EDBT 2026 Demo / reviewers in the wild / expert
Nay Aung Kyaw
dblp:244/7624
· DBLP profile ↗
11ranked-venue papers
0as first author
8since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RASLL: A Removal Attack on SAT-Resistant Logic Locking
Zijian Long, Juncheng Chen, Tong Lin 0001, Nay Aung Kyaw, Bah-Hwee Gwee |
ISCAS | 5 |
| 2025 | N-MUX: Neighborhood-Based Logic Locking Against Machine Learning AttacksabstractMUX-based logic locking (LL) is a hardware security technique that inserts multiplexers (MUX) into circuits to secure them against unauthorized use and reverse engineering by protecting original circuit pathways. Nevertheless, MUX-based LL is vulnerable to Oracle-Guided (OG) and Oracle-Less (OL) attacks. While OG methods, such as the SAT attack, are infeasible for large-scale designs, OL attacks, like those based on machine learning (ML), can exploit structural leakage in locked circuits to recover original pathways. This study introduces N-MUX, an innovative MUX-based LL approach designed to resist state-of-the-art (SOTA) ML attacks. N-MUX effectively reduces structural leakage by identifying maximal overlap structures in the original circuit to configure the MUX logic. Additionally, N-MUX ensures high efficiency by selecting the false input from the direct neighbourhood of the true input. Experimental results on ISCAS’85 and ITC’99 benchmarks demonstrate that N-MUX is the most secure and reliable LL technique against SOTA ML-based attacks, achieving an 81% reduction in attack accuracy compared to existing MUX-based LL methods and delivering up to 480× greater efficiency. Xuenong Hong, Shirui Sheng, Juncheng Chen, Nay Aung Kyaw, Kwen-Siong Chong, Zhiping Lin 0001, Bah-Hwee Gwee |
ISCAS | 5 |
| 2024 | A Novel Non-profiling Side-Channel Attack on Masked Devices with Connectivity MatrixabstractIn this paper, we propose a novel pre-processing technique known as the Connectivity Matrix (CM). Building upon the foundation of the CM, we present an effective Second-Order Side-Channel Attack, called Connectivity Matrix Attack (CMA). Our work aims to efficiently counter hardware devices fortified with Masking countermeasures, and it contributes in three significant ways. First, the proposed CM has lower data complexity, as it is constant regarding the number of measurements. Second, we propose the decomposition of the CMs and the utilization of their eigenvalues as feature vectors in CMA. This approach effectively removes noisy components from the CMs and reduces their dimensions. Third, the proposed CMA employs the selected eigenvalues to establish a frequency distribution, followed by a chi-square test. This approach allows CMA to expose both the linear and non-linear leakages present in CMs. The proposed CMA is validated on the public dataset ASCAD and can reveal all the masked bytes successfully. Notably, the concept of the Connectivity Matrix extends beyond the confines of a correlation matrix used in this paper, opening the door to a promising avenue for future research. Juncheng Chen, Zishuo Yang, Nay Aung Kyaw, Kwen-Siong Chong, Zhiping Lin 0001, Bah-Hwee Gwee |
ISCAS | 5 |
| 2024 | Securing Against Side-Channel Attacks With Wide-Range In Situ Random Voltage Dithering on Async-Logic AES EngineabstractWe present a wide-range in situ random voltage dithering (WIS-RVD) on async-logic advanced encryption standard (AES) engine to counteract side-channel attacks (SCAs). There are three contributions in this brief. First, we propose the WIS-RVD based on a dual-rail asynchronous-logic (async-logic) AES engine, leveraging on the self-timed clockless operations for robust encryption under dynamic voltage and timing variations. Second, we propose an in situ voltage dithering to dither the supply voltage instantaneously during the encryption, without the requirement of additional control circuits for clock modulation, to increase the SCA resistance. Third, we propose a wide-range voltage swing technique that spans from 0.3 V (subthreshold) to 1.1 V (above threshold), obfuscating the transistor’s current models between subthreshold and threshold voltage to further enhance SCA resistance. We perform comprehensive SCA evaluations with 50-M power and EM measurements, and the SCA evaluations show that our proposed WIS-RVD on async-logic AES accelerator can resist SCAs with 50-M measurements, i.e.,$\gt 2083\times $and$\gt 2778\times $improvement for power and EM SCAs, respectively, when compared to the standard synchronous-logic AES. Jun-Sheng Ng, Juncheng Chen, Nay Aung Kyaw, Kwen-Siong Chong, Bah-Hwee Gwee |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2023 | Improving FPGA-based Async-logic AES Accelerator with the Integration of Sync-logic Block RAMsabstractWe present a side-channel attack (SCA) resistant asynchronous-logic (async-logic) AES accelerator that integrates