EDBT 2026 Demo / reviewers in the wild / expert
Bodhisatwa Mazumdar
dblp:79/11161
· DBLP profile ↗
20ranked-venue papers
7as first author
5since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 15 · 5 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A novel minutiae-oriented approach for partial fingerprint-based MasterPrint mitigation
Mahesh Joshi, Bodhisatwa Mazumdar, Somnath Dey |
Pattern Recognit. | 2 |
| 2024 | DefScan: Provably Defeating Scan Attack on AES-Like CiphersabstractScan-based Design-for-testability (DfT) is the de facto standard in the semiconductor testing industry to guarantee the functional and structural correctness of chips. It provides improved observability and controllability, leading to enhanced fault coverage. However, owing to widespread usage, attackers devise techniques to misuse this method to steal secret keys embedded in a security-critical chip. A vast majority of off-the-shelf defense mechanisms are based on either randomizing the scan output or restricting access to the scan. However, none of these defense mechanisms leverage the fundamental properties of the scan attack; thus, they tend to be complex and incur high area and computation overhead. In this paper, we propose a defense mechanism by preventing the vulnerabilities of fundamental properties from being exploited in scan attacks. The paper first pinpoints the ultimate condition of the scan attack on Advanced Encryption Standard (AES). This attack condition is inherent to the cryptographic property of the cipher, which, when violated, thwarts the attack. To implement our defense, we interchange the AES round outputs by applying pre-computed masks. The designer chooses inputs with a fixed difference to swap the outputs. A modified incorrect key is recovered instead of an actual key if a scan-based attack is launched. To show the generality of the proposed defense, it is extended to another AES-like cipher, Light Encryption Device (LED). To the best of our knowledge, this is the first defense against a scan attack wherein the complete testing process, including structural and functional tests, can be outsourced to untrusted third parties without compromising the actual key. In comparison, logic locking techniques limaye2020thwarting can outsource only structural testing to untrusted third parties. Yogendra Sao, Subidh Ali, Bodhisatwa Mazumdar |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2024 | Semi-Permanent Stuck-At Fault injection attacks on Elephant and GIFT lightweight ciphersabstractFault attacks pose a potent threat to modern cryptographic implementations, particularly those used in physically approachable embedded devices in IoT environments. Information security in such resource-constrained devices is ensured using lightweight ciphers, where combinational circuit implementations of SBox are preferable over look-up tables as they are more efficient regarding area, power, and memory requirements. Most existing fault analysis techniques focus on fault injection in memory cells and registers. Recently, a novel fault model and analysis technique, namelySemi-Permanent Stuck-At(SPSA) fault analysis, has been proposed to evaluate the security of ciphers with combinational circuit implementation ofSubstitution layerelements, SBox. In this work, we propose optimized techniques to recover the key in a minimum number of ciphertexts in such implementations of lightweight ciphers. Based on the proposed techniques, a key recovery attack on the NIST lightweight cryptography (NIST-LWC) standardization process finalist,ElephantAEAD, has been proposed. The proposed key recovery attack is validated on two versions ofElephantcipher. The proposed fault analysis approach recovered the secret key within 85–240 ciphertexts, calculated over 1,000 attack instances. To the best of our knowledge, this is the first work on fault analysis attacks on theElephantscheme. Furthermore, an optimized combinational circuit implementation ofSpongentSBox (SBox used inElephantcipher) is proposed, having a smaller gate count than the optimized implementation reported in the literature. The proposed fault analysis techniques are validated on primary and optimized versions ofSpongentSBox through Verilog simulations. Further, we pinpoint SPSA hotspots in the lightweightGIFTcipher SBox architecture. We observe thatGIFTSBox exhibits resilience toward the proposed SPSA fault analysis technique under the single fault adversarial model. However,eightSPSA fault patterns reduce the nonlinearity of the SBox to zero, rendering it vulnerable to linear cryptanalysis. Conclusively, SPSA faults may adversely affect the cryptographic properties of an SBox, thereby leading to trivial key recovery. TheGIFTcipher is used as an example to focus on two aspects: (i) its SBox construction is resilient to the proposed SPSA analysis and therefore characterizing such constructions for SPSA resilience and (ii) an SBox even though resilient to the proposed SPSA analysis, may exhibit vulnerabilities toward other classical analysis techniques when subjected to SPSA faults. Our work reports new vulnerabilities in fault analysis in the combinational circuit implementations of cryptographic protocols. Priyanka Joshi, Bodhisatwa Mazumdar |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2021 | mMIG: Inversion optimization in majority inverter graph with minority operations
