Thwarting All Logic Locking Attacks: Dishonest Oracle With Truly Random Logic Locking

Thwarting All Logic Locking Attacks: Dishonest Oracle With Truly Random Logic Locking
复制标题

阻止所有逻辑锁定攻击:具有真正随机逻辑锁定的不诚实预言机

DOI:
10.1109/tcad.2020.3029133
复制
发表时间:
2021
影响因子:
2.9
通讯作者:
O. Sinanoglu
O. Sinanoglu
中科院分区:
计算机科学3区
文献类型:
--
作者:
Nimisha Limaye;E. Kalligeros;N. Karousos;Irene G. Karybali;O. Sinanoglu

文献摘要

被引文献

相似文献

虽然逻辑锁定是保护硬件设计的一种很有前途的防御措施,但已有许多攻击被证明通过检索密钥来破坏其安全性。所有强大的攻击都依赖于正常工作的芯片,即Oracle,尤其是大量使用测试访问。所提出的技术DisORC在检测到潜在攻击时会将先知变成不诚实的先知。DisORC的工作前提是不需要使用正确的功能执行芯片的结构测试。我们通过在逻辑锁定设计周围添加电路来实现这一功能,该设计在检测到对扫描链的访问时重新配置其功能。任何访问扫描链的尝试都会断开密钥与电路的连接,并清除其所有痕迹,从而隔离并保护密钥。我们还将这一防御与真正的随机逻辑锁定(TRLL)方案配对,该方案在插入钥匙门和保留信号极性时做出随机决定,而不依赖任何逻辑合成技术来执行气泡推送。任何已知或预期的基于网表分析的攻击都不会得到任何有用的信息来推断关键值。组合防御DisORC+TRLL可挫败基于Oracle和基于网表分析的攻击,同时在输出端提供足够的腐败级别。我们还表明,所提出的防御措施是经济有效的,并且可以很容易地集成到设计流程中。拟议的逻辑锁定防御提供保护,防止不可信的代工厂、测试设施、最终用户以及它们的任何组合串通在一起。
While logic locking is a promising defense to protect hardware designs, many attacks have been shown to undermine its security by retrieving the secret key. All the powerful attacks rely on a working chip, i.e., an oracle, and in particular, heavily use the test access. The proposed technique DisORC turns the oracle into a dishonest one whenever a potential attack is detected. DisORC works on the premise that structural testing of chips need not be performed with the correct functionality. We implement this capability by adding circuitry around a logic-locked design that reconfigures its functionality upon detecting access to scan chains. Any attempt to access scan chains disconnects the secret key from the circuit, and clears all of its traces, isolating and securing it. We also pair this defense with a truly random logic locking (TRLL) scheme that makes random decisions in inserting key gates and retaining signal polarities without relying on any logic synthesis technique to perform bubble pushing. Any netlist analysis-based attack, known or anticipated, will then learn nothing useful to infer the key values. The combined defense DisORC + TRLL thwarts oracle-based and netlist analysis-based attacks while delivering sufficient corruption levels at the outputs. We also show that the proposed defense is cost effective and can be integrated into the design flow easily. The proposed logic locking defense provides protection against untrusted foundry, testing facility, end users, and any combination of them colluding together.