EDBT 2026 Demo / reviewers in the wild / expert
Giorgio Di Natale
dblp:71/5847
· DBLP profile ↗
132ranked-venue papers
11as first author
43since 2021 · last 2026
0000-0001-8063-5388ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 129 · 11 first-author · 42 since 2021Software engineering, systems software and programming languages · 42 · 3 first-author · 15 since 2021Security and privacy · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Focus Session: Advanced CMOS and 5.5D Packaging: Perspectives and Challenges for Design, Reliability and SecurityabstractAI workloads are driving exceptional demand for performance and energy efficiency, forcing semiconductor innovation to advance along two major directions simultaneously. On the device roadmap, the transition from FinFETs to gate-all-around nanosheet FETs and, subsequently, monolithic 3D Complementary FETs (CFETs) is enabling scaling toward the 2 nm era and beyond while targeting aggressive logic density. In parallel, advanced packaging, spanning 2.5D integration on silicon interposers, true 3D stacking, and hybrid 5.5D assemblies, is becoming essential to deliver ultra-high bandwidth, low-energy die-to-die connectivity required by rapidly growing AI model sizes and the resulting memory-wall bottlenecks. This focus session discusses the opportunities and challenges of this co-evolution, with emphasis on system-technology co-optimization and the inevitable need for multiphysics analysis across electrical, thermal, mechanical, and reliability domains. We highlight how reliability and security concerns are increasingly shaping architectural and packaging choices, and we discuss the role of deep learning as a practical enabler for faster simulation and design-space exploration under rising complexity. Hussam Amrouch, Dragomir Milojevic, Giorgio Di Natale, Jérôme Toublanc |
DATE | 3 |
| 2026 | Future Result Capture: Timing Anomalies Reveal Data from Instructions in the SuccessorabstractFault injection remains a critical threat to modern embedded processors, enabling adversaries to violate the expected execution of programs. In this paper, we introduce a new fault model, named Future Result Capture (FRC), observed on a commercial processor implementing the RISC-V instruction set architecture. Unlike classical models, FRC occurs when an instruction captures the result of a subsequent instruction, effectively creating a temporal inversion in the pipeline. Through extensive clock and voltage glitch experiments on a SiFive RISC-V core, we show that this phenomenon can be consistently triggered, producing instruction-level causality violations not explained by existing models. This new fault behavior exposes unexplored vulnerabilities in commercial processors, demonstrating that subtle microarchitectural effects can be exploited by physical attacks. Our findings highlight the necessity to revisit current fault models by taking into account a thorough understanding of the microarchitectural features of microprocessors, in order to design efficient countermeasures specifically addressing such vulnerabilities. Roua Boulifa, Marwa Chehab, Paolo Maistri, Giorgio Di Natale |
DATE | 4 |
| 2026 | A Framework for Chiplet Authentication During Post-Stacking TestabstractThe semiconductor industry is adopting chiplets as an alternative to integrated circuit design. With adoption of off-the-shelf chiplets, supply chain attacks are likely to increase, making chiplet authentication essential. This work identifies post-stacking testing as the best phase for authentication and proposes a framework using existing industry standards. The framework includes a flexible authentication IP integrated into the chiplet design, compatible with various authentication methods; an IP insertion flow compatible with commercial DFT insertion tools; a secure module for the test environment; and the corresponding test procedure. Results show that chiplet authentication can be implemented without disrupting industry practices, with multiple authentication methods available based on the context. Juan Suzano, Anthony Philippe, Fady Abouzeid, Philippe Roche, Giorgio Di Natale |
DDECS | 5 |
| 2026 | Hardware Trojans Horses: Two Decades Later, What We Really KnowabstractInternational audience Giorgio Di Natale, Emanuele Valea |
ETS | 1 |
| 2026 | On the Evaluation of FPGA-Based Physical Unclonable Functions
Daniele Lombardi, Mario Barbareschi, Valentina Casola, Elena I. Vatajelu, Giorgio Di Natale |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2026 | Thermal Attack on RO-PUFs: The Cases of Bulk 65 nm and FDSOI 28 nmabstractPhysical Unclonable Functions (PUFs) play a crucial role in enhancing the security of electronic devices by leveraging inherent manufacturing variations to generate unique and unclonable identifiers. This study explores the vulnerability of Ring Oscillator-based PUFs (RO-PUFs) to thermal attacks, focusing on two semiconductor technologies: Bulk 65 nm and Fully Depleted Silicon on Insulator (FDSOI) in 28 nm. Through detailed simulations, the effects of uniform and localized thermal variations on the stability of ring oscillator frequencies are analyzed. The results reveal that while the Bulk 65 nm technology shows resistance to uniform thermal attacks, it is highly sensitive to localized attacks. In contrast, the FDSOI 28 nm technology is vulnerable to both types of attacks due to its low variability. These observations underscore the need for robust countermeasures in the design of PUFs to ensure their reliability under varying thermal conditions. Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale |
ACM Trans. Design Autom. Electr. Syst. | 6 |
| 2026 | A Revision of the Quality Metrics of Physical Unclonable FunctionsabstractPhysical unclonable functions (PUFs) leverage process variability to generate unique signatures in electronic devices. They are a strong alternative to conventional security mechanisms as they do not rely on non-volatile memories (NVMs) to store the secrets. However, PUFs can be influenced by external factors and may exhibit biased output distributions, leading to vulnerabilities that could compromise their uniqueness and resistance to cloning. The quality of a PUF is evaluated through a common set of metrics such as uniformity, bit-aliasing, uniqueness, and reliability. However, the lack of standardized methodologies hinders effective comparisons between diverse PUF designs, limiting the broader understanding of their performance. Besides, the underlying physics and mechanisms of PUFs makes them difficult to study and mitigate potential vulnerabilities and attacks. Overall, the quality metrics for PUFs are still evolving, and there is ongoing research to address these challenges and develop more robust and reliable PUFs. In this article, we demonstrate the limitations of current PUF evaluation metrics using experimental data and introduce a novel set of metrics that provide a more rigorous and comprehensive assessment. Sergio Vinagrero Gutierrez, Elena I. Vatajelu, Giorgio Di Natale |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2025 | Improving RO-PUFs on FPGAs: A Filtering Approach for Improved Reliability and EntropyabstractPhysical Unclonable Functions (PUFs) have emerged in recent years as a reliable alternative to non-volatile memory for cryptographic applications. Their main advantage lies in the fact that they do not store data within the chip but generate unique responses on demand. However, some responses may be unreliable over time due to small variations in temperature or voltage, whether under normal operating conditions or during attacks, such as thermal attacks. This paper presents a novel filtering technique that has been applied to a ring oscillator PUF (RO-PUF) implemented on an FPGA, designed to address the issue of unreliable and biased responses. Vasilii Kulagin, Giorgio Di Natale, Elena I. Vatajelu |
ATS | 2 |
| 2025 | Late Breaking Results: Automatic Anomaly Detection Method in Physical Unclonable Functions using Data Mining TechniquesabstractPhysical Unclonable Functions (PUFs) present a promising alternative to traditional cryptographic techniques for securing sensitive information in modern circuits. By exploiting inherent process variability, PUFs generate unique secrets dynamically, thus eliminating the need for data storage. However, a major challenge in PUF-based security is distinguishing valid PUFs from those that may have been tampered with or are invalid (i.e., not belonging to the original design). This paper proposes a data mining-based approach for detecting anomalies and identifying tampered or invalid PUFs. The proposed method mines a set of rules that describe the expected behavior of the PUF, with deviations from these rules signaling potential security issues and vulnerabilities. Experimental results demonstrate that the method effectively identifies invalid or tampered PUFs, showcasing its potential for enhancing PUF-based security systems. Mohammad Reza Heidari Iman, Sergio Vinagrero Gutierrez, Elena I. Vatajelu, Giorgio Di Natale |
DATE | 4 |
| 2025 | Improving Software Reliability with Rust: Implementation for Enhanced Control Flow Checking MethodsabstractThe C language, traditionally used in developing safety-critical systems, often faces memory management issues, leading to potential vulnerabilities. Rust emerges as a safer and secure alternative, aiming to mitigate these risks with its robust memory protection features, making it suitable for producing reliable code in critical environments, such as the automotive industry. This study proposes employing Rust code hardened by Control Flow Checking (CFC) in real-time embedded systems, which software is traditionally developed by Assembly and C languages. The methods have been implemented at the application level, i.e., in the Rust source code, to make them platform-agnostic. A methodology for leveraging the Rust advantages is presented, such as stronger security guarantees and modern features, to implement these methods more effectively. Highlighting a use case in the automotive sector, our research demonstrates the Rust capacity to enhance system reliability through CFC, especially against Random Hardware Faults. Two CFC algorithms from the literature, YACCA, and RACFED, have been implemented in the Rust language to assess their effectiveness, obtaining 46.5% Diagnostic Coverage for the YACCA method and 50.1% for RACFED. The proposed approach is aligned with functional safety standards, showcasing how Rust can balance safety requirements and cost considerations in industries reliant on software solutions for critical functionalities. Jacopo Sini, Mohammadreza Amel Solouki, Massimo Violante, Giorgio Di Natale |
DATE | 4 |
| 2025 | An Innovative Data Mining Technique for Automatic Anomaly Detection in Physical Unclonable FunctionsabstractPhysical Unclonable Functions (PUFs) offer a promising alternative to conventional cryptographic techniques to secure sensitive information in modern circuits. PUFs leverage inherent process variability to dynamically generate unique secrets, eliminating the need for data storage. However, a significant challenge in PUF-based security is differentiating between valid PUFs and those that may have been tampered with or are invalid (i.e., not belonging to the original design). This paper presents an innovative data mining-based technique for detecting anomalies and identifying tampered or invalid PUFs. The proposed method extracts a set of rules that describe the expected behavior of the PUF, where deviations from these rules indicate potential security issues and vulnerabilities. Experimental results demonstrate that the method effectively detects invalid or tampered PUFs, highlighting its potential to strengthen PUF-based security systems. Mohammad Reza Heidari Iman, Sergio Vinagrero Gutierrez, Elena I. Vatajelu, Giorgio Di Natale |
DDECS | 4 |
| 2025 | A Survey on Automatic Assertion MinersabstractIn the area of functional verification, AssertionBased Verification (ABV) has gained significant attention for the advantages it provides in verifying hardware designs. This approach relies on assertions generated by automatic assertion miners. These miners employ various techniques and methods to automatically mine assertions. This paper focuses on studying the most recent, advanced, and widely used assertion miners in the field and provides an analytical comparison between them. This study aims to highlight the strengths and shortcomings of current automatic assertion miners to assist researchers and verification engineers in understanding the functionality, strengths, and limitations of each miner. By addressing these limitations, more advanced automatic assertion miners can be developed in the future. Mohammad Reza Heidari Iman, Giorgio Di Natale, Katell Morin-Allory |
DDECS | 2 |
| 2025 | Pulsed ElectroMagnetic Fault Injection Attack on a Time Measurement-based Arbiter-PUFabstractPhysically Unclonable Functions (PUFs) have emerged as a promising hardware-based solution that leverages inherent process variations during IC manufacturing for secure key generation and device authentication, by generating unique and irreproducible challenge-response pairs (CRPs). Among various PUF designs, arbiter PUFs are particularly attractive due to their simplicity, scalability, and compatibility with lightweight cryptographic systems. However, their resistance to fault injection attacks remains an underexplored area. In this work, we investigate the impact of pulsed ElectroMagnetic (EM) fault injection (FI) on a novel Time Measurement-based Arbiter-PUF (TMAPUF) implemented on an FPGA. Experimental results reveal that a single precisely tuned EM pulse can consistently alter the PUF’s output, exposing a critical security weakness. This finding highlight the need for improved fault resilience in PUF architectures and suggest that the studied PUF variant could serve as a foundation for developing inherent countermeasures against EMFI and similar fault-based attacks. Azzadine Thajte, Sami El Amraoui, Paolo Maistri, Régis Leveugle, Giorgio Di Natale, Laurent Fesquet |
DSD | 5 |
| 2025 | Early Result Capture: Racing Conditions in Pipeline due to Clock Glitches
Roua Boulifa, Paolo Maistri, Giorgio Di Natale |
ETS | 3 |
| 2025 | Reliability Under Stress: The Impact of Localized Aging on RO-PUF Architectures in FPGAs
Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale |
ETS | 6 |
| 2025 | Physical Unclonable Functions (PUFs): Foundations, Evaluation, and Testing for Secure Hardware Systems
Sergio Vinagrero Gutierrez, Giorgio Di Natale, Elena I. Vatajelu |
ETS | 2 |
| 2025 | European Test Symposium Teams: an Anniversary SnapshotabstractThe IEEE European Test Symposium (ETS) has been facilitating progress in electronic systems testing since its launch in 1996. On the occasion of its 30th anniversary, this collaborative paper gathers sections by 21 ETS teams to outline their influential ideas and milestones. Each team’s section highlights historical perspective, current research, frameworks and projects as well as forward-looking research agendas in the area of electronic-based circuits and systems testing, reliability, safety, security and validation. This anniversary summary documents how research of various ETS teams, exemplifying the test community, has been evolving and transitioning from concepts to practical standards and Electronic Design Automation (EDA) tools and flows. This legacy is a strong base to drive the next generation of advances in electronic systems testing. Maksim Jenihhin, Jaan Raik, Artur Jutman, Natalia Cherezova, Raimund Ubar, Liviu Miclea, Szilárd Enyedi, Iulia Stefan, Ovidiu Stan, Cosmina Corches, Zebo Peng, Petru Eles, Rolf Drechsler, S. Eggersglüß, Görschwin Fey, Andreas Glowatz, Daniel Tille, Georges Gielen, Anthony Coyette, Wim Dobbelaere, Ronny Vanhooren, Po-Yao Chuang, Erik Jan Marinissen, Giorgio Di Natale, M. Barragan, Paolo Maistri, S. Mir, Vatajelu I. Vatajelu, Paolo Bernardi 0002, Stefano Di Carlo, Paolo Prinetto, Matteo Sonza Reorda, Massimo Violante, Haralampos-G. D. Stratigopoulos, M. K. Michael, Stelios Neophytou, Stavros Hadjitheophanous, Kyriakos Christou, M. Skitsas, Alberto Bosio, Bastien Deveautour, Patrick Girard 0001, Marcello Traiola, Arnaud Virazel, Fernando Santos 0001, Angeliki Kritikakou, Gioele Casagranda, Marzio Vallero, Flavio Vella, Paolo Rech, Letícia Maria Veiras Bolzani, Milos Krstic, Marko S. Andjelkovic, Fabian Vargas 0001, Grigor Tshagharyan, Gurgen Harutunyan, Valery A. Vardanian, Samvel K. Shoukourian, Yervant Zorian, Jennifer Dworak, Kundan Nepal, Theodore W. Manikas, Mottaqiallah Taouil, Moritz Fieback, Anteneh Gebregiorgis, Rajendra Bishnoi, Said Hamdioui, Abhijit Chatterjee, Anurup Saha, Suhasini Komarraju, K. Ma, Chandramouli N. Amarnath, Mehdi Baradaran Tahoori, Mahta Mayahinia, Maryam Rajabalipanah, Katayoon Basharkhah, N. Nosrati, Zahra Jahanpeima, Zainalabedin Navabi, Hans-Joachim Wunderlich, Sybille Hellebrand |
