IC Logic Locking With Barrier FSM Against Oracle-Guided Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The outsourcing of integrated circuit (IC) fabrication and testing to untrusted third parties poses significant risks of intellectual property theft, counterfeiting, and hardware Trojan insertion due to exposure of IC designs, necessitating robust protection mechanisms against removal and oracle-guided attacks.
Innovation Solution
A built-in-self-testing (BIST) framework with logic locking techniques, including a barrier finite state machine and signal scrambler, coupled with a dynamic authentication circuit using reconfigurable linear feedback shift registers, is employed to protect IC designs. This framework ensures that only authorized users can unlock the IC functionality by applying the correct key sequence, thereby preventing unauthorized access and attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If logic locking is implemented to protect IC design integrity, then security against design theft is improved, but device complexity increases due to additional locking logic and key mechanisms
Solution Approach 1:
The patent embeds the barrier FSM and authentication logic within the existing BIST framework, nesting security functions inside the test infrastructure. The barrier FSM is integrated into the BIST controller, and authentication logic is combined with existing test patterns and response evaluation, allowing security mechanisms to reuse existing structural elements rather than adding completely separate systems
Solution Approach 2:
The BIST framework is made multi-functional by combining its original self-test functionality with new security functions. The same BIST infrastructure that generates test patterns and evaluates responses is also used to enforce authentication keys and prevent design theft, allowing a single system to serve both testing and security purposes
2Reliability
If a barrier FSM with key sequence input is added to unlock controller functionality, then protection against unauthorized access is improved, but manufacturing complexity increases
Solution Approach 1:
The barrier FSM is nested within the existing BIST controller structure, utilizing the same control logic and state machine infrastructure already present in the design. This integration allows the security mechanism to be implemented using existing manufacturing processes and toolchains without requiring separate fabrication steps or additional manufacturing complexity
3Reliability
If signal scrambler with multiple initialization inputs is implemented, then resistance to oracle-guided attacks is improved, but device complexity increases
Solution Approach 1:
The signal scrambler is integrated into the existing BIST response evaluation path, nesting the scrambling function within the response compaction and evaluation logic. The scrambler uses the same initialization inputs already present in the BIST framework (such as test pattern seeds and control signals), avoiding the need for separate initialization mechanisms and reducing overall system complexity
Solution Approach 2:
The BIST response evaluation infrastructure is made multi-functional by combining its original fault detection capability with new authentication capability. The same response compaction logic and evaluation mechanisms that detect manufacturing defects are also used to verify authentication keys and detect oracle-guided attacks, eliminating the need for separate authentication hardware
4Reliability
If dynamic authentication circuit with reconfigurable LFSRs is added, then security against design theft is improved, but ease of manufacture deteriorates due to reconfigurable logic
Solution Approach 1:
The reconfigurable LFSRs are nested within the existing BIST pattern generation and response evaluation infrastructure. The reconfiguration capability is triggered by authentication keys that are already part of the BIST control signals, allowing the same physical hardware to dynamically change its behavior based on authentication state without requiring separate reconfiguration mechanisms or additional manufacturing steps
Data Source
AI summary
An integrated circuit (IC) protection circuit for an IC includes a controller with a barrier finite state machine (FSM) having a key sequence input that unlocks the controller; and a signal scrambler coupled to receive at least two initialization inputs and a primary input path and output a signal to the IC, wherein at least one initialization input of the at least two initialization inputs is based on an output of the barrier FSM. The IC protection circuit can further include a dynamic authentication circuit coupled to receive the output of the barrier finite state machine and output a signal to the signal scrambler for one of the at least two initialization inputs. The dynamic authentication circuit can be formed of a dynamic sequence generator and a dynamic sequence authenticator, each formed of one or more reconfigurable linear feedback shift registers, and a comparator.


