EDBT 2026 Demo / reviewers in the wild / expert
Mohammed Nabeel Thari Moopan
dblp:207/6599 · also Mohammed Nabeel 0001, Mohammed Thari Nabeel
· DBLP profile ↗
31ranked-venue papers
7as first author
20since 2021 · last 2026
0000-0002-3924-7356ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 28 · 7 first-author · 18 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Focus Session: LLM4PQC - Accurate and Efficient Synthesis of PQC Cores by Feedback-Driven LLMsabstractThe design of post-quantum cryptography (PQC) hardware is a complex and hierarchical process with many challenges. A primary bottleneck is the conversion of PQC reference codes from C to high-level synthesis (HLS) specifications, which requires extensive manual refactoring [1]–[3]. Another bottleneck is the scalability of synthesis for complex PQC primitives, including number theoretic transform (NTT) accelerators and wide memory interfaces. While large language models (LLMs) have shown remarkable results for coding in general-purpose languages like Python, coding for hardware design is more challenging; feedback-driven and agentic integration are key principles of successful state-of-the-art approaches. Here, we propose LLM4PQC, an LLM-based framework that refactors high-level PQC specifications and reference C codes into HLS-ready and synthesizable C code. Our framework generates and verifies the resulting RTL code. For correctness, we leverage a hierarchy of checks, covering fast C compilation and simulation as well as RTL simulation. Case studies on NIST PQC reference designs demonstrate a reduction in manual effort and accelerated design-space exploration compared to traditional flows. Overall, LLM4PQC provides a powerful and efficient pathway for synthesizing complex hardware accelerators. Buddhi Perera, Weihua Xiao, Mohammed Nabeel Thari Moopan, Ozgur Sinanoglu, Johann Knechtel, Ramesh Karri |
DATE | 4 |
| 2026 | Power Side-Channel Attacks in Nanosheet Circuits
Mohammed Nabeel Thari Moopan, Hadi Nour Eddine, Mahdi Benkhelifa, Ozgur Sinanoglu, Michail Maniatakos, Johann Knechtel, Hussam Amrouch |
ISCAS | 1 |
| 2026 | @NTT: Algorithm-Targeted NTT hardware acceleration via design-time constant optimization
Mohammed Nabeel Thari Moopan, Mahmoud Hafez, Michail Maniatakos |
ISCAS | 1 |
| 2026 | LLM4SecurePQC: LLM-Driven and Side-Channel Resilient Hardware Synthesis of PQC Cores
Mohammed Nabeel Thari Moopan, Buddhi Perera, Ozgur Sinanoglu, Johann Knechtel, Ramesh Karri |
VTS | 1 |
| 2026 | Big Integer Parallel Stream Modular Multiplier With Variable Bit-WidthsabstractIn this paper, we present a new modular multiplier design that offers flexibility regarding the operand sizes it processes in parallel. The multiplier can efficiently compute different sizes using the same ASIC hardware, enabling parallel computations for smaller sizes, for example a 1024-bit instantiation of our multiplier can perform either one 1024-bit, sixteen 64-bit, or four 256-bit multiplications, etc. This capability is particularly valuable in accelerating a plethora of cryptosystems, such as RSA, ECC, or Fully Homomorphic Encryption, using the same ASIC hardware, since operand sizes can vary depending on the security parameters and the application requirements. The multiplier can be used in conjunction with software methods for parallelization. For instance, our multiplier enables users to employ both RNS and non-RNS versions of FHE using a single hardware accelerator. We implement our multiplier in hardware and demonstrate its efficiency compared to state-of-theart Montgomery designs, while offering the additional advantage of parallel processing flexibility Oleg Mazonka, Eduardo Chielle, Mohammed Nabeel Thari Moopan, Homer Gamil, Michail Maniatakos |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2025 | LiCSPA: Lightweight Countermeasure against Static Power Side-Channel AttacksabstractThis paper presents LiCSPA, a novel defense strategy against a critical threat to cryptographic hardware in modern technology nodes: static power side-channel attacks. Our method is based on (1) carefully tuning high-Vth versus low-Vth cell selection as well as driver strengths during synthesis, accounting for both security and timing impact, and (2), at runtime, randomly switching the operation between these cells. By doing so, LiCSPA achieves to significantly obscures data-dependent static power patterns. Our experimental results on a commercial 28nm node show a drastic increase in the effort required for a successful attack, namely up to 96 times more traces. LiCSPA incurs little cost, namely only 6% in area, making it a lightweight and practical defense that excels prior art. Jitendra Bhandari, Mohammed Nabeel Thari Moopan, Likhitha Mankali, Ozgur Sinanoglu, Ramesh Karri, Johann Knechtel |
