Jiaji He 0001

dblp:206/6467-1 · DBLP profile ↗
← Back
28ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0003-1443-9279ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 22 · 8 first-author · 17 since 2021Security and privacy · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021
YearPublicationVenuePosition
2026 X-Matrix Shield: Defeating Tilted FIB and Rerouting Attacks through 3D-Interlaced Protection
abstract
As focused ion beam (FIB) technology advances and invasive attack methods evolve, tilted FIB and rerouting attacks pose serious threats to chip security. Existing single-layer active shields exhibit inherent limitations in defending against these advanced invasive attacks. This paper presents the X-Matrix Shield, a dual-layer structure that fortifies integrated circuits against sophisticated physical tampering. This research establishes a novel information theory-based evaluation framework with quantifiable direction entropy metrics. Additionally, the work develops an improved artificial fish-swarm algorithm (DAFSA) to generate optimized 3D-interlaced protection paths. X-Matrix Shield can be directly integrated into the standard EDA layout flow, enabling security-aware physical design co-optimization. When implemented in 55 nm standard process technology, the X-Matrix Shield achieves a quality metric of $\mathbf{1. 9 9}$. GDS3D simulations of protected AES modules further confirm the shield’s effectiveness against advanced physical attacks compared to single-layer protection.
Jiaji He 0001, Junfeng Cai, Mao Ye 0007, Yongqiang Lyu 0001
ASP-DAC1
2026 SCPrompt: Semantic Compression and Prompt-Guided LLM Reasoning for RTL Trojan Detection
abstract
The increasing scale and complexity of integrated circuit (IC) designs present significant challenges to hardware security. Hardware Trojans (HTs)-stealthy, malicious alterations to hardware logic-are especially difficult to detect at the register-transfer level (RTL), where both structural and semantic understanding are essential. While recent advances have explored the use of large language models (LLMs) for RTL analysis, their performance is often constrained by token limits and a lack of targeted semantic abstraction. To overcome these limitations, we propose SCPrompt, a novel and extensible framework that, for the first time, integrates RTL instance-level compression with prompt-guided LLM reasoning for hardware Trojan detection. SCPrompt compresses RTL inputs by over 90%, significantly reducing prompt length while retaining critical control and data flow semantics. This enables LLMs to perform accurate Trojan analysis without taskspecific fine-tuning. Unlike prior binary classification approaches, SCPrompt supports instance-grained localization of suspicious logic components, identifying both trigger and payload modules within a design. Evaluated on 51 RTL designs with hardware Trojans inserted, our method achieves up to 100% precision, 90% recall, and an F1 score of 94.74%, demonstrating strong generalization across diverse circuits. These results validate SCPrompt as the first effective and scalable framework to unify RTL feature engineering with general-purpose language model reasoning for advanced hardware security analysis.
Jiaji He 0001, Yongqiang Lyu 0001
ASP-DAC1
2026 Ring-oscillator-assisted CTR_DRBG on FPGA with improved statistical properties
Tianhao Yan, Xianli Xie, Penghui Guan, Jiaji He 0001
Integr.8
2025 EO-Shield: A Shield-Based Protection Scheme Against Both Invasive and Non-Invasive Attacks
abstract
Smart devices, especially Internet-connected devices, typically incorporate security protocols and cryptographic algorithms to ensure the control flow integrity and information security. However, various types of attacks try to tamper with these devices, including invasive and non-invasive. Chip-level shields have been proven effective against invasive attacks, but the potential of shields as a protection mechanism against side-channel analysis (SCA) attacks remains under-explored. To bridge this gap, we propose a shield-based multi-functional protection scheme, named EO-Shield, capable of simultaneously thwarting invasive and non-invasive attacks. EO-Shield is implemented using the chip’s top metal layer and includes an Information Leakage Obfuscation Module (ILOM) underneath. This module generates its protection patterns based on the operating conditions of the circuit that need to be protected, thus reducing the correlation between electromagnetic (EM) emanations and cryptographic data. Additionally, we introduce a simulation technique to test the protection efficacy of EO-Shield at the layout level, utilizing commercial Electronic Design Automation (EDA) tools and the EMSim/EMSim+ tool. Simulation experiments demonstrate that the ILOM decreases the signal-to-noise (SNR) ratio to below 0.6 and improves the difficulty of SCA attacks by more than 100 times. Compared to existing single-function protection methods against physical attacks, EO-Shield leverages the EM protection potential of shields to offer multi-functional protection.
