EDBT 2026 Demo / reviewers in the wild / expert
Aijiao Cui
dblp:67/1816
· DBLP profile ↗
36ranked-venue papers
17as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 31 · 14 first-author · 4 since 2021Security and privacy · 3 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VeriRepair: Toward Reliable LLM-Based RTL Repair via CoT-Supervised Multi-Objective Fine-Tuning and Hybrid Retrieval
Aijiao Cui, Yier Jin |
DATE | 2 |
| 2024 | A Hardware Security Evaluation Platform on RISC-V SoCabstractThe escalating complexity of integrated circuits (ICs) enables a substantial computational power, yet also results in a challenging verification of vulnerability. Effective and efficient verification of ICs in a high design complexity turns to a great concern to be solved. This paper presents a hardware security evaluation platform constructed on the open-source RISC-V System-on-Chip (SoC) - OpenPiton to facilitate the development of the techniques on design vulnerability discovery. Some pertinent hardware vulnerabilities are compiled and integrated into both the processor core and the peripheral modules of the OpenPiton hardware platform. Aijiao Cui, Yier Jin |
ITC-Asia | 2 |
| 2022 | A Memristor-based Secure Scan Design against the Scan-based Side-Channel AttacksabstractScan chain design can improve the testability of a circuit while it can be used as a side-channel to access the sensitive information inside a cryptographic chip for the crack of cipher key. To secure the scan design while maintaining its testability, this paper proposes a memristor-based secure scan design. A lock and key scheme is introduced. Physical unclonable function (PUF) is used to generate a unique test key for each chip. When an input test key matches the PUF-based key, the scan chain can be used normally for testing. Otherwise, the data in some scan cells are obfuscated by the random bits, which are generated by reading the status of a memristor. As the random bits do not relate to the original test data, an adversary cannot access useful information from scan chain to deduce the cipher key. The experimental results show that the proposed secure scan design can resist all existing attacks while incurring low overhead. Also, the testability of the original design is not affected. Mengqiang Lu, Aijiao Cui, Gang Qu 0001 |
ACM Great Lakes Symposium on VLSI | 2 |
| 2021 | Identification of Counter Registers through Full Scan ChainabstractCounters have been widely adopted in modern circuit design. Also, they have been used to facilitate the implementation of hardware Trojan. It is necessary to reverse engineer the counter design from a chip so as to detect the possible Trojan. However, the existing reverse engineering technique is expensive and intrusive. In this work, we first propose to rely on the scan dump data to identify the registers included in a counter. In this scheme, the scan data can be collected by operating the chip in testing mode, thus the proposed scheme never impacts or impairs a chip as the traditional reverse engineering techniques. The regularity of data from different types of counters is first analyzed. The relationship between the data from a pair of registers is explored so that the counter registers can be distinguished from other normal registers. The proposed method is applied on several circuits containing counters from OpenCores. The experiment results show the proposed method can accurately identify the counter registers with a perfect true positive rate and true negative rate. Qidong Wang, Aijiao Cui, Gang Qu 0001 |
ITC-Asia | 2 |
| 2021 | Identification of FSM State Registers by Analytics of Scan-Dump DataabstractBig data analytics have gained tremendous successes in mining valuable information in various fields. However, its potential to solve complex problems in hardware security has not been adequately tapped. This paper presents a non-invasive approach to identify the state registers of a finite state machine (FSM) in an integrated chip. The state registers of the FSM are mined from the scan-dump data by exploiting the strongly connected property and chronologically correlated state codes of the FSM. The sequence of data scanned out of each scan register is partitioned into non-overlapping strings of high weighted frequencies by a string-matching algorithm. A coherency between a pair of registers is defined and computed based on the partitioned strings. The dimension of the coherency matrix is first reduced by pruning some registers of low influence by a regression analysis. The registers are then clustered to minimize the within-cluster variances based on their coherency values. The proposed scheme is applied to some IP cores from OpenCores. The experimental results show that our scheme can correctly identify the FSM