EDBT 2026 Demo / reviewers in the wild / expert
Chester Rebeiro
dblp:37/4129
· DBLP profile ↗
44ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0001-8063-0026ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 26 · 2 first-author · 12 since 2021Security and privacy · 17 · 6 first-author · 9 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FIDES: End-to-end Compartments for Mixed-language SystemsabstractMemory-unsafe code and monolithic designs remain major sources of vulnerabilities in embedded systems. Although developers are increasingly adopting memory-safe languages such as Rust and OCaml, mixed-language applications still rely on C libraries, which weakens security boundaries. Existing compartment schemes are built for C and cannot accommodate essential high-level language features such as higher-order functions, closures, exceptions and tail-call optimisation. This makes them unsuitable for modern safe-language ecosystems. Sai Venkata Krishnan Rajeswari Sridevi, Arjun Menon, Chester Rebeiro, KC Sivaramakrishnan |
AsiaCCS | 3 |
| 2025 | GLiTCH: GLiTCH induced Transitions for Secure Crypto-HardwareabstractConventionally, glitch reduction is well-studied in digital design to improve power, efficiency, and security. In contrast, this paper combines the addition and removal of glitches to minimize the power side-channel leakage. Glitch Manipulation is achieved through gate sizing-based arrival time control, which is cast as a Geometric Programming formulation. We develop a framework, GLiTCH, for glitch manipulation that is guided by functional and timing simulations. The framework is evaluated on popular cipher designs like AES, CLEFIA, and SM4. Our findings illustrate up to 52.82% improvement in the Guessing Entropy for a 38.74% area overhead on average across the evaluated ciphers. C. Rohin Menon, Jayanth Balasubramanian, E. Akshay Kumar, Annapurna Valiveti, Chester Rebeiro, Janakiraman Viraraghavan |
DAC | 5 |
| 2025 | Valkyrie: A Response Framework to Augment Runtime Detection of Time-Progressive AttacksabstractA popular approach to detect cyberattacks is to monitor systems in real-time to identify malicious activities as they occur. While these solutions aim to detect threats early, minimizing damage, they suffer from a significant challenge due to the presence of false positives. False positives have a detrimental impact on computer systems, which can lead to interruptions of legitimate operations and reduced productivity. Most contemporary works tend to use advanced Machine Learning and AI solutions to address this challenge. Unfortunately, false positives can, at best, be reduced but not eliminated.In this paper, we propose an alternate approach that focuses on reducing the impact of false positives rather than eliminating them. We introduce Valkyrie, a framework that can enhance any existing runtime detector with a post-detection response. Valkyrie is designed for time-progressive attacks, such as micro-architectural attacks, rowhammer, ransomware, and cryptominers, that achieve their objectives incrementally using system resources. As soon as an attack is detected, Valkyrie limits the allocated computing resources, throttling the attack, until the detector’s confidence is sufficiently high to warrant a more decisive action. For a false positive, limiting the system resources only results in a small increase in execution time. On average, the slowdown incurred due to false positives is less than 1% for single-threaded programs and 6.7% for multi-threaded programs. On the other hand, attacks like rowhammer are prevented, while the potency of micro-architectural attacks, ransomware, and cryptominers is greatly reduced. Nikhilesh Singh, Chester Rebeiro |
DSN | 2 |
| 2025 | Improved Side Channel Attacks on TRIVIUM, GRAIN-128-AEAD, ACORN-128 v3 and ASCON-128a
Soumya Sahoo 0001, Raghavendra Patil, Sandip Kumar Mondal, Santanu Sarkar 0001, Chester Rebeiro |
Des. Codes Cryptogr. | 5 |
| 2025 | SUNDEW: A Case-Sensitive Detection Engine to Counter Malware DiversityabstractMalware programs are diverse, with varying objectives, functionalities, and threat levels ranging from mere pop-ups to significant financial losses. Consequently, their run-time footprints across the system differ, impacting the optimal data source (Network, Operating system (OS), Hardware) and features that are instrumental to malware detection. Further, the variations in threat levels of malware classes affect the user policies for detection. Thus, the optimal tuple of$\langle \tt data$-$\tt source$,$\tt features$,$\tt user$-$\tt policies \rangle$, determined experimentally, is different for each malware class, impacting the state-of-the-art detection solutions that are agnostic to these subtle differences. This paper presents${\sf SUNDEW}$, a framework to detect malware classes using the corresponding optimal tuple of$\langle \tt data$-$\tt source$,$\tt features$,$\tt user$-$\tt policies \rangle$.${\sf SUNDEW}$uses an ensemble of specialized predictors, each trained with a particular data source (network, OS, and hardware) and tuned for features and policies of a specific class. While the specialized ensemble with a holistic view across the system improves detection, aggregating the independent conflicting inferences from the different predictors is challenging.${\sf SUNDEW}$resolves such conflicts with a hierarchical aggregation considering the threat-level, noise in the data sources, and prior domain knowledge. We evaluate${\sf SUNDEW}$on a real-world dataset of over 10,000 malware samples from 8 classes. It achieves an F1-Score of one for most classes, with an average of 0.93, and has a limited performance overhead of 1.5%. Our experiments on a common multi-featured dataset show that${\sf SUNDEW}$is 10% more accurate, with 89% lower false positives, than prior state-of-the-art predictors. Sareena Karapoola, Nikhilesh Singh, Chester Rebeiro, V. Kamakoti 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Systematic Analysis of Moving Target Defenses for Branch Prediction AttacksabstractWhile branch predictors play a crucial role in high-performance processors, they are easy targets for micro-architectural attacks. A promising direction to counter these attacks is to randomize the branch predictor's state periodically to create moving targets for the attacker. While