Francesco Regazzoni 0001

dblp:31/1489-1 · DBLP profile ↗
← Back
81ranked-venue papers
11as first author
25since 2021 · last 2026
0000-0001-6385-0780ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 58 · 7 first-author · 17 since 2021Security and privacy · 19 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 16 · 3 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SwiftSNNI: Optimized Scheduling for Secure Neural Network Inference (SNNI) on Multi-Core Systems
abstract
Secure Neural Network Inference (SNNI) enables privacy-preserving inference on encrypted data with strong cryptographic guarantees. However, practical deployments suffer from high preprocessing overhead, significant communication costs, and sequential execution. These limitations lead to low throughput, underutilized system resources, long queueing delays, and poor scalability. This work introduces SwiftSNNI, a unified, resource-aware scheduling framework for SNNI. It implements a hybrid offline–online strategy that orchestrates offline preprocessing (Tpre,i) and online inference (Ton,i) jobs to maximize parallelism. By formulating SNNI scheduling as a constrained optimization problem, SwiftSNNI overlaps Tpre,i phase execution of future requests with active Ton,j, jobs. SwiftSNNI also incorporates optional advance notices to enable proactive Tpre,i, which further reduces average input delay (D). Evaluations using five benchmark neural networks (M1, M2, HiNet, AlexNet, VGG-16) under diverse workloads and stochastic arrival rates confirm substantial performance gains. Compared to a parallelized sequential baseline (MS-SHARK), SwiftSNNI achieves up to 97% lower average input delay (D), a 81% reduction in makespan (≈ 5.4 × speedup), and delivers 5.6 × increase in throughput. Furthermore, SwiftSNNI reduces average waiting time (W) by over 99%, demonstrating robust starvation prevention for high-concurrency workloads. SwiftSNNI supports concurrent execution, scales to larger neural networks, and provides an efficient runtime for SNNI deployments. The SwiftSNNI implementation is available online.
Kanwal Batool, Saleem Anwar, Francesco Regazzoni 0001, Andy D. Pimentel, Zoltán Ádám Mann
ICPE3
2025 Architectures for Sustainable Security in the Computing Continuum
abstract
Security is a fundamental extra-functional requirement that systems should provide. As such, it should be implemented in a sustainable way, namely achieving at least a very limited energy consumption, and being at least capable of supporting Crypto-Agility (so to allow updates of security primitives rather than replacement of whole system). These two properties are challenging to offer, since attacks and weaknesses are discovered everyday and simple updates could not be sufficient to defeat them. The situation is further complicated by the fact that, in this moment, families of cryptographic algorithm are being replaced by novel standards (such as the post quantum one). Security can even be of great help to support sustainability, for instance by allowing secure update of devices and enabling maintenance that would extend the devices live. Yet, support for these features should be studied in depth and fully understood to avoid the involuntary insertion of security weaknesses. With a focus on the computing continuum paradigm, in this paper we address one side of the relation between sustainability and security and we discuss what can be done to make security more sustainable.
Francesco Regazzoni 0001
ASAP1
2025 Tutorial: The Energy Cost of Privacy and Security
abstract
Security and privacy are key enablers (and often also a legal requirement) for a number of applications, including smart grid and smart cities, health care, data analytics, and personalized services. Because of this, research in the domain of security and privacy-preserving techniques is progressing at high pace. However, if on the one side the research community devoted large attention to the study of more efficient algorithms and the design of more efficient architectures implementing them, on the other, the energy cost and the energy implications of the use of these technologies have not yet been explored in the needed depth, with the majority of literature focusing on block ciphers. This tutorial exposes the community to the main current research results and best practices in this research area, and aims to foster the exchange of ideas between all the involved stakeholders. The tutorial presents the background and latest achievements in the field of energy assessment and reduction for security and privacy-preserving primitives. This tutorial covers the needed background on security algorithms, discusses their energy consumption, and presents, by means of relevant examples, how to design and implement security primitives that achieve a limited energy footprint. In particular, the focus is on two families of security primitives: block ciphers and privacy-preserving primitives. The tutorial introduces the basic concepts and the main algorithms belonging to these families, discusses recent advances in the domain, and presents in detail the energy consumption of these technologies and in their applications such as machine learning. Further, the tutorial will show optimizations that have been proposed to minimize the energy footprint of security primitives, with a particular focus on block ciphers, discussing also the design of lightweight and low-energy cryptographic algorithms. The tutorial concludes discussing open problems, limitations, and possible research directions. The tutorial is divided into three sections and will begin with a talk providing a detailed introduction of the needed concepts, to allow attendees not familiar with the topic to be able to successfully follow the whole tutorial. More in details, the sections are: • "Introduction to Security Primitives and Privacy Preserving Technologies". This talk will introduce the audience to the security primitives and the relevant privacy preserving technologies and protocols, [1] that will be analyzed in the rest of the tutorial. • "Energy Assessment of Security Primitives". This talk summarizes current research in energy assessment [2] of security primitives, reporting the method used to assess them and presenting literature result on the energy consumption of security primitives. The talk will conclude presenting open problems and future research directions. • "Energy Efficient Design and Implementation of Security Primitives". This talk reviews the strategies that have been applied to security primitives to reduce their energy consumption and presents the algorithms that have been designed, since the beginning, to achieve a limited energy footprint [3] , [4] . The talk will conclude presenting open problems and future research directions.
Ayse K. Coskun, Paolo Palmieri 0001, Francesco Regazzoni 0001
ISLPED3
2024 SECURED for Health: Scaling Up Privacy to Enable the Integration of the European Health Data Space
abstract
In this paper, we present the SECURED project11Funded in part by the European Union (EU), Grant Agreement no. 10109571. Views and opinions expressed are those of the authors and do not necessarily reflect those of the EU or the Health and Digital Executive Agency. Neither the EU nor the granting authority are responsible for them., aimed at improving privacy-preserving processing of data in the health domain. The technologies developed in the project will be demonstrated in four health-related use cases and with the involvement of SME's selected through an open funding call.
Francesco Regazzoni 0001, Gergely Ács, Albert Zoltan Aszalos, Christos Avgerinos, Nikolaos Bakalos, Josep Lluís Berral, Joppe W. Bos, Marco Brohet, Andrés G. Castillo, Gareth T. Davies, Stefanos Florescu, Pierre-Elisée Flory, Alberto Gutierrez-Torre, Evangelos Haleplidis, Alice Héliou, Sotiris Ioannidis, Alexander El-Kady, Katarzyna Kapusta, Konstantina Karagianni, Pieter Kruizinga, Kyrian Maat, Zoltán Ádám Mann, Kalliopi Mastoraki, SeoJeong Moon, Maja Nisevic, Balazs Pejo, Kostas Papagiannopoulos, Vassilis Paliouras, Paolo Palmieri 0001, Francesca Palumbo, Juan Carlos Pérez Baun, Péter Pollner, Eduard Porta-Pardo, Luca Pulina, Muhammad Ali Siddiqi, Daniela Spajic, Christos Strydis, George Tasopoulos, Vincent Thouvenot, Christos Tselios, Apostolos P. Fournaris
DATE1
2024 Demonstrating Post-Quantum Remote Attestation for RISC-V Devices
abstract
The rapid proliferation of Internet of Things (IoT) devices has revolutionized many aspects of modern computing. Experience has shown that these devices often have severe security problems and are common targets for malware. One approach to ensure that only trusted software is executed on these devices is Remote Attestation (RA), which allows a verifier to attest the integrity of software running on such a prover device. As malware is typically not trusted, an infected device will fail to generate a valid signature, which allows the verifier to detect the presence of malware on the prover. To achieve its security guarantees, RA requires a trust anchor, often found in the form of dedicated hardware on the prover. For IoT and embedded devices such hardware has only recently become largely deployed. Current RA protocols rely on classical asymmetric signatures that are vulnerable to quantum attacks, which are expected to become feasible in the near future. In this work we present SPRAV, a software-based RA system that leverages the Physical Memory Protection (PMP) primitive of RISC-V to achieve its security guarantees and employs quantum-safe cryptographic algorithms to ensure resistance against quantum attacks in the future. Our evaluation shows that it is feasible to deploy this solution on RISC-V devices without incurring a prohibitive overhead or the need for additional hardware, paving the way towards quantum-resistant functionalities also in IoT.
Maximilian Barger, Marco Brohet, Francesco Regazzoni 0001
DATE3
2024 A System Development Kit for Big Data Applications on FPGA-based Clusters: The EVEREST Approach
abstract
Modern big data workflows are characterized by computationally intensive kernels. The simulated results are often combined with knowledge extracted from AI models to ultimately support decision-making. These energy-hungry workflows are increasingly executed in data centers with energy-efficient hard-ware accelerators since FPG As are well-suited for this task due to their inherent parallelism. We present the H2020 project EVEREST, which has developed a system development kit (SDK) to simplify the creation of FPGA-accelerated kernels and manage the execution at runtime through a virtualization environment. This paper describes the main components of the EVEREST SDK and the benefits that can be achieved in our use cases.
