System, method, and computer-accessible medium for register-transfer level locking against an untrusted foundry

Inventors

Karri, Ramesh • Garg, Siddharth • PILATO, Christian

Assignees

Politecnico di Milano • New York University

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12511354-B2

Patent

Publication Date

2025-12-30

Expiration Date


Abstract

Exemplary system, method, and computer-accessible medium for protecting at least one integrated circuit (IC) design, includes generating an abstract syntax tree (“AST”) based on a hardware description language and a first register-transfer level (RTL) design. The method also includes selecting semantic elements in the AST to lock and locking the selected semantic elements. Additionally, the method includes a procedure for generating a second RTL design.

Core Innovation

The problem addressed is protecting integrated circuit (IC) design against an untrusted foundry by performing register-transfer level (RTL) locking of IC IP. The disclosure describes an ASSURE system that locks semantic elements in an IC design at the RTL based on selecting elements from an abstract syntax tree (AST) derived from an input hardware description language (HDL). The locked design is represented as a second RTL design whose functionality matches the original only when a predetermined locking key is applied to the second RTL design.

ASSURE generates an opaque predicate that is performed in hardware, and obfuscates the locked semantic elements with an input key. The technique uses AST-based selection and locking of semantic elements, including constant obfuscation, operation obfuscation, and branch obfuscation, so that the resulting second RTL design exhibits functionality matching conditioned on application of the predetermined locking key. The approach is also described as using an oracle-less threat model and provides mathematical/provable indistinguishability security arguments.

To control which parts of the design are processed for locking, the disclosure describes a blacklist-based module exclusion approach, including excluding reset processes and loop induction variables and other reset-related constants to avoid synthesis/execution issues. The disclosure further describes key-bit budgeting, depth-first analysis, and procedures such as obfuscating selected semantic elements using hardware opaque predicates, while reporting correctness and key-effect metrics. Experimental validation is described using a Verilog/Pyverilog implementation and synthesis with reported area overhead and timing overhead across multiple benchmark suites.

Claims Coverage

The document includes three independent claims: a method claim, a system claim, and a non-transitory computer-accessible medium claim. Across these independent claims, the coverage centers on parsing an input RTL HDL into an abstract syntax tree, selecting semantic elements to lock them via an opaque predicate performed in hardware, obfuscating the locked semantic elements with an input key, and generating a second RTL design whose functionality matches the first when a predetermined locking key is applied. Additional inventive features are described in the dependent claims for key application, selection scope, and predicate characterization.

Ast-based selection of semantic elements for RTL locking

receiving a first register-transfer level (RTL) design comprising an input hardware description language (HDL); generating, by parsing the input HDL, an abstract syntax tree associated with the IC design; selecting semantic elements in the abstract syntax tree to lock the first RTL design

Hardware opaque predicate locking with key-conditioned functionality match

locking the semantic elements selected from the generated abstract syntax tree, wherein the locking of the selected semantic elements includes generating an opaque predicate which is performed in hardware; obfuscating the locked semantic elements with an input key; and generating a second RTL design based on the obfuscated locked semantic elements, wherein a functionality of the first RTL design matches a functionality of the second RTL design when a predetermined locking key is applied to the second RTL design

Computer hardware arrangement for RTL locking workflow

a computer hardware arrangement configured to: receive a first register-transfer level (RTL) design comprising an input hardware description language (HDL); generate, by parsing the input HDL, an abstract syntax tree associated with the IC design; select semantic elements in the abstract syntax tree to lock the first RTL design; lock the selected semantic elements selected from the generated abstract syntax tree, wherein the locking of the selected semantic elements includes generating an opaque predicate which is performed in hardware; obfuscate the locked semantic elements with an input key; and generate a second RTL design based on the obfuscated locked semantic elements; wherein a functionality of the first RTL design matches a functionality of the second RTL design when a predetermined locking key is applied to the second RTL design

Non-transitory computer-accessible medium executing RTL locking procedures

a non-transitory computer-accessible medium having stored thereon computer-executable instructions for protecting at least one integrated circuit (IC) design, wherein, when a computing arrangement executes the instructions, the computing arrangement is configured to perform procedures comprising: receiving a first register-transfer level (RTL) design comprising an input hardware description language (HDL); generating, by parsing the input HDL, an abstract syntax tree associated with the IC design; selecting semantic elements in the abstract syntax tree first data to lock the first RTL design; locking the selected semantic elements selected from the generated abstract syntax tree, wherein the locking of the selected semantic elements includes generating an opaque predicate which is performed in hardware; obfuscating the locked semantic elements with an input key; and generating a second RTL design based on the obfuscated locked sematic elements; wherein a functionality of the first RTL design matches a functionality of the second RTL design when a predetermined locking key is applied to the second RTL design

Across the independent claims, the core inventive coverage consists of parsing input RTL HDL into an abstract syntax tree, selecting semantic elements to lock, performing the locking using a hardware opaque predicate, obfuscating locked semantic elements with an input key, and generating a second RTL design that matches the original functionality only when the predetermined locking key is applied. Dependent claim refinements mentioned in the partial content further characterize selection and key/locking constraints.

Stated Advantages

Provides functionality of the first RTL design matching the second RTL design when a predetermined locking key is applied to the second RTL design.

Provides provable security/indistinguishability security arguments under an oracle-less threat model.

Experimental validation includes correctness and key-effect metrics.

Reports area overhead and timing overhead results across multiple benchmark suites.

Documented Applications

Protecting at least one IC design against an untrusted foundry by performing RTL logic locking (ASSURE system).

Experimental evaluation using benchmark suites with reported area and timing overheads.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.