state registers in most designs with high hit rate. Aijiao Cui, Chengkang He, Chip-Hong Chang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | A New Aging Sensor for the Detection of Recycled ICsabstractThe electronics industry has become the main target of counterfeiting. Integrated circuits (ICs) are highly vulnerable to various types of counterfeiting such as recycling. The recycled ICs do not have the performance and service lifetime of the genuine ones, which poses a threat to reliability of electronic systems. In this paper, we propose a novel recycled IC detection method. An authentication mechanism and a parallel circuit unit structures, as an aging sensor, are used to distinguish recycled ICs from fresh ICs. Due to degradation in the field, the path delay of used circuit unit (scan-flip flop for example) will become larger than that in fresh circuit unit, which inspire us to use an authentication procedure to "freeze" the circuit unit-ref, and utilize SR-latch to compare the transmission speed of two circuit channels. Both HSPICE simulation and FPGA silicon implementation results show that this is a cost-effective method with high detection accuracy and secure again standard attacks. Aijiao Cui, Gang Qu 0001 |
ACM Great Lakes Symposium on VLSI | 2 |
| 2020 | A New Secure Scan Design with PUF-based Key for AuthenticationabstractScan-based side-channel attack has become a new threat to cryptographic chips. Many countermeasures are proposed to safeguard scan design against the scan-based attacks. Among which, the methods based on lock and key scheme present more effective and popular. In this paper, we propose a new lock and key scheme which adopts physical unclonable function (PUF) design to generate a unique key for each design. The uniqueness of PUF enables each chip taped out from one mask to possess a different golden key. Once the PUF is invoked for the first time, the PUF response will be hardcoded into the design so that even the environment changes, the PUF-based key maintains. The proposed secure scan design with PUF-based key can protect the cryptographic chips against all known scan-based side-channel attacks while incurring negligible overhead. Qidong Wang, Aijiao Cui, Gang Qu 0001, Huawei Li 0001 |
VTS | 2 |
| 2020 | A Guaranteed Secure Scan Design Based on Test Data Obfuscation by Cryptographic HashabstractDesign-for-testability (DfT) techniques have been widely adopted into the integrated circuit (IC) design process to facilitate manufacture testing. The scan-based DfT architecture is a popular DfT feature that provides full testability for the circuit under test. However, this turns into a double-edged sword for some ICs such as cryptographic chips because scan design could be used as a side channel to access the intermediate encryption results, with which the cipher key can be deduced easily. To resist such scan-based side-channel attacks, many countermeasures are proposed to obfuscate the test data in scan chain. Unfortunately, most of the obfuscation logic, due to the performance and resource constraints, cannot be proven to be irreversible and hence suffers a high risk for the correct test data being derived from the obfuscated output. In this article, we propose to utilize the cryptographic hash module for some post-processing of the test responses in order to secure the scan design. Our approach has several clear advantages over existing ones. First, the security is guaranteed based on the preimage resistance of cryptographic hash function and the introduced salt information and data collection scheme. Second, it incurs low overhead because the hash module is normally available on the IC, in particular, those where security is important. Finally, full testability is retained as we are not modifying any test input. We present the implementation of the proposed secure design, report the experimental results, and demonstrate that our approach can resist all known scan-based side-channel attacks with negligible overhead while maintaining the testability and other testing performances. Aijiao Cui, Gang Qu 0001, Huawei Li 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2019 | A New Pay-Per-Use Scheme for the Protection of FPGA IPabstractField-programmable gate arrays (FPGAs) are widely applied in various fields for its merit of reconfigurability. The reusable intellectual property (IP) design blocks are usually adopted in the more complex FPGA designs to shorten design cycle. IP infringement hence becomes a concern. In this paper, we propose a new pay-per-use scheme using the lock and key mechanism for the protection of FPGA IP. Physical Unclonable Function (PUF) is adopted to generate a unique ID for each IP instance. An extra Finite State Machine (FSM) is introduced for the secure retrieval of PUF information by the FPGA IP vendor. The lock is implemented on the original FSM. Only when the FPGA developer can provide a correct license, can the FSM be unlocked and start normal operation. The FPGA IP can hence be protected from illegal use or distribution. The scheme is applied on some benchmarks and the experimental results show that it just incurs acceptably low overhead while it can resist typical attacks. Peiqi Sun, Aijiao Cui |
