TGA: An Oracle-less and Topology-Guided Attack on Logic Locking

TGA: An Oracle-less and Topology-Guided Attack on Logic Locking
复制标题

TGA:针对逻辑锁定的无 Oracle 拓扑引导攻击

DOI:
10.1145/3338508.3359576
复制
发表时间:
2019
期刊:
ASHES'19: Proceedings of the 3rd ACM Workshop on Attacks and Solutions in Hardware Security Workshop
影响因子:
--
通讯作者:
Guin, Ujjwal
Guin, Ujjwal
中科院分区:
--
文献类型:
--
作者:
Zhang, Yuqiao;Cui, Pinchen;Zhou, Ziqi;Guin, Ujjwal

文献摘要

参考文献

被引文献

相似文献

由于半导体设计和制造的外包,近年来出现了许多威胁,它们是集成电路(IC)的生产过剩、非法销售有缺陷的IC以及知识产权(IP)的盗版。逻辑锁定是在这种复杂的IC设计和制造过程中实现信任的一种方法,其中通过插入锁来修改底层功能以使对手无法使芯片正常工作来混淆设计。一个被锁定的芯片只有在通过将一个秘密密钥编程到其防篡改存储器中而被激活时才能正常工作。多年来,研究人员已经提出了不同的锁定机制,主要是为了防止基于布尔可满足性(SAT)的攻击,并成功地保持了锁定设计的安全性。然而,一个不可信的代工厂,对手,可以使用许多其他有效的手段来找出秘密密钥。在本文中,我们提出了一种新的预言和拓扑引导的攻击表示为TGA。攻击依赖于识别用于确定密钥位的值的重复函数。该攻击不需要来自未锁定芯片的任何数据,并且消除了对oracle的需求。攻击是基于自我参照,即,它比较内部网表以找到密钥。所提出的图搜索算法有效地找到了电路的锁定部分的重复功能。我们提出的攻击正确地估计一个关键位非常有效,它只需要几秒钟来确定的关键位。我们还提出了一个解决方案,以阻止TGA和使逻辑锁定安全。
Due to the outsourcing of semiconductor design and manufacturing, a number of threats have emerged in recent years, and they are overproduction of integrated circuits (ICs), illegal sale of defective ICs, and piracy of intellectual properties (IPs). Logic locking is one method to enable trust in this complex IC design and manufacturing processes, where a design is obfuscated by inserting a lock to modify the underlying functionality so that an adversary cannot make a chip to function properly. A locked chip will only work properly once it is activated by programming with a secret key into its tamper-proof memory. Over the years, researchers have proposed different locking mechanisms primarily to prevent Boolean satisfiability (SAT)-based attacks, and successfully preserve the security of a locked design. However, an untrusted foundry, the adversary, can use many other effective means to find out the secret key. In this paper, we present a novel oracle-less and topology-guided attack denoted as TGA. The attack relies on identifying repeated functions for determining the value of a key bit. The proposed attack does not require any data from an unlocked chip, and eliminates the need for an oracle. The attack is based on self-referencing, i.e., it compares the internal netlist to find the key. The proposed graph search algorithm efficiently finds a duplicate function of the locked part of the circuit. Our proposed attack correctly estimate a key bit very efficiently, and it only takes few seconds to determine the key bit. We also present a solution to thwart TGA and make logic locking secure.
FORTIS:建立前向信任以保护 IP 和 IC 的综合解决方案
DOI: 10.1145/2893183
发表时间: 2016
期刊: ACM Trans. Design Autom. Electr. Syst.
影响因子: --
作者:
Ujjwal Guin;Qihang Shi;Domenic Forte;M. Tehranipoor
通讯作者: M. Tehranipoor
通过设计扣留和纠缠预防 IC 盗版
DOI: 10.1109/aspdac.2015.7059112
发表时间: 2015
期刊: The 20th Asia and South Pacific Design Automation Conference
影响因子: --
作者:
Soroush Khaleghi;K. Zhao;Wenjing Rao
通讯作者: Wenjing Rao
CSST:防止 IC 盗版的高效安全拆分测试
DOI: 10.1109/natw.2014.17
发表时间: 2014
期刊: 2014 IEEE 23rd North Atlantic Test Workshop
影响因子: --
作者:
Md. Tauhidur Rahman;Domenic Forte;Quihang Shi;Gustavo K. Contreras;M. Tehranipoor
通讯作者: M. Tehranipoor
通过网表级混淆进行硬件保护和身份验证
DOI: 10.1109/iccad.2008.4681649
发表时间: 2008
期刊: 2008 IEEE/ACM International Conference on Computer-Aided Design
影响因子: --
作者:
R. Chakraborty;S. Bhunia
通讯作者: S. Bhunia
一种新颖的安全设计 (DFS) 架构,可防止未经授权的 IC 过量生产
DOI: 10.1109/vts.2017.7928946
发表时间: 2017
期刊: 2017 IEEE 35th VLSI Test Symposium (VTS)
影响因子: --
作者:
Ujjwal Guin;Ziqi Zhou;A. Singh
通讯作者: A. Singh