IC Timing-Based Secret Storage Against Reverse Engineering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing countermeasures against reverse engineering of integrated circuits are large, expensive, and noticeable, making them vulnerable to attackers who can clone and sell similar circuits, as they rely on physical properties and complex logic cells that are difficult to stabilize and camouflage effectively.
Innovation Solution
The method involves creating a secret bit by manipulating the timing relationships between clocked memory elements, such as latches or flip-flops, where the logic level change affects the output at specific clock edges, making the secret bit hidden in the timing rather than physical properties, and using existing memory elements to reduce area and visibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secret protection cells (tie cells, NVM, camouflage cells) are used to protect against reverse engineering, then security protection is improved, but chip area increases and cost increases
Solution Approach 1:
The patent changes the fundamental parameter of secret storage from physical state (voltage levels in NVM cells, resistance states in tie cells) to temporal characteristics (timing relationships between clock edges). By encoding secrets in the timing domain rather than the physical domain, the patent eliminates the need for large dedicated secret storage cells, thereby reducing chip area while maintaining security protection.
2Reliability
If traditional secret protection cells are used to protect against reverse engineering, then security protection is improved, but the cells become noticeable and attract attacker attention
Solution Approach 1:
The patent makes the secret protection mechanism homogeneous with the rest of the digital circuit logic by implementing it using standard clocked memory elements and logic gates. The secret is embedded in the timing relationships of ordinary digital signals rather than in specially designed protection cells, making it indistinguishable from normal circuit operation and thus difficult for attackers to detect and target.
3Reliability
If traditional secret protection cells are used, then security protection is improved, but stability cannot be assured by automated design flows and relies on analog simulations
Solution Approach 1:
The patent replaces the analog/physical-based secret storage mechanism (relying on transistor models and analog simulations) with a digital/timing-based mechanism. The secret is encoded in the temporal relationships between digital clock edges, which can be precisely controlled and verified through automated digital design flows and timing analysis tools, eliminating the need for complex analog simulations and manual stability verification.
Data Source
AI summary
A method for protecting an integrated circuit against reverse engineering including predefining a secret bit, forming a first clocked memory element having a first data input, a first data output and a first clock input in the integrated circuit, forming a second clocked memory element having a second data input, a second data output and a second clock input in the integrated circuit, forming a logic path in the integrated circuit and coupling the first data output to the second data input via the logic path and forming a clock signal line in the integrated circuit and coupling the first clock input to the second clock input via the clock signal line. The logic path and the clock signal line are formed such that their delays are such that, depending on a value of the secret bit, a logic level change of the first clocked memory element with a clock edge of a clock signal on the clock signal line affects a logic level output by the second clocked memory element with the same clock edge of the clock signal, or a logic level change of the first clocked memory element with a clock edge of a clock signal on the clock signal line affects a logic level output by second clocked memory element with any clock edge coming after the next clock edge of the clock signal.


