Ming Tang 0002

dblp:73/4373-2 · DBLP profile ↗
← Back
40ranked-venue papers
8as first author
22since 2021 · last 2025
0000-0003-2218-0164ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 18 · 4 first-author · 11 since 2021Security and privacy · 13 · 1 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-authorComputer networks · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 BranchGauge: Modeling and Quantifying Side-Channel Leakage in Randomization-Based Secure Branch Predictors
Quancheng Wang, Ming Tang 0002, Han Wang 0057
AsiaCCS2
2025 ZenLeak: Practical Last-Level Cache Side-Channel Attacks on AMD Zen Processors
abstract
While Last-Level Cache (LLC) side-channel attacks often target inclusive caches, directory-based attacks on noninclusive caches have been demonstrated on Intel and ARM processors. However, the vulnerability of AMD’s non-inclusive caches to such attacks has remained uncertain, primarily due to challenges in reverse-engineering cache addressing, constructing eviction sets, and evicting private cache lines. This paper addresses these challenges and demonstrates the feasibility of conducting LLC side-channel attacks on AMD’s non-inclusive caches. We first reverse-engineer the cache addressing functions for the L2 set index, L3 slice, and L3 set index. Leveraging this insight, we construct the first eviction sets on AMD processors. We then introduce the first LLC sidechannel attack on AMD’s Zen series CPUs. The effectiveness of our approach is validated by attacking OpenSSL’s AES T-table.
Han Wang 0057, Ming Tang 0002, Quancheng Wang, Yinqian Zhang
DAC2
2025 New First-Order Secure AES Implementation Without Online Fresh Randomness Records
Ming Tang 0002
ICICS (1)2
2025 Unveiling and Evaluating Vulnerabilities in Branch Predictors via a Three-Step Modeling Methodology
abstract
With the emergence and proliferation of microarchitectural attacks targeting branch predictors, the once-established security boundary in computer systems and architectures is facing unprecedented challenges. This article introduces an innovative branch predictor modeling methodology that abstractly characterizes 19 states and 53 operations of branch predictors, aiming to assist hardware designers in addressing overlooked security concerns during the microarchitecture design phase. Building upon this modeling discipline, we develop a symbolic execution-based framework to analyze and derive potential vulnerabilities in branch predictors. This framework finally yields 156 valid three-step attack patterns against branch predictors, including 89 novel variants not discovered in previous work. Subsequently, we extend the framework to automatically generate a benchmark suite for assessing the practical feasibility of derived attacks in real-world scenarios. Evaluation across five commercial Intel processors underscores the substantial threat posed by branch predictor attacks, with 130 of the 156 derived attacks proving viable on at least one processor. Finally, we theoretically model and evaluate 12 secure designs related to branch predictors. The evaluation results demonstrate that existing secure branch predictors can offer better security guarantees than secure speculation schemes, indicating that secure branch predictor designs are promising solutions to maintain the confidentiality and integrity of computer systems.
Quancheng Wang, Ming Tang 0002, Han Wang 0057
ACM Trans. Archit. Code Optim.2
2025 Microarchitectural Attacks and Mitigations on Retire Resources in Modern Processors
abstract
In modern processors, the Retire Control Unit (RCU) is responsible for receiving the µops decoded from the frontend and retiring the completed µops in order through the retirement. Consequently, the retirement may stall differently depending on the execution time of the first instruction in the RCU, causing varying stalling in the RCU reception. Moreover, We find that the RCU reception in AMD processors and retirement in Intel processors are shared between two logical cores of the same physical core, allowing an attacker to infer the instructions executed by another logical core based on its retire resources efficiency. Based on these findings, we introduce the retirement covert channel on Intel processors and the RCU covert channel on AMD processors. Furthermore, we explores additional applications of retire resources. On the one hand, we combined the misprediction penalty mechanism to apply our covert channels to the Spectre attacks. On the other hand, based on the principle that different programs result in varied usage patterns of retire resources, we propose an attack method that leverages the retire resources to infer the program run by the victim. Finally, we design the corresponding mitigations and extend our mitigation to fetch unit to reduce the performance overhead.
