Integrated Circuit Design Lockout With Limited Key Attempts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional obfuscation techniques for integrated circuit designs are vulnerable to reverse engineering and do not effectively protect against unauthorized duplication and piracy, particularly when subjected to removal attacks, and they incur substantial performance overhead.
Innovation Solution
The DLockout technique integrates a lightweight design lockout module with an input obfuscation module, using comparators to verify the applied key and lock out the design after a predefined number of incorrect attempts, without storing the key within the circuit, thus enhancing security and minimizing overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional obfuscation techniques embed random XOR circuits throughout an IC design, then the design is transformed into an equivalent design with a greater barrier to uncover functional semantics, but the design becomes vulnerable to removal attacks and incurs substantial performance overhead
Solution Approach 1:
The patent extracts the key storage function from the obfuscation circuitry itself and places it in an external secure element. This removes the vulnerability of having the key stored within the IC while maintaining the obfuscation functionality. The XOR circuits remain but the key is now externally managed, preventing removal attacks while reducing internal circuit complexity.
Solution Approach 2:
The patent introduces an external secure element as an intermediary between the obfuscation logic and the key. This mediator holds the key securely outside the IC while still enabling the obfuscation function when needed, thus protecting against removal attacks without requiring complex internal key management circuits.
2Reliability
If conventional obfuscation techniques embed random XOR circuits throughout an IC design, then the design is transformed into an equivalent design with a greater barrier to uncover functional semantics, but substantial performance overhead is incurred
Solution Approach 1:
By extracting key management to an external secure element, the patent reduces the number of internal XOR circuits needed for key management and verification. This extraction eliminates the performance overhead associated with internal key storage and protection mechanisms while maintaining security through the external element.
3Ease of operation
If the key is stored within the circuit for verification, then key verification can be performed, but the design becomes vulnerable to reverse engineering and removal attacks
Solution Approach 1:
The patent extracts the key from the IC circuitry and stores it in an external secure element. This allows key verification to be performed through external authentication mechanisms while eliminating the vulnerability of having the key physically present within the circuit, thus preventing reverse engineering and removal attacks.
Solution Approach 2:
The external secure element acts as an intermediary that performs key verification without the key being stored in the IC. This mediator enables authentication functionality while maintaining security by keeping the key external to the vulnerable circuit environment.
Data Source
AI summary
An exemplary integrated circuit design lockout system comprises an integrated circuit and a key obfuscated circuit embedded with the integrated circuit. The key obfuscated circuit is configured to verify that a user provides a valid key for the integrated circuit before the user is allowed to operate the integrated circuit. The exemplary integrated circuit design lockout system further comprises a lockout circuit embedded with the key obfuscated circuit, wherein the lockout circuit is configured to allow for a threshold number of failed attempts for the user to provide the valid key before the lockout circuit prohibits the user from making any further attempts at providing the valid key for the integrated circuit.


