Hardware Backdoor Prevention via Runtime Input Scrambling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hardware backdoors, especially those introduced by malicious insiders, are difficult to detect and can pose significant security threats to critical systems as they can remain dormant during testing and be triggered later, exploiting the complexity of hardware systems and the large number of engineers involved in their design.
Innovation Solution
The solution involves scrambling inputs to hardware units at runtime, making it infeasible for malicious components to perform malicious actions by using techniques such as power resets, data obfuscation, and sequence breaking, thereby preventing the activation of digital, design-level hardware backdoors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If hardware systems use third-party IP components and increase design complexity, then functionality and performance are improved, but security vulnerability to backdoors increases
Solution Approach 1:
The patent applies preliminary action by implementing validation tests during the fabrication phase to detect backdoors before the hardware is deployed. The system performs formal verification and statistical analysis on the netlist and fabricated circuit to identify malicious modifications in advance, preventing them from causing harm in the operational system.
Solution Approach 2:
The patent introduces an intermediary validation system that acts as a mediator between the third-party IP components and the final hardware system. This validation layer analyzes the netlist, detects suspicious patterns, and verifies the fabricated circuit before integration, thereby isolating the system from potential backdoors without preventing the use of third-party components.
2Measurement precision
If formal verification is performed on complete hardware designs, then detection accuracy of backdoors is improved, but computational time and resources increase exponentially
Solution Approach 1:
The patent segments the verification process into multiple phases: netlist validation, fabrication verification, and operational monitoring. Each phase focuses on specific aspects of backdoor detection using appropriate methods (formal verification on netlist, statistical analysis on fabricated circuit), thereby avoiding the need to perform complete formal verification on the entire design at once.
Solution Approach 2:
The patent applies partial verification by focusing formal verification efforts on critical sections and the netlist level, where backdoors are most likely to be inserted. Statistical sampling and anomaly detection are used on the fabricated circuit to cover areas where formal verification would be too costly, achieving sufficient detection accuracy without exhaustive verification of every component.
3Reliability
If validation testing duration is extended to detect dormant backdoors, then backdoor detection capability is improved, but productivity and time to market deteriorate
Solution Approach 1:
The patent performs backdoor detection activities during the fabrication phase before the hardware is deployed to customers. By validating the netlist and analyzing the fabricated circuit early in the development process, the system detects dormant backdoors before they can cause harm, eliminating the need for extended testing during operational use.
Solution Approach 2:
The patent replaces traditional extended operational testing with formal verification methods and statistical analysis that can detect backdoors more quickly. Instead of running the hardware for extended periods to trigger dormant backdoors, the system uses mathematical proofs and anomaly detection algorithms to identify suspicious patterns in the circuit design and fabrication results.
Data Source
AI summary
Methods for preventing activation of hardware backdoors installed in a digital circuit, the digital circuit comprising one or more hardware units to be protected. A timer is repeatedly initiated for a period less than a validation epoch, and the hardware units are reset upon expiration of the timer to prevent activation of a time-based backdoor. Data being sent to the hardware unit is encrypted in an encryption element to render it unrecognizable to a single-shot cheat code hardware backdoor present in the hardware unit. The instructions being sent to the hardware unit are reordered randomly or pseudo-randomly, with determined sequential restraints, using an reordering element, to render an activation instruction sequence embedded in the instructions unrecognizable to a sequence cheat code hardware backdoor present in the hardware unit.


