Gaurav Kumar 0001

dblp:24/6847-1 · DBLP profile ↗
← Back
18ranked-venue papers
12as first author
18since 2021 · last 2026
0000-0002-2357-6382ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 15 · 10 first-author · 15 since 2021Software engineering, systems software and programming languages · 4 · 4 first-author · 4 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 On Evaluating the Security of TRNG-driven SRAM Scrambling Architecture
Manan Kumar Singh, Gaurav Kumar 0001, Kashvi Bansal, Yamuna Prasad, Satyadev Ahlawat
ETS2
2026 On Evaluating the Security of Complete Access Protocol of IJTAG Architecture
Gaurav Kumar 0001, Raj Kumar Choudhary, Satyadev Ahlawat
ISCAS1
2026 Secure and scalable access protocol for enhancing IEEE 1687 network security
abstract
Abstract Modern System-on-Chip (SoC) designs integrate various embedded instruments and proprietary data to support critical operations such as testing, diagnosis, and in-field health monitoring. The IEEE Std. 1687 (IJTAG) is widely adopted to provide efficient and flexible access to these on-chip instruments. However, its reconfigurable nature exposes a significant attack surface, making it vulnerable to advanced security threats, including machine learning, differential analysis, and power analysis attacks, which can extract Chip IDs and cryptographic keys. To enhance the security of the IJTAG architecture, a secure access protocol has been proposed in the literature. In this secure access scheme, a random number generator produces a bitstream, and whenever a predefined template matches, a key bit is inserted into the bitstream; this process continues until all key bits are embedded. However, the reliance on a single static template renders the scheme predictable and susceptible to key recovery. To overcome this limitation, we propose a multi-dynamic template based secure access protocol , where multiple templates are employed for key insertion. For each comparison, the specific template is dynamically selected based on the last generated bit of the bitstream, thereby introducing randomness into the embedding process and obfuscating adversarial analysis. The experimental evaluation demonstrates that, with eight templates, the proposed protocol reduces machine learning attack accuracy from 98.31 to 0.0002%, increases the complexity of differential analysis by extending the key retrieval time from 3 ms to approximately $$ 1.67 \times 10^{10} $$ 1.67 × 10 10 years, and renders power analysis attacks completely infeasible. In addition, the proposed scheme significantly reduces the bitstream length required for key insertion. For instance, with a 16-bit template and a 256-bit key, the required bitstream length decreases from 16.6 million to 12.8 thousand, while for a 24-bit template and a 256-bit key, it decreases from 4.2 billion to 57.2 thousand, while maintaining security. Furthermore, hardware synthesis on ITC’16 IJTAG benchmarks confirms negligible implementation cost, with area overheads of only 1.65% and 1.53% for the TreeFlatEx and TreeBalanced benchmarks, respectively. These results demonstrate that the proposed protocol provides scalable, resource-efficient and robust protection for IJTAG-enabled SoCs against state-of-the-art attacks.
Gaurav Kumar 0001, Mahendra Kumar Gurve, Nitin 0001, Yamuna Prasad, Satyadev Ahlawat
Cybersecur.1
2026 Round key attack: Exploiting AES round key generation reversibility through scan analysis
Gaurav Kumar 0001, Yamuna Prasad, Satyadev Ahlawat
J. Inf. Secur. Appl.1
2026 On Enhancing the Security of Streaming Scan Network through Dual-Functional TDR
abstract
The increasing complexity and core count of modern System-on-Chips (SoCs) have raised significant concerns regarding test time and test data volume. Despite advancements in SoC design, the physical size of SoCs remains relatively constant, imposing stringent constraints on the number of additional I/O pins to support parallel testing. Furthermore, the disparity in scan chain lengths exacerbates these challenges due to padding requirements, which significantly increase the test data volume. Recently, a novel test architecture, the Streaming Scan Network (SSN), has been introduced, which demonstrates a significant reduction in both test time and test data volume. However, the SSN lacks robust security countermeasures, making it susceptible to threats such as unauthorized access and data tampering. To mitigate these threats, this article presents a lightweight and inherently secure solution that leverages the IJTAG Static Test Data Register (TDR) as a dual-functional module, ensuring both security and the preservation of the SSN’s original functionality. The experimental results demonstrate that the proposed countermeasure incurs 9.08%, 18.34%, 77.54%, and 167.28% less area overhead compared to the state-of-the-art Masking, NLFSR, UAU, and ROT countermeasures, respectively, while maintaining a security level equivalent to a 1024-bit key. Additionally, the proposed approach maintains low computational overhead and minimal authorization cycles, making it a scalable and practical solution for secure SoC testing.