Ya Gao 0007, Qizhi Zhang 0001, Xintong Song, Haocheng Ma, Jiaji He 0001, Yiqiang Zhao
IEEE Trans. Circuits Syst. I Regul. Pap.5
2025 Boosting Cryptographic ICs' Side-Channel Resistance: A Formal Framework for Automatic Identification and Protection of Leaky Paths
abstract
Side-channel analysis (SCA) attacks pose a significant threat to cryptographic integrated circuits (ICs). While designers have endeavored to introduce various countermeasures during the IC development phase, many of these solutions incur substantial overheads in terms of area, power, and performance. Additionally, they often necessitate a full-custom circuit design for effective deployment. This issue arises due to the absence of systematic methodologies and analytical tools for circuit designers to accurately identify the sources of side-channel leakage within the hardware design. In this article, we propose the concept of side-channel tracking logic and, building upon this foundation, introduce a novel framework that seamlessly integrates with commercial design flows to automatically identify and safeguard leaky paths. Our approach begins by pinpointing partial logic cells that exhibit the highest information leakage using dynamic correlation analysis. Subsequently, formal-based leakage property checking constructs comprehensive leaky paths centered on these cells. In this process, side-channel tracking logic was proposed and applied for the first time to trace and extract side-channel leakage paths. Based on this, an automated formal modeling and leakage property verification tool was designed. Once these paths are discerned, we deploy apt hardware countermeasures, encompassing Boolean masking and random precharge, to eradicate information leakage along these routes. This framework has been experimentally validated across different encryption circuits and the efficacy of our methodology is corroborated through both simulated and real-world measurements on FPGA implementations. Empirical results showcase an enhancement of over 1000× in side-channel resistance, incurring a modest overhead of less than 6.53% across power, area, and performance metrics.
Qizhi Zhang 0001, Ya Gao 0007, Haocheng Ma, Jiaji He 0001, Yiqiang Zhao, Xiaolong Guo 0001
ACM Trans. Embed. Comput. Syst.4
2024 Static Gate-Level Information Flow for Hardware Information Security with Bounded Model Checking
abstract
Information flow security is an essential component of hardware security. Ensuring the confidentiality, integrity, and availability of data within hardware systems is critical to protect against unauthorized access, data breaches, tampering, and other security threats. Gate-level information flow technology can trace the flow of signals to detect malicious information flow and security vulnerabilities in the design. In this paper, we introduce a novel framework that combines GLIFT and bounded model checking to enable the static verification of information flow within hardware systems. This combination facilitates designers conducting exhaustive analysis, tracking of information flows and detecting potential security threats in their designs. When the design violates security policies, our framework provides a counterexample that assists designers in identifying malicious information flows in the hardware circuits. To demonstrate the efficiency of our framework, we conducted verification on hardware Trojan benchmarks from the Trust-hub. The results indicate that our verification framework is capable of detecting malicious information flows that exist in the designs.
