arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

LIB-TRAP: 标准单元库硬件木马风险评估与防范

LIB-TRAP: Standard Cell Library Hardware Trojan Risk Assessment and Prevention

Harish Kumar Dharavath, Md Muhtasim Alam Chowdhury, Rozhin Yasaei, Soheil Salehi

arXiv 2607.01526首次发表:更新:

AI 中文总结

提出标准单元库被篡改的新型威胁模型,通过将恶意库应用于基准设计,评估木马插入的隐蔽性和有效性。

AI 中文摘要

无晶圆半导体制造模式固有的漏洞显著增加了恶意硬件木马(HT)插入的风险,对硬件安全构成严重威胁。已有多种HT缓解和检测策略被开发,现有工作探索了在集成电路标准单元之间插入HT。然而,对于当今市场上大多数数字设计的基本构建块——标准单元所构成的漏洞,缺乏研究。本文研究了一种新的威胁模型,其中标准单元被视为不可信。我们提出的威胁模型为设计公司提供了一个被篡改的标准单元库。预期的网表使用被篡改的库进行综合和实现。在制造过程中,恶意代工厂将库中未激活的HT单元替换为激活的对应单元。使用开源和行业标准的电子设计自动化(EDA)工具,将现有的标准单元库Saed32nm和Sky130nm转换为恶意库,这些库能够掩盖任意HT的存在,使其不被IC设计者察觉。然后,将恶意库应用于多个标准基准设计并进行表征。为了展示这种基于标准单元的攻击向量的有效性和隐蔽性,使用Synopsys 32nm和SkyWater 130nm技术,分别用干净库和受木马感染的库综合了三个基准电路:AES-128加密核心、以太网控制器和WISHBONE DMA引擎。从这些综合电路中提取设计级特征,包括总单元数、总面积、动态功耗和静态功耗,作为二元分类的输入。

英文摘要

Vulnerabilities inherent to the fabless semiconductor manufacturing model have significantly increased the risk of malicious Hardware Trojan (HT) insertion, posing severe threats to hardware security. Several HT mitigation and detection strategies have been developed, and existing works explore the insertion of HTs in the space between standard cells in an integrated circuit. However, there is a lack of research into the vulnerabilities posed by the building blocks of most digital designs on the market today, the standard cells. This work investigates a novel threat model in which standard cells are considered untrusted. Our proposed threat model provides the design house with a tampered standard cell library. The intended netlist is synthesized and implemented using the tampered library. During fabrication, a nefarious foundry replaces the library's deactivated HT cells with activated counterparts. Using open-source and industry-standard Electronic Design Automation (EDA) tools, existing standard cell libraries, Saed32nm and Sky130nm, are converted into malicious libraries capable of masking the presence of arbitrary HTs from IC designers. The malicious library is then applied and characterized in multiple standard benchmark designs. To demonstrate the efficacy and stealthiness of this standard cell-based attack vector, three benchmark circuits, an AES-128 encryption core, an Ethernet controller, and a WISHBONE DMA engine, were synthesized using both clean and Trojan-infected libraries across Synopsys 32nm and SkyWater 130nm technologies. Design-level features, including total cell count, total area, dynamic power consumption, and static power, were extracted from these synthesized circuits to serve as inputs for binary classification

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