ATPG-Guided Fault Injection Attacks on Logic Locking

ATPG-Guided Fault Injection Attacks on Logic Locking
复制标题

DOI:
10.1109/paine49178.2020.9337734
复制
发表时间:
2020-07
期刊:
2020 IEEE Physical Assurance and Inspection of Electronics (PAINE)
影响因子:
--
通讯作者:
Ayush Jain;Tanjidur Rahman;Ujjwal Guin
Ayush Jain;Tanjidur Rahman;Ujjwal Guin
中科院分区:
其他
文献类型:
--
作者:
Ayush Jain;Tanjidur Rahman;Ujjwal Guin

文献摘要

被引文献

相似文献

逻辑锁定是一种广泛接受的保护技术,用于支持集成电路(IC)的外包设计和制造过程,其中通过在网表中加入额外的密钥门来修改原始设计,从而产生依赖于密钥的功能电路。一旦用密钥编程,芯片的原始功能就恢复了,否则,它会对某些输入模式产生错误的结果。在过去的十年中,已经提出了不同的攻击来打破逻辑锁定,同时激励研究人员开发更安全的对策。在本文中,我们提出了一种新的基于固定故障的差分故障分析(DFA)攻击,它可以用来打破依赖于存储的密钥的逻辑锁定。这种攻击是基于自引用的,其中的密钥是通过在密钥线中注入故障并将响应与其无故障的对应物进行比较来确定的。商业ATPG工具可用于生成检测这些故障的测试模式,这些测试模式将在DFA中用于确定密钥。一个测试模式足以确定一个密钥位,这导致最多$\vert\pmb{K}\vert$个测试模式来确定大小为$\vert\pmb{K}\vert$的整个密钥。所提出的攻击是通用的,可以扩展到打破任何逻辑锁定电路。
Logic Locking is a well-accepted protection technique to enable trust in the outsourced design and fabrication processes of integrated circuits (ICs) where the original design is modified by incorporating additional key gates in the netlist, resulting in a key-dependent functional circuit. The original functionality of the chip is recovered once it is programmed with the secret key, otherwise, it produces incorrect results for some input patterns. Over the past decade, different attacks have been proposed to break logic locking, simultaneously motivating researchers to develop more secure countermeasures. In this paper, we propose a novel stuck-at fault-based differential fault analysis (DFA) attack, which can be used to break logic locking that relies on a stored secret key. This proposed attack is based on self-referencing, where the secret key is determined by injecting faults in the key lines and comparing the response with its fault-free counterpart. A commercial ATPG tool can be used to generate test patterns that detect these faults, which will be used in DFA to determine the secret key. One test pattern is sufficient to determine one key bit, which results in at most $\vert\pmb{K}\vert$ test patterns to determine the entire secret key of size $\vert\pmb{K}\vert$. The proposed attack is generic and can be extended to break any logic locked circuits.