Theses

Die Embedded-Security-Gruppe bietet nach individueller Rücksprache weiter Bachelor- und Masterarbeiten mit Themenschwerpunkten FPGA Security, Hardware Reverse Engineering sowie Physical-Layer Security an.

Anfragen zu Abschlussarbeiten sind an die Kontakt-Emailadresse emsec+BA_MA@rub.de zu richten. Wir bitten um ein kurzes Anschreiben (einige Worte zur eigenen Person, Stärken/Schwächen, Motivation,…) sowie einen aktuellen Notenspiegel.

Open positions (BA/MA/SHK/WHB) on FPGA Security

FPGAs are reconfigurable devices used in a wide range of security-critical applications. Securing their boot process and the loading of their configuration — the so-called bitstream — is essential for building trustworthy systems. Internally, the bitstream configures all basic elements such as LUTs and flip-flops, as well as the routing between them. For most commercially available FPGAs, the bitstream encoding and its security features remain proprietary.

Our research has leveraged hardware fuzzing to uncover several flaws in the bitstream protection of AMD 7-Series and UltraScale(+) FPGAs [1, 2]. To advance this work, we are looking for motivated students to join our team as SHK/WHK or through a BA/MA thesis. If you are interested in FPGA security — or related topics — do not hesitate to contact Felix Hahn to discuss opportunities, regardless of your course of study or current stage.

The projects listed below can serve as a starting point for that conversation:

  • Project 1 — Security Analysis of AMD Spartan UltraScale+ FPGAs
    AMD recently released the first devices in the Spartan UltraScale+ family, featuring a substantially overhauled configuration process. We aim to explore how this differs from older AMD FPGA families and to improve automated security analysis methods for hardware. As a first step, we are interested in developing tooling to enable meaningful security research on these devices — specifically, reverse engineering the new configuration process sufficiently to support custom FPGA configuration via OpenOCD (JTAG) and Python. Subsequent steps include integrating these tools into our fuzzing framework, ConFuzz [2], and improving automated security analysis through state-of-the-art fuzzing techniques, including LLM-assisted approaches.
  • Project 2 — Hardware Fuzzing with Side Channels
    This project combines power side-channel analysis with hardware fuzzing. Power traces captured during configuration reveal information about the configuration engine’s internal state — information that can guide ConFuzz [2] toward inputs that trigger security-relevant behavior. Building on an existing partial implementation, the goal is to complete the hardware and software integration of our custom JTAG controller with ConFuzz and the side-channel measurement setup, then use the combined system to perform targeted fuzzing campaigns.
  • Project 3 — Power Glitching with custom PCB
    Power glitching attacks deliberately disturb a chip’s power supply at precisely timed moments to cause faults in its computation — for example, skipping an authentication check or bypassing a memory clear at the beginning of configuration. We have designed and fabricated a custom PCB that exposes the individual power rails of an AMD 7-Series FPGA to perform targeted power glitching. The goal is to develop software tooling to automate glitching campaigns and attack several security-relevant operations on the FPGA.
[1] https://tches.iacr.org/index.php/TCHES/article/view/11435
[2] https://github.com/emsec/ConFuzz

Open positions (BA/MA/SHK/WHB) on Wireless Physical-Layer Security

We are permanently surrounded by radio waves, which form the backbone of modern wireless communication systems such as 4G, 5G, Wi-Fi, and Bluetooth. Radio waves interact with their propagation environment, allowing extraction of detailed information about the physical environment. With regard to security and privacy, such physical-layer information comes with both risks and opportunities. Physical-layer information is not protected by current cryptographic primitives which are geared towards digital information. For example, eavesdroppers can exploit Wi-Fi signals to detect motion [1] and monitor vital signs, potentially violating privacy of individuals. In the coming years, wireless communication systems will increasingly incorporate radar-like sensing capabilities, demanding novel security solutions to ensure confidentiality, integrity, and authenticity of wireless sensing information. More constructively, radio-wave propagation effects can be utilized to verify physical integrity and authenticity of computing systems and entire rooms: Our Anti-Tamper Radio (ATR) solution [2] is capable of detecting insertions of metallic needles with a diameter as small as 100 µm into a running 19″ server. In a recent study [3], we’ve demonstrated that complex radio-wave propagation effects allow to treat entire rooms as Physical Unclonable Functions (PUFs), enabling secure remote inspection in mutual distrust settings, such as nuclear arms control verification.

If this sounds interesting to you, please contact Paul Staat. We are looking for motivated students to join our team as WHK/SHK or as BA/MA thesis workers. Potential areas that you could focus on include, but are not limited to:

  • Security and privacy aspects of wireless systems with software-controlled metasurfaces / Reconfigurable Intelligent Surfaces (RISs)
  • Wi-Fi sensing using Channel State Information (CSI) and Beamforming Feedback Information (BFI)
  • Security of wireless distance measurements (Ultra Wideband (UWB) and phase-based ranging)
  • mmWave radar sensing
  • Physical tamper detection
  • Machine learning on physical-layer information
  • Channel reciprocity-based key generation
  • Wireless jamming attacks
  • Emission security
[1] https://arxiv.org/abs/2112.01967
[2] https://arxiv.org/abs/2112.09014
[3] https://www.nature.com/articles/s41467-023-42314-2