Christian Pilato, Subhadeep Banik, Jakub Beránek, Fabien Brocheton, Jerónimo Castrillón, Riccardo Cevasco, Radim Cmar, Serena Curzel, Fabrizio Ferrandi, Karl F. A. Friebel, Antonella Galizia, Matteo Grasso, Paulo Silva 0002, Jan Martinovic, Gianluca Palermo, Michele Paolino, Andrea Parodi, Antonio Parodi, Fabio Pintus, Raphael Polig, David Poulet, Francesco Regazzoni 0001, Burkhard Ringlein, Roberto Rocco, Katerina Slaninová, Tom Slooff, Stephanie Soldavini, Felix Suchert, Mattia Tibaldi, Beat Weiss, Christoph Hagleitner
DATE22
2024 Special Issue on Post-Quantum Cryptography for Embedded Systems
abstract
In 2014, the National Institute of Standards and Technology (NIST) suggested that a quantum computer capable of breaking RSA could be built by 2030.The National Security Agency (NSA) warned in 2015 that progress in quantum computing had reached a point at which organizations should start deploying encryption algorithms designed to withstand attacks performed on quantum computers.Post-quantum cryptography refers to cryptographic algorithms that are resistant to attacks by quantum computers.To ensure a smooth transition from current cryptographic asymmetric algorithms to post-quantum algorithms, two key aspects shall be considered: implementation security and performance.This is particularly important for constrained devices, such as embedded and IoT devices, in various application domains, including industrial networks, critical infrastructures, banking, health, transportation, and many others.This motivates an urgent need for evaluating post-quantum cryptographic implementations on embedded systems for physical security and performance, including the integration of such implementations in current protocols and systems.This special issue brings together original manuscripts that explore the latest developments in implementing secure and efficient post-quantum cryptographic algorithms for embedded and IoT applications.After undergoing a comprehensive and rigorous review, nine papers have been selected to be featured in this special issue.The following is a brief summary of the papers included in this issue.The article titled "Side-Channel Analysis of Lattice-Based Post-Quantum Cryptography: Exploiting Polynomial Multiplication " [ 1 ] presents side-channel analysis methodologies targeting all polynomial multiplications of all lattice-based post-quantum key encapsulation mechanisms in the final round of the NIST post-quantum standardization procedure.The article presents practical experiments on real side-channel measurements demonstrating that the proposed methods allow one to extract the secret key from all lattice-based post-quantum key encapsulation mechanisms.Furthermore, the analysis shows that the used polynomial multiplication strategy can significantly impact the time complexity of the attack.The article titled "MemFHE: End-to-End Computing with Fully Homomorphic Encryption in Memory " [ 2 ] presents MemFHE, a first HW accelerator that supports both client and server functionalities for the latest homomorphic encryption schemes based on Ring-GSW.This accelerator utilizes Processing In Memory (PIM) technology.The authors thoroughly evaluate MemFHE across different security levels and compare its performance against state-of-the-art CPU implementations for Ring-GSW-based Fully Homomorphic Encryption (FHE) .MemFHE achieves
Shivam Bhasin, Fabrizio De Santis, Francesco Regazzoni 0001
ACM Trans. Embed. Comput. Syst.3
2023 Resource-Constrained Encryption: Extending Ibex with a QARMA Hardware Accelerator
abstract
The increasing prevalence of IoT devices calls for the need for strong, but efficient cryptography. In this paper we present two instruction set extensions for the lightweight encryption cipher QARMA-64 to the RISC-V instruction set, implemented for the Ibex core. The first extension performs the entire algorithm in hardware, divided over ten instructions. The second extension takes a more granular approach and instead implements the basic operations that the algorithm uses as custom instructions. The first extension achieves a speedup of ~600x over the software implementation and a binary size reduction of over 2x. It achieves these results at the cost of an added field-programmable gate array (FPGA) utilization over the base Ibex design of 43.9% and 18.7% for, respectively, the number of lookup tables (LUTs) and flip-flops (FFs). The application-specific integrated circuit (ASIC) area for synthesis is increased by 92.4% over the base design. The second extension achieves a speedup of ~19x over the software version while roughly maintaining the same binary size. This extension increases the number of utilized LUTs and FFs respectively by only 0.1% and 4.9%. The ASIC area for this design is increased by only 5.1%. The power consumption for the first extension is estimated at$543\mu \mathrm{W}$and for the second extension at$468\mu \mathrm{W}$.
Mathijs De Kremer, Marco Brohet, Subhadeep Banik, Roberto Maria Avanzi, Francesco Regazzoni 0001
ASAP5
2023 Data Sanitization on eMMCs
abstract
Data sanitization of modern digital devices is an important issue given that electronic wastes are being recycled and repurposed. The embedded Multi Media Card (eMMC), one of the NAND flash memory-based commodity devices, is one of the popularly recycled products in the current recycling ecosystem. We analyze a repurposed devices and evaluate its sanitization practice. Data from the formerly used device can still be recovered, which may lead to an unintentional leakage of sensitive data such as personally identifiable information (PII). Since the internal storage of an eMMC is the NAND flash memory, sanitization practice of the NAND flash memory-based systems should apply to the eMMC. However, proper sanitize operation is obviously not always performed in the current recycling ecosystem. We discuss how data stored in eMMC and other flash memory-based devices need to be deleted in order to avoid the potential data leakage. We also review the NAND flash memory data sanitization schemes and discuss how they should be applied in eMMCs.
Aya Fukami, Francesco Regazzoni 0001, Zeno J. M. H. Geradts
ASP-DAC2
2023 CCSW '23: Cloud Computing Security Workshop
abstract
Clouds and massive-scale computing infrastructures are starting to dominate computing and will likely continue to do so for the foreseeable future. Major cloud operators are now comprising millions of cores hosting substantial fractions of corporate and government IT infrastructure. CCSW is the world's premier forum bringing together researchers and practitioners in all security aspects of cloud-centric and outsourced computing, including:
Francesco Regazzoni 0001, Apostolos P. Fournaris
CCS1
2023 Secrets Leaking Through Quicksand: Covert Channels in Approximate Computing
abstract
Approximate computing (AxC) has emerged as an attractive architectural paradigm especially for artificial-intelligence applications, yet its security implications are being neglected. We demonstrate a novel covert channel where the malicious sender modulates transmission by switching between regular and AxC realizations of the same computational task. The malicious receiver identifies the transmitted information by either reading out the workload statistics or by creating controlled congestion. We demonstrate the channel on both an Android simulator and an actual smartphone and systematically study measures to increase its robustness. The achievable transmission rates are comparable with earlier covert channels based on power consumption, but the malicious behavior of our channel is more stealthy and less detectable.
Lorenzo Masciullo, Roberto Passerone, Francesco Regazzoni 0001, Ilia Polian
ETS3
2023 Invited Paper: Instruction Set Extensions for Post-Quantum Cryptography
abstract
Quantum computing is one of the latest break-throughs in the field of computer science, having the potential of breaking the underlying assumptions of public-key cryptography. With the National Institute of Standards and Technology (NIST) having announced that lattice-based KYBER as Key Encapsulation Mechanism (KEM) and DILITHIUMAND FALCON as digital signatures are going to be standardized as the first Post-Quantum Cryptography (PQC) schemes, the scientific community needs to investigate how to efficiently implement these new primitives to ensure a smooth transition. We review in this work the state-of-the-art in Instruction Set Extensions (ISEs) for the lattice-based PQC schemes to be standardized. We categorize them into three groups. Firstly, tightly-integrated implementations that aim to be small and only accelerate the core functions, secondly more generic and bigger ISEs that target more lattice operations, and thirdly a special class that focuses on vectorized processing. While we observe promising results in improving on runtime and energy consumption, the memory footprint is often overlooked in the evaluation, even though this is a serious issue in PQC where keys, ciphertexts and signatures tend to be larger. Additionally, we envision that more generic lattice-based ISEs will surface, and that side-channel and fault attacks will become more important.
Marco Brohet, Felipe Valencia, Francesco Regazzoni 0001
ICCAD3
2023 Data Under Siege: The Quest for the Optimal Convolutional Autoencoder in Side-Channel Attacks
abstract
Encryption is a method to keep our data safe from third parties. However, side-channel information may be leaked during encryption due to physical properties. This information can be used in side-channel attacks to recover critical values such as the secret encryption key. To this end, it is necessary to understand the robustness of implementations to assess the security of data handled by a device. Side-channel attacks are one such method which allow researchers to evaluate the robustness of implementations using appropriate metrics. In the security community, machine learning is playing a prominent role in the study of side-channel attacks. A notable example of this is the use of Convolutional Autoencoders (CAE) as a preprocessing step on the measurements. In this work we study in depth the problem of finding the most suitable architecture of such Convolutional Autoencoders. To this end, Optuna is used to explore the CAE hyperparameter space. This process allows us to identify hyperparameters that outperform state-of-the-art autoencoders, reducing the needed traces for a succesful attack by approximately 37 % in the presence of Gaussian noise and reducing the trainable parameters needed to attack desynchronization by a factor of 29. In addition to the promising results, experiments carried out in this paper allow a better understanding of the hyperparameter space in the field of side channel attacks, providing a solid base for future use of CAE in this specific domain.
Danny van den Berg, Tom Slooff, Marco Brohet, Kostas Papagiannopoulos, Francesco Regazzoni 0001
IJCNN5
2023 A Visionary Look at the Security of Reconfigurable Cloud Computing
abstract
Field-programmable gate arrays (FPGAs) have become critical components in many cloud computing platforms. These devices possess the fine-grained parallelism and specialization needed to accelerate applications ranging from machine learning to networking and signal processing, among many others. Unfortunately, fine-grained programmability also makes FPGAs a security risk. Here, we review the current scope of attacks on cloud FPGAs and their remediation. Many of the FPGA security limitations are enabled by the shared power distribution network in FPGA devices. The simultaneous sharing of FPGAs is a particular concern. Other attacks on the memory, host microprocessor, and input/output channels are also possible. After examining current attacks, we describe trends in cloud architecture and how they are likely to impact possible future attacks. FPGA integration into cloud hypervisors and system software will provide extensive computing opportunities but invite new avenues of attack. We identify a series of system, software, and FPGA architectural changes that will facilitate improved security for cloud FPGAs and the overall systems in which they are located.