Yiqiang Zhao, Gonsen Qu, Qizhi Zhang 0001, Yao Li 0024, Jiaji He 0001
VTS6
2024 EMSim+: Accelerating Electromagnetic Security Evaluation With Generative Adversarial Network and Transfer Learning
abstract
Electromagnetic side-channel analysis (EM SCA) attack poses a serious threat to integrated circuits (ICs), necessitating timely vulnerability detection before deployment to enhance EM side-channel security. Various EM simulation methods have emerged for analyzing EM side-channel leakage, providing sufficiently accurate results. However, these simulator-based methods still face two principal challenges in the design process of high security chips. Firstly, the large volume of measurement data required for a single security evaluation results in substantial time overhead. Secondly, design iterations lead to repetitive security evaluations, thus increasing the evaluation cost. In this paper, we propose EMSim+ which includes two efficient and accurate layout-level EM side-channel leakage evaluation frameworks named EMSim+GAN and EMSim+GAN+TL to mitigate the above challenges, respectively. EMSim+GAN integrates a Generative Adversarial Network (GAN) model that utilizes the chip’s cell current and power grid information to predict EM emanations quickly. EMSim+GAN+TL further incorporates transfer learning (TL) within the framework, leveraging the experience of existing designs to reduce the training datasets for new designs and achieve the target accuracy. We compare the simulation results of EMSim+ with the state-of-the-art EM simulation tool, EMSim as well as silicon measurements. Experimental results not only prove the high efficiency and high simulation accuracy of EMSim+, but also verify its generalization ability across different designs and technology nodes.
Ya Gao 0007, Haocheng Ma, Qizhi Zhang 0001, Xintong Song, Yier Jin, Jiaji He 0001, Yiqiang Zhao
IEEE Trans. Inf. Forensics Secur.6
2024 A CMOS Readout Circuit for Resistive Tactile Sensor Array Using Crosstalk Suppression and Nonuniformity Compensation Techniques
abstract
This article presents a novel readout circuit for the resistive tactile sensor array. Based on the 2-D scanning mechanism, a crosstalk suppression technique is proposed by combining the correlated double sampling (CDS) and zero potential method (ZPM). The output of the same sensor under different bias conditions is captured twice and amplified by a channel-parallel fully differential gain stage, performing analogous subtraction. To achieve nonuniformity compensation, the current injected into the readout channel is adjusted by the channel-parallel digital-to-analog converter (DAC). A successive approximation register (SAR) analog-to-digital converter (ADC) performs quantization, and the chip can be used as a serial peripheral interface (SPI) slave to update register values for gain configuration, power consumption control, and nonuniformity compensation. The 180-nm CMOS prototype chip occupies an area of$4.8~\text {mm}^{2}$and consumes$285~\mu $W. In order to validate the design, a tactile sensing system is built, using the readout circuit along with a$10\times 10$flexible sensor array. With the techniques proposed in this article, the readout error of the sensors in array is less than 0.3‰.
Yao Li 0024, Junfeng Geng, Mao Ye 0007, Jiaji He 0001, Xiaoxiao Zheng, Qiuwei Wang, Yiqiang Zhao
IEEE Trans. Very Large Scale Integr. Syst.4
2023 EO-Shield: A Multi-Function Protection Scheme against Side Channel and Focused Ion Beam Attacks
abstract
Smart devices, especially Internet-connected devices, typically incorporate security protocols and cryptographic algorithms to ensure the control flow integrity and information security. However, there are various invasive and non-invasive attacks trying to tamper with these devices. Chip-level active shield has been proved to be an effective countermeasure against invasive attacks, but existing active shields cannot be utilized to counter side-channel attacks (SCAs). In this paper, we propose a multi-function protection scheme and an active shield prototype to against invasive and non-invasive attacks simultaneously. The protection scheme has a complex active shield implemented using the top metal layer of the chip and an information leakage obfuscation module underneath. The leakage obfuscation module generates its protection patterns based on the operating conditions of the circuit that needs to be protected, thus reducing the correlation between electromagnetic (EM) emanations and cryptographic data. We implement the protection scheme on one Advanced Encryption Standard (AES) circuit to demonstrate the effectiveness of the method. Experiment results demonstrate that the information leakage obfuscation module decreases SNR below 0.6 and reduces the success rate of SCAs. Compared to existing single-function protection methods against physical attacks, the proposed scheme provides good performance against both invasive and non-invasive attacks.
