SCOPE: Synthesis-Based Constant Propagation Attack on Logic Locking

SCOPE: Synthesis-Based Constant Propagation Attack on Logic Locking
复制标题

范围:对逻辑锁定的基于综合的恒定传播攻击

DOI:
--
复制
发表时间:
2021
影响因子:
2.8
通讯作者:
S. Bhunia
S. Bhunia
中科院分区:
工程技术2区
文献类型:
--
作者:
A. Alaql;Md. Moshiur Rahman;S. Bhunia

文献摘要

被引文献

相似文献

硬件知识产权(IP)盗版和滥用给半导体行业带来了新的挑战,因为IP生命周期中的不可信方可能会克隆、逆向工程或从IP中提取重要的设计秘密。保护硬件IP免受此类攻击的一个有前途的解决方案是执行逻辑锁定,其中由密钥控制的附加逻辑被插入IP的战略位置,以在正确的密钥不可用时锁定功能。在过去的十年中,随着大量逻辑锁定技术的出现,研究界也开发了针对它们的强大攻击,以暴露各种漏洞,这些漏洞可以被对手利用来破坏保护。虽然最先进的逻辑锁定解决方案已经证明了对已知攻击的鲁棒性,但迫切需要探索新的攻击向量并减轻它们以实现更高级别的保护。在这篇文章中,我们提出了范围,一种新的基于合成的常数传播攻击的安全评估逻辑锁定技术。SCOPE是一个无预言的协议,攻击者不需要知道锁定算法或锁定的设计。引入的攻击对每个单独的密钥输入端口执行基于合成的分析,并寻找可能有助于导出正确密钥值的有意义的设计特征。SCOPE提供了两种具有不同复杂性和有效性的攻击模式,线性回归测试和无监督机器学习分析。我们执行范围到现有的锁定技术,并证明,平均攻击准确率为84.13%,具有高可扩展性的设计规模。根据SCOPE识别的漏洞,我们提供了一个低开销的对策,可以帮助减轻这种不断传播攻击。
Hardware intellectual property (IP) piracy and misuse have introduced new challenges in the semiconductor industry as untrusted parties in the IP’s life cycle may clone, reverse-engineer, or extract important design secrets from an IP. A promising solution to protect a hardware IP against such attacks is to perform logic locking, where additional logic controlled by a secret key is inserted in strategic locations of an IP to lock the functionality when the correct key is not available. As a multitude of logic locking techniques has emerged in the past decade, the research community has also developed strong attacks against them to expose various vulnerabilities that can be exploited by an adversary to break the protection. While state-of-the-art logic locking solutions have demonstrated provable robustness against known attacks, there is a critical need to explore new attack vectors and mitigate them to achieve a higher level of protection. In this article, we present SCOPE, a novel synthesis-based constant propagation attack for security evaluation of logic locking techniques. SCOPE is oracle-less and requires no knowledge about the locking algorithm or the locked design by an attacker. The introduced attack performs a synthesis-based analysis on each individual key-input port and looks for meaningful design features that may help derive the correct key value. SCOPE offers two attack modes with varying complexity and effectiveness, a linear regression test, and an unsupervised machine-learning analysis. We perform SCOPE to a number of existing locking techniques and demonstrate that the average attack accuracy is 84.13% with high scalability in terms of design size. Based on the vulnerabilities identified by SCOPE, we provide a low-overhead countermeasure that can help mitigate such constant propagation attacks.