Ming Tang 0002, Quancheng Wang, Han Wang 0057
IEEE Trans. Computers2
2025 ESM: A Plug-in Power Side Channel Shuffling Protection for Scalar Processors
abstract
Hiding is a protection method against power side channel attacks on processor chips. Compared to masking, hiding has less area and time overhead. Existing hiding schemes usually have to identify the instructions which need protection to change their execution moments. This makes these efforts problematic in that 1) these hiding schemes need extension of the ISA and modification of the compiler, 2) large changes to the original microarchitecture, and 3) protection targets limited to cryptographic algorithms and the corresponding arithmetic instructions. In this work, we design a plug-in shuffling protection called external shuffling module (ESM), between the front-end and the back-end of the processor based on the instructions which can change the order of execution in program segments. By constructing an instruction dependency table, the order in which instructions are executed each time is changed within the processor, thus avoiding modifications to the compiler. ESM receives all signals from the front-end and forwards them to the back-end through internal processing, without the need for any other components in the microarchitecture. This allows ESM to be started and stopped at any time and applied to different microarchitectures. ESM applies protection to all instructions flowing through it. On the SAKURA-GIII board, we implement ESM on a RISC-V processor. When the processor is able to counter an multilayered perceptron-based power attack of 1 million training traces, ESM requires an additional 1.23% area overhead as well as 12.12% time overhead.
Yao Zhang 0015, Ming Tang 0002
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2025 LD-PA: Distilling Univariate Leakage for Deep Learning-Based Profiling Attacks
abstract
The deep learning-based profiling attacks have received significant attention for their potential against masking-protected devices. Currently, additional capabilities like exploiting only a segment of the side-channel traces or having knowledge of the specific countermeasure scheme have been granted to attackers during the profiling phase. In case either capability is removed, a practical profiling attack faces great difficulty and complexity. To address this challenge, we propose an efficient and scheme-agnostic Leakage Distillation-based Profiling Attack (LD-PA). By distilling univariate leakage from a reference, we can train an encoder that extracts multivariate leakage from raw traces and transforms it into an effective representation (transitional leakage). An indirect connection between multivariate leakage and the target variable is established by bridging through the transitional leakage, thereby facilitating the inference of leaked values. Remarkably, LD-PA achieves successful attacks on multiple public datasets using a simple multilayer perceptron (MLP) without necessitating an exhaustive hyperparameter search, while its performance is competitive with state-of-the-art methods. Simultaneously, we delve into the nature of transitional leakage, confirming the existence of combined leakage. This, in turn, validates that the guidance from univariate leakage references aids in the combination of multivariate leakage. Besides that, each component of the multivariate leakage is extracted and stacked in a highly aligned manner. Moreover, we explored several factors impacting LD-PA performance, covering scenarios with limited profiling traces, noisy references, alternative references, and hyperparameter tuning.
Chong Xiao, Ming Tang 0002, Sengim Karayalcin, Wei Cheng 0003
IEEE Trans. Inf. Forensics Secur.2
2024 Cache Bandwidth Contention Leaks Secrets
abstract
In the modern CPU architecture, enhancements such as the Line Fill Buffer (LFB) and Super Queue (SQ), which are designed to track pending cache requests, have significantly boosted performance. To exploit this structure, we deliberately engineered blockages in the L2 to L1d route by controlling LFB conflict and triggering prefetch prediction failures, while consciously dismissing other plausible influencing factors. This approach was subsequently extended to the L3 to L2 and L2 to Lli pathways, resulting in three potent covert channels, termed L2CC, L3CC, and LiCC, with capacities of 10.02 Mbps, 10.37 Mbps, and 1.83 Mbps, respectively. Strikingly, the capacities of L2CC and L3CC surpass those of earlier non-shared-memory-based covert channels, reaching a level comparable to their shared memory-dependent equivalents. Leveraging this congestion further facilitated the extraction of key bits from RSA and EdDSA designs. Coupled with Spectre V1 and V2, our covert channels effectively evade the majority of traditional Spectre defenses. Their confluence with Branch Prediction (BP) Timing assaults additionally undercuts balanced branch protections, hence broadening their capability to infiltrate a wide range of cryptography libraries.
Han Wang 0057, Ming Tang 0002, Quancheng Wang
DATE2
2024 Modeling, Derivation, and Automated Analysis of Branch Predictor Security Vulnerabilities
abstract
With the intensification of microarchitectural side-channel attacks targeting branch predictors, the security boundary of computer systems and users' security-critical data are under serious threat. Since the root cause of these attacks is the neglect of security issues in the microarchitecture design of branch predictors, an analysis framework that can exhaustively and automatically explore these concerns in the design phase is imminent. In this paper, we propose a comprehensive and automated evaluation framework for inspecting the security guarantees of branch predictors at the microarchitecture design stage. Our technique involves a three-step modeling approach that abstractly characterizes 19 branch predictor states and 53 operations that could affect these states. Subsequently, we develop a symbolic execution-based framework to investigate all three-step combinations and derive 156 valid attack patterns against branch predictors, including 89 novel attacks never considered in the previous work. Finally, we apply our framework to 8 secure branch predictor designs and four typical hardware-based countermeasures against speculative execution attacks to evaluate their security capabilities. The result demonstrates that these security branch predictors provide efficient security guarantees and outperform those hardware-based alleviations against speculative execution attacks, indicating that the security branch predictors are promising in mitigating branch predictor security vulnerabilities.
