Pqc logic lock device and method based on physical camouflage and cross-shuffling
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING LANGKONG QUANTUM TECHNOLOGY CO LTD
- Filing Date
- 2026-04-01
- Publication Date
- 2026-08-07
AI Technical Summary
但通过全局配置端口修改配置存储器(CFGLUTs)会耗费大量时钟周期,并引发极其巨大且特征分明的瞬态配置功耗,不仅破坏了恒定时间特性,还为攻击者提供了完美的电磁侧信道锚点
[0027]免疫图神经网络(GNN)的拓扑逆向攻击:本发明摒弃了传统逻辑锁的密钥门插入架构,在底层物理层面采用外观形态完全一致的物理伪装标准单元构建密钥控制阵列。这种设计从物理版图和显微成像层面彻底抹除了保护结构的拓扑畸变特征,使自动化逆向工程无法识别和剥离逻辑锁,有效抵御了代工厂环节的硬件木马植入与知识产权盗用。
Smart Images

Figure CN122533727A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of post-quantum cryptography technology, and in particular relates to a PQC logic lock device and method based on physical camouflage and cross-shuffling. Background Technology
[0002] The global division of labor in the integrated circuit industry inevitably exposes high-value post-quantum cryptography (PQC) hardware accelerator IPs to supply chain security threats from untrusted foundries during the design, manufacturing, and tape-out stages. These threats manifest as IP piracy, overproduction, hardware reverse engineering, and malicious implantation of hardware malware, seriously threatening the intellectual property rights and operational security of post-quantum cryptography hardware IPs.
[0003] Logic lock technology, as a core means of integrated circuit hardware security protection, ensures that the chip can only function normally when the correct activation key is loaded by inserting key gates into the chip's original netlist, making it an important technical solution to resist the aforementioned supply chain security threats. However, when traditional logic lock technology is directly applied to PQC cryptographic circuits, three fatal physical and algebraic defects are exposed due to the algorithmic characteristics and hardware implementation requirements of PQC circuits, making it impossible to meet the high security protection requirements of PQC hardware IP.
[0004] Traditional logic lock technology can lead to topology anomalies and AI reverse identification risks. The lookup tables or dense XOR gates introduced by this technology can create significant topology distortions on the local physical layout of the chip. These distortions can be captured by attackers using machine learning models based on graph neural networks (GNNs), thereby enabling automatic identification and precise stripping of logic locks, resulting in lock protection failure.
[0005] Traditional logic lock technology suffers from the LEDA / LEDFA vulnerability, which allows for cryptographic side-channel backlash. Recent security research indicates that applying logic locks in cryptographic circuits is extremely insecure. When an incorrect activation key is input, the nonlinear structure inside the circuit is often disrupted, making the implementation of logic locks vulnerable to classical algebra attacks (i.e., LEDA attacks without injecting faults) and dimensionality reduction attacks from Lock Enable Differential Fault Analysis (LEDFA).
[0006] Traditional logic lock technology suffers from power consumption explosions due to dynamic reconfiguration. To resist detection, existing technologies attempt to introduce Dynamic Local Reconfiguration (DPR) to construct hardware moving targets. However, modifying configuration memories (CFGLUTs) through global configuration ports consumes a large number of clock cycles and causes extremely large and distinctive transient configuration power consumption, which not only destroys the constant-time characteristics but also provides attackers with a perfect electromagnetic side-channel anchor. Summary of the Invention
[0007] The purpose of this invention is to provide a PQC logic lock device and method based on physical camouflage and cross-shuffling, so as to achieve immune graph neural network topology recognition, Boolean satisfiability attack, and enable differential fault analysis and zero-fault algebra attack in the unauthorized unlock state of the absolutely immune lock, thus achieving high security against forgery and tampering.
[0008] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is a PQC logic lock method based on physical camouflage and cross-shuffling, including the following steps:
[0009] S1. Construct a physical spoofing and substitution network to achieve key control in post-quantum cryptography hardware;
[0010] S2. Construct a generalized anti-SAT locking state machine and cascade it with the physical camouflage replacement network to provide a mathematical barrier against Boolean satisfiability attacks;
[0011] S3. Execute the error-state side-channel equivalence mechanism to make the power consumption characteristics of the circuit equivalent to those of the normal state when an incorrect key is input.
