EDBT 2026 Demo / reviewers in the wild / expert
Subidh Ali
dblp:80/9687 · also Sk Subidh Ali
· DBLP profile ↗
28ranked-venue papers
14as first author
7since 2021 · last 2026
0000-0001-5942-4455ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 20 · 9 first-author · 5 since 2021Security and privacy · 7 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GAN-Invert: Unveiling Vulnerabilities in Privacy-Preserving Facial TransformationsabstractFace recognition is now widely used in authentication, surveillance, and social media, but it also raises serious privacy risks. Face recognition models enable unauthorized identification of individuals from publicly shared images, support mass surveillance and tracking without consent, and allow inference of sensitive personal attributes such as age, gender, or health conditions. Since biometric data cannot be revoked like a password, once facial embeddings are leaked, they can be exploited for identity theft and cross-platform re-identification. To address these challenges, many deep learning based methods have been proposed to alter facial images so that identity is concealed while the images remain useful for deep learning tasks such as age estimation, attribute recognition, expression analysis, and face recognition for an authorized system. These methods include pixel-level manipulation, generative adversarial makeup, feature disentanglement, and key-based reversible encryptions. However, most of them follow the idea of bounded distortion, where the image is slightly altered for privacy preservation while keeping the image quality and the corresponding deep learning task accuracy intact. In this paper, we perform a detailed security analysis of these deep learning based privacy-preserving methods and show that these defense mechanisms are fundamentally insecure. Using theoretical as well as extensive experimental analysis, we demonstrate that a conditional GAN model can be trained to reconstruct the original image from the privacy-preserving protected image. Our attack analysis on the ten best-known privacy-preserving methods recovers the original from the protected image with high accuracy. Our results expose the key limitations of existing deep learning based privacy preserving methods and stress the need for privacy-preserving solutions based on stronger principles, such as information theory or cryptography, while still ensuring functionality for deep learning tasks. Umesh Kashyap, Subidh Ali |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | DefScan: Provably Defeating Scan Attack on AES-Like CiphersabstractScan-based Design-for-testability (DfT) is the de facto standard in the semiconductor testing industry to guarantee the functional and structural correctness of chips. It provides improved observability and controllability, leading to enhanced fault coverage. However, owing to widespread usage, attackers devise techniques to misuse this method to steal secret keys embedded in a security-critical chip. A vast majority of off-the-shelf defense mechanisms are based on either randomizing the scan output or restricting access to the scan. However, none of these defense mechanisms leverage the fundamental properties of the scan attack; thus, they tend to be complex and incur high area and computation overhead. In this paper, we propose a defense mechanism by preventing the vulnerabilities of fundamental properties from being exploited in scan attacks. The paper first pinpoints the ultimate condition of the scan attack on Advanced Encryption Standard (AES). This attack condition is inherent to the cryptographic property of the cipher, which, when violated, thwarts the attack. To implement our defense, we interchange the AES round outputs by applying pre-computed masks. The designer chooses inputs with a fixed difference to swap the outputs. A modified incorrect key is recovered instead of an actual key if a scan-based attack is launched. To show the generality of the proposed defense, it is extended to another AES-like cipher, Light Encryption Device (LED). To the best of our knowledge, this is the first defense against a scan attack wherein the complete testing process, including structural and functional tests, can be outsourced to untrusted third parties without compromising the actual key. In comparison, logic locking techniques limaye2020thwarting can outsource only structural testing to untrusted third parties. Yogendra Sao, Subidh Ali, Bodhisatwa Mazumdar |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2023 | On Securing Cryptographic ICs against Scan-based Attacks: A Hamming Weight Distribution PerspectiveabstractScan chain-based Design for Testability is the industry standard in use for testing manufacturing defects in the semiconductor industry to ensure the structural and functional correctness of chips. Fault coverage is significantly enhanced due to the higher observability and controllability of the internal