Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Christian Boit

dblp:69/2567 · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
2since 2021 · last 2021
0000-0002-4169-6943ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-authorSystems, architecture and hardware · 6 · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Hardware security and side channels · 100%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Integrated circuit design · 55% Reconfigurable computing and FPGAs · 45%

Topics — the 8 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › integrated circuit security
FPGA security
0.522017
On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAs · CCS 2017
No Place to Hide: Contactless Probing of Secret Data on FPGAs · CHES 2016
Hardware security and side channels
side-channel attack
0.522017
Photonic Side-Channel Analysis of Arbiter PUFs · J. Cryptol. 2017
No Place to Hide: Contactless Probing of Secret Data on FPGAs · CHES 2016
Hardware security and side channels › hardware security primitives
physical unclonable function
0.522017
Photonic Side-Channel Analysis of Arbiter PUFs · J. Cryptol. 2017
Physical Characterization of Arbiter PUFs · CHES 2014
Hardware security and side channels › side-channel attack › physical side channel
optical side channel
0.312017
Photonic Side-Channel Analysis of Arbiter PUFs · J. Cryptol. 2017
Hardware security and side channels
physical attacks
0.312017
On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAs · CCS 2017
Hardware security and side channels › hardware security primitives › physical unclonable function
arbiter PUF
0.212014
Physical Characterization of Arbiter PUFs · CHES 2014
Reconfigurable computing and FPGAs › FPGA security
bitstream protection
0.112017
On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAs · CCS 2017
Integrated circuit design
digital circuit design
0.112014
Physical Characterization of Arbiter PUFs · CHES 2014

Methods — techniques the papers use, named apart from their topics

optical contactless probing · 0.6backside IC debug · 0.6physical characterization · 0.4photonic emission analysis · 0.3contactless probing · 0.2
YearPublicationVenuePosition
2021 Nano Security: From Nano-Electronics to Secure Systems
abstract
The field of computer hardware stands at the verge of a revolution driven by recent breakthroughs in emerging nanodevices. “Nano Security” is a new Priority Program recently approved by DFG, the German Research Council. This initial-stage project initiative at the crossroads of nano-electronics and hardware-oriented security includes 11 projects with a total of 23 Principal Investigators from 18 German institutions. It considers the interplay between security and nano-electronics, focusing on a dichotomy which emerging nano-devices (and their architectural implications) have on system security. The projects within the Priority Program consider both: potential security threats and vulnerabilities stemming from novel nano-electronics, and innovative approaches to establishing and improving system security based on nano-electronics. This paper provides an overview of the Priority Program's overall philosophy and discusses the scientific objectives of its individual projects.
Ilia Polian, Frank Altmann, Tolga Arul, Christian Boit, Ralf Brederlow, Lucas Davi, Rolf Drechsler, Nan Du 0004, Thomas Eisenbarth 0001, Tim Güneysu, Sascha Hermann, Matthias Hiller, Rainer Leupers, Farhad Merchant, Thomas Mussenbrock, Stefan Katzenbeisser 0001, Akash Kumar 0001, Wolfgang Kunz, Thomas Mikolajick, Vivek Pachauri, Jean-Pierre Seifert, Frank Sill, Jens Trommer
DATE4
2021 Special Session: Physical Attacks through the Chip Backside: Threats, Challenges, and Opportunities
abstract
This paper reviews the evolution of a powerful class of physical attacks against integrated circuits (ICs), developed initially for performing failure analysis (FA) from the IC backside. Over the last two decades, several publications have demonstrated the effectiveness of these techniques in bypassing the IC protection schemes and extracting the stored assets inside secure ICs. In this work, we take a fresh look at such hardware attacks from three different perspectives. First, we will discuss the potential threat of the attacks against modern technologies and demystify a set of wrong beliefs about the attacks' complexity. Second, we review some technical challenges of such attacks from a law enforcement agency's perspective for unraveling crimes and preventing further crimes by criminals involved. Finally, we give an insight into the future development of FA tools and the opportunities for designing effective countermeasures against attacks through the chip backside.
