EDBT 2026 Demo / reviewers in the wild / expert
Honghui Tang
dblp:296/0737
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0003-3142-1812ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Fault Model Analysis of DRAM under Electromagnetic Fault Injection AttackabstractElectromagnetic fault injection (EMFI) attack has posed serious threats to the security of integrated circuits. Memory storing sensitive codes and data has become the first choice of attacking targets. This work performs a thorough characterization of the induced faults and the associated fault model of EMFI attacks on DRAM. Specifically, we firstly carry out a set of experiments to analyse the sensitivity of various types of memory to EMFI. The analysis shows that DRAM is more sensitive to EMFI than EEPROM, Flash, and SRAM in this experiment. Then, we classify the induced faults in DRAM and formulate the fault models. Finally, we find the underlying reasons that explain the observed fault models by circuit-level simulation of DRAM under EMFI. The in-depth understanding of the fault models will guide design of DRAM against EMFI attacks. Qiang Liu 0011, Longtao Guo, Honghui Tang |
DATE | 3 |
| 2022 | MPFA: An Efficient Multiple Faults-Based Persistent Fault Analysis Method for Low-Cost FIAabstractIn recent studies, a fault analysis method, called persistent fault analysis (PFA), is proposed for cracking block ciphers. Unlike widely used differential fault analysis methods, PFA does not require correct cihpertexts and precise time control of fault injection. The existing PFA methods mainly assume single fault, i.e., the fault injection process induces a single fault in the target cipher devices. However, the existing low-cost fault injection attack (FIA) techniques, such as clock glitch injection and electromagnetic pulse (EMP) injection usually induce multiple faults per injection. Given multiple faults, the existing PFA methods are either not applicable or faced with high computational complexity in practice. In this article, a new PFA method, called MPFA, is proposed for multiple persistent faults, which reduces both the computational complexity and the required ciphertexts. MPFA can be applied to the ciphertexts-only attack scenario, where all fault positions, fault values, and fault quantity are unknown. The experiments show that compared to the existing PFA methods, the MPFA method reduces the required ciphertexts for cracking AES by at least 57.5% and reduces the computational complexity$NF^{16}$times for$NF$faults. The proposed MPFA is also evaluated on the block ciphers LED and PRINCE. Moreover, a real EMP FIA is carried out and the key of AES-128 is successfully cracked by the MPFA method, demonstrating its validity and efficiency. Honghui Tang, Qiang Liu 0011 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2022 | Fault Injection Attack Emulation Framework for Early Evaluation of IC DesignsabstractFault injection attack (FIA) has become a serious threat to the confidentiality and fault tolerance of integrated circuits (ICs). Circuit designers need an effective method to evaluate the countermeasures of the IC designs against the FIAs at the design stage. To address the need, this article, based on FPGA emulation, proposes an in-circuit early evaluation framework, in which FIAs are emulated with parameterized fault models. To mimic FIAs, an efficient scan approach is proposed to inject faults at any time at any circuit nodes, while both the time and area overhead of fault injection are reduced. After the circuit design under test (CUT) is submitted to the framework, the scan chains insertion, fault generation, and fault injection are executed automatically, and the evaluation result of the CUT is generated, making the evaluation a transparent process to the designers. Based on the framework, the confidentiality and fault-tolerance evaluations are demonstrated with an information-based evaluation approach. Experiment results on a set of ISCAS89 benchmark circuits show that on average, our approach reduces the area overhead by 41.08% compared with the full scan approach and by over 20.00% compared with existing approaches. The confidentiality evaluation experiments on AES-128 and DES-56 and the fault-tolerance evaluation experiments on two CNN circuits, a RISC-V core, a Cordic core, and the float point arithmetic units show the effectiveness of the proposed framework. Qiang Liu 0011, Honghui Tang |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2021 | Lightweight and Configurable Synchronizer and Demodulator Design for PDSCH on FPGAabstractTargeting at small satellite applications, we propose a lightweight and configurable circuit design for synchronization and demodulation, which are the key processing steps of PDSCH receiver, on FPGA. We design an elaborately pipelined circuit with balanced speed and area, by analysing the operation complexity and sharing resources among the operations. The circuit design is configurable such that the circuit can switch state at run-time to support multiple data rates and modulation schemes. Also, a parametric truncation module is realized to implement the circuit with fixed-point numbers. Experiments prove that the lightweight circuit can perform real-time processing of received data with good demodulation performance. Chongguang Yao, Qiang Liu 0011, Linan Wang, Qingye Zhang, Honghui Tang, Maoshen Zhang |
ISCAS | 5 |