latches. These ensuing benefits to testing, if misused, expose vulnerabilities that can be detrimental to the security aspects, especially in the context of crypto-chips that contain a secret key. Hence, it remains of paramount importance for a chip designer to secure crypto-chips against various scan attacks. A countermeasure is proposed in this article that preserves the secrecy of an embedded key in a cryptographic integrated circuit running an Advanced Encryption Standard (AES) implementation. A novel design involving a hardware unit is illustrated that circumvents differential scan attacks by essentially performing bit flips deterministically, using a pre-computed mask value. This helps secure the chip while retaining full testability. The controller logic directly depends on a mask determination algorithm that can defend against any scan attack with 𝒪 theoretical complexity. Security analysis of our proposed defense procedure is performed in the framework of Discrete Event Systems (DES). The sequential scan circuit of an AES cryptosystem is modeled as a DES using Finite State Automata. A security notion, Opacity , is used to quantify and formally verify the security aspects of our controlled system, which shows that the entropy of the secret key is preserved. A case study is performed that shows to mitigate state-of-the-art differential scan attacks successfully at a nominal extra overhead of 1.78%. Dipojjwal Ray, Yogendra Sao, Santosh Biswas, Subidh Ali |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2023 | Security Analysis of Scan Obfuscation TechniquesabstractScan is the de-facto standard for testing, which provides high observability and test coverage by enabling direct access to chip memory elements. The scan-based Design-for-Testability (DfT) technique has also become the prime target of attackers whose aim is to extract the secret information embedded inside a chip by misusing its scan infrastructure. Several countermeasures have been proposed to protect the chip against scan-based attacks. Recently, obfuscation-based defense mechanisms have gained significant popularity, which protect scan data by corrupting some of the scan cell’s content. In this paper, we perform a detailed security analysis of three best-known obfuscation techniques, namely, static, dynamic, and advanced dynamic obfuscation techniques, designed to protect the AES crypto-chip. We exploit their vulnerabilities and propose a generic scan-based signature attack, leading to the leakage of the secret cipher key that too, using only one observable scan cell. We also propose upgrades to the two dynamic scan obfuscation techniques to patch the discovered vulnerabilities with negligible changes to the original design. In order to show the generality of the attack, we also applied our attack to the similar cipher PRESENT and seven other scan obfuscation techniques. The result shows that in addition to the above three best-known obfuscation techniques, five out of the seven other scan obfuscation techniques were also successfully broken by our generic attack. Yogendra Sao, Subidh Ali |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Evaluating Security of New Locking SIB-based ArchitecturesabstractThe IEEE Std 1687 (IJT AG) provides enhanced access to the on-chip test instruments, which are included on the chip for test, post-silicon debug, in field maintenance, and diagnosis purposes. Although the on-chip instruments access provides data and features explicitly for test and debug, these features are misused by the malicious user to access sensitive data such as encryption keys, Chip-IDs, etc. Hence, it is desired to limit the access to sensitive on-chip instruments via IJT AG network. One of the various schemes proposed to mitigate the vulnerability of the IJT AG network is to use a secure access protocol, which is based on LSIB, Chip-ID, and licensed access software.In this paper, the detailed security analysis is performed on IJT AG, it is shown that the secure access protocol technique is vulnerable to differential analysis attack. It can be used to break the secure communication between the board and the licensed access software and thus, the sensitive on-chip test instruments can be accessed illegitimately. It is shown that our proposed algorithm can recover the template used for secure communication within a fraction of a second. Yogendra Sao, Anjum Riaz, Satyadev Ahlawat, Subidh Ali |
ETS | 4 |