Quancheng Wang, Ming Tang 0002, Han Wang 0057
HPCA2
2024 Exploitation of Security Vulnerability on Retirement
abstract
The backend of the processor executes the μops decoded from the frontend out of order, while the retirement is responsible for retiring completed μops in the Reorder Buffer in order. Consequently, the retirement may stall differently depending on the execution time of the first instruction in the Reorder Buffer. Moreover, since retirement is shared between two logical cores on the same physical core, an attacker can deduce the instructions executed on the other logical core by observing the availability of its own retirement. Based on this finding, we introduce two novel covert channels: the Different Instructions covert channel and the Same Instructions covert channel, which can transmit information across logical cores and possess the ability to bypass the existing protection strategies. Furthermore, this paper explores additional applications of retirement. On the one hand, we propose a new variant of Spectre v1 by applying the retirement to the Spectre attack using the principle that the fallback penalty of misprediction is related to the instructions speculated to be executed. On the other hand, based on the principle that different programs result in varied usage patterns of retirement, we propose an attack method that leverages the retirement to infer the program run by the victim. Finally, we discuss possible mitigations against new covert channels.
Ming Tang 0002, Quancheng Wang, Han Wang 0057
HPCA2
2024 MS-LW-TI: Primitive-Based First-Order Threshold Implementation for 4 × 4 S-boxes
abstract
Threshold implementation (TI) is a lightweight countermeasure against side‐channel attacks when glitches happen. As to masking schemes, an S‐box is the key part to protection. In this paper, we propose a general first‐order lightweight TI scheme for 4 × 4 S‐boxes and name it as MiniSat‐lightweight‐threshold implementation (MS‐LW‐TI). First, we use MiniSat to optimally decompose an S‐box into the least number of three different logic gate operations, AND, OR, and XOR. Among these operations, we define two primitives and the extension of two primitives for TI design. Furthermore, we prove that the primitives and their extensions strictly comply with the security properties. Finally, we implement MS‐LW‐TI on Xilinx Spartan‐6 Field Programmable Gate Array (FPGA) to show that the S‐boxes of PRESENT, GIFT, and PICCOLO consume only 17, 15, and 13 look‐up‐tables (LUTs), 16, 9, and 16 flip‐flops (FFs), 6, 5, and 6 slices, respectively. Compared with the existing lightweight TI design, our TI for PRESENT S‐box has a 22%, 38%, and 25% reduction of LUTs, FFs, and slices to the design by Shahmirzadi and Moradi at IACR Transactions on Cryptographic Hardware and Embedded Systems (TCHES) 2021, and our TI for GIFT S‐box has a 6%, 25%, and 28% reduction of LUTs, FFs, and slices to the design by Jati et al., which is the smallest.
Ming Tang 0002
IET Inf. Secur.2
2024 EavesDroid: Eavesdropping User Behaviors via OS Side Channels on Smartphones
abstract
As the Internet of Things (IoT) continues to evolve, smartphones have become essential components of IoT systems. However, with the increasing amount of personal information stored on smartphones, user privacy is at risk of being compromised by malicious attackers. Although malware detection engines are commonly installed on smartphones against these attacks, attacks that can evade these defenses may still emerge. In this article, we analyze the return values of system calls on Android smartphones and find two never-disclosed vulnerable return values that can leak fine-grained user behaviors. Based on this observation, we present EavesDroid, an application-embedded side-channel attack on Android smartphones that allows unprivileged attackers to accurately identify fine-grained user behaviors (e.g., viewing messages and playing videos) via on-screen operations. Our attack relies on the correlation between user behaviors and the return values associated with hardware and system resources. While this attack is challenging since these return values are susceptible to fluctuation and misalignment caused by many factors, we show that attackers can eavesdrop on fine-grained user behaviors using a CNN-GRU classification model that adopts min–max normalization and multiple return value fusion. Our experiments on different models and versions of Android smartphones demonstrate that EavesDroid can achieve 98% and 86% inference accuracy for 17 classes of user behaviors in the test set and real-world settings, highlighting the risk of our attack on user privacy. Finally, we recommend effective malware detection, carefully designed obfuscation methods, or restrictions on reading vulnerable return values to mitigate this attack.