such approaches have been successfully applied to mitigate similar attacks in cache memories, applying them in branch predictors offers a unique set of challenges. Unlike cache memories, branch predictors differ widely in architecture. Their proximity to the processor's pipeline requires the countermeasures to be highly efficient to minimize overheads. In this paper, we present a systematic analysis of the moving target countermeasure on branch predictors. To capture different branch predictor architectures, we propose a generic branch predictor model. We use the model to formally define various attack strategies on branch predictors and then use the attack complexities to systematically derive randomization intervals for various mitigation techniques. We then identify the appropriate mitigation to be applied for a branch predictor based on the performance overheads incurred. For evaluation, we instantiate five different branch predictors from the generic predictor model and adapt the attack models and randomization techniques for each predictor. We compute the randomization interval for mitigation strategies and show that the interval intricately depends on the branch predictor architecture and the mitigation technique. We study the performance and area overheads by extending the branch predictor in an OpenRISC processor, enhanced with the randomization countermeasure. Gnanambikai Krishnakumar, Chester Rebeiro |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in Processors
Pallavi Borkar, Chen Chen 0125, Mohamadreza Rostami, Nikhilesh Singh, Rahul Kande, Ahmad-Reza Sadeghi, Chester Rebeiro, Jeyavijayan Rajendran |
USENIX Security Symposium | 7 |
| 2024 | FortiFix : A Fault Attack Aware Compiler Framework for Crypto ImplementationsabstractFault attacks are one of the most powerful forms of cryptanalytic attack on embedded systems, which can corrupt a cipher’s operations leading to a breach of confidentiality and integrity. A single precisely injected fault during the execution of a cipher can be exploited to retrieve the secret key in a few milliseconds. Naive countermeasures introduced into implementation can lead to huge overheads, making them unusable in resource-constraint environments. However, optimized countermeasures require significant knowledge, not only about the attack but also on the the cryptographic properties of the cipher, the program structure, and the underlying hardware architecture. This makes the protection against fault attacks tedious and error prone. In this article, we introduce FortiFix , the first automated compiler framework that can detect and patch fault exploitable regions in a block cipher implementation. The framework has two phases. The pre-compilation phase identifies regions in the source code of a block cipher that are vulnerable to fault attacks. The second phase is incorporated as transformation passes in the LLVM compiler to find exploitable instructions, quantify the impact of a fault on these instructions, and finally insert appropriate countermeasures based on user-defined security requirements. As a proof of concept, we have evaluated two block cipher implementations, AES-128 and CLEFIA-128, on three different hardware platforms: MSP430 (16-bit), ARM (32-bit), and RISCV (32-bit). Keerthi K. 0002, Chester Rebeiro |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2023 | YODA: Covert Communication Channel over Public DNS ResolversabstractEnterprises are increasingly migrating to public domain name system (DNS) resolvers for reliability, cost optimizations, and, most importantly, improved security and user privacy. The integrated threat intelligence feeds at these resolvers enable easy identification and blocking of malicious exploits that use DNS queries. However, we observe that the shared local caches at these public DNS resolvers enable covert communication channels from otherwise secure enterprises accessible to any remote adversary, thus cautioning the migration to public DNS resolvers. We present YODA, a covert communication channel via public DNS resolvers that can exfiltrate sensitive information from a victim enterprise to a remote adversary. Unlike prior works, YODA overloads DNS queries for popular domains to transfer the data without revealing any identity of the adversary. Consequently, YODA cannot be blocked by domain name filtering. We demonstrate our attack on public DNS resolvers such as Google, Cloudflare, Quad9, OpenDNS, and LibreDNS. Our evaluations show that the adversary can achieve a bandwidth of 480bps with desktop devices. Sandip Saha, Sareena Karapoola, Chester Rebeiro, V. Kamakoti 0001 |
DSN | 3 |
| 2023 | SIGNED: A Challenge-Response Scheme for Electronic Hardware WatermarkingabstractThe emergence of distributed manufacturing ecosystems for electronic hardware involving untrusted parties has led to diverse trust issues. In particular, Intellectual Property (IP) piracy, reverse engineering, and overproduction pose significant threats to integrated circuits (IC) manufacturers. Watermarking has been one of the solutions employed by the semiconductor industry to overcome many of the trust issues. However, existing watermarking techniques often suffer from one or more of the following deficiencies: (1) low structural coverage, (2) applicability to specific design abstraction level (e.g., gate or layout), (3) high design overhead, and (4) vulnerabilities to removal or tampering attacks. We address these deficiencies by introducing a new watermarking scheme, calledSIGNED:SignatureInsertion through challenGe respoNse inElectronicDesign.SIGNEDrelies on a challenge-response protocol-based interrogation scheme for generating the watermark. It identifies strategic locations of an input design and samples them in response to select input patterns to form a set of compact signatures representing the functional and structural characteristics of a design. We show that this signature set can be used as high-quality watermark of an IP to verify its provenance. We evaluateSIGNEDon the ISCAS85, ITC, and MIT CEP benchmark circuits with respect to all major quality parameters of hardware watermark. We show thatSIGNEDachieves excellent structural coverage and robustness against identification and removal attacks, while introducing modest design overheads. Patanjali SLPSK, Abhishek Anil Nair, Chester Rebeiro, Swarup Bhunia |
