EDBT 2026 Demo / reviewers in the wild / expert
Yiqiang Zhao
dblp:89/2791
· DBLP profile ↗
35ranked-venue papers
4as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 22 · 2 first-author · 15 since 2021Security and privacy · 5 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An 11.5-bit ENOB 312.5kS/s Column-Parallel Two-Step Single-Slope ADC for Infrared Focal Plane Readout Circuit
Qiuwei Wang, Yiqiang Zhao |
ISCAS | 4 |
| 2025 | EO-Shield: A Shield-Based Protection Scheme Against Both Invasive and Non-Invasive AttacksabstractSmart devices, especially Internet-connected devices, typically incorporate security protocols and cryptographic algorithms to ensure the control flow integrity and information security. However, various types of attacks try to tamper with these devices, including invasive and non-invasive. Chip-level shields have been proven effective against invasive attacks, but the potential of shields as a protection mechanism against side-channel analysis (SCA) attacks remains under-explored. To bridge this gap, we propose a shield-based multi-functional protection scheme, named EO-Shield, capable of simultaneously thwarting invasive and non-invasive attacks. EO-Shield is implemented using the chip’s top metal layer and includes an Information Leakage Obfuscation Module (ILOM) underneath. This module generates its protection patterns based on the operating conditions of the circuit that need to be protected, thus reducing the correlation between electromagnetic (EM) emanations and cryptographic data. Additionally, we introduce a simulation technique to test the protection efficacy of EO-Shield at the layout level, utilizing commercial Electronic Design Automation (EDA) tools and the EMSim/EMSim+ tool. Simulation experiments demonstrate that the ILOM decreases the signal-to-noise (SNR) ratio to below 0.6 and improves the difficulty of SCA attacks by more than 100 times. Compared to existing single-function protection methods against physical attacks, EO-Shield leverages the EM protection potential of shields to offer multi-functional protection. Ya Gao 0007, Qizhi Zhang 0001, Xintong Song, Haocheng Ma, Jiaji He 0001, Yiqiang Zhao |
IEEE Trans. Circuits Syst. I Regul. Pap. | 6 |
| 2025 | Boosting Cryptographic ICs' Side-Channel Resistance: A Formal Framework for Automatic Identification and Protection of Leaky PathsabstractSide-channel analysis (SCA) attacks pose a significant threat to cryptographic integrated circuits (ICs). While designers have endeavored to introduce various countermeasures during the IC development phase, many of these solutions incur substantial overheads in terms of area, power, and performance. Additionally, they often necessitate a full-custom circuit design for effective deployment. This issue arises due to the absence of systematic methodologies and analytical tools for circuit designers to accurately identify the sources of side-channel leakage within the hardware design. In this article, we propose the concept of side-channel tracking logic and, building upon this foundation, introduce a novel framework that seamlessly integrates with commercial design flows to automatically identify and safeguard leaky paths. Our approach begins by pinpointing partial logic cells that exhibit the highest information leakage using dynamic correlation analysis. Subsequently, formal-based leakage property checking constructs comprehensive leaky paths centered on these cells. In this process, side-channel tracking logic was proposed and applied for the first time to trace and extract side-channel leakage paths. Based on this, an automated formal modeling and leakage property verification tool was designed. Once these paths are discerned, we deploy apt hardware countermeasures, encompassing Boolean masking and random precharge, to eradicate information leakage along these routes. This framework has been experimentally validated across different encryption circuits and the efficacy of our methodology is corroborated through both simulated and real-world measurements on FPGA implementations. Empirical results showcase an enhancement of over 1000× in side-channel resistance, incurring a modest overhead of less than 6.53% across power, area, and performance metrics. Qizhi Zhang 0001, Ya Gao 0007, Haocheng Ma, Jiaji He 0001, Yiqiang Zhao, Xiaolong Guo 0001 |
ACM Trans. Embed. Comput. Syst. | 5 |
| 2024 | Static Gate-Level Information Flow for Hardware Information Security with Bounded Model CheckingabstractInformation flow security is an essential component of hardware security. Ensuring the confidentiality, integrity, and availability of data within hardware systems is critical to protect against unauthorized access, data breaches, tampering, and other security threats. Gate-level information flow technology can trace the flow of signals to detect malicious information flow and security vulnerabilities in the design. In this paper, we introduce a novel framework that combines GLIFT and bounded model checking to enable the static verification of information flow within hardware systems. This combination facilitates designers conducting exhaustive analysis, tracking of information flows and detecting potential security threats in their designs. When the design violates security policies, our framework provides a counterexample that assists designers in identifying malicious information flows in the hardware circuits. To demonstrate the efficiency of our framework, we conducted verification on hardware Trojan benchmarks from the Trust-hub. The results indicate that our verification framework is capable of detecting malicious information flows that exist in the designs. Yiqiang Zhao, Gonsen Qu, Qizhi Zhang 0001, Yao Li 0024, Jiaji He 0001 |
