Mantıksal kilitleme tekniği ile üçüncü taraf fikri mülkiyetlerin korunmasına yönelik kripto mimari ve FPGA güvenlik modülü tasarımı
Design of a cryptographic architecture and FPGA security module for protecting third-party intellectual property using the logic locking technique
- Tez No: 995606
- Danışmanlar: PROF. DR. SIDDIKA BERNA ÖRS YALÇIN
- Tez Türü: Yüksek Lisans
- Konular: Elektrik ve Elektronik Mühendisliği, Electrical and Electronics Engineering
- Anahtar Kelimeler: FPGA, FPGA
- Yıl: 2026
- Dil: Türkçe
- Üniversite: İstanbul Teknik Üniversitesi
- Enstitü: Lisansüstü Eğitim Enstitüsü
- Ana Bilim Dalı: Elektronik ve Haberleşme Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Elektronik Mühendisliği Bilim Dalı
- Sayfa Sayısı: Belirtilmemiş.
Özet
Günümüzde donanım tasarımları kullanıcıya sunduğu kolaylıklar, çok çeşitli kapasiteleri ve ucuz maliyetleri nedeniyle Alanda Programlanabilir Kapı Dizileri (Field Programmable Gate Arrays – FPGA) üzerinde gerçekleştirilmektedir. FPGA tasarımcıları tasarımlarının fikri mülkiyet hakkını (Intellectual Property - IP) korumak amacıyla genellikle şifreleme veya gizleme teknikleri kullanmaktadır. Birçok FPGA modeli üzerindeki konfigürasyonu korumak amaçlı bir sistem mimarisine sahiptir. FPGA geliştirme ortamında tasarımcı donanım tanımlama dili (hardware definition language - HDL) ve hazır kütüphaneler kullanarak gerçekleştirdiği IP'sini sentezley- erek FPGA üzerine yüklenebilecek hale getirir. Sentezleme sırasında tasarım önce netlist biçimine, ardından bitstream dosyası biçimine çevrilir. Tersine mühendislik yoluyla bitstream dosyası formatından netliste ve ardından tasarımın orijinal haline erişilebilmektedir. FPGA geliştirme aracı bitstream dosyasını oluştururken şifreleme seçeneği kullanılırsa bitstream dosyası şifreli olarak üretilir. Bitstream dosyasının şifrelenmesi önemli ölçüde güvenlik sağlamaktadır. FPGA üreticileri bitstream dosyasının elde edilebilmesine yönelik saldırı ve önlemlerle ilgili gelişmeleri takip ederek yeni güvenlik önlemlerini sistemlerine dahil etmektedir. FPGA ile gerçekleştirilmiş çözümlerin yaygınlaşması ile birlikte tasarımcılar IP'lerini oluştururken iş gücü ve zaman maliyetlerini düşürmek amacıyla tasarımın bazı özel tanımlı kısımlarını hazır IP olarak kullanmak istemektedir. Bazı işlemler için geliştirilmiş IP'ler hazır olarak FPGA geliştirme aracı ile sunulurken, bazı IP'lerin lisanslı olarak dış kaynaktan tedarik edilmesi gerekebilir. Dış kaynaktan tedarik edilmesi durumunda üçüncü bir taraf söz konusu olduğu için bu hazır IP'ler üçüncü taraf fikri mülkiyet hakkı (Third Party Intellectual Property - 3PIP) olarak anılmaktadır. Bazı 3PIP'ler FPGA üreticisi desteği ile geliştirme aracı ile katalog olarak sunulurken, bazısı doğrudan tasarımcı tarafından kullanıcıya sunulmaktadır. 3PIP'lerinin şifrelenmesi ve yönetimi için IEEE tarafından yayınlanmış tavsiye edilen uygulama standardı bulunmaktadır. FPGA üreticileri de bu standarda uymaktadır. 3PIP'lerin telif haklarını korumak için şifreleme yöntemi veya ayrık donanım bazlı çözümler kullanılabilir. Ayrık bir donanım kullanılması 3PIP için maliyeti artırırken aynı zamanda 3PIP kullanıcısının tasarımını zorlaştırmakta ve PCB maliyetini de yükseltmektedir. 3PIP şifreli olsa bile 3PIP içeren FPGA tasarımı sentezlenip bitstream dosyası üretilirken şifrelenmiş IP orijinal haline dönmektedir. şifrelenmeden üretilmiş bitstream dosyasına tersine mühendislik yapılarak 3PIP tasarımının orijinal hali elde edilebilir. 3PIP tasarımının orijinal haline FPGA üzerine yüklendikten sonra gelmesi sağlanabilirse 3PIP tasarımı için güvenli bir koruma sağlanmış olacaktır. Benzer problemler uygulamaya özgü tümleşik devreler (Application Specific Inte- grated Circuit - ASIC) içinde söz konusu olup farklı önlem yöntemleri geliştirilmiştir. Bu önlemlerden mantıksal kilitleme tekniği ASIC ürünlerin orijinal devre yapısına ilave anahtar girişleri ve mantık kapıları ekleyerek tasarım sonrası süreçlerde ASIC IP'sinin korunmasını sağlamaktadır. ASIC devre doğru anahtar değeri güvenli belleğe yüklenerek son kullanıcı aşamasında orijinal tasarımı gibi çalışmaktadır. Bu çalışmada amaç ASIC IP tasarımları için kullanılan mantıksal kilitleme tekniğinin 3PIP'lerde kullanılması sağlayacak bir sistem tasarımı yapmaktır. Bu amaçla FPGA üreticilerinin FPGA modellerine ekleyebilecekleri bir güvenlik modülü ve uygulanacak kripto mimari tasarımı yapılmıştır. 3PIP orijinal netlist yapısına mantıksal kilitleme uygulayarak ilave anahtar girişleri ve mantık kapıları eklenecektir. Kilitlenmiş 3PIP devresine ait doğru anahtar değeri FPGA içinde bulunan güvenlik modülü yardımıyla kripto mimari adımlar uygulanarak elde edilecek ve 3PIP orijinal haline dönerek çalışacaktır. Önerilen sistemde FPGA üreticileri güvenilir çözüm ortaklarıdır. Bu sistem uygulandığında 3PIP sadece FPGA üzerinde orijinal halinde bulunacak, güvenilmeyen taraflara karşı korunmuş olacaktır.
