Defensive Routing for IC Security-Critical Wires
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current post-fabrication detection and pre-fabrication prevention techniques are inadequate in preventing hardware trojan attacks during integrated circuit (IC) fabrication, as they either require a 'golden' reference chip or alter IC layouts to high densities that are not economically feasible.
Innovation Solution
Defensive routing of guard wires around security-critical wires within the IC design, which can be either natural or synthetic, to create obstacles for adversaries attempting to attach rogue wires, thereby preventing hardware trojan insertion during fabrication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If placement-centric pre-fabrication prevention techniques are used to limit open space on IC device layer, then security against hardware trojan insertion is improved, but IC design density cannot be optimized to economically feasible levels
Solution Approach 1:
The patent segments the IC design into two distinct density zones: a first density for non-security-critical wires and a second, higher density for security-critical wires. This segmentation allows each region to be optimized independently - non-critical areas maintain routability at 60-70% density while critical areas achieve near 100% density to prevent trojan insertion, thereby resolving the contradiction between security and economic feasibility.
Solution Approach 2:
The patent applies local quality by implementing different density requirements for different locations within the IC design. Specifically, security-critical wires receive enhanced protection through higher density routing in their vicinity, while non-critical wires maintain standard density. This localized approach ensures security is strengthened where needed without compromising overall IC economic feasibility.
2Measurement precision
If post-fabrication detection techniques are used to detect hardware trojan, then detection capability is improved, but requirement for golden reference chip increases complexity
Solution Approach 1:
The patent implements preliminary action by preventing hardware trojan insertion through pre-fabrication design measures rather than detecting them after fabrication. By establishing high-density routing around security-critical wires before fabrication, the design proactively eliminates the need for post-fabrication detection and golden reference chips, thereby reducing complexity while maintaining detection capability.
3Reliability
If functional testing is used to trigger hardware trojan, then detection without golden reference chip is achieved, but exhaustive testing of complex IC is infeasible
Solution Approach 1:
The patent applies preliminary anti-action by designing the IC layout to prevent hardware trojan insertion in the first place, rather than relying on functional testing to trigger and detect trojans. The high-density routing around security-critical wires creates a protective barrier that makes trojan insertion infeasible, eliminating the need for time-consuming exhaustive functional testing of complex ICs.
Data Source
AI summary
Techniques are disclosed for defensive routing of guard wires for security-critical wires in an integrated circuit (IC). Defensive routing provides a routing-centric and preventive layout-level defense against IC fabrication time attacks against security-critical wires within an IC. An example methodology implementing the techniques includes identifying at least one security-critical wire in an IC design, identifying at least one unblocked surface of the identified at least one security-critical wire, and guarding the identified at least one surface of the identified at least one security-critical wire with a guard wire. In one example, the guard wire may be a natural guard wire. In another example, the guard wire may be a synthetic guard wire.


