Globalization of the System-on-Chip (SoC) supply chain has resulted in increased intellectual property (IP) piracy, illegal reuse, and tampering by malicious actors. In response to these challenges, IP watermarking presents itself as a promising solution to protect against these risks; however, traditional methods rely heavily on labor-intensive manual tests by verification engineers and fail to account for the potential threat posed by malicious SoC design houses. To overcome these challenges and improve the efficiency of the watermark verification process while safeguarding against possible attacks, we developed ActiWate as an innovative watermarking approach that not only provides proof of authorship but also prevents unauthorized usage of an IP. Using an automatic self-verification technique, the watermark establishes communication with various peripherals within the SoC. The versatility and effectiveness of ActiWate have been proven through extensive experiments on multiple SoCs with diverse components and peripherals, including the testing of watermarking and the verification of various IPs. Moreover, we discuss the inclusion of this multiple serialized verification in more case studies and results, as well as analyzing prominent security threats, including reverse engineering attacks.
With the ever-increasing size and complexity of system-on-chip (SoC) architectures, where numerous parties (either trusted or untrusted) are involved each playing a crucial role (e.g., providing 3rd-party intellectual properties (IPs), accomplishing design stages like fabrication, testing, and packaging), various hardware-oriented security threats have emerged. One of the solutions against such threats is SoC-level security monitoring, which enables the possibility of validating security policies. However, due to the lack of comprehensive research in this field, its current solutions suffer from significant flaws. This paper identifies a set of quality attributes for SoC security monitoring solutions (which mostly failed to be met by the existing solutions). The potential solutions for SoC security monitoring have been defined each evaluated based on the identified quality attributes.
To meet the demands of diverse and rapidly evolving markets, system-on-chips (SoCs) are becoming more complex in size and functionality. More intellectual properties (IPs) and hardware accelerators are required to support a varied set of applications with faster response. In recent years, there has been a growing trend of using reconfigurable and adaptable hardware for compute-intensive kernels, e.g., neural networks, crypto-engines, and blockchains. Hence, embedded FPGA (eFPGA) technology has emerged as a standard solution incorporated into the SoC to enhance computational performance and provide reconfigurability. However, with the increasing complexity and size of modern SoCs, coupled with the integration of third-party IPs (3PIPs) and accelerators, ensuring the information security, i.e., integrity, confidentiality, and availability, of critical and sensitive data has become more challenging than ever before. Thus, a sustainable and upgradable security auditing infrastructure has become a necessity. This article extends EnSAFe, a framework specially crafted to streamline security policy auditing while enabling upgradability within designs that leverage eFPGA-based accelerators. The EnSAFe framework enables signal monitoring in a plug-and-play fashion, and the monitoring core logic is mapped onto the eFPGA accelerator component with minimal overhead. We extend EnSAFe through novel methodologies and algorithms for security policy generation, optimization of security policy implementations, and enhancement of the reconfigurability of the security status monitor (SSM). We also establish a security policy database and assess the effectiveness of the extended framework for policy checking across various use case scenarios. Our experiments show that EnSAFe can detect runtime threats/vulnerabilities at low area overhead.
The ever-increasing propensity for intellectual property (IP) reuse has reduced the design productivity gap in the supply chain. As a consequence, protecting IPs has become more difficult since IP vendors now make their IPs more flexible so that they can be reused in other designs for greater profits. This has made IP piracy and infringement easier than ever. IP watermarking can detect IP piracy and infringement and it has been an active research topic for the past decade. Various watermarking techniques have been discussed in the literature that embed circuitry into IP to provide proof of ownership. But, in most RT-level watermarking methods, the watermarking circuit is separate from IP functionality and can be easily identified and tampered with. In this paper, we propose CAPEC, a Cellular Automata (CA) guided watermarking technique that embeds watermarking circuits into the don’t care states of the FSM. The watermarking function is a set of configurable CA rules tightly coupled with the functional states of the FSM. CAPEC generates a signature in a challenge-response-based protocol, is resistant to identification, tampering, and removal attacks, and has minimal overhead. We also analyze and evaluate the efficiency of the technique and its resilience to different attacks for varying challenge size and CA rules. After watermarking different benchmarks, the watermark overhead was found to be negligible and formal verification proved no changes to the functional circuit.
The utilization of reconfigurable and flexible acceleration for compute-intensive kernels, e.g., neural networks, crypto-engines, and arithmetics, have been on the rise in recent years, where embedded FPGA (eFPGA) architecture, as a de facto solution, is becoming an integral component of the system-on-chip (SoC) for the acceleration purposes. In the meantime, modern SoCs are getting larger and more complex in size and functionality, and with the inclusion of more IPs along with the eFPGA accelerator, they are getting more exposed to a wide variety of security-critical and sensitive information, hence innovative security infrastructure is needed to ensure the information security, i.e., integrity, confidentiality, and availability. Also, in an SoC equipped with the eFPGA-based accelerator, with the potential reconfigurability over time, sustainable and upgradable security infrastructure becomes a necessity. To address such concerns, in this paper, we introduce EnSAFe, a framework for enabling security policy auditing with upgradability within the designs enabled by eFPGA-based accelerators. The EnSAFe framework enables signal monitoring in a plug-and-play fashion, and the monitoring core logic will be mapped onto the eFPGA accelerator component with minimal overhead (almost zero). Our experiments demonstrate that the EnSAFe framework can detect runtime threats/vulnerabilities with a low area overhead.