Quancheng Wang, Ming Tang 0002, Jianming Fu
IEEE Internet Things J.2
2024 Deep Learning Gradient Visualization-Based Pre-Silicon Side-Channel Leakage Location
abstract
While side-channel attacks (SCAs) have become a significant threat to cryptographic algorithms, masking is considered as an effective countermeasure against SCAs. On the one hand, securely implementing the scheme is a challenging and error-prone task. It is essential to detect leakage in a complicated cryptographic circuit. However, the traditional method of leakage detection is always inaccuracy or time consumption. On the other hand, the deep learning-based power attacks have shown their threat to the masking without combining functions. Compared to the leakage detection done under the traditional provable security framework, the security evaluation against deep learning-based attacks at the pre-silicon stage has not been discussed. To this end, this paper investigates the strategies of leveraging the deep learning techniques to achieve an efficient leakage location method. In this paper, we present the first approach utilizing deep learning-based leakage location for both unprotected and protected implementations at the pre-silicon stage. Firstly, we propose the leakage location method named Gradient Visualization-based location (GVL), which provides leakage location at the different levels of design. Gradient visualization is known as a sensitivity analysis method to understand better how a natural network can learn to predict the sensitive label based on the input. We theoretically show how the gradient visualization can be used to locate leakage components in the netlist efficiently. Moreover, we link the result with the metric in deep learning-based leakage assessment, which fills the lack of leakage evaluation at the pre-silicon stage against deep learning-based SCAs. We further confirm the effectiveness of the proposed method on unprotected implementation, low entropy masked implementation, and provable secure masked implementation. The results show that the proposed methodology outperforms the traditional location methods in the masked cases, where the time consumption is reduced by about 2x to 10x with fewer false negatives and no false positives.
Yanbin Li 0001, Zhe Liu 0001, Ming Tang 0002, Shougang Ren
IEEE Trans. Inf. Forensics Secur.4
2023 One more set: Mitigating conflict-based cache side-channel attacks by extending cache set
Yuzhe Gu, Ming Tang 0002, Quancheng Wang, Han Wang 0057, Haili Ding
J. Syst. Archit.2
2023 Exploiting the microarchitectural leakage of prefetching activities for side-channel attacks
Chong Xiao, Ming Tang 0002, Sylvain Guilley
J. Syst. Archit.2
2023 Reverse-Engineering and Exploiting the Frontend Bus of Intel Processor
abstract
The frontend of modern Intel processors will decode instructions into$\mu$ops and stream them to the backend by the frontend bus, which is shared between two logical cores to maximize utilization without sharing mechanism fully disclosed. Taking Haswell as an example, we reverse the bus from Decoded ICache to Instruction Decode Queue and the bus from Instruction Decode Queue to backend. We find that they are dynamically shared between two logical cores, which makes it possible for observable timing differences in one another through different instructions. Based on these differences, we propose the Synthetical bus covert channel for LSD-enabled architectures like Haswell and the DI bus covert channel for LSD-disabled architectures like Cometlake. We test our covert channels in physical machines and virtual machines. The bandwidth of Synthetical bus covert channel achieves 870 Kbps with 95.69% accuracy in physical machines and 145 Kbps with 92.83% accuracy in virtual machines. The bandwidth of DI bus covert channel reaches 1450 Kbps with 97.2% accuracy in physical machines and 70.33 Kbps with 92.3% accuracy in virtual machines. We further demonstrate a new Spectre variant. Finally, we propose two possible mitigations against our covert channels due to the limitations of existing protection strategies.
Ming Tang 0002, Han Wang 0057, Sylvain Guilley
IEEE Trans. Computers2
2022 TSCL: A time-space crossing location for side-channel leakage detection
Yanbin Li 0001, Ming Tang 0002, Shougang Ren, Fusheng Wu
Comput. Networks3
2022 The Levene test based-leakage assessment
Ming Tang 0002
Integr.2
2022 Gap between Prediction and Truth: A Case Study of False-Positives in Leakage Detection
abstract
Since leakage detection was introduced as a popular side-channel security assessment, it has been plagued by false-positives (a.k.a. type I errors). To fix this error, the previous solutions set detection thresholds based on an assumption-based prediction of false-positive rate (FPR). However, this study points out that such a prediction (of FPR) may be inaccurate. We notice that the prediction in EuroCrypt2016 is much smaller than (approximately 1 / 779 times) the true FPR. The gap between prediction and truth, called underpredicted false-positives (UFP), leads to severe false-positives in leakage detection. Then, we check the statistical distribution of test statistics to analyze the cause of UFP. Our analysis indicates that the overlap between cross-validation (CV) blocks gives rise to an assumption error in the distribution of the CV-based estimates of ρ -statistics, which is the root cause of UFP. Therefore, we tackle the UFP by eliminating the overlap between blocks. Specifically, we propose a profiling-shared validation (PSV) and utilize this validation to improve the detection of any-variate any-order leakages. Our experiments show that the PSV solves the UFP and saves more than 75% of the test time costs. In summary, this article reports a potential flaw in leakage detection and provides a complete analysis of the flaw for the first time.
