IEEE NAECON 2017: "Formal Enforcement of Mission Assurance Properties in Cyber-Physical Systems"

Graf Research and Georgia Tech are publishing and presenting our research on "Formal Enforcement of Mission Assurance Properties in Cyber-Physical Systems" at IEEE NAECON 2017.  Come out and see our presentation!

Formal Enforcement of Mission Assurance Properties in Cyber-Physical Systems
Scott Harper, Jonathan Graf, Michael A. Capone, Justin Eng, Michael Farrell, Lee W. Lerner

Abstract— Cyber-Physical Systems improve efficiency, accuracy, and access in systems ranging from household appliances to power stations to airplanes. They also bring new risks at the intersection of physical, information, and mission assurance. This paper presents CP-SMARTS, a framework providing a means for propagating CPS assurances from planning to deployment.

georgia tech.png
150 2017LogoResolution.jpg

SEE/MAPLD 2017 Invited Lecture: "Optimizing Forward Design Trust for FPGAs"

Jonathan Graf will present an invited lecture on "Optimizing Forward Design Trust for FPGAs" at the 2017 Single Event Effects Symposium / Military and Aerospace Programmable Logic Devices Workshop in San Diego on May 25.  Come on out and see us!

Optimizing Forward Design Trust for FPGAs

Jonathan Graf

Abstract: Graf Research Corporation is developing a workflow to enable optimal forward design trust for Field Programmable Gate Arrays.  This flow is enabled by a blend of commercial EDA software, Graf Research specialized tools and techniques, and, as needed, custom trust analysis tools and techniques.  Custom tools include PV-Bit, which bridges the current gap between a trusted gate level netlist and the FPGA bitstream, bringing trust all the way into the bitstream.  To develop a trusted gate-level netlist, other trust analysis techniques must have preceded the use of PV-Bit.  The Graf Research contribution during synthesis, map, place, and route steps, is a tool called OpTrust, which uses a game theoretic decision engine to prescribe the optimal set of tests for the trust analysis of a design based on current threat data, the criticality of the design, and the availability of commercial verification or custom hardware Trojan detection methods.  Another element of trusted design is trusting the 3rd-Party IP cores present in the design.  The end goal of this assessment flow is to put the trust analysis of FPGA designs within the reach of the FPGA developer.  That is, we wish to ensure that the developer might perform the trust analysis themselves, pushing trust forward as each step in the design process is completed, concluding with a trusted bitstream.

Graf Research and USC-ISI Publish Research Results

Graf Research and the University of Southern California's Information Sciences Institute have published our work on “Irrefutable Tamper Logging through FPGA Key Management” at the 2017 DoD Anti-Tamper Conference.  Co-authors include Jonathan Graf and Ali Asgar Sohanghpurwala from Graf Research and Matthew French and Dr. Andrew Schmidt from USC-ISI.


Graf Research Awarded BAA: DPA Title III Trusted FPGAs

Graf Research has been awarded a Phase 0 BAA research project entitled DPA Title III Trusted FPGAs.  

Brief Program Summary: The Department of Defense (DoD) and Intelligence Community (IC) have identified Field Programmable Gate Arrays (FPGAs) as a critical enabling technology across a wide variety of present and future systems. Advanced, commercially available FPGAs do not meet DoD's requirements for Trusted Systems as they are manufactured in un-Trusted fabrication facilities, primarily off-shore, and are considered vulnerable to tampering and insertion of malicious software and/or hardware. This program seeks to improve the security posture and reduce the risk associated with FPGA technology by addressing security concerns in the design, development, fabrication and supply lifecycle of FPGA devices. The purpose of this study is to conduct an analysis and develop an approach to ensure the availability of advanced “Trusted” and space qualified re-programmable FPGAs technology to support DoD/IC applications including satellite and strategic missile systems. “Trust” is defined as assurance of the integrity and availability of a product wherein that product will reliably operate as intentionally designed and not contain any malicious hardware and/or software that will compromise the intended application; e.g., exfiltration of sensitive data, etc. Efforts envisioned during this Phase 0 study include: analysis of current FPGA manufacturing capabilities; analysis of future technical capabilities needed to meet the needs of the FPGA market (USG and commercial); creation of a draft technical plan and schedule to establish a Trusted source for space qualified FPGA devices, to include (non-binding) high-level cost projections, to establish quantitative “Trust” criteria for FPGAs; identification and analysis of the markets for FPGAs; and identification of business strategies to ensure long term success in the Trusted and space qualified FPGA market.