IEEE Trans. Computers | 3 |
| 2023 | Kryptonite: Worst-Case Program Interference Estimation on Multi-Core Embedded SystemsabstractDue to the low costs and energy needed, cyber-physical systems are adopting multi-core processors for their embedded computing requirements. In order to guarantee safety when the application has real-time constraints, a critical requirement is to estimate the worst-case interference from other executing programs. However, the complexity of multi-core hardware inhibits precisely determining the Worst-Case Program Interference. Existing solutions are either prone to overestimate the interference or are not scalable to different hardware sizes and designs. In this paper we present Kryptonite , an automated framework to synthesize Worst-Case Program Interference (WCPI) environments for multi-core systems. Fundamental to Kryptonite is a set of tiny hardware-specific code gadgets that are crafted to maximize interference locally. The gadgets are arranged using a greedy approach and then molded using a Reinforcement Learning algorithm to create the WCPI environment. We demonstrate Kryptonite on the automotive grade Infineon AURIX TC399 processor with a wide range of programs that includes a commercial real-time automotive application. We show that, while being easily scalable and tunable, Kryptonite creates WCPI environments increasing the runtime by up to 58% for benchmark applications and 26% for the automotive application. Nikhilesh Singh, Karthikeyan Renganathan, Chester Rebeiro, Ralph Mader |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2022 | FORTIFY: Analytical Pre-Silicon Side-Channel Characterization of Digital DesignsabstractPower side-channel attacks are potent security threats that exploit the power consumption patterns of an electronic device to glean sensitive information ranging from secret keys and passwords to web-browsing activity. While pre-Silicon tools promise early detection of side-channel leakage at the design stage, they require several hours of simulation time. In this paper, we present an analytical framework called FORTIFY that estimates the power side-channel vulnerability of digital circuit designs at signal-level granularity, given the RTL or gate-level netlist of the design, at least 100 times faster than contemporary works. We demonstrate the correctness of FORTIFY by comparing it with a recent simulation-based side-channel leakage analysis framework. We also test its scalability by evaluating FORTIFY on an open-source System-on-Chip. A. V. Lakshmy, Chester Rebeiro, Swarup Bhunia |
ASP-DAC | 2 |
| 2022 | Avatar: Reinforcing Fault Attack Countermeasures in EDA with Fault TransformationsabstractCryptography hardware are highly vulnerable to a class of side-channel attacks known as Differential Fault Analysis (DFA). These attacks exploit fault induced errors to compromise secret keys from ciphers within a few seconds. A bias in the error probabilities strengthens the attack considerably. It abets in bypassing countermeasures and is also the basis of powerful attack variants like the Differential Fault Intensity Analysis (DFIA) and Statistical Ineffective Fault Analysis (SIFA). In this paper, we make two significant contributions. First, we identify the correlation between fault induced errors and gatelevel parameters like the threshold voltage, gate size, and${V_{\text{DD}}}$. We show how these parameters can influence the bias in the error probabilities. Then, we propose an algorithm, called Avatar, that carefully tunes gate-level parameters to strengthen the redundancy countermeasures against DFA, DFIA, and SIFA attacks with no additional logic needed. The central idea of Avatar is to reconfigure gates in the redundant circuits so that each circuit has a unique behavior to faults, making fault detection much more efficient. In AES for instance, fault attack resistance improves by 40% for DFA and DFIA, and 99% in the case of SIFA. Avatar incurs negligible area overheads and can be quickly adopted in any cipher design. It can be incorporated in commercial EDA flows and provides users with tunable knobs to trade-off performance and power consumption, for fault attack security. Prithwish Basu Roy, Patanjali SLPSK, Chester Rebeiro |
ASP-DAC | 3 |
| 2022 | RaDaR: A Real-Word Dataset for AI powered Run-time Detection of Cyber-AttacksabstractArtificial Intelligence techniques on malware run-time behavior have emerged as a promising tool in the arms race against sophisticated and stealthy cyber-attacks. While data of malware run-time features are critical for research and benchmark comparisons, unfortunately, there is a dearth of real-world datasets due to multiple challenges to their collection. The evasive nature of malware, its dependence on connected real-world conditions to execute, and its potential repercussions pose significant challenges for executing malware in laboratory settings. Consequently, prior open datasets rely on isolated virtual sandboxes to run malware, resulting in data that is not representative of malware behavior in the wild. Sareena Karapoola, Nikhilesh Singh, Chester Rebeiro, V. Kamakoti 0001 |
CIKM | 3 |
| 2022 | Timed speculative attacks exploiting store-to-load forwarding bypassing cache-based countermeasuresabstractIn this paper, we propose a novel class of speculative attacks, called Timed Speculative Attacks (TSA), that does not depend on the state changes in the cache memory. Instead, it makes use of the timing differences that occur due to store-to-load forwarding. We propose two attack strategies - Fill-and-Forward utilizing correctly speculated loads, and Fill-and-Misdirect using mis-speculated load instructions. While Fill-and-Forward exploits the shared store buffers in a multi-threaded CPU core, the Fill-and-Misdirect approach exploits the influence of rolled back mis-speculated loads on subsequent instructions. As case studies, we demonstrate a covert channel using Fill-and-Forward and key recovery attacks on OpenSSL AES and Romulus-N Authenticated Encryption with Associated Data scheme using Fill-and-Misdirect approach. Finally, we show that TSA is able to subvert popular cache-based countermeasures for transient attacks. Anirban Chakraborty 0003, Nikhilesh Singh, Sarani Bhattacharya, Chester Rebeiro, Debdeep Mukhopadhyay |
DAC | 4 |