Umar Aalam, Bodhisatwa Mazumdar, Neminath Hubballi |
Integr. | 2 |
| 2021 | Entropy Reduction Model for Pinpointing Differential Fault Analysis on SIMON and SIMECK CiphersabstractIn this article, we present a formal model of entropy reduction across the rounds when a fault is injected in SIMON and SIMECK family of lightweight ciphers. The model helps to pinpoint a range of intermediate rounds in a cipher of the same family, which when subjected to a fault injection requires minimal number of such attempts to reveal the secret key. The range of such rounds depict increased vulnerability to fault analysis attacks and, thus, require a stronger countermeasure for such rounds. We demonstrate the proposed entropy-reduction model for all versions of SIMON and SIMECK. The comparisons with existing fault analysis attacks depict that our proposed model requires least number of faults and smaller attack time in almost all versions of SIMON and SIMECK. The proposed entropy-reduction model can be used as a tool for the designers for any generic lightweight Feistel cipher to identify the vulnerable rounds in the encryption/decryption algorithms. Naman Singhal, Priyanka Joshi, Bodhisatwa Mazumdar |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2020 | A comprehensive security analysis of match-in-database fingerprint biometric system
Mahesh Joshi, Bodhisatwa Mazumdar, Somnath Dey |
Pattern Recognit. Lett. | 2 |
| 2020 | Logic Locking With Provable Security Against Power Analysis AttacksabstractOutsourcing of integrated circuit (IC) fabrication to external foundries has lead to many new security vulnerabilities, including IC piracy, overbuilding, and reverse engineering. In this regard, logic locking (LL) was introduced to protect intellectual property from such threats. In this paper, we evaluate the strength of various LL techniques, including earlier works, such as random LL (RLL) and fault analysis-based LL (FLL), against power-based side-channel attack. We have developed attacks where at least 60% of the key bits can be successfully recovered for 60% of the circuits for both RLL and FLL using a 32-bit key. However, the success rate reduces to 45% and 35% for RLL and FLL, respectively, when using a 64-bit key. We demonstrate the practicality of our proposed attack by mounting it against RLL and FLL implementations of ISCAS'85 and MCNC benchmark circuits on Spartan-6 FPGA platform. Further, we present differential power analysis (DPA) results on mutual information analysis on LL techniques that capture any dependence between the intermediate data and the captured power traces. We also formally establish that resilience to satisfiability-based (SAT) attack implies resilience to DPA attack as well for an LL technique. We validate this further via experiments on Spartan-6 FPGA on SAKURA-G development board for a recent LL technique that is known to thwart the SAT attack. Abhrajit Sengupta, Bodhisatwa Mazumdar, Muhammad Yasin, Ozgur Sinanoglu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2019 | Classical Cryptanalysis Attacks on Logic Locking Techniques
Bodhisatwa Mazumdar, Soma Saha, Ghanshyam Bairwa, Souvik Mandal, Tatavarthy Venkat Nikhil |
J. Electron. Test. | 1 |
| 2017 | Security analysis of Anti-SATabstractLogic encryption protects integrated circuits (ICs) against intellectual property (IP) piracy and overbuilding attacks by encrypting the IC with a key. A Boolean satisfiability (SAT) based attack breaks all existing logic encryption technique within few hours. Recently, a defense mechanism known as Anti-SAT was presented that protects against SAT attack, by rendering the SAT-attack effort exponential in terms of the number of key gates. In this paper, we highlight the vulnerabilities of Anti-SAT and propose signal probability skew (SPS) attack against Anti-SAT block. SPS attack leverages the structural traces in Anti-SAT block to identify and isolate Anti-SAT block. The attack is 100% successful on all variants of Anti-SAT block. SPS attack is scalable to large circuits, as it breaks circuits with up to 22K gates within two minutes. Muhammad Yasin, Bodhisatwa Mazumdar, Ozgur Sinanoglu, Jeyavijayan Rajendran |
ASP-DAC | 2 |
| 2017 | Redefining the transparency order
Kaushik Chakraborty 0001, Sumanta Sarkar, Subhamoy Maitra, Bodhisatwa Mazumdar, Debdeep Mukhopadhyay, Emmanuel Prouff |
