EDBT 2026 Demo / reviewers in the wild / expert
James F. Plusquellic
dblp:p/JPlusquellic · also Jim Plusquellic
· DBLP profile ↗
62ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-1876-117XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 50 · 5 first-author · 6 since 2021Computer networks · 5 · 4 since 2021Security and privacy · 4Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LEAD: Link Exploitability Analysis for Die-to-Die Interconnects in Heterogeneous Integration*
Arjun Hati, Eduardo Ortega, Jonti Talukdar, James F. Plusquellic, Krishnendu Chakrabarty |
VTS | 4 |
| 2026 | Jamming Attacks Detection and Ejection in Over the Air Computation Concentrated Solar Power SystemsabstractThe integration of the Over-the-Air Computation (AirComp) in Concentrated Solar Power (CSP) systems offers a transformative potential for real-time data aggregation in 6G-IoT networks. However, such an innovative deployment introduces critical vulnerabilities to jamming attacks that distort the aggregated signals without detection. This paper introduces a robust security framework that leverages an artificial intelligence (AI) statistical signal analysis, adaptive detection thresholds, and spatially-aware mitigation to detect and eject both simple and coordinated jamming attacks in real-world AirComp CSP systems. Detailed experimental validation at the National Solar Thermal Test Facility demonstrates significant improvements in the data aggregation and attack detection rates. It also ensures trustworthy data aggregation from commercial CSP fields, while maintaining their operational resilience. Dipanjan Adhikary, James F. Plusquellic, Eirini-Eleni Tsiropoulou |
IEEE Internet Things J. | 2 |
| 2025 | Denial of Service Attacks in Over-the-Air Computation for Internet of Medical Things
Dipanjan Adhikary, James F. Plusquellic, Eirini-Eleni Tsiropoulou |
GLOBECOM | 2 |
| 2024 | PUF-based Digital Money with Propagation-of-Provenance and Offline Transfers between Two PartiesabstractBuilding on prior concepts of electronic money (eCash), we introduce a digital currency where a physical unclonable function (PUF) engenders devices with the twin properties of being verifiably enrolled as a member of a legitimate set of eCash devices and of possessing a hardware-based root-of-trust. A hardware-obfuscated secure enclave (HOSE) is proposed as a means of enabling a PUF-based propagation-of-provenance (POP) mechanism, which allows eCash tokens ( eCt ) to be securely signed and validated by recipients without incurring any third-party dependencies at transfer time. The POP scheme establishes a chain of custody starting with token creation, extending through multiple bilateral in-field transactions, and culminating in redemption at the token-issuing authority. A lightweight mutual-zero-trust (MZT) authentication protocol establishes a secure channel between any two fielded devices. The POP and MZT protocols, in combination with the HOSE, enable transitivity and anonymity of eCt transfers between online and offline devices. Benjamin Bean, Cyrus Minwalla, Eirini-Eleni Tsiropoulou, James F. Plusquellic |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2024 | Self-Assertion-Based Countermeasures Within a RISC-V Microprocessor for Coverage of Information Leakage FaultsabstractThe execution behavior of a microprocessor$(\mu {P})$in the presence of a fault is difficult to predict because of the complex interactions across pipeline stages and between functional units within the architecture. In prior work, we have observed that fault effects do not introduce any type of anomaly in the input-output behavior for 10s of thousands to millions of clock cycles. These characteristics increase the difficulty of evaluating$\mu {P}$architectures for resilience to information leakage events, i.e., scenarios where a fault causes sensitive data, such as an encryption key, to be inadvertently diverted to a primary output channel. In this article, we use an accelerated fault emulation platform implemented on a Xilinx ZCU102 board to evaluate an ASIC implementation of the Potato RISC-V$\mu {P}$for information leakage events as faults from several different classes are introduced. The effectiveness and latency associated with a set of self-assertion-based countermeasures (SABCs), that perform simple consistency checks on instructions and datapath values, are investigated. The countermeasures are characterized as dynamic verification (or as a continuous symptom monitor) because detection occurs during program execution. The detection and latency results of the SABCs are compared against a periodic counter-based countermeasure proposed in previous work. Idris Somoye, Tom J. Mannos, Brian Dziki, James F. Plusquellic |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2023 | SAFE: Secure Symbiotic Positioning, Navigation, and TimingabstractIncreasing the security and robustness of Positioning, Navigation, and Timing (PNT) systems is a critical issue towards exploiting the PNT service at its full capacity. In this paper, we treat the joint problem of designing a secure and robust alternative PNT solution that supports the targets' PNT services, while simultaneously detecting and ejecting malicious nodes from the system that aim at deteriorating the proposed PNT solution's accuracy. The overall problem is formulated as a non-cooperative game among the targets and other collaborator nodes in order to jointly minimize their personal experienced positioning and timing error, as well as the overall system's error. The theory of potential games is adopted to prove the existence of at least one Pure Nash Equilibrium (PNE), while a log-linear-based reinforcement learning (RL) algorithm is proposed to enable the targets and collaborators to determine such a PNE. A detailed analysis for attack detection is presented considering both single-attack and distributed denial of service (DDoS) attack scenarios, where the malicious collaborators can fake their coordinates and their transmission power, while an overall PNT methodology including their ejection from the system is outlined. The performance evaluation of the proposed approach is achieved via modeling and simulation. Md Sadman Siraj, Eirini-Eleni Tsiropoulou, Symeon Papavassiliou, James F. Plusquellic |
GLOBECOM | 4 |
| 2022 | Network Economics-based Crowdsourcing in UAV-assisted Smart Cities EnvironmentsabstractIn this paper, a novel crowdsourcing mechanism is introduced in Unmanned Aerial Vehicles (UAVs)-assisted smart cities environments based on the principles of Contract Theory and Reinforcement Learning. Initially, a contract-theoretic mechanism is proposed to enable the UAVs to incentivize the Internet of Things (IoT) nodes to report their collected data (i.e., effort) via providing personalized rewards to them. This novel mechanism exploits the IoT nodes’ physical and social characteristics in order to design optimal personalized contracts, i.e., pairs of {effort, reward}, while jointly optimizing the benefits of the UAVs and the IoT nodes from the crowdsourcing process. Additionally, a reinforcement learning-based mechanism is designed to enable the IoT nodes to select a UAV to report their data, while considering the received rewards in the crowdsourcing process. A set of detailed numerical and comparative results are presented to demonstrate the operational characteristics of the proposed crowdsourcing framework, as well as its drawbacks and benefits compared to the state of the art. Fisayo Sangoleye, Md Sahabul Hossain, Eirini-Eleni Tsiropoulou, James F. Plusquellic |
DCOSS | 4 |
