Tamper-Resistant Obfuscation Circuit for IC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing integrated circuits, such as obfuscation circuitry, are vulnerable to reverse-engineering techniques like picosecond imaging circuit analysis and side channel attacks, which can reveal wiring and compromise proprietary designs.

Innovation Solution

A tamper-resistant nonvolatile memory with encoded Boolean functions, implemented as a look-up table in a trusted chip, connects to an untrusted chip, controlling logic functions and power inputs to obfuscate circuitry and protect IP, using a metal mesh for security and reprogrammable via symmetric encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If obfuscation circuitry is used to conceal circuit functionality, then design secrecy is improved, but vulnerability to reverse-engineering attacks increases

Engineering Contradiction:
Improvedesign secrecyVSAvoidsecurity against reverse-engineering
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system divides the obfuscation function into two separate components: a lookup table storing obfuscation data and a multiplexer circuit applying the obfuscation. This segmentation allows the obfuscation logic to be physically separated from the proprietary circuit, making reverse-engineering more difficult while maintaining design secrecy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary obfuscation layer between the proprietary circuit and the external environment. The lookup table and multiplexer act as mediators that transform internal signals into obfuscated outputs, preventing direct observation of the proprietary circuit's functionality while maintaining operational integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If trusted chip components are used to complete circuit connections, then wiring secrecy is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvewiring secrecyVSAvoidmanufacturing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts the sensitive wiring completion function from the untrusted foundry process and places it in the trusted chip component. The lookup table and multiplexer are implemented in the trusted portion, removing the need for trusted foundry involvement in completing circuit connections and thereby protecting wiring secrecy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent moves the obfuscation logic from the spatial dimension (physical wiring layout) to the logical dimension (lookup table data). By storing obfuscation patterns in the lookup table rather than hard-wiring them, the system protects wiring secrecy while simplifying the trusted chip's manufacturing process.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If look-up table encoding is used for Boolean functions, then obfuscation effectiveness is improved, but memory requirements increase

Engineering Contradiction:
Improveobfuscation effectivenessVSAvoidmemory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by implementing the lookup table with selective precision. Only the critical obfuscation data bits are stored in memory, while less critical portions use simpler logic. This approach maintains obfuscation effectiveness for key signals while reducing overall memory requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the obfuscation parameters by loading different lookup table data for different operational modes or security levels. This allows the same hardware structure to provide varying degrees of obfuscation strength, optimizing the balance between obfuscation effectiveness and memory usage for different application scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11748524B2Tamper resistant obfuscation circuit
Publication Date: 2023.09.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11748524B2 patent drawing
  • US11748524B2 patent drawing
  • US11748524B2 patent drawing

AI summary

An obfuscation circuit relies on a tamper-resistant nonvolatile memory which encodes a trusted Boolean function. The Boolean function is used to enable several operations relating to circuit obfuscation, including obfuscation of logic circuitry, obfuscation of operand data, and release of IP blocks. The tamper-resistant nonvolatile memory is part of a trusted integrated circuit structure, i.e., one fabricated by a trusted foundry, separate from another integrated circuit structure which contains the various operational logic circuits of the design and is fabricated by an untrusted foundry. The Boolean function is encoded based on a look-up table implemented as a cascaded multiplexer circuit. Multiple obfuscation functions can be so encoded. The obfuscation functions may be reprogrammed using a protocol that relies on symmetric keys, one of which is stored in the tamper-resistant nonvolatile memory.