Mirjana Stojilovic, Kasper Bonne Rasmussen, Francesco Regazzoni 0001, Mehdi Baradaran Tahoori, Russell Tessier
Proc. IEEE3
2022 CCSW '22: The 2022 Cloud Computing Security Workshop
abstract
Clouds and massive-scale computing infrastructures are starting to dominate computing and will likely continue to do so for the foreseeable future. Major cloud operators are now comprising millions of cores hosting substantial fractions of corporate and government IT infrastructure. CCSW is the world's premier forum bringing together researchers and practitioners in all security aspects of cloud-centric and outsourced computing, including: ·Side channel attacks ·Cryptographic protocols for cloud security ·Secure cloud resource virtualization mechanisms ·Secure data management outsourcing (e.g., database as a service) ·Privacy and integrity mechanisms for outsourcing ·Foundations of cloud-centric threat models ·Secure computation outsourcing ·Remote attestation mechanisms in clouds ·Sandboxing and VM-based enforcements ·Trust and policy management in clouds ·Secure identity management mechanisms ·Cloud-aware web service security paradigms and mechanisms ·Cloud-centric regulatory compliance issues and mechanisms ·Business and security risk models and clouds ·Cost and usability models and their interaction with security in clouds ·Scalability of security in global-size clouds ·Binary analysis of software for remote attestation and cloud protection ·Network security (DOS, IDS etc.) mechanisms for cloud contexts ·Security for emerging cloud programming models ·Energy/cost/efficiency of security in clouds ·mOpen hardware for cloud ·Machine learning for cloud protection CCSW especially encourages novel paradigms and controversial ideas that are not on the above list. The workshop has historically acted as a fertile ground for creative debate and interaction in security-sensitive areas of computing impacted by clouds. This year marked the 13th anniversary of CCSW. In the past decade, CCSW has had a significant impact in our research community.
Marten van Dijk, Francesco Regazzoni 0001
CCS2
2022 Anomaly detection to improve security of big data analytics
abstract
Big data analytics largely rely on data. Because of their central role, it is fundamental to ensure the security and correctness of data used in these applications. Anomaly detection could help to increase the security of big data analytics applications. However, these applications are very diverse both for the properties of the data analyzed and for the computations to be carried out on them. As a result, the selection of the most appropriate anomaly detection method is a challenging and time consuming task for designers. Hierarchical Temporal Memory (HTM) is as an anomaly detection technique sufficiently generic to achieve satisfactory performance on a wide range of applications, thus suitable to ease the burden of selecting the anomaly detection method. To confirm this, in this paper we explore the performance of HTM on a dataset used for air quality prediction. Our preliminary results show that HTM achieves excellent performance when compared to other popular anomaly detection methods.
Tom Slooff, Francesco Regazzoni 0001, Fabien Brocheton, Antonio Parodi, Radim Cmar
CF2
2022 Optimizing Lattice-based Post-Quantum Cryptography Codes for High-Level Synthesis
abstract
High-level synthesis is a mature Electronics Design Automation (EDA) technology for building hardware design in a short time. It produces automatically HDL code for FPGAs out of C/C++, bridging the gap from algorithm to hardware. Nevertheless, sometimes the QoR (Quality of Results) can be sub-optimal due to the difficulties of HLS in handling general-purpose software code. In this paper, we explore the current difficulties of HLS while synthesizing Lattice-based Post-Quantum Cryptog-raphy (PQC) algorithms. We propose code-level optimizations to overcome the limitations of high-level synthesis increasing the QoR of generated hardware. We analyzed and improved the results for the algorithms competing in the 3rd round of the NIST standardization process. We show how, starting from the original reference code submitted for the competition, original performance and resource utilization can be improved, in some cases with a speedup factor up to$200\times$or an area reduction of 80%.
Andrea Guerrieri, Gabriel Da Silva Marques, Francesco Regazzoni 0001, Andres Upegui
DSD3
2022 Experimental Evaluation of e.MMC Data Recovery
abstract
In this paper, we explore the data recovery procedures from e∙MMCs. The e∙MMC is one of the “managed” flash memory devices that are popularly used in modern digital devices as their storage media. The e∙MMC, which consists of flash memory and the flash memory controller, optimizes the data input/output between the host device and the non-volatile memory through its standardized protocol. Its standardized structure and protocol makes forensic physical data acquisition simpler than handling the raw flash memory. However, its secure data purging features, such as Secure Erase and Sanitize, make data recovery from e∙MMC a challenging task. In this research, we investigate inside the e∙MMCs, and evaluate advanced data recovery procedures. By reverse engineering the structures of e∙MMCs and accessing the internal flash memory, we discover that securely erased data is still recoverable from the internal flash memory. In some models, more than 99% of the securely erased data can still be recoverable by accessing the flash memory inside the e∙MMCs. The data extraction method, along with experimental data recovery evaluation, will be explored in this paper.
Aya Fukami, Sasha Sheremetov, Francesco Regazzoni 0001, Zeno J. M. H. Geradts, Cees T. A. M. de Laat
IEEE Trans. Inf. Forensics Secur.3
2021 A Deeper Look at the Energy Consumption of Lightweight Block Ciphers
abstract
In the last few years, the field of lightweight cryptography has seen an influx in the number of block ciphers and hash functions being proposed. In the past there have been numerous papers that have looked at circuit level implementation of block ciphers with respect to lightweight metrics like area power and energy. In the paper by Banik et al. (SAC‘15), for example, by studying the energy consumption model of a CMOS gate, it was shown that the energy consumed per cycle during the encryption operation of an r-round unrolled architecture of any block cipher is a quadratic function in r. However, most of these explorative works were at a gate level, in which a circuit synthesizer would construct a circuit using gates from a standard cell library, and the area power and energy would be estimated by estimating the switching statistics of the nodes in the circuit. Since only a part of the EDA design flow was done, it did not account for issues that might arise when the circuit is finally mapped into silicon post route. Metrics like area, power and energy would need to be re-estimated due to the effect of the parasitics introduced in the circuit by the connecting wires, nodes and interconnects. In this paper, we look to plug this very gap in literature by re-examining the designs of lightweight block ciphers with respect to their performances after completing the placement and routing process. This is a timely exercise to do since three of the block ciphers we analyze in the paper are used in around 13 of the 32 candidates in the second round of the NIST lightweight competition being conducted currently.
Andrea Caforio, Fatih Balli, Subhadeep Banik, Francesco Regazzoni 0001
DATE4
2021 Shared FPGAs and the Holy Grail: Protections against Side-Channel and Fault Attacks
abstract
In this paper, we survey recently proposed methods for protecting against side-channel and fault attacks in shared FPGAs. These methods are quite versatile, targeting FPGA compilation flow, real-time timing-fault detection, on-chip active fences, automated bitstream verification, etc. Despite their versatility, they are mostly designed to counteract a specific class of attacks. To understand how to address the problem of security in shared FPGAs in a comprehensive way, we discuss their individual strengths and weaknesses, in an attempt to identify research directions necessitating further investigation.
Ognjen Glamocanin, Dina Mahmoud, Francesco Regazzoni 0001, Mirjana Stojilovic
DATE3
2021 EVEREST: A design environment for extreme-scale big data analytics on heterogeneous platforms
abstract
High-Performance Big Data Analytics (HPDA) applications are characterized by huge volumes of distributed and heterogeneous data that require efficient computation for knowledge extraction and decision making. Designers are moving towards a tight integration of computing systems combining HPC, Cloud, and IoT solutions with artificial intelligence (AI). Matching the application and data requirements with the characteristics of the underlying hardware is a key element to improve the predictions thanks to high performance and better use of resources. We present EVEREST, a novel H2020 project started on October 1, 2020, that aims at developing a holistic environment for the co-design of HPDA applications on heterogeneous, distributed, and secure platforms. EVEREST focuses on programmability issues through a data-driven design approach, the use of hardware-accelerated AI, and an efficient runtime monitoring with virtualization support. In the different stages, EVEREST combines state-of-the-art programming models, emerging communication standards, and novel domain-specific extensions. We describe the EVEREST approach and the use cases that drive our research.
Christian Pilato, Stanislav Böhm, Fabien Brocheton, Jerónimo Castrillón, Riccardo Cevasco, Vojtech Cima, Radim Cmar, Dionysios Diamantopoulos, Fabrizio Ferrandi, Jan Martinovic, Gianluca Palermo, Michele Paolino, Antonio Parodi, Lorenzo Pittaluga, Daniel Raho, Francesco Regazzoni 0001, Katerina Slaninová, Christoph Hagleitner
DATE16
2021 Extending Circuit Design Flow for Early Assessment of Fault Attack Vulnerabilities
abstract
Modern application-specific integrated circuits (ASICs) are increasingly employed in domains where they must fulfill security requirements. Traditional ASIC design flows include numerous steps to ensure the correctness of a circuit and its freedom from manufacturing defects, but they do not cover security vulnerabilities. In this paper, we show how to leverage state-of-the-art electronic design automation (EDA) tools to validate the resistance of a circuit against fault injection attacks in early design steps (before fabrication). While the approach is generic, we demonstrate it on a specific physical attack vector: Fault Sensitivity Analysis (FSA). We show how existing tools (especially for logic and timing simulation) can be extended by custom scripts to assess the vulnerability of an implementation to such attacks.