ISCAS | 2 |
| 2019 | A Secure and Low-overhead Active IC Metering SchemeabstractIn the horizontal semiconductor business mode, the foundry can tamper or overbuild the integrated circuits (ICs) while the owner of the IC knows nothing about it. IC metering technique has been proposed to solve this problem. In this paper, we propose a new external active IC metering method. The physical unclonable function (PUF) is used to generate a unique key for each chip. We first propose to modify the finite state machine (FSM) so that the PUF-based key can be securely retrieved from the FSM. With regards to overhead and security, this retrieval scheme takes advantage over the existing scheme with encryption module to safeguard the PUF-based key. The experimental results show that the proposed retrieval scheme incurs negligibly low overhead to the original FSM. Also, the overhead due to the metering method accounts for small percentage to the overall design while the proposed scheme can resist typical attacks. Aijiao Cui, Gang Qu 0001, Huawei Li 0001 |
VTS | 1 |
| 2018 | A low-overhead PUF based on parallel scan designabstractPhysical unclonable function (PUF) is a promising security primitive. Most existing delay based PUF designs are independent of the original circuit. The extra PUF circuitry not only makes PUF vulnerable to removal attack, but also incurs high area overhead. In this paper, we propose to reuse the parallel scan design existing in the original circuit to implement PUF. The basic idea is to pass the same input signal to two scannable flip-flops and to use the discrepancy in the two output signals' arrival time to generate a PUF bit. Symmetrical SR-latches are used as arbiters to reduce PUF design cost. Compared to the previous scan based PUF using single scan chain, the proposed approach avoids the requirement of a rigorous clock of high frequency. It simultaneously reduces the area overhead and improves the robustness against removal attack. The proposed PUF design is implemented on XILINX Virtex-5 FPGA boards. Experimental results show that it has a high level of uniqueness of 49.86%, very good randomness, and acceptable reliability under temperature and voltage variations. Aijiao Cui, Gang Qu 0001, Huawei Li 0001 |
ASP-DAC | 2 |
| 2018 | A New Scheme to Extract PUF Information by Scan ChainabstractPhysical unclonable function (PUF) has been widely investigated as a potential security primitive. The unexpected and unclonable PUF information usually serves as a unique ID or secret key in various application scenarios. How to retrieve the PUF information securely at a reasonably low cost is then a concern. In this paper, we propose a new scheme to extract the PUF information by scan chain. PUF information is used to monitor the test control port (tc) of some specific scan cells at certain time. The output response under a designer-specific test vector is hence obfuscated. The difference between the obfuscated output and the normal output can be used to deduce the PUF information. By reusing the existing scan chain design, the design for PUF extraction cannot be removed easily and it incurs negligibly low overhead. As the specific test vector and related design detail are both unknown to others except designer, the probability for an attacker to figure out the PUF information is sufficiently low. This scheme to extract PUF information can be applied in metering technique or other security-sensitive scenarios. Aijiao Cui, Gang Qu 0001, Huawei Li 0001 |
ATS | 1 |
| 2018 | Balancing Testability and Security by Configurable Partial Scan DesignabstractScan chain design facilitates chip testing by providing an interface for the test engineers to access and control the internal states of the circuit. This feature has also been exploited to break systems such as the cryptographic chips by the attack known as scan chain side channel analysis. From the perspective of information access, test engineers and scan chain attackers have the same goal - observe and control the scan chain side channel information. Consequently, all the existing countermeasures have to make the tradeoff between scan chain security and the testability it can provide. In this paper, we propose a novel public-private partial scan chain design which can deliver both full testability and security. The key idea is to partition the flip flops into a public partial chain and a set of parallel private partial chains. The private partial chains are protected by means of a hardware implemented finite state machine and an obfuscation mechanism based on configurable physical unclonable function. We demonstrate how full testability can be achieved by the proposed public-private partial chains. We conduct security and performance analysis to show that our approach is robust against all the known scan chain based attacks and can improve testing time and power consumption with negligible hardware overhead. Xi Chen 0118, Omid Aramoon, Gang Qu 0001, Aijiao Cui |