Des. Codes Cryptogr. | 4 |
| 2017 | Construction of Rotation Symmetric S-Boxes with High Nonlinearity and Improved DPA ResistivityabstractIn this paper, we provide an n × n bijective rotation symmetric S-box (RSSB) construction with improved resistance to differential power analysis (DPA) using rotation-symmetric Boolean functions (RSBFs). The RSSB class is generated from an instance of a proposed RSSB construction and then iteratively applying a simulated annealing algorithm in the respective neighborhood of the RSSB followed by a hill climbing algorithm to obtain a good tradeoff of cryptographic properties. The constructed 8 × 8 RSSBs have a nonlinearity of 102 and transparency order value 7.709 whereas the Rijndael S-box has a higher transparency order of 7.86. The evaluation of security metric called guessing entropy on the constructed RSSBs shows that a side-channel adversary requires more effort to exploit information leakage from the simulated power traces. In comparison to Rijndael S-box, the correlation based DPA on RSSBs which when incorporated in AES-128, shows requirement of significantly more power traces when implemented on Xilinx Virtex-5 FPGA device on SASEBO-GII development board. While the distributed memory and block memory implementations of the Rijndael S-box required 500 and 2,000 power traces to extract the last round key, our proposed RSSBs required 2,000 and 12,000 power traces respectively. Bodhisatwa Mazumdar, Debdeep Mukhopadhyay |
IEEE Trans. Computers | 1 |
| 2017 | A Combined Power and Fault Analysis Attack on Protected Grain Family of Stream CiphersabstractDifferential fault analysis of stream ciphers, such as Grain (Grain v1 and Grain-128) has been an active area of research. Several countermeasures to thwart such analysis have been also proposed in the related cryptographic literature. In this paper, we demonstrate a novel combination of power and fault analysis strategies to devise attacks against such protected implementations of Grain stream cipher. We considered clock glitch induced faults occurring in practice to construct our fault model. In addition, we developed a generic power analysis attack technique against the Grain family of stream ciphers assuming that the cipher implementation can be resynchronized multiple times with a fixed secret key and any randomly generated initialization vector. Subsequently, we combine our proposed power analysis strategy with the notion of the practically occurring faults to mount attacks on various fault attack countermeasures. In order to validate our proposed power analysis attack, we report the results of power trace classifications of a Grain v1 implementation on SASEBO-GII board. The captured power traces were analyzed using least squares support vector machine learning algorithm-based multiclass classifiers to segregate the power traces into the respective Hamming distance (HD) classes. To extract power samples with high information about HD classes, signal-to-noise ratio (SNR) metric was chosen for feature selection. The experimental results of power trace classifications of test set showed success rate as high as 92.5% when the seven largest SNR sample instants over a clock cycle were chosen as features along with a suitable kernel hyperparameter combination. Abhishek Chakraborty 0001, Bodhisatwa Mazumdar, Debdeep Mukhopadhyay |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2016 | CamoPerturb: secure IC camouflaging for minterm protectionabstractIntegrated circuit (IC) camouflaging is a layout-level technique that thwarts reverse engineering attacks on ICs by introducing camouflaged cells that look alike, but can implement one of many possible Boolean functions. Existing camouflaging techniques have been broken by a recent decamouflaging attack, which uses Boolean satisfiability (SAT) techniques to compute specialized discriminating input patterns that prune the functionality search space quickly. This paper presents CamoPerturb, a countermeasure to thwart the decamouflaging attack by integrating logic perturbation with IC camouflaging. CamoPerturb, contrary to all the existing camouflaging schemes, perturbs the functionality of the given design minimally, i.e., adds/removes one minterm, rather than camouflaging the design. A separate camouflaged block CamoFix restores the perturbed minterm, recovering the functionality of the design. The perturbed minterm is the designer's secret and is incorporated into CamoFix using camouflaged cells. CamoPerturb renders the decamouflaging attack effort exponentially harder in the number of camouflaged gates while its overhead grows linearly. The paper presents formal proofs for the security of CamoPerturb along with experimental results. Muhammad Yasin, Bodhisatwa Mazumdar, Ozgur Sinanoglu, Jeyavijayan Rajendran |
ICCAD | 2 |
