4.11 Analytical Review of Basic Techniques …
421
Logic obfuscation. The logic obfuscation procedure is usually performed by the
IC developer to hide from an intruder the real functionality and the main design
features of the chip by inserting built-in locking mechanisms into the original design.
The locking circuits remain completely transparent to the IC developer and allow to
perform the right IC function only when the correct key is applied. The increased
complexity of identifying the genuine functions and the need for such secret key can
prevent Trojan insertion in the IC by attackers. So, to implement the procedure of
combinational logic obfuscation, additional gates of XOR/XNOR type can be introduced at certain locations of the circuit [146, 207]. In sequential logic obfuscation,
additional states are introduced in a standard finite state machine to conceal main
functional states for this IC [49]. In addition, some papers [45, 295, 296] propose
to implement special procedures for insertion of additional reconfigurable logics for
implementing procedures of this logic obfuscation. In this case, the microchip functions normally only if the reconfigurable circuits are “correctly” programmed by the
designer (or the end user).
Camouflaging. Camouflaging is only one of the varieties of the obfuscation
method implemented at the topological level by adding a series of “faking” (dummy)
contacts and metallized connections between layers within a camouflaged logic gate
[297, 71]. This highly effective camouflaging technique can prevent attackers from
extracting the correct gate-level netlist from the equivalent circuit by visualizing
various design and topological layers, thereby providing protection against possible
“unfriendly” operation of inserting Trojans with the given parameters into the original
project. Also, another group of reputable and energetic Trojan Hunters [298] used
a very similar method of introducing dummy contacts and developed its original
set of so-called camouflaging cells based on polarity-controllable silicon field-effect
transistors on nanowires (SiNW FET).
Functional filler cells. It should be noted here that, since modern widely used
layout design tools are very conservative (standardized) regarding the rules for
placing elements on the IC surface, the entire area can’t be filled with standard
special cells in the design. For this reason, the unused spaces are usually filled with
filler cells or decap cells that do not have any functionality. Thus, the most covert
way for attackers to insert Trojans in a circuit layout is replacing filler cells, because
removing these nonfunctional filler cells has no impact on electrical parameters of
the IC. The built-in self-authentication (BISA) approach involves filling all white
spaces with functional filler cells during layout design [299]. The inserted cells are
then connected automatically to form a combinational circuitry that could potentially
be tested. The essence of this method is that alarm of the standard measuring system
when a “failure” occurs during testing will obviously denote that such embedded
special functional filler has been replaced by a Trojan. The task of analysts “Trojan
Hunters” is to determine what type of activation of this Trojan and what its target
functions.
Another original anti-Trojan method is called design-for-trust method. This
method involves trustworthy computing on untrusted components. The difference
between runtime monitoring and trustworthy computing that is hardly distinguishable
for design engineers is that trustworthy computing is tolerant to any Trojan attacks by
421
Logic obfuscation. The logic obfuscation procedure is usually performed by the
IC developer to hide from an intruder the real functionality and the main design
features of the chip by inserting built-in locking mechanisms into the original design.
The locking circuits remain completely transparent to the IC developer and allow to
perform the right IC function only when the correct key is applied. The increased
complexity of identifying the genuine functions and the need for such secret key can
prevent Trojan insertion in the IC by attackers. So, to implement the procedure of
combinational logic obfuscation, additional gates of XOR/XNOR type can be introduced at certain locations of the circuit [146, 207]. In sequential logic obfuscation,
additional states are introduced in a standard finite state machine to conceal main
functional states for this IC [49]. In addition, some papers [45, 295, 296] propose
to implement special procedures for insertion of additional reconfigurable logics for
implementing procedures of this logic obfuscation. In this case, the microchip functions normally only if the reconfigurable circuits are “correctly” programmed by the
designer (or the end user).
Camouflaging. Camouflaging is only one of the varieties of the obfuscation
method implemented at the topological level by adding a series of “faking” (dummy)
contacts and metallized connections between layers within a camouflaged logic gate
[297, 71]. This highly effective camouflaging technique can prevent attackers from
extracting the correct gate-level netlist from the equivalent circuit by visualizing
various design and topological layers, thereby providing protection against possible
“unfriendly” operation of inserting Trojans with the given parameters into the original
project. Also, another group of reputable and energetic Trojan Hunters [298] used
a very similar method of introducing dummy contacts and developed its original
set of so-called camouflaging cells based on polarity-controllable silicon field-effect
transistors on nanowires (SiNW FET).
Functional filler cells. It should be noted here that, since modern widely used
layout design tools are very conservative (standardized) regarding the rules for
placing elements on the IC surface, the entire area can’t be filled with standard
special cells in the design. For this reason, the unused spaces are usually filled with
filler cells or decap cells that do not have any functionality. Thus, the most covert
way for attackers to insert Trojans in a circuit layout is replacing filler cells, because
removing these nonfunctional filler cells has no impact on electrical parameters of
the IC. The built-in self-authentication (BISA) approach involves filling all white
spaces with functional filler cells during layout design [299]. The inserted cells are
then connected automatically to form a combinational circuitry that could potentially
be tested. The essence of this method is that alarm of the standard measuring system
when a “failure” occurs during testing will obviously denote that such embedded
special functional filler has been replaced by a Trojan. The task of analysts “Trojan
Hunters” is to determine what type of activation of this Trojan and what its target
functions.
Another original anti-Trojan method is called design-for-trust method. This
method involves trustworthy computing on untrusted components. The difference
between runtime monitoring and trustworthy computing that is hardly distinguishable
for design engineers is that trustworthy computing is tolerant to any Trojan attacks by
