Thomas Mauldin

dblp:270/3838 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
4since 2021 · last 2022
0000-0001-7754-2164ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2022 Software defined optical time-domain reflectometer
abstract
The rapid growth of high-speed transceiver technology has met the demand for higher data rates in modern society. The field of optical communication has taken advantage of this growth by using these transceivers with small form-factor pluggable modules. This work demonstrates that these readily available, widely deployed, and commercialized modules can be converted into a state-of-the art software defined optical time-domain reflectometer (SD-OTDR). Enabled by the reconfigurable computing resource, the SD-OTDR can realize in-situ diagnostics of optical fiber without adding any overhead to existing systems. This software defined reflectometer can obtain sub-cm spatial resolutions with a measurement sensitivity on the order of -65dB. This is made possible by using the advantages offered by the reconfigurable fabric in modern System-on-Chip platforms often found in communication networks.
Thomas Mauldin, Zhenyu Xu 0007, Tao Wei 0001
FCCM1
2022 Highly Scalable Runtime Countermeasure Against Microprobing Attacks on Die-to-Die Interconnections in System-in-Package
abstract
The emerging System-in-Package (SiP) technology has enabled multiple dies fabricated on a single chip for high performance and energy efficiency. Die-to-die (D2D) communication in SiP is typically unencrypted, exposing sensitive data to possible microprobing attacks. In this paper, we propose an on-chip microprobe detection circuit together with a noise canceling technique to protect D2D buses for future SiP security. The proposed method utilizes the metastable state of a flip-flop to detect the small timing variation caused by the inevitable loading effect of a microprobe. This design requires minimum digital resources with high scalability. Uniquely, the proposed design protects D2D buses at runtime without interfering with normal data transfers. In addition, it introduces zero latency to the communication channel. We built the detection circuit in a Xilinx ZYNQ Ultrascale+ SoC to prove its feasibility. Dynamic partial reconfiguration function is employed to create the test platform and emulate D2D interconnections as well as microprobing attacks on them. To demonstrate its potential to be used in standard communication protocols, we integrated the detection circuit with a fully functional Advanced eXtensible Interface (AXI) bus. Experimental results show that the proposed runtime detection method is effective, resource-efficient, and reliable under temperature-varying environments.
Zhenyu Xu 0007, Thomas Mauldin, Qing Yang 0001, Tao Wei 0001
FPGA2
2021 Runtime Detection of Probing/Tampering on Interconnecting Buses
abstract
It has been reported that physical probing on an off-chip bus can reveal confidential information in an electronic system. An attacker can use non-invasive and inexpensive electric probes (or interposers) to measure signals from circuit traces, such as the memory bus between the memory controller and a memory module. This paper describes a method to detect any bus probing/tampering by tracking the phase shift of output digital waveforms, induced by input impedance change at the bus transmitter (Tx). A low-overhead digital circuit based on flip-flop's metastability is built around the Tx using a field-programmable logic gate array (FPGA) to precisely measure the phase shift of output signals. Uniquely, the output data launched by the Tx is used as a stimulus signal, thus, the proposed method holds the advantage of detecting probing attacks at run-time. That is, the detection action operates in parallel with the normal data transfer on a bus without any interference, imposing zero latency to the communication channel. In order to show its feasibility in a real-world communication protocol, we implemented the proposed method in the DDR memory controller on an FPGA board (Xilinx ZCU104). The working prototype is able to protect a memory bus between the FPGA board and a DDR4 DIMM with a data rate of 2400MT/s. Experimental results show that the proposed method can be used to countermeasure interposer attacks, probing attacks, and cold boot attacks. We believe that the proposed method can be implemented in a variety of communication channels.
Zhenyu Xu 0007, Thomas Mauldin, Qing Yang 0001, Tao Wei 0001
FCCM2
2021 Minimal Overhead Optical Time-Domain Reflectometer Via I/O Integrated Data Converter Enabled by Field Programmable Voltage Offset
Thomas Mauldin, Zhenyu Xu 0007, Tao Wei 0001
FPL1
2020 A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and Beyond
abstract
Tamper-proof hardware designs present a great challenge to computer architects. Most existing research limits hardware trusted computing base (TCB) to a CPU chip and anything off the CPU chip is vulnerable to probing and tampering. This paper introduces a new hardware design that provides strong defenses against physical attacks on interconnecting buses between chips in a computer system thereby extending the hardware TCB beyond CPU chips. The new approach is referred to as DIVOT: Detecting Impedance Variations Of Transmission-lines (Tx-lines). Every Tx-line in a computer system, such as a bus and interconnection wire has a unique, intrinsic, and fingerprint-like property: Impedance Inhomogeneity Pattern (IIP), i.e. the impedance distribution over distance. Such unpredictable, uncontrollable, and non-reproducible IIP fingerprints can be used to authenticate a Tx-line to ensure the confidentiality and integrity of data being transmitted. In addition, physical probes perturb the electromagnetic (EM) field around a Tx-line, leading to an altered IIP. As a result, runtime monitoring of IIPs can also be used to actively detect physical probing, snooping, and wire-tapping on buses. While the physics behind the IIP is known, the major technical breakthrough of DIVOT is the new integrated time domain reflectometer, iTDR, that is capable of carrying out in-situ and runtime monitoring of a Tx-line without interfering with normal data transfers. The iTDR is based on two innovations: analog-to-probability conversion (APC) and probability density modulation (PDM). The iTDR performs runtime IIP measurements noninvasively and is CMOS-compatible allowing it to be integrated with any interface logic connected to a bus. DIVOT is a generic, scalable, cost-effective, and low-overhead security solution for any computer system from servers to embedded computers in smart mobile devices and IoTs. To demonstrate the proposed architecture, a working prototype of DIVOT has been built on an FPGA as a proof of concept. Experimental results clearly showed the feasibility and performance of DIVOT for both hardware authentication and tamperproof applications. More specifically, the probability of correctly identifying a bus is close to 1 with an equal error rate (EER) of less than 0.06% at room temperature. We present an example design that incorporates DIVOT into an off-chip memory bus to protect against physical attacks including probing/snooping, tampering, and cold boot attacks.
Zhenyu Xu 0007, Thomas Mauldin, Zheyi Yao, Shuyi Pei, Tao Wei 0001, Qing Yang 0001
ISCA2