synchronous-logic (sync-logic) Block RAMs (BRAMs) in FPGA as the Substitution-Box. We successfully identify the timing requirements to integrate sync-logic BRAMs in our async-logic AES accelerator and validate our proposed AES accelerator on the Sakura-X FPGA board. With the integration of BRAMs, we improve the resource utilization on FPGA by$1.6\times$when compared to the state-of-the-art async-logic AES accelerator, while reducing the power overhead by$1.4\times$. We comprehensively evaluate the SCA resistance of our proposed async-logic AES accelerator with 11 attacking models in both time and frequency domains. Based on our evaluations, we show that our proposed async-logic AES accelerator is highly secure against SCA with 30 million EM traces. This is more than$6000\times$improvement when compared to the benchmark sync-logic AES accelerator and$1.5\times$improvement when compared to the state-of-the-art async-logic AES accelerator. Jun-Sheng Ng, Juncheng Chen, Nay Aung Kyaw, Kwen-Siong Chong, Zhiping Lin 0001, Bah-Hwee Gwee |
ISCAS | 4 |
| 2022 | Non-profiling based Correlation Optimization Deep Learning AnalysisabstractDifferential Deep Learning Analysis (DDLA) is a deep learning-based non-profiling side-channel attack leveraging neural networks to classify Physical Leakage Information with labels. To avoid the Class Imbalance Problem (CIP) of significantly different data sizes in different data groups, DDLA employs bit labels. However, applying bit labels will be less effective for exploiting leakage. In this paper, we propose to employ Correlation optimization Deep Learning Analysis (CO-DLA) to circumvent the CIP in DDLA by converting the classification in DDLA into a correlation optimization. Bus labels can then be used to exploit stronger leakage information. To validate the attack efficacy improvement, we perform experiments on ASCAD synchronized and de-synchronized masked AES-128 datasets. For the synchronized masked dataset, our proposed CO-DLA requires only 5k traces, which is 75% lesser than the 20k traces required by the reported DDLA, to reveal the key-byte. For the 2 de-synchronized masked datasets, our proposed CO-DLA requires only 10k traces to reveal the key-byte from both of them while the reported DDLA fails to reveal the key-byte. Juncheng Chen, Jun-Sheng Ng, Nay Aung Kyaw, Ne Kyaw Zwa Lwin, Kwen-Siong Chong, Zhiping Lin 0001, Joseph Sylvester Chang, Bah-Hwee Gwee |
ISCAS | 3 |
| 2022 | An Asynchronous-Logic Masked Advanced Encryption Standard (AES) Accelerator and its Side-Channel Attack EvaluationsabstractWe present a side-channel-attack (SCA) resistant asynchronous-logic (async-logic) Advanced Encryption Standard (AES) accelerator embodying both the masking and hiding SCA countermeasures. Our async-logic masked AES accelerator adopts a dual-rail data encoding to perform the masked 128-bit AES operations, and to enable dual-hiding to moderate both the amplitude (vertical dimension) and the time (horizontal dimension) of the side-channel signals. We implement our async-logic masked AES accelerator in FPGA and comprehensively perform the SCA evaluations based on the electromagnetic (EM) emanation. The SCA evaluations are performed based on bus-wise Hamming Distance model, bus-wise & bit-wise Hamming Weight models, and Zero-Value (ZV) model. Based on our experiment results, we show that our async-logic masked AES is secured against SCA with 1 million EM emanations. This is at least $8.3 \times$ more resistant than synchronous-logic masked AES and $200 \times$ more resistant than the synchronous-logic unmasked AES. Jun-Sheng Ng, Juncheng Chen, Nay Aung Kyaw, Ne Kyaw Zwa Lwin, Kwen-Siong Chong, Joseph Sylvester Chang, Bah-Hwee Gwee |
ISCAS | 3 |
| 2021 | Normalized Differential Power Analysis - for Ghost Peaks MitigationabstractThe attack efficacy of Differential Power Analysis (DPA), a popular side channel evaluation technique for key extraction, is compromised by the false highest Difference Of Means (DOMs) value ('ghost peaks') in the DOMs matrix produced in a conventional DPA. The ghost peak is generated by the wrong key guess and always occurs in the conventional DPA when the number of side channel traces is not enough. In this paper, an improved version of the conventional DPA termed as Normalized DPA (NDPA) is proposed to circumvent the ghost peak. With the analysis on the generation of ghost peaks in the conventional DPA, we observed that by normalizing the DOMs matrix, the ghost peaks can be greatly suppressed. We model the proposed NDPA mathematically and show that it performs better than the conventional DPA. We further provide the experimental validations on a set of 200k power simulation traces on AES S- Box and 500 EM traces from ASCAD dataset. Based on the attack results of these datasets, our proposed NDPA requires (up to 68%) lesser number of traces to reveal a correct key when compared to the conventional DPA. Juncheng Chen, Jun-Sheng Ng, Nay Aung Kyaw, Ne Kyaw Zwa Lwin, Weng-Geng Ho, Kwen-Siong Chong, Zhiping Lin 0001, Joseph Sylvester Chang, Bah-Hwee Gwee |