Ming Tang 0002, Shoukun Xiang
Secur. Commun. Networks2
2021 Adaptive Chosen Plaintext Side-Channel Attacks for Higher-Order Masking Schemes
Yanbin Li 0001, Ming Tang 0002, Shougang Ren, Huanliang Xu
WASA (2)3
2021 Process Variation-Resistant Golden-Free Hardware Trojan Detection through a Power Side Channel
abstract
With the globalization of the manufacturing supply chain, the malicious modification existing in the middle of distrust is becoming an important security issue on the chip. These modifications are called hardware Trojan (HT). HT is difficult to detect due to its high concealment and diversity of implementation. HT detection based on the side channel is a relatively effective detection method because it does not need to trigger the Trojan or destroy the chip. However, detection based on the side channel faces two major challenges. Firstly, the side channel detection is quite dependent on the golden model. The second one relates to the accuracy of the samples. Side channel information of the chip comes from the hardware manufacturing process and implementation, so it is obviously affected by process variation. In the existing work, many self-reference detection methods have been proposed to solve the problem of missing golden models. However, the existing methods often have special requirements for the circuit structure (such as the need for self-similar structures in the circuit). And, they can hardly resist process variation. This paper combines design and detection. We select the power consumption generated at different times and construct two self-reference ‘knapsack’ to detect HT. The solution proposed in this article is a kind of self-reference method, but we need neither self-similar structures nor the same state of some clocks in the circuit. Meanwhile, by constructing the ‘knapsack,’ we reduce the impact of process variation on detection accuracy because the process variation in the two sets of power consumption is balanced.
Yidong Yuan, Yao Zhang 0015, Yiqiang Zhao, Xige Zhang, Ming Tang 0002
Secur. Commun. Networks5
2021 Analysis of Multiplicative Low Entropy Masking Schemes Against Correlation Power Attack
abstract
Low Entropy Masking Schemes (LEMS) had been proposed to mitigate the high-performance overhead results from the Full Entropy Masking Schemes (FEMS) while offering good protection against side-channel attacks. The masking schemes usually rely on Boolean masking, however, splitting sensitive variables in a multiplicative way is more amenable to non-linear functions and it had been applied to both software and hardware with a competitive alternative to state-of-the-art masked design. Compared to the comprehensive analysis done for Boolean LEMS, the specific leakage characteristics of Multiplicative LEMS have not yet been analyzed. In this paper, we introduce security models for LEMS to characterize the balance of the mask set. Based on the security model, we present an inherent weakness of Multiplicative LEMS. We prove that this defect of Multiplicative LEMS cannot be compensated by choosing a proper mask set, and the security of FEMS is guaranteed thanks to the Dirac function which is used to resist zero-value attack. Then, we exhibit the leakages in the implementation of Multiplicative LEMS. In particular, we propose a new attack against Multiplicative LEMS more efficient by utilizing the distribution of masked intermediate values. The feasibility of the attack is verified by both simulation and practical experiments.
Yanbin Li 0001, Zhe Liu 0001, Sylvain Guilley, Ming Tang 0002
IEEE Trans. Inf. Forensics Secur.4
2020 A pre-silicon logic level security verification flow for higher-order masking schemes against glitches on FPGAs
Yanbin Li 0001, Ming Tang 0002, Yuguang Li, Huanguo Zhang
Integr.2
2020 Table Recomputation-Based Higher-Order Masking Against Horizontal Attacks
abstract
Masking is a class of well-known countermeasure against side-channel analysis by employing the idea of secret sharing. The theoretical security proof model of higher-order masking was initiated by Ishai, Sahai, and Wagner, and Barthe et al. pushed forward it by proposing a more refine security definition named as t-SNI security. In CHES 2016, a new attack called horizontal side-channel attacks (HSCAs) came forward and successfully broke the Rivain-Prouff countermeasure, which has been proved to satisfy the t-SNI security. It presents a dilemma: instead of more secure, masking with higher-order may be more vulnerable due to the HSCA. Although there already exists an effective countermeasure for the Rivain-Prouff scheme, it is quite difficult to apply this method in the table recomputation-based higher-order masking schemes, such as the scheme introduced by Coron in EUROCRYPT 2014. To fill this gap, we propose a new table recomputation-based higher-order masking scheme, named as table compression masking (TCM) scheme. While meeting the t-SNI security, our new countermeasure is also secure against the HSCA. We give the formal security proof under the t-SNI security definition, as well as a heuristic security analysis considering the HSCA. Our analysis shows that, by dividing the full lookup table into many distinct parts and shifting them by refreshed shares, the same share will never be manipulated for more than twice in TCM scheme. This feature gives a heuristic security against HSCA. To our best knowledge, our countermeasure is the first solution for table recomputation-based higher-order masking to resist HSCA.
