Reverse engineering camouflaged sequential circuits without scan access

Reverse engineering camouflaged sequential circuits without scan access
复制标题

逆向工程伪装时序电路,无需扫描访问

DOI:
--
复制
发表时间:
2017
期刊:
2017 IEEE/ACM International Conference on Computer-Aided Design (ICCAD)
影响因子:
--
通讯作者:
Mahesh V. Tripunitara
Mahesh V. Tripunitara
中科院分区:
--
文献类型:
--
作者:
Mohamed El Massad;S. Garg;Mahesh V. Tripunitara

文献摘要

被引文献

相似文献

集成电路(IC)封装是一种很有前途的技术,以保护设计的芯片从逆向工程。然而,最近的工作表明,即使是封装的IC也可以使用SAT求解器从芯片的观察到的输入/输出行为进行逆向工程。然而,这些所谓的SAT攻击到目前为止只针对封装的组合电路。对于被扫描的时序电路,SAT攻击要求电路的内部状态通过扫描链是可控制和可观察的。已经隐含地假设,限制扫描链访问增加了被封装的IC的安全性以免受逆向工程攻击。在本文中,我们提出了一种新的攻击方法,decamberage时序电路没有扫描访问。我们的攻击使用模型检查器(比SAT求解器更强大的推理工具)来找到一组有区别的输入序列,即,一个足以确定封装栅极的功能性。我们提出了几个改进,包括使用有界模型检查器,以及确定一组输入序列是否有区别的充分条件,以提高我们攻击的运行时间和可扩展性。我们的攻击是能够decamberage一个大型的顺序基准电路,实现了一个子集的VIPER处理器。
Integrated circuit (IC) camouflaging is a promising technique to protect the design of a chip from reverse engineering. However, recent work has shown that even camouflaged ICs can be reverse engineered from the observed input/output behaviour of a chip using SAT solvers. However, these so-called SAT attacks have so far targeted only camouflaged combinational circuits. For camouflaged sequential circuits, the SAT attack requires that the internal state of the circuit is controllable and observable via the scan chain. It has been implicitly assumed that restricting scan chain access increases the security of camouflaged ICs from reverse engineering attacks. In this paper, we develop a new attack methodology to decamouflage sequential circuits without scan access. Our attack uses a model checker (a more powerful reasoning tool than a SAT solver) to find a discriminating set of input sequences, i.e., one that is sufficient to determine the functionality of camouflaged gates. We propose several refinements, including the use of a bounded model checker, and sufficient conditions for determining when a set of input sequences is discriminating to improve the run-time and scalabilty of our attack. Our attack is able to decamouflage a large sequential benchmark circuit that implements a subset of the VIPER processor.