RESAA: A Removal and Structural Analysis Attack Against Compound Logic Locking
Felipe Almeida, Levent Aksoy, Samuel Pagliarini · IEEE Transactions on Very Large Scale Integration (VLSI) Systems · 2025
The semiconductor industry’s paradigm shift toward fabless integrated circuit (IC) manufacturing has introduced security threats, including piracy, counterfeiting, hardware Trojans, and overproduction. In response to these challenges, various countermeasures, including logic locking (LL), have been proposed to protect designs and mitigate security risks. LL is likely the most researched form of intellectual property (IP) protection for ICs. A significant advance has been made with the introduction of compound LL (CLL), where more than one LL technique is concurrently utilized for improved resiliency against attacks. However, the vulnerabilities of LL techniques, particularly CLL, need to be explored further. This article presents a novel framework, RESAA, developed to classify designs locked by CLL, identify critical gates (CGs), and execute various attacks to uncover secret keys. RESAA is agnostic to specific LL techniques, offering comprehensive insights into CLL’s security scenarios. Experimental results demonstrate RESAA’s efficacy in identifying CGs, distinguishing segments corresponding to different LL techniques, and determining associated keys based on different threat models. In particular, for the oracle-less (OL) threat model, RESAA can achieve up to 92.6% accuracy on a relatively complex ITC’99 benchmark circuit. The results reported in this article emphasize the significance of evaluation and thoughtful selection of LL techniques, as all studied CLL variants demonstrated vulnerability to our framework. RESAA is also open-sourced for the community at large.