ITC-Asia | 4 |
| 2017 | A New Active IC Metering Technique Based on Locking Scan CellsabstractIn this paper, we propose a new external active metering technique. Physical unclonable function (PUF) is used to generate a unique key for each IC. The PUF key is encrypted by public-key cryptography (PKC) algorithm and passed to the design house for decryption with private key. Only when the foundry inputs correct key into the design, can the design be unlocked and work normally. A new locking scheme is implemented by controlling the working mode of some specific scan cells in scan chain. Such locking scheme will not affect the timing of the functional path. Also, this metering method allows multiple input of key friendly. After the first successful activation, the unlocking circuitry will not function any more, which overcomes the weakness of multiple queries of correct key from design house due to the variation of PUF key with environmental change or aging. The metering method just incurs acceptably low area overhead and no compromise of testability. It can resist typical attacks. Aijiao Cui, Xuesen Qian, Gang Qu 0001, Huawei Li 0001 |
ATS | 1 |
| 2017 | How to Secure Scan Design Against Scan-Based Side-Channel Attacks?abstractScan-based design-for-testability (DfT) structure has been widely adopted in integrated circuit (IC) design. It enables high testability for circuit under test (CUT). However, security concerns are also caused. For a cryptographic chip or module, an adversary can use scan chain as a side channel to collect sensitive information for the retrieval of cipher key. This poses a high threat for the fields where the cryptographic chips are applied. Effective countermeasures should be explored to solve this problem. In this paper, we survey the existing work on secure scan designs and highlight their merits and weaknesses. Our recent work is presented to illustrate how the weaknesses in existing countermeasures can be overcome. All these work are compared in terms of the area overhead, security and impact on testability. Our ongoing work is briefly introduced to indicate the promising future work in this area. Aijiao Cui, Huawei Li 0001, Gang Qu 0001 |
ATS | 2 |
| 2017 | Practical IP watermarking and fingerprinting methods for ASIC designsabstractWith the rapidly increased integrated circuits (ICs) design complexity and the adoption of third party intellectual property (IP) blocks for use and reuse, concerns on potential IP infringements that violate the legal rights of both IP owners and consumers were raised more than 20 years ago. Digital watermarking and fingerprinting methods have been developed for the purpose of protecting IPs. In this paper, we survey the available watermarking and fingerprinting schemes with high practical values in order to facilitate their industrial adoption. Xi Chen 0118, Gang Qu 0001, Aijiao Cui |
ISCAS | 3 |
| 2017 | A new watermarking scheme on scan chain ordering for hard IP protectionabstractConstraint-based watermarking has been proven as an effective means for hardware intellectual property (IP) protection. Scan chain further facilitates field authentication of the watermarks embedded in densely integrated IP cores and serves as an added layer of tamper-evident protection if it is also watermarked. In this paper, we propose a new scan-chain based watermarking scheme that can be used standalone as a reasonably robust copyright protection of hard IP core. During the process of scan chain ordering for test power optimization, the watermark bits constrain the cost of one connection style over the other for certain pairings of scan cells in the minimization process depending on the output of the IP core under the chosen test vector for watermark verification. Thus, the watermark is better obfuscated since both connection styles are possible to be selected at the watermarked locations. Typical attack scenarios are discussed and our experimental results show that strong authorship can be achieved with low overhead on test power incurred. Xiaonan Huang, Aijiao Cui, Chip-Hong Chang |
ISCAS | 2 |
| 2017 | Why current secure scan designs fail and how to fix them?