150 Wafer 2 - Santi - CC2.0 Attribution.jpg

GOMAC 2017: "Private Verification for FPGAs" and "OpTrust"

Graf Research will present two papers at GOMAC 2017.  The first is on the private verification of FPGA bitstreams: a method for verifying that bitstream contents are trustworthy without reverse engineering them.  The second is on OpTrust, the software tool that encapsulates our game theoretic decision engine for microelectronics trust.


Private Verification for FPGA Bitstreams
Jonathan Graf and Ali Asgar Sohanghpurwala

Abstract: We introduce private verification, a novel paradigm for trustworthy microelectronics design verification. Private verification methods and software simultaneously meet two requirements: (1) comprehensively verifying the design and (2) maintaining the privacy of certain aspects of the design, such as its implementation details or design format. We present an implementation of such a tool, entitled PV-Bit, which is capable of verifying the contents of FPGA bitstreams without exposing the details of the vendor-proprietary bitstream format or posing other security risks.


OpTrust: Software for Determining Optimal Test Coverage and Strategies for Trust
Jonathan Graf

Abstract: Building on our prior work in the theory and practice of applying game theory to determine optimal test strategies for hardware Trojan detection, we present the OpTrust software tool. OpTrust is an automated game solving tool that offers microelectronics developers guidance about the optimal test strategies to ensure the trustworthiness of their designs. It divides roles among a red team, a threat environment team, and the developer. In this way, complexity and sensitive information are hidden from developers, allowing them easy access to test guidance.

Graf Research Awarded SBIR: "CP-SMARTS"

Graf Research has been awarded a Phase 1 SBIR entitled, "CP-SMARTS"  We will create a model of cyber physical security called CP-SMARTS: Cyber Physical Security for Mission-Aware ARmy Tactical Systems. CP-SMARTS will model not only the services required of Cyber Physical Systems (such as computation, communications, control, etc.) but also Mission Assurance requirements (definitions of Mission Essential Function and corresponding vulnerabilities and mitigations) and Information Assurance services (such as Confidentiality, Integrity, Availability, Authentication, etc.). A core element of our teams CPS philosophy one that will permeate our approach in modeling, model checking, and implementation is that we always keep deployment in mind. This means creating models and model checking methods that integrate well into the development environment of the user who will deploy the CPS. In so doing, we create technologies that not only work on the whiteboard and in simulation but also can be readily adopted by commercial and military CPS designers.


Research Award: Custom FPGA EDA Tools

Graf Research has been awarded funding to develop custom electronic design automation (EDA) software for Field Programmable Gate Arrays.  

Graf Research Awarded SBIR: "Optimal Strategies for Cloud-Based Trust Assessment"

Graf Research has been awarded a Phase 1 SBIR to research and develop optimal strategies for cloud-based trust assessment. We anticipate creating not only a novel cloud architecture that can facilitate the use of many of the DARPA-sponsored custom microelectronics trust software tools but also a unique, cloud-hosted software product OpTrust-C which will devise optimal strategies for the proper implementation of defensive measures.

150 SBIR Logo.png

IEEE NAECON 2016: "System-Level Adversary Attack Surface Modeling for Microelectronics Trust"

Continuing our publication of the applications of Game Theory to various levels of trust assessment, we discuss system-level applications in our IEEE NAECON 2016 paper.  Come on out and see our presentation!

Towards System-Level Adversary Attack Surface Modeling for Microelectronics Trust
Jonathan Graf

Abstract—Models of trust for microelectronic systems are difficult to create due to the large variety of adversarial strategies available. Building on previous work, we present a new adversary model that considers the large heterogeneous attack surface that is realistically available on a diverse microelectronic system. We also present an expanded game theoretic model that permits reasoning about optimal adversarial and defensive strategies across this varied attack surface.


Graf Research Awarded SBIR: "Irrefutable Tamper Logging"

Graf Research has been awarded a Phase 1 SBIR entitled "Irrefutable Tamper Logging."  On this project, we will create the GR-TLogger, a tamper logger that makes use of the key management capabilities of next-generation secure FPGAs to store tamper logs that are information rich, semi-permanent, and irrefutable.  