VTS | 1 |
| 2024 | EMSim+: Accelerating Electromagnetic Security Evaluation With Generative Adversarial Network and Transfer LearningabstractElectromagnetic side-channel analysis (EM SCA) attack poses a serious threat to integrated circuits (ICs), necessitating timely vulnerability detection before deployment to enhance EM side-channel security. Various EM simulation methods have emerged for analyzing EM side-channel leakage, providing sufficiently accurate results. However, these simulator-based methods still face two principal challenges in the design process of high security chips. Firstly, the large volume of measurement data required for a single security evaluation results in substantial time overhead. Secondly, design iterations lead to repetitive security evaluations, thus increasing the evaluation cost. In this paper, we propose EMSim+ which includes two efficient and accurate layout-level EM side-channel leakage evaluation frameworks named EMSim+GAN and EMSim+GAN+TL to mitigate the above challenges, respectively. EMSim+GAN integrates a Generative Adversarial Network (GAN) model that utilizes the chip’s cell current and power grid information to predict EM emanations quickly. EMSim+GAN+TL further incorporates transfer learning (TL) within the framework, leveraging the experience of existing designs to reduce the training datasets for new designs and achieve the target accuracy. We compare the simulation results of EMSim+ with the state-of-the-art EM simulation tool, EMSim as well as silicon measurements. Experimental results not only prove the high efficiency and high simulation accuracy of EMSim+, but also verify its generalization ability across different designs and technology nodes. Ya Gao 0007, Haocheng Ma, Qizhi Zhang 0001, Xintong Song, Yier Jin, Jiaji He 0001, Yiqiang Zhao |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | A CMOS Readout Circuit for Resistive Tactile Sensor Array Using Crosstalk Suppression and Nonuniformity Compensation TechniquesabstractThis article presents a novel readout circuit for the resistive tactile sensor array. Based on the 2-D scanning mechanism, a crosstalk suppression technique is proposed by combining the correlated double sampling (CDS) and zero potential method (ZPM). The output of the same sensor under different bias conditions is captured twice and amplified by a channel-parallel fully differential gain stage, performing analogous subtraction. To achieve nonuniformity compensation, the current injected into the readout channel is adjusted by the channel-parallel digital-to-analog converter (DAC). A successive approximation register (SAR) analog-to-digital converter (ADC) performs quantization, and the chip can be used as a serial peripheral interface (SPI) slave to update register values for gain configuration, power consumption control, and nonuniformity compensation. The 180-nm CMOS prototype chip occupies an area of$4.8~\text {mm}^{2}$and consumes$285~\mu $W. In order to validate the design, a tactile sensing system is built, using the readout circuit along with a$10\times 10$flexible sensor array. With the techniques proposed in this article, the readout error of the sensors in array is less than 0.3‰. Yao Li 0024, Junfeng Geng, Mao Ye 0007, Jiaji He 0001, Xiaoxiao Zheng, Qiuwei Wang, Yiqiang Zhao |
IEEE Trans. Very Large Scale Integr. Syst. | 7 |
| 2024 | A CMOS AFE Array With DC Input Current Cancellation for FMCW LiDARabstractThis article presents a low noise and wide linear dynamic 20-channel analog front-end (AFE) array for frequency-modulated continuous-wave (FMCW) light detection and ranging (LiDAR) system. Each channel of the AFE array mainly consists of a shunt feedback transimpedance amplifier (SF-TIA) with a dc cancellation loop (DCL), a post amplifier, and an output buffer. The DCL is proposed to eliminate the dc current, comprising the dc current sunk to ground (dc-STG) and the dc current sourced from power supply (dc-SFP). In addition, the post amplifier, cascaded with an operational transconductance amplifier (OTA) and an SF-TIA, is proposed to decouple the relationship between gain and output common voltage, achieving both large gain and large output swing. Furthermore, the equalization technique is adopted to expand the bandwidth of the AFE array. The AFE array was implemented and fabricated in a 0.18-$\mu \text{m}$CMOS technology. Measurement results show that the AFE array achieves the maximum transimpedance gain of 107 dB and eliminates the dc current between −150 and$250 ~\mu \text{A}$. With the maximum transimpedance gain, the measured bandwidth, the equivalent input-referred rms noise current, and the signal-to-crosstalk ratio (SCR) between adjacent channels are 165 MHz, 29.4 nArms, and −33.9 dB, respectively. The AFE array also achieves a linear dynamic range (DR) of 66 dB and the area of each channel is approximately equal to$0.16\times1.3$mm2. Xiaoxiao Zheng, Mao Ye 0007, Yao Li 0024, Qiuwei Wang, Yiqiang Zhao |