Felipe Valencia, Ilia Polian, Francesco Regazzoni 0001
DSD3
2021 Security, Reliability and Test Aspects of the RISC-V Ecosystem
abstract
RISC-V has emerged as a viable solution on academia and industry. However, to use open source hardware for safety-critical applications, we need a deep understanding of the way in which well established mechanisms for testing and reliability could be integrated and deployed on the RISC-V ecosystem, and we need a clear knowledge on how such an ecosystem can be leveraged to improve security. This paper includes four contributions presenting the potential of RISC-V in security research, the way in which RISC-V can be hardened against power analysis attacks, how to implement, using RISC-V, software and hardware/software solutions for dual core lock step, and how to perform system-level testing in the RISC-V ecosystem.
Jaume Abella 0001, Sergi Alcaide, Jens Anders, Francisco Bas, Steffen Becker 0001, Elke De Mulder, Nourhan Elhamawy, Frank K. Gürkaynak, Helena Handschuh, Carles Hernández 0001, Michael Hutter, Leonidas Kosmidis, Ilia Polian, Matthias Sauer 0002, Stefan Wagner 0001, Francesco Regazzoni 0001
ETS16
2021 Rosita: Towards Automatic Elimination of Power-Analysis Leakage in Ciphers
Madura A. Shelton, Niels Samwel, Lejla Batina, Francesco Regazzoni 0001, Markus Wagner 0007, Yuval Yarom
NDSS4
2021 Tool of Spies: Leaking your IP by Altering the 3D Printer Compiler
abstract
In cyber-physical additive manufacturing systems, side-channel attacks have been used to reconstruct the G/M-code (which are instructions given to a manufacturing system) of 3D objects being produced. This method is effective for stealing intellectual property from an organization, through least expected means, during prototyping stage before the product goes through a large-scale fabrication and comes out in the market. However, an attacker can be far from being able to completely reconstruct the G/M-code due to lack of enough information leakage through the side-channels. In this paper, we propose a novel way to amplify the information leakage and thus boost the chances of recovery of G/M-code by surreptitiously altering the compiler. By using this compiler, an adversary may easily control various parameters to magnify the leakage of information from a 3D printer while still producing the desired object, thus remaining hidden from the authentic users. This type of attack may be implemented by strong attackers having access to the tool chain and seeking high level of stealth. We have implemented such a compiler and have demonstrated that it increases the success rate of recovering G/M-codes from the four side-channels (acoustic, power, vibration, and electromagnetic) by up to 39 percent compared to previously proposed attacks.
Sujit Rokka Chhetri, Anomadarshi Barua, Sina Faezi, Francesco Regazzoni 0001, Arquimedes Canedo, Mohammad Abdullah Al Faruque
IEEE Trans. Dependable Secur. Comput.4
2020 AHEC: End-to-end Compiler Framework for Privacy-preserving Machine Learning Acceleration
abstract
Privacy-preserving machine learning (PPML) is driven by the emerging adoption of Machine Learning as a Service (MLaaS). In a typical MLaaS system, the end-user sends his personal data to the service provider and receives the corresponding prediction output. However, such interaction raises severe privacy concerns about both the user's proprietary data and the server's ML model. PPML integrates cryptographic primitives such as Multi-Party Computation (MPC) and/or Homomorphic Encryption (HE) into ML services to resolve the privacy issue. However, existing PPML solutions have not been widely deployed in practice since: (i) Privacy protection comes at the cost of additional computation and/or communication overhead; (ii) Adapting PPML to different front-end frameworks and back-end hardware incurs prohibitive engineering cost.We propose AHEC, the first automated, end-to-end HE compiler for efficient PPML inference. Leveraging the capability of Domain Specific Languages (DSLs), AHEC enables automated generation and optimization of HE kernels across diverse types of hardware platforms and ML frameworks. We perform extensive experiments to investigate the performance of AHEC from different abstraction levels: HE operations, HE-based ML kernels, and neural network layers. Empirical results corroborate that AHEC achieves superior runtime reduction compared to the state-of-the-art solutions built from static HE libraries.
Huili Chen, Rosario Cammarota, Felipe Valencia, Francesco Regazzoni 0001, Farinaz Koushanfar
DAC4
2020 Are Cloud FPGAs Really Vulnerable to Power Analysis Attacks?
abstract
Recent works have demonstrated the possibility of extracting secrets from a cryptographic core running on an FPGA by means of remote power analysis attacks. To mount these attacks, an adversary implements a voltage fluctuation sensor in the FPGA logic, records the power consumption of the target cryptographic core, and recovers the secret key by running a power analysis attack on the recorded traces. Despite showing that the power analysis could also be performed without physical access to the cryptographic core, these works were mostly carried out on dedicated FPGA boards in a controlled environment, leaving open the question about the possibility to successfully mount these attacks on a real system deployed in the cloud. In this paper, we demonstrate, for the first time, a successful key recovery attack on an AES cryptographic accelerator running on an Amazon EC2 F1 instance. We collect the power traces using a delay-line based voltage drop sensor, adapted to the Xilinx Virtex Ultrascale+ architecture used on Amazon EC2 F1, where CARRY8 blocks do not have a monotonic delay increase at their outputs. Our results demonstrate that security concerns raised by multitenant FPGAs are indeed valid and that countermeasures should be put in place to mitigate them.
Ognjen Glamocanin, Louis Coulon, Francesco Regazzoni 0001, Mirjana Stojilovic
DATE3
2020 Towards Secure Composition of Integrated Circuits and Electronic Systems: On the Role of EDA
abstract
Modern electronic systems become evermore complex, yet remain modular, with integrated circuits (ICs) acting as versatile hardware components at their heart. Electronic design automation (EDA) for ICs has focused traditionally on power, performance, and area. However, given the rise of hardware-centric security threats, we believe that EDA must also adopt related notions like secure by design and secure composition of hardware. Despite various promising studies, we argue that some aspects still require more efforts, for example: effective means for compilation of assumptions and constraints for security schemes, all the way from the system level down to the "bare metal"; modeling, evaluation, and consideration of security-relevant metrics; or automated and holistic synthesis of various countermeasures, without inducing negative cross-effects.In this paper, we first introduce hardware security for the EDA community. Next we review prior (academic) art for EDA-driven security evaluation and implementation of countermeasures. We then discuss strategies and challenges for advancing research and development toward secure composition of circuits and systems.
Johann Knechtel, Elif Bilge Kavun, Francesco Regazzoni 0001, Annelie Heuser, Anupam Chattopadhyay, Debdeep Mukhopadhyay, Soumyajit Dey, Yunsi Fei, Yaacov Belenky, Itamar Levi, Tim Güneysu, Patrick Schaumont, Ilia Polian
DATE3
2020 Friet: An Authenticated Encryption Scheme with Built-in Fault Detection
Thierry Simon, Lejla Batina, Joan Daemen, Vincent Grosso, Pedro Maat Costa Massolino, Kostas Papagiannopoulos, Francesco Regazzoni 0001, Niels Samwel
EUROCRYPT (1)7
2020 Built-in Self-Evaluation of First-Order Power Side-Channel Leakage for FPGAs
abstract
Embedded and cyber-physical systems are pervading all aspects of our lives, including sensitive and critical ones. As a result, they are an alluring target for cyber attacks. These systems, whose implementation is often based on reconfigurable hardware, are typically deployed in places accessible to attackers. Therefore, they require protection against tampering and side-channel attacks. However, a side-channel resistant implementation of a security primitive is not sufficient, as it can be weakened by an adversary, aging, or environmental factors. To detect this, legitimate users should be able to evaluate the side-channel resistance of their systems not only when deploying them for the first time, but also during their entire service life. The most widespread and de facto standard methodology for measuring power side-channel leakage uses Welch's t-test. In practice, collecting the data for the t-test requires physical access to the device, a device-specific test setup, and the equipment for measuring the power consumption during device operation. Consequently, only a small number of cyber-physical systems deployed in the field can be tested this way and the tests to reevaluate the device resistance to side-channel attacks cannot be easily repeated. To address these issues, we present a design and an FPGA implementation of a built-in test for self-evaluation of the resistance to first-order power side-channel attacks. Once our test is triggered, the FPGA measures its own internal power-supply voltage and computes the t-test statistic in real time. Experimental results on two different implementations of the AES-128 algorithm demonstrate that the self-evaluation test is very reliable. We believe that this work is an important step towards the development of security sensors for the next generation of safe and robust cyber-physical systems.
Ognjen Glamocanin, Louis Coulon, Francesco Regazzoni 0001, Mirjana Stojilovic
FPGA3
2020 Side Channel Attacks vs Approximate Computing
abstract
Approximate computing is an architectural paradigm where limited and controlled errors during computation are tolerated. Thanks to approximation, circuits can be faster, more compact, and consume less power. Security aspects of these circuits are however largely unexplored. In this paper we focus on the problem of side channel attacks, and we discuss how they can be different when carried out in approximated circuits. We conclude our work highlighting challenges and possible research directions in this area.
Francesco Regazzoni 0001, Ilia Polian
ACM Great Lakes Symposium on VLSI1
2020 Machine Learning and Hardware security: Challenges and Opportunities -Invited Talk-
abstract
Machine learning techniques have significantly changed our lives. They helped improving our everyday routines, but they also demonstrated to be an extremely helpful tool for more advanced and complex applications. However, the implications of hardware security problems under a massive diffusion of machine learning techniques are still to be completely understood. This paper first highlights novel applications of machine learning for hardware security, such as evaluation of post quantum cryptography hardware and extraction of physically unclonable functions from neural networks. Later, practical model extraction attack based on electromagnetic side-channel measurements are demonstrated followed by a discussion of strategies to protect proprietary models by watermarking them.