| 2022 | Reconfigurable Intelligent Surfaces enabling Positioning, Navigation, and Timing ServicesabstractIn this paper we exploit the advances provided by the Reconfigurable Intelligent Surfaces (RIS) technology, which allows for the software-defined control of the electromagnetic properties of the wireless medium, in order to introduce a low-cost and easily deployable ground-based alternative positioning, navigation, and timing (PNT) service. According to the proposed solution, the positioning of the target is performed by one original signal transmitted by one base station (BS), and three additional signals reflected by three RISs (selected from a set of available RISs), thus reducing significantly the required implementation and infrastructure cost. Different reinforcement learning algorithms, based on the gradient ascent and the log-linear learning models, are introduced and investigated to enable the target, to autonomously and dynamically select the optimal set of three RISs to be used for the optimization of its positioning accuracy. Subsequently, an iterative least square algorithm is realized to determine the position of the target. Detailed numerical results are presented that highlight the tradeoffs of the introduced reinforcement learning algorithms in terms of convergence and impact on achieved positioning precision, and demonstrate the superiority of the proposed methodology against existing ground-based PNT solutions. Md Sahabul Hossain, Nafis Irtija, Eirini-Eleni Tsiropoulou, James F. Plusquellic, Symeon Papavassiliou |
ICC | 4 |
| 2022 | Enhancing Privacy in PUF-Cash through Multiple Trusted Third Parties and Reinforcement LearningabstractElectronic cash ( e-Cash ) is a digital alternative to physical currency such as coins and bank notes. Suitably constructed, e-Cash has the ability to offer an anonymous offline experience much akin to cash, and in direct contrast to traditional forms of payment such as credit and debit cards. Implementing security and privacy within e-Cash, i.e., preserving user anonymity while preventing counterfeiting, fraud, and double spending, is a non-trivial challenge. In this article, we propose major improvements to an e-Cash protocol, termed PUF-Cash, based on physical unclonable functions ( PUFs ). PUF-Cash was created as an offline-first, secure e-Cash scheme that preserved user anonymity in payments. In addition, PUF-Cash supports remote payments; an improvement over traditional currency. In this work, a novel multi-trusted-third-party exchange scheme is introduced, which is responsible for “blinding” Alice’s e-Cash tokens; a feature at the heart of preserving her anonymity. The exchange operations are governed by machine learning techniques which are uniquely applied to optimize user privacy, while remaining resistant to identity-revealing attacks by adversaries and trusted authorities. Federation of the single trusted third party into multiple entities distributes the workload, thereby improving performance and resiliency within the e-Cash system architecture. Experimental results indicate that improvements to PUF-Cash enhance user privacy and scalability. Georgios Fragkos, Cyrus Minwalla, Eirini-Eleni Tsiropoulou, James F. Plusquellic |
ACM J. Emerg. Technol. Comput. Syst. | 4 |
| 2022 | Introduction to the Special Issue on Hardware-Assisted Security for Emerging Internet of Thingsabstractintroduction Share on Introduction to the Special Issue on Hardware-Assisted Security for Emerging Internet of Things Editors: Saraju P. Mohanty University of North Texas University of North TexasView Profile , Jim Plusquellic University of New Mexico University of New MexicoView Profile , Garrett S. Rose University of Tennessee, Knoxville University of Tennessee, KnoxvilleView Profile , Wei Zhang Hong Kong University of Science and Technology Hong Kong University of Science and TechnologyView Profile , Maria K. Michael University of Cyprus University of CyprusView Profile Authors Info & Claims ACM Journal on Emerging Technologies in Computing SystemsVolume 18Issue 1January 2022 Article No.: 1pp 1–3https://doi.org/10.1145/3475952Online:29 September 2021Publication History 0citation90DownloadsMetricsTotal Citations0Total Downloads90Last 12 Months90Last 6 weeks12 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Saraju P. Mohanty, James F. Plusquellic, Garrett S. Rose, Wei Zhang 0012, Maria K. Michael |
ACM J. Emerg. Technol. Comput. Syst. | 2 |
| 2022 | Information Leakage Analysis Using a Co-Design-Based Fault Injection Technique on a RISC-V MicroprocessorabstractThe RISC-V instruction set architecture open licensing policy has spawned a hive of development activity, making a range of implementations publicly available. The environments in which RISC-V operates have expanded correspondingly, driving the need for a generalized approach to evaluating the reliability of RISC-V implementations under adverse operating conditions or after normal wear-out periods. Fault injection (FI) refers to the process of changing the state of registers or wires, either permanently or momentarily, and then observing execution behavior. The analysis provides insight into the development of countermeasures that protect against the leakage or corruption of sensitive information, which might occur because of unexpected execution behavior. In this article, we develop a hardware–software co-design architecture that enables fast, configurable fault emulation and utilize it for information leakage and data corruption analysis. Modern system-on-chip FPGAs enable building an evaluation platform, where control elements run on a processor(s) (PS) simultaneously with the target design running in the programmable logic (PL). Software components of the FI system introduce faults and report execution behavior. A pair of RISC-V FI-instrumented implementations are created and configured to execute the Advanced Encryption Standard and Twister algorithms. Key and plaintext information leakage and degraded pseudorandom sequences are both observed in the output for a subset of the emulated faults. James F. Plusquellic, Donald E. Owen, Tom J. Mannos, Brian Dziki |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2020 | Analysis of IoT Authentication Over LoRaabstractImplementing a full set of security features within IoT devices is challenging because of constraints on the available resources and power consumption. Nevertheless, such devices must be capable of carrying out mutual authentication with gateways and servers before exchanging data. There are a wide variety of authentication methods that can be used including those based on physically unclonable functions (PUFs), PKI, encryption, and secure hash elements such as MD5 and SHA-3. This work assesses the time and energy associated with authentication protocols in the context of Long Range (LoRa), which is an emerging low-power wide-area network (LPWAN) technology used in IoT devices. LoRa has configurable settings that affect the bandwidth and transmission range. We assess the transmit time, which is proportional to energy consumption, of different authentication techniques over a variety of LoRa configurations and address the level of security provided by the authentication protocols. Our findings suggest that PUF-based authentication is well suited for RF devices operating within an energy and data rate constrained LoRa environment. We propose a PUF-based authentication protocol called PARCE that significantly reduces the RF transmissions for IoT devices. Derek Heeger, James F. Plusquellic |
DCOSS | 2 |
| 2020 | UAV-enabled Human Internet of ThingsabstractIn this paper, an Unmanned Aerial Vehicles (UAVs) - enabled human Internet of Things (IoT) architecture is introduced to enable the rescue operations in public safety systems (PSSs). Initially, the first responders select in an autonomous manner the disaster area that they will support by considering the dynamic socio-physical changes of the surrounding environment and following a set of gradient ascent reinforcement learning algorithms. Then, the victims create coalitions among each other and the first responders at each disaster area based on the expected- maximization approach. Finally, the first responders select the UAVs that communicate with the Emergency Control Center (ECC), to which they will report the collected data from the disaster areas by adopting a set of log-linear reinforcement learning algorithms. The overall distributed UAV-enabled human Internet of Things architecture is evaluated via detailed numerical results that highlight its key operational features and the performance benefits of the proposed framework. Kelly Rael, Georgios Fragkos, James F. Plusquellic, Eirini-Eleni Tsiropoulou |
DCOSS | 3 |
