On the Difficulty of FSM-based Hardware Obfuscation

On the Difficulty of FSM-based Hardware Obfuscation
复制标题

论基于FSM的硬件混淆的难度

DOI:
10.13154/tches.v2018.i3.293-330
复制
发表时间:
2018
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
C. Paar
C. Paar
中科院分区:
--
文献类型:
--
作者:
Marc Fyrbiak;Sebastian Wallat;Jonathan Déchelotte;Nils Albartus;Sinan Böcker;R. Tessier;C. Paar

文献摘要

被引文献

相似文献

在当今的集成电路(IC)生产链中,设计师的宝贵知识产权(IP)对不同的利益相关者是透明的,因此不可避免地容易受到盗版。为了防止这种威胁,已经提出了许多基于电路控制路径混淆的防御措施,即有限状态机(FSM),并且通常被认为是安全的。然而,这些顺序混淆方案的安全性是值得怀疑的,因为在安全性分析中通常忽略了逆向工程和后续操作的实际能力。我们的工作的贡献是三方面的:首先,我们演示了如何高层次的控制路径信息可以自动提取第三方,门级网表。为此,我们扩展了最先进的逆向工程算法来处理现场可编程门阵列(FPGA)门级网表配备FSM混淆。其次,现实的逆向工程能力的基础上,我们仔细审查国家的最先进的FSM混淆计划的安全性。我们揭示了几个通用的策略,绕过所谓的安全FSM混淆方案,我们实际上证明了我们的攻击的几个硬件设计,包括加密IP核。第三,我们提出了硬件纳米粒子的设计和实现,一种新的混淆方案的基础上部分动态重新配置,一般减轻现有的算法逆向工程。
In today’s Integrated Circuit (IC) production chains, a designer’s valuable Intellectual Property (IP) is transparent to diverse stakeholders and thus inevitably prone to piracy. To protect against this threat, numerous defenses based on the obfuscation of a circuit’s control path, i.e. Finite State Machine (FSM), have been proposed and are commonly believed to be secure. However, the security of these sequential obfuscation schemes is doubtful since realistic capabilities of reverse engineering and subsequent manipulation are commonly neglected in the security analysis. The contribution of our work is threefold: First, we demonstrate how high-level control path information can be automatically extracted from third-party, gate-level netlists. To this end, we extend state-of-the-art reverse engineering algorithms to deal with Field Programmable Gate Array (FPGA) gate-level netlists equipped with FSM obfuscation. Second, on the basis of realistic reverse engineering capabilities we carefully review the security of state-of-the-art FSM obfuscation schemes. We reveal several generic strategies that bypass allegedly secure FSM obfuscation schemes and we practically demonstrate our attacks for a several of hardware designs, including cryptographic IP cores. Third, we present the design and implementation of Hardware Nanomites, a novel obfuscation scheme based on partial dynamic reconfiguration that generically mitigates existing algorithmic reverse engineering.