ETS | 24 |
| 2025 | Optimizing RO-PUFs: A Filtering Approach to Reliability and Entropy Trade-offsabstractInternational audience Vasilii Kulagin, Giorgio Di Natale, Elena I. Vatajelu |
ETS | 2 |
| 2025 | Real-Time Fault Analysis in RISC-V Processors: A Case Study Using the Internal State MonitorabstractEmbedded systems are widely used in critical applications, making them attractive targets for fault injection attacks. Understanding how these attacks affect microprocessors at the microarchitectural level is essential for assessing their impact and developing effective defenses. In this paper, we present a case study using the Internal State Monitor (ISM) to finely observe and analyze fault injection effects in real time. By capturing faulty microarchitectural signals during an attack, the ISM provides valuable insights into fault propagation and system behavior under adversarial conditions. This real-time observability allows for a more precise characterization of fault effects, aiding in the design of robust countermeasures to enhance processor security. Roua Boulifa, Yongxin Sun, Giorgio Di Natale, Paolo Maistri |
IOLTS | 3 |
| 2025 | A Fuzzy Logic-Based System for Detecting Trustable Physical Unclonable FunctionsabstractPhysical Unclonable Functions (PUFs) provide a promising security mechanism by leveraging inherent process variations to generate unique, hardware-bound secrets without requiring secure storage. However, ensuring PUF reliability and detecting potential tampering remain critical challenges. This paper presents a fuzzy logic-based classification system that determines the authenticity of PUF responses using three key metrics: Reliability, Stability, and Reliability Invariance. The system classifies PUF responses into three categories: Trustable, Tampered, and Undecided. This approach enhances the automatic detection of unreliable responses that may indicate tampering while ensuring the fidelity of PUF responses over time. By applying fuzzy inference rules, our method achieves high accuracy in distinguishing between trustworthy and compromised PUFs. Experimental results demonstrate the effectiveness of our approach, making it a valuable method and tool for hardware security applications. Mohammad Reza Heidari Iman, Sergio Vinagrero Gutierrez, Elena I. Vatajelu, Giorgio Di Natale |
IOLTS | 4 |
| 2025 | TIMA-PUF: Time Measurement Based Arbiter PUFabstractDesigning a reliable and lightweight Physical Unclonable Function (PUF) is of prior importance in the context of hardware security. In this paper, a new variant of an arbiter PUF is proposed. Unlike the classical arbiter PUF that only compares the delay of two symmetrical paths, we propose to measure the path propagation delays and returns the time difference. Such measurements enable the arbiter PUF to be used in conjunction with techniques such as filtering of unreliable or low-entropy challenges and, thus, improve the global PUF performances. This ability is obtained thanks to an asynchronous Time-To-Digital Converter (TDC), which allows the measurements of the path delays. The proposed PUF benefits from the strengths of a classical arbiter PUF, such as the ability to extract a large number of challenge-response pairs at high throughput while improving reliability and entropy. This new arbiter PUF has been implemented on an FPGA and the results show it can achieve almost ideal values for metrics such as uniqueness, reliability and uniformity, simply by filtering the most unreliable responses. Azzadine Thajte, Laurent Fesquet, Giorgio Di Natale |
IOLTS | 3 |
| 2024 | Security Layers and Related Services within the Horizon Europe NEUROPULS ProjectabstractIn the contemporary security landscape, the incorporation of photonics has emerged as a transformative force, unlocking a spectrum of possibilities to enhance the resilience and effectiveness of security primitives. This integration represents more than a mere technological augmentation; it signifies a paradigm shift towards innovative approaches capable of delivering security primitives with key properties for low-power systems. This not only augments the robustness of security frameworks, but also paves the way for novel strategies that adapt to the evolving challenges of the digital age. This paper discusses the security layers and related services that will be developed, modeled, and evaluated within the Horizon Europe NEUROPULS project. These layers will exploit novel implementations for security primitives based on physical un-clonable functions (PUFs) using integrated photonics technology. Their objective is to provide a series of services to support the secure operation of a neuromorphic photonic accelerator for edge comnuting applications. Fabio Pavanello, Cédric Marchand 0002, Paul Jiménez, Xavier Letartre, Ricardo Chaves, Niccolò Marastoni, Alberto Lovato, Mariano Ceccato, George Papadimitriou 0001, Vasileios Karakostas, Dimitris Gizopoulos, Roberta Bardini, Tzamn Melendez Carmona, Stefano Di Carlo, Alessandro Savino 0001, Laurence Lerch, Ulrich Rührmair, Sergio Vinagrero Gutierrez, Giorgio Di Natale, Elena I. Vatajelu |
DATE | 19 |
| 2024 | Modeling Thermal Effects For Biasing PUFsabstractSecurity primitives such as Physical Unclonable Functions (PUFs) or True Random Number Generators (TRNGs), have emerged as hardware roots of trust for ensuring the security of modern applications. However, these primitives display susceptibility to physical attacks, among them, in the face of temperature variations. Previous research has established the feasibility of attacks exploiting temperature fluctuations to compromise the security of these primitives. Specifically, when implemented on FPGAs, programmable components can be vulnerable to alterations induced by thermal changes. These findings underscore the need to deepen the understanding of the implications of temperature sensitivity on the security and robustness of these security mechanisms. This paper studies how heat affects, both instantaneously and permanently, the working of ring oscillators, which are the building blocks of PUFs based on Ring Oscillators. The study also suggests how to exploit these effects to bias the PUf responses, enabling thus the possibility of its cloning. Aghiles Douadi, Elena I. Vatajelu, Paolo Maistri, David Hély, Vincent Beroulle, Giorgio Di Natale |
ETS | 6 |
| 2024 | IEEE 1838 compliant scan encryption and integrity for 2.5/3D ICsabstract2.5D and 3D integrated circuits (IC) are the natural evolution of traditional 2D SoCs. 2.5D and 3D integration is the process of assembling pre-manufactured chiplets in an interposer or in a stack. This process can damage the chiplets or lead to faulty connections. Thus, the importance of post-bond test of chiplets. The IEEE Std 1838(TM)-2019 (IEEE 1838) design-for-testability (DFT) standard defines mandatory and optional structures for accessing DFT functions on the chiplet. Compliant chiplets form a DFT network that can be exploited by attackers to violate the confidentiality or integrity of the message transmitted over the serial path. In this work, we combine a message integrity verification system with a scan encryption mechanism to protect the scan chain of an IEEE 1838-compliant DFT implementation. The scan encryption prevents unauthorized actors from writing meaningful data into the scan chain. Message integrity verification makes messages from untrustworthy sources detectable. In conjunction, both security primitives protect the scan chain from malicious chiplets on the stack, scan-based attacks, and brute force attacks. The proposed solution causes less than 1% area overhead on designs composed of more than 5 million gates and less than 1% test time overhead for typical DFT implementations. Juan Suzano, Antoine Chastand, Emanuele Valea, Giorgio Di Natale, Anthony Philippe, Fady Abouzeid, Philippe Roche |
ETS | 4 |
| 2023 | Open Automation Framework for Complex Parametric Electrical SimulationsabstractThe need to achieve statistically relevant results in electrical simulations requires a large number of iterations under different operating conditions. Moreover, the nature of parametric simulations makes the collection and filtering of the results non-trivial. To tackle these issues, scripts are normally used to control all the parameters. Still, this approach is usually ad-hoc and platform dependent, making the whole procedure hardly reusable, scalable and versatile. We propose a generic, open-source framework to generate complex stimuli and parameters for electrical simulations, together with a programmable Spice- and Verilog-A-based module capable of observing and logging internal states of the circuit to facilitate further result analysis. Sergio Vinagrero Gutierrez, Pietro Inglese, Giorgio Di Natale, Elena I. Vatajelu |
DDECS | 3 |
| 2023 | EUROPULS: NEUROmorphic energy-efficient secure accelerators based on Phase change materials aUgmented siLicon photonicSabstractThis special session paper introduces the Horizon Europe NEUROPULS project, which targets the development of secure and energy-efficient RISC-V interfaced neuromorphic accelerators using augmented silicon photonics technology. Our approach aims to develop an augmented silicon photonics platform, an FPGA-powered RISC-V-connected computing platform, and a complete simulation platform to demonstrate the neuromorphic accelerator capabilities. In particular, their main advantages and limitations will be addressed concerning the underpinning technology for each platform. Then, we will discuss three targeted use cases for edge-computing applications: Global National Satellite System (GNSS) anti-jamming, autonomous driving, and anomaly detection in edge devices. Finally, we will address the reliability and security aspects of the stand-alone accelerator implementation and the project use cases. Fabio Pavanello, Cédric Marchand 0002, Ian O'Connor, Régis Orobtchouk, Fabien Mandorlo, Xavier Letartre, Sébastien Cueff, Elena I. Vatajelu, Giorgio Di Natale, Benoit Cluzel, Aurelien Coillet, Benoît Charbonnier, Pierre Noe, Frantisek Kavan, Martin Zoldak, Michal Szaj, Peter Bienstman, Thomas Van Vaerenbergh, Ulrich Rührmair, Paulo F. Flores, Luís Guerra e Silva, Ricardo Chaves, Luís Miguel Silveira, Mariano Ceccato, Dimitris Gizopoulos, George Papadimitriou 0001, Vasileios Karakostas, Axel Brando, Francisco J. Cazorla, Ramon Canal, Pau Closas, Adria Gusi-Amigo, Paolo Crovetti, Alessio Carpegna, Tzamn Melendez Carmona, Stefano Di Carlo, Alessandro Savino 0001 |
ETS | 9 |
| 2023 | A Study of High Temperature Effects on Ring Oscillator Based Physical Unclonable FunctionsabstractPUFs (Physical Unclonable Functions) have been proposed as a cost-effective solution to provide a root of trust for electronic devices which exploit intrinsic process variability. They generate identification signatures and keys only when the devices are turned on, avoiding the storage of sensitive information in memories that could be targeted by attacks. Although PUFs have many perceived advantages, they also have disadvantages such as sensitivity to temperature. Indeed their behaviour can be affected by the fact that high temperatures can accelerate permanent and transient phenomena, such as aging and transistor switching speed. In this paper we show the effects of externally induced heat on the functioning of Ring Oscillators (ROs), which form the basis of RO-PUFs. Moreover, we discuss the feasibility of temperature attacks on PUFs. Aghiles Douadi, Giorgio Di Natale, Paolo Maistri, Elena I. Vatajelu, Vincent Beroulle |
IOLTS | 2 |
| 2023 | Experimental Evaluation of Delayed-Based Detectors Against Power-off AttackabstractEmbedded systems are vulnerable to significant security threats from Fault Injection Attacks (FIAs), which allow attackers to gain access to confidential information. While various attack detectors have been proposed in the literature to detect different types of FIAs, these detectors themselves are susceptible to such attacks and can be compromised. Hence, the robustness of these detectors is critical in maintaining the security of embedded systems. The focus of this study is to evaluate the robustness of digital circuits and delay-based digital detectors against a new type of FIA called Power-Off Attack (POA). POA occurs when the power to the chip is turned off, and the detectors are not active. Following a POA attack, the circuit or its detectors may not function properly when the power is turned back on, which can allow other attacks to be applied without being detected if the detectors are less sensitive. This study implements two detectors on Xilinx Artix-7 FPGAs and examines the impact of heating cycles on detector characteristics when the FPGA is in various states, including power-off, power-on, and inactive states (such as clock-freezing mode). Our experiments reveal that heating cycles in power-off mode can alter the FPGA component delays and the accuracy of its detectors, which highlights the vulnerability of these systems to POA and potential issues for embedded system security. Maryam Esmaeilian, Aghiles Douadi, Zahra Kazemi, Vincent Beroulle, Amir-Pasha Mirbaha, Mahdi Fazeli, Elena I. Vatajelu, Paolo Maistri, Giorgio Di Natale |
IOLTS | 9 |
| 2023 | On-Line Method to Limit Unreliability and Bit-Aliasing in RO-PUFabstractPhysical Unclonable Functions (PUFs) allow generating an intrinsic signature in electronic device thanks to process variability. One of the most researched solutions for PUF implementation is the Ring Oscillator PUF (RO-PUF). This solution is based on the comparison of the frequency of 2 identically designed ROs in an IC. Ideally these 2 ROs would have the same frequency, however this in not the case in reality due to fabrication-induced process variability. By measuring and comparing their actual frequency, a 1-bit PUF response is generated. The RO-PUF has been demonstrated to satisfy the principal randomness requirements (uniformity and uniqueness) but it suffers from problems such as bitaliasing and unrepeatability (i.e. low reliability). In this paper we perform a thorough analysis of RO-PUF bitaliasing and reliability and propose a methodology for its analytical estimation based on the variability profile of the underling technology. Sergio Vinagrero Gutierrez, Giorgio Di Natale, Elena I. Vatajelu |
IOLTS | 2 |