| 2019 | IEEE International Symposium on Hardware Oriented Security and Trust (HOST): Past, Present, and FutureabstractHardware plays an integral role in system security with many emerging vulnerabilities and defense mechanisms targeting hardware. The IEEE International Symposium on Hardware Oriented Security and Trust (HOST) aims to facilitate the rapid growth of hardware-based security research and development. Since 2008, HOST has provided an environment to present cutting-edge developments in hardware security and trust. With the recent expansion of its scope to include all areas of overlap between hardware and security, HOST has become a premier event in the field of cybersecurity, and is one of the few to bridge the gap between computer security, mircoelectronics, and electronic design automation (EDA) communities. Domenic Forte, Swarup Bhunia, Ramesh Karri, James F. Plusquellic, Mark Tehranipoor |
ITC | 4 |
| 2018 | Hardware Assisted Security Architecture for Smart GridabstractSupervisory Control and Data Acquisition (SCADA) systems are the backbone structures that monitor and actuate large-scale systems in infrastructures like power grids and remote industrial automation. The power distribution network integrates smart grids which actively interact with consumer devices and back end SCADA systems. The communication over the grid is insecure and is susceptible to data compromise, network level and physical device level attacks. The recent exploitations of the connected electronic devices' vulnerabilities in the power domain reinforce the importance of security implementation and integration at the system level and at all levels of integration. This paper proposes a hardware-assisted framework for secure intra smart grid communication. The framework protects the confidentiality and integrity of data between each node and additionally provides authentication for the communicating parties. Furthermore, the presented framework is resistant to software-based remote hijacking as well as secret key extraction. Ali Shuja Siddiqui, Yutian Gui, David Lawrence, Stuart Laval, James F. Plusquellic, Madhav D. Manjrekar, Badrul H. Chowdhury, Fareena Saqib |
IECON | 5 |
| 2018 | Novel Offset Techniques for Improving Bitstring Quality of a Hardware-Embedded Delay PUFabstractStatistical properties including uniqueness, randomness, and reproducibility are commonly used as metrics for physical unclonable functions (PUFs). When PUFs are used in authentication protocols, the first two metrics are critically important to the overall security of the system. In this paper, we investigate the statistical qualities of bitstrings generated by a hardware-embedded delay PUF called HELP using hardware data collected from a set of 500 Xilinx Zynq FPGAs. HELP analyzes variations in path delays that occur within a hardware-implemented macro. Two novel techniques are proposed in which the verifier computes a set of offsets that are used to fine tune the token's digitized path delays as a means of maximizing entropy and reproducibility in the generated bitstrings. The offsets are derived from the enrollment data stored by the server in a secure database. A population-based offset method is proposed, which computes median values using data from multiple tokens. A second chip-specific technique is proposed, which fine tunes path delays using the stored enrollment data associated with the authenticating token. The analysis of FPGA data shows that the population-based offset method significantly improves entropy while the chip-specific technique, used alone or in combination with the population-based method, significantly improves reproducibility. Wenjie Che, Fareena Saqib, James F. Plusquellic |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2016 | Current based PUF exploiting random variations in SRAM cells
Fengchao Zhang, James F. Plusquellic, Swarup Bhunia |
DATE | 3 |
| 2016 | On detecting delay anomalies introduced by hardware trojansabstractA hardware Trojan (HT) detection method is presented that is based on measuring and detecting small systematic changes in path delays introduced by capacitive loading effects or series inserted gates of HTs. The path delays are measured using a high resolution on-chip embedded test structure called a time-to-digital converter (TDC) that provides approx. 25 ps of timing resolution. A calibration method for the TDC as well as a chip-averaging technique are demonstrated to nearly eliminate chip-to-chip and within-die process variation effects on the measured path delays across chips. This approach significantly improves the correlation between Trojan-free chips and a simulation-based golden model. Path delay tests are applied to multiple copies of a 90nm custom ASIC chip having two copies of an AES macro. The AES macros are exact replicas except for the insertion of several additional gates in the second hardware copy, which are designed to model HTs. Simple statistical detection methods are used to isolate and detect systematic changes introduced by these additional gates. We present hardware results which demonstrate that our proposed chip-averaging and calibration techniques in combination with a single nominal simulation model can be used to detect small delay anomalies introduced by the inserted gates of hardware Trojans. Dylan Ismari, James F. Plusquellic, Charles Lamech, Swarup Bhunia, Fareena Saqib |
ICCAD | 2 |
| 2015 | Cyber-physical systems: A security perspectiveabstractA cyber-physical system (CPS) is a composition of independently interacting components, including computational elements, communications and control systems. Applications of CPS institute at different levels of integration, ranging from nation-wide power grids, to medium scale, such as the smart home, and small scale, e.g. ubiquitous health care systems including implantable medical devices. Cyber-physical systems primarily transmute how we interact with the physical world, with each system requiring different levels of security based on the sensitivity of the control system and the information it carries. Considering the remarkable progress in CPS technologies during recent years, advancement in security and trust measures is much needed to counter the security violations and privacy leakage of integration elements. This paper focuses on security and privacy concerns at different levels of the composition and presents system level solutions for ensuring the security and trust of modern cyber-physical systems. Charalambos Konstantinou, Michail Maniatakos, Fareena Saqib, Shiyan Hu 0001, James F. Plusquellic, Yier Jin |
ETS | 5 |
| 2015 | PUF-Based AuthenticationabstractIn the context of hardware systems, authentication refers to the process of confirming the identity and authenticity of chip, board and system components such as RFID tags, smart cards and remote sensors. The ability of physical unclonable functions (PUF) to provide bitstrings unique to each component can be leveraged as an authentication mechanism to detect tamper, impersonation and substitution of such components. However, authentication requires a strong PUF, i.e., one capable of producing a large, unique set of bits per device, and, unlike secret key generation for encryption, has additional challenges that relate to machine learning attacks, protocol attacks and constraints on device resources. In this paper, we describe the requirements for PUF-based authentication, and present a PUF primitive and protocol designed for authentication in resource constrained devices. Our experimental results are derived from a 28 nm Xilinx FPGA. Wenjie Che, Fareena Saqib, James F. Plusquellic |
ICCAD | 3 |