[0012] S4. Activate the local cross-shuffle network to dynamically and randomly reorganize the data path during operation, and perform random fine-grained shuffling of the underlying data path within a single physical clock cycle.
[0013] Furthermore, step S1 includes: constructing a replacement key control circuit network using physical camouflage standard units, and distributively embedding multiple physical camouflage standard units into the netlist of the post-quantum cryptographic arithmetic logic core to form a physical camouflage replacement key control array; wherein, the physical camouflage standard units have a consistent appearance at the geometric layout level composed of polysilicon wiring and metal wiring, and the difference in their actual logical functions is determined by the difference in ion doping concentration in the active region of the silicon substrate.
[0014] Furthermore, the physical camouflage standard unit, under scanning electron microscopy imaging, exhibits a two-dimensional cross-correlation coefficient greater than 0.99 with the real standard unit; its functional transistor channel doping concentration is 1×10⁻⁶. 17 Up to 5×10 17 cm -3 The channel doping concentration of the dummy transistor was modulated to be greater than 5 × 10⁻⁶. 18 cm -3 Or perform inversion doping.
[0015] Furthermore, in step S2, the generalized anti-SAT lock-in state machine is internally configured with a complementary masquerade logic tree to construct a high degree of entanglement constraint between the activation key and the data input; the complementary masquerade logic tree outputs an inverse signal when the correct activation key is input, and outputs a constant authorization signal after XOR convergence to unlock the downstream physical masquerade replacement network.
[0016] Furthermore, step S3 includes: when an erroneous activation key is received, the subsequent operations are smoothly mapped to the pseudo-polynomial ring space through an anti-LEDA side-channel equivalent mapper, and the mapped erroneous state data stream is bound to the underlying clock interleaving network and the hybrid blinding network to smooth out the Hamming weight statistical variance offset between the real key state and the erroneous pseudo-ring state operations.
[0017] Furthermore, the pseudo-modulus q' of the pseudo-polynomial ring space is dynamically determined by the hash value of the current erroneous activation key; the clock interleaving network is a 4-way spread-spectrum multiphase interleaved clock with a 90° phase difference; the hybrid blinding network includes arithmetic blinding and Boolean blinding.
[0018] Furthermore, step S4 includes: activating a nanosecond-level local cross-shuffling network embedded between key pipeline nodes of the processor; the network is controlled by a true random number generator inside the chip to perform random fine-grained shuffling of the underlying data path within a single physical clock cycle.
[0019] Furthermore, the core of the nanosecond-level local cross-shuffle network is a non-blocking Benes cross-switch matrix, which is embedded between the register file data read port and the arithmetic logic unit input port. The minimum granularity of data reconstruction is 16-bit words. The total number of path logic gates in the shuffle operation is kept constant by filling dummy logic.
[0020] A PQC logic lock device based on physical spoofing and cross-shuffling, used in the aforementioned PQC logic lock method based on physical spoofing and cross-shuffling, includes: a physical spoofing replacement key control array, distributed in the netlist of the post-quantum cryptographic arithmetic logic core;
[0021] A generalized anti-SAT locking state machine is cascaded with the physical spoofing replacement key control array;
[0022] An LEDA-resistant side-channel equivalent mapper is connected to the physical masquerading replacement key control array and the generalized SAT-resistant locking state machine.
[0023] A nanosecond-level local cross-shuffling network is embedded between key pipeline nodes in a post-quantum cryptography processor;
[0024] The trusted configuration handshake interface is used to securely obtain, verify, and inject the activation key into the chip from an external security module.
[0025] Furthermore, the physical camouflage replacement key control array is composed of multiple physical camouflage standard units with consistent appearance at the geometric layout level; the nanosecond-level local cross-shuffling network includes a non-blocking Benes cross-switch matrix and is connected to a true random number generator inside the chip; the data path of the trusted configuration handshake interface adopts a leakage-proof design.
[0026] Compared with the prior art, the beneficial effects of the present invention include the following points:
[0027] Topological Reverse Engineering Attacks Using Immune Graph Neural Networks (GNNs): This invention abandons the key-gate insertion architecture of traditional logic locks and constructs a key control array at the underlying physical level using physically identical camouflaged standard units. This design completely erases the topological distortion features of the protective structure from the physical layout and microscopic imaging levels, making it impossible for automated reverse engineering to identify and strip the logic lock, effectively resisting hardware trojan implantation and intellectual property theft in the foundry process.