Özet (Çeviri)
Today, hardware designs are predominantly implemented on Field Programmable Gate Arrays (FPGAs) due to their ease of use, broad range of capabilities, and cost-effectiveness. In order to safeguard the intellectual property (IP) rights of their designs, FPGA developers commonly employ encryption or obfuscation techniques. Many FPGA platforms are equipped with architectural mechanisms specifically designed to protect configuration data. A designer utilizing an FPGA development tool synthesizes the created Intellectual Property (IP) using a Hardware Description Language (HDL) and predefined libraries, thereby making it deployable on the FPGA. During the synthesis process, the design is initially converted into a netlist and subsequently transformed into a bitstream file. Through reverse engineering techniques, it is possible to extract the netlist from the bitstream format and ultimately reconstruct the original design. If the encryption option is enabled during bitstream generation, the resulting bitstream file is produced in an encrypted form. Encrypting the bitstream file significantly enhances security. FPGA manufacturers closely monitor developments related to attacks and countermeasures aimed at unauthorized bitstream access, and continuously integrate new security mechanisms into their systems. With the increasing adoption of FPGA-based solutions, designers often seek to reduce labor and time costs by utilizing pre-designed Intellectual Property (IP) cores for specific parts of their designs. While certain IP cores are readily available through FPGA development tools, others may need to be licensed from external sources. When such cores are sourced externally, they are referred to as Third Party Intellectual Property (3PIP). Some 3PIPs are provided within the toolchain by FPGA vendors as part of an IP catalog, whereas others are delivered directly by independent designers to end users. To address the encryption and management of electronic design 3PIPs, the IEEE has issued a recommended practice standard, which FPGA vendors also adhere to. In order to protect the intellectual property rights of 3PIPs, either encryption techniques or discrete hardware-based solutions may be employed. However, using discrete hardware increases the cost of the 3PIP and complicates the design process for users, in addition to raising the cost of the printed circuit board (PCB). Even when a 3PIP is encrypted, the original IP may be reconstructed during synthesis and bitstream generation. If the bitstream is not encrypted, reverse engineering can be used to retrieve the original 3PIP design. Ensuring that the original design is only recovered after it has been loaded onto the FPGA would provide a secure means of protecting the 3PIP. In the scope of this study, the feasibility of unlocking a 3PIP on an FPGA using a key has been investigated. It was observed that this can be achieved through the application of logic locking techniques, which are commonly employed in Application-Specific Integrated Circuit (ASIC) products. Similar security challenges also arise in ASIC designs, prompting the development of various countermeasures, with research efforts in this area still ongoing. Logic locking enhances the security of ASIC intellectual property by incorporating supplementary key inputs and logic gates into the original circuit design, ensuring protection in the post-design stages. After fabrication and testing, the correct key value is loaded by the designer to ensure that the circuit functions as intended at the end-user stage. Various attack methodologies targeting logic locking have been studied, and corresponding countermeasures resistant to these attacks have been proposed. Chapter 2 provides a detailed analysis of ASIC and FPGA IP design processes, associated threats, and mitigation strategies. This thesis aims to adapt the logic locking technique, originally developed for ASIC IP designs, for secure use in 3PIP within FPGA environments. To achieve this