| 2015 | Pipelined Decision Tree Classification Accelerator Implementation in FPGA (DT-CAIF)abstractDecision tree classification (DTC) is a widely used technique in data mining algorithms known for its high accuracy in forecasting. As technology has progressed and available storage capacity in modern computers increased, the amount of data available to be processed has also increased substantially, resulting in much slower induction and classification times. Many parallel implementations of DTC algorithms have already addressed the issues of reliability and accuracy in the induction process. In the classification process, larger amounts of data require proportionately more execution time, thus hindering the performance of legacy systems. We have devised a pipelined architecture for the implementation of axis parallel binary DTC that dramatically improves the execution time of the algorithm while consuming minimal resources in terms of area. Scalability is achieved when connected to a high-speed communication unit capable of performing data transfers at a rate similar to that of the DTC engine. We propose a hardware accelerated solution composed of parallel processing nodes capable of independently processing data from a streaming source. Each engine processes the data in a pipelined fashion to use resources more efficiently and increase the achievable throughput. The results show that this system is 3.5 times faster than the existing hardware implementation of classification. Fareena Saqib, Aindrik Dutta, James F. Plusquellic, Philip Ortiz, Marios S. Pattichis |
IEEE Trans. Computers | 3 |
| 2015 | Within-Die Delay Variation Measurement and Power Transient Analysis Using REBELabstractVariations in path delays are increasing with scaling, and are increasingly affected by neighborhood interactions. To fully characterize within-die variations, delays must be measured in the context of actual core-logic macros using embedded test structures (ETSs). In this brief, we propose an ETS called regional delay behavior (REBEL) that is designed to measure path delays in a minimally invasive fashion. REBEL provides capabilities similar to an off-chip logic analyzer. We implemented REBEL in a 90-nm test chip and present results on within-die path delay variations in a floating point unit. We also analyze the impact on delay when the chips are subjected to industrial-level temperature and voltage variations. Fareena Saqib, Dylan Ismari, Charles Lamech, James F. Plusquellic |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2014 | A non-volatile memory based physically unclonable function without helper dataabstractStability across environmental variations such as temperature and voltage, is critically important for Physically Unclonable Functions (PUFs). Nearly all existing PUF systems to date need a mechanism to deal with “bit flips” when exact regeneration of the bitstring is required, e.g., for cryptographic applications. Error correction (ECC) and error avoidance schemes have been proposed but both of these require helper data to be stored for the regeneration process. Unfortunately, helper data adds time and area overhead to the PUF system and provides opportunities for adversaries to reverse engineer the secret bitstring. In this paper, we propose a non-volatile memory-based (NVM) PUF that is able to avoid bit flips without requiring any type of helper data. A voltage-to-digital converter technique is described for digitizing the analog entropy source and a robust median-finding algorithm is proposed as the reprograming strategy. Analysis on published experimental data is presented to demonstrate the practicability of our proposed strategy. We describe the technique in the context of emerging nano-devices, in particular, resistive random access memory (Memristor) cells, but the methodology is applicable to any type of NVM including Flash. Wenjie Che, James F. Plusquellic, Swarup Bhunia |
ICCAD | 2 |
| 2013 | A transmission gate physical unclonable function and on-chip voltage-to-digital conversion techniqueabstractA physical unclonable function (PUF) is an embedded integrated circuit (IC) structure that is designed to leverage naturally occurring variations to produce a random bitstring. In this paper, we evaluate a PUF which leverages resistance variations which occur in transmission gates (TGs) of ICs. We also investigate a novel on-chip technique for converting the voltage drops produced by TGs into a digital code, i.e., a voltage-to-digital converter (VDC). The analysis is carried out on data measured from chips subjected to temperature variations over the range of -40°C to +85°C and voltage variations of +/- 10% of the nominal supply voltage. The TG PUF and VDC produce high quality bitstrings that perform exceptionally well under statistical metrics including stability, randomness and uniqueness. Raj Chakraborty, Charles Lamech, Dhruva Acharyya, James F. Plusquellic |
DAC | 4 |
| 2012 | Securing Trusted Execution Environments with PUF Generated Secret KeysabstractTrusted Execution Environments are quickly becoming a preferred method for providing isolation between secure and non-secure execution environments. The protection of these environments, as well as their software structure, is still a primary area of interest and research. The abililty to use a Physically Unclonable Function to generate a unique-per-device AES key provides an excellent mechanism for protection of a Trusted Execution Environment at rest through encryption. These keys can also be used to manage modification of the TEE during execution. In this paper, we present an new methodology for how this protection can be achieved, as well as a framework for the incorporation of Physically Unclonable Functions into cryptographic engines. Matthew Areno, James F. Plusquellic |
TrustCom | 2 |
| 2012 | A Novel Technique for Improving Hardware Trojan Detection and Reducing Trojan Activation TimeabstractFabless semiconductor industry and government agencies have raised serious concerns about tampering with inserting hardware Trojans in an integrated circuit supply chain in recent years. Most of the recently proposed Trojan detection methods are based on Trojan activation to observe either a faulty output or measurable abnormality on side-channel signals. Time to activate a hardware Trojan circuit is a major concern from the authentication standpoint. This paper analyzes time to generate a transition in functional Trojans. Transition is modeled by geometric distribution and the number of clock cycles required to generate a transition is estimated. Furthermore, a dummy scan flip-flop insertion procedure is proposed aiming at decreasing transition generation time. The procedure increases transition probabilities of nets beyond a specific threshold. The relation between circuit topology, authentication time, and the threshold is carefully studied. The simulation results on s38417 benchmark circuit demonstrate that, with a negligible area overhead, our proposed method can significantly increase Trojan activity and reduce Trojan activation time. Hassan Salmani, Mark Tehranipoor, James F. Plusquellic |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2011 | Characterizing within-die and die-to-die delay variations introduced by process variations and SOI history effectabstractVariations in delay caused by within-die and die-to-die process variations and SOI history effect increase timing margins and reduce performance. In order to develop mitigation techniques to reduce the detrimental effects of delay variations, particularly those that occur within-die, new methods of measuring delay variations within actual products are needed. The data provided by such techniques can also be used for validating models, i.e., can assist with model-to-hardware correlation. In this paper, we propose a flush delay technique for measuring both regional delay variations and SOI history effect and validate the method using a test structure fabricated in a 65 nm SOI process. Jim Aarestad, Charles Lamech, James F. Plusquellic, Dhruva Acharyya, Kanak Agarwal 0001 |
DAC | 3 |
| 2011 | REBEL and TDC: Two embedded test structures for on-chip measurements of within-die path delay variationsabstractAs feature printability becomes more challenging in advanced technology nodes, measuring and characterizing process variation effects on delay and power is becoming increasingly important. In this paper, we present two embedded test structures (ETS) for carrying out path delay measurement in actual product designs. Of the two structures proposed here, one is designed to be incorporated into a customer's scan structures, augmenting selected functional units with the ability to perform accurate path delay measurements. We refer to this ETS as REBEL (regional delay behavior). It is designed to leverage the existing scan chain as a means of reducing area overhead and performance impact. For cases in which very high resolution of delay measurements is required, a second standalone structure is proposed which we refer to as TDC for time-to-digital converter. Beyond characterizing process variations, these ETSs can also be used for design debug, detection of hardware Trojans and small delay defects and as physical unclonable functions. Charles Lamech, Jim Aarestad, James F. Plusquellic, Reza M. Rad, Kanak Agarwal 0001 |