Zhipeng Guo 0002, Ming Tang 0002, Emmanuel Prouff, Maixing Luo, Fei Yan 0008
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2019 Practical Evaluation Methodology of Higher-Order Maskings at Different Operating Frequencies
Yuguang Li, Ming Tang 0002, Yanbin Li 0001, Shan Fu
ICICS2
2019 Stripped Functionality Logic Locking With Hamming Distance-Based Restore Unit (SFLL-hd) - Unlocked
abstract
Logic locking is a technique that has received significant attention. It protects a hardware design netlist from a variety of hardware security threats, such as tampering, reverse-engineering, and piracy, stemming from untrusted chip foundry and end-users. This technique adds logic and inputs to a given design netlist to make sure that the locked design is functional only when a key is applied from the new inputs; an incorrect key makes the design produce incorrect outputs. The new inputs, referred to as the key inputs, are driven by a tamper-proof memory on the chip, which stores the secret key. Research in this field has shown that this technique, if not implemented properly, may be vulnerable to attacks that extract the key of logic locking. Recently, a logic locking technique called stripped functionality logic locking (SFLL) has been proposed and shown to withstand all known attacks in a provably secure manner. SFLL strips some functionality from the original design by corrupting its output corresponding to a number of “protected” input patterns. In one version of SFLL, referred to as SFLL-hd, these protected patterns are all of a certain hamming distance h to the key. The modified design is accompanied by additional logic that fixes the output for each protected input pattern only when the key is in the tamper-proof memory. In this paper, we present an attack that breaks SFLL-hd within a minute. Our attack exploits structural traces left behind in the locked design due to the functionality strip operation and is capable of identifying some of the protected patterns. We also present a theoretical framework that helps us develop two different techniques to complete our attack. In the first technique, we use the Gaussian elimination technique to solve a system of equations that we form based on k-identified protected patterns in O(k3) time in the best case, where k is the number of key bits in key. The second technique uses one identified protected pattern to query the oracle k times. In both techniques, we successfully recover the key from the protected pattern(s). We show that our attacks work on the SFLL-locked microprocessor design (more than 50 K gates) that the authors of SFLL made available to the public; we extract the 256-bit key within a minute and reveal it in this paper. We also test our attacks on a few other SFLL-hd benchmarks provided by SFLL authors.
Fangfei Yang, Ming Tang 0002, Ozgur Sinanoglu
IEEE Trans. Inf. Forensics Secur.2
2018 Several weaknesses of the implementation for the theoretically secure masking schemes under ISW framework
Yanbin Li 0001, Ming Tang 0002, Yuguang Li, Huanguo Zhang
Integr.2
2018 Leak Point Locating in Hardware Implementations of Higher-Order Masking Schemes
abstract
Secure masking schemes have been proven in theory to be secure countermeasures against side-channel attacks. The security framework proposed by Ishai, Sahai and Wagner, known as the Ishai-Sahai-Wagner scheme, is one of the most acceptable secure models of the existing dth-order masking schemes, where d represents the masking order and plays the role of a security parameter. However, a gap may exist between scheme and design. Several analyses have determined that the glitch has been regarded as the main challenge of masking in hardware designs. A practical method of locating the precise position of leakage points (LPs) in the original hardware design is very rare. Existing research on this glitch mainly focuses on the first-order leakages; however, higher-order analysis can combine several shares to recover the secret key. In this paper, we propose a practical method, sensitive glitch location (SGL) method to locate the less order leakage in hardware design. Specifically, the SGL method can locate any-order of LP in the hardware implementation of dth-order masking schemes. We conducted experiments and verified that the time complexity of SGL on the dth-order masking schemes is O(nm), where m is the number of signals and n is the number of shares in masking scheme. It can therefore be regarded as an efficient tool for the masking designs. In addition, we analyzed the dth-order masking scheme proposed by Rivain and Prouff (2010) along with the SecMult algorithm from the Rivain-Prouff countermeasure, which has been analyzed by our SGL. The experimental results verified that a higher-order leakage may exist in certain hardware designs, even the masking scheme has been proven as a secure countermeasure. To the best of our knowledge, SGL is the first tool that can be used to locate any-order of power/electromagnetic LP in hardware designs. It thus shows the weakness in the original design file of hardware implementations. This property can help designers directly improve the real security of the designs. Moreover, SGL returns the path of the leakages, which can elucidate the original cause and propagation of the weakness.
