A Guaranteed Secure Scan Design Based on Test Data Obfuscation by Cryptographic Hash

A Guaranteed Secure Scan Design Based on Test Data Obfuscation by Cryptographic Hash
复制标题

基于密码哈希混淆测试数据的保证安全扫描设计

DOI:
10.1109/tcad.2020.2979458
复制
发表时间:
2020
影响因子:
2.9
通讯作者:
Li Huawei
Li Huawei
中科院分区:
计算机科学3区
文献类型:
--
作者:
Cui Aijiao;Li Mengyang;Qu Gang;Li Huawei

文献摘要

相似文献

为便于制造测试,可测试性设计(DFT)技术已被广泛应用于集成电路(IC)设计过程中。基于扫描的DFT架构是一种流行的DFT功能,可为被测电路提供完全的可测试性。然而,这对于密码芯片等集成电路来说却是一把双刃剑,因为扫描设计可以作为获取中间加密结果的侧通道,利用扫描设计可以很容易地推导出密钥。为了抵抗这种基于扫描的旁路攻击,人们提出了许多对策来混淆扫描链中的测试数据。不幸的是,由于性能和资源的限制,大多数模糊逻辑不能被证明是不可逆的,因此从模糊输出中获得正确的测试数据的风险很高。在本文中,我们建议使用加密散列模块对测试响应进行一些后处理,以确保扫描设计的安全。与现有的方法相比,我们的方法有几个明显的优势。首先,基于密码哈希函数的抗原像特性和引入的SALT信息和数据采集方案来保证安全性。其次,它的开销很低,因为散列模块通常在IC上可用,尤其是那些安全性很重要的IC。最后,由于我们没有修改任何测试输入,因此保留了完全的可测试性。我们给出了所提出的安全设计的实现,报告了实验结果,并证明了我们的方法能够在保持可测试性和其他测试性能的同时,以可忽略的开销抵抗所有已知的基于扫描的旁路攻击。
Design-for-testability (DfT) techniques have been widely adopted into the integrated circuit (IC) design process to facilitate manufacture testing. The scan-based DfT architecture is a popular DfT feature that provides full testability for the circuit under test. However, this turns into a double-edged sword for some ICs such as cryptographic chips because scan design could be used as a side channel to access the intermediate encryption results, with which the cipher key can be deduced easily. To resist such scan-based side-channel attacks, many countermeasures are proposed to obfuscate the test data in scan chain. Unfortunately, most of the obfuscation logic, due to the performance and resource constraints, cannot be proven to be irreversible and hence suffers a high risk for the correct test data being derived from the obfuscated output. In this article, we propose to utilize the cryptographic hash module for some post-processing of the test responses in order to secure the scan design. Our approach has several clear advantages over existing ones. First, the security is guaranteed based on the preimage resistance of cryptographic hash function and the introduced salt information and data collection scheme. Second, it incurs low overhead because the hash module is normally available on the IC, in particular, those where security is important. Finally, full testability is retained as we are not modifying any test input. We present the implementation of the proposed secure design, report the experimental results, and demonstrate that our approach can resist all known scan-based side-channel attacks with negligible overhead while maintaining the testability and other testing performances.