Aijiao Cui, Yanhui Luo, Huawei Li 0001, Gang Qu 0001 |
Integr. | 1 |
| 2017 | Static and Dynamic Obfuscations of Scan Data Against Scan-Based Side-Channel AttacksabstractDue to the fallibility of advanced integrated circuit (IC) fabrication processes, scan test has been widely used by cryptographic ICs to provide high fault coverage. Full controllability and observability offered by the scan design also open out the trapdoor to side-channel attacks. To better resist signature attacks on scan testable cryptochip, we propose to fortify the key and lock method by the static obfuscation of scan data. Instead of spatially reshuffling the scan cells, the working mode of some scan cells is altered to jumble up the scan data when the scan test is performed with an incorrect test key. However, when the plaintext is fed directly through the primary inputs for test efficiency, the static obfuscation of scan data is inadequate as demonstrated by a new test-mode-only signature attack (TMOSA) proposed in this paper. To thwart TMOSA, a new countermeasure based on the dynamic obfuscation of scan data is proposed. By cyclically shifting the incorrect test key throughout the test phase, the blocking cells due to the mismatched bits of the test key are made to move temporally to dynamically obfuscate the scan data. This latter scheme is unconditionally resilient against TMOSA and all other known scan-based attacks while preserving the merits of high testability and low area overhead compared with other countermeasures. Aijiao Cui, Yanhui Luo, Chip-Hong Chang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | An improved test power optimization method by insertion of linear functionsabstractScan-based design-for-testability (DFT) structure is widely used to facilitate the testing of integrated circuits (ICs). However, it always incurs much test power consumption. In this paper, we propose an improved test power optimization method by inserting extra logic in scan chain. It explores suitable places in scan chain based on an accurate criterion to insert different linear functions so as to minimize the transitions caused by shifting test data through scan chain. We apply our method on different benchmark circuits and the experimental result shows that the proposed method is more efficient to reduce test power than other optimization methods by inserting extra logic while incurring low area. Lucheng He, Aijiao Cui, André Ivanov |
ISCAS | 2 |
| 2016 | A new countermeasure against scan-based side-channel attacksabstractScan design has been widely used to facilitate the testing of integrated circuits (ICs). However, it also provides attackers a side-channel to access the internal states of crypto chips and thus becomes a great threat to the security of the cipher keys. We propose a secure scan design scheme to protect crypto chips against such scan-based side-channel attacks. In this scheme, we introduce a shift register to control the working mode of certain scan cells. Only when the user configures the shift register correctly, can the scan design work normally under testing mode. We show that the proposed secure scan design can effectively resist the existing scan-based attacks. We also demonstrate that this approach has low area overhead while maintaining the testability of original design. Yanhui Luo, Aijiao Cui, Gang Qu 0001, Huawei Li 0001 |
ISCAS | 2 |
| 2015 | Reliable and Anti-cloning PUFs Based on Configurable Ring OscillatorsabstractRing oscillator Physical Unclonable Function (RO PUF) is a popular silicon PUF due to its ease of implementation on both ASIC and FPGA. However, RO PUFs have severe reliability issues when the operating environment deviates from the nominal condition and security issues as cloning attacks have been reported. In this work, we propose to build configurable RO PUFs based on the notions of configurable RO PUF [6, 16] and highly flexible RO PUF [22] to address these concerns. First, we demonstrate how to build RO PUF from single flexible ROs, which improves both the reliability and hardware efficiency of RO PUFs. Then we propose a novel dual voltage based configurable RO PUF to mitigate the cloning attacks. Our experimental results show that our configurable RO PUFs are more reliable and hardware efficient than the existing RO PUF designs. Using the flexible RO PUF [22] as baseline, we have reduced the bit flip rate by 69% and improve the hardware utilization by 136%. In addition, the anti-cloning approach generates PUF data significantly different from the original PUF secret (average 47.5% Hamming distance) which makes potential cloning attacks very difficult. Khai Lai, Jiliang Zhang 0002, Gang Qu 0001, Aijiao Cui, Qiang Zhou 0001 |
CAD/Graphics | 5 |
| 2015 | An improved scan design for minimization of test power under routing constraintabstractScan cell ordering method is widely applied to reduce test power. Such ordering may result in significant routing overhead. In this paper, we propose a new scan design method to minimize test power under routing constraint. We base on the characteristics of scan cell distribution to cluster them prior to the ordering so as to satisfy routing constraint. Flexible scan cells are identified from each cluster to achieve further reduction of test power under routing constraint. Scan cells are finally ordered based on the evaluation of the transitions caused by connected scan cells during test. The experimental results show that the scan designs by our method can always achieve lower test power than those by other existing optimization method while satisfying the routing constraint. Aijiao Cui, Gang Qu 0001 |