Gaurav Kumar 0001, Mahendra Kumar Gurve, Yamuna Prasad, Satyadev Ahlawat
ACM Trans. Design Autom. Electr. Syst.2
2025 Compatibility Graph Assisted Automatic Hardware Trojan Insertion Framework
abstract
Hardware Trojans (HTs) pose substantial security threats to Integrated Circuits (ICs), compromising their integrity, confidentiality, and functionality. Various HT detection methods have been developed to mitigate these risks. However, the limited availability of comprehensive HT benchmarks necessitates designers to create their own for evaluation purposes. Moreover, the existing benchmarks exhibit several deficiencies, including a restricted range of trigger nodes, susceptibility to detection through random patterns, lengthy HT instance creation and validation process, and a limited number of HT instances per circuit. To address these limitations, we propose a Compatibility Graph assisted automatic Hardware Trojan insertion framework for HT benchmark generation. Given a netlist, this framework generates a design incorporating single or multiple HT instances according to user-defined properties. It allows various configurations of HTs, such as a large number of trigger nodes, low activation probability and large number of unique HT instances. The experimental results demonstrate that the generated HT benchmarks exhibit exceptional resistance to state-of-the-art HT detection schemes. Additionally, the proposed framework achieves an average improvement of 37815.7x and 989.4x over the insertion times of the Random and Reinforcement Learning based HT insertion frameworks, respectively.
Gaurav Kumar 0001, Ashfaq Hussain Shaik, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
DATE1
2025 Approximating Nonlinear Activation Function Using Genetic Programming
abstract
Modern advancements in hardware implementation of Deep Neural Networks (DNNs) have underscored the need for efficient and accurate nonlinear activation function approximations to reduce computational complexity in resource-constrained environments like FPGA. Traditional methods face challenges in achieving an optimal balance between accuracy and hardware efficiency. To address this, we propose PSO-GP, an automated framework that formulates the approximation as an optimization problem. In this framework, Genetic Programming (GP) approximates complex functions in linear functions, while Particle Swarm Optimization (PSO) identifies optimal interval partition to minimize error. The experimental results demonstrate that PSO-GP significantly improves accuracy and reduces hardware overhead compared to state-of-the-art methods.
Mahendra Kumar Gurve, Gaurav Kumar 0001, Satyadev Ahlawat, Yamuna Prasad
ISCAS2
2025 A New Hardware Trojan Attack on Scan-obfuscated Logic-locked Circuits
abstract
Logic locking has emerged as a crucial defense mechanism for securing ICs against threats such as IP theft, counterfeiting, and Hardware Trojans (HTs). However, advanced attacks like Boolean Satisfiability (SAT) attack have exposed vulnerabilities by exploiting scan-unlocked oracle to retrieve secret keys. To mitigate this risk, scan obfuscation techniques were introduced to secure scan access and enhance protection against SAT attack. However, ScanSAT attack has been shown to bypass these defenses, successfully retrieving secret keys even from scan-obfuscated circuits. Recently, a test authentication scheme combined with scan obfuscation has been proposed as a countermeasure against ScanSAT attack.This work presents an attack that employs a stealthy HT to subvert the security provided by the test authentication scheme. Our analysis demonstrates that the inserted Trojan not only facilitates the execution of the ScanSAT attack but also eludes detection by the state-of-the-art Hardware Trojan detection techniques. These results highlight critical vulnerabilities in current IC security measures, emphasizing the need for resilient defenses against increasingly sophisticated attacks.
Anjum Riaz, Gaurav Kumar 0001, Yamuna Prasad, Satyadev Ahlawat, Virendra Singh
ISCAS2
2025 Poster Abstract: SRAM PUF-Based Logic Locking for Secure Authentication and IP Protection
abstract
This paper proposes a novel security framework that integrates Logic locking with intrinsic SRAM PUFs for simultaneous user authorization and hardware authentication. By leveraging stable SRAM cell responses, the approach eliminates external key storage, deriving unlocking keys through a structured transformation process. Experimental validation on ESP32 devices demonstrates high intra-device response consistency and distinct inter-device signatures. This unified mechanism ensures that only authorized users can access the system and only authenticated ICs can function, mitigating risks of overproduction and external attacks. The results establish SRAM PUFs as a lightweight, efficient, and tamper-resistant solution for secure key derivation.