ISCAS | 2 |
| 2025 | GlitchFHE: Attacking Fully Homomorphic Encryption Using Fault Injection
Likhitha Mankali, Mohammed Nabeel Thari Moopan, Faiq Raees, Michail Maniatakos, Ozgur Sinanoglu, Johann Knechtel |
USENIX Security Symposium | 2 |
| 2024 | Exploring Generalization of Shoup Modular MultiplierabstractShoup’s modular multiplication algorithm follows the idea of Barrett reduction algorithm. While Barrett reduction can be used to multiply two arbitrary numbers, Shoup’s multiplier requires a pre-computed value for one of the operands. At the same time, Shoup is more efficient as it requires less computation. In this work, we extend Shoup’s multiplier by adding functionality to operate on arbitrary operands in such a way that the multiplier can be used in both ways: using the original Shoup algorithm when one of the arguments can be pre-computed, or a general multiplier. The general multiplier reuses Shoup functionality in its core. We compare the performance of the multipliers in a software simulator and a hardware design. Oleg Mazonka, Mohammed Nabeel Thari Moopan, Michail Maniatakos |
ACM Great Lakes Symposium on VLSI | 2 |
| 2024 | The Impact of Logic Synthesis and Technology Mapping on Logic Locking SecurityabstractLogic locking is a design-for-trust solution, safe-guarding the intellectual property of integrated circuits within the global semiconductor supply chain. Traditionally, logic syn-thesis has been relied upon to enhance the security of logic locking. However, recent research has unveiled vulnerabilities inherent in this approach, as logic synthesis is not security-aware by design. On the other hand, state-of-the-art logic-locking techniques leveraging specific locking structures, such as routing networks, were initially presumed secure by design. However, the optimization capabilities of logic synthesis have been shown to compromise these structures, diminishing their security assurances and rendering logic locking vulnerable to attacks. This ongoing interplay between logic locking and logic synthesis necessitates thorough reevaluation. This paper discusses the vulnerabilities and challenges that have emerged at the intersection of logic locking and logic synthesis, offering insights into future research directions aimed at mitigating these issues. Lilas Alrahis, Mohammed Nabeel Thari Moopan, Johann Knechtel, Ozgur Sinanoglu |
VLSI-SoC | 2 |
| 2024 | MCS-NTT: Multi-Chip System Design for NTT AccelerationabstractHardware implementations of Number Theoretic Transform (NTT), especially ASIC designs, have provided significant speed improvements for lattice-based cryptography schemes used by Post-Quantum Cryptography (PQC) and Fully Homo-morphic Encryption (FHE). While most of the existing solutions are tailored for fixed polynomial degrees and modulus sizes, both parameters can vary considerably depending on the application and scheme. Toward this end, our paper introduces MCS-NTT, the first hardware architecture for NTT acceleration that is based on a multi-chip-system (MCS) design approach. Our proposed solution provides scalability to existing NTT accelerators by seamlessly integrating multiple accelerator units around an FPGA-based centralized unit. This configuration effectively establishes a customized star network tailored to meet specific use cases. The experimental results indicate that MCS-NTT offers considerable flexibility with better performance metrics. Mohammed Nabeel Thari Moopan, Homer Gamil, Johann Knechtel, Michail Maniatakos |
VLSI-SoC | 1 |