| 2023 | Introduction to the Special Issue on CAD for Security: Pre-silicon Security Sign-off Solutions Through Design CycleabstractThis introduction welcomes all readers to this ACM JETC special issue on CAD for Security: Pre-silicon Security Sign-off Solutions Through Design Cycle. The articles published in this special issue reflect how computer-aided design (CAD) tools are developed to expand the notion of automated security verification throughout the system-on-chip (SoC) design cycle. This special issue aims to demonstrate how the semiconductor industry must look for security-oriented metrics and evaluation as part of automatic CAD solution development to aid analysis, identifying, root-causing, and mitigating SoC security problems. Throughout this introductory note, we first represent the need for such a security-oriented sign-off solution for the ASIC design flow, then it is followed by providing an overview of the articles published in this special issue and how they address such requirements. Farimah Farahmandi, Ankur Srivastava 0001, Giorgio Di Natale, Mark Tehranipoor |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2022 | Elaborating on Sub-Space Modeling as an Enrollment Solution for Strong PUFabstractIn this work we present sub-space modeling of strong PUF as a cost efficient solution for PUF enrollment for the designers’ community. Our goal is to demonstrate a method which can reduce the overall cost in terms of number of CRPs required for training, training time and memory. Instead of modifying the estimated model structure, we propose to reduce the complexity of the modeling target. This means to provide secured access to the internal responses of strong PUF during the enrollment and capture internal CRPs to model each sub-component of the PUF independently. It also necessitates to permanently remove the internal access after the enrollment to prevent exposure of the internal responses. This means that the internal responses should not be directly accessible after enrollment. Our sub-space modeling method requires lesser number of CRPs compared to modeling the whole PUF. We experimentally prove that sub-space modeling can significantly reduce the cost of training compared to some of the latest works. For instance, we could model 128-stage 6-XOR Arbiter PUF with just above 90% prediction accuracy with 5000 CRPs. Here the response in the CRP is a vector including the responses of the sub-components. Our results show that sub-space modeling is potentially a cost-efficient solution to enroll strong PUF with high complexity. Amir Ali Pour, David Hély, Vincent Beroulle, Giorgio Di Natale |
DCOSS | 4 |
| 2022 | Dependability of Alternative Computing Paradigms for Machine Learning: hype or hope?abstractToday we observe amazing performance achieved by Machine Learning (ML); for specific tasks it even surpasses human capabilities. Unfortunately, nothing comes for free: the hidden cost behind ML performance stems from its high complexity in terms of operations to be computed and the involved amount of data. For this reasons, custom Artificial Intelligence hardware accelerators based on alternative computing paradigms are attracting large interest. Such dedicated devices support the energy-hungry data movement, speed of computation, and memory resources that MLs require to realize their full potential. However, when ML is deployed on safety-/mission-critical applications, dependability becomes a concern. This paper presents the state of the art of custom Artificial Intelligence hardware architectures for ML, here Spiking and Convolutional Neural Networks, and shows the best practices to evaluate their dependability. Cristiana Bolchini, Alberto Bosio, Luca Cassano, Bastien Deveautour, Giorgio Di Natale, Antonio Miele, Ian O'Connor, Elena I. Vatajelu |
DDECS | 5 |
| 2022 | On the optimization of Software Obfuscation against Hardware Trojans in MicroprocessorsabstractThe quest of low production cost and short time-to-market, as well as the complexity of modern integrated circuits pushed towards a globalization of the supply chain of silicon devices. Such production paradigm raised a number of security threats among which Hardware Trojan Horses (HTHs), that became a serious issue not only for academy but also for industry in the very last years. Indeed, it has been demonstrated that HTHs can be inserted into microprocessors allowing the attacker to run malicious software, to acquire root privileges or to steal secret information. In this paper we present the use of software obfuscation to protect systems against HTHs that aim at stealing information from the microprocessor while it is executing a program. Moreover, we present a Genetic Algorithm-based approach to optimize such anti-HTH methodology by maximizing the obtained obfuscation while minimizing the introduced overhead. We proved the effectiveness and efficiency of the proposed methodology on the Ariane 64bit RISC-V microprocessor running a set of MiBench benchmarks and cryptographic programs. Luca Cassano, Elia Lazzeri, Nikita Litovchenko, Giorgio Di Natale |
DDECS | 4 |
| 2022 | On-Line Reliability Estimation of Ring Oscillator PUFabstractIn this paper we propose an on-line test methodology for RO-PUF reliability which enables high accuracy in the results since it is not based on predictive simplified models of the device variability and noise, but on actual technological electrical models and high versatility since it is not based on measurements extracted from a single technology. Sergio Vinagrero Gutierrez, Giorgio Di Natale, Elena I. Vatajelu |
ETS | 2 |
| 2022 | Software Product Reliability Based on Basic Block Metrics RecompositionabstractIn the context of functional verification, the focus has always been on hardware and its ability to be both resilient to errors and to recover from them autonomously. In order to evaluate these characteristics, an extensive use of Fault Injection tools is made to achieve clear and granular results. These testing campaigns are carried out on the entire DUT and require a consistent amount of time and computational resources. The possibility of reducing these costs applying modern techniques as the study of the Dysfunctional State Machine or the proof of concept regarding the composability of single block fault injection campaigns to obtain a library of component of which the reliability metrics are well known, as already been extensively discussed and proven on hardware. In this work instead the application of this methodologies to software is presented for the first time. In order to do so, the software has been divided into basic block, atomic chunks of code having precise carachteristics that will ensure the possibility to study them singularly and then recompose them into a software product which reliability metrics are known, without the need for complete Fault injection campaign. Tiziano Fiorucci, Giorgio Di Natale, Jean-Marc Daveau, Philippe Roche |
IOLTS | 2 |
| 2022 | Circuit-to-Circuit Attacks in SoCs via Trojan-Infected IEEE 1687 Test InfrastructureabstractWe demonstrate a Hardware Trojan (HT)-based circuit-to-circuit attack mechanism in the context of Systems-on-Chip (SoCs). The HT trigger is hidden inside the attacking circuit and the HT payload travels from the attacking circuit to the victim circuit via the test infrastructure. The common test infrastructure is configured accordingly by the HT so as to propagate the HT payload. We demonstrate the capability of this HT to perform a denial-of-service attack on an industrial Analog-to-Digital Converter (ADC) connected to a IEEE 1687 test infrastructure. Michele Portolan, Antonios Pavlidis, Giorgio Di Natale, Eric Faehn, Haralampos-G. D. Stratigopoulos |
ITC | 3 |
| 2022 | DETON: DEfeating hardware Trojan horses in microprocessors through software ObfuscatioN
Luca Cassano, Mattia Iamundo, Tomas Antonio López, Alessandro Nazzari, Giorgio Di Natale |
J. Syst. Archit. | 5 |
| 2022 | Nonlinear Code-Based Low-Overhead Fine-Grained Control Flow CheckingabstractA hardware-based control flow monitoring technique enables the detection of errors in both the control flow and the instruction stream executed on a processor. However, as shown in recent publications, these techniques fail to detect malicious carefully-tuned manipulations of the instruction stream in a basic block. This article presents a non-linear encoder and checker that can cope with this weakness. It is a MAC based control flow checker that has the advantage of working with basic blocks of variable length, can detect every error, and performs the computation in real-time. The architecture can easily be modified to support different signature size and error masking probabilities. Gilad Dar, Giorgio Di Natale, Osnat Keren |
IEEE Trans. Computers | 2 |
| 2022 | Digital-to-Analog Hardware Trojan AttacksabstractWe propose a Hardware Trojan (HT) attack for analog circuits with its key characteristic being that it cannot be prevented or detected in the analog domain. The HT attack works in the context of Systems-on-Chip (SoCs) comprising both digital and analog Intellectual Property (IP) blocks. The attacker could be either the SoC integrator or the foundry. More specifically, the HT trigger is placed inside a dense digital IP block where it can be effectively hidden, whereas the HT payload is in the form of a digital pattern transported via the test bus or generated within the test bus, reaching the Design-for-Test (DfT) or programmability interface of the victim analog IP with the test bus. The HT payload unexpectedly activates the DfT and sets the victim analog IP into some possibly partial and undocumented test mode or changes the nominal programmability. The HT payload can be designed to result in performance degradation or complete malfunction, i.e., denial of service. We demonstrate this HT attack scenario on two analog IPs, namely a low-dropout (LDO) regulator using simulation and an RF receiver using hardware measurements. Mohamed Elshamy, Giorgio Di Natale, Alhassan Sayed, Antonios Pavlidis, Marie-Minerve Louërat, Hassan Aboushady, Haralampos-G. D. Stratigopoulos |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2021 | Scramble Cache: An Efficient Cache Architecture for Randomized Set PermutationabstractDriven by the need of performance-efficient computations, a large number of systems resort to cache memories. In this context, cache side-channel attacks have been proven to be a serious threat for many applications. Many solutions and countermeasures exist in literature. Nevertheless, the majority of them do not cope with the constraints and limitations imposed by embedded systems. In this paper, we introduce a novel cache architecture that leverages randomized set placement to defeat cache side-channel analysis. A key property of this architecture is its low impact on performance and its small area overhead. We demonstrate that this countermeasure allows protecting the system against known cache side-channel attacks, while guaranteeing small overheads, making this solution suitable also for embedded systems. Amine Jaamoum, Thomas Hiscock, Giorgio Di Natale |
DATE | 3 |
| 2021 | Identification of Hardware Devices based on Sensors and Switching Activity: a Preliminary StudyabstractHardware device identification has become an important feature for enhancing the security and the trust of interconnected objects. In this paper, we present a device identification method based on measuring physical and electrical properties of the device, while controlling its switching activity. The method is general an applicable to a large range of devices from FPGAs to processors, as long as they embed sensors (such as temperature and voltage) and their measurements are available. The method is enabled by the fact that both the sensors and the effects of the switching activity on the circuit are uniquely affected by manufacturing-induced process variability. The device identification based on this method is made possible by the use of machine learning. The efficiency of the method has been evaluated by a preliminary study conducted on eleven FPGAs. Honorio Martín, Elena I. Vatajelu, Giorgio Di Natale |
DATE | 3 |
| 2021 | Automated Dysfunctional Model Extraction for Model Based Safety Assessment of Digital SystemsabstractIn the field of automatic quality or safety assurance level evaluation, this paper proposes the first approach towards the automation of the extraction processes of both the valid and faulty state machines within a System-on-a-Chip. The data automatically extracted by this method is a relevant input for behavioural modelization and FMEA analysis. The method is based on a semi-automated approach for the systematic extraction of failure modes of a digital design in the hypothesis of a single-event upset (SEU) or stuck-at in flip-flops. This procedure aims to enhance human driven failure analysis and provide inputs for RAMS frameworks in the process of quality assurance of complex devices. The main objective is to transport and apply RAMS methods and tools in the area of SoCs design. Experimental results have been conducted on an I2C - AHB system, laying the base for a complete and more complex analysis on an entire SoC. Tiziano Fiorucci, Jean-Marc Daveau, Giorgio Di Natale, Philippe Roche |
IOLTS | 3 |
| 2021 | Security EDA Extension through P1687.1 and 1687 CallbacksabstractIn recent years, the world of VLSI testing has been living a huge transformation pushed by constraints and requirements coming from a large variety of sources and applications. The traditional need for higher accessibility and controllability led to solutions such as IEEE 1687, while the need for reuse is pushing for innovations like P1687.1. All the while, these same features are raising security concerns for malicious attacks or reverse engineering. Standards usual approach of relying on Domain-Specific Languages to convey information to the EDA tools has difficulty in handling such disparate and often conflicting needs, with the risk of dangerous proliferation of custom and incompatible solutions. In this paper, we show how the usage of Callbacks, defined in P1687.1, can help solve this issue. Michele Portolan, Vincent Reynaud, Paolo Maistri, Régis Leveugle, Giorgio Di Natale |
ITC | 5 |
| 2020 | PUF Enrollment and Life Cycle Management: Solutions and Perspectives for the Test CommunityabstractPhysically Unclonable Functions (PUFs) allow to extract unique fingerprints from silicon chips. The applications are numerous: chip identification, chip master key extraction, authentication protocol, unique seeding, etc. However, secure usage of PUF requires some precautions. This paper reviews industrial concerns associated with PUF operation, including those occurring before and after market. Namely, starting from PUF “secure” specifications, aligned with state-of-the-art standards, we explore innovative techniques to handle enrollment and subsequent PUF queries, in nominal as well as in adversarial environment. Amir Ali Pour, Vincent Beroulle, Bertrand Cambou, Jean-Luc Danger, Giorgio Di Natale, David Hély, Sylvain Guilley, Naghmeh Karimi |
ETS | 5 |
| 2020 | Hardware Trojan Attacks in Analog/Mixed-Signal ICs via the Test Access MechanismabstractWe present a Hardware Trojan (HT) attack scenario for analog circuits. The characteristic of this HT is that it does not reside inside the victim analog circuit. Instead, it resides on an independent digital circuit on the same die where it is triggered, yet its payload is applied only to the analog circuit after being transferred via the common test infrastructure and the test interface of the analog circuit. This HT attack cannot be detected or prevented in the analog domain and it exploits the dense digital circuit to hide effectively its footprint. Mohamed Elshamy, Giorgio Di Natale, Antonios Pavlidis, Marie-Minerve Louërat, Haralampos-G. D. Stratigopoulos |
ETS | 2 |
