HAS THE WORLD’S FIRST UNHACKABLE CHIP ARRIVED?

Ozgur Sinanoglu is obsessed with computer chips — a passion born at age 10 when his father brought home a Commodore 64. Now 42 and the associate dean of engineering at New York University Abu Dhabi, Sinanoglu claims that he and his colleagues have designed an unhackable chip. Given last year’s Meltdown and Spectre — security flaws that researchers are calling catastrophic because they could affect nearly every computer chip manufactured in the past 20 years — producing a chip capable of repelling attacks would restore peace of mind to everyone from government agencies to private companies. 

Sinanoglu, director of the Design for Excellence Lab at NYU Abu Dhabi, is not the first to make the claim. Because chips combined in central processing units (CPUs) are essentially the brains of computers, savvy engineers around the world have come up with all manner of tricks to keep hackers at bay. And most designs ultimately join the ranks of “good effort, but not good enough.” In 2010, former U.S. Army computer specialist Christopher Tarnovsky hacked into Infineon’s allegedly unhackable SLE66 CL PE chip used in PCs, gaming consoles and e-cards. Granted, he used a $70,000 electron microscope, tiny conductive needles and acid to siphon off critical data, but the point was made: not unhackable.

What sets Sinanoglu apart — besides his roughly 20 issued or pending patents — are his heavyweight backers, from the National Science Foundation to the U.S. Department of Defense, which is supporting his research through its Defense Advanced Research Projects Agency (DARPA). Boasting a 15-page résumé of academic accomplishments, the Turkish engineer is most concerned with chips fabricated in foundries, or “fabs,” where designers can’t monitor the manufacturing process. When chips are fabricated at these third-party facilities, can we really trust the end result? No, Sinanoglu asserts, making it critical that we add defenses to make them resistant to theft or tampering by those seeking financial gain, so-called hacktivists or nefarious state actors.

After analyzing the myriad threats, Sinanoglu and his team added locks to their chip that are comparable to computer passwords except that they’re made up of a unique combination of binary code (0’s and 1’s). Fortheir first design, released in fall 2017, the team added logic, or processing information, to obscure the design. Only people with a special key could hack into the chip and replicate, steal or tamper with it. The NYU team issued a public invitation to hackers to hack away — a move that turned out to be premature. By October, they realized the logic they’d added gave away information about the key. Sure enough, the following April, a group from China’s Wuhan University hacked the chip.

Humbled but not disheartened, Sinanoglu set to work again. As he recounts what came next, he becomes visibly animated, his speech speeding up. The team revisited its process, posing new questions and finding stealthier paths to protecting the chip. Their conclusion? They needed to strip out all logic and leave no structural traces. Hackers could identify the chip design, but they would have no sense of its logic or functionality without the special key of 0’s and 1’s. The functionality, says Sinanoglu, is buried in the secret key.They unveiled the subtractive version of their chip in December 2018, and once again invited hackers to have at it. Since then, Sinanoglu says, no one has found the key.

As steeped as he is in cybersecurity now, Sinanoglu started on a different course. As a Ph.D. student in computer engineering at the University of California, San Diego, he was keenly interested in the environmental factors and manufacturing defects that affect chip functionality. After graduating in 2004, he took a job with Qualcomm, a huge multinational chipmaker, as a senior design and test engineer. Then, in 2006, with a new baby and wishing to be closer to his family in Turkey, he accepted an offer to teach computer science at Kuwait University. That gig ended in 2010 with a new job that would change the trajectory of Sinanoglu’s career.

Hired as a visiting assistant professor under the guidance of Ramesh Karri, a professor of electrical and computer engineering at NYU’s Tandon School of Engineering, Sinanoglu got hooked on the challenge of staying ahead of bad actors with malicious intent. “It’s a whole different game,” he says, one that requires constantly outpacing hackers’ creativity and intelligence. “It’s actually a more fun game,” he’s quick to add with a grin.

Karri says that most people in cybersecurity — himself included — are “a little more cautious”than his colleaguesabout claiming the existence of an unhackable chip. But “if anybody can make one, it’s Ozgur and JV,” he says, referring to Jeyavijayan “JV” Rajendran, an assistant professor of electrical and computer engineering at Texas A&M University who’s working closely with Sinanoglu on the DARPA project. But Dan Goldberg, founder of Castlerock Cyber Security and an information security consultant in Virginia, expresses skepticism that anything “as complex as a microprocessor or general purpose computing device” can be truly unhackable.

For starters, Goldberg worries about key discipline: Who has access to the key and what happens when that access is revoked? Could a spurned employee exact revenge? What if the key is lost?Goldberg’s approach is to design networks and systems that follow a “defense in-depth” model. “If a malicious actor gets access to one aspect of the system, they don’t immediately have access to everything,” he explains. Sinanoglu acknowledges that, for now, they can only secure their chip at the hardware layer, but when the hardware is compromised, the whole system is compromised — which is why he considers his team’s latest iteration the unhackable ideal he has been working toward for most of his life.

Sinanoglu clearly recalls the day in Izmir when his father, a petroleum engineer, presented him with that ancient 8-bit home computer. His younger brother, Yigit, who works as a product control manager in Switzerland, says Ozgur was glued to the device, and his competitive drive (nurtured by a natural aptitude for sports) pushed him to master every detail. “Whatever he was doing, he wanted to beat the other guys,” Yigit recalls. The “other guys” now in his sights are bad actors in the chip business.

Assuming his new design withstands scrutiny, Sinanoglu plans to deploy the technology more widely, making it both scalable and practical. Can this competitive computer nerd thwart the world’s hackers? The jury’s still out, but listening to him, it’s easy to believe the future of chip security is now.