| 2024 | Beware Your Standard Cells! On Their Role in Static Power Side-Channel AttacksabstractStatic or leakage power, which is especially prominent in advanced technology nodes, enables so-called static power side-channel attacks (S-PSCAs). While countermeasures exist, they often incur considerable overheads. Besides, hardware Trojans represent another threat. Although the interplay between static power, down-scaling of technology nodes, and the vulnerability to S-PSCA is already established, an important detail was not covered yet: the role of the components at the heart of this sensitive interplay, the standard cells. Here, we study this intricate relationship for two commercial 28 and 65 nm technologies, using a commercial-grade integrated circuit design setup, and under realistic power consumption, performance, and area (PPA) objectives. Specifically, we study how threshold-voltage (VT) tuning of standard cells impacts the resilience of representative AES and PRESENT cipher hardware, including versions with established countermeasures. Our proposed CAD framework enables a security-versus-PPA-aware design-space exploration. Contrary to the belief that high-performance designs are generally more vulnerable to S-PSCA, we find that timing constraints and the distribution of different VT cells are more pivotal factors. Furthermore, we discover that attackers can deploy highly effective and stealthy S-PSCA-based Trojans, all without any gate overheads or any timing violations. Jitendra Bhandari, Likhitha Mankali, Mohammed Nabeel Thari Moopan, Ozgur Sinanoglu, Ramesh Karri, Johann Knechtel |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2024 | Silicon-Proven ASIC Design for the Polynomial Operations of Fully Homomorphic EncryptionabstractIn this work, we elaborate on our endeavors to design, implement, fabricate, and post-silicon validate CoFHEE 1, a co-processor for low-level polynomial operations targeting Fully Homomorphic Encryption execution. With a compact design area of 12mm2, CoFHEE features ASIC implementations of fundamental polynomial operations, including polynomial addition and subtraction, Hadamard product, and Number Theoretic Transform, which underlie most higher-level FHE primitives. CoFHEE is capable of natively supporting polynomial degrees of up to n = 214 with a coefficient size of 128 bits, and has been fabricated and silicon-verified using 55nm CMOS technology. To evaluate it, we conduct performance and power experiments on our chip, and compare it to state-of-the-art software implementations and other ASIC designs. Mohammed Nabeel Thari Moopan, Homer Gamil, Deepraj Soni, Mohammed Ashraf, Mizan Abraha Gebremichael, Eduardo Chielle, Ramesh Karri, Mihai Sanduleanu, Michail Maniatakos |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2023 | CoFHEE: A Co-processor for Fully Homomorphic Encryption ExecutionabstractIn this paper, we present the blueprint of a specialized co-processor for Fully Homomorphic Encryption, dubbed CoFHEE. With a small design area of$12mm^{2}$, CoFHEE incorporates ASIC implementations of fundamental polynomial operations, such as polynomial addition and subtraction, Hadamard product, and Number Theoretic Transform, which are underneath all higher-level FHE primitives. CoFHEE has native support of polynomial degrees of up to$n=2^{14}$with a coefficient size of 128 bits. We evaluate our chip with performance and power experiments and compare it against state-of-the-art software implementations and other ASIC designs. A more elaborate description of the CoFHEE design can be found in [1]. Mohammed Nabeel Thari Moopan, Deepraj Soni, Mohammed Ashraf, Mizan Abraha Gebremichael, Homer Gamil, Eduardo Chielle, Ramesh Karri, Mihai Sanduleanu, Michail Maniatakos |
DATE | 1 |