As modern SoC architectures incorporate many complex/heteroge-neous intellectual properties (IPs), the protection of security assets has become imperative, and the number of vulnerabilities revealed is rising due to the increased number of attacks. Over the last few years, penetration testing (PT) has become an increasingly effective means of detecting software (SW) vulnerabilities. As of yet, no such technique has been applied to the detection of hardware vulnera-bilities. This paper proposes a PT framework, SHarPen, for detecting hardware vulnerabilities, which facilitates the development of a SoC-level security verification framework. SHarPen proposes a formalism for performing gray-box hardware (HW) penetration testing instead of relying on coverage-based testing and provides an automation for mapping hardware vulnerabilities to logical/-mathematical cost functions. SHarPen supports both simulation and FPGA-based prototyping, allowing us to automate security testing at different stages of the design process with high capabilities for identifying vulnerabilities in the targeted SoC.
Watermarking offers a viable solution to combat IP piracy and illegal re-use. However, watermarking verification techniques rely heavily on manual testing by verification engineers and ignore the possibility of having a rogue SoC design house. To automate the watermarking-based verification process and to be against wider attacks (e.g., rogue design house), this paper presents ActiWate, which conducts automatic self-verification by communicating with various peripherals within the SoC. Showing its resilience against removal and spoofing attacks, ActiWate is architectured to be an IP/SoC-agnostic watermarking and our experiments demonstrate its versatility by implementing it on multiple RISC-V SoCs with different components/peripherals.
As modern SoC architectures incorporate many complex/heterogeneous intellectual properties (IPs), the protection of security assets has become imperative, and the number of vulnerabilities revealed is rising due to the increased number of attacks. Over the last few years, penetration testing (PT) has become an increasingly effective means of detecting software (SW) vulnerabilities. As of yet, no such technique has been applied to the detection of hardware vulnerabilities. This paper proposes a PT framework, SHarPen, for detecting hardware vulnerabilities, which facilitates the development of a SoC-level security verification framework. SHarPen proposes a formalism for performing gray-box hardware (HW) penetration testing instead of relying on coverage-based testing and provides an automation for mapping hardware vulnerabilities to logical/mathematical cost functions. SHarPen supports both simulation and FPGA-based prototyping, allowing us to automate security testing at different stages of the design process with high capabilities for identifying vulnerabilities in the targeted SoC.
—Intellectual property (IP) cores are essential to creating modern system-on-chips (SoCs). Protecting the IPs deployed in modern SoCs has become more difficult as the IP houses have been established across the globe over the past three decades. The threat posed by IP piracy and overuse has been a topic of research for the past decade or so and has led to creation of a field called watermarking. IP watermarking aims of detecting unauthorized IP usage by embedding excess, non-functional circuitry into the SoC. Unfortunately, prior work has been built upon assumptions that cannot be met within the modern SoC design and verification processes. In this paper, we first provide an extensive overview of the current state-of-the-art IP watermarking. Then, we challenge these dated assumptions and propose a new path for future effective IP watermarking approaches suitable for today’s complex SoCs in which IPs are deeply embedded.
With the increasing complexity of system-on-chip (SoC) designs, security has become a vital requirement. The confidentiality and integrity of critical information, access controls as well as chip authentication at both software and hardware levels should be guaranteed for SoCs. A secure and trusted component is necessary to provide those required security and trust mechanisms in SoCs. The goal of this component is to provide support for security-critical operations and functionalities like provisioning and protection of assets, watermark generation, intellectual property (IP) unlocking, as well as providing isolation at the hardware and software levels. In this paper, we provide a comprehensive overview of the requirements and components for the design of a root-of-trust (RoT) termed as Security Engine that protects against various attacks at the manufacturing floor and during in-field operations while providing security-critical functionalities and features. In addition to that, we identify several critical protocols and security policies for RoT. Policies ensure secure operations and safe transfer of assets while maintaining confidentiality and integrity. Policies are in the form of access control, data integrity and retention, encryption, and asset management for a Security Engine. Similarly, we identify several critical functionalities and protocols of the SoC development like secure boot, self-test, provisioning protocols, security IPs, watermark generation, secure debug, etc., and give a conceivable solution for every one of them with the assistance of the proposed Security Engine while making not many presumptions. Policies and protocols can be implemented in hardware and software with minimum overhead. They can also be checked and enforced by integrating them into the firmware code of the RoT processor. Moreover, this paper will define different types of security policies like access control, data integrity and retention, encryption, and asset management policy for a Security Engine, which is the hub of security operations in an SoC.
Hardware intellectual property (IP) infringement is a serious concern due to the horizontal model of the semiconductor supply chain. Several untrusted entities in this globalized supply chain are entitled to white-box accessibility of the reusable and valuable hardware IPs, making them vulnerable to piracy, cloning, tampering, and reverse engineering at different phases of system-on-chip (SoC) design and fabrication. Hardware obfuscation is a design transformation mechanism to protect the IPs from being exposed to the untrusted entities by locking the functionality of the IP while hiding the design intent. Unfortunately, existing obfuscation approaches are not resistant to various functional and structural attacks that are capable of unlocking the obfuscated designs. Due to the inability to analyze an obfuscation technique from the attackers’ standpoint, numerous vulnerabilities inherent to the obfuscation methods go undetected unless a true adversary discovers them. In this paper, we present a collaborative approach between two entities one acting as a red team and another as a blue team to replicate the real attacker-defender scenario, which in return strengthens the sequential obfuscation techniques. The blue team performs sequential obfuscation of gate-level IPs. On the other hand, the red team plays the role of an adversary/evaluator and tries to unlock the design by extracting the unlocking key or recovering the obfuscation circuitries. Keywords—FSM obfuscation; Reverse engineering; Red teamblue team