ICCAD | 3 |
| 2011 | An Experimental Analysis of Power and Delay Signal-to-Noise Requirements for Detecting Trojans and Methods for Achieving the Required Detection SensitivitiesabstractNew validation methods are needed for ensuring integrated circuit (IC) Trust, and in particular for detecting hardware Trojans. In this paper, we investigate the signal-to-noise ratio (SNR) requirements for detecting Trojans by conducting ring oscillator (RO) experiments on a set of V2Pro FPGAs. The ROs enable a high degree of control over the switching activity in the FPGAs while simultaneously permitting subtle delay and transient power supply anomalies to be introduced through simple modifications to the RO logic structure. Power and delay analyses are first carried out across a set of FPGAs using RO configurations that emulate Trojan-free conditions. These experiments are designed to determine the magnitude of process and environmental (PE) variations, and are used to establish statistical limits on the noise floor for the subsequent emulated Trojan experiments. The emulated Trojan experiments introduce anomalies in power and delay in subtle ways as additional loads and series inserted gates. The data from both experiments is used to determine the detection sensitivity of several statistical methods to the transient anomalies introduced by these types of design modifications. A calibration technique is proposed that improves sensitivity to small transient anomalies significantly. Finally, we describe testing techniques that enable high resolution measurements of power and delay to support the proposed calibration and statistics-based detection methods. Charles Lamech, Reza M. Rad, Mark Tehranipoor, James F. Plusquellic |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2010 | Quality metric evaluation of a physical unclonable function derived from an IC's power distribution systemabstractThe level of security provided by digital rights management functions and cryptographic protocols depend heavily on the security of an embedded secret key. The current practice of embedding the key as digital data in the integrated circuit (IC) weakens these security protocols because the keys can be learned through attacks. Physical unclonable functions (PUFs) are a recent alternative to storing digital keys on the IC. A PUF leverages the inherent manufacturing variations of an IC to define a random function. Given environmental variations such as temperature and supply noise, PUF quality criteria such as reproducibility and the level of randomness in the responses may be difficult to achieve for a given PUF circuit architecture. In this paper, we evaluate a PUF derived from the power distribution system of an IC with regard to a set of quality metrics including single-bit and collision probability and entropy. The analysis is carried out using data obtained from 36 chips fabricated in IBM's 65 nm SOI technology. Ryan Helinski, Dhruva Acharyya, James F. Plusquellic |
DAC | 3 |
| 2010 | Leveraging existing power control circuits and power delivery architecture for variability measurementabstractEmbedded test structures are increasingly being used to measure and analyze performance and power variations in product chips to better understand the impact of process variations. In this work, we propose a minimally-invasive, low-overhead technique for characterizing within-die and die-to-die leakage variation. The proposed technique leverages existing power control circuitry added by designers to reduce the power consumption of inactive functional units. We manipulate these `sleep islands' to isolate and measure their leakage current contribution to the chip-wide leakage current. The measured set of sleep island leakage currents reflect the leakage current variation across the chip at a coarse level of resolution. In order to improve resolution, we propose a multiple power supply port (MSP) measurement technique to provide `within-island' leakage current measurements. A calibration technique is described that corrects for differences between the sleep island and MSP approaches, effectively enabling the same information to be obtained using either technique. We demonstrate the techniques on a set of test chips fabricated in 65-nm SOI technology. The results show that leakage current variations across a small test structure array have both a locally random and globally deterministic component that can be accurately mapped using the sleep island or MSP approaches. Dhruva Acharyya, Kanak Agarwal 0001, James F. Plusquellic |
ITC | 3 |
| 2010 | Detecting Trojans Through Leakage Current Analysis Using Multiple Supply Pad IDDQ sabstractHardware Trojans have emerged as a new threat to the security and trust of computing systems. Hardware Trojans are deliberate and malicious modifications to the logic function implemented within digital and mixed signal chips. In contrast to software Trojans, it is not possible to simply "scan the hard drive" to eradicate a hardware Trojan. Hardware Trojans can be designed to shutdown the chip at some predetermined time and/or when some specific signal or data pattern is received. They may also be designed to remain hidden while leaking confidential information covertly to the adversary. Determining whether a hardware Trojan has been inserted into a chip is extremely difficult for a variety of reasons, e.g., nanometer feature sizes and chip design complexity combine to make optical inspection difficult or impossible. This paper presents experimental results demonstrating the effectiveness of a Trojan detection method that is based on the analysis of a chip's Jddqs (steady-state current), which are measured simultaneously from multiple places on the chip. The proposed method also incorporates a technique for virtually eliminating process and test environment variations effects which act to reduce detection sensitivity of traditional testing approaches. Used together, resolution enhancements of up to a 1000 x are possible over conventional single power supply current measurement techniques. A regression-based statistical technique is applied to the data collected from a set of chips fabricated in a 65-nm process to illustrate the detection capabilities and limitations of this type of approach. Jim Aarestad, Dhruva Acharyya, Reza M. Rad, James F. Plusquellic |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2010 | A Sensitivity Analysis of Power Signal Methods for Detecting Hardware Trojans Under Real Process and Environmental ConditionsabstractTrust in reference to integrated circuits addresses the concern that the design and/or fabrication of the integrated circuit (IC) may be purposely altered by an adversary. The insertion of a hardware Trojan involves a deliberate and malicious change to an IC that adds or removes functionality or reduces its reliability. Trojans are designed to disable and/or destroy the IC at some future time or they may serve to leak confidential information covertly to the adversary. Trojans can be cleverly hidden by the adversary to make it extremely difficult for chip validation processes, such as manufacturing test, to accidentally discover them. This paper investigates the sensitivity of a power supply transient signal analysis method for detecting Trojans. In particular, we focus on determining the smallest detectable Trojan, i.e., the least number of gates a Trojan may have and still be detected, using a set of process simulation models that characterize a TSMC 0.18 μm process. We also evaluate the sensitivity of our Trojan detection method in the presence of measurement noise and background switching activity. Reza M. Rad, James F. Plusquellic, Mark Tehranipoor |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2009 | A physical unclonable function defined using power distribution system equivalent resistance variationsabstractFor hardware security applications, the availability of secret keys is a critical component for secure activation, IC authentication and for other important applications including encryption of communication channels and IP protection in FPGAs. The vulnerabilities of conventional keys derived from digital data can be mitigated if the keys are instead derived from the inherent statistical manufacturing variations of the IC. Robust silicon-derived keys are implemented using physically unclonable functions (PUFs). A PUF consists of a specialized hardware circuit and a mechanism to retrieve a set of responses under a variety of different challenges. In this paper, we propose a PUF that is based on the measured equivalent resistance variations in the power distribution system (PDS) of an IC. The effectiveness of the PUF is evaluated on twenty-four ICs fabricated in a 65 nm technology. Ryan Helinski, Dhruva Acharyya, James F. Plusquellic |
