USENIX Security2023Top-tier venue
FuncTeller: How Well Does eFPGA Hide Functionality?
Zhaokun Han, Mohammed Shayan, Aneesh Dixit, Mustafa M. Shihab, Yiorgos Makris, Jeyavijayan Rajendran
Abstract
Hardware intellectual property (IP) piracy is an emerging threat to the global supply chain. Correspondingly, various countermeasures aim to protect hardware IPs, such as logic locking, camouflaging, and split manufacturing. However, these countermeasures cannot always guarantee IP security. A malicious attacker can access the layout/netlist of the hardware IP protected by these countermeasures and further retrieve the design. To eliminate/bypass these vulnerabilities, a recent approach redacts the design's IP to an embedded field-programmable gate array (eFPGA), disabling the attacker's access to the layout/netlist. eFPGAs can be programmed with arbitrary functionality. Without the bitstream, the attacker cannot recover the functionality of the protected IP. Consequently, state-of-the-art attacks are inapplicable to pirate the redacted hardware IP. In this paper, we challenge the assumed security of eFPGA-based redaction. We present an attack to retrieve the hardware IP with only black-box access to a programmed eFPGA. We observe the effect of modern electronic design automation (EDA) tools on practical hardware circuits and leverage the observation to guide our attack. Thus, our proposed method FuncTeller selects minterms to query, recovering the circuit function within a reasonable time. We demonstrate the effectiveness and efficiency of FuncTeller on multiple circuits, including academic benchmark circuits, Stanford MIPS processor, IBEX processor, Common Evaluation Platform GPS, and Cybersecurity Awareness Worldwide competition circuits. Our results show that FuncTeller achieves an average accuracy greater than 85% over these tested circuits retrieving the design's functionality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on3
- Does logic locking work with EDA tools?Zhaokun Han, Muhammad Yasin, Jeyavijayan (JV) RajendranUSENIX Security 2021 · 35 citations
- Hardening Circuit-Design IP Against Reverse-Engineering AttacksAnimesh Chhotaray, Thomas ShrimptonS&P 2022 · 11 citations
- Circuit Learning for Logic Regression on High Dimensional Boolean SpacePei-Wei Chen, Yu-Ching Huang, Cheng-Lin Lee, Jie-Hong Roland JiangDAC 2020 · 10 citations
Related papers
- On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAsShahin Tajik, Heiko Lohrke, Jean-Pierre Seifert, Christian BoitCCS 2017 · 116 citations
- The Unpatchable Silicon: A Full Break of the Bitstream Encryption of Xilinx 7-Series FPGAsMaik Ender, Amir Moradi, Christof PaarUSENIX Security 2020
- How Not to Protect Your IP - An Industry-Wide Break of IEEE 1735 ImplementationsJulian Speith, Florian Schweins, Maik Ender, Marc Fyrbiak et al.S&P 2022 · 10 citations
- Fortifying RTL Locking Against Oracle-Less (Untrusted Foundry) and Oracle-Guided AttacksNimisha Limaye, Animesh Basak Chowdhury, Christian Pilato, Mohammed Thari Nabeel et al.DAC 2021 · 28 citations
- Stealing Maggie's Secrets-On the Challenges of IP Theft Through FPGA Reverse EngineeringSimon Klix, Nils Albartus, Julian Speith, Paul Staat et al.CCS 2024 · 5 citations