| 2023 | Quantifying the Overheads of Modular MultiplicationabstractAs security and privacy continue to grow in importance, new techniques, including fully homomorphic encryption (FHE) and post-quantum cryptography (PQC), have emerged to provide new capabilities. Many of these techniques are based on the ring learning with errors problem and operate over rings. Elements of a ring are computed using modular arithmetic, with modular multiplication being a primary component. These components are far more complex than standard integer computing, especially when working with large bit widths. As FHE and PQC become increasingly popular, the need for well-designed and optimized modular multipliers also grows in importance. In this paper, we analyze the power, area, performance, energy, and thermal characteristics of two commonly used modular multipliers: Barrett (bit parallel) and Interleaved (bit parallel). To understand these multipliers' characteristics, this study provides necessary insights into the sources of area, power, frequency, and energy overhead, considering a range of different bit widths (16–256). This paper rigorously analyzes the sub-blocks of modular multipliers and their contributions to overall power, performance, and area (PPA). Deepraj Soni, Mohammed Nabeel Thari Moopan, Negar Neda, Ramesh Karri, Michail Maniatakos, Brandon Reagen |
ISLPED | 2 |
| 2023 | RPU: The Ring Processing UnitabstractRing-Learning-with-Errors (RLWE) has emerged as the foundation of many important techniques for improving security and privacy, including homomorphic encryption and post-quantum cryptography. While promising, these techniques have received limited use due to their extreme overheads of running on general-purpose machines. In this paper, we present a novel vector Instruction Set Architecture (ISA) and microarchitecture for accelerating the ring-based computations of RLWE. The ISA, named B512, is developed to meet the needs of ring processing workloads while balancing high-performance and general-purpose programming support. Having an ISA rather than fixed hardware facilitates continued software improvement post-fabrication and the ability to support the evolving workloads. We then propose the ring processing unit (RPU), a high-performance, modular implementation of B512. The RPU has native large word modular arithmetic support, capabilities for very wide parallel processing, and a large capacity highbandwidth scratchpad to meet the needs of ring processing. We address the challenges of programming the RPU using a newly developed SPIRAL backend. A configurable simulator is built to characterize design tradeoffs and quantify performance. The best performing design was implemented in RTL and used to validate simulator performance. In addition to our characterization, we show that a RPU using 20.5mm2of GF12nm can provide a speedup of 1485× over a CPU running a 64k, 128-bit NTT, a core RLWE workload. Deepraj Soni, Negar Neda, Naifeng Zhang, Benedict Reynwar, Homer Gamil, Benjamin Heyman, Mohammed Nabeel Thari Moopan, Ahmad Al Badawi, Yuriy Polyakov, Kellie Canida, Massoud Pedram, Michail Maniatakos, David Cousins, Franz Franchetti, Matthew French, Andrew G. Schmidt, Brandon Reagen |
ISPASS | 7 |
| 2023 | X-Volt: Joint Tuning of Driver Strengths and Supply Voltages Against Power Side-Channel AttacksabstractPower side-channel (PSC) attacks are well-known threats to sensitive hardware like advanced encryption standard (AES) crypto cores. Given the significant impact of supply voltages (VCCs) on power profiles, various countermeasures based on VCC tuning have been proposed, among other defense strategies. Driver strengths of cells, however, have been largely overlooked, despite having direct and significant impact on power profiles as well. Saideep Sreekumar, Mohammed Ashraf, Mohammed Nabeel Thari Moopan, Ozgur Sinanoglu, Johann Knechtel |
ISPD | 3 |
| 2023 | Optimizing Constrained-Modulus Barrett Multiplier for Power and FlexibilityabstractFully Homomorphic Encryption (FHE) promises data protection by computing on encrypted data, but demands resource-intensive computation. FHE hardware accelerators, which improve FHE scheme performance with densely packed computing units, could potentially damage the chip with excessive heat dissipation because of high power consumption. Therefore, it is necessary to reduce the power consumption of the accelerator and its most critical module, i.e., modular multiplier. In this work, we extend the idea of allowing a specific form of modulus to achieve a low-power Barrett modular multiplier (BM). BM with constraint width can reduce power consumption by 15% and area by 20%. We propose an approximation for the number of moduli available with the discussed constraints on the modulus. Deepraj Soni, Mohammed Nabeel Thari Moopan, Ramesh Karri, Michail Maniatakos |