DAC | 3 |
| 2009 | Characterizing within-die variation from multiple supply port IDDQ measurementsabstractThe importance of within-die process variation and its impact on product yield has increased significantly with scaling. Within-die variation is typically monitored by embedding characterization circuits in product chips. In this work, we propose a minimally-invasive, low-overhead technique for characterizing within-die variation. The proposed technique monitors within-die variation by measuring quiescent (IDDQ) currents at multiple power supply ports during wafer-probe test. We show that the spatially distributed nature of power ports enables spatial observation of process variation. We demonstrate our methodology on an experimental test-chip fabricated in 65-nm technology. The measurement results show that the IDDQ currents drawn by multiple power supply ports correlate very well with the variation trends introduced by state-dependent leakage patterns. Kanak Agarwal 0001, Dhruva Acharyya, James F. Plusquellic |
ICCAD | 3 |
| 2009 | A Novel Fault Localization Technique Based on Deconvolution and Calibration of Power Pad Transients Signals
Reza M. Rad, James F. Plusquellic |
J. Electron. Test. | 2 |
| 2008 | Power supply signal calibration techniques for improving detection resolution to hardware TrojansabstractChip design and fabrication is becoming increasingly vulnerable to malicious activities and alternations with globalization. An adversary can introduce a Trojan designed to disable and/or destroy a system at some future time (Time Bomb) or the Trojan may serve to leak confidential information covertly to the adversary. This paper proposes a taxonomy for Trojan classification and then describes a statistical approach for detecting hardware Trojans that is based on the analysis of an ICs power supply transient signals. A key component to improving the resolution of power analysis techniques to Trojans is calibrating for process and test environment (PE) variations. The main focus of this research is on the evaluation of four signal calibration techniques, each designed to reduce the adverse impact of PE variations on our statistical Trojan detection method. Reza M. Rad, Xiaoxiao Wang 0001, Mark Tehranipoor, James F. Plusquellic |
ICCAD | 4 |
| 2007 | Securing Designs against Scan-Based Side-Channel AttacksabstractTraditionally, the only standard method of testing that has consistently provided high fault coverage has been scan test due to the high controllability and high observability this technique provides. The scan chains used in scan test not only allow test engineers to control and observe a chip, but these properties also allow the scan architecture to be used as a means to breach chip security. In this paper, we propose a technique, called Lock & Key, to neutralize the potential for scan-based side-channel attacks. It is very difficult to implement an all inclusive security strategy, but by knowing the attacker, a suitable strategy can be devised. The Lock & Key technique provides a flexible security strategy to modern designs without significant changes to scan test practices. Using this technique, the scan chains are divided into smaller subchains. With the inclusion of a test security controller, access to subchains are randomized when being accessed by an unauthorized user. Random access reduces repeatability and predictability making reverse engineering more difficult. Without proper authorization, an attacker would need to unveil several layers of security before gaining proper access to the scan chain in order to exploit it. The proposed Lock & Key technique is design independent while maintaining a relatively low area overhead. Jeremy Lee, Mark Tehranipoor, Chintan Patel, James F. Plusquellic |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2006 | A Low-Cost Solution for Protecting IPs Against Scan-Based Side-Channel AttacksabstractScan designs used for testing also provide an easily accessible port for hacking. In this paper, we present a new low-cost secure scan design that is effective against scan-based side-channel attacks. By integrating a test key into test vectors that are scanned into the chip, testing and accessing scan chains are guaranteed to be allowed only by an authorized user. Any attempt to use the scan chain without a verified test vector will result in a randomized output preventing potential side-channel attacks. The proposed technique has a negligible area overhead, has no negative impact on chip performance, and places several levels of security over the scan chain protecting it from potential attacks. Jeremy Lee, Mark Tehranipoor, James F. Plusquellic |
VTS | 3 |
| 2006 | Defect Simulation Methodology for iDDT Testing
Abhishek Singh 0001, James F. Plusquellic, Dhananjay S. Phatak, Chintan Patel |
J. Electron. Test. | 2 |
| 2005 | Hardware Results Demonstrating Defect Detection Using Power Supply Signal MeasurementsabstractThe power supply transient signal (I/sub DDT/) method that we propose for defect detection analyzes regional signal variations introduced by defects at a set of power supply pads on the chip under test (CUT). The method is based on the comparison of the CUT with chips that are known to be defect free. A set of defect free chips are analyzed to establish a statistical metric that distinguishes between defect effects and process variation (defect free) effects. This paper presents hardware results that demonstrate the effectiveness of a novel geometry based defect detection technique using nine copies of a test chip. Eight chips are used as defect free chips to derive the statistical limits. Emulated defects are provoked in the ninth chip to evaluate the defect detection capabilities of the method. Dhruva Acharyya, James F. Plusquellic |
VTS | 2 |
| 2005 | At-Speed Transition Fault Testing With Low Speed Scan EnableabstractWith today's design size in millions of gates and working frequency in gigahertz range, at-speed test is crucial. The launch-off-shift method has several advantages over the launch-off-capture but imposes strict requirements on transition fault testing due to at-speed scan enable signal. A novel scan-based at-speed test is proposed which generates multiple local fast scan enable signals. The scan enable control information is encapsulated in the test data and transferred during the scan operation. A new scan cell, referred to as last transition generator (LTG), is inserted in the scan chains to generate the fast local scan enable signal. The proposed technique is robust, practice-oriented and suitable for use in an industrial flow. C. P. Ravikumar, Mark Tehranipoor, James F. Plusquellic |
VTS | 4 |
| 2005 | Defect Detection Using Quiescent Signal Analysis
Chintan Patel, Abhishek Singh 0001, James F. Plusquellic |
J. Electron. Test. | 3 |
