Dynamic Scan Obfuscation for IC Protection Against SAT Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The outsourcing of integrated circuit (IC) fabrication and testing to untrusted third parties poses a significant risk of intellectual property theft, counterfeiting, and hardware Trojan insertion, as existing logic locking techniques are vulnerable to powerful SAT-based oracle-guided attacks.

Innovation Solution

The implementation of a dynamic scan obfuscation scheme that includes a reconfigurable block generating a dynamic key, an authentication block creating an authentication signature, an encryptor encrypting test patterns, and a comparator ensuring only authorized access, using multiplexors to select and output embedded signatures for authentication, thereby protecting against oracle-guided and oracle-free attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If logic locking techniques are used to protect IC design, then intellectual property protection is improved, but vulnerability to SAT-based oracle-guided attacks increases

Engineering Contradiction:
Improveintellectual property protectionVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transforming static logic locking into dynamic scan chain obfuscation. The scan chain configuration changes based on authentication results, with multiplexors dynamically selecting between authenticated and unauthenticated paths. This dynamic reconfiguration prevents attackers from using static SAT-based analysis to extract keys, as the circuit behavior changes based on authentication state.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication mechanism as an intermediary between the scan chain and the logic locking system. The authentication block verifies credentials before allowing access to the scan chain, acting as a mediator that prevents direct attacker access to the locking logic. This intermediary layer blocks the attack path while maintaining legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If scan chains are used for testing, then testing capability is improved, but access for malicious entities increases

Engineering Contradiction:
Improvetesting capabilityVSAvoidaccess for malicious entities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by differentiating access rights to different portions of the scan chain. The authentication mechanism divides the scan chain into authenticated and unauthenticated segments, allowing full testing capability for authorized users while blocking malicious access. Multiplexors locally control access to specific scan chain segments based on authentication results, providing selective protection without compromising overall testing functionality.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If dynamic key generation is implemented, then security against attacks is improved, but device complexity increases

Engineering Contradiction:
Improveresistance to attacksVSAvoidcircuit complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the protection system into distinct functional blocks: authentication block, multiplexor block, and scan chain block. This segmentation allows each component to perform a specific function independently, making the overall system more manageable despite increased complexity. The authentication block handles key generation and verification, while multiplexors handle dynamic routing, separating concerns and enabling modular implementation that reduces design complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12072379B2Dynamic scan obfuscation for integrated circuit protections
Publication Date: 2024.08.27 DUKE UNIV
  • US12072379B2 patent drawing
  • US12072379B2 patent drawing
  • US12072379B2 patent drawing

AI summary

An integrated circuit (IC) protection circuit can include a reconfigurable block that receives a seed value from a tamper-proof memory and generates a dynamic key; an authentication block that receives the dynamic key from the reconfigurable block and taint bits from a scan chain to generate an authentication signature; and an encryptor that encrypts a test pattern response on the scan chain if a mismatch is found between the authentication signature and a test pattern embedded signature.