| 2022 | Privacy-Preserving Decentralized Exchange MarketplacesabstractDecentralized exchange markets leveraging blockchain have been proposed recently to provide open and equal access to traders, improve transparency and avoid single-point-of-compromise of centralized exchanges. However, they compromise on the privacy of traders with respect to their asset ownership, account balance, order details and their identity. In this paper, we present Rialto, a fully decentralized privacy-preserving exchange marketplace with support for matching trade orders, on-chain settlement and market price discovery. Rialto provides order rate and account balance confidentiality and unlinkability between traders and their trade orders, while retaining the desirable properties of a traditional marketplace like front-running resilience and market fairness. We define formal security notions of the marketplace. We perform a detailed evaluation of our solution, demonstrate that it scales well and is suitable for a large class of goods and financial instruments traded in modern exchange markets. Kavya Govindarajan, Dhinakaran Vinayagamurthy, Praveen Jayachandran, Chester Rebeiro |
ICBC | 4 |
| 2022 | FadingBF: A Bloom Filter With Consistent Guarantees for Online ApplicationsabstractBloom filter (BF), when used by an online application, experiences monotonically increasing false-positive errors. The decay of stale elements can control false-positives. Existing mechanisms for decay require unreasonable storage and computation. Inexpensive methods reset the BF periodically, resulting in inconsistent guarantees and performance issues in the underlying computing system. In this article, we propose Fading Bloom filter (FadingBF), which can provide inexpensive yet safe decay of elements. FadingBF neither requires additional storage nor computation to achieve this but instead exploits the underlying storage medium’s intrinsic properties, i.e., DRAM capacitor characteristics. We realize FadingBF by implementing the BF on a DRAM memory module with itsperiodic refresh disabled. Consequently, the capacitors holding the data elements that are not accessed frequently will predictably lose charge and naturally decay. The retention time of capacitors guarantees against premature deletion. However, some capacitors may store information longer than required due to the FadingBF’s software and hardware variables. Using an analytical model of the FadingBF, we show that carefully tuning its parameters can minimize such cases. For a surveillance application, we demonstrate that FadingBF achieves better guarantees through graceful decay, consumes 57 percent lesser energy, and has a system load that is lesser than the standard BF. Prasanna Karthik Vairam, Chester Rebeiro, V. Kamakoti 0001 |
IEEE Trans. Computers | 3 |
| 2021 | A Formal Analysis of Prefetching in Profiled Cache-Timing Attacks on Block Ciphers
Chester Rebeiro, Debdeep Mukhopadhyay |
J. Cryptol. | 1 |
| 2021 | PERI: A Configurable Posit Enabled RISC-V CoreabstractOwing to the failure of Dennard’s scaling, the past decade has seen a steep growth of prominent new paradigms leveraging opportunities in computer architecture. Two technologies of interest are Posit and RISC-V. Posit was introduced in mid-2017 as a viable alternative to IEEE-754, and RISC-V provides a commercial-grade open source Instruction Set Architecture (ISA). In this article, we bring these two technologies together and propose a Configurable Posit Enabled RISC-V Core called PERI. The article provides insights on how the Single-Precision Floating Point (“F”) extension of RISC-V can be leveraged to support posit arithmetic. We also present the implementation details of a parameterized and feature-complete posit Floating Point Unit (FPU). The configurability and the parameterization features of this unit generate optimal hardware, which caters to the accuracy and energy/area tradeoffs imposed by the applications, a feature not possible with IEEE-754 implementation. The posit FPU has been integrated with the RISC-V compliant SHAKTI C-class core as an execution unit. To further leverage the potential of posit , we enhance our posit FPU to support two different exponent sizes (with posit-size being 32-bits), thereby enabling multiple-precision at runtime. To enable the compilation and execution of C programs on PERI, we have made minimal modifications to the GNU C Compiler (GCC), targeting the “F” extension of the RISC-V. We compare posit with IEEE-754 in terms of hardware area, application accuracy, and runtime. We also present an alternate methodology of integrating the posit FPU with the RISC-V core as an accelerator using the custom opcode space of RISC-V. Sugandha Tiwari, Neel Gala, Chester Rebeiro, V. Kamakoti 0001 |
ACM Trans. Archit. Code Optim. | 3 |
| 2021 | FaultDroid: An Algorithmic Approach for Fault-Induced Information Leakage AnalysisabstractFault attacks belong to a potent class of implementation-based attacks that can compromise a crypto-device within a few milliseconds. Out of the large numbers of faults that can occur in the device, only a very few are exploitable in terms of leaking the secret key. Ignorance of this fact has resulted in countermeasures that have either significant overhead or inadequate protection. This article presents a framework, referred to as FaultDroid, for automated vulnerability analysis of fault attacks. It explores the entire fault attack space, identifies the single/multiple fault scenarios that can be exploited by a differential fault attack, rank-orders them in terms of criticality, and provides design guidance to mitigate the vulnerabilities at low cost. The framework enables a designer to automatically evaluate the fault attack vulnerabilities of a block cipher implementation and then incorporate efficient countermeasures. FaultDroid uses a formal model of fault attacks on a high-level specification of a block cipher and hence is equally applicable to both software and hardware implementation of the cipher. As case studies, we employ FaultDroid to comprehensively evaluate the fault scenarios in several common ciphers—AES, CLEFIA, CAMELLIA, SMS4, SIMON, PRESENT, and GIFT—and assess their vulnerability. Indrani Roy, Chester Rebeiro, Aritra Hazra, Swarup Bhunia |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2020 | SOLOMON: An Automated Framework for Detecting Fault Attack Vulnerabilities in HardwareabstractFault attacks are potent physical attacks on crypto-devices. A single fault injected during encryption can reveal the cipher's secret key. In a hardware realization of an encryption algorithm, only a tiny fraction of the gates is exploitable by such an attack. Finding these vulnerable gates has been a manual and tedious task requiring considerable expertise. In this paper, we propose SOLOMON, the first automatic fault attack vulnerability detection framework for hardware designs. Given a cipher implementation, either at RTL or gate-level, SOLOMON uses formal methods to map vulnerable regions in the cipher algorithm to specific locations in the hardware thus enabling targeted countermeasures to be deployed with much lesser overheads. We demonstrate the efficacy of the SOLOMON framework using three ciphers: AES, CLEFIA, and Simon. Milind Srivastava, Patanjali SLPSK, Indrani Roy, Chester Rebeiro, Aritra Hazra, Swarup Bhunia |
DATE | 4 |
| 2020 | SAFARI: Automatic Synthesis of Fault-Attack Resistant Block Cipher ImplementationsabstractMost cipher implementations are vulnerable to a class of cryptanalytic attacks known as fault injection attacks. To reveal the secret key, these attacks make use of faults induced at specific locations during the execution of the cipher. Countermeasures for fault injection attacks require these vulnerable locations in the implementation to be first identified and then protected. However, both these steps are difficult and error-prone and, hence, it requires considerable expertise to design efficient countermeasures. Incorrect or insufficient application of the countermeasures would cause the implementation to remain vulnerable, while inefficient application of the countermeasures could lead to significant performance penalties to achieve the desired fault-attack resistance. In this paper, we present a novel framework called SAFARI for automatically synthesizing fault-attack resistant implementations of block ciphers. The framework takes as input the security requirements and a high-level specification of the block cipher. It automatically detects the vulnerable locations from the specification, applies an appropriate countermeasure based on the user-specified security requirements, and then synthesizes an efficient, fault-attack protected, RTL, or C code for the cipher. We take AES, CAMELLIA, and CLEFIA as case studies and demonstrate how the framework would explore different countermeasures, based on the vulnerability of the locations, the output format, and the required security margins. We then evaluate the efficacy of SAFARI in hardware and software to the design overhead incurred and the fault coverage. Indrani Roy, Chester Rebeiro, Aritra Hazra, Swarup Bhunia |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2020 | ALEXIA: A Processor with Lightweight Extensions for Memory SafetyabstractIllegal use of memory pointers is a serious security vulnerability. A large number of malwares exploit the spatial and temporal nature of these vulnerabilities to subvert execution or glean sensitive data from an application. Recent countermeasures attach metadata to memory pointers, which define the pointer’s capabilities. The metadata is used by the hardware to validate pointer-based memory accesses. However, recent works have considerable overheads. Further, the pointer validation is decoupled from the actual memory access. We show that this could open up vulnerabilities in multithreaded applications and introduce new vulnerabilities due to speculation in out-of-order processors. In this article, we demonstrate that the overheads can be reduced considerably by efficient metadata management. We show that the hardware can be designed in a manner that would remain safe in multithreaded applications and immune to speculative vulnerabilities. We achieve these by ensuring that the pointer validations and the corresponding memory access is always done atomically and in order. To evaluate our scheme, which we call ALEXIA, we enhance an OpenRISC processor to perform the memory validation at runtime and also add compiler support. ALEXIA is the first hardware countermeasure scheme for memory protection that provides such an end-to-end solution. We evaluate the processor on an Altera FPGA and show that the runtime overhead, on average, is 14%, with negligible impact on the processor’s size and clock frequency. There is also a negligible impact on the program’s code and data sizes. Gnanambikai Krishnakumar, Kommuru Alekhya Reddy, Chester Rebeiro |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2019 | Towards Identifying Early Indicators of a Malware InfectionabstractA malware goes through multiple stages in its life-cycle at the target machine before mounting its expected attack. The entire life-cycle can span anywhere from a few weeks to several months. The network communications during the initial phase could be the earliest indicators of a malware infection. While prior works have leveraged network traffic, none have focused on the temporal analysis of how early can the malware be detected. The main challenges here are the difficulty in differentiating benign-looking malware communications in the early stages of the malware life-cycle. In our quest to build an early warning system, we analyze malware communications to identify such early indicators. Sareena Karapoola, Chester Rebeiro, Unnati Parekh, V. Kamakoti 0001 |
AsiaCCS | 2 |