| 2004 | Defect detection under Realistic Leakage Models using Multiple IDDQ MeasurementabstractI/sub DDQ/ or steady state current testing has been extensively used in the industry as a mainstream defect detection and reliability screen. The background leakage current has increased significantly with the advent of ultra deep submicron technologies. The increased background leakage makes it difficult to use single threshold I/sub DDQ/ testing to differentiate defect-free chips from those with defects that draw small amount of currents. Several techniques that improve the resolution of I/sub DDQ/ testing have been proposed to replace the single threshold detection scheme. However, even these techniques are challenged to detect defects in the presence of leakage currents in excess of a few mA. All of these techniques use a single I/sub DDQ/ measurement per circuit configuration for detection and thus the scalability of these techniques is limited. Quiescent signal analysis (QSA) is a novel I/sub DDQ/ defect detection and diagnosis technique that uses I/sub DDQ/ measurements at multiple chip supply pads. Implicit in our methodology is a leakage calibration technique that scales the total leakage current over multiple simultaneous measurements. This helps in decreasing the background leakage component in individual measurements and thus increases the resolution of this technique to subtle defects. The effectiveness of this technique is demonstrated in This work using simulation experiments on portion of a production power grid. Predicted chip size and leakage values from the International Technology Roadmap for semiconductors (ITRS) are used in these experiments. The performance of the proposed technique is evaluated using three different intra-die process variation distribution models. Chintan Patel, Abhishek Singh 0001, James F. Plusquellic |
ITC | 3 |
| 2004 | On-Chip Impulse Response Generation for Analog and Mixed-Signal TestingabstractA technique for testing analog and mixed-signal linear circuit components based on their impulse response (IR) signatures is presented in This work. A simple DFT structure is proposed to enable the on-chip generation of the impulse response signatures from the corresponding step responses of the circuit components. The proposed technique circumvents the need to apply pseudorandom patterns and perform complex on-chip cross-correlation for IR generation. A set of post processing steps based on cross/auto-correlation are proposed to efficiently compare IR signatures. A statistical approach based on linear regression and outlier analysis is used for defect screening. A continuous-time active state variable filter benchmark circuit is used as the device-under-test as a means of validating this technique. The detection sensitivity for shorting and open resistive faults across various defect severity levels is analyzed. The detection results are compared and shown to be superior to a typical specification based test. Abhishek Singh 0001, Chintan Patel, James F. Plusquellic |
ITC | 3 |
| 2004 | Fault Simulation Model for i{DDT} Testing: An InvestigationabstractIn today's technologies, resistive shorting and open defects are becoming more predominant. Conventional fault models, and tools based on these models are becoming inadequate in addressing these defects resulting from new failure mechanisms. In prior works i/sub DDT/ testing techniques have been shown to detect resistive defects. However, in order to incorporate i/sub DDT/ based methods into production test flows, it is necessary to develop a fault simulation strategy to enable ATPG and fault coverage to be determined. To our knowledge, no practical technique exists to perform fault simulation for i/sub DDT/ based methods. At the heart of the difficulty of developing a fault simulation strategy is the analog nature of the test observable. In this paper we investigate a fault simulation model that partitions the task of simulating the CUT (chip under test) into linear and non-linear components. We also propose a path isolation strategy for core-logic as a means of reducing the computational complexity involved in deriving i/sub DDT/ signals in the non-linear portion. More specifically an Impulse Response based method is derived to eliminate the need for transient simulations of the entire CUT. Abhishek Singh 0001, Chintan Patel, James F. Plusquellic |
VTS | 3 |
| 2003 | Comparison of Branching CORDIC ImplementationsabstractWe compare implementations of Duprat and Muller's branching CORDIC and Phatak's double step branching (DSB)-CORDIC algorithms for sine and cosine evaluation. For reference we also report on classical CORDIC implementations for the same wordlengths. We have also implemented double stepping in the classical algorithm and report on the performance of this method. CORDIC evaluation of sine and cosine includes two parts, the zeroer and the rotator. We discuss implementation issues related to the minimization of the delay of each iteration of the algorithm (including delays for both the zeroer as well the rotator). We then examine hybrid methods that select the components from different algorithms (such as a DSB zeroer together with a classical rotator or vice versa). Abhishek Singh 0001, Dhananjay S. Phatak, Tom Goff, Mike Riggs, James F. Plusquellic, Chintan Patel |
ASAP | 5 |
| 2003 | FPGA implementation of a fast Hadamard transformer for WCDMAabstractIn code division multiple access (CDMA) systems the base station identifies each user in a cell by unique orthogonal (Walsh) codes. The Walsh codes are generated at the transmitter using a Walsh-Hadamard function. A Fast Hadamard Transformer (FHT) is used at the receiver to decode the transmitted codes. The purpose of this study is to design a FHT which utilizes less hardware resources as compared to the existing designs and also suggest means for reducing the input length of the Walsh sequence. Our study results indicate that the FHT design using 16-chip sequence achieves 90% reduction in hardware resources (equivalent gate count) as compared to the design which uses 256-chip sequence. Also, the maximum frequency of operation of the 16-chip FHT (35.679 MHz) is more than double as compared to the 256-chip FHT (16.025 MHz). Sanat Kamal Bahl, James F. Plusquellic |
FPGA | 2 |
| 2003 | Path Delay Estimation using Power Supply Transient Signals: A Comparative Study using Fourier and Wavelet Analysis
Abhishek Singh 0001, Jitin Tharian, James F. Plusquellic |
ICCAD | 3 |
| 2003 | Impedance Profile of a Commercial Power Grid and Test System
Dhruva Acharyya, James F. Plusquellic |
ITC | 2 |
| 2003 | IP-in-IP tunneling to enable the simultaneous use of multiple IP interfaces for network level connection striping
Dhananjay S. Phatak, Tom Goff, James F. Plusquellic |
Comput. Networks | 3 |
| 2003 | Defect Diagnosis Using a Current Ratio Based Quiescent Signal Analysis Model for Commercial Power Grids
Chintan Patel, Ernesto Staroswiecki, Smita Pawar, Dhruva Acharyya, James F. Plusquellic |
J. Electron. Test. | 5 |
| 2003 | Power supply transient signal analysis for defect-oriented testabstractTransient signal analysis (TSA) is a testing method that is based on the analysis of a set of V/sub DD/ transient waveforms measured simultaneously at each supply port. Defect detection is performed by applying linear regression analysis to the time or frequency domain representations of these signals. Chip-wide process variation effects introduce signal variations that are correlated across the individual power port measurements. In contrast, defects introduce uncorrelated local variations across these measurements that can be detected as anomalies in the cross-correlation profile derived (using regression analysis) from the power port measurements of defect-free chips. This paper focuses on the application of TSA to the detection of delay faults. James F. Plusquellic, Abhishek Singh 0001, Chintan Patel, Anne E. Gattiker |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2002 | Power Supply Transient Signal Analysis Under Real Process and Test Hardware ModelsabstractA device testing method called Transient Signal Analysis (TSA) is subjected to elements of a real process and testing environment in this paper. Simulation experiments are designed to determine the effects of process skew (obtained from measured parameters of a real process) on the accuracy of TSA in estimating path delays from power supply I/sub DDT/ and V/sub DDT/ waveforms. The circuit model is designed to test TSA under deep submicron process models that incorporate advanced parameters such as transistor V/sub t/ width dependencies. Modeling elements of a testing environment including the probe card are subsequently introduced as a means of evaluating the effects of tester measurement noise in an actual implementation. Abhishek Singh 0001, James F. Plusquellic, Anne E. Gattiker |
