{"id":"https://openalex.org/W4404515209","doi":"https://doi.org/10.1145/3689939.3695779","title":"Patching FPGAs: The Security Implications of Bitstream Modifications","display_name":"Patching FPGAs: The Security Implications of Bitstream Modifications","publication_year":2024,"publication_date":"2024-11-19","ids":{"openalex":"https://openalex.org/W4404515209","doi":"https://doi.org/10.1145/3689939.3695779"},"language":"en","primary_location":{"id":"doi:10.1145/3689939.3695779","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3689939.3695779","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3689939.3695779","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 Workshop on Attacks and Solutions in Hardware Security","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3689939.3695779","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076572791","display_name":"Endres Puschner","orcid":"https://orcid.org/0000-0002-1661-6024"},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Endres Puschner","raw_affiliation_strings":["Max Planck Institute for Security and Privacy, Bochum, Germany"],"raw_orcid":"https://orcid.org/0000-0002-1661-6024","affiliations":[{"raw_affiliation_string":"Max Planck Institute for Security and Privacy, Bochum, Germany","institution_ids":["https://openalex.org/I4210096592"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033295803","display_name":"Maik Ender","orcid":"https://orcid.org/0000-0002-0685-2541"},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Maik Ender","raw_affiliation_strings":["Max Planck Institute for Security and Privacy, Bochum, Germany"],"raw_orcid":"https://orcid.org/0000-0002-0685-2541","affiliations":[{"raw_affiliation_string":"Max Planck Institute for Security and Privacy, Bochum, Germany","institution_ids":["https://openalex.org/I4210096592"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008222051","display_name":"Steffen Becker","orcid":"https://orcid.org/0000-0001-7526-5597"},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]},{"id":"https://openalex.org/I904495901","display_name":"Ruhr University Bochum","ror":"https://ror.org/04tsk2644","country_code":"DE","type":"education","lineage":["https://openalex.org/I904495901"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Steffen Becker","raw_affiliation_strings":["Ruhr University Bochum &amp; Max Planck Institute for Security and Privacy, Bochum, Germany"],"raw_orcid":"https://orcid.org/0000-0001-7526-5597","affiliations":[{"raw_affiliation_string":"Ruhr University Bochum &amp; Max Planck Institute for Security and Privacy, Bochum, Germany","institution_ids":["https://openalex.org/I4210096592","https://openalex.org/I904495901"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5041748332","display_name":"Christof Paar","orcid":"https://orcid.org/0000-0001-8681-2277"},"institutions":[{"id":"https://openalex.org/I4210096592","display_name":"Max Planck Institute for Security and Privacy","ror":"https://ror.org/00bj0r217","country_code":"DE","type":"facility","lineage":["https://openalex.org/I149899117","https://openalex.org/I4210096592"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Christof Paar","raw_affiliation_strings":["Max Planck Institute for Security and Privacy, Bochum, Germany"],"raw_orcid":"https://orcid.org/0000-0001-8681-2277","affiliations":[{"raw_affiliation_string":"Max Planck Institute for Security and Privacy, Bochum, Germany","institution_ids":["https://openalex.org/I4210096592"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.329,"has_fulltext":true,"cited_by_count":3,"citation_normalized_percentile":{"value":0.81718828,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"89","last_page":"99"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T14117","display_name":"Integrated Circuits and Semiconductor Failure Analysis","score":0.9878000020980835,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9830999970436096,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/bitstream","display_name":"Bitstream","score":0.9834696054458618},{"id":"https://openalex.org/keywords/field-programmable-gate-array","display_name":"Field-programmable gate array","score":0.8427873849868774},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7903928756713867},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.6945115327835083},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.4787651598453522},{"id":"https://openalex.org/keywords/computer-hardware","display_name":"Computer hardware","score":0.41033995151519775},{"id":"https://openalex.org/keywords/computer-architecture","display_name":"Computer architecture","score":0.37145745754241943},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.1755521297454834},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.1145697832107544},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.08150646090507507}],"concepts":[{"id":"https://openalex.org/C136695289","wikidata":"https://www.wikidata.org/wiki/Q415568","display_name":"Bitstream","level":3,"score":0.9834696054458618},{"id":"https://openalex.org/C42935608","wikidata":"https://www.wikidata.org/wiki/Q190411","display_name":"Field-programmable gate array","level":2,"score":0.8427873849868774},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7903928756713867},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.6945115327835083},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.4787651598453522},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.41033995151519775},{"id":"https://openalex.org/C118524514","wikidata":"https://www.wikidata.org/wiki/Q173212","display_name":"Computer architecture","level":1,"score":0.37145745754241943},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.1755521297454834},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.1145697832107544},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.08150646090507507}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3689939.3695779","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3689939.3695779","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3689939.3695779","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 