[0028] Constructing an exponential mathematical barrier against Boolean satisfiability (SAT) attacks: By cascading generalized anti-SAT (G-Anti-SAT) locked state machines and introducing complementary masquerading logic tree designs, this invention establishes an extremely high degree of entanglement between the activation key and the data input. When facing SAT and its approximate variants, the size of the solver's Boolean clauses explodes exponentially, completely blocking unauthorized key derivation from the perspective of mathematical complexity.
[0029] Absolute Immunity to Side-Channel Analysis and Algebraic Attacks in Unauthorized States: Addressing the vulnerability of traditional PQC circuits that easily expose nonlinear defects when locked, this invention innovatively introduces an LEDA-resistant side-channel equivalent mapper. When an incorrect key is input, the system smoothly maps its computation to a pseudo-polynomial ring space, and, combined with clock interleaving and a hybrid blinding network, forcibly smooths out the Hamming weight variance offset between the real and incorrect states. Test results show that its T-test statistic is strictly below the security threshold, effectively cutting off the convergence paths of Mutual Information Analysis (MIA), Zero-Fault Algebraic Attack (LEDA), and Lock-Enabled Differential Fault Analysis (LEDFA).
[0030] Achieving dynamic hardware concealment with no power consumption spikes and low overhead: This invention replaces the traditional global dynamic local reconfiguration (DPR) with a nanosecond-level local cross-shuffling network, controlled by an independent true random number generator, enabling random reconfiguration of data paths within a single clock cycle. This mechanism not only strictly maintains the constant-time characteristics of the PQC algorithm but also completely eliminates the huge power consumption spikes during reconfiguration, forming a concealed hardware moving target resistant to physical detection. Simultaneously, the overall silicon area overhead is controlled within 12%, and the power consumption overhead is less than 8%, meeting the timing and resource convergence requirements of high-performance hardware accelerators. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is a flowchart of the PQC logic lock method based on physical camouflage and cross-shuffling provided in the embodiments of the present invention;
[0033] Figure 2 This is a comparison chart of the TVLA side channel leakage assessment test curves based on 107 waveforms between the traditional technical solution and the embodiment of the present invention. Detailed Implementation
[0034] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0035] like Figure 1 This embodiment provides a PQC (post-quantum cryptography) logic lock method based on physical camouflage and cross-shuffling; specifically:
[0036] S1. Construct a physical camouflage gate replacement network that resists GNN topology recognition:
[0037] In this embodiment, for the register transfer level (RTL) design stage and physical synthesis stage of the PQC accelerator IP, the key gate insertion architecture of the traditional logic lock is abandoned, and a key control circuit (RKC) network based on cell replacement is constructed and introduced. This RKC network serves as the core protection unit of the post-quantum cryptographic arithmetic logic core, and its underlying transistors are all built from physical camouflage standard cells.
[0038] The physical camouflage standard unit is a standard logic unit customized through ion doping process. At the geometric layout (GDSII) level composed of polysilicon wiring and metal wiring, physical camouflage standard units with different functions (such as NAND gates and NOR gates) maintain a completely consistent appearance. The difference in their actual logic functions is determined only by the extremely microscopic difference in ion doping concentration in the active region of the silicon substrate. This eliminates the difference in appearance of functional units caused by traditional key gates at the physical layout level.
[0039] This embodiment embeds multiple physical camouflage standard units into the netlist of the post-quantum cryptography arithmetic logic core in a distributed layout, thereby constructing a physical camouflage replacement key control array. This distributed embedding method makes the physical camouflage standard units and conventional logic units have no obvious distribution characteristics in the netlist. Combined with the consistent layout design of the physical camouflage standard units, from the imaging recognition level of optical microscopes and electron microscopes, it completely shields the topology recognition and function stripping of the RKC network by automated reverse engineering, and achieves effective resistance to topology reverse attacks based on graph neural networks (GNN).
