Yogendra Sao

dblp:286/6988 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2024
0000-0003-1392-319XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 3 first-author · 5 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 DefScan: Provably Defeating Scan Attack on AES-Like Ciphers
abstract
Scan-based Design-for-testability (DfT) is the de facto standard in the semiconductor testing industry to guarantee the functional and structural correctness of chips. It provides improved observability and controllability, leading to enhanced fault coverage. However, owing to widespread usage, attackers devise techniques to misuse this method to steal secret keys embedded in a security-critical chip. A vast majority of off-the-shelf defense mechanisms are based on either randomizing the scan output or restricting access to the scan. However, none of these defense mechanisms leverage the fundamental properties of the scan attack; thus, they tend to be complex and incur high area and computation overhead. In this paper, we propose a defense mechanism by preventing the vulnerabilities of fundamental properties from being exploited in scan attacks. The paper first pinpoints the ultimate condition of the scan attack on Advanced Encryption Standard (AES). This attack condition is inherent to the cryptographic property of the cipher, which, when violated, thwarts the attack. To implement our defense, we interchange the AES round outputs by applying pre-computed masks. The designer chooses inputs with a fixed difference to swap the outputs. A modified incorrect key is recovered instead of an actual key if a scan-based attack is launched. To show the generality of the proposed defense, it is extended to another AES-like cipher, Light Encryption Device (LED). To the best of our knowledge, this is the first defense against a scan attack wherein the complete testing process, including structural and functional tests, can be outsourced to untrusted third parties without compromising the actual key. In comparison, logic locking techniques limaye2020thwarting can outsource only structural testing to untrusted third parties.
Yogendra Sao, Subidh Ali, Bodhisatwa Mazumdar
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2023 On Securing Cryptographic ICs against Scan-based Attacks: A Hamming Weight Distribution Perspective
abstract
Scan chain-based Design for Testability is the industry standard in use for testing manufacturing defects in the semiconductor industry to ensure the structural and functional correctness of chips. Fault coverage is significantly enhanced due to the higher observability and controllability of the internal latches. These ensuing benefits to testing, if misused, expose vulnerabilities that can be detrimental to the security aspects, especially in the context of crypto-chips that contain a secret key. Hence, it remains of paramount importance for a chip designer to secure crypto-chips against various scan attacks. A countermeasure is proposed in this article that preserves the secrecy of an embedded key in a cryptographic integrated circuit running an Advanced Encryption Standard (AES) implementation. A novel design involving a hardware unit is illustrated that circumvents differential scan attacks by essentially performing bit flips deterministically, using a pre-computed mask value. This helps secure the chip while retaining full testability. The controller logic directly depends on a mask determination algorithm that can defend against any scan attack with 𝒪 theoretical complexity. Security analysis of our proposed defense procedure is performed in the framework of Discrete Event Systems (DES). The sequential scan circuit of an AES cryptosystem is modeled as a DES using Finite State Automata. A security notion, Opacity , is used to quantify and formally verify the security aspects of our controlled system, which shows that the entropy of the secret key is preserved. A case study is performed that shows to mitigate state-of-the-art differential scan attacks successfully at a nominal extra overhead of 1.78%.
Dipojjwal Ray, Yogendra Sao, Santosh Biswas, Subidh Ali
ACM J. Emerg. Technol. Comput. Syst.2
2023 Security Analysis of Scan Obfuscation Techniques
abstract
Scan is the de-facto standard for testing, which provides high observability and test coverage by enabling direct access to chip memory elements. The scan-based Design-for-Testability (DfT) technique has also become the prime target of attackers whose aim is to extract the secret information embedded inside a chip by misusing its scan infrastructure. Several countermeasures have been proposed to protect the chip against scan-based attacks. Recently, obfuscation-based defense mechanisms have gained significant popularity, which protect scan data by corrupting some of the scan cell’s content. In this paper, we perform a detailed security analysis of three best-known obfuscation techniques, namely, static, dynamic, and advanced dynamic obfuscation techniques, designed to protect the AES crypto-chip. We exploit their vulnerabilities and propose a generic scan-based signature attack, leading to the leakage of the secret cipher key that too, using only one observable scan cell. We also propose upgrades to the two dynamic scan obfuscation techniques to patch the discovered vulnerabilities with negligible changes to the original design. In order to show the generality of the attack, we also applied our attack to the similar cipher PRESENT and seven other scan obfuscation techniques. The result shows that in addition to the above three best-known obfuscation techniques, five out of the seven other scan obfuscation techniques were also successfully broken by our generic attack.
Yogendra Sao, Subidh Ali
IEEE Trans. Inf. Forensics Secur.1
2022 Evaluating Security of New Locking SIB-based Architectures
abstract
The IEEE Std 1687 (IJT AG) provides enhanced access to the on-chip test instruments, which are included on the chip for test, post-silicon debug, in field maintenance, and diagnosis purposes. Although the on-chip instruments access provides data and features explicitly for test and debug, these features are misused by the malicious user to access sensitive data such as encryption keys, Chip-IDs, etc. Hence, it is desired to limit the access to sensitive on-chip instruments via IJT AG network. One of the various schemes proposed to mitigate the vulnerability of the IJT AG network is to use a secure access protocol, which is based on LSIB, Chip-ID, and licensed access software.In this paper, the detailed security analysis is performed on IJT AG, it is shown that the secure access protocol technique is vulnerable to differential analysis attack. It can be used to break the secure communication between the board and the licensed access software and thus, the sensitive on-chip test instruments can be accessed illegitimately. It is shown that our proposed algorithm can recover the template used for secure communication within a fraction of a second.
Yogendra Sao, Anjum Riaz, Satyadev Ahlawat, Subidh Ali
ETS1
2021 Opacity preserving Countermeasure using Finite State Machines against Differential Scan Attacks
abstract
Scan based DfT is the de facto standard for testing the functional and structural correctness of chips. It provides high observability and controllability of internal latches leading to enhanced fault coverage, but can also induce vulnerability in crypto-chips containing an embedded secret key. Protecting crypto-chips against scan attack is of paramount concern to a designer. In this paper, we propose a countermeasure using a controller to circumvent differential scan attacks on crypto-chips running an AES implementation. The controller we design is minimally restrictive and ensures security by performing deterministic bit flips yet maintaining full testability. The controller logic directly depends on input-based pre-computed mask values and the controlled system behaviour is formally verified to be secure using the notion of Opacity. We evaluate our defense by launching recent attacks on the AES cryptosystem. Our security analysis shows that the proposed technique is secure against the state of the art scan based differential scan attacks with a nominal hardware overhead of 0.94%.
Subidh Ali, Yogendra Sao, Santosh Biswas
ETS2
2021 Security Analysis of State-of-the-art Scan Obfuscation Technique
abstract
Scan-based Design for Testability (DfT) is the de-facto standard for detecting manufacturing-related faults in chip manufacturing industries. The observability and accessibility provided by DfT can be misused to launch an attack to reveal the secret key, which is embedded inside a crypto chip. Several countermeasures have been proposed to protect the chip against scan-based attacks. Dynamic obfuscation of scan data prevents scan-based attacks by corrupting scan data in the case of unauthorized access. In this paper, we perform the security analysis of the above state-of-the-art obfuscation technique to showcase its vulnerabilities. Exploiting its vulnerabilities, we propose a scan-based signature attack on state-of-the-art obfuscation technique by applying a maximum of 4096 plaintexts and using only 220signatures with a 100% success rate.
Yogendra Sao, Subidh Ali
ICCD1