Jasper Van Woudenberg

dblp:274/4884 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 Improving CPU Fault Injection Simulations: Insights from RTL to Instruction-Level Models
abstract
Fault injection simulators are essential tools for evaluating the robustness of software programs against hardware faults. Instruction-level simulators offer high speed but lack accuracy, whereas register-transfer level (RTL) simulators provide high accuracy but are slow. This paper demonstrates that the accuracy of instruction-level simulators can be significantly improved by modeling fault effects observed in RTL-level simulations and incorporating those models into the instruction-level simulator. The fault effect models are designed to capture only architecturally visible changes to the CPU state. We first introduce a model based on characterization on the probabilities of observed fault effects, which improves upon traditional models such as NOP and instruction bitflip. By observing how faults affect specific CPU registers, we improve this further and define the ‘regonly’ model. This model achieves significantly higher accuracy than the other models with respect to RTL-level simulations, without incurring the computational overhead associated with RTLbased simulations.
Jasper Van Woudenberg, Rajesh Velegalati, Cees-Bart Breunesse, Dennis Vermoen Riscure
FDTC1
2023 Invited: Pre-silicon Side Channel and Fault Analysis
abstract
In this work, we address the challenges of side channel analysis (SCA) and fault injection (FI) in the pre-silicon design stage, particularly for cryptographic implementations. We show that the industry perspective uncovers different challenges than those usually tackled by academia, emphasizing the need for practical and scalable solutions. We present (Side Channel Attack Testbench Emulator) SCATE, a framework for detecting and mitigating SCA vulnerabilities, leveraging industry-standard electronic design automation (EDA) software for efficient power estimation and FI simulations. Moreover, we demonstrate a significant performance increase in power simulation tools by optimizing EDA algorithms for SCA applications, resulting in faster power trace generation. Additionally, we discuss the application of formal property verification (FPV) for verifying fault injection countermeasures and present a case study on an AES S-box. These approaches enable non-security-expert designers to evaluate SCA and FI resistant designs with significant time savings. The vulnerabilities uncovered by these approaches highlight the importance of pre-silicon analysis at each design stage to produce secure application-specific integrated circuits (ASICs).
Jasper Van Woudenberg, Peter Grossmann, Avinash L. Varna, Joseph Friel, Daniel Dinu, Ronnie Lindsay, Steve J. Brown
DAC1
2023 Special Session: CAD for Hardware Security - Promising Directions for Automation of Security Assurance
abstract
Hardware security creates a hardware-based security foundation for secure and reliable operation of systems and applications used in our modern life. The presence of design for security, security assurance, and general security design life cycle practices in product life cycle of many large semiconductor design and manufacturing companies these days indicates that the importance of hardware security has been very well observed in industry. However, the high cost, time, and effort for building security into designs and assuring their security - due to using many manual processes - is still an important obstacle for economy of secure product development. This paper presents several promising directions for automation of design for security and security assurance practices to reduce the overall time and cost of secure product development. First, we present security verification challenges of SoCs, possible vulnerabilities that could be introduced inadvertently by tools mapping a design model in one level of abstraction to its lower level, and our solution to the problem by automatically mapping security properties from one level to its lower level incorporating techniques for extension and expansion of the properties. Then, we discuss the foundation necessary for further automation of formal security analysis of a design by incorporating threat model and common security vulnerabilities into an intermediate representation of a hardware model to be used to automatically determine if there is a chance for direct or indirect flow of information to compromise confidentiality or integrity of security assets. Finally, we discuss a pre-silicon-based framework for practical and time-and-cost effective power-side channel leakage analysis, root-causing the side-channel leakage by using the automatically generated leakage profile of circuit nodes, providing insight to mitigate the side-channel leakage by addressing the high leakage nodes, and assuring the effectiveness of the mitigation by reprofiling the leakage to prove its acceptable level of elimination. We hope that sharing these efforts and ideas with the security research community can accelerate the evolution of security-aware CAD tools targeted to design for security and security assurance to enrich the ecosystem to have tools from multiple vendors with more capabilities and higher performance.
Sohrab Aftabjahani, Mark Tehranipoor, Farimah Farahmandi, Bulbul Ahmed, Ryan Kastner, Francesco Restuccia 0002, Andres Meza 0001, Kaki Ryan, Nicole Fern, Jasper Van Woudenberg, Rajesh Velegalati, Cees-Bart Breunesse, Cynthia Sturton, Calvin Deutschbein
VTS10
2021 Rewrite to Reinforce: Rewriting the Binary to Apply Countermeasures against Fault Injection
abstract
Fault injection attacks can cause errors in software for malicious purposes. Oftentimes, vulnerable points of a program are detected after its development. It is therefore critical for the user of the program to be able to apply last-minute security assurance to the executable file without having access to the source code. In this work, we explore two methodologies based on binary rewriting that aid in injecting countermeasures in the binary file. The first approach injects countermeasures by reassembling the disassembly whereas the second approach leverages a full translation to a high-level IR and lowering that back to the target architecture.
Pantea Kiaei, Cees-Bart Breunesse, Mohsen Ahmadi, Patrick Schaumont, Jasper Van Woudenberg
DAC5