[0040] In some specific implementations, the specific process of the physical masquerade gate replacement network that resists GNN topology recognition is as follows:
[0041] S101. Construct a library of physically disguised standard cells. The disguised standard cells (such as NAND gates and NOR gates) maintain absolute consistency in appearance regarding the geometric layout (GDSII) of the polysilicon gate and metal interconnect layer above the silicon substrate. Specifically, in a 28nm CMOS process, the polysilicon gate spacing is strictly maintained at 114nm, and the spacing of the first metal layer (M1) is maintained at 90nm. Under scanning electron microscopy (SEM) imaging at a resolution of 2nm, the two-dimensional cross-correlation coefficient between them and the real standard cells is greater than 0.99, thus achieving indistinguishability under optical and conventional electron microscopy. In this embodiment, the logical function difference of the physically disguised standard cells is achieved through the ion doping concentration of the transistor active region: the channel doping concentration of a functionally normal transistor is controlled at... The channel doping concentration of the dummy transistor was modulated to... Alternatively, it can be inversely doped to induce a failure state that is either "normally off" or "normally on".
[0042] Subsequently, in the design of the post-quantum cryptography (PQC) accelerator IP, the aforementioned masquerading unit was used to construct a substitution key control circuit (RKC). During the register-transfer level (RTL) design phase, the number-theoretic transformation butterfly operation unit of the M2-KEM algorithm and the nonlinear substitution layer of the Keccak hash module were selected. The key logic gates in the (step) are replaced. Boolean expression rewriting techniques are used to rewrite the original function. Reconstructed into a key-controlled reconstruction function In the form of, For key variables, The key is deeply integrated into the complex logic expression by using a pre-defined decoy logic, rather than simply inserting an XOR key gate.
[0043] During the physical synthesis phase, cell replacement and integration are performed. Using place-and-route tools, based on the key mapping table, selected conventional standard cells are replaced with physically masquerading standard cells that have completely identical pin definitions and layout (LEF) information. After replacement, incremental static timing analysis is performed to insert buffers on non-critical paths to compensate for picosecond-level timing deviations introduced by doping differences, ensuring that no new identifiable topology or timing distortions are introduced.
[0044] Finally, multiple physical camouflage standard units, customized and integrated through the above process, are distributed and embedded in the netlist of the post-quantum cryptography arithmetic logic core, forming the physical camouflage replacement key control array. This array blocks or disrupts normal data flow when the correct key is not loaded, and its consistent physical appearance makes it impossible for automated reverse engineering based on graph neural networks (GNNs) to identify and remove the protection structure from the layout topology, thus achieving black-box protection of hardware IP at the foundry level.
[0045] S2. Constructing a G-Anti-SAT state machine with exponential mathematical barriers (generalized anti-SAT locked state machine):
[0046] This implementation builds upon the RKC masking network by cascading generalized anti-SAT (G-Anti-SAT) control logic. By configuring complementary and non-complementary masquerading logic trees, it constructs an extremely high entanglement constraint between the activation key and the data input, causing the locked PQC hardware to experience a strictly exponential increase in solution time when facing SAT and its approximate variant (AppSAT) attacks, thus mathematically blocking key derivation.
[0047] S201. Determine hardware structure and connections.
[0048] In some specific implementations, the generalized anti-SAT lock-lock state machine is physically cascaded with the Physically Disguised Replacement Key Control Array (RKC) described in S1. The generalized anti-SAT lock-lock state machine includes a 256-bit state register set, and its state transition function is determined by three inputs: the current state (S_t), the data input from the PQC core (D_in), and the 256-bit activation key (K_active). The output of the state machine is used to generate authorization signals that control the RKC network.
[0049] S202, Design of a Disguised Logic Tree
[0050] In some specific implementations, the core of the generalized anti-SAT locking state machine is two complementary dummy logic trees, denoted as follows: Trees and Trees. Each logic tree is designed with a depth of 8 to 12 levels, and each tree has more than 128 nodes. Two trees will necessarily have opposite outputs when the correct activation key is input (e.g., ...). In this implementation, the two logic trees are constructed as strictly complementary Boolean functions at the netlist level; a specific correct key vector can be used as an enabling condition to activate their complementary evaluation paths, thereby maintaining absolutely complementary outputs under any data input.
[0051] The complementary outputs of this pair are converged through an XOR convergence gate to output a constant authorization signal, thereby unlocking the downstream RKC network and allowing the correct PQC data stream to pass through. If there is any error in the input activation key, the complementary relationship between the outputs of the two logic trees will be disrupted, causing the converged authorization signal to fail. This, in turn, causes the RKC network to output corrupted data, resulting in the malfunction of the entire PQC core function.