IEEE Trans. Very Large Scale Integr. Syst. | 6 |
| 2023 | EO-Shield: A Multi-Function Protection Scheme against Side Channel and Focused Ion Beam AttacksabstractSmart devices, especially Internet-connected devices, typically incorporate security protocols and cryptographic algorithms to ensure the control flow integrity and information security. However, there are various invasive and non-invasive attacks trying to tamper with these devices. Chip-level active shield has been proved to be an effective countermeasure against invasive attacks, but existing active shields cannot be utilized to counter side-channel attacks (SCAs). In this paper, we propose a multi-function protection scheme and an active shield prototype to against invasive and non-invasive attacks simultaneously. The protection scheme has a complex active shield implemented using the top metal layer of the chip and an information leakage obfuscation module underneath. The leakage obfuscation module generates its protection patterns based on the operating conditions of the circuit that needs to be protected, thus reducing the correlation between electromagnetic (EM) emanations and cryptographic data. We implement the protection scheme on one Advanced Encryption Standard (AES) circuit to demonstrate the effectiveness of the method. Experiment results demonstrate that the information leakage obfuscation module decreases SNR below 0.6 and reduces the success rate of SCAs. Compared to existing single-function protection methods against physical attacks, the proposed scheme provides good performance against both invasive and non-invasive attacks. Ya Gao 0007, Qizhi Zhang 0001, Haocheng Ma, Jiaji He 0001, Yiqiang Zhao |
ASP-DAC | 5 |
| 2023 | EMSim+: Accelerating Electromagnetic Security Evaluation with Generative Adversarial NetworkabstractElectromagnetic side-channel analysis (EM SCA) attack is a serious threat to integrated circuits (ICs). In order to detect vulnerabilities in time at the pre-silicon stage and to improve the chip's robustness to EM SCA attacks, several EM simulation methods have emerged for EM side-channel leakage evaluation. Although the simulated results are accurate, the chip security evaluation in practice requires up to hundreds of millions simulation traces, which imposes an unrealistic computational and time overhead on these simulator-based methods. In this paper, we develop a tool named EMSim+. Different from the general EM security evaluation process, EMSim+ introduces machine learning (ML) to accelerate the simulation of layout-level EM emanations. Based on the generative adversarial network (GAN), a well-trained EMSim+ model can accept the cell current and power grid information of the chip and rapidly predict the EM emanation of the chip surface. We apply EMSim+ to a series of representative cryptographic circuits and compare the simulation results with the state-of-the-art EM simulation method and silicon measurements. The experimental results prove that EMSim+ has high simulation accuracy and achieves more than 242 times evaluation time reduction for 1 M sample data. Ya Gao 0007, Haocheng Ma, Jindi Kong, Jiaji He 0001, Yiqiang Zhao, Yier Jin |
ICCAD | 5 |
| 2023 | A large-scale point cloud semantic segmentation network via local dual features and global correlations
Yiqiang Zhao, Xingyi Ma, Bin Hu 0024, Mao Ye 0007, Guoqing Zhou 0001 |
Comput. Graph. | 1 |
| 2023 | Side Channel Security Oriented Evaluation and Protection on Hardware Implementations of KyberabstractThe emergence of quantum computing and its impact on current cryptographic algorithms has triggered the migration to post-quantum cryptography (PQC). Among the PQC candidates, CRYSTALS-Kyber is a key encapsulation mechanism (KEM) that stands out from the National Institute of Standards and Technology (NIST) standardization project. While software implementations of Kyber have been developed and evaluated recently, Kyber’s hardware implementations especially those designed with parallel architecture, are rarely discussed. To help better understand Kyber hardware designs and their security against side-channel analysis (SCA) attacks, in this paper, we first adapt the two most recent Kyber hardware designs for FPGA implementations. We then perform SCA attacks against these hardware designs with different architectures, i.e., parallelization and pipelining. Our experimental results show that Kyber designs on FPGA boards are vulnerable to SCA attacks including electromagnetic (EM) and power side channels. An attacker only needs$27 \sim 1,600$power traces or$60 \sim 2,680$EM traces to recover the decryption key successfully. Furthermore, we propose two first-order IND-CPA Kyber decapsulation masking protected designs, and then we evaluate their securities and overheads. The experimental results demonstrate that the side channel security of masked Kyber designs has increased by more than 10x. Yiqiang Zhao, Shijian Pan, Haocheng Ma, Ya Gao 0007, Xintong Song, Jiaji He 0001, Yier Jin |