| 2021 | Opacity preserving Countermeasure using Finite State Machines against Differential Scan AttacksabstractScan based DfT is the de facto standard for testing the functional and structural correctness of chips. It provides high observability and controllability of internal latches leading to enhanced fault coverage, but can also induce vulnerability in crypto-chips containing an embedded secret key. Protecting crypto-chips against scan attack is of paramount concern to a designer. In this paper, we propose a countermeasure using a controller to circumvent differential scan attacks on crypto-chips running an AES implementation. The controller we design is minimally restrictive and ensures security by performing deterministic bit flips yet maintaining full testability. The controller logic directly depends on input-based pre-computed mask values and the controlled system behaviour is formally verified to be secure using the notion of Opacity. We evaluate our defense by launching recent attacks on the AES cryptosystem. Our security analysis shows that the proposed technique is secure against the state of the art scan based differential scan attacks with a nominal hardware overhead of 0.94%. Subidh Ali, Yogendra Sao, Santosh Biswas |
ETS | 1 |
| 2021 | Security Analysis of State-of-the-art Scan Obfuscation TechniqueabstractScan-based Design for Testability (DfT) is the de-facto standard for detecting manufacturing-related faults in chip manufacturing industries. The observability and accessibility provided by DfT can be misused to launch an attack to reveal the secret key, which is embedded inside a crypto chip. Several countermeasures have been proposed to protect the chip against scan-based attacks. Dynamic obfuscation of scan data prevents scan-based attacks by corrupting scan data in the case of unauthorized access. In this paper, we perform the security analysis of the above state-of-the-art obfuscation technique to showcase its vulnerabilities. Exploiting its vulnerabilities, we propose a scan-based signature attack on state-of-the-art obfuscation technique by applying a maximum of 4096 plaintexts and using only 220signatures with a 100% success rate. Yogendra Sao, Subidh Ali |
ICCD | 2 |
| 2016 | Power-side-channel analysis of carbon nanotube FET based designabstractContinuous scaling of CMOS technology beyond sub-nanometer region has aggravated short-channel effects, resulting in increased leakage current and high power densities. Furthermore, elevated leakage current and power density render CMOS based security-critical applications vulnerable to power-side-channel attacks. Carbon Nanotubes (CNT) is a promising alternative to CMOS technology. It offers superior transport properties, excellent thermal conductivities, high current capacities, and low power densities. Besides area, power and performance, adherence to hardware security aspects have become an important criteria today. In this work, we present the first study on power-side-channel analysis of ciphers implemented using CNTFETs. Our simulation results show that for 130 power traces, the simple power analysis (SPA) attack success rate is less than 0.35 for CNTFET based ciphers, whereas it is greater than 0.95 for CMOS based ciphers. For correlation power analysis, the difference of correlation coefficient of the correct key and closest wrong key guess is 1.3 for CMOS based design, and less than 0.56 for CNTFET based ciphers for 20,000 power traces, which implies lesser distinguishability of correct key in case of CNTFETs. These results indicate that CNT offers a higher resilience to power-side-channel attacks than CMOS. Chandra K. H. Suresh, Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
IOLTS | 3 |
| 2016 | Thwarting timing attacks on NEMS relay based designsabstractNEMS relay technology is a promising class of emerging devices that offer zero static leakage and hence overcomes the power dissipation issues of deep-submicron CMOS technology devices. As NEMS relay based digital circuits have potentially higher energy-efficiency than those based on CMOS transistors, circuits based on NEMS relay device are worth exploring. However, NEMS relay devices suffer from large delay compared to CMOS technology; Binary Decision Diagram (BDD) based implementation targets to minimize the total circuit delay, fixing this problem. However, such an implementation renders the timing delay of a NEMS based circuit input-dependent, which can be exploited to infer on-chip secret information from delay information. In this presentation, we illustrate these security vulnerabilities and present countermeasures for a recently proposed energy-efficient block cipher Midori128 that has an on-chip secret key that needs to be protected. Bodhisatwa Mazumdar, Samah Mohamed Saeed, Subidh Ali, Ozgur Sinanoglu |
VTS | 3 |
