Scalable Attack-Resistant Logic Circuit Obfuscation via Partitioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing obfuscation techniques for hardware IP cores are vulnerable to piracy and security attacks due to their deterministic nature, which can be uncovered and bypassed by attackers, and they lack robust graphical alteration, limiting their effectiveness in large-scale designs.
Innovation Solution
The method involves partitioning a circuit design into multiple partitions, applying randomized transformations, and merging them with randomized circuits using multiplexers, while varying the number and size of partitions and randomly selecting logic gates to create a scalable, attack-resistant obfuscation that adds distributed protection against structural and functional attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If deterministic obfuscation techniques are used to protect hardware IP cores, then implementation simplicity is maintained, but security against piracy and reverse engineering attacks deteriorates
Solution Approach 1:
The circuit design is divided into multiple partitions, with different obfuscation techniques applied to different partitions. This segmentation allows the system to balance between simplicity and security by using lighter obfuscation where needed and stronger techniques where security is critical
Solution Approach 2:
The patent transforms the deterministic obfuscation approach into a randomized one, where obfuscation parameters such as key selection, transformation functions, and partitioning strategies are randomized rather than fixed. This fundamentally changes the security model from predictable to unpredictable, resisting attacks
2Reliability
If strong obfuscation techniques are applied to entire large-scale designs, then security is improved, but computational complexity and processing time deteriorate
Solution Approach 1:
By dividing the large-scale design into multiple smaller partitions, the patent enables parallel processing of obfuscation operations. Each partition can be processed independently, reducing the computational burden on any single processing unit and allowing the overall system to scale efficiently
Solution Approach 2:
The patent applies different levels of obfuscation strength to different partitions based on their security requirements. Not all partitions require the same degree of protection, allowing optimization of computational resources by applying stronger obfuscation only where necessary
3Productivity
If fixed partitioning is used for obfuscation, then processing efficiency is maintained, but adaptability to different design sizes and security requirements deteriorates
Solution Approach 1:
The patent introduces dynamic partitioning where the number, size, and configuration of partitions can be adjusted based on the specific design requirements, security level needed, and available computational resources. This dynamic approach maintains efficiency by optimizing partitioning for each case while providing adaptability
4Ease of manufacture
If static obfuscation keys are used, then implementation simplicity is maintained, but ability to update security during development deteriorates
Solution Approach 1:
The patent implements dynamic key management where obfuscation keys can be updated, regenerated, and refreshed during different development stages and throughout the product lifecycle. This allows security to be adapted as threats evolve while maintaining the core obfuscation mechanism
Data Source
AI summary
A method of obfuscating a circuit design includes, in part, receiving a netlist of the circuit design, splitting the circuit design into a multitude of partitions, transforming each partitions so as to obfuscate each partition, and stitching the multitude of transformed partitions to form the obfuscated circuit. The netlist may be a register transfer level netlist. The number and the size of partitions may vary. The partitions may be distributed throughout the entirety of the design. The method may further include generating a randomized circuit associated with at least a subset of the partitions, and merging each partition with the partition's associated randomized circuit. The method may further include quantifying the amount of transformation associated with each partition. The method may further include adding a first key to at least one of the obfuscated partitions, and adding a second key to the partition's associated randomized circuit.


