-channels, their deployment through existing VLSI design-flows remains an important engineering issue. Besides, most existing solutions result in significant hardware overhead hindering their practical usage for resource-constrained settings, such as Internet-of-Things (IoT) or embedded devices. In this paper, we address both of these issues through an integrated electronic design automation (EDA) tool-flow operating on gate-level designs. Based on an interesting observation that not every net in a design is equally susceptible to side-channel leakage, we devise a generic testing mechanism and lightweight albeit customizable protection strategy for a given trace count. We first analytically establish the observation based on certain physical properties of VLSI circuits and also validate it on ISCAS benchmark circuits. Next, we present a tool calledVALIANT, which can identify the leaking nets for a given number of traces from the gate-level netlist of a cipher.VALIANTworks alongside state-of-the-art design automation tools and, therefore, can be directly incorporated in existing design flows. After identifying the leaky subset of nets in a design, we propose a lightweight variant of an existing masking scheme to eliminate the leakage concerning a given trace count. The main feature of our protection scheme is that it takes into account subset of nets are not “leaky” and optimizes the usage of randomness and extra gates according to this information to minimize the overhead. Experimental evaluation over state-of-the-art lightweight S-Boxes and the GIFT block cipher establishes the efficacy of the proposed idea for generating lightweight protected solutions in an automated manner.
Rajat Sadhukhan, Sayandeep Saha, Sudipta Paria, Swarup Bhunia, Debdeep Mukhopadhyay
IEEE Trans. Computers1
2022 AntiSIFA-CAD: A Framework to Thwart SIFA at the Layout Level
abstract
Fault Attacks (FA) have gained a lot of attention from both industry and academia due to their practicality, and wide applicability to different domains of computing. In the context of symmetric-key cryptography, designing countermeasures against FA is still an open problem. Recently proposed attacks such as Statistical Ineffective Fault Analysis (SIFA) has shown that merely adding redundancy or infection-based countermeasure to detect the fault doesn't work and a proper combination of masking and error correction/detection is required. In this work, we show that masking which is mathematically established as a good countermeasure against a certain class of SIFA faults, in practice may fall short if low-level details during physical design layout development are not taken care of. We initiate this study by demonstrating a successful SIFA attack on a post placed-and-routed masked crypto design for ASIC platform. Eventually, we propose a fully automated approach along with a proper choice of placement constraints which can be realized easily for any commercial CAD tools to successfully get rid of this vulnerability during the physical layout development process. Our experimental validation of our tool flow over masked implementation on PRESENT cipher establishes our claim.
Rajat Sadhukhan, Sayandeep Saha, Debdeep Mukhopadhyay
ICCAD1
2022 A Classical and Machine Learning-Based Reliability Analysis on Catalan Object Encryption Scheme
abstract
Designinglightweightsecure cryptographic schemes for Internet of Things (IoT) and radio frequency identification (RFID)-based devices is challenging as a designer needs to address resource-constraints along with physical and classical security notions. Even though plethora of such lightweight encryption schemes have been proposed in the literature, computationally efficient attacks on some has also been published, which stresses the fact that robust and reliable design paradigms to consider during design process. In this article, using classical methods, we launched the full-key attack on a Catalan-object-based encryption scheme proposed by Saracevicet al.(2020) inIEEE Transactions on Reliability. Their proposed encryption scheme is efficient and lightweight specifically meant for IoT applications and is based upon combinatorial structure of Catalan key objects. We proved data privacy violation and recover the full encryption-key with computationally efficient algorithm. We also proposed the machine-learning-based regression model to efficiently predict all bits of ciphertext using just a single plaintext without any key. A high correlation between plaintext and ciphertext and full-key recovery poses the encryption scheme to be unreliable to be used for IoT-based applications. To the best of authors’ knowledge, this is the first work on reliability analysis on Catalan-based encryption schemes.
Rajat Sadhukhan
IEEE Trans. Reliab.1
2021 Shortest Path to Secured Hardware: Domain Oriented Masking with High-Level-Synthesis
abstract
Implementing hardware secure against side-channel attacks (SCA) demands significant time and expertise in hardware design. In this paper, we propose a simple and fast approach for synthesizing masked block cipher hardware from a C-code exploiting High-Level-Synthesis (HLS), which allows a very short design time. Compared to previous approaches, our proposal provides a systematic and general flow based on state-of-the-art Domain-Oriented Masking (DOM). We also present a fast security-validation flow for the synthesized circuits at the early design stages using commercial-off-the-shelf CAD tools. Efficacy of the proposed design-flow has been established over a set of representative benchmarks including a masked S-Box and a lightweight block-cipher.
Rajat Sadhukhan, Sayandeep Saha, Debdeep Mukhopadhyay
DAC1
2020 Design Automation for Side Channel Resistant Lightweight Cryptography
abstract
The scaling of devices in loT era has opened doors to broad range of privacy and security concerns making it vulnerable to various side channel attacks (SCA) and differential fault attacks (DFA). The generic EDA flows provide powerful solutions for simulation, verification, power, performance and area (PPA) optimizations. But these flows are not enabled to detect side channel leakages or provide countermeasures or handle huge search space under both lightweightedness and security dimension paradigm. So, we propose to augment classical EDA flow with security aware notion addressing the challenges wrt primitive design, SCA and DFA thereby helping crypto-designers to reduce overall design cycle-time and early detection of security flaws in lightweight design and provide countermeasure.
