EDBT 2026 Demo / reviewers in the wild / expert
Sergej Meschkov
dblp:307/3689
· DBLP profile ↗
9ranked-venue papers
2as first author
9since 2021 · last 2024
0000-0003-1552-589XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 2 first-author · 9 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | In-Field Detection of Small Delay Defects and Runtime Degradation Using On-Chip SensorsabstractThe increasing safety requirements for modern complex systems mandate Silicon Lifecycle Management (SLM) using various sensors for in-field test. In this work, we evaluate so-called Path Transient Monitors (PTMs), which are based on delay lines, to detect path delay increase caused by manufacturing defects or runtime degradation. These sensors are integrated into a RISC-V SoC on an FPGA, allowing software-controlled measurements and calibration. Additionally, we introduce means to emulate delay defects and degradations by injecting additional delay elements into a custom add instruction. Furthermore, by using power wasters, we provoke runtime voltage variations. Our evaluation in different temperatures shows the dependencies between different sources of delay variations and how the sensors can help in better detection of delay defects. Seyedeh Maryam Ghasemi, Sergej Meschkov, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
DATE | 2 |
| 2024 | Degradation Monitoring Through Software-controlled On-chip Sensors for RISC-VabstractComplex systems are subject to various hardware and software defects and faults through the entire design and deployment lifecycle. Many of such defects originate at the electrical or circuit levels, but manifest as functional failures in the field. In this study, we present a methodology for embedding and employing software-controlled runtime variation and degradation sensors on a RISC-V SoC to enable system-level and functional testing in the field. We demonstrate the effectiveness of the entire platform through an FPGA implementation. Delay defects and path degradations are emulated by injecting artificial delay elements into the critical path of a specific instruction. We also emulate the effect of workload-induced runtime stress with tunable software-controlled power wasters. Combining various sensors, we show that transient fluctuations, which are caused by temperature or workload, can be effectively separated from persistent delay increase, which is caused by latent manufacturing defects or aging. Seyedeh Maryam Ghasemi, Jonas Krautter, Tara Gheshlaghi, Sergej Meschkov, Dennis Gnad, Mehdi Baradaran Tahoori |
ETS | 4 |
| 2024 | Side-Channel Attack with Fault Analysis on Memristor-based Computation-in-MemoryabstractThe inherent limitations of traditional processor-centric architectures have led to the emergence of Computationin-Memory (CiM), offering an energy-efficient hardware solution for diverse applications such as deep learning and cryptography. However, CiM’s analog domain computations, relying on curren sensing for output, expose potential vulnerabilities to glitch-based fault injections. These are still unexplored in CiM and can prevent their widespread adoption. Our work investigates side-channel vulnerabilities in scouting logic CiM, revealing that an attacker can extract sensitive information with minimal measurements through side-channel analysis based on an effective Fault Sen sitivity Analysis (FSA). We demonstrate that with access to data-dependent delays at the transient output level, correlation analysis between fault sensitivity and transient output characteristics facilitates input data recovery. To counter these threats, we propose a power- and area-efficient circuit-level countermeasure tailored for CiM architectures, proving its effectiveness through comprehensive assessments, including correlation attacks and Test Vector Leakage Analysis (TVLA) with one million traces. Brojo Gopal Sapui, Sergej Meschkov, Mehdi Baradaran Tahoori |
IOLTS | 2 |
| 2023 | Power Side-Channel Attacks and Countermeasures on Computation-in-Memory Architectures and TechnologiesabstractTo overcome the bottleneck of the classical processor-centric architectures, Computation-in-Memory (CiM) is a promising paradigm where operations are performed directly in memory. Recent works propose the use of CiM to accelerate neural networks or hyperdimensional computing, but also for memory encryption solutions. As CiM facilitates the computation in the analog domain and the output is driven through current sensing, CiM could potentially be highly vulnerable to power side-channel attacks. In this work, we analyze the vulnerability for power side-channel attacks in various CiM implementations based on Static Random Access Memory (SRAM) and emerging nonvolatile memristive technologies. Our results show that a side-channel attacker can recover secret data used in an XOR operation with only a few hundred measurements, where CiM architectures based on emerging memristive technologies are more vulnerable than SRAM-based CiM. Therefore, we propose two different types of countermeasures based on hiding and masking, which are tailored to CiM architectures. The efficiency of our proposed countermeasures is shown by both attacks and leakage assessment methodologies using one million measurement traces. Brojo Gopal Sapui, Jonas Krautter, Mahta Mayahinia, Atousa Jafari, Dennis Gnad, Sergej Meschkov, Mehdi Baradaran Tahoori |
ETS | 6 |
