Stripped Functionality Logic Locking With Hamming Distance-Based Restore Unit (SFLL-hd) - Unlocked

Stripped Functionality Logic Locking With Hamming Distance-Based Restore Unit (SFLL-hd) - Unlocked
复制标题

DOI:
10.1109/tifs.2019.2904838
复制
发表时间:
2019-10-01
影响因子:
6.8
通讯作者:
Sinanoglu, Ozgur
Sinanoglu, Ozgur
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yang, Fangfei;Tang, Ming;Sinanoglu, Ozgur

文献摘要

被引文献

相似文献

逻辑锁定是一种受到极大关注的技术。它可以保护硬件设计网表免受各种硬件安全威胁,例如来自不受信任的芯片代工厂和最终用户的篡改、逆向工程和盗版。这种技术将逻辑和输入添加到给定的设计网表中,以确保锁定的设计仅在从新输入应用密钥时才起作用;不正确的密钥会使设计产生不正确的输出。新的输入(称为密钥输入)由芯片上的防篡改存储器驱动,该存储器存储密钥。这一领域的研究表明,这种技术,如果不正确地实现,可能容易受到攻击,提取逻辑锁定的关键。最近,一种逻辑锁定技术,称为剥离功能逻辑锁定(SFLL)已被提出,并证明能够承受所有已知的攻击,在一个可证明的安全方式。SFLL通过破坏与许多“受保护”的输入模式相对应的输出,从原始设计中剥离了一些功能。在SFLL的一个版本(称为SFLL-hd)中,这些受保护模式都具有到密钥的特定汉明距离h。修改后的设计伴随着附加的逻辑,仅当密钥在防篡改存储器中时,才固定每个受保护输入模式的输出。在本文中,我们提出了一种在一分钟内打破SFLL-hd的攻击。我们的攻击利用了锁定设计中由于功能条操作而留下的结构痕迹,并且能够识别一些受保护的模式。我们还提出了一个理论框架,帮助我们开发两种不同的技术来完成我们的攻击。在第一种技术中,我们使用高斯消除技术来求解一个方程组,该方程组是我们在O(k(3))时间内基于k个标识的保护模式形成的,其中k是密钥中的密钥位数。第二种技术使用一个识别的保护模式来查询oracle k次。在这两种技术中,我们都成功地从受保护的模式中恢复了密钥。我们表明,我们的攻击SFLL锁定的微处理器设计(超过50 K门),SFLL的作者提供给公众,我们提取的256位密钥在一分钟内,并揭示了它在本文中。我们还测试了我们的攻击SFLL作者提供的其他几个SFLL-hd基准。
Logic locking is a technique that has received significant attention. It protects a hardware design netlist from a variety of hardware security threats, such as tampering, reverse-engineering, and piracy, stemming from untrusted chip foundry and end-users. This technique adds logic and inputs to a given design netlist to make sure that the locked design is functional only when a key is applied from the new inputs; an incorrect key makes the design produce incorrect outputs. The new inputs, referred to as the key inputs, are driven by a tamper-proof memory on the chip, which stores the secret key. Research in this field has shown that this technique, if not implemented properly, may be vulnerable to attacks that extract the key of logic locking. Recently, a logic locking technique called stripped functionality logic locking (SFLL) has been proposed and shown to withstand all known attacks in a provably secure manner. SFLL strips some functionality from the original design by corrupting its output corresponding to a number of "protected" input patterns. In one version of SFLL, referred to as SFLL-hd, these protected patterns are all of a certain hamming distance h to the key. The modified design is accompanied by additional logic that fixes the output for each protected input pattern only when the key is in the tamper-proof memory. In this paper, we present an attack that breaks SFLL-hd within a minute. Our attack exploits structural traces left behind in the locked design due to the functionality strip operation and is capable of identifying some of the protected patterns. We also present a theoretical framework that helps us develop two different techniques to complete our attack. In the first technique, we use the Gaussian elimination technique to solve a system of equations that we form based on k-identified protected patterns in O(k(3)) time in the best case, where k is the number of key bits in key. The second technique uses one identified protected pattern to query the oracle k times. In both techniques, we successfully recover the key from the protected pattern(s). We show that our attacks work on the SFLL-locked microprocessor design (more than 50 K gates) that the authors of SFLL made available to the public; we extract the 256-bit key within a minute and reveal it in this paper. We also test our attacks on a few other SFLL-hd benchmarks provided by SFLL authors.