Papers for
hardware security engineers
Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.
Analog input pins can leak data through unexpected signal paths
Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs
Abstract: Mixed-signal SoCs rely on nominally input-only analog pins to acquire off-chip signals, but the directionality of these interfaces is generally treated as a functional property rather than explicitly verified as a security property. This work identifies and experimentally demonstrates a directionality-based class of analog and mixed-signal (AMS) exfiltration attacks in which data-dependent circuit-offset modulation converts a nominally input-only pin into an outbound information channel. We analytically model the attack mechanism and identify three enabling host conditions: a closed-loop amplifier, an exposed amplifier input, and sufficiently high impedance at that pin. This attack class is validated through a representative silicon case study using a photoplethysmography (PPG) analog front-end (AFE) fabricated in a commercial 55-nm CMOS process. The payload incurs $<$0.001\% area overhead relative to typical biosensing AFEs. Under the evaluated conditions, payload activation reduces the filtered PPG-output SNR by only 0.03~dB, while the maximum HT-induced perturbation of 5.9\% of the PPG amplitude remains within the 34.3\% benign variation at the exposed sensor-input pin across process and temperature. The raw exfiltration SINR remains below -20~dB, while targeted filtering increases it above 14~dB and enables signal recovery. Silicon measurements demonstrate data exfiltration through the input pin at bit rates up to 10~kbps and error-free recovery of a PRBS message. These results expose a conventional test-observability gap and establish analog pin directionality as an AMS security property requiring explicit verification, test coverage, and defense rather than being inferred from nominal signal flow.
New codes improve security against hardware attacks in cryptography
Constructions of LCPs and LCD codes from twisted Reed-Solomon codes
Abstract: Linear complementary pairs (LCPs) and linear complementary dual (LCD) codes have important applications in orthogonal direct-sum masking (ODSM), which provides effective countermeasures against side-channel attacks and fault-injection attacks. While LCD codes have been extensively investigated, comparatively fewer results are available for general LCPs. In this paper, we further investigate LCPs of twisted Reed--Solomon (TRS) codes. We derive necessary conditions for two TRS codes to form an LCP and establish several sufficient conditions and explicit constructions. We also study LCD codes constructed from TRS codes and investigate the security parameters of the resulting LCPs. Furthermore, under suitable conditions, we obtain MDS LCPs of TRS codes.