DAF: An Effective Design-for-Testability Authorization Framework Based on Obfuscation Mechanisms for Defending Complex Attacks
Weizheng Wang, Xingxing Gong, Xiangqi Wang, Shuo Cai, Peng Liu, Naixue N. Xiong · IEEE Internet of Things Journal · 2024
The data privacy and security of Internet of Things (IoT) applications are progressively crucial and cryptography is frequently used to ensure security. Cryptographic hardware implementation is commonly adopted for high throughput and low-computational resources. The crypto circuits have to be strictly tested to guarantee the correctness of data. Scan-based design-for-testability (DFT) widely employed in the chip industry improves the controllability and observability of circuits. However, it facilitates illegal users to steal the internal data for cracking cryptographic keys. Many researchers have recently suggested effective defense technologies against scan-based attacks, but each technology has its own negative aspects. In this article, we propose an effective DFT authorization framework (DAF) based on obfuscation mechanisms. The authentication module is embedded to verify users’ keys, and it can empower each chip distinctive key to minimize the loss of key divulgence. If the test authorization key is accurate, the typical scan operation can be carried out. Conversely, if the key is inaccurate, the inserted obfuscation module comes into play to scramble the scan data. Additionally, a random number generation circuit is used to increase the uncertainty of data obfuscation, effectively preventing attackers from inferring sensitive information. Simulation results show that this design has a low overhead, and theoretical analysis demonstrates that the design has high security with no impact on the testability of the chip.