Ming Tang 0002, Yanbin Li 0001, Dongyan Zhao 0002, Yuguang Li, Fei Yan 0008, Huanguo Zhang
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2018 An Efficient SCA Leakage Model Construction Method Under Predictable Evaluation
abstract
Leakage models, regarded as a bridge between the physical signal and the sensitive operation, have a great influence on the effectiveness of the side channel analysis. The existing leakage models are usually divided into two categories, the non-profiled leakage models which have been chosen before sampling and analyzing, such as Hamming weight and Hamming distance, while the profiled leakage models, whose parameters have to be trained in the profiling phase, such as the Stochastic model of which both coefficient vector and pooled covariance matrix are required to be estimated based on the acquired samples. In general, a profiled leakage model is more accurate than a non-profiled one. However, it may lead to an inefficient attack if the leakage function is inaccurate, e.g., the over-fitting and under-fitting in the profiling phase. In this paper, we mathematically prove the relationship among different stochastic models, and propose a new method named ECM to solve the problem that much time is required to solve matrix in the profiling phase. Replacing the observations in the matrix solution with the average signals, the new method accelerates the construction of any stochastic model significantly, as long as the data-dependent signal has the property equal images under different subkeys. On the basis of theoretical results, we analyze the reasons why over-fitting and under-fitting happen, and quantify the condition when some of them occur. Finally, comparing with the existing construction method (HSS2012), we verify the effectiveness and efficiency of ECM with different metrics. Under the same accuracy, the ECM obviously has lower time complexity than HSS2012.
Ming Tang 0002, Xiaoqi Ma, Wenjie Chang, Huanguo Zhang, Guojun Peng, Jean-Luc Danger
IEEE Trans. Inf. Forensics Secur.1
2017 PFD - A Flexible Higher-Order Masking Scheme
abstract
Based on the idea of secret sharing, masking is one of the most popular countermeasure to prevent side channel attacks (SCAs). Despite the redundant time and resource consumption, the existing masking schemes have constant speed and resources, and thus unsuitable for different applications with variable demand for time or space. Motivated by the reconfiguration technology of programmable hardware and disjunctive normal form expression of any logic function, we define a random variable logic circuit to reach the same security for any-order masking schemes. During the encryption, we induce random sequences and utilize them as configuration sequences to generate variable logic circuits, whose results are independent from the original and divided into several shares. We call our new approach polynomial function division (PFD) masking. Furthermore, we analyze the effectiveness and proof the security of PFD in theory. Our experiments using PFD on the advanced encryption standard (AES) algorithm show that the space complexity is almost as small as an implementation of the original AES without any countermeasure. Moreover, due to the flexible structure of PFD, the cost-to-efficiency ratio of PFD is much lower than state-of-the art in software, and its flexibility is coin with the reconfigurable chip.
Ming Tang 0002, Zhipeng Guo 0002, Annelie Heuser, Yanzhen Ren, Jean-Luc Danger
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2017 A Generic Table Recomputation-Based Higher-Order Masking
abstract
Masking is a class of well-known countermeasure against side-channel attacks by employing the idea of secret sharing. In this paper, we propose a generic table recomputation-based masking scheme at any chosen order t, named divided S-box masking (DSM), and its security has been proved under the security framework from Crypto 2003. The table recomputation-based masking is suitable for software implementation and the masked table can be stored in memory, where it can be accessed fast. For any input, DSM scheme generates n output shares by two queries. DSM scheme requires two vectors L and R, and a matrix M of random numbers. Each element of L is the XOR result of the output of S-box and n - 1 random numbers. These n - 1 random numbers are stored in two lines of M and R which is a vector of indexes for the second query. Furthermore, we performed the attacks on the software implementation of DSM to evaluate its practical security, and compared the timing and space complexity with the existing table recomputation-based masking in the same platform to verify the advantage of the DSM.