| 2016 | Security Assessment of Cyberphysical Digital Microfluidic BiochipsabstractA digital microfluidic biochip (DMFB) is an emerging technology that enables miniaturized analysis systems for point-of-care clinical diagnostics, DNA sequencing, and environmental monitoring. A DMFB reduces the rate of sample and reagent consumption, and automates the analysis of assays. In this paper, we provide the first assessment of the security vulnerabilities of DMFBs. We identify result-manipulation attacks on a DMFB that maliciously alter the assay outcomes. Two practical result-manipulation attacks are shown on a DMFB platform performing enzymatic glucose assay on serum. In the first attack, the attacker adjusts the concentration of the glucose sample and thereby modifies the final result. In the second attack, the attacker tampers with the calibration curve of the assay operation. We then identify denial-of-service attacks, where the attacker can disrupt the assay operation by tampering either with the droplet-routing algorithm or with the actuation sequence. We demonstrate these attacks using a digital microfluidic synthesis simulator. The results show that the attacks are easy to implement and hard to detect. Therefore, this work highlights the need for effective protections against malicious modifications in DMFBs. Subidh Ali, Mohamed Ibrahim 0002, Ozgur Sinanoglu, Krishnendu Chakrabarty, Ramesh Karri |
IEEE ACM Trans. Comput. Biol. Bioinform. | 1 |
| 2016 | A Compact Implementation of Salsa20 and Its Power Analysis VulnerabilitiesabstractIn this article, we present a compact implementation of the Salsa20 stream cipher that is targeted towards lightweight cryptographic devices such as radio-frequency identification (RFID) tags. The Salsa20 stream cipher, ann addition-rotation-XOR (ARX) cipher, is used for high-security cryptography in NEON instruction sets embedded in ARM Cortex A8 CPU core-based tablets and smartphones. The existing literature shows that although classical cryptanalysis has been effective on reduced rounds of Salsa20, the stream cipher is immune to software side-channel attacks such as branch timing and cache timing attacks. To the best of our knowledge, this work is the first to perform hardware power analysis attacks, where we evaluate the resistance of all eight keywords in the proposed compact implementation of Salsa20. Our technique targets the three subrounds of the first round of the implemented Salsa20. The correlation power analysis (CPA) attack has an attack complexity of 2 19 . Based on extensive experiments on a compact implementation of Salsa20, we demonstrate that all these keywords can be recovered within 20,000 queries on Salsa20. The attacks show a varying resilience of the key words against CPA that has not yet been observed in any stream or block cipher in the present literature. This makes the architecture of this stream cipher interesting from the side-channel analysis perspective. Also, we propose a lightweight countermeasure that mitigates the leakage in the power traces as shown in the results of Welch’s t -test statistics. The hardware area overhead of the proposed countermeasure is only 14% and is designed with compact implementation in mind. Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2015 | Security implications of cyberphysical digital microfluidic biochipsabstractA digital microfluidic biochip (DMFB) is an emerging technology that enables miniaturized analysis systems for point-of-care clinical diagnostics, DNA sequencing, and environmental monitoring. A DMFB reduces the rate of sample and reagent consumption, and automates the analysis of assays. In this paper, we highlight the security vulnerabilities of DMFBs by identifying two potential attacks on a DMFB that performs enzymatic glucose assay on serum. In the first attack, the attacker adjusts the concentration of the glucose sample and thereby modifies the final result. In the second attack, the calibration curve of the assay operation is maliciously modified in order to make it deviate from the nominal/golden calibration curve. We demonstrate these attacks using a digital microluidics synthesis simulator. The results show that the attacks are stealthy as they do not result in any noticeable change in the DMFB synthesis. Subidh Ali, Mohamed Ibrahim 0002, Ozgur Sinanoglu, Krishnendu Chakrabarty, Ramesh Karri |
ICCD | 1 |
| 2015 | Power analysis attacks on ARX: An application to Salsa20abstractIn this paper, we analyze the vulnerability of Salsa20 stream cipher against power analysis attacks, especially against correlation power analysis (CPA), which is the strongest form of power analysis attacks. In recent literature, a rigorous study of optimal differential characteristics is presented, but an analysis of the resistance of the cipher against power analysis side-channel attacks remains absent. Our technique targets the three subrounds of the first round of Salsa20. The overall correlation based differential power analysis (DPA) has an attack complexity of 219. From extensive experiments on a reduced area implementation of Salsa20, we demonstrate that two key words k0, k7of a block in Salsa20 are extremely vulnerable to CPA while a combination of two key words k2, k4produced a very low success rate of 0.2, which shows a high resilience against correlation-analysis DPA. This varying resilience of the key words towards correlation-analysis DPA has not been observed in any stream or block cipher in present literature, which makes the architecture of this stream cipher interesting from the side-channel analysis perspective. Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