VLSI-SoC | 2 |
| 2022 | Design-time exploration of voltage switching against power analysis attacks in 14 nm FinFET technology
Johann Knechtel, Tarek Ashraf, Natascha Fernengel, Satwik Patnaik, Mohammed Nabeel Thari Moopan, Mohammed Ashraf, Ozgur Sinanoglu, Hussam Amrouch |
Integr. | 5 |
| 2021 | Fortifying RTL Locking Against Oracle-Less (Untrusted Foundry) and Oracle-Guided AttacksabstractLogic locking protects integrated circuits (IC) against intellectual property (IP) theft, IC overbuilding, and hardware Trojan insertion. Prior locking schemes operate after logic synthesis and cannot protect the semantic information embedded into the logic. Register-transfer level (RTL) locking can protect the sensitive IP semantics and are EDA tool-chain agnostic, allowing seamless integration into arbitrary design flows. State-of-the-art RTL locking protects against the untrusted foundry assuming no access to working chip (oracle). However, it does not protect against oracle-based attacks. In this work, we propose to fortify RTL locking to protect against all untrusted entities in the supply chain, including foundry for oracle-less attacks, and test facility and end users for oracle-guided attacks. Nimisha Limaye, Animesh Basak Chowdhury, Christian Pilato, Mohammed Nabeel Thari Moopan, Ozgur Sinanoglu, Siddharth Garg, Ramesh Karri |
DAC | 4 |
| 2021 | Toward Security Closure in the Face of Reliability Effects ICCAD Special Session PaperabstractThe reliable operation of ICs is subject to physical effects like electromigration, thermal and stress migration, negative bias temperature instability, hot-carrier injection, etc. While these effects have been studied thoroughly for IC design, threats of their subtle exploitation are not captured well yet. In this paper, we open up a path for security closure of physical layouts in the face of reliability effects. Toward that end, we first review migration effects in interconnects and aging effects in transistors, along with established and emerging means for handling these effects during IC design. Next, we study security threats arising from these effects; in particular, we cover migration effects-based, disruptive Trojans and aging-exacerbated side-channel leakage. Finally, we outline corresponding strategies for security closure of physical layouts, along with an outline for CAD frameworks. Jens Lienig, Susann Rothe, Matthias Thiele, Nikhil Rangarajan, Mohammed Ashraf, Mohammed Nabeel Thari Moopan, Hussam Amrouch, Ozgur Sinanoglu, Johann Knechtel |
ICCAD | 6 |
| 2020 | Muon-Ra: Quantum random number generation from cosmic raysabstractTrue Random Number Generators (TRNGs) are the cornerstone of modern cryptographic applications. In this work, we present the first quantum1random number generator based on muon detection. The proposed implementation utilizes silicon photomultipliers and plastic scintillators to convert the time interval between crossing muons to random bits. Compared to the state-of-the-art, this design operates using a passive entropy source, scaling down its power consumption significantly. Additionally, the proposed muon-based TRNG can be fully integrated in modern computer hardware, making it suitable for low-power embedded device applications. We evaluate the proposal on its throughput and ability to pass standard randomness tests. Our method is successful in passing the NIST STS SP 800-22 and Dieharder evaluations. Finally, the implementation is compared to other well-established methods of generating random numbers.1We use the term “quantum” to denote the utilization of elementary particles as the output generation source, and not necessarily their properties, similar to related work [1], [2]. Homer Gamil, Pranav Mehta, Eduardo Chielle, Adriano Di Giovanni, Mohammed Nabeel Thari Moopan, Francesco Arneodo, Michail Maniatakos |
IOLTS | 5 |