IEEE Trans. Circuits Syst. I Regul. Pap. | 1 |
| 2023 | Off-Axis Four-Reflection Optical Structure for Lightweight Single-Band Bathymetric LiDARabstractA traditional bathymetric LiDAR (light detection and ranging) has disadvantages such as large volume, heavy weight, necessity for airport and runway, and high cost for operation. For these reasons, this paper presents an off-axis four-reflection optical structure for single-band (532 nm) bathymetric LiDAR carried on UAV (Unmanned Aerial Vehicle). This optical system fully considers characteristics of the laser echo energy under different water conditions, which relate with the optical system parameters, such as peak power of laser emission, field of view (FOV), receiver aperture area, etc. The proposed optical system designs the objective lens, which are composed of one APD detector and two PMT detectors, the primary mirror, the second mirror, the plane mirror and the third mirror, two split field mirrors that separate the echo signals from shallow water, medium water and deep water, respectively. This proposed optical system was verified in laboratory tank, swimming pool, Lijiang River, lake, and the Qiaogang Sea Bay. It is found that the maximum water depth measured can reach 25.0 m with an error less than 0.1 m averagely. The dimension and weight of this LiDAR reach 90mm×160mm×90mm, and 10.25 kg, respectively, which is lightest and smallest bathymetric LiDAR worldwide. Guoqing Zhou 0001, Jiasheng Xu, Haocheng Hu, Zhexian Liu, Haotian Zhang 0014, Xiang Zhou 0002, Jiazhi Yang, Xueqin Nong, Naihui Song, Guoshuai Jia, Hanjiang Xiong, Yiqiang Zhao |
IEEE Trans. Geosci. Remote. Sens. | 15 |
| 2023 | EMSim: A Fast Layout Level Electromagnetic Emanation Simulation Framework for High Accuracy Pre-Silicon VerificationabstractElectromagnetic (EM) emanation measurement and evaluation is one important testing for modern integrated circuits (ICs). Severe electromagnetic interference may degrade the performance of electronic devices or even cause system crashes. As a result, modern ICs need to follow strict electromagnetic compatibility (EMC) requirements. Moreover, EM emanations offer a covert channel for adversaries to steal secret information from fabricated ICs, causing side channel attacks. Due to the lack of fast and high-accuracy EM simulation tools, existing EM measurements often happen at the post-silicon stage. Any identification of side channel vulnerability or EM incompatibility may lead to high cost and delay the time-to-market. As a result, design-time EM simulation tools with fast simulation speed and high accuracy for pre-silicon designs are urgently needed. To this end, we propose EMSIM, a layout-level EM simulation framework that significantly speeds up the EM simulation process while maintaining high accuracy of the simulated EM emanations. To achieve this goal, we provide the theoretical explanation for the root cause of EM emanations from ICs. Guiding by this, EMSIM leverages techniques of parasitic network reduction and device model approximation to reduce the computation complexities while still ensuring high simulation accuracy. EMSIM further leverages Graphics Processing Unit (GPU) resources to solve equations for EM simulation. The efficiency and effectiveness of EMSIM are validated by showing the consistency between simulation results and physical measurements obtained from fabricated circuit designs. Haocheng Ma, Max Panoff, Jiaji He 0001, Yiqiang Zhao, Yier Jin |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | PathFinder: side channel protection through automatic leaky paths identification and obfuscationabstractSide-channel analysis (SCA) attacks show an enormous threat to cryptographic integrated circuits (ICs). To address this threat, designers try to adopt various countermeasures during the IC development process. However, many existing solutions are costly in terms of area, power and/or performance, and may require full-custom circuit design for proper implementations. In this paper, we propose a tool, namely PathFinder, to automatically identify leaky paths and protect the design, and is compatible with the commercial design flow. The tool first finds out partial logic cells that leak the most information through dynamic correlation analysis. PathFinder then exploits static security checking to construct complete leaky paths based on these cells. After leaky paths are identified, PathFinder will leverage proper hardware countermeasures, including Boolean masking and random precharge, to eliminate information leakage from these paths. The effectiveness of PathFinder is validated both through simulation and physical measurements on FPGA implementations. Results demonstrate more than 1000X improvements on side-channel resistance, with less than 6.53% penalty to the power, area and performance. Haocheng Ma, Qizhi Zhang 0001, Ya Gao 0007, Jiaji He 0001, Yiqiang Zhao, Yier Jin |
