IC Timing-Based Secret Storage Against Reverse Engineering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing countermeasures against reverse engineering of integrated circuits are large, expensive, and noticeable, making them vulnerable to attackers who can clone and sell similar circuits, as they rely on physical properties and complex logic cells that are difficult to stabilize and camouflage effectively.

Innovation Solution

The method involves creating a secret bit by manipulating the timing relationships between clocked memory elements, such as latches or flip-flops, where the logic level change affects the output at specific clock edges, making the secret bit hidden in the timing rather than physical properties, and using existing memory elements to reduce area and visibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional secret protection cells (tie cells, NVM, camouflage cells) are used to protect against reverse engineering, then security protection is improved, but chip area increases and cost increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidchip area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent changes the fundamental parameter of secret storage from physical state (voltage levels in NVM cells, resistance states in tie cells) to temporal characteristics (timing relationships between clock edges). By encoding secrets in the timing domain rather than the physical domain, the patent eliminates the need for large dedicated secret storage cells, thereby reducing chip area while maintaining security protection.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional secret protection cells are used to protect against reverse engineering, then security protection is improved, but the cells become noticeable and attract attacker attention

Engineering Contradiction:
Improvesecurity protectionVSAvoiddetectability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent makes the secret protection mechanism homogeneous with the rest of the digital circuit logic by implementing it using standard clocked memory elements and logic gates. The secret is embedded in the timing relationships of ordinary digital signals rather than in specially designed protection cells, making it indistinguishable from normal circuit operation and thus difficult for attackers to detect and target.

Inventive Principle:
Principle #33Homogeneity

3Reliability

If traditional secret protection cells are used, then security protection is improved, but stability cannot be assured by automated design flows and relies on analog simulations

Engineering Contradiction:
Improvesecurity protectionVSAvoiddesign complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the analog/physical-based secret storage mechanism (relying on transistor models and analog simulations) with a digital/timing-based mechanism. The secret is encoded in the temporal relationships between digital clock edges, which can be precisely controlled and verified through automated digital design flows and timing analysis tools, eliminating the need for complex analog simulations and manual stability verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12182316B2Integrated circuit protection against reverse engineering
Publication Date: 2024.12.31 INFINEON TECHNOLOGIES AG
  • US12182316B2 patent drawing
  • US12182316B2 patent drawing
  • US12182316B2 patent drawing

AI summary

A method for protecting an integrated circuit against reverse engineering including predefining a secret bit, forming a first clocked memory element having a first data input, a first data output and a first clock input in the integrated circuit, forming a second clocked memory element having a second data input, a second data output and a second clock input in the integrated circuit, forming a logic path in the integrated circuit and coupling the first data output to the second data input via the logic path and forming a clock signal line in the integrated circuit and coupling the first clock input to the second clock input via the clock signal line. The logic path and the clock signal line are formed such that their delays are such that, depending on a value of the secret bit, a logic level change of the first clocked memory element with a clock edge of a clock signal on the clock signal line affects a logic level output by the second clocked memory element with the same clock edge of the clock signal, or a logic level change of the first clocked memory element with a clock edge of a clock signal on the clock signal line affects a logic level output by second clocked memory element with any clock edge coming after the next clock edge of the clock signal.