Super Control Dataflow Graphs for IC Reverse Engineering Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ESL design methodologies are vulnerable to reverse engineering attacks, particularly in the context of integrated circuits, where an attacker can recover the controller and insert malicious circuits or overbuild ICs, highlighting the need for enhanced security measures to protect the design from rogue elements within the foundry or malicious users.
Innovation Solution
The proposed solution involves generating a super control dataflow graph (CDFG) by applying ESL design constraints to an integrated circuit, determining upper and lower bounds for the number of CDFGs, and inserting components into the register transfer level netlist to enhance the circuit's resilience against reverse engineering attacks, including the use of dummy components and decoy connections to increase the search space complexity for attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If ESL design constraints are applied to generate super CDFGs, then the number of possible CDFGs an attacker must explore is significantly reduced, making reverse engineering exponentially harder, but the design complexity and number of components in the netlist increases
Solution Approach 1:
The controller is segmented into multiple CDFGs (control dataflow graphs) that represent different possible implementations. By applying ESL design constraints, the system generates a super CDFG that encompasses all valid controller implementations, making it difficult for attackers to identify the correct path through the complex design space.
Solution Approach 2:
The patent introduces a new dimension to the design space by creating super CDFGs that represent multiple possible controller implementations simultaneously. This dimensional expansion from single CDFG to super CDFG structure increases the search space complexity for attackers while maintaining functional equivalence.
2Reliability
If components are inserted into the register transfer level netlist to enhance security, then the circuit's resilience against reverse engineering attacks increases, but the area and power consumption of the IC increases
Solution Approach 1:
The patent creates copies of the controller logic in the form of alternative CDFGs within the super CDFG structure. These copies are functionally equivalent but structurally different, providing security through redundancy without requiring additional physical hardware resources beyond the logical design space.
Solution Approach 2:
The system changes the parameter of design representation from a single fixed implementation to a family of parameterized implementations. By varying the controller implementation parameters while maintaining functional equivalence, the system achieves security enhancement without proportionally increasing physical area.
3Difficulty of detecting and measuring
If multiple CDFGs are generated to increase search space complexity, then the security against controller recovery attacks improves, but the time required for design verification and synthesis increases
Solution Approach 1:
The super CDFG structure serves multiple functions: it represents all valid controller implementations, provides security through increased search space complexity, and enables verification through unified constraint-based validation. This multi-functionality allows the system to achieve security enhancement without proportionally increasing verification time.
Solution Approach 2:
The ESL design constraints provide feedback mechanisms that guide the synthesis process. By using constraint-based verification, the system can efficiently validate multiple CDFG implementations against the original design specifications, reducing the time required to verify security properties compared to exhaustive manual verification.
Data Source
AI summary
An exemplary system, method and computer-accessible medium can be provided which can include, for example, generating a super control dataflow graph(s) (CDFG) by applying a plurality of electronic system level ESL design constraints associated with an integrated circuit, determining an upper bound(s) number and a lower bound(s) number based on a number of CDFGs in the super CDFG(s)—with each number being one metric of a capability of the integrated circuit to resist reverse engineering attack—, and inserting a component(s) into a register transfer level netlist to effectuate a modification of the upper bound(s) and the lower bound(s).