IOLTS | 2 |
| 2015 | A secure design-for-test infrastructure for lifetime security of SoCsabstractModular design of a system-on-chip (SoC) exposes intellectual property (IP) and SoC assets to attacks in test, debug, and functional modes. We enhance the SoC Design-for-Test (DfT) infrastructure with security countermeasures to thwart these attacks. We first secure IP and SoC assets from attacks in test and debug modes, then reuse the DfT infrastructure to detect attacks in functional mode. Jerry Backer, Subidh Ali, Kurt Rosenfeld, David Hély, Ozgur Sinanoglu, Ramesh Karri |
ISCAS | 2 |
| 2015 | Timing attack on NEMS relay based design of AESabstractIn deep submicron CMOS transistors, the static leakage current has become a significant contributor to power consumption with channel length and subthreshold voltage being continuously scaled down. Also, this increased leakage has recently led to the rise of side-channel attacks on CMOS based implementations. Nanoelectromechanical System (NEMS) relay technology is emerging as an alternative to CMOS with one of its most prominent advantages being the zero static leakage, providing an inherent defense against power side-channel attacks at the same time. On the other hand, this emerging technology introduces timing challenges in the design process; to minimize the timing delay of NEMS relays, binary decision diagram (BDD) based implementation is utilized to design combinational logic. What's important from a security perspective is that the timing delay of the BDD implementation of a NEMS relay based design is inherently input dependent. An adversary can therefore leverage the data dependency to identify secret information of the chip. We propose a timing delay based attack on NEMS relay based designs, use AES as a case study, and show that it can achieve a success rate of 1.0 for interconnect delay variations within a standard deviation of 0.0022. To the best of our knowledge, this paper is the first to expose an inherent security vulnerability of a NEMS relay based design. Samah Mohamed Saeed, Bodhisatwa Mazumdar, Subidh Ali, Ozgur Sinanoglu |
VLSI-SoC | 3 |
| 2015 | TMO: A new class of attack on cipher misusing test infrastructureabstractWe present a new class of scan attack on hardware implementation of ciphers. The existing scan attacks on ciphers exploit the Design for Testability (DfT) infrastructure of the implementation, where an attacker applies cipher inputs in the functional mode and then by switching to the test mode retrieves the secret key in the form of test responses. These attacks can be thwarted by applying a reset operation when there is a switch of mode. However, the mode-reset countermeasure can be thwarted by using only the test mode of a secure chip. In this work we show how a Test-Mode-Only (TMO) attack can overcome the constraints imposed by a mode-reset countermeasure and demonstrate TMO attacks on private key as well as public key ciphers. Subidh Ali, Ozgur Sinanoglu |
VTS | 1 |
| 2015 | Novel Test-Mode-Only Scan Attack and Countermeasure for Compression-Based Scan ArchitecturesabstractScan design is a de facto design-for-testability (DfT) technique that enhances access during manufacturing test process. However, it can also be used as a back door to leak secret information from a secure chip. In existing scan attacks, the secret key of a secure chip is retrieved by using both the functional mode and the test mode of the chip. These attacks can be thwarted by applying a reset operation when there is a switch of mode. However, the mode-reset countermeasure can be thwarted by using only the test mode of a secure chip. In this paper, we perform a detailed analysis on the test-mode-only scan attack. We propose attacks on an advanced encryption standard (AES) design with a basic scan architecture as well as on an AES design with an advanced DfT infrastructure that comprises decompressors and compactors. The attack results show that indeed the secure chips are vulnerable to test-mode-only attacks. The secret key can be recovered within 1 s even in the presence of decompressors and compactors. We then propose new countermeasures to thwart these attacks. The proposed countermeasures incur minimal cost while providing high success rate. Subidh Ali, Samah Mohamed Saeed, Ozgur Sinanoglu, Ramesh Karri |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2014 | Test-mode-only scan attack using the boundary scan chainabstractBoundary-scan is a very popular technology with wide applications in product life cycle that ranges from product design, prototype debugging, production to field service. However, when it comes to securing a product such as smart card, RFID tag, set-top-box, etc., the technology can be targeted by an attacker to reveal the secret information of the chip. In this paper, for the first time, we will show that the boundary scan chain can be used to