Elham Amini, Kai Bartels, Christian Boit, Marius Eggert, Norbert Herfurth, Tuba Kiyan, Thilo Krachenfels, Jean-Pierre Seifert, Shahin Tajik
VTS3
2017 On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAs
abstract
Modern Integrated Circuits (ICs) employ several classes of countermeasures to mitigate physical attacks. Recently, a powerful semi-invasive attack relying on optical contactless probing has been introduced, which can assist the attacker in circumventing the integrated countermeasures and probe the secret data on a chip. This attack can be mounted using IC debug tools from the backside of the chip. The first published attack based on this technique was conducted against a proof-of-concept hardware implementation on a Field Programmable Gate Array (FPGA). Therefore, the success of optical probing techniques against a real commercial device without any knowledge of the hardware implementation is still questionable. The aim of this work is to assess the threat of optical contactless probing in a real attack scenario. To this end, we conduct an optical probing attack against the bitstream encryption feature of a common FPGA. We demonstrate that the adversary is able to extract the plaintext data containing sensitive design information and intellectual property (IP). In contrast to previous optical attacks from the IC backside, our attack does not require any device preparation or silicon polishing, which makes it a non-invasive attack. Additionally, we debunk the myth that small technology sizes are unsusceptible to optical attacks, as we use an optical resolution of about 1 um to successfully attack a 28 nm device. Based on our time measurements, an attacker needs less than 10 working days to conduct the optical analysis and reverse-engineer the security-related parts of the hardware. Finally, we propose and discuss potential countermeasures, which could make the attack more challenging.
Shahin Tajik, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit
CCS4
2017 PUFMon: Security monitoring of FPGAs using physically unclonable functions
abstract
Mainstream FPGAs and programmable SoCs employ different countermeasures during configuration and runtime to mitigate physical attacks. However, it has been demonstrated that sophisticated active attack techniques, such as laser voltage probing, can still bypass the bitstream protections during the configuration phase. On the other hand, although the security monitoring IP cores provided by FPGA vendors can ensure the physical security during the runtime of applications, they are unable to detect such attacks during configuration. In this work, we propose a novel approach to using PUFs as physical sensors to monitor the integrity of FPGAs against active attacks. Small modifications in existing PUF architectures enable us to design a PUF-based security scheme, which can be deployed for integrity monitoring and authentication/key generation at the same time. We evaluate the effectiveness of our framework against a range of powerful attacks, such as optical probing and fault attacks. We further discuss how this scheme can be deployed during bitstream configuration in FPGAs with partial reconfiguration capability.
Shahin Tajik, Julian Fietkau 0002, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit
IOLTS5
2017 Photonic Side-Channel Analysis of Arbiter PUFs
Shahin Tajik, Enrico Dietz, Sven Frohmann, Helmar Dittrich, Dmitry Nedospasov, Clemens Helfmeier, Jean-Pierre Seifert, Christian Boit, Heinz-Wilhelm Hübers
J. Cryptol.8
2016 No Place to Hide: Contactless Probing of Secret Data on FPGAs
Heiko Lohrke, Shahin Tajik, Christian Boit, Jean-Pierre Seifert
CHES3
2015 Laser Fault Attack on Physically Unclonable Functions
abstract
Physically Unclonable Functions (PUFs) are introduced to remedy the shortcomings of traditional methods of secure key storage and random key generation on Integrated Circuits (ICs). Due to their effective and low-cost implementations, intrinsic PUFs are popular PUF instances employed to improve the security of different applications on reconfigurable hardware. In this work we introduce a novel laser fault injection attack on intrinsic PUFs by manipulating the configuration of logic cells in a programable logic device. We present two fault attack scenarios, where not only the effectiveness of modeling attacks can be dramatically increased, but also the entropy of the targeted PUF responses are drastically decreased. In both cases, we conduct detailed theoretical analyses by considering XOR arbiter PUFs and RO PUFs as the examples of PUF-based authenticators and PUF-based random key generators, respectively. Finally we present our experimental results based on conducting laser fault injection on real PUFs, implemented on a common complex programmable logic device manufactured in 180 nm technology.
Shahin Tajik, Heiko Lohrke, Fatemeh Ganji, Jean-Pierre Seifert, Christian Boit
FDTC5
2014 Physical Characterization of Arbiter PUFs
Shahin Tajik, Enrico Dietz, Sven Frohmann, Jean-Pierre Seifert, Dmitry Nedospasov, Clemens Helfmeier, Christian Boit, Helmar Dittrich
CHES7
2014 Physical vulnerabilities of Physically Unclonable Functions
abstract
In recent years one of the most popular areas of research in hardware security has been Physically Unclonable Functions (PUF). PUFs provide primitives for implementing tamper detection, encryption and device fingerprinting. One particularly common application is replacing Non-volatile Memory (NVM) as key storage in embedded devices like smart cards and secure microcontrollers. Though a wide array of PUF have been demonstrated in the academic literature, vendors have only begun to roll out PUFs in their end-user products. Moreover, the improvement to overall system security provided by PUFs is still the subject of much debate. This work reviews the state of the art of PUFs in general, and as a replacement for key storage in particular. We review also techniques and methodologies which make the physical response characterization and physical/digital cloning of PUFs possible.