[0052] S203, Entanglement Indices and Key Mapping for M2-KEM Adaptation
[0053] In some specific implementations, the entanglement index is specifically defined as follows: the algebraic immunity of the key and data input must be greater than 12 to ensure that the number of CNF (conjunctive normal form) clauses explodes exponentially when the Boolean satisfaction solver constructs the joint equation system.
[0054] For post-quantum cryptography algorithms such as M2-KEM, this implementation uses a 256-bit logical lock key. The mapping rule for this key is as follows: the first 128 bits are mapped to a Physically Disguised Substitution Key Control Array (RKC) spoofing and substitution network via a random hash function; the last 128 bits are directly hardwired one-to-one to the control nodes of the two spoofing logic trees within the G-Anti-SAT state machine. This segmented mapping method binds the entire locking mechanism to the key depth, ensuring that the key space is protected as a whole, preventing attackers from splitting the RKC and G-Anti-SAT parts.
[0055] Through the above design, the generalized anti-SAT lock-in state machine and the physical spoofing replacement key control array together form a protection layer that is difficult to crack both mathematically and physically, blocking hardware IP theft through key derivation from a logical level.
[0056] S3. Introduce a cross-level error-state side-channel equivalent mechanism for immune LEDA:
[0057] This specific implementation involves constructing the LEDA-resistant side-channel equivalent mapper. This mapper is connected to a physical masquerading substitution key control array and a generalized anti-SAT lockout state machine. Its core function is that when the device receives an incorrect activation key, it does not simply output an error or lockout, but instead smoothly maps subsequent cryptographic operations to a pre-designed pseudo-operational algebra space with equal nonlinear depth and power confusion characteristics. This counteracts LEDA and LEDFA attacks and prevents side-channel information leakage.
[0058] To address the algebraic degradation vulnerability caused by erroneous keys, this implementation imposes strict algebraic homomorphism constraints on the erroneous output space of RKC during the synthesis phase. Specifically, for the target PQC algorithm (such as M2-KEM based on Module-LWE), in its actual computational loop... For variables in the ring (e.g., the true modulus) Dimension When an incorrect key is input, the LEDA-resistant side-channel equivalent mapper forces it to be mapped to a dynamically generated pseudo-polynomial ring space. middle.
[0059] The pseudo-modulus q' is dynamically determined by the hash value of the current erroneous key. The mapping follows an operational mechanism: ; This represents the modulo operation. This represents the actual, functionally correct arithmetic operations performed by the post-quantum cryptography (PQC) core hardware when the correct activation key is input; This represents the actual computation result performed by the PQC core hardware when an incorrect activation key is input. Due to the change in modulus, the output result is devastating to the normal decryption function (resulting in function lockout). However, the addition and multiplication logic units, data paths, and pipeline activation rates called by the underlying hardware are completely consistent with the operations in the actual computation loop under the correct key, thus avoiding the unique side-channel characteristics caused by the lack of nonlinearity in the computation path.
[0060] In some specific implementations, to achieve statistical indistinguishability between the error state and the real state in terms of side-channel information such as power consumption and electromagnetic radiation, this implementation hardwires the aforementioned error state data stream to the clock and blinding network built into the PQC coprocessor at the hardware level. The specific parameters are as follows:
[0061] Spread spectrum multiphase interleaved clock: employs 4-way phase difference The clock interleaving network is superimposed with a spread spectrum clock (SSCG) with a center frequency of 500MHz and a width of ±5%.
[0062] Addition-multiplication global hybrid blinding network: performs hybrid blinding processing on data, including arithmetic blinding. and Boolean blinding .
[0063] Physical white noise injection: A thermal noise source is provided by a 32-stage ring oscillator (RO) array embedded in the chip, which is injected into the power rail and ground network, with the noise amplitude controlled at 10mV~15mV.
[0064] By entangled this cryptographic blinding with physical noise, the LEDA-resistant side-channel equivalent mapper of this embodiment, combined with the blinding and physical noise network, forcibly smooths out the Hamming weight statistical variance offset between the real key state and the erroneous pseudo-ring state operations.