Ya Gao 0007, Qizhi Zhang 0001, Haocheng Ma, Jiaji He 0001, Yiqiang Zhao
ASP-DAC4
2023 EMSim+: Accelerating Electromagnetic Security Evaluation with Generative Adversarial Network
abstract
Electromagnetic side-channel analysis (EM SCA) attack is a serious threat to integrated circuits (ICs). In order to detect vulnerabilities in time at the pre-silicon stage and to improve the chip's robustness to EM SCA attacks, several EM simulation methods have emerged for EM side-channel leakage evaluation. Although the simulated results are accurate, the chip security evaluation in practice requires up to hundreds of millions simulation traces, which imposes an unrealistic computational and time overhead on these simulator-based methods. In this paper, we develop a tool named EMSim+. Different from the general EM security evaluation process, EMSim+ introduces machine learning (ML) to accelerate the simulation of layout-level EM emanations. Based on the generative adversarial network (GAN), a well-trained EMSim+ model can accept the cell current and power grid information of the chip and rapidly predict the EM emanation of the chip surface. We apply EMSim+ to a series of representative cryptographic circuits and compare the simulation results with the state-of-the-art EM simulation method and silicon measurements. The experimental results prove that EMSim+ has high simulation accuracy and achieves more than 242 times evaluation time reduction for 1 M sample data.
Ya Gao 0007, Haocheng Ma, Jindi Kong, Jiaji He 0001, Yiqiang Zhao, Yier Jin
ICCAD4
2023 Side Channel Security Oriented Evaluation and Protection on Hardware Implementations of Kyber
abstract
The emergence of quantum computing and its impact on current cryptographic algorithms has triggered the migration to post-quantum cryptography (PQC). Among the PQC candidates, CRYSTALS-Kyber is a key encapsulation mechanism (KEM) that stands out from the National Institute of Standards and Technology (NIST) standardization project. While software implementations of Kyber have been developed and evaluated recently, Kyber’s hardware implementations especially those designed with parallel architecture, are rarely discussed. To help better understand Kyber hardware designs and their security against side-channel analysis (SCA) attacks, in this paper, we first adapt the two most recent Kyber hardware designs for FPGA implementations. We then perform SCA attacks against these hardware designs with different architectures, i.e., parallelization and pipelining. Our experimental results show that Kyber designs on FPGA boards are vulnerable to SCA attacks including electromagnetic (EM) and power side channels. An attacker only needs$27 \sim 1,600$power traces or$60 \sim 2,680$EM traces to recover the decryption key successfully. Furthermore, we propose two first-order IND-CPA Kyber decapsulation masking protected designs, and then we evaluate their securities and overheads. The experimental results demonstrate that the side channel security of masked Kyber designs has increased by more than 10x.
Yiqiang Zhao, Shijian Pan, Haocheng Ma, Ya Gao 0007, Xintong Song, Jiaji He 0001, Yier Jin
IEEE Trans. Circuits Syst. I Regul. Pap.6
2023 EMSim: A Fast Layout Level Electromagnetic Emanation Simulation Framework for High Accuracy Pre-Silicon Verification
abstract
Electromagnetic (EM) emanation measurement and evaluation is one important testing for modern integrated circuits (ICs). Severe electromagnetic interference may degrade the performance of electronic devices or even cause system crashes. As a result, modern ICs need to follow strict electromagnetic compatibility (EMC) requirements. Moreover, EM emanations offer a covert channel for adversaries to steal secret information from fabricated ICs, causing side channel attacks. Due to the lack of fast and high-accuracy EM simulation tools, existing EM measurements often happen at the post-silicon stage. Any identification of side channel vulnerability or EM incompatibility may lead to high cost and delay the time-to-market. As a result, design-time EM simulation tools with fast simulation speed and high accuracy for pre-silicon designs are urgently needed. To this end, we propose EMSIM, a layout-level EM simulation framework that significantly speeds up the EM simulation process while maintaining high accuracy of the simulated EM emanations. To achieve this goal, we provide the theoretical explanation for the root cause of EM emanations from ICs. Guiding by this, EMSIM leverages techniques of parasitic network reduction and device model approximation to reduce the computation complexities while still ensuring high simulation accuracy. EMSIM further leverages Graphics Processing Unit (GPU) resources to solve equations for EM simulation. The efficiency and effectiveness of EMSIM are validated by showing the consistency between simulation results and physical measurements obtained from fabricated circuit designs.