goal, a cryptographic architecture and a dedicated security module capable of performing the necessary cryptographic operations have been designed. The proposed system is intended to function as an integrated component of the FPGA security architecture. Ownership of the designed system is attributed to FPGA vendors, who are expected to incorporate the security module as a feature in future FPGA models. In this framework, both 3PIP designers and end-users will utilize the system, while FPGA vendors are assumed to be trusted parties with respect to the protection of 3PIP designs. Within the scope of this study, the proposed cryptographic architecture incorporates the use of Keyed HMAC-SHA256 and RSA Digital Signature algorithms. The Keyed HMAC algorithm is employed to derive the correct key for the locked 3PIP and to verify its authenticity. On the other hand, the RSA digital signature algorithm is utilized to ensure the integrity and authenticity of the key used to lock the 3PIP, by verifying it prior to the synthesis process within the FPGA design tool. Chapter 4 provides detailed descriptions of the Keyed HMAC and RSA signature algorithms used in the system. Chapter 5 presents the design of the cryptographic architecture and the associated security module. It describes how the 3PIP designer applies logic locking to the original netlist structure of the 3PIP by inserting additional key inputs and logic gates. Subsequently, the cryptographic steps carried out by the FPGA manufacturer to generate the necessary parameters are outlined. Finally, the procedures for the 3PIP user to utilize the security module and the locked 3PIP are explained. The correct key required to unlock the locked 3PIP circuit is derived through the cryptographic operations performed by the on-chip security module within the FPGA. Once unlocked, the 3PIP will operate in its original form. This approach ensures that the original form of the 3PIP remains confined to the FPGA and is protected from untrusted entities. In addition, this section examines the impact of the logic locking technique on 3PIP circuits and the costs introduced by the LUL module. Chapter 6 presents the security analysis of the proposed system, including an evaluation of potential threats and attack scenarios. A comparative analysis is conducted against existing studies in the literature that aim to protect 3PIP designs. Subsequently, the validation procedures of the proposed system are described. In this context, the security module was implemented using AMD's Vivado tool and the VHDL language. The ITC99 benchmark circuits were utilized as representative 3PIPs. Logic locking was applied to the selected benchmark circuits using the Neos tool. After verifying the benchmark circuits through simulation, they were integrated with the developed security module, and the correct functionality of the system was confirmed via simulation. The conclusion chapter discusses the advantages and disadvantages of the proposed system and outlines potential improvements for future work.
Benzer Tezler
- Paralel hata ayıklama
Parallel debugging
SİNAN KUL
Yüksek Lisans
Türkçe
2014
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolAtatürk ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
YRD. DOÇ. DR. DENİZ DAL
- The Design and implemetation of a distributed DBMS for logob, a deductive data model with object predicates
Nesne tanımlı mantısal veri tabanı logob için, dağıtık veri tabanı yönetim sisteminin tasarım ve uygulaması
CÜNEYT SEVİM
Yüksek Lisans
İngilizce
1996
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolBoğaziçi ÜniversitesiDOÇ.DR. TAFLAN I. GÜNDEM
- Techniques for runtime monitoring and static verification of concurrent software
Koşut-zamanlı yazılımlar için çalışma-zamanı izleme ve durağan doğrulama teknikleri
TAYFUN ELMAS
Doktora
İngilizce
2010
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolKoç ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
DR. SHAZ QADEER
YRD. DOÇ. DR. SERDAR TAŞIRAN
- Açık hatla istasyon bölgelerinin hatada güvenli anklaşman tasarımı ve PLC de gerçeklenmesi
Fail-safe interlocking design of open line and station areas and implementation with PLC
MUHAMMED İKBAL YILDIZ
Yüksek Lisans
Türkçe
2021
Ulaşımİstanbul Teknik ÜniversitesiRaylı Sistemler Mühendisliği Ana Bilim Dalı
PROF. DR. MEHMET TURAN SÖYLEMEZ
- Dağıtık veritabanı konfigürasyonlu stok kontrol sistemi
Stock control system with distributed database
ASUMAN EROL