SOAR: Secure Once, Adapt at Runtime With eFPGA-Based Redaction for IP Protection

Voktho Das, Kimia Zamiri Azar, Hadi Mardani Kamali · IEEE Access · 2025

The increasing complexity of modern system-on-chip (SoC) designs and the reliance on outsourcing have raised significant concerns about intellectual property (IP) confidentiality and integrity. eFPGA-based IP redaction has emerged as a robust countermeasure by replacing security-critical IPs with embedded FPGAs (eFPGAs), concealing their functionality through secret bitstreams. However, recent studies have revealed forms of black-box attacks, exploiting in/out queries to approximate the functionality of redacted IPs, leading to IP piracy. This paper proposes SOAR, a runtime-adaptive IP protection architecture that elevates eFPGA redaction from a static concealment technique to a dynamic and reconfigurable countermeasure. SOAR integrates two key mechanisms: (1) a lightweight runtime monitoring module embedded outside the eFPGA fabric to observe eFPGA in/out queries, enabling the detection of the flowused for black-box attacks; (2) logic obfuscation via dummy inputs/gates inside the fabric to enhance functional ambiguity and interfere attack procedure. Using these two key mechanisms, SOAR enables a real-time flush-and-configure capability (in response to attacks) that is uniquely enabled by the dynamic nature of eFPGAs. Implemented as a plug-and-play backend enhancement to the OpenFPGA platform, SOAR requires no manual changes to front-end design, making the process of IP protection fully automated. Our experiments demonstrate the effectiveness of our approach on multiple modules from a multicycle RISC-V processor, evaluating its impact on attack resilience, area, and power overhead using OpenFPGA for architecture-level synthesis and Cadence Genus for physical design.

Read the paper · More papers on PaperTik