ISCAS | 1 |
| 2015 | A new decompressor with ordered parallel scan design for reduction of test data and test timeabstractScan design is regarded as the best design-for-testability (DfT) discipline. High test data volume and long test time are always two major concerns that our work here addresses. Here we combine a test data compression technique and broadcast-based decompressor architecture to relieve these problems. We propose a new decompressor architecture with bidirectional shift register as a source chain to broadcast compressed data into parallel scan chains. It enables one more broadcasting mode which leads to a higher broadcast ratio. We also propose a heuristic method to order the scan cells in each sub scan chain to improve the broadcast ratio so as to reduce the test data and test time. We apply our method on several benchmark circuits and the experimental results show that our method can reduce test data volume by 22.8% and shorten test application time by 19.5% on average with low area overhead in comparison to other state-of-the-art approaches. Aijiao Cui, André Ivanov |
ISCAS | 2 |
| 2015 | Design of Optimal Scan Tree Based on Compact Test Patterns for Test Time ReductionabstractScan tree architecture has been proposed to reduce the test application time of full scan chain by placing multiple scan cells in parallel. Most existing techniques rely on non-compact test pattern sets to construct the scan tree. However, they produce inefficient scan tree when highly compact test sets with few don't cares are used. In this paper, the depth of the scan tree based on approximate compatibility relation for completely specified test data set is analyzed probabilistically by modeling its construction as a vertex coloring problem. The upper bound of edges-per-vertex is computed and demonstrated to be a prime factor that limits the efficiency of scan tree construction based on both compatible and approximately compatible test data between two flip-flops. Inverse compatibility and aggressive approximate compatibility are then proposed to increase the edges-per-vertex for vertex coloring. The Q'-SD connection between two adjacent scan cells is exploited to implement the inverse compatibility with no cost or timing impact. To maintain the fault coverage, the missing faults under the tree scan mode can be detected by switching the same base architecture into the linear scan mode with negligible hardware overhead as shown by the experimental results on ISCAS89, ISCAS99 and LGSynth93 benchmark circuits. On average, the scan tree generated by our method reduces the test time of the full scan chain by 56.65 percent, and that of the scan tree designed by the approximate compatibility method by 39.18 percent under the same compact test sets. Linfeng Chen, Aijiao Cui, Chip-Hong Chang |
IEEE Trans. Computers | 2 |
| 2015 | Ultra-Low Overhead Dynamic Watermarking on Scan Design for Hard IP ProtectionabstractUnlike conventional legal means, digital watermark enables an effective self-protection mechanism for Very Large Scale Integration (VLSI) designers to protect their intellectual property (IP). However, existing watermarking techniques come with unpredictable and often high design and performance overhead, which makes them impractical. In this paper, we propose an ultra-low overhead watermarking scheme to protect hard IPs, the dominating form of commercial IPs. Our approach is based on the observation that an optimized scan design uses two complementary connections between two adjacent scan cells. Such scan design flexibility in the selection of local connection styles provides a vehicle to embed watermarking constraints. It can conveniently be implemented by local rewiring and/or introducing dummy scan cells. The test vectors will be changed accordingly to reflect the watermarked connection styles in order to guarantee the test coverage. This approach offers two unique features: 1) ultra-low overhead and 2) easy detectability. First, because the scan chain order is maintained and these changes are local, the proposed watermarking technique will introduce ultra-low overhead in terms of area, power, and speed. Next, watermark can be extracted from the test vectors and/or the corresponding scan output. Experimental results validate that the performance overhead is negligible (almost zero on the most cases) and the watermark is resilient to various possible attacks. Aijiao Cui, Gang Qu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | A low-overhead dynamic watermarking scheme on scan design for easy authenticationabstractThis paper proposes a new dynamic watermarking scheme during the Design-for-Testability (DfT) stage. The extra design constraints due to watermark are imposed on the connection styles between some scan cells. As the scan chain order is maintained, no routing overhead is caused. It thus overcomes the weakness of the watermarking schemes based on scan chain reordering, which usually incur unpredicted long routing or even congestion during physical design. Most of the performances are not compromised. Experimental results show that only negligible overhead on test power is caused while a strong authorship proof is achieved. Aijiao Cui, Gang Qu 0001 |