Ozgur Sinanoglu

Ozgur Sinanoglu

Director, Center of Cyber Security; Professor of Electrical and Computer Engineering, NYU Abu Dhabi

Ozgur Sinanoglu is a professor of electrical and computer engineering at New York University Abu Dhabi. He earned his BS degrees, one in Electrical and Electronics Engineering and one in Computer Engineering, both from Bogazici University, Turkey in 1999. He obtained his MS and PhD in Computer Science and Engineering from University of California San Diego in 2001 and 2004, respectively. During his PhD, he won the IBM PhD fellowship award twice. He has industry experience at Texas Instruments, IBM, and Qualcomm, and has been with NYU Abu Dhabi as an assistant professor during 2010-2014, associate professor with tenure during 2014-2018, and full professor with tenure since 2018.

Professor Sinanoglu’s research interests include design-for-test, design-for-security, and design-for-trust for VLSI circuits, where he has more than 170 conference and journal papers, and 20 issued and pending US Patents. He is the recipient of the best paper awards at IEEE VLSI Test Symposium 2011 and ACM Conference on Computer and Communication Security 2013. Sinanoglu has given around two dozen tutorials on hardware security and trust in leading CAD and test conferences, such as DAC, DATE, ITC, VTS, ETS, ICCD, ISQED, etc. He is serving or has served as general/program/track/topic chair or technical program committee member in about 20 conferences, and as (guest) associate editor for IEEE TIFS, IEEE TETC, IEEE TCAD, ACM JETC, Elsevier MEJ, JETTA, and IET CDT journals. He chaired and hosted the top cybersecurity conference in Asia, ACM ASIACCS 2017, in Abu Dhabi.

Professor Sinanoglu is the director of the Design-for-Excellence Lab at NYU Abu Dhabi. His recent research in hardware security and trust has been funded by US National Science Foundation, US Department of Defense (Army Research Office and DARPA), Intel Corporation, Semiconductor Research Corporation, and Mubadala Technology.

Mahmoud Rasras

Mahmoud Rasras

Associate Professor of Electrical and Computer Engineering, NYU Abu Dhabi

Dr. Mahmoud Rasras is an Associate Professor of the Electrical and Computer Engineering at New York University, Abu Dhabi. He received a PhD degree in physics from the Catholic University of Leuven, Belgium in 2000. He conducted his PhD research at IMEC (Interuniversity Microelectronics Center) focusing on the development of a spectroscopic photon-emission microscopy technique to study CMOS device reliability.

Dr. Rasras has more than 11 years of industrial research experience. He was a Member of Technical Staff at Bell Labs, Alcatel-Lucent, NJ, USA. His research spanned a wide range of activities towards the development of novel photonic components for next-generation optical and microwave photonic networks. This includes silicon photonics, opto-electronics, optical transceivers, photonic sensors, and all-optical logic technology for high-speed data encryption. He also developed a novel linearized optical FM discriminator for microwave photonics applications.

Prior to joining NYUAD, Dr. Rasras was a faculty member of the Electrical Engineering and Computer science at Masdar Institute (MI), Abu Dhabi. His group worked on a variety of research problems to address the current limitation of communication bandwidth. This includes designing high-speed transceiver circuits for 400Gb/s links and beyond. Additionally, much of his group research efforts focused on developing process technology for low-temperature germanium photodetectors integration on CMOS compatible platform (above 64 Gb/s). He also developed multi-axis opto-MEMS accelerometers in collaboration with GlobalFoundries (GF) and A*Star’s Institute of Microelectronics-Singapore.

Dr. Rasras authored and co-authored several journals and conference papers and holds 33 US issued patents. He has also advised several PhD and MSc students. He is a former Director of the SRC/GF Center-for-Excellence on Integrated Photonics at MI. He served on several TPC committees, including the Frontiers in Optics and Laser Science (FIO/LS) Conference. Dr. Rasras is currently an Associate Editor of Optics Express journal and a Senior IEEE Member.

Borja García de Soto

Borja García de Soto

Assistant Professor of Civil and Urban Engineering, NYU Abu Dhabi

Borja García de Soto is an Assistant Professor of Civil and Urban Engineering at New York University Abu Dhabi (NYUAD) and holds an appointment as Global Network Assistant Professor in the Department of Civil and Urban Engineering at the Tandon School of Engineering at New York University (NYU). He is the director of the S.M.A.R.T. Construction Research Group at NYUAD and conducts research in the areas of automation and robotics in construction, cybersecurity in the AEC industry, artificial intelligence, lean construction, and BIM.

Borja has extensive experience in the industry as a structural engineer, project manager, and construction consultant. He is a Professional Engineer (PE) with licenses in California and Florida and has international experience in multiple aspects of construction projects.

Borja received his PhD from ETH Zurich in Switzerland. He also holds an MSc in Civil Engineering with a concentration in engineering and project management from the University of California at Berkeley, an MSc in Civil Engineering with a concentration in structural design from Florida International University (FIU), and a BSc in Civil Engineering (graduated cum laude) also from FIU.

Christina Pöpper

Christina Pöpper

Assistant Professor of Computer Science,
NYU Abu Dhabi

Christina Pöpper is an assistant professor of computer science at NYU Abu Dhabi, focusing on information and communication security of current and future IT/communication systems. Specific research interests are in the security of wireless systems and applications and – increasingly – on aspects of privacy.

Prior to joining NYUAD, Christina Pöpper was an assistant professor at the Ruhr-University Bochum in Germany, heading the Information Security Group at the Department of Electrical Engineering and Information Technology. She received her doctoral and graduate degrees in computer science from ETH Zurich.