| 2020 | 2.5D Root of Trust: Secure System-Level Integration of Untrusted ChipletsabstractFor the first time, we leverage the 2.5D interposer technology to establish system-level security in the face of hardware- and software-centric adversaries. More specifically, we integrate chiplets (i.e., third-party hard intellectual property of complex functionality, like microprocessors) using a security-enforcing interposer. Such hardware organization provides a robust 2.5D root of trust for trustworthy, yet powerful and flexible, computation systems. The security paradigms for our scheme, employed firmly by design and construction, are: 1) stringent physical separation of trusted from untrusted components and 2) runtime monitoring. The system-level activities of all untrusted commodity chiplets are checked continuously against security policiesvia physically separated security features. Aside from the security promises, the good economics of outsourced supply chains are still maintained; the system vendor is free to procure chiplets from the open market, while only producing the interposer and assembling the 2.5D system oneself. We showcase our scheme using the Cortex-M0 core and the AHB-Lite bus by ARM, building a secure 64-core system with shared memories. We evaluate our scheme through hardware simulation, considering different threat scenarios. Finally, we devise a physical-design flow for 2.5D systems, based on commercial-grade design tools, to demonstrate and evaluate our 2.5D root of trust. Mohammed Nabeel Thari Moopan, Mohammed Ashraf, Satwik Patnaik, Vassos Soteriou, Ozgur Sinanoglu, Johann Knechtel |
IEEE Trans. Computers | 1 |
| 2020 | Truly Stripping Functionality for Logic Locking: A Fault-Based PerspectiveabstractLogic locking is a holistic solution to counter manufacturing threats, such as intellectual property (IP) piracy and overbuilding at the hardware level. However, years of research has exposed various flaws in locking, including a Boolean satisfiability (SAT)-based attack. Consequently, several SAT-resilient locking techniques, such as SARLock, Anti-SAT, and SFLL have been proposed, although certain instances of them have also been broken by a class of attacks, called removal attack. In this article, we approach logic locking by leveraging well-known principles from very large-scale integration (VLSI) testing and elicit logic locking properties that dictate the resilience of a locking technique against different attacks. We present a revised version of SFLL, namely SFLL-rem, that not only retains all security properties of SFLL, delivering resilience to all the state-of-the-art attacks SFLL can thwart, but also to the latest removal attacks that broke some SFLL instances. Further, we develop a security-aware CAD framework integrated with industry tools that incurs only -1.5%, 0%, and 4.13% overhead for power, performance, and area, respectively. We demonstrate a silicon implementation of SFLL-rem on ARM Cortex-M0 microprocessor in 65 nm. Moreover, we provide a framework for an SoC designer to customize logic locking based on the SoC blocks and their threat models; this is illustrated by locking a multimillion-gate SoC provided by DARPA, and taking the SoC all the way to GDSII layout. Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Nimisha Limaye, Mohammed Ashraf, Ozgur Sinanoglu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2019 | MixLock: Securing Mixed-Signal Circuits via Logic LockingabstractIn this paper, we propose a hardware security methodology for mixed-signal Integrated Circuits (ICs). The proposed methodology can be used as a countermeasure for IC piracy, including counterfeiting and reverse engineering. It relies on logic locking of the digital section of the mixed-signal IC, such that unless the correct key is provided, the mixed-signal performance will be pushed outside of the acceptable specification range. We employ a state-of-the-art logic locking technique, called Stripped Functionality Logic Locking (SFLL). We show that strong security levels are achieved in both mixed-signal and digital domains. In addition, the proposed methodology presents several appealing properties. It is non-intrusive for the analog section, it incurs reasonable area and power overhead, it can be fully automated, and it is virtually applicable to a wide range of mixed-signal ICs. We demonstrate it on a ΣΔ Analog-to-Digital Converter (ADC). Julian Leonhard, Muhammad Yasin, Shadi Turk, Mohammed Nabeel Thari Moopan, Marie-Minerve Louërat, Roselyne Chotin-Avot, Hassan Aboushady, Ozgur Sinanoglu, Haralampos-G. D. Stratigopoulos |
