IC Logic Locking With Barrier FSM Against Oracle-Guided Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The outsourcing of integrated circuit (IC) fabrication and testing to untrusted third parties poses significant risks of intellectual property theft, counterfeiting, and hardware Trojan insertion due to exposure of IC designs, necessitating robust protection mechanisms against removal and oracle-guided attacks.

Innovation Solution

A built-in-self-testing (BIST) framework with logic locking techniques, including a barrier finite state machine and signal scrambler, coupled with a dynamic authentication circuit using reconfigurable linear feedback shift registers, is employed to protect IC designs. This framework ensures that only authorized users can unlock the IC functionality by applying the correct key sequence, thereby preventing unauthorized access and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If logic locking is implemented to protect IC design integrity, then security against design theft is improved, but device complexity increases due to additional locking logic and key mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds the barrier FSM and authentication logic within the existing BIST framework, nesting security functions inside the test infrastructure. The barrier FSM is integrated into the BIST controller, and authentication logic is combined with existing test patterns and response evaluation, allowing security mechanisms to reuse existing structural elements rather than adding completely separate systems

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The BIST framework is made multi-functional by combining its original self-test functionality with new security functions. The same BIST infrastructure that generates test patterns and evaluates responses is also used to enforce authentication keys and prevent design theft, allowing a single system to serve both testing and security purposes

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a barrier FSM with key sequence input is added to unlock controller functionality, then protection against unauthorized access is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The barrier FSM is nested within the existing BIST controller structure, utilizing the same control logic and state machine infrastructure already present in the design. This integration allows the security mechanism to be implemented using existing manufacturing processes and toolchains without requiring separate fabrication steps or additional manufacturing complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If signal scrambler with multiple initialization inputs is implemented, then resistance to oracle-guided attacks is improved, but device complexity increases

Engineering Contradiction:
Improveresistance to oracle-guided attacksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The signal scrambler is integrated into the existing BIST response evaluation path, nesting the scrambling function within the response compaction and evaluation logic. The scrambler uses the same initialization inputs already present in the BIST framework (such as test pattern seeds and control signals), avoiding the need for separate initialization mechanisms and reducing overall system complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The BIST response evaluation infrastructure is made multi-functional by combining its original fault detection capability with new authentication capability. The same response compaction logic and evaluation mechanisms that detect manufacturing defects are also used to verify authentication keys and detect oracle-guided attacks, eliminating the need for separate authentication hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If dynamic authentication circuit with reconfigurable LFSRs is added, then security against design theft is improved, but ease of manufacture deteriorates due to reconfigurable logic

Engineering Contradiction:
Improvesecurity against design theftVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The reconfigurable LFSRs are nested within the existing BIST pattern generation and response evaluation infrastructure. The reconfiguration capability is triggered by authentication keys that are already part of the BIST control signals, allowing the same physical hardware to dynamically change its behavior based on authentication state without requiring separate reconfiguration mechanisms or additional manufacturing steps

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12039091B2Integrated circuit protections against removal and oracle-guided attacks
Publication Date: 2024.07.16 DUKE UNIV
  • US12039091B2 patent drawing
  • US12039091B2 patent drawing
  • US12039091B2 patent drawing

AI summary

An integrated circuit (IC) protection circuit for an IC includes a controller with a barrier finite state machine (FSM) having a key sequence input that unlocks the controller; and a signal scrambler coupled to receive at least two initialization inputs and a primary input path and output a signal to the IC, wherein at least one initialization input of the at least two initialization inputs is based on an output of the barrier FSM. The IC protection circuit can further include a dynamic authentication circuit coupled to receive the output of the barrier finite state machine and output a signal to the signal scrambler for one of the at least two initialization inputs. The dynamic authentication circuit can be formed of a dynamic sequence generator and a dynamic sequence authenticator, each formed of one or more reconfigurable linear feedback shift registers, and a comparator.