CCS2026

Proving Circuit Functional Equivalence in Zero Knowledge

Sirui Shen, Zunchen Huang, Chenglu Jin

摘要

The modern integrated circuit (IC) ecosystem is increasingly reliant on third-party intellectual property (3PIP) integration, which introduces security risks, including hardware Trojans, security bugs/vulnerabilities. Addressing the resulting trust deadlock between IP vendors and system integrators without exposing proprietary designs requires novel privacy-preserving verification techniques. However, existing privacy-preserving hardware verification methods are all simulation-based and therefore fail to offer formal guarantees. In this paper, we propose ZK-CEC, the first privacypreserving framework for hardware formal verification. By combining formal verification and zero-knowledge proof (ZKP), ZK-CEC establishes a foundation for formally verifying IP correctness and security without compromising the confidentiality of the designs. We observe that existing zero-knowledge protocols for formal verification are designed to prove statements of public formulas. However, in a privacy-preserving verification context where the formula is secret, these protocols cannot prevent a malicious prover from forging the formula, thereby compromising the soundness of the verification. To address these gaps, we first propose a general blueprint for proving the unsatisfiability of a secret design against a public constraint, which is widely applicable to proving properties in software, hardware, and cyber-physical systems. Based on the proposed blueprint, we construct ZK-CEC, which enables a prover to convince the verifier that a secret IP's functionality aligns perfectly with the public specification in zero knowledge, revealing the size of the proof and the gate-count of the IP. We implement ZK-CEC and evaluate its performance across various circuits, including arithmetic units and cryptographic components. Experimental results show that ZK-CEC successfully verifies practical designs, such as the AES S-Box, within practical time limits. CCS Concepts • Hardware → Equivalence checking; • Security and privacy → Privacy-preserving protocols.