Francesco Regazzoni 0001, Shivam Bhasin, Amir Ali Pour, Ihab Alshaer, Furkan Aydin, Aydin Aysu, Vincent Beroulle, Giorgio Di Natale, Paul D. Franzon, David Hély, Naofumi Homma, Akira Ito 0002, Dirmanto Jap, Priyank Kashyap, Ilia Polian, Seetal Potluri, Rei Ueno, Elena I. Vatajelu, Ville Yli-Mäyry
ICCAD1
2020 Synthesis of Flexible Accelerators for Early Adoption of Ring-LWE Post-quantum Cryptography
abstract
The advent of the quantum computer makes current public-key infrastructure insecure. Cryptography community is addressing this problem by designing, efficiently implementing, and evaluating novel public-key algorithms capable of withstanding quantum computational power. Governmental agencies, such as NIST, are promoting standardization of quantum-resistant algorithms that is expected to run for 7 years. Several modern applications must maintain permanent data secrecy; therefore, they ultimately require the use of quantum-resistant algorithms. Because algorithms are still under scrutiny for eventual standardization, the deployment of the hardware implementation of quantum-resistant algorithms is still in early stages. In this article, we propose a methodology to design programmable hardware accelerators for lattice-based algorithms, and we use the proposed methodology to implement flexible and energy efficient post-quantum cache-based accelerators for NewHope , Kyber , Dilithium , Key Consensus from Lattice ( KCL ), and R.EMBLEM submissions to the NIST standardization contest. To the best of our knowledge, we propose the first efficient domain-specific, programmable cache-based accelerators for lattice-based algorithms. We design a single accelerator for a common kernel among various schemes with different kernel sizes, i.e., loop count, and data types. This is in contrast to the traditional approach of designing one special purpose accelerators for each scheme. We validate our methodology by integrating our accelerators into an HLS-based SoC infrastructure based on the X86 processor and evaluate overall performance. Our experiments demonstrate the suitability of the approach and allow us to collect insightful information about the performance bottlenecks and the energy efficiency of the explored algorithms. Our results provide guidelines for hardware designers, highlighting the optimization points to address for achieving the highest energy minimization and performance increase. At the same time, our proposed design allows us to specify and execute new variants of lattice-based schemes with superior energy efficiency compared to the main application processor without changing the hardware acceleration platform. For example, we manage to reduce the energy consumption up to 2.1× and energy-delay product (EDP) up to 5.2× and improve the speedup up to 2.5×.
Hamid Nejatollahi, Felipe Valencia, Subhadeep Banik, Francesco Regazzoni 0001, Rosario Cammarota, Nikil Dutt
ACM Trans. Embed. Comput. Syst.4
2019 ASHES 2019: 3rd Workshop on Attacks and Solutions in Hardware Security
Chip-Hong Chang, Daniel E. Holcomb, Francesco Regazzoni 0001, Ulrich Rührmair, Patrick Schaumont
CCS3
2019 CERBERO: Cross-layer modEl-based fRamework for multi-oBjective dEsign of reconfigurable systems in unceRtain hybRid envirOnments: Invited paper: CERBERO teams from UniSS, UniCA, IBM Research, TASE, INSA-Rennes, UPM, USI, Abinsula, AmbieSense, TNO, S&T, CRF
abstract
Cyber-Physical Systems (CPS) are embedded computational collaborating devices, capable of sensing and controlling physical elements and, often, responding to humans. Designing and managing systems able to respond to different, concurrent requirements during operation is not straightforward, and introduce the need of proper support at design-time and run-time. The Cross-layer modEl-based fRamework for multi-oBjective dEsign of Reconfigurable systems in unceRtain hybRid envirOnments (CERBERO) EU project has developed a design environment for adaptive CPS. CERBERO approach leverages on model-based methodologies including different technologies and tools developed to cover design and operation from user interactions down to low level computing layer implementation.
Francesca Palumbo, Tiziana Fanni, Carlo Sau, Luca Pulina, Luigi Raffo, Michael Masin, Evgeny Shindin, Pablo Sanchez de Rojas, Karol Desnos, Maxime Pelcat, Alfonso Rodríguez 0002, Eduardo Juárez Martínez, Francesco Regazzoni 0001, Giuseppe Meloni, Maria Katiuscia Zedda, Hans I. Myrhaug, Leszek Kaliciak, Joost Adriaanse, Julio de Oliveira Filho, Antonella Toffetti
CF13
2019 High-Level Synthesis of Benevolent Trojans
abstract
High-Level Synthesis (HLS) allows designers to create a register transfer level (RTL) description of a digital circuit starting from its high-level specification (e.g., C/C++/SystemC). HLS reduces engineering effort and design-time errors, allowing the integration of additional features. This study introduces an approach to generate benevolent Hardware Trojans (HT) using HLS. Benevolent HTs are Intellectual Property (IP) watermarks that borrow concepts from well-known malicious HTs to ward off piracy and counterfeiting either during the design flow or in fielded integrated circuits. Benevolent HTs are difficult to detect and remove because they are intertwined with the functional units used to implement the IP. Experimental results testify to the suitability of the approach and the limited overhead.
Christian Pilato, Kanad Basu, Mohammed Shayan, Francesco Regazzoni 0001, Ramesh Karri
DATE4
2019 Security in Autonomous Systems
abstract
Autonomous systems promise solutions to a wide range of technical and societal problems, and their use appears especially attractive in safety-critical domains, like transportation or factory automation. This paper focuses on an underestimated aspect of autonomous systems: their security implications. Many approaches to design traditional secure systems do not readily transfer to autonomous systems, due to their high complexity and exposure to a broad spectrum of threats. Moreover, autonomous systems are often designed to be extremely long-living, and any security solutions should anticipate future threats to some extent. This paper starts with an overview of security threats applicable to autonomous systems and today's countermeasures to address these threats. Then, two representative techniques are elucidated in more detail: the use of post-quantum cryptography to achieve secure communication, and remote attestation as one essential building block for platform security.
Stefan Katzenbeisser 0001, Ilia Polian, Francesco Regazzoni 0001, Marc Stöttinger
ETS3
2019 PlaidML-HE: Acceleration of Deep Learning Kernels to Compute on Encrypted Data
abstract
Machine Learning as a Service (MLaaS) is becoming a popular practice where Service Consumers, e.g., end-users, send their data to a ML Service and receive the prediction outputs. However, the emerging usage of MLaaS has raised severe privacy concerns about users' proprietary data. PrivacyPreserving Machine Learning (PPML) techniques aim to incorporate cryptographic primitives such as Homomorphic Encryption (HE) and Multi-Party Computation (MPC) into ML services to address privacy concerns from a technology standpoint. Existing PPML solutions have not been widely adopted in practice due to their assumed high overhead and integration difficulty within various ML front-end frameworks as well as hardware backends. In this work, we propose PlaidML-HE, the first end-toend HE compiler for PPML inference. Leveraging the capability of Domain-Specific Languages, PlaidML-HE enables automated generation of HE kernels across diverse types of devices. We evaluate the performance of PlaidML-HE on different ML kernels and demonstrate that PlaidML-HE greatly reduces the overhead of the HE primitive compared to the existing implementations.
Huili Chen, Rosario Cammarota, Felipe Valencia, Francesco Regazzoni 0001
ICCD4
2019 Fault Attack Countermeasures for Error Samplers in Lattice-Based Cryptography
abstract
Lattice-based cryptography is one of the leading candidates for NIST's post-quantum standardisation effort, providing efficient key encapsulation and signature schemes. Most of these schemes base their hardness on variants of LWE, and thus rely heavily on error samplers to provide necessary uncertainty by obfuscating computations on secret information. Because of this it is a clear and obvious target for side-channel analysis, with numerous types of attacks targeting this component to gain secret-key information. In order to bring potential lattice-based cryptographic standards to practical realisation, it is important to protect these modules from past and future fault and side-channel attacks. This paper proposes countermeasures that exploit the distributions expected from these error samples, that is either Gaussian or binomial, by using statistical tests to verify the samplers are operating properly. The novel countermeasures are designed to protect against all previous fault attacks on error samplers. We optimize hardware implementation of the proposed tests to avoid division and square root calculations, however, the countermeasure we propose is sufficiently generic to be suitable also for software. We measure the impact of these countermeasures on performance and area consumption on a Xilinx Artix-7 FPGA. Our countermeasure achieve promising performance while resulting in a minimal overhead.
James Howe, Ayesha Khalid, Marco Martinoli, Francesco Regazzoni 0001, Elisabeth Oswald
ISCAS4
2019 TaintHLS: High-Level Synthesis for Dynamic Information Flow Tracking
abstract
Dynamic information flow tracking (DIFT) is a technique to track potential security vulnerabilities in software and hardware systems at run time. Untrusted data are marked with tags (tainted), which are propagated through the system and their potential for unsafe use is analyzed to prevent them. DIFT is not supported in heterogeneous systems especially hardware accelerators. Currently, DIFT is manually generated and integrated into the accelerators. This process is error-prone, potentially hurting the process of identifying security violations in heterogeneous systems. We present TaintHLS, to automatically generate a micro-architecture to support baseline operations and a shadow microarchitecture for intrinsic DIFT support in hardware accelerators while providing variable granularity of taint tags. TaintHLS offers a companion high-level synthesis (HLS) methodology to automatically generate such DIFT-enabled accelerators from a high-level specification. We extended a state-of-the-art HLS tool to generate DIFT-enhanced accelerators and demonstrated the approach on numerous benchmarks. The DIFT-enabled accelerators have negligible performance and no more than 30% hardware overhead.