ISCAS | 1 |
| 2013 | An Efficient Zero-Aliasing Space Compactor Based on Elementary Gates Combined with XOR GatesabstractSpace compactor is usually applied in DfT design to compact the output response data in order to reduce testing time and storage. We propose an efficient method to implement a tree-like zero-aliasing space compactor with elementary logic gates combined with the XOR gates. Based on the fault-output response table, our method selects appropriate logic gates to combine the outputs of the CUT with remaining most D and D'. When faults are concealed in the table, all other available test patterns for these faults will be checked to determine whether the faults can be detected. No ATPG is involved in the search of new test patterns for the covered faults during compaction. To reduce the hardware overhead, the XOR gate is only used when all other elementary gates fail to achieve further compaction. When compared with existing ATPG-based compactors, our proposed compactor can achieve similar compaction ratio with similar hardware cost. However, our method will be much more efficient because it does not perform the time-consuming ATPG procedure. When compared with other XOR-based compactors, our method can achieve higher compaction ratio with smaller area overhead. Yongxia Liu, Aijiao Cui |
CAD/Graphics | 2 |
| 2013 | A power-efficient scan tree design by exploring the Q'-D connectionabstractFull scan design is usually time-consuming. Scan tree-based architectures can be applied to reduce test time, but few of them are power-efficient. Many low-power techniques have been proposed for scan chain design, while they are not applicable to scan tree architecture. To achieve a time-efficient and low-power scan design, in this paper, we propose a scheme to reduce the test power consumption of scan tree design by exploiting the Q' ports of scan flip-flops. As the structure of scan tree is not affected, the scheme resembles the time-efficiency of scan tree design. The modification for low power maintains the order of scan cells. It thus avoids the consequent design overhead due to scan reordering. Furthermore, no extra hardware is introduced. Experimental results on ISCAS'89 benchmarks show that 8.38% weighted transitions during test application can be reduced on average. Linfeng Chen, Aijiao Cui |
ISCAS | 2 |
| 2011 | A hybrid watermarking scheme for sequential functionsabstractMost watermarking schemes for intellectual property (IP) protection embed authorship information at a single design abstraction level. Effective means to directly verify the watermark distributed at the downstream designs are lacking, particularly after the IP core is packaged into chip. This paper proposes a hybrid scheme for watermarking sequential designs. At behavioral level, the finite state machine (FSM) is watermarked by interweaving the watermark bits into the outputs of its existing and unspecified transitions. During the Design-for-Testability (DfT) process, the scan chain that incorporates the watermarked FSM as one of the test kernels is further watermarked to provide a second level of protection. It enables the watermark on the FSM to be publicly detectable by the legitimate end users off chip via the scan test. Experimental results on ISCAS'89 and LGSynth'93 benchmark circuits show that the watermarked circuits have acceptably low overheads with stronger authorship proof. Aijiao Cui, Chip-Hong Chang |
ISCAS | 1 |
| 2011 | A Robust FSM Watermarking Scheme for IP Protection of Sequential Circuit DesignabstractFinite state machines (FSMs) are the backbone of sequential circuit design. In this paper, a new FSM watermarking scheme is proposed by making the authorship information a non-redundant property of the FSM. To overcome the vulnerability to state removal attack and minimize the design overhead, the watermark bits are seamlessly interwoven into the outputs of the existing and free transitions of state transition graph (STG). Unlike other transition-based STG watermarking, pseudo input variables have been reduced and made functionally indiscernible by the notion of reserved free literal. The assignment of reserved literals is exploited to minimize the overhead of watermarking and make the watermarked FSM fallible upon removal of any pseudo input variable. A direct and convenient detection scheme is also proposed to allow the watermark on the FSM to be publicly detectable. Experimental results on the watermarked circuits from the ISCAS'89 and IWLS'93 benchmark sets show lower or acceptably low overheads with higher tamper resilience and stronger authorship proof in comparison with related watermarking schemes for sequential functions. Aijiao Cui, Chip-Hong Chang, Sofiène Tahar, Amr Talaat Abdel-Hamid |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2009 | An Improved Publicly Detectable Watermarking Scheme based on