DATE | 4 |
| 2019 | A New Paradigm in Split Manufacturing: Lock the FEOL, Unlock at the BEOLabstractSplit manufacturing was introduced as an effective countermeasure against hardware-level threats such as IP piracy, overbuilding, and insertion of hardware Trojans. Nevertheless, the security promise of split manufacturing has been challenged by various attacks, which exploit the well-known working principles of physical design tools to infer the missing BEOL interconnects. In this work, we advocate a new paradigm to enhance the security for split manufacturing. Based on Kerckhoff's principle, we protect the FEOL layout in a formal and secure manner, by embedding keys. These keys are purposefully implemented and routed through the BEOL in such a way that they become indecipherable to the state-of-the-art FEOL-centric attacks. We provide our secure physical design flow to the community. We also define the security of split manufacturing formally and provide the associated proofs. At the same time, our technique is competitive with current schemes in terms of layout overhead, especially for practical, large-scale designs (ITC'99 benchmarks). Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Johann Knechtel, Ozgur Sinanoglu |
DATE | 2 |
| 2019 | Is Robust Design-for-Security Robust Enough? Attack on Locked Circuits with Restricted Scan Chain AccessabstractThe security of logic locking has been called into question by various attacks, especially a Boolean satisfiability (SAT) based attack, that exploits scan access in a working chip. Among other techniques, a robust design-for-security (DFS) architecture was presented to restrict any unauthorized scan access, thereby, thwarting the SAT attack (or any other attack that relies on scan access). Nevertheless, in this work, we successfully break this technique by recovering the secret key despite the lack of scan access. Our security analysis on a few benchmark circuits protected by the robust DFS architecture demonstrates the effectiveness of our attack; on average ~95% of the key bits are correctly recovered, and almost 100% in most cases. To overcome this and other prevailing attacks, we propose a defense by making fundamental changes to the robust DFS technique; the new defense can withstand all logic locking attacks. We observe, on average, lower area overhead (~1.65%) than the robust DFS design (~5.15%), and similar test coverage (~99.88%). Nimisha Limaye, Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Ozgur Sinanoglu |
ICCAD | 3 |
| 2019 | Power, Area, Speed, and Security (PASS) Trade-Offs of NIST PQC Signature Candidates Using a C to ASIC Design FlowabstractNational Institute of Standards and Technology (NIST) is standardizing post-quantum cryptographic (PQC) algorithms. Most of the PQC algorithms are complex; rendering their hardware modeling, evaluation, and benchmarking challenging. We developed a High-Level Synthesis (HLS) → ASIC flow for fast evaluation of Power, Area, Speed, and Security (PASS) trade-offs of the NIST round 2 PQC algorithms using an industry-standard design flow. In this paper, we discuss this flow and the preliminary results on some of the PQC signature algorithms. Deepraj Soni, Mohammed Nabeel Thari Moopan, Kanad Basu, Ramesh Karri |
ICCD | 2 |
| 2019 | CAD-Base: An Attack Vector into the Electronics Supply ChainabstractFabless semiconductor companies design system-on-chips (SoC) by using third-party intellectual property (IP) cores and fabricate them in offshore, potentially untrustworthy foundries. Owing to the globally distributed electronics supply chain, security has emerged as a serious concern. In this article, we explore electronics computer-aided design (CAD) software as a threat vector that can be exploited to introduce vulnerabilities into the SoC. We show that all electronics CAD tools—high-level synthesis, logic synthesis, physical design, verification, test, and post-silicon validation—are potential threat vectors to different degrees. We have demonstrated CAD-based attacks on several benchmarks, including the commercial ARM Cortex M0 processor [1]. Kanad Basu, Samah Mohamed Saeed, Christian Pilato, Mohammed Ashraf, Mohammed Nabeel Thari Moopan, Krishnendu Chakrabarty, Ramesh Karri |