| 2023 | Automated Masking of FPGA-Mapped DesignsabstractDue to the importance of FPGAs for secure systems, dealing with private data, protection against side-channel analysis attacks is a must. Although masking is a widely-deployed countermeasure, its application - particularly in hardware - is costly and error-prone. Therefore, generating masked hardware automatically with publicly-available tools such as AGEMA is attractive. As AGEMA was introduced to generate ASIC designs, its direct application on FPGAs is inefficient. In this work, we present AGEMA_FPGA to automatically generate highly-efficient masked circuits for FPGAs. Compared to the original AGEMA designs, our masked FPGA-based circuits utilize up to 64% fewer LUTs and at most 22% fewer FFs while the power consumption is reduced by at most 59%. We further provide an experimental side-channel security analysis of our designs confirming their provable security nature. Nicolai Müller, Sergej Meschkov, Dennis Gnad, Mehdi Baradaran Tahoori, Amir Moradi 0001 |
FPL | 2 |
| 2023 | SLM ISA and Hardware Extensions for RISC-V ProcessorsabstractNowadays, RISC-V processors have attracted much attention due to their extendability, for targeting high performance applications with strict demands on functional safety. Silicon Lifecycle Management (SLM) is a new emerging concept aiming at functional safety among other features such as availability, maintainability, and lifetime extension. This concept helps to monitor the system health during its lifecycle, in the various timespans, to ensure that safety margins while running critical applications are not exceeded. Hence, enabling both the collection of chip parametrics as well as in-field testing will provide the means to fulfill this concept. In this work, we propose instruction set extensions for enabling SLM in a RISC-V based system. For this purpose, we introduce Path Transient Monitors (PTM) and Voltage Fluctuations Monitors (VFM) for monitoring path delay and voltage fluctuations. Using power wasters as a mean to inject voltage fluctuations in the FPGA system, we evaluate the abilities of this system to monitor chip degradation in early stages before system failure. Seyedeh Maryam Ghasemi, Sergej Meschkov, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
IOLTS | 2 |
| 2023 | Enabling In-Field Parametric Testing for RISC-V CoresabstractRecently, RISC-V processors have been proposed in domains with high demand on both performance as well as functional safety, such as autonomous driving or medical devices. Therefore, enabling in-field test and measurement methods to ensure correct functionality over the entire chip lifecycle has become a necessity. In this paper, we propose an instruction set extension for RISC-V cores to enable on-chip telemetry for software-controlled in-field parametric testing. To that end, we introduce a so-called Path Transient Monitor (PTM) sensor, which is connected to the critical path of the core. Through custom instructions, the PTM is able to measure output transients with a timing resolution 1000 times (∼11.5 ps) higher than the rated clock period (few ns) of the RISC-V core, allowing thorough assessment of the device health state during in-field operation. As a case study, we implement our proposed setup as an FPGA-based hardware prototype and investigate the impact of process and design variation, temperature, and input data, to evaluate the usefulness of the collected sensor data. Seyedeh Maryam Ghasemi, Sergej Meschkov, Jonas Krautter, Dennis Gnad, Mehdi Baradaran Tahoori |
ITC | 2 |
| 2023 | New Approaches of Side-Channel Attacks Based on Chip Testing MethodsabstractThe state-of-the-art test infrastructure security is based on the assumption of preventing access to the sensitive information and the (publicly) accessible outputs or test infrastructure subset are supposed to not leak any secret information. In addition, for achieving functional safety requirements, the on-chip test infrastructure is reused in-field and cannot be completely disabled after the manufacturing test phase. Therefore, the access to the scan chains or similar test access ports which can lead to sensitive information needs to be restricted or encrypted to guarantee the security of the test infrastructure. However, in this work we show that having access to (small delay) test results on insensitive (public) outputs can in fact reveal secret data. Using real hardware, we have performed template attacks using the results of delay testing on the output of cryptographic circuits and were able to retrieve the key with very few test inputs. This template attack requires only a few random patterns on the victim device, which could be different from the device used for template building. In addition, the attack is also resilient against runtime variation and noise, as well as inaccuracies and down sampling of delay testing measurements. Sergej Meschkov, Dennis Gnad, Jonas Krautter, Mehdi Baradaran Tahoori |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | Is your secure test infrastructure secure enough? : Attacks based on delay test patterns using transient behavior analysisabstractThe existing work on securing test infrastructure is based on the assumption of restricting or encrypting access to the sensitive information, which otherwise can be accessed by the scan chains or similar test access ports. Hence, the (publicly) accessible outputs or test infrastructure subset supposedly do not leak secret information. Since the on-chip test infrastructure is reused in-field for achieving functional safety requirements, disabling them completely after manufacturing test phase is not an option. In this work we invalidate this assumption by showing that having access to (small delay) test results on insensitive (public) outputs can in fact reveal secret data. Using real hardware, we have performed template attacks using the results of delay testing on the output of cryptographic circuits and were able to retrieve the key with very few test inputs. This template attack requires only few random patterns on the victim device, which could be different from the device used for template building. Sergej Meschkov, Dennis Gnad, Jonas Krautter, Mehdi Baradaran Tahoori |
ITC | 1 |