Rajat Sadhukhan, Debdeep Mukhopadhyay
VLSI-SOC1
2019 United We Stand: A Threshold Signature Scheme for Identifying Outliers in PLCs
abstract
This work proposes a scheme to detect, isolate and mitigate malicious disruption of electro-mechanical processes in legacy PLCs where each PLC works as a finite state machine (FSM) and goes through predefined states depending on the control flow of the programs and input-output mechanism. The scheme generates a group-signature for a particular state combining the signature shares from each of these PLCs using (k,l)-threshold signature scheme. If some of them are affected by the malicious code, signature can be verified by k out of l uncorrupted PLCs and can be used to detect the corrupted PLCs and the compromised state. We use OpenPLC software to simulate Legacy PLC system on Raspberry Pi and show I/O pin configuration attack on digital and pulse width modulation (PWM) pins. We describe the protocol using a small prototype of five instances of legacy PLCs simultaneously running on OpenPLC software. We show that when our proposed protocol is deployed, the aforementioned attacks get successfully detected and the controller takes corrective measures. This work has been developed as a part of the problem statement given in the Cyber Security Awareness Week-2017 competition.
Urbi Chatterjee, Pranesh Santikellur, Rajat Sadhukhan, Vidya Govindan, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty
DAC3
2019 Count Your Toggles: a New Leakage Model for Pre-Silicon Power Analysis of Crypto Designs
Rajat Sadhukhan, Paulson Mathew, Debapriya Basu Roy, Debdeep Mukhopadhyay
J. Electron. Test.1
2019 Building PUF Based Authentication and Key Exchange Protocol for IoT Without Explicit CRPs in Verifier Database
abstract
Physically Unclonable Functions (PUFs) promise to be a critical hardware primitive to provide unique identities to billions of connected devices in Internet of Things (IoTs). In traditional authentication protocols a user presents a set of credentials with an accompanying proof such as password or digital certificate. However, IoTs need more evolved methods as these classical techniques suffer from the pressing problems of password dependency and inability to bind access requests to the “things” from which they originate. Additionally, the protocols need to be lightweight and heterogeneous. Although PUFs seem promising to develop such mechanism, it puts forward an open problem of how to develop such mechanism without needing to store the secret challenge-response pair (CRP) explicitly at the verifier end. In this paper, we develop an authentication and key exchange protocol by combining the ideas of Identity based Encryption (IBE), PUFs and Key-ed Hash Function to show that this combination can help to do away with this requirement. The security of the protocol is proved formally under the Session Key Security and the Universal Composability Framework. A prototype of the protocol has been implemented to realize a secured video surveillance camera using a combination of an Intel Edison board, with a Digilent Nexys-4 FPGA board consisting of an Artix-7 FPGA, together serving as the IoT node. We show, though the stand-alone video camera can be subjected to man-in-the-middle attack via IP-spoofing using standard network penetration tools, the camera augmented with the proposed protocol resists such attacks and it suits aptly in an IoT infrastructure making the protocol deployable for the industry.
Urbi Chatterjee, Vidya Govindan, Rajat Sadhukhan, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty, Debashis Mahata, Mukesh M. Prabhu
IEEE Trans. Dependable Secur. Comput.3
2019 Power Efficiency of S-Boxes: From a Machine-Learning-Based Tool to a Deterministic Model
abstract
Designing cryptographically good and power-efficient 4 × 4 S-boxes is a challenging problem in the era of lightweight cryptography. Although the optimal cryptographic properties are easy to determine, verifying the power efficiency of an S-box is nontrivial. The conventional approach of determining the power consumption using commercially available CAD tools is highly time-consuming, which becomes formidable while dealing with a large pool of S-boxes. This mandates the development of automation that should quickly characterize the power efficiency from the Boolean function representation of an S-box. In this paper, we present a supervised machine-learning-assisted automated framework to resolve the problem for 4 × 4 S-boxes, which turns out to be 14 times faster than the traditional approach. The key idea is to extrapolate the knowledge of literal counts, AND-OR-NOT gate counts in the sum-of-products (SOP) form of the underlying Boolean functions to predict the dynamic power efficiency. We demonstrate the effectiveness of our framework by reporting on a set of power-efficient (involutive) optimal S-boxes from a large set of S-boxes. We also develop a deterministic model using results obtained from supervised learning to predict the dynamic power of an S-box that can be used in an evolutionary algorithm to generate cryptographically good and low-power S-boxes.
Rajat Sadhukhan, Nilanjan Datta, Debdeep Mukhopadhyay
IEEE Trans. Very Large Scale Integr. Syst.1
2018 DFARPA: Differential fault attack resistant physical design automation
abstract
Differential Fault Analysis (DFA), aided by sophisticated mathematical analysis techniques for ciphers and precise fault injection methodologies, has become a potent threat to cryptographic implementations. In this paper, we propose, to the best of the our knowledge, the first “DFA-aware” physical design automation methodology, that effectively mitigates the threat posed by DFA. We first develop a novel floorplan heuristic, which resists the simultaneous corruption of cipher states necessary for successful fault attack, by exploiting the fact that most fault injections are localized in practice. Our technique results in the computational complexity of the fault attack to shoot up to exhaustive search levels, making them practically infeasible. In the second part of the work, we develop a routing mechanism, which tackles more precise and costly fault injection techniques, like laser and electromagnetic guns. We propose a routing technique by integrating a specially designed ring oscillator based sensor circuit around the potential fault attack targets without incurring any performance overhead. We demonstrate the effectiveness of our technique by applying it on state of the art ciphers.
Mustafa Khairallah, Rajat Sadhukhan, Radhamanjari Samanta, Jakub Breier, Shivam Bhasin, Rajat Subhra Chakraborty, Anupam Chattopadhyay, Debdeep Mukhopadhyay
DATE2