Dynamic Scan Obfuscation for IC Protection Against SAT Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The outsourcing of integrated circuit (IC) fabrication and testing to untrusted third parties poses a significant risk of intellectual property theft, counterfeiting, and hardware Trojan insertion, as existing logic locking techniques are vulnerable to powerful SAT-based oracle-guided attacks.
Innovation Solution
The implementation of a dynamic scan obfuscation scheme that includes a reconfigurable block generating a dynamic key, an authentication block creating an authentication signature, an encryptor encrypting test patterns, and a comparator ensuring only authorized access, using multiplexors to select and output embedded signatures for authentication, thereby protecting against oracle-guided and oracle-free attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If logic locking techniques are used to protect IC design, then intellectual property protection is improved, but vulnerability to SAT-based oracle-guided attacks increases
Solution Approach 1:
The patent applies dynamics by transforming static logic locking into dynamic scan chain obfuscation. The scan chain configuration changes based on authentication results, with multiplexors dynamically selecting between authenticated and unauthenticated paths. This dynamic reconfiguration prevents attackers from using static SAT-based analysis to extract keys, as the circuit behavior changes based on authentication state.
Solution Approach 2:
The patent introduces an authentication mechanism as an intermediary between the scan chain and the logic locking system. The authentication block verifies credentials before allowing access to the scan chain, acting as a mediator that prevents direct attacker access to the locking logic. This intermediary layer blocks the attack path while maintaining legitimate access.
2Productivity
If scan chains are used for testing, then testing capability is improved, but access for malicious entities increases
Solution Approach 1:
The patent applies local quality by differentiating access rights to different portions of the scan chain. The authentication mechanism divides the scan chain into authenticated and unauthenticated segments, allowing full testing capability for authorized users while blocking malicious access. Multiplexors locally control access to specific scan chain segments based on authentication results, providing selective protection without compromising overall testing functionality.
3Object-affected harmful factors
If dynamic key generation is implemented, then security against attacks is improved, but device complexity increases
Solution Approach 1:
The patent segments the protection system into distinct functional blocks: authentication block, multiplexor block, and scan chain block. This segmentation allows each component to perform a specific function independently, making the overall system more manageable despite increased complexity. The authentication block handles key generation and verification, while multiplexors handle dynamic routing, separating concerns and enabling modular implementation that reduces design complexity.
Data Source
AI summary
An integrated circuit (IC) protection circuit can include a reconfigurable block that receives a seed value from a tamper-proof memory and generates a dynamic key; an authentication block that receives the dynamic key from the reconfigurable block and taint bits from a scan chain to generate an authentication signature; and an encryptor that encrypts a test pattern response on the scan chain if a mismatch is found between the authentication signature and a test pattern embedded signature.