| 2019 | Karna: A Gate-Sizing based Security Aware EDA Flow for Improved Power Side-Channel Attack ProtectionabstractPower side-channel attacks pose a serious threat to the security of embedded devices. Most available countermeasures have significant overheads resulting in the application not meeting its requirements of low-power, high-performance and small area. We propose an algorithm called Karna11Karna, much like Achilles from Greek mythology, was born with a shield that protected him from attacks. Similarly, Our proposed scheme, Karna protects the design from power side-channel attacks in the manufacturing phase or in other words the chip is manufactured(born) with a shield. that can be incorporated in the Electronic Design Automation (EDA) flow, in order to significantly improve the side-channel security of the device, without impacting the other device characteristics. Karna does not add additional logic but rather achieves this by first identifying vulnerable gates in the design and then reconfiguring these gates to increase side-channel resistance. Unlike contemporary works, Karna does not require any specialized gate library but uses the gates available in the standard cell library. We integrate Karna into the Synopsys Design Compiler and demonstrate its efficacy at reducing side-channel leakage in implementations of AES, PRESENT and Simon block ciphers, synthesized for a 28nm technology node. An interesting observation is that Karna only uses the available space around the gates to perform this optimization and does not incur any additional area overheads. We showcase the side-channel resistance of these optimized designs using a Differential Power Analysis attack. Our proposed approach is able to reduce the power side-channel of the designs while incurring no penalty in delay, power and gate-count. Patanjali SLPSK, Prasanna Karthik Vairam, Chester Rebeiro, V. Kamakoti 0001 |
ICCAD | 3 |
| 2019 | Towards Measuring Quality of Service in Untrusted Multi-Vendor Service Function Chains: Balancing Security and Resource ConsumptionabstractThe IT infrastructure of large organizations consists of devices and software services purchased from multiple vendors. The problem of measuring the quality of service (QoS) of each of these vendor devices (and services) is challenging since the vendors may tamper with the measurements for monetary benefits or saving debugging efforts. Existing solutions for QoS measurement in trusted environments cannot be extended for this problem since the vendors can easily circumvent them. Solutions borrowed from other areas such as client-server QoS measurement do not help either since they incur unreasonable storage and network overheads, or require extensive modifications to the packet headers. In this paper, we propose the Measuring Tape scheme, comprised of (1) a novel data structure called evidence Bloom filter (e-BF) that can be deployed at the vendor devices (and services), and (2) unique querying techniques, which can be used by the administrator to query the e-BF to measure QoS. While e-BF uses storage and computational resources judiciously, the querying techniques ensure resilience to adversarial behavior. We evaluate our solution based on a few real-world and synthetic traces and with different adversaries. Our results highlight the trade-off between resources (i.e., storage and computation) and the accuracy of QoS predictions, as well as its implications on security. We also present an analytical model of e-BF that establishes the relationship between storage, prediction accuracy, and security. Further, we present security arguments to illustrate how our solution thwarts adversarial attempts to tamper QoS. Prasanna Karthik Vairam, Gargi Mitra, Vignesh Manoharan, Chester Rebeiro, Byrav Ramamurthy, V. Kamakoti 0001 |
INFOCOM | 4 |
| 2019 | SHAKTI-MS: a RISC-V processor for memory safety in CabstractIn this era of IoT devices, security is very often traded off for smaller device footprint and low power consumption. Considering the exponentially growing security threats of IoT and cyber-physical systems, it is important that these devices have built-in features that enhance security. In this paper, we present Shakti-MS, a lightweight RISC-V processor with built-in support for both temporal and spatial memory protection. At run time, Shakti-MS can detect and stymie memory misuse in C and C++ programs, with minimum runtime overheads. The solution uses a novel implementation of fat-pointers to efficiently detect misuse of pointers at runtime. Our proposal is to use stack-based cookies for crafting fat-pointers instead of having object-based identifiers. We store the fat-pointer on the stack, which eliminates the use of shadow memory space, or any table to store the pointer metadata. This reduces the storage overheads by a great extent. The cookie also helps to preserve control flow of the program by ensuring that the return address never gets modified by vulnerabilities like buffer overflows. Shakti-MS introduces new instructions in the microprocessor hardware, and also a modified compiler that automatically inserts these new instructions to enable memory protection. This co-design approach is intended to reduce runtime and area overheads, and also provides an end-to-end solution. The hardware has an area overhead of 700 LUTs on a Xilinx Virtex Ultrascale FPGA and 4100 cells on an open 55nm technology node. The clock frequency of the processor is not affected by the security extensions, while there is a marginal increase in the code size by 11% with an average runtime overhead of 13%. R. Harikrishnan Unnithan, Arjun Menon, Chester Rebeiro, V. Kamakoti 0001 |
LCTES | 4 |
| 2018 | An Algorithmic Approach to Formally Verify an ECC LibraryabstractThe weakest link in cryptosystems is quite often due to the implementation rather than the mathematical underpinnings. A vast majority of attacks in the recent past have targeted programming flaws and bugs to break security systems. Due to the complexity, empirically verifying such systems is practically impossible, while manual verification as well as testing do not provide adequate guarantees. In this article, we leverage model checking techniques to prove the functional correctness of an elliptic curve cryptography (ECC) library with respect to its formal specification. We demonstrate how the huge state space of the C library can be aptly verified using a hierarchical assume-guarantee verification strategy. To test the scalability of this approach, we verify the correctness of five NIST-specified elliptic curve implementations. We also verify the newer curve25519 elliptic curve, which is finding multiple applications, due to its higher security and simpler implementation. The 192-bit NIST elliptic curve took 1 day to verify. This was the smallest curve we verified. The largest curve with a 521-bit prime field took 26 days to verify. Curve25519 took 1.5 days to verify. Keerthi K. 0002, Chester Rebeiro, Aritra Hazra |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2017 | XFC: A Framework for eXploitable Fault Characterization in Block CiphersabstractFault attacks recover secret keys by exploiting faults injected during the execution of a block cipher. However, not all faults are exploitable and every exploitable fault is associated with an offline complexity to determine the key. The ideal fault attack would recover maximum key bits with minimum offline effort. Finding the ideal fault attack for a block cipher is a laborious manual task, which can take several months to years before such an attack is discovered. Punit Khanna, Chester Rebeiro, Aritra Hazra |