ISCAS | 3 |
| 2020 | A DPA-Resistant Asynchronous-Logic NoC Router with Dual-Supply-Voltage-Scaling for Multicore Cryptographic ApplicationsabstractWe propose a 5-port asynchronous-logic Network-on-Chip (ANoC) router based on the Sense-Amplifier Half-Buffer (SAHB) approach for cryptographic processing cores to counteract side channel attack differential power analysis (DPA) in multicore platform. There are three features in the proposed DPA-resistant ANoC router. First, the proposed ANoC router embodies dual-supply-voltage SAHB cells, where the non-critical subsidiary supply voltage is adjustable from 0.3V to 1.2V, increasing the noise variance and hence reducing the Signal-to-Noise (SNR) ratio to hide the information leakage. Second, the proposed ANoC router performs as a noise engine by increasing the number of power-on IO ports, further randomizing the overall power dissipation. Third, the proposed ANoC router can switch between DPA-resistant mode and energy-efficient nominal (non-secure) mode, saving the power dissipation when the DPA secure countermeasure is unnecessary. Based on 65nm CMOS process, the multicore platform embedded with the proposed ANoC router is implemented, and the experiment is demonstrated by running the advanced encryption standard (AES) cryptography operation. When benchmarked against the nominal mode, the noise power variance of the proposed ANoC router increases by 2.3× in the DPA-resistant mode, reducing the overall SNR ratio by 56%. When comparing to other reported noise engines, our proposed ANoC router is one of the most DPA-secure, area-efficient and power-efficient designs for multicore cryptographic applications. Weng-Geng Ho, Ne Kyaw Zwa Lwin, Nay Aung Kyaw, Jun-Sheng Ng, Juncheng Chen, Kwen-Siong Chong, Bah-Hwee Gwee, Joseph Sylvester Chang |
ISCAS | 3 |
| 2020 | A Highly Efficient Power Model for Correlation Power Analysis (CPA) of Pipelined Advanced Encryption Standard (AES)abstractWe evaluate the vulnerability of a pipelined Advanced Encryption Standard (AES) against Correlation Power Analysis (CPA) Side-Channel Attack (SCA). We identify that the registers in pipelined AES are most vulnerable against CPA SCA and propose a new power model targeting the switching activities of the registers. The proposed power model is constructed based on the Hamming Distance (HD) between the intermediate values stored in the registers in two consecutive clock cycles. Then, we analyze the vulnerability of pipelined AES under two scenarios. First, during regular pipeline operation where the device is performing AES pipeline operation. Second, in non-pipeline operation where we assume the adversaries can insert delay to the input of the device to increase the signal to noise ratio of the physical leakage information. The simulation results show that under regular pipelined operation, our proposed power model can reveal all the 16 key bytes in less than 4,900 traces, resulting in 4.7× more effective than the conventional power models. Under non-pipelined operation, our proposed power model requires only 590 traces to reveal all the 16 key bytes, which is 5.9× more effective than other power models. Jun-Sheng Ng, Juncheng Chen, Nay Aung Kyaw, Ne Kyaw Zwa Lwin, Weng-Geng Ho, Kwen-Siong Chong, Bah-Hwee Gwee |
ISCAS | 3 |
| 2019 | Low Gate-Count Ultra-Small Area Nano Advanced Encryption Standard (AES) DesignabstractWe present a low gate-count ultra-small area nano advanced encryption standard (AES) design. We achieve the low gate-count by the following means. First, we repeatedly reuse the area-critical circuits, i.e. one 8-bit Substitute-Box (S-Box) circuit and one 32-bit MixColumn circuit, for AES. Second, we cascade the input flip-flops (FFs) with our data transfer architecture so that the outputs of the MixColumn circuit are connected directly to the first 32-bit input FFs without extra multiplexing circuits. Third, the ShiftRow operation is implicitly performed by assigning the data sequence to the input FFs (during the S-Box and MixColumn operations). Fourth, we use independent XOR gates for AddRound and KeyExpansion operations. The collective means enables our design to feature 1457 gates, and to occupy 100um×100um area @ 65nm CMOS. When compared to the normalized area (@ 65nm CMOS) of the reported AES designs, our design features the smallest normalized area, 10% smaller than the most competitive reported AES design. Our design is targeted for ultra-small area applications including biomedical applications. Aparna Shreedhar, Kwen-Siong Chong, Ne Kyaw Zwa Lwin, Nay Aung Kyaw, L. Nalangilli, Wei Shu, Joseph Sylvester Chang, Bah-Hwee Gwee |
ISCAS | 4 |