Security Against Hardware Trojan Attacks Using Key-Based Design Obfuscation

Security Against Hardware Trojan Attacks Using Key-Based Design Obfuscation
复制标题

使用基于密钥的设计混淆来防御硬件木马攻击

DOI:
--
复制
发表时间:
2011
期刊:
Journal of electronic testing
影响因子:
--
通讯作者:
S. Bhunia
S. Bhunia
中科院分区:
--
文献类型:
--
作者:
R. Chakraborty;S. Bhunia

文献摘要

被引文献

相似文献

恶意修改不可信制造设施中的硬件,被称为硬件木马,已经成为一个主要的安全问题。在制造后测试期间全面检测这些木马已被证明是极其困难的。因此,重要的是要开发设计技术,提供有效的对策,防止硬件木马的攻击,或在测试过程中方便检测。混淆是一种传统上用于防止软件和硬件知识产权(IP)盗版的技术。在这项工作中,我们提出了一种新的应用程序的关键电路结构和功能混淆,以实现对罕见的内部电路条件触发的硬件木马程序的保护。所提出的混淆方案是基于明智的修改状态转换函数,它创建两个不同的功能模式:正常和混淆。电路仅在应用定义密钥的特定输入序列时才从混淆模式转换到正常模式。我们表明,它提供了两种方式对木马攻击的安全性:(1)它使一些插入的木马良性,即它们变得有效,只有在混淆模式;(2)它防止对手利用电路中的真正罕见的事件插入难以检测的木马。因此,所提出的设计方法可以实现同时保护硬件木马和硬件IP盗版。除了保护芯片免受特洛伊木马攻击的铸造,我们还表明,它可以防止恶意修改的不可信的计算机辅助设计(CAD)工具在SoC和FPGA设计流程。一组基准电路的仿真结果表明,该方案是能够实现高水平的安全性,以适度的面积,功耗和延迟开销的木马攻击。
Malicious modification of hardware in untrusted fabrication facilities, referred to as hardware Trojan, has emerged as a major security concern. Comprehensive detection of these Trojans during post-manufacturing test has been shown to be extremely difficult. Hence, it is important to develop design techniques that provide effective countermeasures against hardware Trojans by either preventing Trojan attacks or facilitating detection during test. Obfuscation is a technique that is conventionally employed to prevent piracy of software and hardware intellectual property (IP). In this work, we propose a novel application of key-based circuit structure and functionality obfuscation to achieve protection against hardware Trojans triggered by rare internal circuit conditions. The proposed obfuscation scheme is based on judicious modification of the state transition function, which creates two distinct functional modes: normal and obfuscated. A circuit transitions from the obfuscated to the normal mode only upon application of a specific input sequence, which defines the key. We show that it provides security against Trojan attacks in two ways: (1) it makes some inserted Trojans benign, i.e. they become effective only in the obfuscated mode; and (2) it prevents an adversary from exploiting the true rare events in a circuit to insert hard-to-detect Trojans. The proposed design methodology can thus achieve simultaneous protection from hardware Trojans and hardware IP piracy. Besides protecting ICs against Trojan attacks in foundry, we show that it can also protect against malicious modifications by untrusted computer-aided design (CAD) tools in both SoC and FPGA design flows. Simulation results for a set of benchmark circuits show that the scheme is capable of achieving high levels of security against Trojan attacks at modest area, power and delay overhead.