DAC | 2 |
| 2016 | Template attack on SPA and FA resistant implementation of Montgomery ladderabstractHardware implementations of the well‐known Rivest–Shamir–Adleman (RSA) algorithm have been shown to be vulnerable to power and fault analysis (FA) attacks. To implement protected designs of RSA‐Chinese remainder theorem in embedded devices, like smart cards or RFIDs, the one needs to find solutions which require less computations as well as incurs low storage overheads. One such efficient scheme was proposed by Joye et al . in CHES'02 and it was claimed to be secure against both simple power analysis (SPA) and FA attacks. In this study, the authors demonstrate a template attack (TA) against Joye's countermeasure and show that the scheme can be broken with a low number of power traces. In addition, the authors report the experimental results of the proposed attack against an implementation of Joye's scheme on a Xilinx Microblaze soft‐core processor of SASEBO‐W standard side‐channel analysis board. The authors used least squares support vector machine (LS‐SVM) based binary classifiers to analyse the collected power traces. The authors also describe the potential threat posed by cache timing attacks on Joye's ladder in presence of a concurrently running spy process and outline a probable countermeasure to the posed attacks. Abhishek Chakraborty 0001, Sarani Bhattacharya, Tanu Hari Dixit, Chester Rebeiro, Debdeep Mukhopadhyay |
IET Inf. Secur. | 4 |
| 2015 | Micro-Architectural Analysis of Time-Driven Cache Attacks: Quest for the Ideal ImplementationabstractTime-driven attacks on the data cache are a lethal form of cryptanalytic attacks for block-ciphers implemented with look-up tables. The difference of means (DOM) observed in the execution time of a block cipher is often used as a distinguisher to glean information about the secret key. The root cause for the distinguisher to work has long been attributed to the number of cache-misses that occur during the encryption. In this paper, we show that micro-architectural acceleration features in cache memories that are used to reduce miss-penalty (such as pipelining, parallelism, out-of-order, and non-blocking memory accesses) contribute significantly to the leakage. We develop a framework to analyze the DOM distinguisher considering architectural as well as micro-architectural acceleration components in the cache memory. Our findings, which are experimentally verified, show that the two contributing leakage factors (namely the number of cache misses and the micro-architectural acceleration features) affect the DOM in opposite directions. One leakage source results in a positive DOM while the other causes a negative DOM. This opposing characteristic of the leakages makes it feasible to implement block ciphers in a way such that the two leakages cancel each other, thus leading to implementations with higher resistance against time-driven cache-attacks. Chester Rebeiro, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 1 |
| 2013 | PERMS: A Bit Permutation Instruction for Accelerating Software CryptographyabstractThis paper proposes a new bit-permutation instruction, named PERMS for accelerating software cryptography. Bit permutation is a very commonly used operation in standard cryptographic algorithms. However, modern processors are word oriented and provide little support for high-speed implementation of bit permutations. With the help of PERMS instruction, any arbitrary n bit permutation can be performed using less than log(n) number of instructions. The proposed instruction is also scalable to perform 2n bit permutation, using an n bit instruction. The comparison with the existing bit-permutation instructions shows that PERMS needs least area requirement in hardware and also provides better throughput/slice ratio than one of the best bit-permutation instruction found in literature. The instruction format of PERMS provides the scope to be added with all the modern ISAs. Further, due to the very less hardware requirement, PERMS can also be considered for resource constrained devices, like PDAs. Souvik Kolay, Sagar Khurana, Anupam Sadhukhan, Chester Rebeiro, Debdeep Mukhopadhyay |
DSD | 4 |
| 2013 | Formalizing the Effect of Feistel Cipher Structures on Differential Cache AttacksabstractThe success of a side-channel attack depends mainly on three factors, namely, the cipher algorithm, the attack platform, and the measurement noise. In this paper, we consider a class of side-channel attacks known as differential cache attacks on Feistel ciphers, and develop a theoretical framework to understand the relationship between the attack's success, the target platform, and the cipher algorithm. The framework allows a comparison of various differential cache attack forms, and is supported by case studies on the block ciphers CLEFIA and CAMELLIA. To understand the effect of noise in the attack's success, the paper uses empirical methods on standard Intel platforms in a time driven side-channel analysis scenario. Chester Rebeiro, Phuong Ha Nguyen, Debdeep Mukhopadhyay, Axel Poschmann |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Theoretical Modeling of Elliptic Curve Scalar Multiplier on LUT-Based FPGAs for Area and SpeedabstractThis paper uses a theoretical model to approximate the delay of different characteristic two primitives used in an elliptic curve scalar multiplier architecture (ECSMA) implemented onkinput lookup table (LUT)-based field-programmable gate arrays. Approximations are used to determine the delay of the critical paths in the ECSMA. This is then used to theoretically estimate the optimal number of pipeline stages and the ideal placement of each stage in the ECSMA. This paper illustrates suitable scheduling for performing point addition and doubling in a pipelined data path of the ECSMA. Finally, detailed analyses, supported with experimental results, are provided to design the fastest scalar multiplier over generic curves. Experimental results for GF(2163) show that, when the ECSMA is suitably pipelined, the scalar multiplication can be performed in only 9.5 μs on a Xilinx Virtex V. Notably the design has an area which is significantly smaller than other reported high-speed designs, which is due to the better LUT utilization of the underlying field primitives. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2012 | Pushing the Limits of High-Speed GF(2 m ) Elliptic Curve Scalar Multiplication on FPGAs