Chandranshu Gupta, Gaurav Kumar 0001, Satyadev Ahlawat, Gaurav Varshney
SenSys2
2025 Robust LFSR-based Scrambling to Mitigate Stencil Attack on Main Memory
abstract
Main memory plays a pivotal role in the storage of computational data in a wide range of applications, including highly sensitive assets such as banking transactions, cryptographic keys, and user credentials. However, memory systems remain vulnerable to advanced physical and side-channel attacks, including cold boot attacks that exploit residual data after power-down. To mitigate such risks, Intel’s DDR3 memory scrambler uses a Linear Feedback Shift Register (LFSR)-based stream cipher to obscure memory contents. Nevertheless, this mechanism has been shown to be susceptible to stencil attack, a cold boot technique that reconstructs the scrambling key by leveraging the linear and periodic nature of the keystream. This article proposes a novel, lightweight, and secure scrambling architecture based on a generic LFSR designed to enhance the security of DDR3 memory against cold boot attacks. The proposed generic LFSR-based mechanism eliminates differential keystream periodicity by introducing an address- and seed-dependent LFSR structure, thereby rendering differential key recovery techniques computationally infeasible. Furthermore, unlike traditional AES-based memory encryption that incurs high latency and area overhead, the proposed approach achieves comparable security guarantees with low hardware complexity and zero access latency. The hardware implementation results on the Xilinx VCU118 FPGA show that the proposed scheme consumes only 252 LUTs, 256 registers and 104 slices, comparable to the Intel DDR3 scrambler, while offering superior resilience against the cold boot, warm boot, and probing attacks. These results demonstrate the practicality of the proposed scheme for secure memory systems in resource-constrained environments.
Gaurav Kumar 0001, Kushal Pravin Nanote, Sohan Lal, Yamuna Prasad, Satyadev Ahlawat
ACM Trans. Embed. Comput. Syst.1
2024 On Evaluating Test Response Obfuscation and Encryption Countermeasures
abstract
The scan design is a widely accepted technique employed to enhance the testability of VLSI designs. However, it introduces exploitable side channels that allow attackers to illicitly access confidential information within crypto-cores. To address this concern, several countermeasures have been proposed. Among these countermeasures, two specific types include obfuscation and encryption of the test response at the Scan-Out (SO) port, rendering the test response inaccessible for analysis by potential attackers. This paper proposes a scan attack that effectively retrieves the AES encryption key, even in the presence of both obfuscation and encryption countermeasures.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
IOLTS1
2023 On Enhancing the Security of Streaming Scan Network Architecture
abstract
Test data volume and test time have become a major concern in the testing of complex System on Chips (SoCs). This is due to the fact that the complexity, as well as the number of cores, keeps increasing while the physical size of SoCs remains relatively constant. Consequently, there is limited space available for additional IO pins for scan purposes, which restricts the ability to test multiple cores in parallel. Moreover, testing multiple cores concurrently with different scan chain lengths further increases the test data volume and test time due to the padding. To mitigate the above problems, a new testing architecture called a Streaming Scan Network (SSN) has been recently developed. It is a bus-based architecture that enables the testing of multiple cores with reduced test data volume and test time. However, the SSN-based architecture lacks essential security features, rendering it susceptible to various security threats, including unauthorized user access, as well as data sniffing and alteration attacks. In this paper, a simple, lightweight, inherently secure solution is proposed to counteract the above security threats. The proposed approach involves leveraging IJTAG static registers to incorporate security features into the SSN architecture. The proposed solution keeps the SSN functionality intact and incurs a minimal area overhead as compared to the existing solutions.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
ATS1
2023 On Evaluating the Security of Dynamic Scan Obfuscation Scheme
abstract
Scan design is the most commonly used technique to ensure high test coverage in contemporary chips. However, attackers may use it as a trapdoor to gain access to the chip internals. Thus, it affects the overall chip security. Several techniques have been proposed to protect sensitive data from hackers. Recently, a countermeasure has been proposed that obfuscates the scan data using a test key. This scheme looks simple and effective against all the existing scan-based attacks. However, a detailed analysis of the scheme reveals that it is vulnerable to scan-based side-channel attacks. In this paper, it is shown that the test key could be retrieved successfully, and hence the security provided by this scheme is rendered ineffective. To address this vulnerability, a countermeasure is also proposed.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
IOLTS1
2023 On Protecting IJTAG using an Inherently Secure SIB
abstract
Modern VLSI circuits feature various embedded instruments that support non-functional features, e.g., test/debug, diagnosis, post silicon validation, in-field maintenance, etc. The IEEE Std. 1687 (IJTAG) facilitates efficient access to these on-chip instruments using a special scan cell known as Segment Insertion Bit (SIB). Concomitantly, it provides a covert channel for potential intruders to gain unauthorized access to these embedded instruments and thus extract confidential data such as FPGA firmware, secret keys, etc. Thus, it is quite imperative to restrict access to embedded instruments. Various techniques are present in the literature for enhancing the security of IJTAG network. However, securing the test infrastructure at the cost of complex hardware resources is not always a feasible solution.In this paper, a new mechanism to secure the IJTAG network which is based on a new Inherently Secure SIB (ISSIB) is proposed. The proposed technique makes use of an LFSR that is formed using the update cell of the ISSIBs. The proposed scheme is simple to implement, highly scalable and provides high level of security against unauthorized access. In addition to that, the proposed scheme preserves the conventional IJTAG features and has negligible area overhead.