DAC | 5 |
| 2022 | Security Oriented Design Framework for EM Side-Channel Protection in RTL ImplementationsabstractElectromagnetic (EM) side-channel analysis is a powerful attack for extracting secret information from cryptographic hardware implementations. Countermeasures have been proposed at the register-transfer level (RTL), layout level, and device level. However, existing EM radiation modeling and side-channel vulnerability mitigation methods do not consider the structural resilience of original designs, nor do they provide fine-grained security enhancements to those vulnerable submodules/components. These universal solutions may introduce unnecessary overheads on the circuit under protection and may not be optimized for individual designs. In this article, we propose a design/synthesis for side-channel security evaluation and optimization framework based on the${t}$-test evaluation results derived from RTL hardware implementations. While the framework apply to different side-channel leakage, we focus more on EM side channels. Supported by this framework, different RTL implementations of the same cryptographic algorithm will be evaluated for their side-channel resistance. In vulnerable implementations, submodules with the most significant side-channel leakages will be identified. Security design/synthesis rules will then be applied to these vulnerable submodules for security enhancements against side-channel attacks (SCAs). Experiments, including simulations and FPGA implementations on different AES designs, are performed to validate the effectiveness of the proposed framework as well as the security design/synthesis rules. Jiaji He 0001, Haocheng Ma, Max Panoff, Hanning Wang, Yiqiang Zhao, Leibo Liu, Xiaolong Guo 0001, Yier Jin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2021 | MM-Flow: Multi-modal Flow Network for Point Cloud CompletionabstractPoint cloud is often noisy and incomplete. Existing completion methods usually generate the complete shapes for missing regions of 3D objects based on the deterministic learning frameworks, which only predict a single reconstruction output. However, these methods ignore the ill-posed nature of the completion problem and do not fully account for multiple possible completion predictions corresponding to one incomplete input. To address this problem, we propose a flow-based network together with a multi-modal mapping strategy for 3D point cloud completion. Specially, an encoder is first introduced to encode the input point cloud data into a rich latent representation suitable for conditioning in all flow-layers. Then we design a conditional normalizing flow architecture to learn the exact distribution of the plausible completion shapes over the multi-modal latent space. Finally, in order to fully utilize additional shape information, we propose a tree-structured decoder to perform the inverse mapping for complete shape generation with high fidelity. The proposed flow network is trained using a single loss named the negative log-likelihood to capture the distribution variations between input and output, without complex reconstruction loss and adversarial loss. Extensive experiments on ShapeNet dataset, KITTI dataset and measured data demonstrate that our method outperforms the state-of-the-art point cloud completion methods through qualitative and quantitative analysis. Yiqiang Zhao, Yiyao Zhou, Rui Chen 0006, Bin Hu 0024, Xiding Ai |
ACM Multimedia | 1 |
| 2021 | Point cloud denoising using non-local collaborative projections
Yiyao Zhou, Rui Chen 0006, Yiqiang Zhao, Xiding Ai, Guoqing Zhou 0001 |
Pattern Recognit. | 3 |
| 2021 | Process Variation-Resistant Golden-Free Hardware Trojan Detection through a Power Side ChannelabstractWith the globalization of the manufacturing supply chain, the malicious modification existing in the middle of distrust is becoming an important security issue on the chip. These modifications are called hardware Trojan (HT). HT is difficult to detect due to its high concealment and diversity of implementation. HT detection based on the side channel is a relatively effective detection method because it does not need to trigger the Trojan or destroy the chip. However, detection based on the side channel faces two major challenges. Firstly, the side channel detection is quite dependent on the golden model. The second one relates to the accuracy of the samples. Side channel information of the chip comes from the hardware manufacturing process and implementation, so it is obviously affected by process variation. In the existing work, many self-reference detection methods have been proposed to solve the problem of missing golden models. However, the existing methods often have special requirements for the circuit structure (such as the need for self-similar structures in the circuit). And, they can hardly resist process variation. This paper combines design and detection. We select the power consumption generated at different times and construct two self-reference ‘knapsack’ to detect HT. The solution proposed in this article is a kind of self-reference method, but we need neither self-similar structures nor the same state of some clocks in the circuit. Meanwhile, by constructing the ‘knapsack,’ we reduce the impact of process variation on detection accuracy because the process variation in the two sets of power consumption is balanced. Yidong Yuan, Yao Zhang 0015, Yiqiang Zhao, Xige Zhang, Ming Tang 0002 |