Haocheng Ma, Max Panoff, Jiaji He 0001, Yiqiang Zhao, Yier Jin
IEEE Trans. Inf. Forensics Secur.3
2022 PathFinder: side channel protection through automatic leaky paths identification and obfuscation
abstract
Side-channel analysis (SCA) attacks show an enormous threat to cryptographic integrated circuits (ICs). To address this threat, designers try to adopt various countermeasures during the IC development process. However, many existing solutions are costly in terms of area, power and/or performance, and may require full-custom circuit design for proper implementations. In this paper, we propose a tool, namely PathFinder, to automatically identify leaky paths and protect the design, and is compatible with the commercial design flow. The tool first finds out partial logic cells that leak the most information through dynamic correlation analysis. PathFinder then exploits static security checking to construct complete leaky paths based on these cells. After leaky paths are identified, PathFinder will leverage proper hardware countermeasures, including Boolean masking and random precharge, to eliminate information leakage from these paths. The effectiveness of PathFinder is validated both through simulation and physical measurements on FPGA implementations. Results demonstrate more than 1000X improvements on side-channel resistance, with less than 6.53% penalty to the power, area and performance.
Haocheng Ma, Qizhi Zhang 0001, Ya Gao 0007, Jiaji He 0001, Yiqiang Zhao, Yier Jin
DAC4
2022 An energy-efficient dynamically reconfigurable cryptographic engine with improved power/EM-side-channel-attack resistance
Chenchen Deng, Min Zhu 0001, Jinjiang Yang, Youyu Wu, Jiaji He 0001, Bohan Yang 0001, Jianfeng Zhu 0001, Shouyi Yin, Shaojun Wei, Leibo Liu
Sci. China Inf. Sci.5
2022 Security Oriented Design Framework for EM Side-Channel Protection in RTL Implementations
abstract
Electromagnetic (EM) side-channel analysis is a powerful attack for extracting secret information from cryptographic hardware implementations. Countermeasures have been proposed at the register-transfer level (RTL), layout level, and device level. However, existing EM radiation modeling and side-channel vulnerability mitigation methods do not consider the structural resilience of original designs, nor do they provide fine-grained security enhancements to those vulnerable submodules/components. These universal solutions may introduce unnecessary overheads on the circuit under protection and may not be optimized for individual designs. In this article, we propose a design/synthesis for side-channel security evaluation and optimization framework based on the${t}$-test evaluation results derived from RTL hardware implementations. While the framework apply to different side-channel leakage, we focus more on EM side channels. Supported by this framework, different RTL implementations of the same cryptographic algorithm will be evaluated for their side-channel resistance. In vulnerable implementations, submodules with the most significant side-channel leakages will be identified. Security design/synthesis rules will then be applied to these vulnerable submodules for security enhancements against side-channel attacks (SCAs). Experiments, including simulations and FPGA implementations on different AES designs, are performed to validate the effectiveness of the proposed framework as well as the security design/synthesis rules.