| 2020 | Nonlinear Codes for Control Flow CheckingabstractA hardware-based control flow monitoring technique enables to detect both errors in the control flow and the instruction stream being executed on a processor. However, as was shown in recent papers, these techniques fail to detect malicious carefully-tuned manipulation of the instruction stream in a basic block. This paper presents a non-linear encoder and checker that can cope with this weakness. Giorgio Di Natale, Osnat Keren |
ETS | 1 |
| 2020 | Machine Learning and Hardware security: Challenges and Opportunities -Invited Talk-abstractMachine learning techniques have significantly changed our lives. They helped improving our everyday routines, but they also demonstrated to be an extremely helpful tool for more advanced and complex applications. However, the implications of hardware security problems under a massive diffusion of machine learning techniques are still to be completely understood. This paper first highlights novel applications of machine learning for hardware security, such as evaluation of post quantum cryptography hardware and extraction of physically unclonable functions from neural networks. Later, practical model extraction attack based on electromagnetic side-channel measurements are demonstrated followed by a discussion of strategies to protect proprietary models by watermarking them. Francesco Regazzoni 0001, Shivam Bhasin, Amir Ali Pour, Ihab Alshaer, Furkan Aydin, Aydin Aysu, Vincent Beroulle, Giorgio Di Natale, Paul D. Franzon, David Hély, Naofumi Homma, Akira Ito 0002, Dirmanto Jap, Priyank Kashyap, Ilia Polian, Seetal Potluri, Rei Ueno, Elena I. Vatajelu, Ville Yli-Mäyry |
ICCAD | 8 |
| 2019 | Hidden-Delay-Fault Sensor for Test, Reliability and SecurityabstractIn this paper we present a novel hidden-delay-fault sensor design and a preliminary analysis of its circuit integration and applicability. In our proposed method, the delay sensing is achieved by sampling data on both rising and falling clock edges and using a variable duty cycle to control the length of the path to be tested. The main advantage of our proposed method is that it works at nominal frequency, it can detect hidden-delay-faults on short paths and it is versatile in its applicability. It can be used (i) during testing to perform user-defined hidden-delay-fault test, (ii) for reliability degradation estimation due to process, environmental variations and ageing, and (iii) in security to detect the insertion of Trojan horses that alter the path delay. Giorgio Di Natale, Elena I. Vatajelu, Kalpana Senthamarai Kannan, Lorena Anghel |
DATE | 1 |
| 2019 | Encryption-Based Secure JTAGabstractStandard test infrastructures, such as IEEE Std. 1149.1 (JTAG), IEEE Std. 1500 and IEEE Std. 1687 (IJTAG), are widely used in nowadays Integrated Circuits (ICs). However, they pose an important security challenge to the designers because of the high controllability and observability they offer through the Test Access Port (TAP). For instance, malicious users can exploit test infrastructures in order to access the internal scan chains of crypto-cores and perform scan attacks. Moreover, these infrastructures connect all the devices of the system to the same network. For this reason, the data sent to a target device are potentially visible to all the others. Consequently, this poses a threat to the confidentiality of data content. The encryption of test data is a countermeasure that has been conceived in order to overcome these threats. In this paper, we propose a new secure version of the JTAG infrastructure, relying on stream-based encryption. Emanuele Valea, Mathieu Da Silva, Marie-Lise Flottes, Giorgio Di Natale, Bruno Rouzeyre |
DDECS | 4 |
| 2019 | Alternatives to Fault Injections for Early Safety/Security EvaluationsabstractFunctional Safety standards like ISO 26262 require a detailed analysis of the dependability of components subjected to perturbations. Radiation testing or even much more abstract RTL fault injection campaigns are costly and complex to set up especially for SoCs and Cyber Physical Systems (CPSs) comprising intertwined hardware and software. Moreover, some approaches are only applicable at the very end of the development cycle, making potential iterations difficult when market pressure and cost reduction are paramount. In this tutorial, we present a summary of classical state-of-the-art approaches, then alternative approaches for the dependability analysis that can give an early yet accurate estimation of the safety or security characteristics of HW-SW systems. Designers can rely on these tools to identify issues in their design to be addressed by protection mechanisms, ensuring that system dependability constraints are met with limited risk when subjected later to usual fault injections and to e.g., radiation testing or laser attacks for certification. Michele Portolan, Alessandro Savino 0001, Régis Leveugle, Stefano Di Carlo, Alberto Bosio, Giorgio Di Natale |
ETS | 6 |
| 2019 | HATE: a HArdware Trojan Emulation Environment for Microprocessor-based SystemsabstractThe constant quest of low production cost and short time-to-market, together with the growing complexity of integrated circuits led to the globalization of the supply chain of silicon devices. One of the threats related to such a supply chain are Hardware Trojan Horses (HWTs), that, in the last years, became a serious issue not only for academy but also for industry. Although a large number of methodologies for HWTs prevention, detection and tolerance have been proposed, there is a lack of well-recognized methods and metrics to evaluate their effectiveness. In this paper we present HATE1, a HArdware Trojan Emulation Environment. The goal of HATE is twofold: (i) the tool can be used to analyse whether a given HWT (or a given set of HWTs) is activated by a software running on a microprocessor, and (ii) it can be used to assess HWTs detection techniques in microprocessors against a set of generated HWTs (either randomly or not). HATE represents, in our vision, a step towards the definition of a reference benchmarking scenario, to provide a comparative ground for evaluating different proposals focusing on HWT detection/tolerance. A subset of MiBench programs have been used to analyse the efficiency of HATE. Cristiana Bolchini, Luca Cassano, Ivan Montalbano, Giampiero Repole, Andrea Zanetti, Giorgio Di Natale |
IOLTS | 6 |
| 2019 | On the Encryption of the Challenge in Physically Unclonable FunctionsabstractPhysically Unclonable Functions (PUFs) are cryptographic primitives used to implement low-cost device authentication and secure secret key generation. Weak PUFs (i.e., devices able to generate a single signature or to deal with a limited number of challenges) and Strong PUFs (i.e., devices able to deal with large number of challenges) are widely discussed in literature. Strong PUFs are susceptible to machine learning and modeling attacks. In this paper we propose a solution where the challenges of a Strong PUF are encrypted in order to remove the linear challenge-response correlation that can be exploited by those attacks. In this context, a ZeroBit Error Rate Weak PUF generates the encryption key so that all PUF instances have a different, nonlinear correlation between respective challenges and responses. We present two implementations of the proposed solution, and we demonstrate their resilience against machine learning attacks. Elena I. Vatajelu, Giorgio Di Natale, Mohd Syafiq Mispan, Basel Halak |
IOLTS | 2 |
| 2019 | Special Session: Reliability of Hardware-Implemented Spiking Neural Networks (SNN)abstractThe research work presented in this paper deals with the fault analysis in hardware-implemented Spiking Neural Networks with special emphasis on circuits designed to perform unsupervised, on-line learning. The paper describes the benefits of such neuromorphic systems, the possibilities of their hardware integration, but more importantly, it underlines the main concerns related to their resilience face to different types of faults. An overview of pertinent fault models and a methodology for conducting fault injection campaigns is described and different scenarios of faulty behaviors occurring after/before the STDP learning are shown. Elena I. Vatajelu, Giorgio Di Natale, Lorena Anghel |
VTS | 2 |
| 2019 | Memory-Aware Design Space Exploration for Reliability Evaluation in Computing Systems
Maha Kooli, Giorgio Di Natale, Alberto Bosio |
J. Electron. Test. | 2 |
| 2019 | SyRA: Early System Reliability Analysis for Cross-Layer Soft Errors Resilience in Memory Arrays of Microprocessor SystemsabstractCross-layer reliability is becoming the preferred solution when reliability is a concern in the design of a microprocessor-based system. Nevertheless, deciding how to distribute the error management across the different layers of the system is a very complex task that requires the support of dedicated frameworks for cross-layer reliability analysis. This paper proposes SyRA, a system-level cross-layer early reliability analysis framework for radiation induced soft errors in memory arrays of microprocessor-based systems. The framework exploits a multi-level hybrid Bayesian model to describe the target system and takes advantage of Bayesian inference to estimate different reliability metrics. SyRA implements several mechanisms and features to deal with the complexity of realistic models and implements a complete tool-chain that scales efficiently with the complexity of the system. The simulation time is significantly lower than micro-architecture level or RTL fault-injection experiments with an accuracy high enough to take effective design decisions. To demonstrate the capability of SyRA, we analyzed the reliability of a set of microprocessor-based systems characterized by different microprocessor architectures (i.e., Intel x86, ARM Cortex-A15, ARM Cortex-A9) running both the Linux operating system or bare metal in the presence of single bit upsets caused by radiation induced soft errors. Each system under analysis executes different software workloads both from benchmark suites and from real applications. Alessandro Vallero, Alessandro Savino 0001, Athanasios Chatzidimitriou, Manolis Kaliorakis, Maha Kooli, Marc Riera, Martí Anglada, Giorgio Di Natale, Alberto Bosio, Ramon Canal, Antonio González 0001, Dimitris Gizopoulos, Riccardo Mariani, Stefano Di Carlo |
IEEE Trans. Computers | 8 |
| 2019 | Preventing Scan Attacks on Secure Circuits Through Scan Chain EncryptionabstractScan attacks exploit facilities offered by scan chains to retrieve embedded secret data, in particular, secret keys used by the device for data encryption/decryption in mission mode. This paper presents a scan attack countermeasure based on the encryption of the data written to or read from the scan chains. The secret-key management system already embedded in the device is used to provide appropriate keys for encryption of data flowing on the scan chains. The goal of the proposed solution is to counteract the scan-related security threats while preserving test and diagnosis efficiency provided by conventional design-for-testability techniques, as well as to allow debugging capabilities in mission mode. The proposed solution can deal with both stuck-at and transition-faults test schemes as well as single and multiple scan chain configurations using test data compression schemes. We will show that the proposed scheme provides expected test/diagnostic and debug facilities as classical scan design with marginal impacts on area, test time and design flows, while successfully preventing control and observation of data flowing in the scan chains by unauthorized users. Mathieu Da Silva, Marie-Lise Flottes, Giorgio Di Natale, Bruno Rouzeyre |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2019 | High-Entropy STT-MTJ-Based TRNGabstractHardware true random number generators (TRNGs) yield random numbers from physical processes. Traditionally, such devices are based on statistically random events such as thermal noise or other quantum phenomena. In this brief, we propose a novel TRNG design using a spin-transfer torque magnetic tunnel junction (MTJ) device. Our solution exploits the stochastic nature of the MTJ switching, and the behavior of an XOR gate dealing with probabilistic signals. We show that by using multiple MTJ devices, the proposed TRNG succeeds in filtering the negative effect of environmental changes as well as fabrication-induced variability and generates random sequences with high-entropy under any conditions. Elena I. Vatajelu, Giorgio Di Natale |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2018 | Laser Fault Injection at the CMOS 28 nm Technology Node: an Analysis of the Fault ModelabstractS. Skorobogatov and R. Anderson identified laser illumination as an effective technique to conduct fault attacks in 2002. In these early days of laser-induced fault injection, it was proven to be possible to inject single-bit faults into integrated circuits. This corresponds to the more restrictive fault model found in the fault attack bibliography. The target area under laser illumination (a few micrometers, down to ~1 µm) broadly matched that of a single transistor. It was consistent with a single-bit fault model. However, since then the technology of secure devices has evolved. In current circuits even the smallest laser spots may illuminate several logic cells. This raises the question of the validity of the single-bit fault model: does it still hold? In this work, we report an assessment of its validity through experimental results obtained from circuits designed at the 28 nm CMOS technology node. We also describe the main properties of the corresponding fault model obtained from both static and dynamic experiments. Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Stephan De Castro, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre |
FDTC | 11 |
| 2018 | The case of using CMOS FD-SOI rather than CMOS bulk to harden ICs against laser attacksabstractAt first used to emulate the effects of radioactive ionizing particules passing through integrated circuits (ICs), laser illumination is also used to inject faults into the computations of secure ICs for the purpose of retrieving secret data. The CMOS FD-SOI technology is expected to be less sensitive to laser faults injection than the more usual CMOS bulk technology. We report in this work an experimental assessment of the interest of using FD-SOI rather than CMOS bulk to decrease laser sensitivity. Our experiments were conducted on test chips at the 28nm node for both technologies with laser pulse durations in the picosecond and nanosecond ranges. Jean-Max Dutertre, Vincent Beroulle, Philippe Candelier, Louis-Barthelemy Faber, Marie-Lise Flottes, Philippe Gendrier, David Hély, Régis Leveugle, Paolo Maistri, Giorgio Di Natale, Athanasios Papadimitriou, Bruno Rouzeyre |
IOLTS | 10 |
| 2018 | A Novel Use of Approximate Circuits to Thwart Hardware Trojan Insertion and Provide ObfuscationabstractHardware Trojans have become in the last decade a major threat in the Integrated Circuit industry. Many techniques have been proposed in the literature aiming at detecting such malicious modifications in fabricated ICs. For the most critical circuits, prevention methods are also of interest. The goal of such methods is to prevent the insertion of a Hardware Trojan thanks to ad-hoc design rules. In this paper, we present a novel prevention technique based on approximation. An approximate logic circuit is a circuit that performs a possibly different but closely related logic function, so that it can be used for error detection or error masking where it overlaps with the original circuit. We will show how this technique can successfully detect the presence of Hardware Trojans, with a solution that has a smaller impact than triplication. Honorio Martín, Luis Entrena, Sophie Dupuis, Giorgio Di Natale |
IOLTS | 4 |