[0065] After processing by the aforementioned anti-LEDA side-channel equivalent mapper, its security performance is guaranteed by the following quantitative indicators: In the test vector leakage assessment (TVLA) of the side-channel waveforms (power consumption or electromagnetic interference), the T-test statistic |t| between the correct and incorrect key states is strictly less than the security threshold of 4.5; at the same time, the Hamming weight variance offset between the two is smoothed to less than 0.1%. This ensures that the probability density distribution of dynamic power consumption and electromagnetic leakage remains absolutely statistically equivalent to that under normal operation in the incorrect unlock state, thus cutting off the convergence path of mutual information analysis (MIA) and LEDA attacks from the information theory limit.
[0066] S4. Implant a nanosecond-level local cross-shuffling network to achieve nanosecond-level local cross-shuffling without power consumption mutation.
[0067] During the operation of the quantum cryptography hardware accelerator chip after deploying the PQC logic lock device described in this embodiment, the global DPR mechanism is abandoned, and an extremely low-power local crossbar network (nanosecond-level local crossbar shuffling network) is implanted inside the PQC core operator. The nanosecond-level local crossbar shuffling network is controlled by a true random number generator (TRNG) isolated inside the chip, which can perform random fine-grained shuffling of the underlying mask transformation network and cryptographic state machine connection within a single physical clock cycle (nanosecond level). This operation eliminates the electromagnetic radiation mutation during reconfiguration while strictly maintaining the constant-time characteristics of the cryptographic algorithm, forming a stealthy hardware moving target resistant to physical detection.
[0068] Specifically, the nanosecond-level local cross-shuffling network is embedded between key pipeline nodes of the post-quantum cryptography (PQC) processor. Its core is a 16×16 non-blocking Benes cross-switch matrix. This matrix is specifically embedded between the register file data read port of the PQC core operator and the input port of the number-theoretic transform (NTT) or Keccak algorithm arithmetic logic unit (ALU). The minimum granularity of data reconstruction is set to 16-bit words. The nanosecond-level local cross-shuffling network consists of multiple high-speed multiplexers and the aforementioned cross-switch, used to dynamically reconstruct the physical connections between selected data paths or operands.
[0069] In some specific implementations, the shuffling operation of the nanosecond-level local cross-shuffling network is completed within a single physical clock cycle. With a system clock frequency of 500MHz, its reconfiguration latency is only 2 nanoseconds (ns). The shuffling trigger condition is programmable, for example, set to the pipeline bubble cycle of each NTT computation stage or after processing a polynomial coefficient block. The network is controlled by an internally independent and physically isolated true random number generator (TRNG). This TRNG employs a metastability-based design, has a 32-bit output width, and generates random numbers at a rate of 500Mbps. To prevent the TRNG itself from becoming a side-channel attack point, it is physically isolated from the cross-switch control interface using dual-track precharge logic (WDDL).
[0070] To strictly maintain the constant-time characteristics of the cryptographic algorithm, regardless of how the cross-switch matrix reconstructs the data path, the total number of logic gates (Depth) of the entire path from the register file to the ALU is kept constant by filling dummy logic, thereby ensuring that the number of clock cycles required to complete each calculation is absolutely consistent and that no timing side channels are generated.
[0071] This local reconfiguration mechanism fundamentally abandons global dynamic local reconfiguration (DPR), thereby eliminating the huge power spikes caused by global configuration port operations. By design, the transient power fluctuations caused by the cross-switch matrix reconfiguration are limited to less than 3% of the total dynamic power consumption. This fluctuation is far lower than the 400% power consumption surge that traditional global DPR might produce, and can be effectively masked by the chip's physical white noise. The network exhibits an extremely high mutation frequency, achieving tens of thousands of dynamic morphological changes per million instructions (MIPS), thus forming a stealthy hardware moving target resistant to physical detection.
[0072] This embodiment also constructs a trusted configuration handshake interface for connecting to an external Physically Unclonable Function (PUF) or hardware root of trust to securely receive, verify, and inject the chip's unique activation key. This trusted configuration handshake interface connects to the external PUF or hardware root of trust via a standard on-chip bus interface (e.g., using APB or AXI protocols) or an asynchronous request / response (Req / Ack) mechanism. The communication process employs a challenge-response secure handshake protocol to securely obtain the chip's unique activation key from the external root of trust. Upon receiving the 256-bit raw key data from the PUF, the lightweight verification module built into the trusted configuration handshake interface (such as a Cyclic Redundancy Check (CRC) or Error Correction Code (ECC) module) first verifies the integrity of the key data to prevent fault injection or other tampering during transmission. To further prevent transient power leakage that can be detected by side-channel detection during key transmission and injection across clock domains, the entire data path of the interface employs a leakage-proof logic design. Specifically, this implementation eliminates the significant power consumption characteristics caused by data jumps by employing dual-track pre-charge logic or inserting dedicated physical isolation units on the critical path.