Jiaji He 0001, Haocheng Ma, Max Panoff, Hanning Wang, Yiqiang Zhao, Leibo Liu, Xiaolong Guo 0001, Yier Jin
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2022 A Comprehensive Evaluation of Integrated Circuits Side-Channel Resilience Utilizing Three-Independent-Gate Silicon Nanowire Field Effect Transistors-Based Current Mode Logic
abstract
Side-channel attack (SCA) is one of the physical attacks, which will reveal the confidential information from cryptographic circuits by statistically analyzing physical manifestations. Various circuit-level countermeasures have been proposed as fundamental solutions to eliminate the correlations between side-channel information and circuit’s internal operations. The existing solutions, however, will introduce nonnegligible power and area overheads, making them difficult to be deployed in resource-constrained applications. In this article, a novel three-independent-gate silicon nanowire field effect transistor (TIGFET) with the intrinsic SCA-resilience characteristics is introduced to balance the tradeoffs among cost, performance, and security of cryptographic implementations. We construct six TIGFET-based current mode logic (CML) gates that can retain lower power variation under all possible transitions compared to the CMOS counterparts. As a proof of concept, advanced encryption standard (AES), SM4 block cipher algorithm (SM4), and lightweight cryptographic algorithm PRESENT are implemented utilizing the TIGFET-based CML gates. Correlation power attack is performed to evaluate the improvement of SCA resilience. Simulation results verify that the TIGFET-based cryptographic implementations decrease 42.37% area usage, lower 61.16% energy efficiency, reduce$5.35\times $power variation, and achieve a similar level of SCA resistance compared to the CMOS counterpart, which is applicable for the resource-constrained applications.
Yanjiang Liu, Jiaji He 0001, Haocheng Ma, Tongzhou Qu, Zibin Dai
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2021 On-Chip Trust Evaluation Utilizing TDC-Based Parameter-Adjustable Security Primitive
abstract
Field-programmable gate arrays (FPGAs) are integrated circuits (ICs) that can be reconfigured to the desired functionalities, without manufacturing dedicated chips. Due to their programmable nature, FPGAs have been prevalent in the large majority of modern systems. This raises high demands for verifying the security of circuit implementations on FPGAs, since they are vulnerable to hardware trojans (HTs) that can be inserted through modified configuration files. In this article, we propose an on-chip security framework to ensure the trustworthiness of circuit implementations on FPGAs at runtime. The core of the framework is a time-to-digital converter (TDC)-based hardware security primitive that can be predeployed on FPGAs to verify whether the FPGA-based designs are tampered with or corrupted by HTs. The parameter-adjustable TDC sensor, which is the primary component of the primitive, is carefully designed, adjusted, and implemented, thus the TDC sensor can monitor the transient voltage fluctuations within FPGAs with a high resolution. Versus statistical data analysis, tiny abnormal variations introduced by the Trojan insertion and activation are distinguished. Experimental results on Xilinx Spartan-6 FPGAs demonstrate the effectiveness of the proposed TDC-based on-chip trust evaluation framework and HT detection method.
Haocheng Ma, Jiaji He 0001, Yanjiang Liu, Jun Kuai, He Li 0008, Leibo Liu, Yiqiang Zhao
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2021 Security-Driven Placement and Routing Tools for Electromagnetic Side-Channel Protection
abstract
Side-channel analysis (SCA) attacks are major threats to hardware security. Upon this security threat, various countermeasures at different design layers have been proposed against SCA attacks. These approaches often introduce significant overheads and impose high requirements of side-channel security backgrounds to integrated circuit (IC) designers. In this article, we propose an automatic computer-aided design (CAD) tool that can be utilized to enhance the circuit resistance against electromagnetic (EM) SCA attacks. This new tool will guide security-driven placement and routing processes and can be seamlessly integrated into the modern IC design flow. The protected IC design will be resilient to SCA attacks with negligible area and power overheads. In order to develop this tool, we first investigate the root-cause of EM leakage at the layout level and mathematically demonstrate the feasibility of security-driven placement and routing through the EM leakage modeling. We then identify that the correlation between the data under protection and the EM leakage can be significantly reduced through data-dependent register reallocation and wire length adjustments. Simulation results on cryptographic circuits prove the effectiveness of both the constructed EM leakage model and the EM model-based CAD tool for EM side-channel security.