| 2016 | Power-side-channel analysis of carbon nanotube FET based designabstractContinuous scaling of CMOS technology beyond sub-nanometer region has aggravated short-channel effects, resulting in increased leakage current and high power densities. Furthermore, elevated leakage current and power density render CMOS based security-critical applications vulnerable to power-side-channel attacks. Carbon Nanotubes (CNT) is a promising alternative to CMOS technology. It offers superior transport properties, excellent thermal conductivities, high current capacities, and low power densities. Besides area, power and performance, adherence to hardware security aspects have become an important criteria today. In this work, we present the first study on power-side-channel analysis of ciphers implemented using CNTFETs. Our simulation results show that for 130 power traces, the simple power analysis (SPA) attack success rate is less than 0.35 for CNTFET based ciphers, whereas it is greater than 0.95 for CMOS based ciphers. For correlation power analysis, the difference of correlation coefficient of the correct key and closest wrong key guess is 1.3 for CMOS based design, and less than 0.56 for CNTFET based ciphers for 20,000 power traces, which implies lesser distinguishability of correct key in case of CNTFETs. These results indicate that CNT offers a higher resilience to power-side-channel attacks than CMOS. Chandra K. H. Suresh, Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
IOLTS | 2 |
| 2016 | Thwarting timing attacks on NEMS relay based designsabstractNEMS relay technology is a promising class of emerging devices that offer zero static leakage and hence overcomes the power dissipation issues of deep-submicron CMOS technology devices. As NEMS relay based digital circuits have potentially higher energy-efficiency than those based on CMOS transistors, circuits based on NEMS relay device are worth exploring. However, NEMS relay devices suffer from large delay compared to CMOS technology; Binary Decision Diagram (BDD) based implementation targets to minimize the total circuit delay, fixing this problem. However, such an implementation renders the timing delay of a NEMS based circuit input-dependent, which can be exploited to infer on-chip secret information from delay information. In this presentation, we illustrate these security vulnerabilities and present countermeasures for a recently proposed energy-efficient block cipher Midori128 that has an on-chip secret key that needs to be protected. Bodhisatwa Mazumdar, Samah Mohamed Saeed, Subidh Ali, Ozgur Sinanoglu |
VTS | 1 |
| 2016 | A Compact Implementation of Salsa20 and Its Power Analysis VulnerabilitiesabstractIn this article, we present a compact implementation of the Salsa20 stream cipher that is targeted towards lightweight cryptographic devices such as radio-frequency identification (RFID) tags. The Salsa20 stream cipher, ann addition-rotation-XOR (ARX) cipher, is used for high-security cryptography in NEON instruction sets embedded in ARM Cortex A8 CPU core-based tablets and smartphones. The existing literature shows that although classical cryptanalysis has been effective on reduced rounds of Salsa20, the stream cipher is immune to software side-channel attacks such as branch timing and cache timing attacks. To the best of our knowledge, this work is the first to perform hardware power analysis attacks, where we evaluate the resistance of all eight keywords in the proposed compact implementation of Salsa20. Our technique targets the three subrounds of the first round of the implemented Salsa20. The correlation power analysis (CPA) attack has an attack complexity of 2 19 . Based on extensive experiments on a compact implementation of Salsa20, we demonstrate that all these keywords can be recovered within 20,000 queries on Salsa20. The attacks show a varying resilience of the key words against CPA that has not yet been observed in any stream or block cipher in the present literature. This makes the architecture of this stream cipher interesting from the side-channel analysis perspective. Also, we propose a lightweight countermeasure that mitigates the leakage in the power traces as shown in the results of Welch’s t -test statistics. The hardware area overhead of the proposed countermeasure is only 14% and is designed with compact implementation in mind. Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2015 | Power analysis attacks on ARX: An application to Salsa20abstractIn this paper, we analyze the vulnerability of Salsa20 stream cipher against power analysis attacks, especially against correlation power analysis (CPA), which is the strongest form of power analysis attacks. In recent literature, a rigorous study of optimal differential characteristics is presented, but an analysis of the resistance of the cipher against power analysis side-channel attacks remains absent. Our technique targets the three subrounds of the first round of Salsa20. The overall correlation based differential power analysis (DPA) has an attack complexity of 219. From extensive experiments on a reduced area implementation of Salsa20, we demonstrate that two key words k0, k7of a block in Salsa20 are extremely vulnerable to CPA while a combination of two key words k2, k4produced a very low success rate of 0.2, which shows a high resilience against correlation-analysis DPA. This varying resilience of the key words towards correlation-analysis DPA has not been observed in any stream or block cipher in present literature, which makes the architecture of this stream cipher interesting from the side-channel analysis perspective. Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
IOLTS | 1 |
| 2015 | Timing attack on NEMS relay based design of AESabstractIn deep submicron CMOS transistors, the static leakage current has become a significant contributor to power consumption with channel length and subthreshold voltage being continuously scaled down. Also, this increased leakage has recently led to the rise of side-channel attacks on CMOS based implementations. Nanoelectromechanical System (NEMS) relay technology is emerging as an alternative to CMOS with one of its most prominent advantages being the zero static leakage, providing an inherent defense against power side-channel attacks at the same time. On the other hand, this emerging technology introduces timing challenges in the design process; to minimize the timing delay of NEMS relays, binary decision diagram (BDD) based implementation is utilized to design combinational logic. What's important from a security perspective is that the timing delay of the BDD implementation of a NEMS relay based design is inherently input dependent. An adversary can therefore leverage the data dependency to identify secret information of the chip. We propose a timing delay based attack on NEMS relay based designs, use AES as a case study, and show that it can achieve a success rate of 1.0 for interconnect delay variations within a standard deviation of 0.0022. To the best of our knowledge, this paper is the first to expose an inherent security vulnerability of a NEMS relay based design. Samah Mohamed Saeed, Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
VLSI-SoC | 2 |
| 2013 | Constrained Search for a Class of Good Bijective S-Boxes With Improved DPA ResistivityabstractThe transparency order is proposed as a parameter for the robustness of S-boxes to differential power analysis (DPA): lower transparency order implying more resistance. However, most cryptographically strong S-boxes have been found to have high transparency order. In this paper, we characterize transparency order for various classes of S-boxes by computing the upper and lower bounds of transparency order for both even and odd numbers of variables. We find high transparency order values in the class of S-boxes whose sum of autocorrelation spectra of the coordinate functions has zero value for a large number of vectors a. Also instead of propagation characteristics, autocorrelation spectra of the S-box function F are found to be stronger in deciding the transparency order. With this characterization, we performed a constrained random generation and search of a class of balanced 8 × 8 S-boxes with transparency order upper bounded by 7.8. The nonlinearity and absolute indicator values of global avalanche characteristics of the coordinate functions of the S-boxes are in the range (98, 110) and (48, 88), respectively. A correlation analysis DPA on table look-up implementation of AES Rijndael S-box revealed the last round key in 700 power traces, while it took at least 1500 power traces with S-boxes from our proposed class. Bodhisatwa Mazumdar, Debdeep Mukhopadhyay, Indranil Sengupta 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2006 | A Real Time Speckle Noise Cleaning Filter for Ultrasound ImagesabstractUltrasound images are masked by multiplicative speckle noise caused by random interference between coherent backscattered waves. This paper presents an efficient algorithm for real-time speckle cleaning filter of ultrasound images and its VLSI implementation in FPGA. The algorithm presented here implements a regular, tunable filter with an optimized architecture having proper parallelism and pipelining to achieve high speed. The performance of the proposed filter is compared to that of the aggressive region growing filter (ARGF). The processed images obtained from the proposed filter are speckle removed and the edge details are also restored effectively. Also, the PSNR performance is better than the ARGF filter while noise variance is lower indicating a cleaner image as more speckle is reduced Bodhisatwa Mazumdar, Aman Mediratta, Joydeep Bhattacharyya, Swapna Banerjee |
CBMS | 1 |