VTS | 2 |
| 2001 | Power supply transient signal integration circuitabstractWe discuss a circuit which measures and analyses power supply transients as defined in the test technique, Transient Signal Analysis (TSA). This circuit can replace the benchtop instrumentation and offline signal processing software used in previous work. The circuit accepts voltage transients as analog inputs from the Device-Under-Test (DUT), performs integration and outputs an analog value to the tester. The tester compares the output value to a predetermined threshold as a means of determining the pass/fail status of the DUT. This circuit is designed to simplify the hardware requirements of TSA. Chintan Patel, Fidel Muradali, James F. Plusquellic |
ITC | 3 |
| 2001 | Detecting delay faults using power supply transient signal analysisabstractA delay-fault testing strategy based on the analysis of power supply transient signals is presented. The method is an extension to a Go/No-Go device testing method called Transient Signal Analysis (TSA). TSA detects defects through the analysis of a set of power supply transient waveforms in the time or frequency domain, e.g., Fourier phase components. A recent extension to TSA demonstrated a correlation between the V/sub DDT/ Fourier phase components and path delays in defect-free devices. The method proposed here is able to detect increases in delay due to resistive shorting and open defects using a similar technique. In particular simulation results show that a delay defective device can be distinguished from a defect-free device through an anomaly in the Fourier phase correlation profile of the device. Abhishek Singh 0001, Chintan Patel, Shirong Liao, James F. Plusquellic, Anne E. Gattiker |
ITC | 4 |
| 2001 | A Process and Technology-Tolerant IDDQ Method for IC DiagnosisabstractThe use of I/sub DDQ/ test as a defect reliability screen has been widely used to improve device quality. However, the increase in subthreshold leakage currents in deep submicron technologies has made it difficult to set an absolute pass/fail threshold. Recent work has focused on strategies that calibrate for process and/or technology-related variation effects. In this paper, a new I/sub DDQ/ technique is proposed that is based on an extension of a V/sub DDT/-based method called Transient Signal Analysis (TSA). The method, called Quiescent Signal Analysis or QSA, uses the I/sub DDQ/s measured at multiple supply pins as a means of localizing defects. Increases in I/sub DDQ/ due to a defect are regionalized by the resistive element of the supply grid. Therefore, each supply pin sources a unique fraction of the total I/sub DDQ/ drawn by the defect. The method analyzes the regional I/sub DDQ/s and "triangulates" the position of the defect to an (x,y) location in the layout. This information can be used in combination with fault dictionary-based techniques as a means of further resolving the defect's location. Chintan Patel, James F. Plusquellic |
VTS | 2 |
| 2000 | Predicting device performance from pass/fail transient signal analysis dataabstractTransient Signal Analysis (TSA) is a Go/No-Go device testing method that is based on the analysis of voltage transients at multiple test points. In this paper a technique based on an extension to TSA is presented that is able to predict critical path delay using data from non-critical (predictor) path tests. A characterization phase is performed a priori in which both predictor path and critical path delays are measured from a set of defect-free devices. The characterization data is used to define the relationship between the power supply transient signal data and the actual delays. Once established, prediction is performed during production test by simply re-analyzing the data from the predictor path Go/No-Go TSA tests, and therefore, no speed bin testing is required. Simulations on an 8-bit multiplier are used to demonstrate a linear relationship between a range of supply rail Fourier Phase harmonics and delay under various process models. The accuracy of the prediction is evaluated statistically against the measured delays from an additional set of critical path simulations. James F. Plusquellic, Amy Germida, Jonathan Hudson, Ernesto Staroswiecki, Chintan Patel |
ITC | 1 |
| 2000 | Detection of CMOS Defects under Variable Processing ConditionsabstractTransient signal analysis is a digital device testing method that is based on the analysis of voltage transients at multiple test points. In this paper, the power supply transient signals from simulation experiments on an 8-bit multiplier are analyzed at multiple test points in both the time and frequency domain. Linear regression analysis is used to separate and identify the signal variations introduced by defects and those introduced by process variation. Defects were introduced into the simulation model by adding material (shorts) or removing material (opens) from the layout. 246 circuit models were created and 1440 simulations performed on defect-free, bridging defective and open defective circuits in which process variation was modeled by varying circuit and transistor parameters within a range of /spl plusmn/25% of the nominal parameters. The results of the analysis show that it is possible to distinguish between defect-free and defective devices with injected process variation. Amy Germida, James F. Plusquellic |
VTS | 2 |
| 1999 | Defect detection using power supply transient signal analysisabstractTransient Signal Analysis is a digital device testing method that is based on the analysis of voltage transients at multiple test points. The power supply transient signals of an 8-bit multiplier are analyzed using both hardware and simulation experiments. The small signal variations generated at these test points are analyzed in both the time and frequency domain. A simple statistical procedure is presented that captures the variation introduced by defects while attenuating those variations introduced by process variations. The results of the analysis show that it is possible to distinguish between defect-free and defective devices in both simulation and hardware. Amy Germida, James F. Plusquellic, Fidel Muradali |
ITC | 3 |
| 1997 | Identification of Defective CMOS Devices Using Correlation and Regression Analysis of Frequency Domain Transient Signal DataabstractTransient signal analysis is a digital device testing method that is based on the analysis of voltage transients at multiple test points and on I/sub DD/ switching transients on the supply rails. We show that it is possible to identify defective devices by analyzing the transient signals produced at test points on paths not sensitized from the defect site. The small signal variations produced at these test points are analyzed in the frequency domain. Correlation analysis shows a high degree of correlation in these signals across the outputs of defect-free devices. We use regression analysis to show the absence of correlation across the outputs of bridging and open drain defective devices. James F. Plusquellic, Donald M. Chiarulli, Steven P. Levitan |
ITC | 1 |
| 1996 | Digital Integrated Circuit Testing using Transient Signal AnalysisabstractA novel approach to testing CMOS digital circuits is presented that is based on an analysis of I/sub DD/ switching transients on the supply rails and voltage transients at selected test points. We present simulation and hardware experiments which show distinguishable characteristics between the transient waveforms of defective and non-defective devices. These variations are shown to exist for CMOS open drain and bridging defects, located both on and off of a sensitized path. James F. Plusquellic, Donald M. Chiarulli, Steven P. Levitan |
ITC | 1 |