Anjum Riaz, Gaurav Kumar 0001, Yamuna Prasad, Satyadev Ahlawat
VLSI-SoC2
2022 A New Access Protocol for Elevating the Security of IJTAG Network
abstract
The modern-day SoCs have various instruments and proprietary data embedded on chip for test, diagnosis, post-silicon debug, in-field health monitoring, authentication, counterfeit detection, etc. The testing infrastructure such as IEEE Std. 1687 (IJTAG) is incorporated into the ICs for flexible access to these on-chip instruments. However, this standard can be illegitimately used by malicious users for instigating side-channel attacks. In order to improve the security of the IJTAG network, a secure access protocol based on Chip ID, access software and Locking SIB (LSIB) has been proposed. Although this protocol elevates the security of the IJTAG network, in recent works, it has been shown that the secure access protocol is vulnerable to machine learning attack and differential analysis attack. In this work, a new secure access protocol is proposed which is built over the existing secure access protocol. The proposed protocol uses multiple templates which are selected randomly for embedding the key bits. It is shown that the proposed protocol can mitigate the efficacy of machine learning attack and differential analysis attack significantly. Moreover, it is simple to implement and incurs a marginal overhead in terms of area.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
ATS1
2022 On Attacking Locking SIB based IJTAG Architecture
abstract
The IEEE 1687 standard, which is commonly used for efficient access of on-chip instruments, could be exploited by an intruder and thus needs to be secured. One of the techniques to alleviate the vulnerability of 1687 network is to use a secure access protocol that is based on licensed access software, Chip ID and locking SIB. A licensed access software is generally used to gain control of the embedded instruments and use them as per requirement.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
ACM Great Lakes Symposium on VLSI1
2022 On Attacking IJTAG Architecture based on Locking SIB with Security LFSR
abstract
In recent decennium, hardware security has gained a lot of attention due to different types of attacks being launched, such as IP theft, reverse engineering, counterfeiting, etc. The critical testing infrastructure incorporated into ICs is very popular among attackers to mount side-channel attacks. The IEEE standard 1687 (IJTAG) is one such testing infrastructure that is the focus of attackers these days. To secure access to the IJTAG network, various techniques based on Locking SIB (LSIB) have been proposed. One such very effective technique makes use of Security Linear Feedback Shift Register (SLFSR) along with LSIB. The SLFSR obfuscates the scan chain information from the attacker and hence makes the brute-force attack against LSIB ineffective.In this work, it is shown that the SLFSR based Locking SIB is vulnerable to side-channel attacks. A power analysis attack along with known-plaintext attack is used to determine the IJTAG network structure. First, the known-plaintext attack is used to retrieve the SLFSR design information. This information is further used along with power analysis attack to determine the exact length of the scan chain which in turn breaks the whole security scheme. Further, a countermeasure is proposed to prevent the aforementioned hybrid attack.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
IOLTS1
2022 Power Analysis Attack on Locking SIB based IJTAG Achitecture
abstract
Today’s integrated circuits contain a large number and variety of embedded instruments that support testing, infield monitoring, post-silicon validation, etc. The IEEE Std. 1687 (IJTAG) provides efficient access to these embedded instruments by dynamically reconfiguring the IJTAG network. At the same time, it opens a backdoor for malicious users to steal sensitive information. Hence, access to embedded instruments through IJTAG must be restricted/secured. Various techniques have been proposed to prevent unauthorized access to the IJTAG network. One such very effective technique that improves the security of IJTAG network is a secure access protocol that uses licensed access software, Locking SIB (LSIB) and Chip ID. Although this technique is simple to implement and is very effective against scan attacks; however, it does not consider the power analysis attack.In this study, it is demonstrated that the security of the secure access protocol technique could be easily breached using a power analysis side-channel attack. The attack leads to unauthorized access to the embedded instruments which in turn could be used for various malicious purposes. Moreover, a countermeasure that mitigates the efficacy of power analysis attack significantly is proposed. It incurs a minimal area overhead and can be easily integrated into the existing secure access protocol.
Gaurav Kumar 0001, Anjum Riaz, Yamuna Prasad, Satyadev Ahlawat
VLSI-SoC1