Obfuscated Watermarking Framework for IC Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing watermarking techniques in the semiconductor supply chain fail to provide immutability, undetectability, uniqueness, verifiability, high structural coverage, and low hardware cost, and are vulnerable to tampering and cloning attacks, making it difficult to authenticate and verify intellectual property (IP) and integrated circuits (ICs) effectively.
Innovation Solution
The Framework for Obfuscated Watermark Labeling (FOWL) employs a powerful obfuscation-based IP watermarking scheme that embeds watermarks in the state space of sequential designs, using secret keys to lock and unlock finite state machines, integrates authentication modes, digest generation, and physical unclonable functions to ensure immutability, undetectability, and uniqueness, while providing high structural coverage and low overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing watermarking techniques are used, then IP provenance and traceability can be established, but the watermarks are vulnerable to tampering and cloning attacks
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using a Finite State Machine (FSM) that mediates between the watermark embedding and verification processes. The FSM acts as a secure intermediary that controls access to watermark data through secret keys, preventing direct tampering or cloning of the watermark while maintaining provenance information.
Solution Approach 2:
The patent replaces traditional mechanical or simple digital watermarking mechanisms with a cryptographic-based authentication system. Instead of directly embedding watermarks that can be copied, the system uses key-based authentication mechanisms and physical unclonable functions (PUFs) to provide security against tampering and cloning attacks.
2Reliability
If watermarks are made more secure against tampering, then authentication reliability improves, but hardware cost and complexity increase
Solution Approach 1:
The patent segments the authentication function into distinct components: a watermark embedding module, an FSM authentication module, and a verification module. This segmentation allows each component to be optimized independently, reducing overall hardware complexity while maintaining high authentication reliability through specialized security functions.
Solution Approach 2:
The patent changes the parameter of security from direct watermark protection to key-based cryptographic protection. By transforming the security mechanism from structural watermark obfuscation to cryptographic authentication, the system achieves higher reliability without proportionally increasing hardware complexity, as cryptographic operations can be implemented efficiently with standard hardware primitives.
3Ease of operation
If existing watermarking techniques are used, then IP authentication is possible, but the watermarks are easy to locate and detect
Solution Approach 1:
The FSM acts as an intermediary layer that hides the watermark data from direct detection. Instead of placing watermarks in easily detectable locations, the system uses the FSM as a mediator that only reveals watermark information to authorized users with the correct secret keys, making watermarks undetectable to unauthorized parties while maintaining ease of authentication for legitimate users.
Solution Approach 2:
The patent introduces asymmetry in the watermark detection process through key-based authentication. The verification process requires specific cryptographic keys that are not publicly available, creating an asymmetric system where only authorized users can detect and verify watermarks. This asymmetry makes watermarks undetectable to attackers while maintaining ease of operation for authenticated users.
4Reliability
If obfuscation-based watermarking is implemented, then watermark immutability and undetectability are achieved, but design transformation may affect watermark integrity
Solution Approach 1:
The patent makes the watermark system dynamic by integrating it with the FSM's state transitions. The watermark is not a static embedded signal but a dynamic authentication mechanism that adapts to different design transformations. The FSM can transition between states based on design changes while maintaining watermark integrity through cryptographic authentication, providing both immutability and adaptability.
Solution Approach 2:
The FSM-based authentication mechanism provides universal functionality that works across different design transformations. The same cryptographic authentication mechanism can verify watermarks in various forms of the IP design, making the system versatile while maintaining immutability. The authentication function remains consistent regardless of specific design changes, providing multi-functional verification capability.
Data Source
AI summary
The present disclosure describes systems, apparatuses, and methods for obfuscation-based intellectual property (IP) watermark labeling. One such method comprises identifying, by one or more computing processors, a specific net within an integrated circuit design that is likely to be used in a malicious attack; and adding additional nets to the integrated circuit design that add additional logic states to a finite state machine present in the integrated circuit design. The additional logic states comprise watermarking states for performing authentication of the integrated circuit design, in which a watermark digest can be captured upon application of secret key inputs to the additional nets. Other methods, systems, and apparatuses are also presented.