[0073] Once the key integrity verification passes, the trusted configuration handshake interface control logic securely injects the verified key. The key is distributed and latched into a set of dedicated key registers designed with radiation hardening or anti-probe masking, completing the final secure configuration and activation of the entire logic lock device.
[0074] This embodiment provides a complete implementation based on a 28nm process node and the M2-KEM algorithm. System-level simulation and verification of the logic lock device and method of this invention were performed, and the results are as follows:
[0075] 1. Implementation Example Setup and Physical Implementation
[0076] This embodiment was implemented using a standard Electronic Design Automation (EDA) toolchain within the TSMC 28nm HPC+ process design kit (PDK) environment. During the physical design phase, the masquerading gate cells of the Physically Masqueraded Replaceable Key Control Array (RKC) are discretely distributed throughout the entire post-quantum cryptography (PQC) macrocell netlist, occupying approximately 5% of the total area. The True Random Number Generator (TRNG) module is placed at the chip corners in the layout and physically isolated via an independent Guard Ring to suppress noise coupling. The Generalized Anti-SAT (G-Anti-SAT) locked state machine is positioned adjacent to the chip's key storage registers to optimize timing and signal integrity.
[0077] 2. Performance overhead assessment results
[0078] Post-layout simulation data based on standard EDA toolchains such as Synopsys Design Compiler and IC Compiler show that after introducing this logic lock system, the overall silicon area overhead is strictly controlled within 12%; dynamic power consumption simulation by PrimeTimePX shows that the power consumption overhead is <8%, and the throughput of the PQC core remains at 0 loss, which fully meets the timing convergence requirements of high-performance accelerators.
[0079] 3. Safety simulation verification results
[0080] The device's anti-hacking capabilities and side-channel resilience were theoretically verified through software simulation.
[0081] Resistance to Boolean Satisfactionability (SAT) attacks: The hardware netlist containing the protection mechanism of this invention is exported after synthesis, and model verification is performed on a server equipped with a high-performance SAT solver (such as CaDiCaL). For the solution process of the 256-bit activation key, the equivalent runtime exceeds 10... 10 The process terminated after a few seconds due to a memory overflow, demonstrating, in terms of mathematical computational complexity, that the device possesses exponential immunity to attacks on SAT and its approximate algorithm (AppSAT).
[0082] Side-channel resistance analysis capability: The signal toggle rate of the gate-level netlist is extracted and combined with the current model from the technology library to generate a simulated power consumption trajectory. For example... Figure 2 As shown, in 10 7In the test vector leakage assessment (TVLA) of the side-channel waveforms, the T-test statistic |t| of the embodiments of the present invention is strictly constrained below the security threshold of 4.5, while the traditional technical solution shows significant peak leakage. This intuitively proves that the present invention effectively blinds side-channel analysis in the unauthorized state. The results show that the envelopes of the obtained power consumption waveforms have extremely high statistical similarity under both incorrect and correct input keys, with a Pearson correlation coefficient r > 0.999. This result confirms that, in the unauthorized state, the present invention effectively blinds side-channel analysis that relies on missing nonlinear computational paths, such as zero-fault algebra attacks (LEDA), through mechanisms such as "error-state side-channel equivalence".
[0083] Simulation verification in this embodiment shows that the logic lock device implemented by the present invention under the 28nm process can effectively ensure the functional security of PQC hardware IP while introducing controllable limited area and power consumption overhead, and exhibits extremely high anti-attack resilience at both the mathematical and side-channel levels.
[0084] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0085] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of protection of the present invention.