Chester Rebeiro, Sujoy Sinha Roy, Debdeep Mukhopadhyay |
CHES | 1 |
| 2012 | Improved Differential Cache Attacks on SMS4
Phuong Ha Nguyen, Chester Rebeiro, Debdeep Mukhopadhyay, Huaxiong Wang |
Inscrypt | 2 |
| 2012 | A Parallel Architecture for Koblitz Curve Scalar Multiplications on FPGA PlatformsabstractElliptic curve scalar multiplication is the central operation in elliptic curve cryptography. The paper presents a parallel architecture to accelerate scalar multiplications on Koblitz curves. The scalar multiplier architecture converts the scalar into τ-NAF representation and processes the zero digits of the scalar in parallel to point additions. Since the conversion from integer to τ-NAF is a time consuming operation, the proposed architecture uses recently developed double lazy reduction algorithm for conversion of scalar. The scalar multiplier processes two consecutive τ-NAF digits in every iteration. This facilitates parallel processing of large number of consecutive zero digits during a single point addition and practically no time is spent for processing the zero digits of the scalar. The proposed techniques are incorporated in a scalar multiplier and validated on Xilinx Virtex IV FPGA. Experimental results show that our architecture in F2163 has the best performance and has the computation time comparable with the fastest known implementation, which uses window based scalar multiplication algorithm. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
DSD | 2 |
| 2012 | Generalized high speed Itoh-Tsujii multiplicative inversion architecture for FPGAs
Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
Integr. | 2 |
| 2012 | Boosting Profiled Cache Timing Attacks With A Priori AnalysisabstractThe vulnerability of cryptographic devices to side-channel attacks is of interest in the domain of information security. The success of a side-channel attack depends on the crypto-algorithm implementation, the platform being attacked, and the attack strategy. While the former two parameters are generally beyond the adversary's control, the choice of the attack strategy is solely with the adversary. However, there is no unique “best attack strategy.” The attack strategy that works best for one platform may not be the best for another. Further there is no systematic way to choose the best attack strategy from the available pool. In this paper, we analyze a category of side-channel attacks known as profiled cache-timing attacks and develop a methodology by which an adversary capable of limited number of side-channel measurements can choose the best strategy prior to the actual attack. The methodology is tested on several platforms and cipher implementations and shows that the best attacking strategy can be estimated closely, without the requirement of an exhaustive search. Chester Rebeiro, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2011 | Cryptanalysis of CLEFIA Using Differential Methods with Cache Trace Patterns
Chester Rebeiro, Debdeep Mukhopadhyay |
CT-RSA | 1 |
| 2011 | Theoretical modeling of the Itoh-Tsujii Inversion algorithm for enhanced performance on k-LUT based FPGAsabstractMaximizing the performance of the Itoh-Tsujii finite field inversion algorithm (ITA) on FPGAs requires tuning of several design parameters. This is often time consuming and difficult. This paper presents a theoretical model for the ITA for any Galois field and fc-input LUT based FPGA (k >; 3). Such a model would aid a hardware designer to select the ideal design parameters quickly. The model is experimentally validated with the NIST specified fields and with 4 and 6 LUT based FPGAs. Finally, it is demonstrated that the resultant designs of the Itoh-Tsujii Inversion algorithm is most optimized among contemporary works on LUT based FPGAs. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
DATE | 2 |
| 2011 | Accelerating Itoh-Tsujii multiplicative inversion algorithm for FPGAsabstractThe Itoh-Tsujii multiplicative inversion algorithm (ITA) is the most efficient finite field inversion algorithm for hardware based implementations over extended binary fields. In this paper we propose a novel technique to reduce the computation time of the ITA by saving clock cycles without increasing the delay and area significantly. In order to compare, we have designed the architecture for the ITA in the field GF(2193). The architecture uses a configuration of a cascaded quad-root block in parallel with a 297 circuit to compute the inverse in only .53 ¼secs on a Virtex E FPGA and .14 ¼secs on a Virtex V FPGA. Experimental results are presented to support that the architecture takes least computation time compared to other reported results. Sujoy Sinha Roy, Chester Rebeiro, Debdeep Mukhopadhyay |
ACM Great Lakes Symposium on VLSI | 2 |
| 2011 | Revisiting the Itoh-Tsujii Inversion Algorithm for FPGA PlatformsabstractThe Itoh-Tsujii multiplicative inverse algorithm (ITA) forms an integral component of several cryptographic implementations such as elliptic curve cryptography. For binary fields generated by irreducible trinomials, this paper proposes a modified ITA algorithm for efficient implementations on field-programmable gate-array (FPGA) platforms. Efficiency is obtained by the fact that the adapted ITA algorithm uses FPGA resources better and requires shorter addition chains. Evidence is furnished and supported with experimental results to show that the proposed architecture outperforms reported results. The proposed method is also shown to be scalable with respect to field sizes. Chester Rebeiro, Sujoy Sinha Roy, Sankara Reddy, Debdeep Mukhopadhyay |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2006 | Bitslice Implementation of AES
Chester Rebeiro, A. David Selvakumar, A. S. L. Devi |
CANS | 1 |