2026 Theses Doctoral
Physical Attack Detection and On-Demand Protection for Hardware Security
Hardware security is a specialized field dedicated to safeguarding the physical components of electronic systems. Its primary objective is to ensure that hardware functions reliably as intended, free from tampering throughout its entire lifecycle—from initial design and fabrication to final deployment. This security layer is crucial because the hardware serves as the "root of trust" for the entire computing stack. If the underlying hardware is compromised, no amount of software-based protection can be considered truly secure. A significant threat to this foundation is the physical attack.
In this scenario, an adversary gains direct access to manipulate the silicon chip or the printed circuit board (PCB) on which it is mounted. Given that these electronic systems underpin modern technology—ranging from personal devices to critical infrastructure—maintaining their physical integrity is paramount. A successful physical attack can bypass all software-level security measures, leading to catastrophic outcomes such as data theft, system malfunction, or complete device takeover. Consequently, designing circuits capable of defending against these physical threats is an essential aspect of creating secure and reliable electronic systems.
The central theme of this thesis is on-demand protection, a paradigm designed to overcome the inefficiencies of traditional hardware defenses. While continuous protection offers strong security, it incurs significant power and performance penalties that are often unnecessary given the infrequency of severe physical attacks. To address this, we propose a "detect-then-protect" strategy that balances robust security with operational efficiency. This method utilizes a two-step process: a low-power sensor remains active to identify potential threats, and only upon positive detection is a resource-intensive protection mechanism engaged for the duration of the attack. By limiting high-overhead defenses to moments of actual danger, the system minimizes energy consumption and performance loss during normal operation.
This thesis presents new circuits and system designs of attack detectors and protection circuits. It first focuses on probing attacks. Chapter 2 presents a run-time probing attack detector for low-speed GPIO based on a Time-to-Digital Converter (TDC). It does not require a pause from IO cells to activate detection, incurring minimum performance overhead. It also leverages an on-chip IO replica to mitigate Process, Voltage, and Temperature (PVT) variations, which is critical for such a detector as it is required to work robustly under any circumstances. Chapter 3 outlines a detection circuit based on a regenerative comparator that achieves high resolution and can be used on multi-Gbps links, also with robustness against PVT variations. Chapter 4 improves the detector further by using new fully digital circuits that occupy 36um2 for the detection core. Chapter 5 shifts focus to side channel attack (SCA), presenting a detection and on-demand protection system for a secure AES engine. Chapter 6 presents an improved SCA detector that can detect both contact and contactless probes. Finally, Chapter 7 presents circuits on the detection of clock and voltage glitch attacks, with low-latency clock-gating-based protection for on-chip processors.
Subjects
Files
This item is currently under embargo. It will be available starting 2028-01-07.
More About This Work
- Academic Units
- Electrical Engineering
- Thesis Advisors
- Seok, Mingoo
- Degree
- Ph.D., Columbia University
- Published Here
- May 13, 2026
Notes
Electrical Engineering, Integrated circuits, Detectors, Computer security, Cryptography