Claims
1. A PQC logic lock method based on physical camouflage and cross-shuffling, characterized in that, Includes the following steps S1. Construct a physical spoofing and substitution network to achieve key control in post-quantum cryptography hardware; S2. Construct a generalized anti-SAT locking state machine and cascade it with the physical camouflage replacement network to provide a mathematical barrier against Boolean satisfiability attacks; S3. Execute the error-state side-channel equivalence mechanism to make the power consumption characteristics of the circuit equivalent to those of the normal state when an incorrect key is input. S4. Activate the local cross-shuffle network to dynamically and randomly reorganize the data path during operation, and perform random fine-grained shuffling of the underlying data path within a single physical clock cycle.
2. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 1, characterized in that, Step S1 includes: constructing a replacement key control circuit network using physical camouflage standard units, and distributively embedding multiple physical camouflage standard units into the netlist of the post-quantum cryptographic arithmetic logic core to form a physical camouflage replacement key control array; wherein, the physical camouflage standard units have a consistent appearance at the geometric layout level composed of polysilicon wiring and metal wiring, and the difference in their actual logic functions is determined by the difference in ion doping concentration in the active region of the silicon substrate.
3. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 2, characterized in that, The physical camouflage standard unit, when imaged with a scanning electron microscope, has a two-dimensional cross-correlation coefficient greater than 0.99 with the real standard unit; The doping concentration of its functional transistor channel is 1×10⁻⁶. 17 Up to 5×10 17 cm -3 The channel doping concentration of the dummy transistor was modulated to be greater than 5 × 10⁻⁶. 18 cm -3 Or perform inversion doping.
4. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 1, characterized in that, In step S2, the generalized anti-SAT lock-in state machine is internally configured with a complementary masquerade logic tree to construct a high degree of entanglement constraint between the activation key and the data input; the complementary masquerade logic tree outputs an inverse signal when the correct activation key is input, and outputs a constant authorization signal after XOR convergence to unlock the downstream physical masquerade replacement network.
5. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 1, characterized in that, Step S3 includes: when an erroneous activation key is received, the subsequent operations are smoothly mapped to the pseudo-polynomial ring space through the anti-LEDA side-channel equivalent mapper, and the mapped erroneous state data stream is bound to the underlying clock interleaving network and the hybrid blinding network to smooth out the Hamming weight statistical variance offset between the real key state and the erroneous pseudo-ring state operations.
6. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 5, characterized in that, The pseudomodulus q' of the pseudo-polynomial ring space is dynamically determined by the hash value of the current erroneous activation key; The clock interleaving network consists of four spread-spectrum multiphase interleaved clocks with a 90° phase difference; the hybrid blinding network includes arithmetic blinding and Boolean blinding.
7. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 1, characterized in that, Step S4 includes: activating a nanosecond-level local cross-shuffling network embedded between critical pipeline nodes of the processor; the network is controlled by a true random number generator inside the chip to perform random fine-grained shuffling of the underlying data path within a single physical clock cycle.
8. The PQC logic lock method based on physical camouflage and cross-shuffling according to claim 7, characterized in that, The core of the nanosecond-level local cross-shuffle network is a non-blocking Benes cross-switch matrix, which is embedded between the register file data read port and the arithmetic logic unit input port. The minimum granularity of data reconstruction is 16-bit words. The total number of path logic gates in the shuffle operation is kept constant by filling dummy logic.
9. A PQC logic lock device based on physical camouflage and cross-shuffling, used to implement the PQC logic lock method based on physical camouflage and cross-shuffling as described in any one of claims 1 to 8, characterized in that, include: A physical camouflage replacement key control array is distributed in a netlist within the core of post-quantum cryptographic arithmetic logic; A generalized anti-SAT locking state machine is cascaded with the physical spoofing replacement key control array; An LEDA-resistant side-channel equivalent mapper is connected to the physical masquerading replacement key control array and the generalized SAT-resistant locking state machine. A nanosecond-level local cross-shuffling network is embedded between key pipeline nodes in a post-quantum cryptography processor; The trusted configuration handshake interface is used to securely obtain, verify, and inject the activation key into the chip from an external security module.
10. A PQC logic lock device based on physical camouflage and cross-shuffling according to claim 9, characterized in that, The physical camouflage replacement key control array consists of multiple physical camouflage standard units with consistent appearance at the geometric layout level; the nanosecond-level local cross-shuffling network includes a non-blocking Benes cross-switch matrix and is connected to a true random number generator inside the chip; the data path of the trusted configuration handshake interface adopts a leakage-proof design.