Secur. Commun. Networks | 3 |
| 2021 | On-Chip Trust Evaluation Utilizing TDC-Based Parameter-Adjustable Security PrimitiveabstractField-programmable gate arrays (FPGAs) are integrated circuits (ICs) that can be reconfigured to the desired functionalities, without manufacturing dedicated chips. Due to their programmable nature, FPGAs have been prevalent in the large majority of modern systems. This raises high demands for verifying the security of circuit implementations on FPGAs, since they are vulnerable to hardware trojans (HTs) that can be inserted through modified configuration files. In this article, we propose an on-chip security framework to ensure the trustworthiness of circuit implementations on FPGAs at runtime. The core of the framework is a time-to-digital converter (TDC)-based hardware security primitive that can be predeployed on FPGAs to verify whether the FPGA-based designs are tampered with or corrupted by HTs. The parameter-adjustable TDC sensor, which is the primary component of the primitive, is carefully designed, adjusted, and implemented, thus the TDC sensor can monitor the transient voltage fluctuations within FPGAs with a high resolution. Versus statistical data analysis, tiny abnormal variations introduced by the Trojan insertion and activation are distinguished. Experimental results on Xilinx Spartan-6 FPGAs demonstrate the effectiveness of the proposed TDC-based on-chip trust evaluation framework and HT detection method. Haocheng Ma, Jiaji He 0001, Yanjiang Liu, Jun Kuai, He Li 0008, Leibo Liu, Yiqiang Zhao |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2021 | Security-Driven Placement and Routing Tools for Electromagnetic Side-Channel ProtectionabstractSide-channel analysis (SCA) attacks are major threats to hardware security. Upon this security threat, various countermeasures at different design layers have been proposed against SCA attacks. These approaches often introduce significant overheads and impose high requirements of side-channel security backgrounds to integrated circuit (IC) designers. In this article, we propose an automatic computer-aided design (CAD) tool that can be utilized to enhance the circuit resistance against electromagnetic (EM) SCA attacks. This new tool will guide security-driven placement and routing processes and can be seamlessly integrated into the modern IC design flow. The protected IC design will be resilient to SCA attacks with negligible area and power overheads. In order to develop this tool, we first investigate the root-cause of EM leakage at the layout level and mathematically demonstrate the feasibility of security-driven placement and routing through the EM leakage modeling. We then identify that the correlation between the data under protection and the EM leakage can be significantly reduced through data-dependent register reallocation and wire length adjustments. Simulation results on cryptographic circuits prove the effectiveness of both the constructed EM leakage model and the EM model-based CAD tool for EM side-channel security. Haocheng Ma, Jiaji He 0001, Yanjiang Liu, Leibo Liu, Yiqiang Zhao, Yier Jin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2021 | Golden Chip-Free Trojan Detection Leveraging Trojan Trigger's Side-Channel FingerprintingabstractHardware Trojans (HTs) have become a major threat for the integrated circuit industry and supply chain and have motivated numerous developments of HT detection schemes. Although the side-channel HT detection approach is among the most promising solutions, most of the previous methods require a trusted golden chip reference. Furthermore, detection accuracy is often influenced by environmental noise and process variations. In this article, a novel electromagnetic (EM) side-channel fingerprinting-based HT detection method is proposed. Different from previous methods, the proposed solution eliminates the requirement of a trusted golden fabricated chip. Rather, only the genuine RTL code is required to generate the EM signatures as references. A factor analysis method is utilized to extract the spectral features of the HT trigger’s EM radiation, and then a k -means clustering method is applied for HT detection. Experimentation on two selected sets of Trust-Hub benchmarks has been performed on FPGA platforms, and the results show that the proposed framework can detect all dormant HTs with a high