bypass the mode-reset countermeasure, which is used to thwart all the scan attacks that rely on switching between the normal mode and the test mode of the chip. We propose two attacks on the AES core. The first attack uses the boundary scan chain to apply input plaintexts to the first round of AES, whereas the second attack targets the final round by applying the inputs through the internal scan chain(s) and the round output is captured in the boundary scan chain. The attacks not only bypass the mode-reset countermeasure but also circumvent the affect of stimulus decompressor (first attack) or the response compactor (second attack). Both attacks retrieve the 128-bit secret key within one minute of execution. Subidh Ali, Ozgur Sinanoglu, Ramesh Karri |
ETS | 1 |
| 2014 | Test-mode-only scan attack and countermeasure for contemporary scan architecturesabstractScan design is a de facto design-for-testability technique that enhances access during the manufacturing test process. However, it can also be exploited to leak secret information off a secure chip. A mode-reset countermeasure has been used to thwart all the existing scan attacks, as they all rely on switching between the test and normal modes. Recently, the countermeasure was circumvented by a new scan attack that utilizes only the test mode to identify the secret key of an AES chip. However, this test-mode-only attack has overlooked the other test structures, such as a decompressor and a compactor, on the scan path, which act as fortuitous countermeasures against test-mode-only scan attacks. In this work, we present a scan attack analysis for contemporary scan architectures with a stimulus decompressor unit. A stimulus decompressor poses a challenge for the test-mode-only attack, as the bit-flips required to launch the attack may not be created through the decompressor. The problem bears similarities to the test pattern encodability problem, where certain test cubes cannot be delivered due to the correlation induced by the stimulus decompressor. This paper sheds light to the intrinsic connections between the scan attack and the test pattern encodability problem, and presents a new test-mode-only scan attack in the presence of a decompressor of any type. Our analysis on an AES design shows that the proposed attack is successful for contemporary scan architectures. We also propose countermeasures that diminish the success of the proposed attack. Samah Mohamed Saeed, Subidh Ali, Ozgur Sinanoglu, Ramesh Karri |
ITC | 2 |
| 2014 | AES design space exploration new line for scan attack resiliencyabstractCrypto-chips are vulnerable to side-channel attacks. Scan attack is one such side-channel attack which uses the scan-based DFT test infrastructure to leak the secret information of the crypto-chip. In the presence of scan, an attacker can run the chip in normal mode, and then by switching to the test mode, retrieve the intermediate results of the crypto-chip. Using only a few input-output pairs one can retrieve the entire secret key. Almost all the scan attacks on AES crypto-chip use the same iterative 128-bit AES design where the round register is placed exactly after the round operation. However, the attack potency may vary depending on the design of AES. In this work, we consider various designs of AES. We shed light on the impact of design style on the scan attack. We also consider response compaction in our analysis. We show that certain design decisions deliver inherent resistance to scan attack. Subidh Ali, Ozgur Sinanoglu, Ramesh Karri |
VLSI-SoC | 1 |
| 2013 | Improved Differential Fault Analysis of CLEFIAabstractCLEFIA is already shown to be vulnerable to differential fault analysis (DFA). The existing state-of-the-art DFA shows that two faults are enough to break CLEFIA-128, whereas for CLEFIA-192 and CLEFIA-256 ten faults are needed. Side-by-side it emphasizes the need for protecting last four rounds of the cipher in order to make it secure against the attack. In this paper we propose an improved DFA on CLEFIA. The analysis shows that an attack is possible even if the last four rounds of CLEFIA are protected against DFA. Further, the proposed attacks on CLEFIA-192 and CLEFIA-256 show that 8 faults are sufficient to successfully retrieve the 192 and 256-bit key respectively. The work shows improvement over the previous work. Extensive simulation results have been presented to validate the proposed attack. The simulation results show that the attack can retrieve the 128-bit secret key in around one minute of execution time whereas the attack on 192 and 256-bit key requires around one second to retrieve the secret key. Subidh Ali, Debdeep Mukhopadhyay |
FDTC | 1 |