Haocheng Ma, Jiaji He 0001, Yanjiang Liu, Leibo Liu, Yiqiang Zhao, Yier Jin
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2021 Golden Chip-Free Trojan Detection Leveraging Trojan Trigger's Side-Channel Fingerprinting
abstract
Hardware Trojans (HTs) have become a major threat for the integrated circuit industry and supply chain and have motivated numerous developments of HT detection schemes. Although the side-channel HT detection approach is among the most promising solutions, most of the previous methods require a trusted golden chip reference. Furthermore, detection accuracy is often influenced by environmental noise and process variations. In this article, a novel electromagnetic (EM) side-channel fingerprinting-based HT detection method is proposed. Different from previous methods, the proposed solution eliminates the requirement of a trusted golden fabricated chip. Rather, only the genuine RTL code is required to generate the EM signatures as references. A factor analysis method is utilized to extract the spectral features of the HT trigger’s EM radiation, and then a k -means clustering method is applied for HT detection. Experimentation on two selected sets of Trust-Hub benchmarks has been performed on FPGA platforms, and the results show that the proposed framework can detect all dormant HTs with a high confidence level.
Jiaji He 0001, Haocheng Ma, Yanjiang Liu, Yiqiang Zhao
ACM Trans. Embed. Comput. Syst.1
2021 Test Generation for Hardware Trojan Detection Using Correlation Analysis and Genetic Algorithm
abstract
Hardware Trojan (HT) is a major threat to the security of integrated circuits (ICs). Among various HT detection approaches, side channel analysis (SCA)-based methods have been extensively studied. SCA-based methods try to detect HTs by comparing side channel signatures from circuits under test with those from trusted golden references. The pre-condition for SCA-based HT detection to work is that the testers can collect extra signatures/anomalies introduced by activated HTs. Thus, activation of HTs and amplification of the differences between circuits under test and golden references are the keys to SCA-based HT detection methods. Test vectors are of great importance to the activation of HTs, but existing test generation methods have two major limitations. First, the number of test vectors required to trigger HTs is quite large. Second, the HT circuit’s activities are marginal compared with the whole circuit’s activities. In this article, we propose an optimized test generation methodology to assist SCA-based HT detection. Considering the HTs’ inherent surreptitious nature, inactive nodes with low transition probability are more likely to be selected as HT trigger nodes. Therefore, the correlations between circuit inputs and inactive nodes are first exploited to activate HTs. Then a test reordering process based on the genetic algorithm (GA) is implemented to increase the proportion of the HT circuit’s activities to the whole circuit’s activities. Experiments on 10 selected ISCAS benchmarks, wb_conmax benchmark, and b17 benchmark demonstrate that the number of test vectors required to trigger HTs reduces 28.8% on average compared with the result of MERO and MERS methods. After the test vector reordering process, the proportion of the HT circuit’s activities to the whole circuit’s activities is improved by 95% on average, compared with the result of MERS method.
Zhendong Shi, Haocheng Ma, Qizhi Zhang 0001, Yanjiang Liu, Yiqiang Zhao, Jiaji He 0001
ACM Trans. Embed. Comput. Syst.6
2020 Design for EM Side-Channel Security through Quantitative Assessment of RTL Implementations
abstract
Electromagnetic (EM) side-channel attacks aim at extracting secret information from cryptographic hardware implementations. Countermeasures have been proposed at device level, register-transfer level (RTL) and layout level, though efficient, there are still requirements for quantitative assessment of the hardware implementations' resistance against EM side-channel attacks. In this paper, we propose a design for EM side-channel security evaluation and optimization framework based on the t-test evaluation results derived from RTL hardware implementations. Different implementations of the same cryptographic algorithm are evaluated under different hypothesis leakage models considering the driven capabilities of logic components, and the evaluation results are validated with side-channel attacks on FPGA platform. Experimental results prove the feasibility of the proposed side-channel leakage evaluation method at pre-silicon stage. The remedies and suggested security design rules are also discussed.