Workshop on Attacks and Solutions in Hardware Security","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2411.11060","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2411.11060","pdf_url":"https://arxiv.org/pdf/2411.11060","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:hss-opus.ub.ruhr-uni-bochum.de:14116","is_oa":true,"landing_page_url":"https://hss-opus.ub.ruhr-uni-bochum.de/opus4/frontdoor/index/index/docId/14116","pdf_url":null,"source":{"id":"https://openalex.org/S4306400167","display_name":"Dokumentenrepositorium der RUB (Ruhr University Bochum)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I904495901","host_organization_name":"Ruhr University Bochum","host_organization_lineage":["https://openalex.org/I904495901"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"doc-type:article"}],"best_oa_location":{"id":"doi:10.1145/3689939.3695779","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3689939.3695779","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3689939.3695779","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 Workshop on Attacks and Solutions in Hardware Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G18682879","display_name":null,"funder_award_id":"390781972","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"},{"id":"https://openalex.org/G5856086275","display_name":null,"funder_award_id":"EXC 2092 CASA - 390781972","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"}],"funders":[{"id":"https://openalex.org/F4320320879","display_name":"Deutsche Forschungsgemeinschaft","ror":"https://ror.org/018mejw64"},{"id":"https://openalex.org/F4320323817","display_name":"Universitas Brawijaya","ror":"https://ror.org/01wk3d929"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4404515209.pdf"},"referenced_works_count":28,"referenced_works":["https://openalex.org/W1975607764","https://openalex.org/W1997144957","https://openalex.org/W2005006301","https://openalex.org/W2060389684","https://openalex.org/W2107937248","https://openalex.org/W2115222032","https://openalex.org/W2481358287","https://openalex.org/W2570260769","https://openalex.org/W2588369819","https://openalex.org/W2612354329","https://openalex.org/W2891839221","https://openalex.org/W2895952230","https://openalex.org/W2904259375","https://openalex.org/W2919561762","https://openalex.org/W2963001922","https://openalex.org/W2984653719","https://openalex.org/W3036522585","https://openalex.org/W3048100242","https://openalex.org/W4254778745","https://openalex.org/W4281666926","https://openalex.org/W4288057799","https://openalex.org/W4288100545","https://openalex.org/W4321637277","https://openalex.org/W4378191169","https://openalex.org/W4388505081","https://openalex.org/W4388763411","https://openalex.org/W4401568774","https://openalex.org/W4405181304"],"related_works":["https://openalex.org/W4319430423","https://openalex.org/W4390224957","https://openalex.org/W4323831234","https://openalex.org/W2544043553","https://openalex.org/W4311839959","https://openalex.org/W1982685694","https://openalex.org/W49599899","https://openalex.org/W2121309702","https://openalex.org/W3217774925","https://openalex.org/W2040087757"],"abstract_inverted_index":{"Field":[0],"Programmable":[1],"Gate":[2],"Arrays":[3],"(FPGAs)":[4],"are":[5,18],"known":[6],"for":[7,12,73,177],"their":[8],"reprogrammability":[9,36],"that":[10],"allows":[11],"post-manufacture":[13],"circuitry":[14],"changes.":[15],"Nowadays,":[16],"they":[17],"integral":[19],"to":[20,54],"a":[21,70,95,103,126],"variety":[22],"of":[23,56,62,98,130,156,200],"systems":[24],"including":[25],"high-security":[26],"applications":[27],"such":[28,184],"as":[29,42,185,208],"aerospace":[30],"and":[31,59,144,153,188,196],"military":[32],"systems.":[33],"However,":[34],"this":[35,66],"also":[37],"introduces":[38],"significant":[39],"security":[40],"challenges,":[41],"bitstream":[43,88,100,135,186,213],"manipulation":[44,214],"can":[45,216],"directly":[46],"alter":[47],"hardware":[48,63],"circuits.":[49],"Malicious":[50],"manipulations":[51],"may":[52],"lead":[53],"leakage":[55],"secret":[57],"data":[58],"the":[60,82,140,147,150,157,160,173,198],"implementation":[61],"Trojans.":[64],"In":[65],"paper,":[67],"we":[68],"present":[69],"comprehensive":[71],"framework":[72,128,166],"manipulating":[74],"bitstreams":[75],"with":[76,86,159],"minimal":[77],"reverse":[78,136],"engineering,":[79,137],"thereby":[80],"exposing":[81],"potential":[83],"risks":[84],"associated":[85],"inadequate":[87],"protection.":[89],"Our":[90],"methodology":[91],"does":[92],"not":[93],"require":[94],"complete":[96],"understanding":[97],"proprietary":[99],"formats":[101],"or":[102],"fully":[104],"reverse-engineered":[105],"target":[106],"design.":[107],"Instead,":[108],"it":[109],"enables":[110],"precise":[111],"modifications":[112],"by":[113],"inserting":[114],"pre-synthesized":[115],"circuits":[116],"into":[117,149],"existing":[118,151],"bitstreams.":[119],"This":[120],"novel":[121],"approach":[122],"is":[123],"demonstrated":[124],"through":[125,167],"semi-automated":[127],"consisting":[129],"five":[131],"steps:":[132],"(1)":[133],"partial":[134],"(2)":[138],"designing":[139],"modification,":[141],"(3)":[142],"placing":[143],"(4)":[145],"routing":[146],"modification":[148,158],"circuit,":[152],"(5)":[154],"merging":[155],"original":[161],"bitstream.":[162],"We":[163,204],"validate":[164],"our":[165,193],"four":[168],"practical":[169],"case":[170],"studies":[171],"on":[172],"OpenTitan":[174],"design":[175],"synthesized":[176],"Xilinx":[178],"7-Series":[179],"FPGAs.":[180],"While":[181],"current":[182],"protections":[183],"authentication":[187],"encryption":[189],"often":[190],"fall":[191],"short,":[192],"work":[194],"highlights":[195],"discusses":[197],"urgency":[199],"developing":[201],"effective":[202],"countermeasures.":[203],"recommend":[205],"using":[206],"FPGAs":[207],"trust":[209],"anchors":[210],"only":[211],"when":[212],"attacks":[215],"be":[217],"reliably":[218],"excluded.":[219]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
