On the Security of Lightweight Homomorphic Obfuscation for Protecting Against Hardware Trojans

Tanvir Hossain, Matthew Showers, Mahmudul Hasan, Tamzidul Hoque · IACR Transactions on Cryptographic Hardware and Embedded Systems · 2026

Hardware Trojan (HT) attacks pose a critical threat to modern microelectronics by enabling the leakage of sensitive information, such as cryptographic keys, or by inducing functional faults. This risk is amplified in Commercial-Off-the-Shelf (COTS) processors, where users have limited control over the supply chain and cannot verify the integrity of integrated circuits. Existing countermeasures often fall short in this context, as they rely on trusted design houses or foundries and require access to design data for modification or analysis. Moreover, most golden-reference-free detection methods can only identify but not bypass HTs. To address these challenges, we present HOACS (Homomorphic Obfuscation Assisted Concealing of Secrets), a software-oriented framework that protects confidential data from HT-based leakage without any trust or modification at the hardware level. HOACS employs the Residue Number System (RNS) to homomorphically encode computations, transforming standard C-based programs into residue-obfuscated equivalents. Implemented as an LLVM compiler pass, HOACS automatically protects arbitrary programs with minimal developer effort. We evaluate HOACS across AES key expansion, RSA, and MAC (multiply–accumulate) operations on x86 (via gem5) and RISC-V platforms, including FPGA validation on the Cappuccino soft-core. Results confirm that plaintext secrets never appear in processor registers and that RNC-based encoding significantly disrupts side-channel leakage. A detailed threat and complexity analysis demonstrates that Trojan activation before encoding is mathematically improbable and that brute-force decoding of unknown moduli is computationally infeasible. Finally, performance comparisons show that HOACS achieves far lower overhead than existing fully or partially homomorphic encryption frameworks, offering a practical, lightweight obfuscation method for securing COTS processors in untrusted environments.

Read the paper · More papers on PaperTik