ACM Trans. Design Autom. Electr. Syst. | 5 |
| 2018 | Customized locking of IP blocks on a multi-million-gate SoCabstractReliance on off-site untrusted fabrication facilities has given rise to several threats such as intellectual property (IP) piracy, overbuilding and hardware Trojans. Logic locking is a promising defense technique against such malicious activities that is effected at the silicon layer. Over the past decade, several logic locking defenses and attacks have been presented, thereby, enhancing the state-of-the-art. Nevertheless, there has been little research aiming to demonstrate the applicability of logic locking with large-scale multi-million-gate industrial designs consisting of multiple IP blocks with different security requirements. In this work, we take on this challenge to successfully lock a multi-million-gate system-on-chip (SoC) provided by DARPA by taking it all the way to GDSII layout. We analyze how specific features, constraints, and security requirements of an IP block can be leveraged to lock its functionality in the most appropriate way. We show that the blocks of an SoC can be locked in a customized manner at 0.5%, 15.3%, and 1.5% chip-level overhead in power, performance, and area, respectively. Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Mohammed Ashraf, Ozgur Sinanoglu |
ICCAD | 2 |
| 2018 | ATPG-based cost-effective, secure logic lockingabstractThe globalization of IC supply chain lead to the emergence of hardware security threats such as IP piracy, reverse engineering, overbuilding, and hardware Trojans. Among the techniques developed to mitigate these threats, logic locking offers the most versatile protection and is being actively researched. The most recent locking technique SFLL thwarts with provable and quantifiable security all the state-of-the-art attacks including SAT, AppSAT, and the removal attack. However, the implementation cost of SFLL can sometimes be prohibitive, as it lacks an automated framework that explores cost-effective implementation options. In this paper, we show how VLSI testing principles and tools can be adopted to automate critical steps in SFLL and minimize its cost. We propose “SFLL-fault” that utilizes fault injection driven synthesis to efficiently explore design options and ATPG to assess security levels. Our experimental results confirm the efficacy of our strategy; SFLL-fault can reduce the implementation cost by 35% compared to SFLL without compromising security. Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Muhammad Yasin, Ozgur Sinanoglu |
VTS | 2 |
| 2017 | Provably-Secure Logic Locking: From Theory To PracticeabstractLogic locking has been conceived as a promising proactive defense strategy against intellectual property (IP) piracy, counterfeiting, hardware Trojans, reverse engineering, and overbuilding attacks. Yet, various attacks that use a working chip as an oracle have been launched on logic locking to successfully retrieve its secret key, undermining the defense of all existing locking techniques. In this paper, we propose stripped-functionality logic locking (SFLL), which strips some of the functionality of the design and hides it in the form of a secret key(s), thereby rendering on-chip implementation functionally different from the original one. When loaded onto an on-chip memory, the secret keys restore the original functionality of the design. Through security-aware synthesis that creates a controllable mismatch between the reverse-engineered netlist and original design, SFLL provides a quantifiable and provable resilience trade-off between all known and anticipated attacks. We demonstrate the application of SFLL to large designs (>100K gates) using a computer-aided design (CAD) framework that ensures attaining the desired security level at minimal implementation cost, 8%, 5%, and 0.5% for area, power, and delay, respectively. In addition to theoretical proofs and simulation confirmation of SFLL's security, we also report results from the silicon implementation of SFLL on an ARM Cortex-M0 microprocessor in 65nm technology. Muhammad Yasin, Abhrajit Sengupta, Mohammed Nabeel Thari Moopan, Mohammed Ashraf, Jeyavijayan Rajendran, Ozgur Sinanoglu |
CCS | 3 |