Ming Tang 0002, Zhenlong Qiu, Zhipeng Guo 0002, Yi Mu 0001, Xinyi Huang 0001, Jean-Luc Danger
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2016 Power analysis attacks against FPGA implementation of KLEIN
abstract
Abstract KLEIN is a family of block ciphers whose lightweight features are suitable for resource‐constrained devices. However, the original design of KLEIN does not consider the potential attacks by power analysis methods. This paper presents power analysis attacks against an field‐programmable gate array (FPGA) implementation of KLEIN by the authors of KLEIN. The attacking strategy, attacking point, and complexity of our attacks via power analysis against KLEIN are discussed in detail. Besides, the implementation of the attacks is also described, and the experimental data is given. A lot of attacking experiments are launched by this paper; the best method in our experiment is Correlation Power Analysis (CPA) attack that requires only 4000 random plaintexts and 115 s to reveal the 64‐bit key of KLEIN, with the storage complexity nearly 212 and the success probability of attack nearly 100%. Finally, a defensive countermeasure against our attacks is proposed. Copyright © 2017 John Wiley & Sons, Ltd.
Shaohua Tang, Jianhao Wu, Ming Tang 0002
Secur. Commun. Networks5
2015 AMR Steganalysis Based on the Probability of Same Pulse Position
abstract
This paper presents a method for detection of adaptive multirate (AMR) audio steganography. AMR audio codec is an audio data compression scheme optimized for speech coding, and widely used in some mobile telecommunications system. The AMR audio steganography schemes are emerging recently and they embed secret messages by modifying the nonzero pulse positions which are determined by fixed codebook search in AMR compression procedure. Those methods have high embedding capacity and good imperceptivity. We have observed that those steganography schemes will cause the probability of same pulse positions in the same track increasing. Based on this phenomenon, this paper presents a set of steganalysis features of the probability of same pulse position. The support vector machine is applied to the proposed features and used as the steganalyzer. The performance of the scheme is tested on a database containing ~140714 audios. Experimental results show that the correct detection rate of our proposed method is 90% when the embedding bit rate is 30% or above, and can reach above 85% for cover audios.
Yanzhen Ren, Tingting Cai, Ming Tang 0002, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.3
2014 Toward reverse engineering on secret S-boxes in block ciphers
Ming Tang 0002, Zhenlong Qiu, Hongbo Peng, Yi Mu 0001, Huanguo Zhang
Sci. China Inf. Sci.1
2014 Power analysis based reverse engineering on the secret round function of block ciphers
abstract
SUMMARY The recent cryptanalysis on block ciphers has two major trends. Side channel analysis (SCA) has become a new threat to the hardware implementations of encryption algorithms. On the other hand, reverse engineering has been adopted to explore the unknown part of the encryption algorithms, which has become a new target of the cryptanalysis. Some drawbacks have been found in the existing methods of reverse engineering, which target on the special structures or utilize the flaws in the unknown parts. The major disadvantage is that the number of rounds to be analyzed is limited, and the complexity is high. The existing SCAs for reverse engineering depend on the leakage models in a large extent and mainly focus on the single component of the algorithms, whereas the other parts of the target algorithm are known. In this paper, we present a more general and feasible reverse analysis by combining the mathematical methods and the SCA methods. We use the strict avalanche criterion for the non‐linear operations of block ciphers and apply the power analysis to reverse the structure parameters. We propose a new reverse analysis method to reduce the dependency on the leakage models, which can be combined with the structural cryptanalysis to reverse the internal parameters of the linear and non‐linear operations. We finally achieve the reverse analysis on the unknown round function of block ciphers. Copyright © 2013 John Wiley & Sons, Ltd.
Ming Tang 0002, Zhenlong Qiu, Weijin Sun, Huanguo Zhang
Concurr. Comput. Pract. Exp.1
2012 Polar differential power attacks and evaluation
Ming Tang 0002, Zhenlong Qiu, Yi Mu 0001, Huanguo Zhang, Yingzhen Jin
Sci. China Inf. Sci.1
2012 Evolutionary ciphers against differential power analysis and differential fault analysis
Ming Tang 0002, Zhenlong Qiu, Min Yang 0001, Pingpan Cheng, Qingshu Meng
Sci. China Inf. Sci.1
2011 Extended multivariate public key cryptosystems with secure encryption function
Huanguo Zhang, Zhang-yi Wang, Ming Tang 0002
Sci. China Inf. Sci.4
2011 Capability of evolutionary cryptosystems against differential cryptanalysis
Huanguo Zhang, Chunlei Li 0001, Ming Tang 0002
Sci. China Inf. Sci.3
2011 Evolutionary cryptography against multidimensional linear cryptanalysis
Huanguo Zhang, Chunlei Li 0001, Ming Tang 0002
Sci. China Inf. Sci.3