confidence level. Jiaji He 0001, Haocheng Ma, Yanjiang Liu, Yiqiang Zhao |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2021 | Test Generation for Hardware Trojan Detection Using Correlation Analysis and Genetic AlgorithmabstractHardware Trojan (HT) is a major threat to the security of integrated circuits (ICs). Among various HT detection approaches, side channel analysis (SCA)-based methods have been extensively studied. SCA-based methods try to detect HTs by comparing side channel signatures from circuits under test with those from trusted golden references. The pre-condition for SCA-based HT detection to work is that the testers can collect extra signatures/anomalies introduced by activated HTs. Thus, activation of HTs and amplification of the differences between circuits under test and golden references are the keys to SCA-based HT detection methods. Test vectors are of great importance to the activation of HTs, but existing test generation methods have two major limitations. First, the number of test vectors required to trigger HTs is quite large. Second, the HT circuit’s activities are marginal compared with the whole circuit’s activities. In this article, we propose an optimized test generation methodology to assist SCA-based HT detection. Considering the HTs’ inherent surreptitious nature, inactive nodes with low transition probability are more likely to be selected as HT trigger nodes. Therefore, the correlations between circuit inputs and inactive nodes are first exploited to activate HTs. Then a test reordering process based on the genetic algorithm (GA) is implemented to increase the proportion of the HT circuit’s activities to the whole circuit’s activities. Experiments on 10 selected ISCAS benchmarks, wb_conmax benchmark, and b17 benchmark demonstrate that the number of test vectors required to trigger HTs reduces 28.8% on average compared with the result of MERO and MERS methods. After the test vector reordering process, the proportion of the HT circuit’s activities to the whole circuit’s activities is improved by 95% on average, compared with the result of MERS method. Zhendong Shi, Haocheng Ma, Qizhi Zhang 0001, Yanjiang Liu, Yiqiang Zhao, Jiaji He 0001 |
ACM Trans. Embed. Comput. Syst. | 5 |
| 2020 | Design for EM Side-Channel Security through Quantitative Assessment of RTL ImplementationsabstractElectromagnetic (EM) side-channel attacks aim at extracting secret information from cryptographic hardware implementations. Countermeasures have been proposed at device level, register-transfer level (RTL) and layout level, though efficient, there are still requirements for quantitative assessment of the hardware implementations' resistance against EM side-channel attacks. In this paper, we propose a design for EM side-channel security evaluation and optimization framework based on the t-test evaluation results derived from RTL hardware implementations. Different implementations of the same cryptographic algorithm are evaluated under different hypothesis leakage models considering the driven capabilities of logic components, and the evaluation results are validated with side-channel attacks on FPGA platform. Experimental results prove the feasibility of the proposed side-channel leakage evaluation method at pre-silicon stage. The remedies and suggested security design rules are also discussed. Jiaji He 0001, Haocheng Ma, Xiaolong Guo 0001, Yiqiang Zhao, Yier Jin |
ASP-DAC | 4 |
| 2020 | Runtime Trust Evaluation and Hardware Trojan Detection Using On-Chip EM SensorsabstractIt has been widely demonstrated that the utilization of postdeployment trust evaluation approaches, such as side-channel measurements, along with statistical analysis methods is effective for detecting hardware Trojans in fabricated integrated circuits (ICs). However, more sophisticated Trojans proposed recently invalidate these methods with stealthy triggers and very-low side-channel signatures. Upon these challenges, in this paper, we propose an electromagnetic (EM) side-channel based post-fabrication trust evaluation framework which monitors EM radiations at runtime. The key component of the runtime trust evaluation framework is an on-chip EM sensor which can constantly measure and collect EM side-channel information of the target circuit. The simulation results validate the capability of the proposed framework in detecting stealthy hardware Trojans. Further, we fabricate an AES circuit protected by the proposed trust evaluation framework along with four different types of hardware Trojans. The measurements on the fabricated chips prove two key findings. First, the on-chip EM sensor can achieve a higher signal to noise ratio (SNR) and thus facilitate a better Trojan detection accuracy. Second, the trust evaluation framework can help detect different hardware Trojans at runtime. Jiaji He 0001, Xiaolong Guo 0001, Haocheng Ma, Yanjiang Liu, Yiqiang Zhao, Yier Jin |
DAC | 5 |
| 2020 | Golden chip free Trojan detection leveraging probabilistic neural network with genetic algorithm applied in the training phase