150 SBIR Logo.png

Jonathan Graf Invited Talk at Virginia Tech CESCA

Jonathan Graf of Graf Research along with co-presenter Dale Reese of Idaho Scientific will be giving an invited lecture to Virginia Tech's Center for Embedded Systems for Critical Applications (CESCA)The topic is "FPGA MPSoC Security: Design and Runtime."  Come on out and hear us!  Details below:

FPGA MPSoC Security: Design and Runtime

Jonathan Graf, Founder, Graf Research; Dale Reese, Founder and Chief Scientist, Idaho Scientific

2:30pm - 3:30pm on April 15, 2016 (Friday) at Whittemore Hall 457

Abstract:   An emerging class of Field Programmable Gate Array (FPGA) – the Multi-Processor System on Chip (MPSoC) – holds enormous promise for novel processing architectures in a variety of domains. Within the context of high-security systems, the same-die close coupling of heterogeneous processing structures with hardened security resources is of particular interest. Modern FPGA MPSoCs provide not only programmable FPGA fabric, ARM CPUs, graphics processor units (GPUs), and digital signal processors (DSPs) but also cryptographic accelerators, physically unclonable functions (PUFs), and hardware random number generators (HRNGs). This pairing of processing and security resources raises the possibility of using them to create tightly integrated, custom secure processors for emerging networked applications that demand the highest security standards. FPGA MPSoCs hold the potential of revolutionizing the security posture for high-security Internet of Things (IoT) applications such as autonomous vehicles, intelligent energy grid devices, home and industrial automation, cyber-physical systems – and even the datacenter.

In this seminar, Jonathan Graf (Graf Research) and Dale Reese (Idaho Scientific) will introduce the variety of embedded computing security disciplines that meet within the confines of FPGA MPSoCs. Security must be built into these devices from the moment they are first designed, all the way through their supply chains, during the development of each piece of software and firmware, and throughout every runtime operation of each disparate processing structure. Collectively, this makes the FPGA MPSoC an exciting new device class with exceptional opportunities for new embedded computing security innovation.

150 VT Logo.jpg

IEEE HOST 2016: "Trust Games"

We are continuing to publish our research on the use of Game Theory to optimize hardware Trojan detection processes in our paper at IEEE HOST 2016.  Make sure to come by and chat with us!


Trust Games: How Game Theory Can Guide the Development of Hardware Trojan Detection Methods

Jonathan Graf

Abstract—The development of circuit testing and verification methods is commonly driven by formal analysis centered on an abstract mathematical model of the error or defect the method is designed to detect. Hardware Trojans, however, confound attempts to develop simple representative models due to the varieties of their physical embodiments in a circuit and the creative nature of a rational human adversary. Since it is nonetheless desirable to have a mathematical framework for determining the effectiveness of hardware Trojan detection methods, we present a game theoretic framework for so doing. Modeling the Trojan maker and detection method designer as opposing players in a 2-person strategic game is a necessary step in our process. However, the ultimate utility of the approach depends on an accurate security economic model of both players that can correctly consider the players’ incentives, empirically-derived detection method efficacy metrics, a comprehensive taxonomy of hardware Trojans, and the places in the design cycle of the circuit where the Trojan insertion and detection occur. In this paper, we present such a security economic model and the resulting game, which we call the Trust Game. We illustrate the value of this game primarily in the context of how it may guide the development of new hardware Trojan detection methods. We solve a representative game, illustrating the value of two common solution concepts, the iterated elimination of dominated strategies and Nash equilibrium. We further show that this framework has utility to both of the opposing players in the game. Finally, we recommend the development of standardized Trust Games that can be used to quickly measure the efficacy of both new hardware Trojans and hardware Trojan detection methods.

GOMAC 2016: "Optimal Hardware Trojan Detection through Security Economics and Game Theory"

We're going to GOMAC this year to present our paper, "Toward Optimal Hardware Trojan Detection through Security Economics and Game Theory."  Come on out to see us!

Toward Optimal Hardware Trojan Detection through Security Economics and Game Theory

Jonathan Graf

Abstract: We present a security economic model that informs the optimal selection of hardware Trojan detection strategies.  Our model accurately represents the economics and efficacy of available verification and Trojan detection methods and accounts for the varieties of available hardware Trojans.  Paired with game theoretic analysis, this model informs ASIC/FPGA designers and associated policy makers of optimal defensive strategies. 

Keywords: Trust, Hardware Trojan, Hardware Security, ASIC, FPGA, Security Economics, Game Theory


Hello world!

Graf Research has been founded!

Graf Research-logo - 280 PX.jpg