Hardware Obfuscation of Digital Data Using Test Data Registers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hardware manufacturers face challenges in securely hiding cryptographic keys and secret information within system on a chip (SoC) architectures to prevent unauthorized access and reverse engineering, especially during the verification and provisioning processes.
Innovation Solution
A hardware-based obfuscation method using test data registers (TDRs) to hide secret information bits within the SoC, employing a multi-layered approach that includes setting primary input bits to logic high or low, applying a derivation function through a network of digital logic gates, and using a bit mapping list to reorder output bits, thereby making it difficult to reverse-engineer the circuits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are embedded in SoC architectures for authentication, then security verification capability is improved, but vulnerability to hardware-based attacks and reverse engineering increases
Solution Approach 1:
The cryptographic key is segmented into multiple individual key bits that are distributed across different TDRs. Each TDR stores only a portion of the key material, and the complete key can only be reconstructed through the orchestrated sequence of capture, shift, and derivation operations. This segmentation prevents attackers from extracting the entire key through a single point of failure or reverse engineering effort.
Solution Approach 2:
The patent introduces temporal and operational dimensions to key storage by using the TDR shift register mechanism. Instead of static key storage, the key material is dynamically shifted through multiple registers over multiple clock cycles, with different portions exposed at different times. This temporal distribution across operational cycles adds a dimension that complicates hardware attacks and reverse engineering.
2Difficulty of detecting and measuring
If secret information is hidden using hardware-based obfuscation methods, then security against reverse engineering is improved, but device complexity increases
Solution Approach 1:
The patent repurposes existing TDR infrastructure, which was originally designed for testing and verification purposes, to serve dual functions: maintaining testability while simultaneously providing cryptographic key obfuscation. By leveraging the existing shift register architecture and control mechanisms, the system achieves security enhancement without adding entirely new hardware components, thus limiting the increase in device complexity.
Solution Approach 2:
The TDRs and their associated control logic perform multiple functions including key storage, key shifting, and authentication participation, all through their inherent operational mechanisms. The same infrastructure that enables test data registration and verification automatically provides the obfuscation and security functions, eliminating the need for separate dedicated security hardware and reducing overall system complexity.
3Reliability
If multiple TDRs are used to distribute secret information bits, then security against compromise is improved, but manufacturing and configuration complexity increases
Solution Approach 1:
The bit mapping list is pre-configured during manufacturing or system initialization, establishing the exact correspondence between TDR addresses and key bit positions before the device enters service. This preliminary configuration step simplifies subsequent operations, as the mapping relationships are predetermined and stored, eliminating the need for complex runtime determination or manual configuration of each TDR's role in the key distribution scheme.
Data Source
AI summary
Some aspects of this disclosure are directed to implementing hardware-based obfuscation of digital data. For example, some aspects of this disclosure relate to a method, including performing a capture operation that loads a plurality of primary input (PI) bits into corresponding shift registers of a plurality of test data registers (TDRs) disposed on one or more digital semiconductor devices and configured to store a plurality of secret information bits. The method further includes performing a sequence of shift operations on the plurality of TDRs to obtain a plurality of output bits. The method further includes applying, by an authenticating processor, a derivation function on the plurality of output bits to extract the plurality of secret information bits thereby authenticating the one or more digital semiconductor devices.