| 2018 | Neuromorphic Computing - From Robust Hardware Architectures to Testing StrategiesabstractThis paper provides an overview of the challenges faced by hardware implemented Spiking Neural Networks, from device to circuit design, reliability and test. We present a comprehensive description of the state-of-the-art neuromorphic architectures inspired by brain computation, with special emphasis on Spiking Neural Networks (SNNs), together with emerging technologies that have enabled such systems, namely Phase Change and Metal Oxide Resistive Memories. Finally, we discuss the main challenges faced by hardware implementations of SNNs, their reliability and post-fabrication test issues. Lorena Anghel, Denys Ly, Giorgio Di Natale, Benoît Miramond, Elena I. Vatajelu, Elisa Vianello |
VLSI-SoC | 3 |
| 2017 | Scan chain encryption for the test, diagnosis and debug of secure circuitsabstractScan attacks exploit facilities offered by scan chains to retrieve embedded secret data, in particular secret keys used in crypto-processors for encoding information in such a way that only knowledge of the secret key allows to access it. This paper presents a scan attack countermeasure based on the encryption of the scan chain content. The goal is to counteract the security threats and, at the same time, to preserve test efficiency, diagnosis and debugging abilities. We propose to use the secret-key management policy embedded in the device under test in order to encrypt both control and observed data at test time. This solution does not require additional key management, provides same test/diagnostic and debug facilities as under classical scan design with marginal impacts on area and test time. Mathieu Da Silva, Marie-Lise Flottes, Giorgio Di Natale, Bruno Rouzeyre, Paolo Prinetto, Marco Restifo |
ETS | 3 |
| 2017 | Reliability of computing systems: From flip flops to variablesabstractReliability evaluation is a critical task in computing systems. From one side, the results must be accurate enough not to under-or over-estimate the overall system reliability (thus either resulting in a non-reliable system, or a system for which too expensive solutions have been adopted). On the other side, the time required for the analysis should be kept at the minimum. This paper presents some new advances in the reliability assessment of computing systems, by showing techniques targeting both hardware and software levels, and the combination of both. Giorgio Di Natale, Maha Kooli, Alberto Bosio, Michele Portolan, Régis Leveugle |
IOLTS | 1 |
| 2016 | Towards a highly reliable SRAM-based PUFs
Elena I. Vatajelu, Giorgio Di Natale, Paolo Prinetto |
DATE | 2 |
| 2016 | System-level reliability evaluation through cache-aware software-based fault injectionabstractDeveloping new methods to evaluate the software reliability in an early design stage of the system can save the design costs and efforts, and will positively impact the product time-to-market. In this paper, we propose a novel fault injection technique to evaluate the reliability of a computing system running a software at early design stage where the hardware architecture is not completely defined yet. The proposed approach efficiently operates on the original source code of the software in order to inject transient faults in the data or the instructions. To be accurate and to achieve a better characterization of the system, we simulate faults occurring in the system memory units such as the data cache and the RAM by developing a system emulator. To validate our approach, we compare the simulation results to those obtained with an FPGA-based fault injector. The similarity of the results proves the accuracy of our approach to evaluate system reliability with a gain in the execution time and without requiring a fully defined hardware system. Firas Kaddachi, Maha Kooli, Giorgio Di Natale, Alberto Bosio, Mojtaba Ebrahimi, Mehdi Baradaran Tahoori |
DDECS | 3 |
| 2016 | ETS 2016 forewordabstractOn behalf of the Steering, Program and Organizing Committees, we would like to welcome you to the European Test Symposium 2016 (ETS'16); the largest event in Europe entirely devoted to presenting and discussing scientific trends, emerging results, hot topics, and applications in the area of electronic circuit and system testing. ETS'16 is the 21st edition of the symposium and is held in Amsterdam, The Netherlands. Amsterdam is the capital and most populous city of the Kingdom of the Netherlands. Amsterdam's name derives from Amstelredamme, indicative of the city's origin as a dam of the river Amstel. Said Hamdioui, Giorgio Di Natale, Bram Kruseman, Maria K. Michael, Haralampos-G. D. Stratigopoulos |
ETS | 2 |
| 2016 | Revisiting software-based soft error mitigation techniques via accurate error generation and propagation modelsabstractRadiation-induced soft errors are growing reliability concerns, especially in mission- and safety-critical systems. A variety of software-based fault tolerant techniques have widely been proposed and used to mitigate soft errors at the application-level. Such techniques are typically evaluated using statistical fault injection at software-visible variables of the system as fault injection at higher levels of abstraction is much faster than logic-level or Register Transfer Level (RTL). Recent studies revealed that software-based fault injection techniques are not accurate for analyzing soft errors originating in flip-flops. However, the effectiveness of such techniques for evaluation of the entire processor including register-files and cache arrays are not studied yet. In this paper, we comprehensively study the soft error rate of several workloads and their protected version using software-based fault tolerance by performing detailed error generation and propagation analysis at hardware-level. Our detailed experimental analysis shows that there is no significant correlation between the results of hardware- and software-based fault injection for the effectiveness of software-based fault tolerance. Furthermore, software-based fault injection cannot accurately model the relative improvement provided by fault tolerant software implementation, and hence, its results could be misleading. Mojtaba Ebrahimi, Maryam Rashvand, Firas Kaddachi, Mehdi Baradaran Tahoori, Giorgio Di Natale |
IOLTS | 5 |
| 2016 | Cache-aware reliability evaluation through LLVM-based analysis and fault injectionabstractReliability evaluation is a high costly process that is mainly carried out through fault injection or by means of analytical techniques. While the analytical techniques are fast but inaccurate, the fault injection is more accurate but extremely time consuming. This paper presents an hybrid approach combining analytical and fault injection techniques in order to evaluate the reliability of a computing system, by considering errors that affect both the data and the instruction cache. Compared to existing techniques, instead of targeting the hardware model of the cache (e.g., VHDL description), we only consider the running application (i.e., the software layer). The proposed approach is based on the Low-Level Virtual Machine (LLVM) framework coupled with a cache emulator. As input, the tool requires the application source code, the cache size and policy, and the target microprocessor instruction set. The main advantage of the proposed approach is the achieved speed up quantified in magnitude orders compared to existing fault injection techniques. For the validation, we compare the simulation results to those obtained with an FPGA-based fault injector. The similarity of the results proves the accuracy of the approach. Maha Kooli, Giorgio Di Natale, Alberto Bosio |
IOLTS | 2 |
| 2016 | STT-MTJ-based TRNG with on-the-fly temperature/current variation compensationabstractA hardware True Random Number Generator (TRNG) yields random numbers from a physical process. Traditionally, such devices are based on statistically random signals such as thermal noise or other quantum phenomena. In this paper we propose an innovative TRNG design using a Spin Transfer Torque Magnetic Tunnel Junction (STT-MTJ) device. We exploit the stochastic nature of the MTJ device switching, and perform on-the-fly temperature/current variation compensation. We show that the proposed solution keeps up with environmental changes and generates random sequences with high probability. Elena I. Vatajelu, Giorgio Di Natale, Paolo Prinetto |
IOLTS | 2 |
| 2016 | Cross-layer system reliability assessment framework for hardware faultsabstractSystem reliability estimation during early design phases facilitates informed decisions for the integration of effective protection mechanisms against different classes of hardware faults. When not all system abstraction layers (technology, circuit, microarchitecture, software) are factored in such an estimation model, the delivered reliability reports must be excessively pessimistic and thus lead to unacceptably expensive, over-designed systems. We propose a scalable, cross-layer methodology and supporting suite of tools for accurate but fast estimations of computing systems reliability. The backbone of the methodology is a component-based Bayesian model, which effectively calculates system reliability based on the masking probabilities of individual hardware and software components considering their complex interactions. Our detailed experimental evaluation for different technologies, microarchitectures, and benchmarks demonstrates that the proposed model delivers very accurate reliability estimations (FIT rates) compared to statistically significant but slow fault injection campaigns at the microarchitecture level. Alessandro Vallero, Alessandro Savino 0001, Gianfranco Politano, Stefano Di Carlo, Athanasios Chatzidimitriou, Sotiris Tselonis, Manolis Kaliorakis, Dimitris Gizopoulos, Marc Riera, Ramon Canal, Antonio González 0001, Maha Kooli, Alberto Bosio, Giorgio Di Natale |
ITC | 14 |
| 2016 | Faster-than-at-speed execution of functional programs: An experimental analysisabstractBurn-In (BI) test is usually applied in manufacturing process to screen out chip early life failures, especially for safety critical applications. Unfortunately, this test method has elevated costs for companies. In recent days, Faster-than-at-Speed-Test (FAST) has become a useful technique to discover small delay defects. At the same time, overclocking methods to enhance system performances have been studied, which focus on temperature management to preserve system functionalities. In this paper, a FAST technique is approached with the aim of intentionally provoking a thermal overheating in the microprocessor by mean of the execution of functional test programs, partly regardless of system behavior preservation. The goal is to introduce an internal stress stronger than current procedures used during BI in order to speed up early detection of latent faults. The method illustrates how to avoid blocking configurations due to timing constraints violation and leads to a significant increase of the switching activity. Experimental results on a MIPS architecture show that, by using the described technique, the processor is not falling into an unpredictable state even at frequencies up to about 20 times higher than the nominal one and the switching activity is increasing up to 300% per nanoseconds. Paolo Bernardi 0002, Alberto Bosio, Giorgio Di Natale, Andrea Guerriero, Federico Venini |
VLSI-SoC | 3 |
| 2016 | Cache- and register-aware system reliability evaluation based on data lifetime analysisabstractDeveloping new methods to evaluate the software reliability in an early design stage of the system can save the design costs and efforts, and will positively impact product time-to-market. This paper introduces a new approach to evaluate, at early design phase, the reliability of a computing system running a software. The approach can be used when the hardware architecture is not completely defined yet. In order to be independent of the hardware architecture and at the same time accurate, we propose to use the Low-Level Virtual Machine (LLVM) framework. In addition, to reduce the reliability evaluation time, our approach consists in analyzing the variable lifetimes to compute the probability of masked faults. Finally, to achieve a better characterization we propose to consider also the presence of caches and register files. For this purpose, a cache emulator as well as a register file emulator are developed. Simulations run with our approach produce very similar results to those run with a hardware-based fault injector. This proves the accuracy of our approach to evaluate system reliability with a gain in the simulation time and without requiring a hardware platform. Maha Kooli, Firas Kaddachi, Giorgio Di Natale, Alberto Bosio |
VTS | 3 |
| 2016 | Security primitives (PUF and TRNG) with STT-MRAMabstractThe rapid development of low power, high density, high performance SoCs has pushed the embedded memories to their limits and opened the field to the development of emerging memory technologies. The Spin-Transfer-Torque Magnetic Random Access Memory (STT-MRAM) has emerged as a promising choice for embedded memories due to its reduced read/write latency and high CMOS integration capability. Inner properties of STT-MRAMs make them suitable for the implementation of basic security primitives such Physically Unclonable Functions (PUFs) and True Random Number Generators (TRNGs). PUFs are emerging primitives used to implement low-cost device authentication and secure secret key generation. On the other hand, TRNGs generate random numbers from a physical process. We will show how it is possible to exploit (i) the high variability affecting the electrical resistance of the magnetic device to build a robust, unclonable and unpredictable PUF, and (ii) the stochastic nature of the write operation in the magnetic device to generate randomly distributed numbers. Elena I. Vatajelu, Giorgio Di Natale, Paolo Prinetto |
VTS | 2 |
| 2016 | Frontside Versus Backside Laser Injection: A Comparative StudyabstractThe development of cryptographic devices was followed by the development of so-called implementation attacks, which are intended to retrieve secret information exploiting the hardware itself. Among these attacks, fault attacks can be used to disturb the circuit while performing a computation to retrieve the secret. Among possible means of injecting a fault, laser beams have proven to be accurate and powerful. The laser can be used to illuminate the circuit either from its frontside (i.e., where metal interconnections are first encountered) or from the backside (i.e., through the substrate). Historically, frontside injection was preferred because it does not require the die to be thinned. Nevertheless, due to the increasing integration of metal layers in modern technologies, frontside injections do not allow targeting of any desired location. Indeed, metal lines act as mirrors, and they reflect and refract most of the energy provided by the laser beam. Conversely, backside injections, although more difficult to set up, allow an increase of the resolution of the target location and remove the drawbacks of the frontside technique. This article compares experimental results from frontside and backside fault injections. The effectiveness of the two techniques is measured in terms of exploitable errors on an AES circuit (i.e., errors that can be used to extract the value of the secret key used during the encryption process). We will show, conversely to what is generally assumed, that frontside injection can provide even better results compared to backside injection, especially for low-cost beams with a large laser spot. Stephan De Castro, Jean-Max Dutertre, Bruno Rouzeyre, Giorgio Di Natale, Marie-Lise Flottes |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2016 | STT-MRAM-Based PUF Architecture Exploiting Magnetic Tunnel Junction Fabrication-Induced VariabilityabstractPhysically Unclonable Functions (PUFs) are emerging cryptographic primitives used to implement low-cost device authentication and secure secret key generation. Weak PUF s (i.e., devices able to generate a single signature or to deal with a limited number of challenges) are widely discussed in literature. One of the most investigated solutions today is based on SRAMs. However, the rapid development of low-power, high-density, high-performance SoCs has pushed the embedded memories to their limits and opened the field to the development of emerging memory technologies. The Spin-Transfer-Torque Magnetic Random Access Memory (STT-MRAM) has emerged as a promising choice for embedded memories due to its reduced read/write latency and high CMOS integration capability. In this article, we propose an innovative PUF design based on STT-MRAM memory. We exploit the high variability affecting the electrical resistance of the Magnetic Tunnel Junction (MTJ) device in anti-parallel magnetization. We will demonstrate that the proposed solution is robust, unclonable, and unpredictable. Elena I. Vatajelu, Giorgio Di Natale, Mario Barbareschi, Lionel Torres, Marco Indaco, Paolo Prinetto |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2015 | New testing procedure for finding insertion sites of stealthy hardware trojans