Christian Pilato, Kaijie Wu 0001, Siddharth Garg, Ramesh Karri, Francesco Regazzoni 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2019 Black-Hat High-Level Synthesis: Myth or Reality?
abstract
Hardware Trojans are a major concern for integrated circuits. All parts of the electronics supply chain are vulnerable to this threat. Trojans can be inserted directly by a rogue employee or through a compromised computer-aided design tool at each step of the design cycle, including an alteration of the design files in the early stages and the fabrication process in a third-party malicious foundry. While Trojan insertion during the latter stages has been largely investigated, we focus on high-level synthesis (HLS) tools as a likely attack vector. HLS tools are used to generate intellectual property blocks from high-level specifications. To demonstrate the threat, we compromised an open-source HLS tool to inject three examples of HLS-aided hardware Trojans with functional and nonfunctional effects. Our results show that a black-hat HLS tool can be successfully used to maliciously alter electronic circuits to add latency, drain energy, or undermine the security of cryptographic hardware cores. This threat is an important security concern to address.
Christian Pilato, Kanad Basu, Francesco Regazzoni 0001, Ramesh Karri
IEEE Trans. Very Large Scale Integr. Syst.3
2018 ASHES 2018- Workshop on Attacks and Solutions in Hardware Security
abstract
As in the successful first edition, the second Workshop on Attacks and Solutions in Hardware Security (ASHES) 2018 deals with all aspects of hardware security. Among others, this year, the workshop particularly highlights emerging techniques and methods as well as recent application areas within the field. These include new attack vectors, attack countermeasures, and novel designs and implementations on the methodological side, as well as the Internet of Things, automotive security, smart homes, pervasive and wearable computing on the applications side. In order to meet the requirements of these rapidly developing subareas, ASHES calls for paper submissions in four categories: 1) classical full papers; 2) classical short papers; 3) systematization of knowledge papers which overview, structure, and categorize a subarea; and 4) wild and crazy papers whose purpose is rapid dissemination of promising, potentially game-changing ideas.
Chip-Hong Chang, Jorge Guajardo, Daniel E. Holcomb, Francesco Regazzoni 0001, Ulrich Rührmair
CCS4
2018 TAO: techniques for algorithm-level obfuscation during high-level synthesis
abstract
Intellectual Property (IP) theft costs semiconductor design companies billions of dollars every year. Unauthorized IP copies start from reverse engineering the given chip. Existing techniques to protect against IP theft aim to hide the IC's functionality, but focus on manipulating the HDL descriptions. We propose TAO as a comprehensive solution based on high-level synthesis to raise the abstraction level and apply algorithmic obfuscation automatically. TAO includes several transformations that make the component hard to reverse engineer during chip fabrication, while a key is later inserted to unlock the functionality. Finally, this is a promising approach to obfuscate large-scale designs despite the hardware overhead needed to implement the obfuscation.
Christian Pilato, Francesco Regazzoni 0001, Ramesh Karri, Siddharth Garg
DAC2
2018 Rethinking Secure FPGAs: Towards a Cryptography-Friendly Configurable Cell Architecture and Its Automated Design Flow
abstract
This work proposes the first fine-grained configurable cell array specifically tailored for the implementation of cryptographic algorithms that can be configured using widely adopted hardware description languages. Our solution can be added as a small, crypto-friendly reconfigurable hardware block to be included as an application-specific configurable building block in the next generation of FPGAs, exactly like DSP slices and embedded memory blocks were added in the past. Another application scenario uses our configurable cell array as a small embedded FPGA (eFPGA) which we envision to be added to an ASIC design or a microprocessor. This will solve the need for so-called cryptographic agility, allowing cryptographic algorithms to be upgraded or updated depending on newly detected vulnerabilities or changing standards. We focus on block ciphers and we derive the most suitable cell structure for mapping state-of-the-art algorithms. We develop the related automated design flow, exploiting the synthesis capabilities of Synopsys Design Compiler. We evaluate the performance of our solution by mapping a number of well-known ciphers onto our new cells. The obtained results show that the proposed architecture drastically outperforms commercial FPGAs in terms of silicon area and configuration memory resources, while obtaining a similar throughput.
Nele Mentens, Edoardo Charbon, Francesco Regazzoni 0001
FCCM3
2018 Physical Protection of Lattice-Based Cryptography: Challenges and Solutions
abstract
The impending realization of scalable quantum computers will have a significant impact on today's security infrastructure. With the advent of powerful quantum computers public key cryptographic schemes will become vulnerable to Shor's quantum algorithm, undermining the security current communications systems. Post-quantum (or quantum-resistant) cryptography is an active research area, endeavoring to develop novel and quantum resistant public key cryptography. Amongst the various classes of quantum-resistant cryptography schemes, lattice-based cryptography is emerging as one of the most viable options. Its efficient implementation on software and on commodity hardware has already been shown to compete and even excel the performance of current classical security public-key schemes. This work discusses the next step in terms of their practical deployment, i.e., addressing the physical security of lattice-based cryptographic implementations. We survey the state-of-the-art in terms of side channel attacks (SCA), both invasive and passive attacks, and proposed countermeasures. Although the weaknesses exposed have led to countermeasures for these schemes, the cost, practicality and effectiveness of these on multiple implementation platforms, however, remains under-studied.
Ayesha Khalid, Tobias Oder, Felipe Valencia, Máire O'Neill, Tim Güneysu, Francesco Regazzoni 0001
ACM Great Lakes Symposium on VLSI6
2018 Security: the dark side of approximate computing?
abstract
Approximate computing promises significant advantages over more traditional computing architectures with respect to circuit area, performance, power efficiency, flexibility, and cost. Its use is suitable in applications where limited and controlled inaccuracies are tolerable or uncertainty is intrinsic in input or their data processing, e.g., as it happens in (deep-) machine learning, image and signal processing. This paper discusses a dimension of approximate computing that has been neglected so far, despite it represents nowadays a major asset, that of security. A number of hardware-related security threats are considered, and the implications of approximate circuits or systems designed to address these threats are discussed.
Francesco Regazzoni 0001, Cesare Alippi, Ilia Polian
ICCAD1
2018 Compact, Scalable, and Efficient Discrete Gaussian Samplers for Lattice-Based Cryptography
abstract
Lattice-based cryptography, one of the leading candidates for post-quantum security, relies heavily on discrete Gaussian samplers to provide necessary uncertainty, obfuscating computations on secret information. For reconfigurable hardware, the cumulative distribution table (CDT) scheme has previously been shown to achieve the highest throughput and the smallest resource utilisation, easily outperforming other existing samplers. However, the CDT sampler does not scale well. In fact, for large parameters, the lookup tables required are far too large to be practically implemented. This research proposes a hierarchy of multiple smaller samplers, extending the Gaussian convolution lemma to compute optimal parameters, where the individual samplers require much smaller lookup tables. A large range of parameter sets, covering encryption, signatures, and key exchange are evaluated. Hardware-optimised parameters are formulated and a practical implementation on Xilinx Artix-7 FPGA device is realised. The proposed sampling designs demonstrate promising performance on reconfigurable hardware, even for large parameters, that were otherwise thought infeasible.
Ayesha Khalid, James Howe, Ciara Rafferty, Francesco Regazzoni 0001, Máire O'Neill
ISCAS4
2018 On Practical Discrete Gaussian Samplers for Lattice-Based Cryptography
abstract
Lattice-based cryptography is one of the most promising branches of quantum resilient cryptography, offering versatility and efficiency. Discrete Gaussian samplers are a core building block in most, if not all, lattice-based cryptosystems, and optimised samplers are desirable both for high-speed and low-area applications. Due to the inherent structure of existing discrete Gaussian sampling methods, lattice-based cryptosystems are vulnerable to side-channel attacks, such as timing analysis. In this paper, the first comprehensive evaluation of discrete Gaussian samplers in hardware is presented, targeting FPGA devices. Novel optimised discrete Gaussian sampler hardware architectures are proposed for the main sampling techniques. An independent-time design of each of the samplers is presented, offering security against side-channel timing attacks, including the first proposed constant-time Bernoulli, Knuth-Yao, and discrete Ziggurat sampler hardware designs. For a balanced performance, the Cumulative Distribution Table (CDT) sampler is recommended, with the proposed hardware CDT design achieving a throughput of 59.4 million samples per second for encryption, utilising just 43 slices on a Virtex 6 FPGA and 16.3 million samples per second for signatures with 179 slices on a Spartan 6 device.
James Howe, Ayesha Khalid, Ciara Rafferty, Francesco Regazzoni 0001, Máire O'Neill
IEEE Trans. Computers4
2017 Securing the hardware of cyber-physical systems
abstract
The cyber-physical system (CPS) paradigm offers tremendous advantages in many application scenarios and promises a solution to a large number of pressing individual and societal needs. However, their properties such as heterogeneity, lack of perimeter protection, longevity, pervasive diffusion and strictly constrained resources also give rise to new security vulnerabilities. In this paper, we discuss security threats related to the hardware blocks of a CPS. We first review attack scenarios affecting security attributes confidentiality, integrity and authenticity, and then outline novel attack vectors that target the cyber and the physical aspects of a CPS simultaneously.