Jiaji He 0001, Haocheng Ma, Xiaolong Guo 0001, Yiqiang Zhao, Yier Jin
ASP-DAC1
2020 Runtime Trust Evaluation and Hardware Trojan Detection Using On-Chip EM Sensors
abstract
It has been widely demonstrated that the utilization of postdeployment trust evaluation approaches, such as side-channel measurements, along with statistical analysis methods is effective for detecting hardware Trojans in fabricated integrated circuits (ICs). However, more sophisticated Trojans proposed recently invalidate these methods with stealthy triggers and very-low side-channel signatures. Upon these challenges, in this paper, we propose an electromagnetic (EM) side-channel based post-fabrication trust evaluation framework which monitors EM radiations at runtime. The key component of the runtime trust evaluation framework is an on-chip EM sensor which can constantly measure and collect EM side-channel information of the target circuit. The simulation results validate the capability of the proposed framework in detecting stealthy hardware Trojans. Further, we fabricate an AES circuit protected by the proposed trust evaluation framework along with four different types of hardware Trojans. The measurements on the fabricated chips prove two key findings. First, the on-chip EM sensor can achieve a higher signal to noise ratio (SNR) and thus facilitate a better Trojan detection accuracy. Second, the trust evaluation framework can help detect different hardware Trojans at runtime.
Jiaji He 0001, Xiaolong Guo 0001, Haocheng Ma, Yanjiang Liu, Yiqiang Zhao, Yier Jin
DAC1
2020 Golden chip free Trojan detection leveraging probabilistic neural network with genetic algorithm applied in the training phase
Yanjiang Liu, Jiaji He 0001, Haocheng Ma, Yiqiang Zhao
Sci. China Inf. Sci.2
2020 Random active shield generation based on modified artificial fish-swarm algorithm
Ruishan Xin, Yidong Yuan, Jiaji He 0001, Shuai Zhen, Yiqiang Zhao
Comput. Secur.3
2019 High-efficient generation algorithm for large random active shield
Ruishan Xin, Yidong Yuan, Jiaji He 0001, Yuehui Li, Yiqiang Zhao
Sci. China Inf. Sci.3
2019 Hardware Trojan Detection Leveraging a Novel Golden Layout Model Towards Practical Applications
Yanjiang Liu, Jiaji He 0001, Haocheng Ma, Yiqiang Zhao
J. Electron. Test.2
2019 SoC interconnection protection through formal verification
Jiaji He 0001, Xiaolong Guo 0001, Travis Meade, Raj Gautam Dutta, Yiqiang Zhao, Yier Jin
Integr.1
2017 Hardware Trojan Detection Through Chip-Free Electromagnetic Side-Channel Statistical Analysis
abstract
The hardware Trojan (HT) has become a major threat for the integrated circuit (IC) industry and supply chain, and has motivated numerous developments of Trojan detection schemes. Although the side-channel method is the most promising one, nearly all of the side-channel methods require fabricated golden chips, which are very difficult to obtain in reality. In this paper, we propose a novel strategy for HT detection using electromagnetic side-channel-based spectrum modeling and analyzing. We utilize the design data at early stage of the IC lifecycle, and the generated spectrum can serve as the golden reference, and thus we do not need the fabricated golden chips anymore. Another very important feature is that our method is immune to the process variation theoretically. Experimental results on selected Advanced Encryption Standard benchmark circuits on FPGA show that our proposed method can effectively detect Trojans even with very small traces.
Jiaji He 0001, Yiqiang Zhao, Xiaolong Guo 0001, Yier Jin
IEEE Trans. Very Large Scale Integr. Syst.1