Sophie Dupuis, Papa-Sidi Ba, Marie-Lise Flottes, Giorgio Di Natale, Bruno Rouzeyre |
DATE | 4 |
| 2015 | STT MRAM-Based PUFs
Elena I. Vatajelu, Giorgio Di Natale, Marco Indaco, Paolo Prinetto |
DATE | 2 |
| 2015 | Session-less based thermal-aware 3D-SIC test schedulingabstractThis paper presents an original solution to the test scheduling problem for 3D stacked integrated circuits. We explore a session-less approach where the test procedure of any core can start at any time as long as Test Access Mechanisms (TAMs) are available and constraints in terms of power and thermal limits are respected. Given a set of test procedure with fixed length and a set of test resources (TAM width), we determine test procedure start times such that the system test time is minimized. The proposed greedy heuristic is applied on fully detailed benchmarks and is compared with solutions obtained from session-based approaches. The results show that the session-less solutions outperforms the session-based ones. This is so even though the session-based solution is optimal, which is generally not the case for scheduling solutions resulting from heuristics used for dealing with large systems. Marie-Lise Flottes, Joao Azevedo, Giorgio Di Natale, Bruno Rouzeyre |
ETS | 3 |
| 2015 | Challenges in designing trustworthy cryptographic co-processorsabstractSecurity is becoming ubiquitous in our society. However, the vulnerability of electronic devices that implement the needed cryptographic primitives has become a major issue. This paper starts by presenting a comprehensive overview of the existing attacks to cryptography implementations. Thereafter, the state-of-the-art on some of the most critical aspects of designing cryptographic co-processors are presented. This analysis starts by considering the design of asymmetrical and symmetrical cryptographic primitives, followed by the discussion on the design and online testing of True Random Number Generation. To conclude, techniques for the detection of Hardware Trojans are also discussed. Ricardo Chaves, Giorgio Di Natale, Lejla Batina, Shivam Bhasin, Baris Ege, Apostolos P. Fournaris, Nele Mentens, Stjepan Picek, Francesco Regazzoni 0001, Vladimir Rozic, Nicolas Sklavos 0001, Bohan Yang 0001 |
ISCAS | 2 |
| 2014 | Testing PUF-based secure key storage circuitsabstractDesign for test is an integral part of any VLSI chip. However, for secure systems extra precautions have to be taken to prevent that the test circuitry could reveal secret information. This paper addresses secure test for Physical Unclonable Function based systems. In particular it provides the testability analysis and a secure Built-In Self-Test (BIST) solution for Fuzzy Extractor (FE) which is the main component of PUF-based systems. The scheme targets high stuck-at-fault (SAF) coverage by performing scan-chain free functional testing, to prevent scan-chain abuse for attacks. The scheme reuses existing FE sub-blocks (for pattern generation and compression) to minimize the area overhead. The scheme is integrated in FE design and simulated; the results show that a SAF fault coverage of 95.1% can be realized with no more than 50k clock cycles at the cost of a negligible area overhead of only 2.2%. Higher fault coverage is possible to realize at extra cost. Mafalda Cortez, Gijs Roelofs, Said Hamdioui, Giorgio Di Natale |
DATE | 4 |
| 2014 | Hacking and protecting IC hardwareabstractTraditionally most of people treat a hardware solution as an inherently trusted box. “it is hardware not software; so it is secure and trustworthy”, they say. Recent research shows the need to re-asses this trust in hardware and even in its supply chain. For example, attacks are performed on ICs to retrieve secret information such as cryptographic keys. Moreover, backdoors can be inserted into electronic designs and allow for silent intruders into the system. And, even protecting intellectual-property is becoming a serious concern in the modern globalized, horizontal semiconductor business model. This paper discusses hardware security, both from hacking and protecting aspects. A classification of all possible hardware attacks is provided and most popular attacks are discussed including the countermeasures. Said Hamdioui, Jean-Luc Danger, Giorgio Di Natale, Fethulah Smailbegovic, Gerard van Battum, Mark Tehranipoor |
DATE | 3 |
| 2014 | Cross-Layer Early Reliability Evaluation for the Computing cOntinuumabstractAdvanced multifunctional computing systems realized in forthcoming technologies hold the promise of a significant increase of the computational capability that will offer end-users ever improving services and functionalities (e.g., next generation mobile devices, cloud services, etc.). However, the same path that is leading technologies toward these remarkable achievements is also making electronic devices increasingly unreliable, posing a threat to our society that is depending on the ICT in every aspect of human activities. Reliability of electronic systems is therefore a key challenge for the whole ICT technology and must be guaranteed without penalizing or slowing down the characteristics of the final products. CLERECO EU FP7 (GA No. 611404) research project addresses early accurate reliability evaluation and efficient exploitation of reliability at different design phases, since these aspects are two of the most important and challenging tasks toward this goal. Stefano Di Carlo, Alessandro Vallero, Dimitris Gizopoulos, Giorgio Di Natale, Arnaud Grasset, Riccardo Mariani, Frank Reichenbach |
DSD | 4 |
| 2014 | A novel adaptive fault tolerant flip-flop architecture based on TMRabstractThe use of Triple Modular Redundancy (TMR) was historically introduced long time ago for improving reliability of computer systems [1]. Recently, the advances in miniaturizing of CMOS devices made digital circuits more and more unreliable. The current trend goes towards the Internet of Things and the cloud computing, where small devices have high requirements in terms of reduced power consumption and increased reliability [2]. Classical TMR solutions allow for high reliability but they cannot satisfy low-power require-ments, since they consume about three times more than the equivalent single device. However, the type of applications that are implemented in the new cloud scenario do not require high reliability all the time, but it can be assumed that some computations are more important, and thus require to be executed by a reliable hardware, while other computations are less important, and thus they can tolerate failures [3]. Luca Cassano, Alberto Bosio, Giorgio Di Natale |
ETS | 3 |
| 2014 | Cross-layer early reliability evaluation: Challenges and promisesabstractEvaluation of computing systems reliability must be accurate enough to provide hints for the required fault protection mechanisms that will guarantee correctness of operation at acceptance costs. To be useful, reliability evaluation must be performed early enough in the design cycle when, however, the available details of the system are largely unknown. This inherent contradiction in terms: early vs. accurate, requires a cross-layer approach for reliability evaluation. Different layers of abstraction contribute differently in the overall system reliability; if this contribution can be assessed independently, the reliability of the system can be evaluated at the early stages of the design. We review the state-of-the-art in the area and discuss corresponding challenges . Stefano Di Carlo, Alessandro Vallero, Dimitris Gizopoulos, Giorgio Di Natale, Antonio González 0001, Ramon Canal, Riccardo Mariani, Mauro Pipponzi, Arnaud Grasset, Philippe Bonnot 0001, Frank Reichenbach, Gulzaib Rafiq, Trond Løkstad |
IOLTS | 4 |
| 2014 | A novel hardware logic encryption technique for thwarting illegal overproduction and Hardware TrojansabstractHardware piracy is a threat that is becoming more and more serious these last years. The different types of threats include mask theft, illegal overproduction, as well as the insertion of malicious alterations to a circuit, referred to as Hardware Trojans. To protect circuits from overproduction, circuits can be encrypted so that only authorized users can use the circuits. In this paper, we propose an encryption technique that also helps thwarting Hardware Trojan insertion. Assuming that an attacker will attach a Hardware Trojan to signals with low controllability in order to make it stealthy, the principle of the encryption is to minimize the number of signals with low controllability. Sophie Dupuis, Papa-Sidi Ba, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
IOLTS | 3 |
| 2014 | Customized cell detector for laser-induced-fault detectionabstractLaser is an effective mean to inject faults in a secure circuit and then to perform a subsequent fault attack. While high-precision laser beams are very expensive, a large-spot laser is far more affordable and easier to set-up for fault injection. In this paper, we discuss hardware countermeasures against laser-induced fault attacks and we propose a new laser detector based on customized logic gates. This detector is smaller and more sensitive than most standard cells. According to simulation results, it is very effective in detecting large spot laser attacks. Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
IOLTS | 2 |
| 2014 | Laser-induced fault effects in security-dedicated circuitsabstractLasers have become one of the most efficient means to attack secure integrated systems. Actual faults or errors induced in the system depend on many parameters, including the circuit technology and the laser characteristics. Understanding the physical effects is mandatory to correctly evaluate during the design flow the potential consequences of a laser-based attack and implement efficient counter-measures. This paper presents results obtained within the LIESSE project, aiming at defining a comprehensive approach for designers. Outcomes include the definition of fault/error models at several levels of abstraction, specific CAD tools using these models and new counter-measures well-suited to thwart laser-based attacks. Actual measures on components manufactured in the new 28 nm FDSOI technology are also presented. Régis Leveugle, Paolo Maistri, Pierre Vanhauwaert, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Athanasios Papadimitriou, David Hély, Vincent Beroulle, Guillaume Hubert, Stephan De Castro, Jean-Max Dutertre, Alexandre Sarafianos, Noemie Beringuier-Boher, Mathieu Lisart, Joel Damiens, Philippe Candelier, Clément Tavernier |
VLSI-SoC | 5 |
| 2014 | Built-in self-test for manufacturing TSV defects before bondingabstractIn this paper we present a BIST method for TSV pre-bond testing. A dedicated test circuitry per TSV is designed and simulated w.r.t a variety of defects and PVT variations. Based on discharge delay evaluation, the BIST scheme supports concurrent testing, requires small-area implementation and it is robust against PVT variations. Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Hakim Zimouche |
VTS | 1 |
| 2014 | Testing Methods for PUF-Based Secure Key Storage Circuits
Mafalda Cortez, Gijs Roelofs, Said Hamdioui, Giorgio Di Natale |
J. Electron. Test. | 4 |
| 2014 | Thwarting Scan-Based Attacks on Secure-ICs With On-Chip ComparisonabstractHardware implementation of cryptographic algorithms is subject to various attacks. It has been previously demonstrated that scan chains introduced for hardware testability open a back door to potential attacks. Here, we propose a scan-protection scheme that provides testing facilities both at production time and over the course of the circuit's life. The underlying principles to scan-in both input vectors and expected responses and to compare expected and actual responses within the circuit. Compared to regular scan tests, this technique has no impact on the quality of the test or the model-based fault diagnosis. It entails negligible area overhead and avoids the use of an authentication test mechanism. Jean DaRolt, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2013 | Laser-Induced Fault SimulationabstractInternational audience Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
DSD | 2 |
| 2013 | A smart test controller for scan chains in secure circuitsabstractStructural testing is one important step in the production of integrated circuits. The most common DIT technique is the insertion of scan-chains, which increases the observability and the controllability of the circuit's internal nodes. Nevertheless, malicious users can use the scan chains to observe confidential data stored in devices implementing cryptographic primitives. Therefore, scan chains inserted in secure ICs can be considered as a source of information leakage. Several countermeasures exist to cope with this type of problem. However, they either introduce high area overheads or they require modifications to the original design or the test protocol. In this paper we present a smart test controller that is able to prevent all known scan attacks. The controller does not require any additional signals, it is transparent to the designer and it does not require any modifications of the test protocol and procedure. Moreover, it introduces a very small area overhead. Jean DaRolt, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
IOLTS | 2 |
| 2013 | A New Recovery Scheme Against Short-to-Long Duration Transient Faults in Combinational Logic
Rodrigo Possamai Bastos, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
J. Electron. Test. | 2 |
| 2013 | Secure JTAG Implementation Using Schnorr Protocol
Amitabh Das, Jean DaRolt, Santosh Ghosh, Stefaan Seys, Sophie Dupuis, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Ingrid Verbauwhede |
J. Electron. Test. | 6 |