Francesco Regazzoni 0001, Ilia Polian
ASP-DAC1
2017 Cross-layer design of reconfigurable cyber-physical systems
abstract
In the last few years, besides the concepts of embedded and interconnected systems, also the notion of Cyber-Physical Systems (CPS) has emerged: embedded computational collaborating devices, capable of sensing and controlling physical elements and, often, responding to humans. The continuous interaction between physical and computing layers makes their design and maintenance extremely complex. Uncertainty management and runtime reconfigurability, to mention the most relevant ones, are rarely tackled by available toolchains. In this context, the Cross-layer modEl-based fRamework for multi-oBjective dEsign of Reconfigurable systems in unceRtain hybRid envirOnments (CERBERO) EU project aims at developing a design environment for CPS based of two pillars: 1) a cross-layer model-based approach to describe, optimize, and analyze the system and all its different views concurrently and 2) an advanced adaptivity support based on a multi-layer autonomous engine. In this work, we describe the components and the required developments for seamless design of reusable and reconfigurable CPS and System of Systems in uncertain hybrid environments.
Michael Masin, Francesca Palumbo, Hans I. Myrhaug, J. A. de Oliveira Filho, M. Pastena, Maxime Pelcat, Luigi Raffo, Francesco Regazzoni 0001, A. A. Sanchez, Antonella Toffetti, Eduardo de la Torre, Maria Katiuscia Zedda
DATE8
2017 Counteracting malicious faults in cryptographic circuits
abstract
In the area of testing, faults represent defects that occur during circuit manufacturing, or transient disturbances due to radiation or noise. This paper provides an introduction into the area of fault-injection attacks, that is, faults that an attacker deliberately injects into a security-critical circuit. We will explain the threats posed by fault-injection attacks, pointing out similarities and differences between “natural” and malicious faults, and detection methods and countermeasures applicable in both cases. We will describe various methods of malicious fault injection with high and low precision and discuss the necessary equipment (including commercially available solutions), as well as potential impact of such faults to system security. In particular, we will discuss the relationship of fault-injection attacks with other attack vectors and with test and measurement techniques.
Ilia Polian, Francesco Regazzoni 0001
ETS2
2016 Standard lattices in hardware
abstract
Lattice-based cryptography has gained credence recently as a replacement for current public-key cryptosystems, due to its quantum-resilience, versatility, and relatively low key sizes. To date, encryption based on the learning with errors (LWE) problem has only been investigated from an ideal lattice standpoint, due to its computation and size efficiencies. However, a thorough investigation of standard lattices in practice has yet to be considered. Standard lattices may be preferred to ideal lattices due to their stronger security assumptions and less restrictive parameter selection process.
James Howe, Ciara Rafferty, Máire O'Neill, Francesco Regazzoni 0001, Tim Güneysu, K. Beeden
DAC4
2016 Instruction Set Extensions for secure applications
Francesco Regazzoni 0001, Paolo Ienne
DATE1
2016 Evaluating the Impact of Environmental Factors on Physically Unclonable Functions (Abstract Only)
abstract
Fabrication process introduces some inherent variability to the attributes of transistors (in particular length, widths, oxide thickness). As a result, every chip is physically unique. Physical uniqueness of microelectronics components can be used for multiple security applications. Physically Unclonable Functions (PUFs) are built to extract the physical uniqueness of microelectronics components and make it usable for secure applications.
Sebastien Bellon, Claudio Favi, Miroslaw Malek, Marco Macchetti, Francesco Regazzoni 0001
FPGA5
2016 Physical Attacks and Beyond
Francesco Regazzoni 0001
SAC1
2015 Midori: A Block Cipher for Low Energy
Subhadeep Banik, Andrey Bogdanov, Takanori Isobe 0001, Kyoji Shibutani, Harunaga Hiwatari, Toru Akishita, Francesco Regazzoni 0001
ASIACRYPT (2)7
2015 200 MS/s ADC implemented in a FPGA employing TDCs
abstract
Analog signals are used in many applications and systems, such as cyber physical systems, sensor networks and automotive applications. These are also applications where the use of FPGAs is continuously growing. To date, however there is no direct integration between FPGAs, which are digital, and the analog world (except for the newest generation of FPGAs). Currently, an external analog-to-digital converter (ADC) has to be added to the system, thus limiting its overall compactness and flexibility.
Harald Homulle, Francesco Regazzoni 0001, Edoardo Charbon
FPGA2
2015 A survey on hardware trojan detection techniques
abstract
Hardware Trojans recently emerged as a serious issue for computer systems, especially for those used in critical applications such as medical or military. Trojan proposed so far can affect the reliability of a device in various ways. Proposed effects range from the leakage of secret information to the complete malfunctioning of the device. A crucial point for securing the overall operation of a device is to guarantee the absence of hardware Trojans. In this paper, we survey several techniques for detecting malicious modification of circuit introduced at different phases of the design flow. We also highlight their capabilities limitations in thwarting hardware Trojans.
Shivam Bhasin, Francesco Regazzoni 0001
ISCAS2
2015 Challenges in designing trustworthy cryptographic co-processors
abstract
Security is becoming ubiquitous in our society. However, the vulnerability of electronic devices that implement the needed cryptographic primitives has become a major issue. This paper starts by presenting a comprehensive overview of the existing attacks to cryptography implementations. Thereafter, the state-of-the-art on some of the most critical aspects of designing cryptographic co-processors are presented. This analysis starts by considering the design of asymmetrical and symmetrical cryptographic primitives, followed by the discussion on the design and online testing of True Random Number Generation. To conclude, techniques for the detection of Hardware Trojans are also discussed.
Ricardo Chaves, Giorgio Di Natale, Lejla Batina, Shivam Bhasin, Baris Ege, Apostolos P. Fournaris, Nele Mentens, Stjepan Picek, Francesco Regazzoni 0001, Vladimir Rozic, Nicolas Sklavos 0001, Bohan Yang 0001
ISCAS9
2015 Exploring Energy Efficiency of Lightweight Block Ciphers
Subhadeep Banik, Andrey Bogdanov, Francesco Regazzoni 0001
SAC3
2015 Automatic Application of Power Analysis Countermeasures
abstract
We introduce a compiler that automatically inserts software countermeasures to protect cryptographic algorithms against power-based side-channel attacks. The compiler first estimates which instruction instances leak the most information through side-channels. This information is obtained either by dynamic analysis, evaluating an information theoretic metric over the power traces acquired during the execution of the input program, or by static analysis. As information leakage implies a loss of security, the compiler then identifies (groups of) instruction instances to protect with a software countermeasure such as random precharging or Boolean masking. As software protection incurs significant overhead in terms of cryptosystem runtime and memory usage, the compiler protects the minimum number of instruction instances to achieve a desired level of security. The compiler is evaluated on two block ciphers, AES and Clefia; our experiments demonstrate that the compiler can automatically identify and protect the most important instruction instances. To date, these software countermeasures have been inserted manually by security experts, who are not necessarily the main cryptosystem developers. Our compiler offers significant productivity gains for cryptosystem developers who wish to protect their implementations from side-channel attacks.
Ali Galip Bayrak, Francesco Regazzoni 0001, David Novo, Philip Brisk, François-Xavier Standaert, Paolo Ienne
IEEE Trans. Computers2
2014 SPADs for quantum random number generators and beyond
abstract
Single-Photon Avalanche Diodes (SPADs) are solid-state photo-detectors capable of detecting single photons by exploiting the avalanche effect that occurs in the breakdown of a p-n junction biased above breakdown voltage. By this effect, a SPAD translates an incoming photon to a macroscopic current pulse. These devices are currently used for building medical devices characterized by a very high time resolution. An appealing application of SPAD is to use them as a basic block for building the entropy source of true random number generators. In this paper we focus on such application, and we explore the design challenges behind the realization of a quantum random number generator based on a massively parallel array of SPADs. The matrix under investigation comprises 512×128 independent cells that convert photons onto a raw bit-stream, which, as ensured by the properties of quantum physics, is characterized by a very high level of randomness. The sequences are read out in a 128-bit parallel bus, concatenated, and pipelined onto a de-biasing filter. Subsequently, we fabricated the proposed chip using a standard CMOS process. Our results, achieved on the manufactured device and coupling two matrices, show that our architecture can reach up to 5 Gbit/s while consuming 25pJ/bit, thus demonstrating scalability and performance for any random number generators based on SPADs.
Samuel Burri, Damien Stucki, Yuki Maruyama, Claudio Bruschini, Edoardo Charbon, Francesco Regazzoni 0001
ASP-DAC6
2014 THOR - The hardware onion router
abstract
Security and privacy of data traversing internet have always been a major concern for all users. In this context, The Onion Routing (Tor) is the most successful protocol to anonymize global Internet traffic and is widely deployed as software on many personal computers or servers. In this paper, we explore the potential of modern reconfigurable devices to efficiently realize the Tor protocol on embedded devices. In particular, this targets the acceleration of the complex cryptographic operations involved in the handshake of routing nodes and the data stream encryption. Our hardware-based implementation on the Xilinx Zynq platform outperforms previous embedded solutions by more than a factor of 9 with respect to the cryptographic handshake - ultimately enabling quite inexpensive but highly efficient routers. Hence, we consider our work as a further milestone towards the development and the dissemination of low-cost and high performance onion relays that hopefully ultimately leads again to a more private Internet.
