Score
Designs and evaluates circuits and algorithms that extract symbol timing and reconstruct digital data from serial or encoded signal streams, including phase/frequency detectors, phase-locked loops, data slicers, and retiming/deskew logic. Work includes building and analyzing CDR loops, assessing lock range and acquisition, quantifying jitter and phase-noise impacts, and measuring bit-error rates and timing margins.
To address the bottlenecks of low resolution, severe nonlinearity, and missing codes in time-to-digital converters (TDCs) implemented on 16 nm FPGAs, this paper proposes two hardware-agnostic post-processing techniques: Partial Order Reconstruction (POR) and Iterative Time-bin Interleaving (ITI). These methods effectively fuse multiple delay chains and reconstruct missing codewords. Integrated with code-density testing, directed acyclic graph (DAG)-based analysis, and tap-delay-line calibration, the approach achieves picosecond-level timing measurement accuracy: a minimum time resolution of 1.15 ps, an RMS time error of 3.38 ps, differential nonlinearity (DNL) within [−0.43, 0.24] LSB, and integral nonlinearity (INL) within [−2.67, 0.15] LSB. The proposed scheme significantly improves the linearity and completeness of usable time bins in FPGA-embedded TDCs, outperforming or matching state-of-the-art solutions, and is well-suited for high-precision delay measurement and timing calibration applications.
This study investigates the circuit complexity bounds of fundamental Boolean operators in digital circuit design. By systematically analyzing known upper and lower complexity bounds for canonical Boolean functions—such as counters, adders, encoders, and multiplexers—and integrating both classical and modern Boolean function synthesis techniques, the work proposes efficient circuit synthesis strategies. Emphasizing the interplay between theoretical complexity and practical synthesis efficiency for basic operators, this research not only consolidates existing results but also provides a theoretical foundation and practical guidance for optimizing the design of complex digital circuits.
This work addresses the limitations of existing hardware parser designs, which suffer from excessive complexity, poor reusability, and inadequate support for sophisticated matching and diverse deployment scenarios. To overcome these challenges, the authors propose an open-source tool that enhances pattern-matching capabilities through customizable symbolic tokens—enabling range validation, negation, and comparisons with external ports—and introduces a Parser Intermediate Representation (PIR) to decouple frontend protocol specification from backend implementation. The frontend allows flexible protocol description, while the backend automatically generates FPGA-optimized SystemVerilog code supporting arbitrary bit-width state machines, byte alignment, and cross-cycle field stitching. Experimental results on an Ethernet parser demonstrate up to a 226% increase in operating frequency and a 97% reduction in logic resource usage; furthermore, the hierarchical design achieves up to 8× greater resource efficiency compared to monolithic architectures.
This study addresses the lack of industrial-grade EDA support and limited high-level synthesis for asynchronous circuits by implementing automated synthesis from imperative programs to asynchronous hardware based on the AHIR framework. The proposed methodology employs a delay-insensitive controller coupled with a single-rail datapath architecture. Furthermore, it introduces 1-safe Petri net modeling and formally proves the necessary and sufficient conditions for timing constraints, while maintaining full compatibility with standard ASIC toolchains. As an end-to-end demonstration, the AES encryption algorithm is synthesized, and post-layout simulations validate both the functional correctness and performance metrics of the resulting circuit. This work ultimately provides a comprehensive solution for the automated design of asynchronous circuits.
This work addresses two key challenges in large language model (LLM)-based Verilog code generation: (1) the difficulty of modeling non-textual hardware representations—such as Karnaugh maps, state transition diagrams, and waveforms—and (2) training instability caused by sensitivity to minor, stochastic errors. To tackle these, we propose two core innovations: (1) a correctness-guaranteed synthetic data construction method for non-textual hardware representations, enabling *correct-by-construction* data generation; and (2) a targeted code repair data auto-generation framework leveraging model error reports, integrated with multi-stage, controllable error injection. After fine-tuning StarCoder2-15B on our synthesized data, we achieve new state-of-the-art pass@1 scores on VerilogEval-Machine (+3.8%), VerilogEval-Human (+10.9%), and RTLLM (+6.6%). These improvements demonstrate substantial gains in functional correctness and robustness for hardware-oriented code generation.
This work addresses the limitations of hardware reverse engineering in accounting for physical design decisions, particularly the difficulty of inferring design intent from clock networks. To this end, it proposes a placement-aware clock network recovery method that constructs a four-stage pipeline integrating gate-level netlists with layout information extracted from scanning electron microscopy (SEM) images. This approach achieves, for the first time, the recovery of clock distribution networks from manufactured chips to infer underlying design intent. Experimental evaluations on chips fabricated in a 450nm process node demonstrate the successful reconstruction of clock topologies and delay characteristics, enabling the quantification of critical metrics such as clock skew. By bridging this gap in the reverse analysis of physical designs, the study advances the state of the art in hardware security. All associated algorithms have been released as open source.
This study addresses the challenges of reverse engineering embedded radio frequency (RF) systems by proposing a non-invasive, bus-level parameter recovery framework that requires no prior firmware knowledge. Leveraging bus tracing, state machine-based protocol decoding, and register mapping, the method enables second-scale extraction and application-layer parsing of RF configurations, frequency hopping sequences, and cryptographic keys. Experimental evaluations on unmanned aerial vehicles and Meshtastic nodes demonstrate that the framework can fully recover RF parameters and decode application data under unknown firmware conditions. These results significantly enhance both the efficiency and practicality of reverse engineering for embedded RF systems, offering a robust solution for security analysis and system validation in scenarios where firmware access is restricted or unavailable.
Traditional simulation-based dynamic timing analysis struggles to balance accuracy and efficiency, and existing gate delay models lack sufficient expressiveness to enable precise, exhaustive path delay analysis for digital circuits. This work proposes a symbolic execution framework integrated with an analytical gate delay model that automatically generates symbolic delay expressions for all paths under a given input transition ordering. For the first time, it incorporates an analytical delay model accounting for both drafting effects and multi-input switching into symbolic execution. By employing a path-sensitive, goal-directed inference mechanism together with symbolic pruning strategies, the approach significantly enhances the completeness and precision of timing analysis while effectively mitigating the combinatorial explosion problem.
本文开发了软件驱动程序,通过低成本的HackRF One SDR实现精确时间应用,使用AI辅助开发流程,提高了软件维护性并大幅减少了开发工作量。
This work addresses the challenges of limited scalability and insufficient attribution accuracy in identifying root causes of power side-channel leakage during pre-silicon processor design. The paper introduces SPARC, a novel framework that enables, for the first time, automated and highly accurate end-to-end leakage detection and root-cause tracing in the pre-silicon phase. SPARC achieves this by performing macrocell-level information flow tracking and employing enhanced shadow logic to tag key-dependent switching activity, which is then correlated with software instructions through statistical leakage testing. Evaluation on multiple open-source RISC-V processors demonstrates that SPARC not only reproduces known vulnerabilities but also uncovers previously unknown microarchitectural side channels, while achieving an 8× speedup in single-trace simulation compared to existing approaches.