| 2013 | A novel differential scan attack on advanced DFT structuresabstractScan chains insertion is the most common technique to ensure the testability of digital cores, providing high fault coverage. However, for ICs dealing with secret information, scan chains can be used as back doors for accessing secret data thus becoming a threat to system security. So far, advanced test structures used to reduce test costs (e.g., response compaction) and achieve high fault coverage (e.g., X's masking decoder) have been considered as intrinsic countermeasures against these threats. This work proposes a new generic scan-based attack demonstrating that these test structures are not sufficiently effective to prevent leakage through the test infrastructure. This generic attack can be easily adapted to several cryptographic implementations for both symmetric and public key algorithms. The proposed attack is demonstrated on several ciphers. Jean DaRolt, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2012 | On-chip test comparison for protecting confidential data in secure ICsabstractHardware implementations of secure applications, e.g. cryptographic algorithms, are subject to various attacks. In particular, it has been demonstrated that scan chains introduced by Design for Testability open a backdoor to potential attacks. In this paper we propose a scan protection scheme that provides testing facilities both at production time and during the circuit's lifetime. The underlying principle is to scan-in both input vectors and expected responses, and to perform the comparison between expected and actual responses within the circuit. Compared to regular scan test, this technique has no impact on test quality and no impact on diagnostic of modeled faults. It entails a negligible area overhead and it avoids the use of an authentication test mechanism. Jean DaRolt, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
ETS | 2 |
| 2012 | Are advanced DfT structures sufficient for preventing scan-attacks?abstractStandard Design for Testability (DfT) structures are well known as potential sources of confidential information leakage. Scan-based attacks have been reported in publications since the early 2000s. It has been shown for instance that the secret key for symmetric encryption standards (DES, AES) could be retrieved from information gathered on scan-out pins when scan-chains are fully observed through these pins. However DfT practices have progressed to adapt to large and complex designs such as test response compaction, associated X-masking structure, partial scan, etc. As a side effect, these techniques mask part of the information collected on scan outputs. Thus, at first glance, they may appear as countermeasures against scan-based attacks. Nevertheless, in this paper we show that DfT structures, regardless of their nature, do not inherently enhance security and that specific additional countermeasures are still needed. We propose a new-scan attack able to deal with designs where only part of the internal circuit's state is observed for test purpose. Jean DaRolt, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
VTS | 2 |
| 2012 | Statistical Reliability Estimation of Microprocessor-Based SystemsabstractWhat is the probability that the execution state of a given microprocessor running a given application is correct, in a certain working environment with a given soft-error rate? Trying to answer this question using fault injection can be very expensive and time consuming. This paper proposes the baseline for a new methodology, based on microprocessor error probability profiling, that aims at estimating fault injection results without the need of a typical fault injection setup. The proposed methodology is based on two main ideas: a one-time fault-injection analysis of the microprocessor architecture to characterize the probability of successful execution of each of its instructions in presence of a soft-error, and a static and very fast analysis of the control and data flow of the target software application to compute its probability of success. The presented work goes beyond the dependability evaluation problem; it also has the potential to become the backbone for new tools able to help engineers to choose the best hardware and software architecture to structurally maximize the probability of a correct execution of the target software. Alessandro Savino 0001, Stefano Di Carlo, Gianfranco Politano, Alfredo Benso, Alberto Bosio, Giorgio Di Natale |
IEEE Trans. Computers | 6 |
| 2011 | Power consumption traces realignment to improve differential power analysisabstractCryptographic devices can be subject to side-channel attacks. Among those attacks, Differential Power Analysis (DPA) has proven to be very effective and easy to perform. Several countermeasures have been proposed in the literature. However, the effectiveness of these counter measures is still evaluated by resort-ing to intensive DPA simulations and constitutes a very time-consuming design task. In this paper we show that the knowledge of the structure of the circuit can be exploited to improve performances of the DPA. We propose to realign power consumption traces according timing information (i.e., path delays). We show the usefulness of the proposed method by comparing the efficiency of classic DPA w.r.t. timing aware DPA. Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre, Miroslav Valka, Denis Réal |
DDECS | 1 |
| 2011 | Scan Attacks and Countermeasures in Presence of Scan Response CompactorsabstractThe conflict between security and testability is still a concern of hardware designers. While secure devices must protect confidential information from unauthorized users, quality testing of these devices requires the controllability and observability of a substantial quantity of embedded information, and thus may jeopardize the data confidentiality. Several attacks using the test infrastructures (and in particular scan chains) have been described. More recently it has been shown how test response compaction structures provide a natural counter-measure against this type of attack. However, in this paper, we show that even in the presence of response compactors the scan-based attack is still possible and it requires low complexity computation. We then give some perspectives concerning the techniques that can be used to increase the scan-based attack complexity without affecting the testability of the device.1 Jean DaRolt, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
ETS | 2 |
| 2010 | Ensuring high testability without degrading security: Embedded tutorial on "test and security"abstractCryptographic algorithms are used to protect sensitive information when the communication medium is not secure. Unfortunately, the hardware implementation of these cryptographic algorithms allows secret key retrieval using different forms of attacks based on the observation of key-related information: physical information (side-channel attacks), faulty behaviors (fault-based attacks), or internal states (DFT-based attacks) for instance. Dedicated design for security techniques have been proposed so far, ranging from the development of specific cell libraries to the implementation of extra functions for preventing the leakage of useful information for key identification. On the other hand, users can expect high quality product for secure applications and this expectation requires the development of test solutions for every component of the secure device. However, testing those devices faces a double dilemma: (i) how to test and, possibly, develop design-for-testability schemes providing high testability (high controllability/observability) while maintaining high security (no leakage), (ii) how to provide high security using dedicated design rules while maintaining high testability. This tutorial will address these issues presenting the security weaknesses generated by classical DFT techniques, pros and cons of security-dedicated DFT, BIST and Fault tolerance solutions, and impact of design for security techniques on testability. Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
DDECS | 1 |
| 2010 | Evaluation of concurrent error detection techniques on the Advanced Encryption StandardabstractIn nowadays technologies, circuits are more and more sensitive to aging phenomenon, as well as soft errors. Furthermore several attacks that used a fault to derive secret information have been demonstrated on cryptosystems. Concurrent fault detection is thus of prime interest for such systems. The purpose of this paper is to compare several code-based concurrent fault detection schemes dedicated to the hardware implementation of the Advanced Encryption Standard. The protection schemes under comparison are either directly issued from the literature, or built from several complementary solutions for protection of the full implementation. The evaluation of these schemes is performed in terms of costs with particular emphasis on fault injection vs errors detection capabilities. Kaouthar Bousselam, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
ETS | 2 |
| 2010 | Evaluation of concurrent error detection techniques on the advanced encryption standardabstractDue to the shrinking of transistors dimensions in nowadays technologies, circuits are more and more sensitive to aging phenomenon, as well as soft errors. Furthermore cryptographic circuits are prone to fault attacks, which intend to retrieve secret data by mean of fault injection. Thus, concurrent fault detection is of prime interest for such crypto devices. The purpose of this paper is to compare several concurrent fault detection schemes dedicated to the hardware implementation of the advanced encryption standard. The schemes under comparison are directly issued from the literature or built from several complementary solutions. The evaluation of these schemes is performed in terms of costs and performance with particular emphasis on errors vs faults detection capabilities. Kaouthar Bousselam, Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
IOLTS | 2 |
| 2010 | Self-Test Techniques for Crypto-DevicesabstractThis paper describes a generic built-in self-test strategy for devices implementing symmetric encryption algorithms. Taking advantage of the inner iterative structures of crypto-cores, test facilities are easily set-up for circular self-test of the crypto-cores, built-in pseudorandom test generation and response analysis for other cores in the host device. Main advantages of the proposed test implementation are an architecture with no visible scan chain, 100% fault coverage on crypto-cores with negligible area overhead, availability of pseudorandom test sources, and very low aliasing response compaction for other cores. Giorgio Di Natale, M. Doulcier, Marie-Lise Flottes, Bruno Rouzeyre |
IEEE Trans. Very Large Scale Integr. Syst. | 1 |
| 2009 | A Reliable Architecture for Parallel Implementations of the Advanced Encryption Standard
Giorgio Di Natale, M. Doulcier, Marie-Lise Flottes, Bruno Rouzeyre |
J. Electron. Test. | 1 |
| 2008 | LIFTING: A Flexible Open-Source Fault SimulatorabstractThis paper presents LIFTING (LIRMM fault simulator), an open-source simulator able to perform both logic and fault simulations for single/multiple stuck-at faults and single event upset (SEU) on digital circuits described in Verilog. Compared to existing tools, LIFTING provides several features for the analysis of the fault simulation results, meaningful for research purposes. Moreover, as an open-source tool, it can be customized to meet any user requirements. Experimental results show how LIFTING has been exploited on research fields. Eventually, execution time for large circuit simulations is comparable to the one of commercial tools. Alberto Bosio, Giorgio Di Natale |
ATS | 2 |
| 2008 | On-Line Instruction-Checking in Pipelined MicroprocessorsabstractMicroprocessors performances have increased by more than five orders of magnitude in the last three decades. As technology scales down, these components become inherently unreliable posing major design and test challenges. This paper proposes an instruction-checking architecture to detect erroneous instruction executions caused by both permanent and transient errors in the internal logic of a microprocessor. Monitoring the correct activation sequence of a set of predefined microprocessor control/status signals allow distinguishing between correctly and not correctly executed instructions. Stefano Di Carlo, Giorgio Di Natale, Riccardo Mariani |
ATS | 2 |
| 2008 | A Reliable Architecture for the Advanced Encryption StandardabstractIn this paper we propose an on-line self-test architecture for hardware implementations of advanced encryption standard (AES). The solution assumes a parallel architecture and exploits the inherent spatial replications of this implementation. We show that our solution is very effective for on-line fault detection while keeping the area overhead very low. Moreover, it does not weak the device with respect to side-channel attacks based on power analysis. Giorgio Di Natale, M. Doulcier, Marie-Lise Flottes, Bruno Rouzeyre |
ETS | 1 |
| 2008 | A Modular Memory BIST for Optimized Memory RepairabstractAn efficient on-chip infrastructure for memory test and repair is crucial to enhance yield and availability of SoCs. Most of the existing built-in self-repair solutions reuse IP-Cores for BIST without modifications. However, this prevents an optimized test and repair interaction. In this paper, the concept of modular BIST for memories is introduced, which supports a more efficient interleaving of test and repair and can be achieved with only small modifications in the BIST control. Philipp Öhler, Alberto Bosio, Giorgio Di Natale, Sybille Hellebrand |
IOLTS | 3 |
| 2008 | March Test Generation RevealedabstractMemory testing commonly faces two issues: the characterization of detailed and realistic fault models, and the definition of time-efficient test algorithms to detect them. March tests have proven to be a fast, simple and regularly structured class of memory test algorithms. This paper proposes a new polynomial algorithm to automatically generate march tests. The formal model adopted to represent memory faults allows the definition of a general methodology to deal with both static, dynamic and linked faults. Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
IEEE Trans. Computers | 4 |
| 2007 | Analysis of System-Failure Rate Caused by Soft-Errors using a UML-Based Systematic Methodology in an SoCabstractThis paper proposes an analytical method to assess the soft-error rate (SER) in the early stages of a System-on-Chip (SoC) platform-based design methodology. The proposed method gets an executable UML (Unified Modeling Language) model of the SoC and the raw softerror rate of different parts of the platform as its inputs. Soft-errors on the design are modeled by disturbances on the value of attributes in the classes of the UML model and disturbances on opcodes of software cores. The Dynamic behavior of each core is used to determine the propagation probability of each variable disturbance to the core outputs. Furthermore, the SER and the execution time of each core in the SoC and a Failure Modes and Effects Analysis (FMEA) that determines the severity of each failure mode in the SoC are used to compute the System-Failure Rate (SFR) of the SoC. Mohammad Hosseinabady, Mohammad Hossein Neishaburi, Zainalabedin Navabi, Alfredo Benso, Stefano Di Carlo, Paolo Prinetto, Giorgio Di Natale |
IOLTS | 7 |
| 2007 | An On-Line Fault Detection Scheme for SBoxes in Secure CircuitsabstractIn this paper we propose an on-line fault detection architecture for bijective Substitution Boxes used in cryptographic circuits. Concurrent fault detection is important not only to protect the encryption/decryption process from random and production faults, it also protects the system against side-channel attacks, in particular those based on fault injection. We will prove that our solution is very effective while keeping the area overhead very low. Besides, we will analyze the correlation between the information processed by the circuit and the power consumption in order to asses the quality of the solution with respect to other side- channel attacks such as Power Analysis techniques. Giorgio Di Natale, Marie-Lise Flottes, Bruno Rouzeyre |
IOLTS | 1 |
