Xiang Li 0158

dblp:40/1491-158 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0003-3933-2099ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 2 first-author · 4 since 2021Security and privacy · 1
YearPublicationVenuePosition
2025 On-die Differential Sensing for Monitoring and Analysis of Dynamic Computing Environments
abstract
With increasing popularity of cloud FPGAs and future multi-tenant usage, security threats are posed including on-die side channel attacks, fault injection or denial of service caused by power wasting circuits. Monitoring FPGA circuit activity with sensors is a common technique used by attackers and defenders. Combining data from multiple sensors makes it possible to pinpoint power wasting circuits, but with limited precision. In this paper we demonstrate how a network of sensors and differential analysis can together increase robustness of monitoring, making it possible to determine the location of target circuits even if their power consumption is relatively low. The sensors are ring oscillator (RO) or time-to-digital converter (TDC) circuits that collect timeseries information of the local voltage at different FPGA points. The sensor data and knowledge of when target circuits are active, enables the differential analysis technique that boosts the sensitivity beyond that of prior works. We analyze how the performance varies with sensor coverage and circuit parameters and show how a pre-characterization procedure can further improve accuracy over uncalibrated analysis.
Shahriar Hadayeghparast, Xiang Li 0158, Aleksa Deric, Daniel E. Holcomb
ISCAS2
2023 Jitter-based Adaptive True Random Number Generation Circuits for FPGAs in the Cloud
abstract
In this article, we present and evaluate a true random number generator (TRNG) design that is compatible with the restrictions imposed by cloud-based Field Programmable Gate Array (FPGA) providers such as Amazon Web Services (AWS) EC2 F1. Because cloud FPGA providers disallow the ring oscillator circuits that conventionally generate TRNG entropy, our design is oscillator-free and uses clock jitter as its entropy source. The clock jitter is harvested with a time-to-digital converter (TDC) and a controllable delay line that is continuously tuned to compensate for process, voltage, and temperature variations. After describing the design, we present and validate a stochastic model that conservatively quantifies its worst-case entropy. We deploy and model the design in the cloud on 60 EC2 F1 FPGA instances to ensure sufficient randomness is captured. TRNG entropy is further validated using NIST test suites, and experiments are performed to understand how the TRNG responds to on-die power attacks that disturb the FPGA supply voltage in the vicinity of the TRNG. After introducing and validating our basic TRNG design, we introduce and validate a new variant that uses four instances of a linkable sampling module to increase the entropy per sample and improve throughput. The new variant improves throughput by 250% at a modest 17% increase in CLB count.
Xiang Li 0158, Peter Stanwicks, George Provelengios, Russell Tessier, Daniel E. Holcomb
ACM Trans. Reconfigurable Technol. Syst.1
2023 Voltage Sensor Implementations for Remote Power Attacks on FPGAs
abstract
This article presents a study of two types of on-chip FPGA voltage sensors based on ring oscillators (ROs) and time-to-digital converter (TDCs), respectively. It has previously been shown that these sensors are often used to extract side-channel information from FPGAs without physical access. The performance of the sensors is evaluated in the presence of circuits that deliberately waste power, resulting in localized voltage drops. The effects of FPGA power supply features and sensor sensitivity in detecting voltage drops in an FPGA power distribution network (PDN) are evaluated for Xilinx Artix-7, Zynq 7000, and Zynq UltraScale+ FPGAs. We show that both sensor types are able to detect supply voltage drops, and that their measurements are consistent with each other. Our findings show that TDC-based sensors are more sensitive and can detect voltage drops that are shorter in duration, while RO sensors are easier to implement because calibration is not required. Furthermore, we present a new time-interleaved TDC design that sweeps the sensor phase. The new sensor generates data that can reconstruct voltage transients on the order of tens of picoseconds.
Shayan Moini, Aleksa Deric, Xiang Li 0158, George Provelengios, Wayne P. Burleson, Russell Tessier, Daniel E. Holcomb
ACM Trans. Reconfigurable Technol. Syst.3
2022 Precise Fault Injection to Enable DFIA for Attacking AES in Remote FPGAs
abstract
Differential Fault Intensity Analysis (DFIA) is a class of biased-fault attacks that aim to recover secret keys from block ciphers such as Advanced Encryption Standard (AES). In DFIA an attacker collects a set of ciphertexts generated while carefully controlling the fault intensity, and then performs an analysis on the results that reveals the secret encryption key. In AES, DFIA requires injecting varied intensity faults during exactly the 9th round of encryption, which could be accomplished using clock or supply voltage glitching, although previous works give scant consideration to shaping the fault within a realistic scenario.In this work, we demonstrate DFIA against an FPGA implementation of AES without assuming arbitrary external control of clock or supply voltage. Instead we use on-chip ring oscillators (ROs) to create a precise and controllable voltage drop in the vicinity of the AES circuit, which causes timing faults to occur. The fault intensity is finely controlled by changing the number of activated ROs, and we explore how to optimize the timing of the RO activation to cause a fault in the 9th round as is required in DFIA. We use this approach to perform DFIA against AES on Xilinx Spartan-7 FPGA, show that it successfully extracts AES key bytes, and discuss its performance.
Xiang Li 0158, Russell Tessier, Daniel E. Holcomb
FCCM1
2020 COUNTERFOIL: Verifying Provenance of Integrated Circuits using Intrinsic Package Fingerprints and Inexpensive Cameras
Siva Nishok Dhanuskodi, Xiang Li 0158, Daniel E. Holcomb
USENIX Security Symposium2