Tim Güneysu, Francesco Regazzoni 0001, Pascal Sasdrich, Marcin Wójcik
FPL2
2013 Sleuth: Automated Verification of Software Power Analysis Countermeasures
Ali Galip Bayrak, Francesco Regazzoni 0001, David Novo, Paolo Ienne
CHES2
2013 Stealthy Dopant-Level Hardware Trojans
Georg T. Becker, Francesco Regazzoni 0001, Christof Paar, Wayne P. Burleson
CHES2
2013 Single-photon image sensors
abstract
The main goal of this paper is to expose the EDA community to the emerging class of circuits operating with single quanta of energy (e.g. photons or electrical carriers). We describe recent developments in the field of single-photon detection and single-photon imaging based on the avalanche effect. Single-photon detection is useful in a number of applications, from time-of-flight based 3D vision systems to fluorescence lifetime imaging microscopy, from low-light cameras to quantum random number generators, from positron emission tomography to time-resolved Raman spectroscopy. These applications have speed and accuracy requirements that conventional systems cannot provide if not at a very high cost. EDA has not yet adapted to the revolution introduced by avalanching devices and, though tools capable of simulating these devices exist, there is little or no capability to do so in a coherent flow, let alone at system level. We challenge CAD designers to fill this gap and prepare them to the circuits of the future, quantum in nature but built in standard CMOS technology.
Edoardo Charbon, Francesco Regazzoni 0001
DAC2
2013 An EDA-friendly protection scheme against side-channel attacks
abstract
This paper introduces a generic and automated methodology to protect hardware designs from side-channel attacks in a manner that is fully compatible with commercial standard cell design flows. The paper describes a tool that artificially adds jitter to the clocks of the sequential elements of a cryptographic unit, which increases the non-determinism of signal timing, thereby making the physical device more difficult to attack. Timing constraints are then specified to commercial EDA tools, which restore the circuit functionality and efficiency while preserving the introduced randomness. The protection scheme is applied to an AES-128 hardware implementation that is synthesized using both ASIC and FPGA design flows.
Ali Galip Bayrak, Nikola Velickovic, Francesco Regazzoni 0001, David Novo, Philip Brisk, Paolo Ienne
DATE3
2013 ALE: AES-Based Lightweight Authenticated Encryption
Andrey Bogdanov, Florian Mendel, Francesco Regazzoni 0001, Vincent Rijmen, Elmar Tischhauser
FSE3
2012 Security Enhanced Linux on embedded systems: A hardware-accelerated implementation
abstract
Security Enhanced Linux implements fine-grained mandatory access control. Despite its usefulness, the overhead of implementing it on embedded devices is prohibitive. Therefore, in the past it has been proposed to accelerate SELinux by means of dedicated hardware; in this work we demonstrate the feasibility of such an approach by implementing a hardware accelerator for SELinux on a FPGA-based platform. Our implementation obtains a huge reduction in the performance overhead and energy consumption of SELinux, yet employing a limited chip area.
Leandro Fiorin, Alberto Ferrante, Konstantinos Padarnitsas, Francesco Regazzoni 0001
ASP-DAC4
2012 Compact Implementation and Performance Evaluation of Hash Functions in ATtiny Devices
Josep Balasch, Baris Ege, Thomas Eisenbarth 0001, Benoît Gérard, Tim Güneysu, Stefan Heyse, Stéphanie Kerckhof, François Koeune, Thomas Plos, Thomas Pöppelmann, Francesco Regazzoni 0001, François-Xavier Standaert, Gilles Van Assche, Ronny Van Keer, Loïc van Oldeneel tot Oldenzeel, Ingo von Maurich
CARDIS12
2011 Compact FPGA Implementations of the Five SHA-3 Finalists
Stéphanie Kerckhof, François Durvaux, Nicolas Veyrat-Charvillon, Francesco Regazzoni 0001, Guerric Meurice de Dormale, François-Xavier Standaert
CARDIS4
2011 Fresh Re-keying II: Securing Multiple Parties against Side-Channel and Fault Attacks
Marcel Medwed, Christophe Petit 0001, Francesco Regazzoni 0001, Mathieu Renauld, François-Xavier Standaert
CARDIS3
2011 A first step towards automatic application of power analysis countermeasures
abstract
In cryptography, side channel attacks, such as power analysis, attempt to uncover secret information from the physical implementation of cryptosystems rather than exploiting weaknesses in the cryptographic algorithms themselves. The design and implementation of physically secure cryptosystems is a challenge for both hardware and software designers. Measuring and evaluating the security of a system is manual and empirical, which is costly and time consuming; this work demonstrates that it is possible to automate these processes. We introduce a systematic methodology for automatic application of software countermeasures and demonstrate its effectiveness on an AES software implementation running on an 8-bit AVR microcontroller. The framework identifies the most vulnerable instructions of the implementation to power analysis attacks, and then transforms the software using a chosen countermeasure to protect the vulnerable instructions. Lastly, it evaluates the security of the system using an information-theoretic metric and a direct attack.
Ali Galip Bayrak, Francesco Regazzoni 0001, Philip Brisk, François-Xavier Standaert, Paolo Ienne
DAC2
2011 Power-gated MOS current mode logic (PG-MCML): a power aware DPA-resistant standard cell library
abstract
MOS Current Mode Logic (MCML) is one of the most promising logic style to counteract power analysis attacks. Unfortunately, the static power consumption of MCML standard cells is significantly higher compared to equivalent functions implemented using static CMOS logic. As a result, the use of such a logic style is very limited in portable devices. Paradoxically, these devices are the most sensitive to physical attacks, thus the ones which would benefit more from the adoption of MCML.
Alessandro Cevrero, Francesco Regazzoni 0001, Micheal Schwander, Stéphane Badel, Paolo Ienne, Yusuf Leblebici
DAC2
2010 A reconfigurable multiprocessor architecture for a reliable face recognition implementation
abstract
Face Recognition techniques are solutions used to quickly screen a huge number of persons without being intrusive in open environments or to substitute id cards in companies or research institutes. There are several reasons that require to systems implementing these techniques to be reliable. This paper presents the design of a reliable face recognition system implemented on Field Programmable Gate Array (FPGA). The proposed implementation uses the concepts of multiprocessor architecture, parallel software and dynamic reconfiguration to satisfy the requirement of a reliable system. The target multiprocessor architecture is extended to support the dynamic reconfiguration of the processing unit to provide reliability to processors fault. The experimental results show that, due to the multiprocessor architecture, the parallel face recognition algorithm can achieve a speed up of 63% with respect to the sequential version. Results regarding the overhead in maintaining a reliable architecture are also shown.
Antonino Tumeo, Francesco Regazzoni 0001, Gianluca Palermo, Fabrizio Ferrandi, Donatella Sciuto
DATE2
2009 A Design Flow and Evaluation Framework for DPA-Resistant Instruction Set Extensions
Francesco Regazzoni 0001, Alessandro Cevrero, François-Xavier Standaert, Stéphane Badel, Theo Kluter, Philip Brisk, Yusuf Leblebici, Paolo Ienne
CHES1
2008 A 640 Mbit/S 32-Bit Pipelined Implementation of the AES Algorithm
Guido Bertoni, Luca Breveglieri, Roberto Farina, Francesco Regazzoni 0001
SECRYPT4
2007 Hardware scheduling support in SMP architectures
abstract
In this paper the authors propose a hardware real time operating system (HW-RTOS) that implements the OS layer in a dual-processor SMP architecture. Intertask communication is specified by means of dedicated APIs and the HW-RTOS takes care of the communication requirements of the application and also implements the task scheduling algorithm. The HW-RTOS allows to have smaller footprints, since it avoids the need to link to the final executables traditional software RTOS libraries. Moreover, the HW-RTOS is able to exploit the easy task migration feature provided by an SMP architecture much more efficiently than a traditional software RTOS, due to its faster execution and the authors show how this significantly overcomes the performance achievable with optimal static task partitioning among two processors. Preliminary results show that the hardware overhead in a dual processor architecture is less than 20K gates
André C. Nácul, Francesco Regazzoni 0001, Marcello Lajolo
DATE2
2006 Speeding Up AES By Extending a 32 bit Processor Instruction Set
abstract
Nowadays the need of speed in cipher and decipher operations is more important than in the past. This is due to the diffusion of real time applications, which fact involves the use of cryptography. Many co-processors for cryptography were studied and presented in the past, but only few works were addressed to the enhancement of the instruction set architecture (ISA) of the embedded processor. This paper presents an extension of the ISA of a 32 bit processor, that aims at speeding up the software implementations of the AES algorithm. After the identification of the most frequently executed and the most time consuming sections of the algorithm, a set of dedicated instructions is designed in order to improve the performances of the cipher operations. We validate our instruction set extension by measuring the speed up for different optimized implementations of AES using an ARM processor simulator, but the enhancements we propose are general enough to be applied to almost all 32 bit processors.
Guido Bertoni, Luca Breveglieri, Roberto Farina, Francesco Regazzoni 0001
ASAP4
2006 Hardware/software partitioning of operating systems: a behavioral synthesis approach
abstract
In this paper we propose a hardware real time operating system(HW-RTOS) solution that makes use of a dedicated hardware in order to replace the standard support provided by the POSIX layer of a general purpose RTOS for implementing task synchronization and scheduling. By redefining only the I/O APIs of the tasks, the HW-RTOS then takes care of the communication requirements of the original application and also implements the task scheduling algorithm. The new software application can then be compiled without any need for POSIX support. The main advantages are smaller and faster executables. We present results that show how a small hardware area, less than 10K gates, can result in a 15X performance improvement when the original software scheduler is replaced by a dedicated HW-RTOS.
Sathish Chandra, Francesco Regazzoni 0001, Marcello Lajolo
ACM Great Lakes Symposium on VLSI2
2005 Automatic synthesis of the Hardware/Software Interface
Francesco Regazzoni 0001, André C. Nácul, Marcello Lajolo
FDL1