TimingCamouflage+: Netlist Security Enhancement with Unconventional Timing (with Appendix)
arXiv:2003.00862 · doi:10.1109/TCAD.2020.2974338
Abstract
With recent advances in reverse engineering, attackers can reconstruct a netlist to counterfeit chips by opening the die and scanning all layers of authentic chips. This relatively easy counterfeiting is made possible by the use of the standard simple clocking scheme, where all combinational blocks function within one clock period, so that a netlist of combinational logic gates and flip-flops is sufficient to duplicate a design. In this paper, we propose to invalidate the assumption that a netlist completely represents the function of a circuit with unconventional timing. With the introduced wave-pipelining paths, attackers have to capture gate and interconnect delays during reverse engineering, or to test a huge number of combinational paths to identify the wave-pipelining paths. To hinder the test-based attack, we construct false paths with wave-pipelining to increase the counterfeiting challenge. Experimental results confirm that wave-pipelining true paths and false paths can be constructed in benchmark circuits successfully with only a negligible cost, thus thwarting the potential attack techniques.
References in corpus (5)
- Physical Design Obfuscation of Hardware: A Comprehensive Investigation of Device- and Logic-Level Techniques
- Statistical Timing Analysis and Criticality Computation for Circuits with Post-Silicon Clock Tuning Elements
- Sampling-based Buffer Insertion for Post-Silicon Yield Improvement under Process Variability
- PieceTimer: A Holistic Timing Analysis Framework Considering Setup/Hold Time Interdependency Using A Piecewise Model
- TimingCamouflage+: Netlist Security Enhancement with Unconventional Timing (with Appendix)