Scan Chain OrderingabstractThis paper proposes an improved version of watermarking scheme at the Design-for-testability (DfT) stage for VLSI Intellectual Property (IP) protection. The improved scheme overcomes the weaknesses of previous scan chain watermarking scheme by imposing the extra ordering constraints generated by the IP owner's signature on all scan flip-flops impartially. IP authorship can be publicly authenticated in the field by injecting a given test vector and matching a permuted output response vector against a transformed reference pattern. Both the output response and the reference sequence are related to a pseudorandom sequence generated by a public-key cryptographic algorithm. Experimental results show that the improved method has a low probability of coincidence and low test power overhead. Aijiao Cui, Chip-Hong Chang |
ISCAS | 1 |
| 2008 | Intellectual property authentication by watermarking scan chain in design-for-testability flowabstractThis paper proposes an intellectual property (IP) protection scheme at the Design-for-Testability (DfT) stage of VLSI design flow. Additional constraints generated by the owner’s digital signature have been imposed on the NP-hard problem of ordering the scan cells to achieve a watermarked solution which minimizes the penalty on power and cost of testing. As only the order of the scan cells is varied, the number of test vectors for the desired fault coverage is not affected. The advantage of this scheme is the ownership legitimacy can be publicly authenticated on-site by IP buyers after the chip has been packaged by loading a specific verification code into the scan chain. We propose to integrate the scan chain watermarking with dynamic watermarking of the IP core to make the design hard-to-attack while the ownership is easy-to-trace. The proposed scheme is applied to an optimization instance of scan cell ordering targeting at test power reduction. The results on several MCNC benchmarks show that the watermarking scheme has a very low probability of solution coincidence and hence provides strong proof of authorship. Aijiao Cui, Chip-Hong Chang |
ISCAS | 1 |
| 2008 | IP Watermarking Using Incremental Technology Mapping at Logic Synthesis LevelabstractThis paper proposes an adaptive watermarking technique by modulating some closed cones in an originally optimized logic network (master design) for technology mapping. The headroom of each disjoint closed cone is evaluated based on its slack and slack sustainability. The notion of slack sustainability in conjunction with an embedding threshold enables closed cones in the critical path to be qualified as watermark hosts if their slacks can be better preserved upon remapping. The watermark is embedded by remapping only qualified disjoint closed cones randomly selected and templates constrained by the signature. This parametric formulation provides a means to capitalize on the headroom of a design to increase the signature length or strengthen the watermark resilience. With the master design, the watermarked design can be authenticated as in nonoblivious media watermarking. Experimental results show that the design can be efficiently marked by our method with low overhead. Aijiao Cui, Chip-Hong Chang, Sofiène Tahar |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2007 | Watermarking for IP Protection through Template Substitution at Logic Synthesis LevelabstractFunctionality preservation and area-time overhead are two major concerns of VLSI designers when the watermarking technique is used to protect their intellectual property. For a given technology library and a logically synthesized circuit, replacing cells with the templates of the same function will not alter the topology and original function of the circuit but the performances of some datapaths may be affected. If the resultant circuit can still satisfy the synthesis constraints with an acceptably low overhead, watermarking through template substitution at logic synthesis level is feasible. In this paper, we propose an algorithm to select appropriate cells for the replacement to realize the watermarking scheme. The method is tested on a set of combinational MCNC benchmarks. The results show that this watermarking process can provide a sufficiently strong proof of authorship with trivial area overhead. Aijiao Cui, Chip-Hong Chang |
ISCAS | 1 |
| 2006 | Stego-signature at logic synthesis level for digital design IP protectionabstractThis paper presents a logic re-synthesis method for embedding the IP designer information into a distributed copy of a master design that has been synthesized to meet the application constraints. Slack information of the master copy is used to identify seed cells and extract their kernels for watermark insertion at the logic synthesis level. The embedded watermark can be recovered by comparing the topological mismatches between the marked circuit and the master copy. We demonstrate the difficulty of embedding or removing the watermark. The method has been tested on several MCNC multi-level logic synthesis benchmarks. Experimental results show that the method possesses high embedding capacity with trivial quality overhead for the synthesized solution. Aijiao Cui, Chip-Hong Chang |
ISCAS | 1 |