Yanjiang Liu, Jiaji He 0001, Haocheng Ma, Yiqiang Zhao |
Sci. China Inf. Sci. | 4 |
| 2020 | Random active shield generation based on modified artificial fish-swarm algorithm
Ruishan Xin, Yidong Yuan, Jiaji He 0001, Shuai Zhen, Yiqiang Zhao |
Comput. Secur. | 5 |
| 2020 | A Low-Complexity Hybrid Readout Circuit for Lidar ReceiverabstractThis brief presents a low-complexity hybrid readout architecture that can extract both timing and amplitude information of the return pulse concurrently for a light detection and ranging radar (Lidar) receiver. To reconstruct the short return pulse, the core circuit of one sampling and storage array with an embedded time-to-digital converter (SSA-TDC) is proposed. Instead of relying on the conventional power-hungry high-speed ADC, it selectively samples the interested return pulse with high speed and stores the voltages for later quantization in the long idle interval. In the preceding stage of the SSA-TDC, the analog front-end circuit cascaded of a narrow-bandwidth transimpedance amplifier, a voltage amplifier, and an equalizer circuit is included. The prototype chip of the eight readout channels is designed and fabricated with the 0.18-μm CMOS process. The active circuit occupies an area of 1200 μm × 2100 μm, and the power consumption of one single channel is 45 mW with 3.3-V supply. The proposed SSA-TDC has achieved a dynamic error of 180 ps in the experimental study. Mao Ye 0007, Xiaoxiao Zheng, Yao Li 0024, Yiqiang Zhao |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2019 | High-efficient generation algorithm for large random active shield
Ruishan Xin, Yidong Yuan, Jiaji He 0001, Yuehui Li, Yiqiang Zhao |
Sci. China Inf. Sci. | 5 |
| 2019 | Hardware Trojan Detection Leveraging a Novel Golden Layout Model Towards Practical Applications
Yanjiang Liu, Jiaji He 0001, Haocheng Ma, Yiqiang Zhao |
J. Electron. Test. | 4 |
| 2019 | SoC interconnection protection through formal verification
Jiaji He 0001, Xiaolong Guo 0001, Travis Meade, Raj Gautam Dutta, Yiqiang Zhao, Yier Jin |
Integr. | 5 |
| 2018 | A study of residual characteristics in floating gate transistors
Yiqiang Zhao, Ruishan Xin, Mao Ye 0007 |
Sci. China Inf. Sci. | 2 |
| 2017 | Hardware Trojan Detection Through Chip-Free Electromagnetic Side-Channel Statistical AnalysisabstractThe hardware Trojan (HT) has become a major threat for the integrated circuit (IC) industry and supply chain, and has motivated numerous developments of Trojan detection schemes. Although the side-channel method is the most promising one, nearly all of the side-channel methods require fabricated golden chips, which are very difficult to obtain in reality. In this paper, we propose a novel strategy for HT detection using electromagnetic side-channel-based spectrum modeling and analyzing. We utilize the design data at early stage of the IC lifecycle, and the generated spectrum can serve as the golden reference, and thus we do not need the fabricated golden chips anymore. Another very important feature is that our method is immune to the process variation theoretically. Experimental results on selected Advanced Encryption Standard benchmark circuits on FPGA show that our proposed method can effectively detect Trojans even with very small traces. Jiaji He 0001, Yiqiang Zhao, Xiaolong Guo 0001, Yier Jin |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2011 | Green challenges to system software in data centers
Yuzhong Sun, Yiqiang Zhao, Yajun Yang, Haifeng Fang, Hongyong Zang, Yaqiong Li, Yunwei Gao |
Frontiers Comput. Sci. China | 2 |
| 2010 | TRIOB: A Trusted Virtual Computing Environment Based on Remote I/O Binding Mechanism
Haifeng Fang, Yiqiang Zhao, Yuzhong Sun, Zhiyong Liu 0002 |
CANS | 3 |
| 2010 | VMGuard: An Integrity Monitoring System for Management Virtual MachinesabstractA cloud computing provider can dynamically allocate virtual machines (VM) based on the needs of the customers, while maintaining the privileged access to the Management Virtual Machine that directly manages the hardware and supports the guest VMs. The customers must trust the cloud providers to protect the confidentiality and integrity of their applications and data. However, as the VMs from different customers are running on the same host, an attack to the management virtual machine will easily lead to the compromise of the guest VMs. Therefore, it is critical for a cloud computing system to ensure the trustworthiness of management VMs. To this end, we propose VMGuard, an integrity monitoring and detecting system for management virtual machines in a distributed environment. VMGuard utilizes a special VM, Guard Domain, which runs on each physical node to monitor the co-resident management VMs. The integrity measurements collected by the Guard Domains are sent to the VMGuard server for safe store and independent analysis. The experimental evaluation of a Xen-based prototype shows that VMGuard can quickly detect the root kit attacks while the performance overhead is low. Haifeng Fang, Yiqiang Zhao, Hongyong Zang, H. Howie Huang, Yuzhong Sun, Zhiyong Liu 0002 |
ICPADS | 2 |