| 2006 | Memory Fault Simulator for Static-Linked FaultsabstractStatic linked faults are considered an interesting class of memory faults. Their capability of influencing the behavior of other faults causes the hiding of the fault effect and makes test algorithm design and validation a very complex task. This paper presents a memory fault simulator architecture targeting the full set of linked faults Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
ATS | 4 |
| 2006 | ATPG for Dynamic Burn-In Test in Full-Scan CircuitsabstractYield and reliability are two key factors affecting costs and profits in the semiconductor industry. Stress testing is a technique based on the application of higher than usual levels of stress to speed up the deterioration of electronic devices and increase yield and reliability. One of the standard industrial approaches for stress testing is high temperature burn-in. This work proposes a full-scan circuit ATPG for dynamic burn-in. The goal of the proposed ATPG approach is to generate test patterns able to force transitions into each node of a full scan circuit to guarantee a uniform distribution of the stress during the dynamic burn-in test Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
ATS | 4 |
| 2006 | Automatic march tests generations for static linked faults in SRAMsabstractStatic linked faults are considered an interesting class of memory faults. Their capability of influencing the behavior of other faults causes the hiding of the fault effect and makes test algorithm design a very complex task. A large number of March tests with different fault coverage have been published and some methodologies have been presented to automatically generate March tests. In this paper we present an approach to automatically generate March tests for static linked faults. The proposed approach generates better test algorithms then previous, by reducing the test length Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
DATE | 4 |
| 2006 | A 22n March Test for Realistic Static Linked Faults in SRAMsabstractLinked faults are considered an interesting class of memory faults. Their capability of influencing the behavior of other faults causes the hiding of the fault effect and makes test algorithm design a very complex task. Although several March tests have been developed for the wide memory faults spread, a few of them are able to detect linked faults. In the present paper March AB, a March test targeting the set of realistic memory linked fault is presented. Comparison results show that the proposed March test provides the same fault coverage of already published algorithms but, it reduces the test complexity and therefore the test time. Moreover, a complete taxonomy of linked faults will be presented Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
ETS | 4 |
| 2006 | Single-Event Upset Analysis and Protection in High Speed CircuitsabstractThe effect of single-event transients (SETs) (at a combinational node of a design) on the system reliability is becoming a big concern for ICs manufactured using advanced technologies. An SET at a node of combinational part may cause a transient pulse at the input of a flip-flop and consequently is latched in the flip-flop and generates a soft-error. When an SET conjoined with a transition at a node along a critical path of the combinational part of a design, a transient delay fault may occur at the input of a flip-flop. On the other hand, increasing pipeline depth and using low power techniques such as multi-level power supply, and multi-threshold transistor convert almost all paths in a circuit to critical ones. Thus, studying the behavior of the SET in these kinds of circuits needs special attention. This paper studies the dynamic behavior of a circuit with massive critical paths in the presence of an SET. We also propose a novel flip-flop architecture to mitigate the effects of such SETs in combinational circuits. Furthermore, the proposed architecture can tolerant a single event upset (SEU) caused by particle strike on the internal nodes of a flip-flop Mohammad Hosseinabady, Pejman Lotfi-Kamran, Giorgio Di Natale, Stefano Di Carlo, Alfredo Benso, Paolo Prinetto |
ETS | 3 |
| 2005 | Automatic March tests generation for static and dynamic faults in SRAMsabstractNew memory production modern technologies introduce new classes of faults usually referred to as dynamic memory faults. Although some hand-made March tests to deal with these new faults have been published, the problem of automatically generate March tests for dynamic faults has still to be addressed, in this paper we propose a new approach to automatically generate March tests with minimal length for both static and dynamic faults. The proposed approach resorts to a formal model to represent faulty behaviors in a memory and to simplify the generation of the corresponding tests. Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
ETS | 4 |
| 2005 | March AB, March AB1: new March tests for unlinked dynamic memory faultsabstractAmong the different types of algorithms proposed to test static random access memories (SRAMs), March tests have proven to be faster, simpler and regularly structured. New memory production technologies introduce new classes of faults usually referred to as dynamic memory faults. A few March tests for dynamic fault, with different fault coverage, have been published. In this paper, we propose new March tests targeting unlinked dynamic faults with lower complexity than published ones. Comparison results show that the proposed March tests provide the same fault coverage of the known ones, but they reduce the test complexity, and therefore the test time. Alfredo Benso, Alberto Bosio, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
ITC | 4 |
| 2003 | Exhaustive Test of Several Dependable Memory Architectures Designed by GRAAL ToolabstractThis paper presents a customizable injection fault system and performance evaluations of dependable memory collars designed by GRAAL tool. The novelty consists in a large number of tests and architecture comparisons which can demonstrate the efficiency and validity of GRAAL and how it helps the designer to experiment the architecture sensitivity and evaluate changes in performances when a particular dependable memory collar is chosen or bypassed. Moreover, a complete test set-tip and real case study where the memory interacts in a complex system is described The system collects information to measure the effects of fault detection and fault tolerance. The hardware is assembled in a configurable test board with a FPGA where are one of several memory wrapper which GRAAL generates and a serial link to receive and send data from an acquisition system. Two commercial Personal Computers interact thought the boards and collect data from the experiment. Fabrizio Bertuccelli, Franco Bigongiari, Andrea S. Brogna, Giorgio Di Natale, Paolo Prinetto, Roberto Saletti |
Asian Test Symposium | 4 |
| 2003 | A Watchdog Processor to Detect Data and Control Flow ErrorsabstractA watchdog processor for the MOTOROLA M68040 microprocessor is presented. Its main task is to protect from transient faults caused by SEUs the transmission of data between the processor and the system memory, and to ensure a correct instructions' flow, just monitoring the external bus, without modifying the internal architecture of the M68040. A description of the principal procedures is given, together with the method used for monitoring the instructions' flow. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
IOLTS | 3 |
| 2003 | FAUST: FAUlt-injection Script-based ToolabstractThe tool described in this paper aims at evaluating the effectiveness of software-implemented fault-tolerant techniques used in safety-critical systems. The target application is stressed with the injection of transient or permanent faults. The user can therefore observe the real behaviour of the application in presence of a fault, and, if necessary, take the appropriate countermeasures. The accent is put on the extreme easiness of the use and the portability on all UNIX platforms. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto, I. Solcia, Luca Tagliaferri |
IOLTS | 3 |
| 2003 | Data Critically Estimation In Software ApplicationsabstractIn safety-critical applications it is often possible to exploit software techniques to increase system's fault- tolerance. Common approaches are based on data redundancy to prevent data corruption during the software execution. Duplicating most critical variables only can significantly reduce the memory and performance overheads, while still guaranteeing very good results in terms of fault-tolerance improvement. This paper presents a new methodology to compute the criticality of variables in target software applications. Instead of resorting to time consuming fault injection experiments, the proposed solution is based on the run- time analysis of the variables' behavior logged during the execution of the target application under different workloads. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto, Luca Tagliaferri |
ITC | 3 |
| 2002 | Specification and Design of a New Memory Fault SimulatorabstractThis paper presents a new fault simulator architecture for RAM memories. The key features of the proposed tool are: (1) user-definable fault models, test algorithm, and memory architecture; (2) very fast simulation algorithm; (3) ability to compute the coverage of any provided test sequence with respect to a user-defined set of fault models, and to eliminate redundant operations; (4) assessment of the power consumption generated by the test application. Moreover, the tool is able to modify the test algorithm in order to guarantee the compliance to user-defined power consumption constraints. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
Asian Test Symposium | 3 |
| 2002 | An Optimal Algorithm for the Automatic Generation of March TestsabstractAmong the different types of algorithms proposed to test random access memories (RAM), March tests have proven to be faster, simpler, regularly structured and linear in complexity. A March test consists of a sequence of March elements, each composed of a sequence of basic read/write operations to be performed on each cell of the memory, in either ascending or descending order, before proceeding to the next memory cell. The complexity of a March test is given by the number of memory operations in all March elements performed on each memory cell. This paper presents an innovative algorithm for the automatic generation of March tests. The proposed approach is able to generate an optimal March test for an unconstrained set of memory faults in very low computation time. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
DATE | 3 |
| 2002 | Static Analysis of SEU Effects on Software ApplicationsabstractControl flow errors have been widely addressed in literature as a possible threat to the dependability of computer systems, and many clever techniques have been proposed to detect and tolerate them. Nevertheless, it has never been discussed if the overheads introduced by many of these techniques are justified by a reasonable probability of incurring control flow errors. This paper presents a static executable code analysis methodology able to compute, depending on the target microprocessor platform, the upper-bound probability that a given application incurs in a control flow error. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
ITC | 3 |
| 2002 | An on-line BIST RAM architecture with self-repair capabilitiesabstractThe emerging field of self-repair computing is expected to have a major impact on deployable systems for space missions and defense applications, where high reliability, availability, and serviceability are needed. In this context, RAM (random access memories) are among the most critical components. This paper proposes a built-in self-repair (BISR) approach for RAM cores. The proposed design, introducing minimal and technology-dependent overheads, can detect and repair a wide range of memory faults including: stuck-at, coupling, and address faults. The test and repair capabilities are used on-line, and are completely transparent to the external user, who can use the memory without any change in the memory-access protocol. Using a fault-injection environment that can emulate the occurrence of faults inside the module, the effectiveness of the proposed architecture in terms of both fault detection and repairing capability was verified. Memories of various sizes have been considered to evaluate the area-overhead introduced by this proposed architecture. Alfredo Benso, Silvia Chiusano, Giorgio Di Natale, Paolo Prinetto |
IEEE Trans. Reliab. | 3 |
| 2001 | Memory Read Faults: Taxonomy and Automatic Test GenerationabstractThis paper presents an innovative algorithm for the automatic generation of March tests. The proposed approach is able to generate an optimal March test for an unconstrained set of memory faults in very low computation time. Moreover, we propose a new complete taxonomy for memory read faults, a class of faults never carefully addressed in the past. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
Asian Test Symposium | 3 |
| 2001 | Control-Flow Checking via Regular ExpressionsabstractThe present paper explains a new approach to program control flow checking. The check has been inserted at source-code level using a signature methodology based on regular expressions. The signature checking is performed without a dedicated watchdog processor but resorting to inter-process communication (IPC) facilities offered by most of the modern operating systems. The proposed approach allows very low memory overhead and trade-off between fault latency and program execution time overhead. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto, Luca Tagliaferri |
Asian Test Symposium | 3 |
| 2001 | SEU effect analysis in an open-source router via a distributed fault injection environmentabstractThe paper presents a detailed error analysis and classification of the behavior of an open-source router when affected by Single Event Upsets (SEUs). The experimental results have been gathered on a real communication network, resorting to an ad-hoc Fault Injection system. The injector has been designed to corrupt the router during its normal service and to analyze the SEU injection effects on the overall distributed system. The performed experiments allowed the authors to identify the most critical memory regions and to cluster the router variables according to their impact on system dependability. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto |
DATE | 3 |
| 2001 | GRAAL: a tool for highly dependable SRAMs generationabstractPresents a tool to achieve proper reliability levels in systems based on memories, allowing the automatic insertion of BIST architectures for both OFF-line and ON-line memory testing. While OFF-line memory testing was partially targeted by the available commercial tools, ON-line memory testing has so far not been covered. The set of algorithms and architectures supported by the tool is not limited, and it can be easily extended to include innovative architectures and achieve the reliability requirements in any application. Using the tool, the designer can generate dependable memories, trading-off in the design process dependability properties and costs. Silvia Chiusano, Giorgio Di Natale, Paolo Prinetto, Franco Bigongiari |
ITC | 2 |
| 2000 | A programmable BIST architecture for clusters of multiple-port SRAMsabstractThis paper presents a BIST architecture, based on a single microprogrammable BIST processor and a set of memory wrappers, designed to simplify the test of a system containing many distributed multi-port SRAMs of different sizes (number of bits, number of words), access protocol (asynchronous, synchronous), and timing. Alfredo Benso, Stefano Di Carlo, Giorgio Di Natale, Paolo Prinetto, Monica Lobetti Bodoni |
ITC | 3 |