Logic Locking for Secure Outsourced Chip Fabrication: A New Attack and Provably Secure Defense Mechanism

Logic Locking for Secure Outsourced Chip Fabrication: A New Attack and Provably Secure Defense Mechanism
复制标题

DOI:
--
复制
发表时间:
2017-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Mohamed El Massad;Jun Zhang;S. Garg;Mahesh V. Tripunitara
Mohamed El Massad;Jun Zhang;S. Garg;Mahesh V. Tripunitara
中科院分区:
其他
文献类型:
--
作者:
Mohamed El Massad;Jun Zhang;S. Garg;Mahesh V. Tripunitara

文献摘要

被引文献

相似文献

芯片设计师将芯片制造外包给外部代工厂,但存在知识产权被盗的风险。逻辑锁定是缓解这种威胁的一种很有前途的解决方案,它为芯片增加了额外的逻辑门(密钥门)和输入(密钥位),以便只有在应用了只有设计师而不是代工厂才知道的正确密钥时才能正常工作。在本文中,我们确定了一个新的漏洞,在所有现有的逻辑锁定方案。先前对逻辑锁定的攻击假设,除了被锁定芯片的设计之外,攻击者还可以访问芯片的工作副本。我们的攻击不需要一个工作副本,但我们成功地恢复了相当大一部分的关键位,从设计的锁定芯片。从经验上讲,我们证明了我们的攻击成功的8个大的基准电路,从基准套件,已专门为逻辑综合研究,为两种不同的逻辑锁定方案。然后,为了解决这个漏洞,我们开始研究可证明安全的逻辑锁定机制。我们正式,第一次我们的知识,一个精确的概念,逻辑锁的安全性。我们确定,任何根据我们的定义是安全的锁定过程,保证抵御我们的desynthesis攻击,以及所有其他已知的攻击。然后,我们设计了一个新的逻辑锁定程序,猫鼬,保证锁定的芯片显示没有信息的关键或设计师的预期功能。Meerkat背后的一个主要见解是,通过简化有序二进制决策图(ROBDD)的布尔功能的规范表示可以有效地利用来提供安全性。我们分析了Meerkat的安全属性和它所产生的开销。因此,我们的工作是对保护数字IC的基础和实践的贡献。
Chip designers outsource chip fabrication to external foundries, but at the risk of IP theft. Logic locking, a promising solution to mitigate this threat, adds extra logic gates (key gates) and inputs (key bits) to the chip so that it functions correctly only when the correct key, known only to the designer but not the foundry, is applied. In this paper, we identify a new vulnerability in all existing logic locking schemes. Prior attacks on logic locking have assumed that, in addition to the design of the locked chip, the attacker has access to a working copy of the chip. Our attack does not require a working copy and yet we successfully recover a significant fraction of key bits from the design of the locked chip only. Empirically, we demonstrate the success of our attack on eight large benchmark circuits from a benchmark suite that has been tailored specifically for logic synthesis research, for two different logic locking schemes. Then, to address this vulnerability, we initiate the study of provably secure logic locking mechanisms. We formalize, for the first time to our knowledge, a precise notion of security for logic locking. We establish that any locking procedure that is secure under our definition is guaranteed to counter our desynthesis attack, and all other such known attacks. We then devise a new logic locking procedure, Meerkat, that guarantees that the locked chip reveals no information about the key or the designer's intended functionality. A main insight behind Meerkat is that canonical representations of boolean functionality via Reduced Ordered Binary Decision Diagrams (ROBDDs) can be leveraged effectively to provide security. We analyze Meerkat with regards to its security properties and the overhead it incurs. As such, our work is a contribution to both the foundations and practice of securing digital ICs.