| 2013 | Scan attack in presence of mode-reset countermeasureabstractDesign for testability (DFT) is the most common testing technique used in the modern VLSI industries. However, when this technique is incorporated in a cryptographic circuit, it may open a back door to an attacker. The attacker can get access to the internal scan chains by switching the device from the normal mode to the test mode and then observe the chip content. The scan cells which were originally used to enhance the testability, can thus be misused to access the intermediate results of the cryptographic algorithm running inside the chip. One countermeasure against such attacks is to reset the device whenever there is a switch from the normal mode to the test mode. In this work we are going to analyse this countermeasure and show that it is not completely secure against scan attack. We show that an attack is possible using only the test mode which will bypass the countermeasure. Subidh Ali, Samah Mohamed Saeed, Ozgur Sinanoglu, Ramesh Karri |
IOLTS | 1 |
| 2013 | New scan-based attack using only the test modeabstractScan attack is a threat to crypto-chips. An attacker can leverage the test mode of the chip and control the scan chains in order to reveal the secret key. One solution for this kind of attacks is to hamper the ability to switch the device from normal mode to test mode and corrupt the data in the scan cells. If the device is reset each time it switches the mode from normal to test, all existing attacks can be thwarted. We propose a new scan-based attack by controlling only the scan chains and demonstrate it on the AES hardware. The attack uses only the test mode of the hardware and it does not require switching between normal and test mode. The attack will work even in the presence of mode blocking countermeasure. The attack requires only 375 test vectors with an attack time complexity around 212.58. Subidh Ali, Ozgur Sinanoglu, Samah Mohamed Saeed, Ramesh Karri |
VLSI-SoC | 1 |
| 2012 | Differential Fault Analysis of Twofish
Subidh Ali, Debdeep Mukhopadhyay |
Inscrypt | 1 |
| 2011 | Differential Fault Analysis of AES-128 Key Schedule Using a Single Multi-byte Fault
Subidh Ali, Debdeep Mukhopadhyay |
CARDIS | 1 |
| 2011 | Multi-level attacks: An emerging security concern for cryptographic hardwareabstractModern hardware and software implementations of cryptographic algorithms are subject to multiple sophisticated attacks, such as differential power analysis (DPA) and fault-based attacks. In addition, modern integrated circuit (IC) design and manufacturing follows a horizontal business model where different third-party vendors provide hardware, software and manufacturing services, thus making it difficult to ensure the trustworthiness of the entire process. Such business practices make the designs vulnerable to hard-to-detect malicious modifications by an adversary, termed as “Hardware Trojans”. In this paper, we show that malicious nexus between multiple parties at different stages of the design, manufacturing and deployment makes the attacks on cryptographic hardware more potent. We describe the general model of such an attack, which we refer to as Multi-level Attack, and provide an example of it on the hardware implementation of the Advanced Encryption Standard (AES) algorithm, where a hardware Trojan is embedded in the design. We then analytically show that the resultant attack poses a significantly stronger threat than that from a Trojan attack by a single adversary. We validate our theoretical analysis using power simulation results as well as hardware measurement and emulation on a FPGA platform. Subidh Ali, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay, Swarup Bhunia |
DATE | 1 |
| 2011 | A Differential Fault Analysis on AES Key Schedule Using Single FaultabstractLiterature on Differential Fault Analysis (DFA) on AES-128 shows that it is more difficult to attack AES when the fault is induced in the key schedule, than when it is injected in the intermediate states. Recent research shows that DFA on AES key schedule still requires two faulty cipher texts, while it requires only one faulty cipher text and a brute-force search of 28AES-128 keys when the fault is injected inside the round of AES. The present paper proposes a DFA on AES-128 key schedule which requires only one single byte fault and a brute-force search of 28keys, showing that a DFA on AES key schedule is equally dangerous as a fault analysis when the fault is injected in the intermediate state of AES. Further, the fault model of the present attack is a single byte fault. This is more realistic than the existing fault model of injecting three byte faults in a column of the AES key which has a less chance of success. To the best of our knowledge the proposed attack is the best known DFA on AES key schedule and requires minimum number of faulty cipher text. The simulated attack, running on 3GHz Intel Core 2 Duo desktop machine with 2GB RAM, takes around 35 minutes to reveal the secret key. Subidh Ali, Debdeep Mukhopadhyay |
FDTC | 1 |
| 2011 | Differential Fault Analysis of the Advanced Encryption Standard Using a Single Fault
Michael Tunstall, Debdeep Mukhopadhyay, Subidh Ali |
WISTP | 3 |