Clemens Helfmeier, Christian Boit, Dmitry Nedospasov, Shahin Tajik, Jean-Pierre Seifert
DATE2
2014 Emission Analysis of Hardware Implementations
abstract
Today, hardware implementations are the basis for many security applications, such as cryptographic ciphers. Such applications are realized using complex combinatorial logic circuits of substantial size. Therefore, understanding the gate-level implementation can be crucial for the attacker. However, Hardware Description Language (HDL) behavioral models and gate-level net list are seldom available for a particular design. Executing software directly on the device to assist in understanding the implementation is one potential solution. However, this may either be infeasible or completely impossible in practice as target devices may be incapable of executing code. Currently, few works have proposed forms of dynamic gate-level analysis of the actual hardware implementations. Moreover, current reverse-engineering techniques based on physical delayering and optical imaging cannot be applied to programmable logic. In this work we present the first dynamic emission analysis of a hardware implementation. This technique does not require any prior knowledge about the target device. Furthermore, it does not require code to be executed by the target. Hardware implementations consist of basic primitives that form the building blocks of complex hardware functions. By individually analyzing each primitive and correlating the corresponding optical images, the emission fingerprint of each primitive can be identified. As a result the hardware implementation of the device can be reconstructed. We present practical results for a common Complex Programmable Logic Device (CPLD). However, the same approach can be applied to hardware implementations in general.
Shahin Tajik, Dmitry Nedospasov, Clemens Helfmeier, Jean-Pierre Seifert, Christian Boit
DSD5
2013 Breaking and entering through the silicon
abstract
As the surplus market of failure analysis equipment continues to grow, the cost of performing invasive IC analysis continues to diminish. Hardware vendors in high-security applications utilize security by obscurity to implement layers of protection on their devices. High-security applications must assume that the attacker is skillful, well-equipped and well-funded. Modern security ICs are designed to make readout of decrypted data and changes to security configuration of the device impossible. Countermeasures such as meshes and attack sensors thwart many state of the art attacks. Because of the perceived difficulty and lack of publicly known attacks, the IC backside has largely been ignored by the security community. However, the backside is currently the weakest link in modern ICs because no devices currently on the market are protected against fully-invasive attacks through the IC backside. Fully-invasive backside attacks circumvent all known countermeasures utilized by modern implementations. In this work, we demonstrate the first two practical fully-invasive attacks against the IC backside. Our first attack is fully-invasive backside microprobing. Using this attack we were able to capture decrypted data directly from the data bus of the target IC's CPU core. We also present a fully invasive backside circuit edit. With this attack we were able to set security and configuration fuses of the device to arbitrary values.
Clemens Helfmeier, Dmitry Nedospasov, Christopher Tarnovsky, Starbug, Christian Boit, Jean-Pierre Seifert
CCS5
2013 Security Risks Posed by Modern IC Debug and Diagnosis Tools
abstract
Silicon debug and diagnosis (SDD) has successfully combined recent developments of IC Failure Analysis (FA) techniques in order to have local physical interaction with the circuit function down to nano scale. These techniques, mainly optical interactions applied through chip backside, are assisted by a revolutionary Focused Ion Beam (FIB) backside preparation technique that keeps the chip fully functional while leaving sub micron thickness of Si substrate on an area large enough to call it semi-global. With such a treatment, any physical interaction, even electrical probing to any node, is possible through chip backside. On top of that, the performance of the devices can be modulated in situ with this FIB process. All these FA and SDD innovations open up a new world of hardware attack processes, accessible in FA labs world wide on an hourly basis, that security sensitive ICs need to be protected against.
Christian Boit, Clemens Helfmeier, Uwe Kerst
FDTC1
2013 Invasive PUF Analysis
abstract
In this work we consider the suitability of Phyiscaly Unclonable Functions (PUFs) for high-security applications. For PUFs to be considered secure in such scenarios they must be resilient to both semi-invasive and fully-invasive attacks. We introduce a new failure analysis technique for semi-invasive, single-trace, backside readout of logic states. We apply this technique to characterize the unique physical response of a memory-based PUF. With these results we identify several weakness in current PUF schemes. We extend current PUF definitions to be resilient against such attacks by requiring that PUFs be implemented in a serialized manner. Finally, we improve already existing PUF architectures to include these concepts.
Dmitry Nedospasov, Jean-Pierre Seifert, Clemens Helfmeier, Christian Boit
FDTC4
2007 Backside E-Beam Probing on Nano scale devices
abstract
IC debug with E-beam probing is presented in an innovative application accessing the active device directly from chip backside after FIB preparation. The potential of this approach in nanoscale and gigahertz dimensions is evaluated.
Rudolf Schlangen, Reiner Leihkauf, Uwe Kerst, Christian Boit, Rajesh Jain, Tahir Malik, Keneth R. Wilsher, Ted R. Lundquist, Bernd Krüger
ITC4