The growth of SOC devices in the latest technologies going high every day. Powerful side-channel analysis (SCA) attacks based on failure analysis (FA) techniques can bypass conventional countermeasures on integrated circuits (ICs), and therefore, break the entire system’s security. Laser Logic State Imaging (LLSI) from the IC backside is an example of such attacks, making the contactless probing of static on-die signals possible. Several countermeasures have been proposed to prevent optical probing attacks, such as LSI. However, these schemes are designed according to the laser properties and its impact on transistors, and hence, they have complex fabrication steps and large area overhead. As a result, they are difficult to verify and implement. In this paper, we propose a twofold detection self-timed sensor, which is the first attempt, to our knowledge, for an easy-to implement circuit-based countermeasure to thwart LLSI attacks. To perform LLSI, the attacker needs to freeze the clock at a point of interest and modulate the voltage supply line at a known frequency to leak the state of transistors through laser light reflections. With these two attack requirements in mind, we design, simulate, and implement clock- and voltage-based sensors that can detect VLSI attacks with very high confidence.
Introduction
Field Programmable Gate Arrays (FPGAs) are widely used in modern electronic systems because of their flexibility, reconfigurability, and high performance. However, the involvement of multiple stakeholders such as FPGA vendors, foundries, IP providers, system developers, and end users creates several security risks during design, fabrication, and deployment. Major threats include hardware Trojan insertion, reverse engineering, cloning, replay attacks, and information leakage. Therefore, secure FPGA design techniques are required to protect intellectual property and ensure system reliability.
The project focuses on improving FPGA security using logic locking and obfuscation techniques. Logic locking methods such as XOR/XNOR key gates prevent unauthorized access to FPGA designs, while obfuscation techniques like multiplexers and functional stripping make reverse engineering more difficult. These approaches help protect sensitive IP cores and reduce vulnerabilities caused by malicious modifications.
Problem Statement
Existing FPGA security solutions mainly focus on physical attack detection, such as laser injection and voltage-based sensor analysis. However, FPGA systems remain vulnerable to several attacks during the complete design lifecycle. There is a need for effective security mechanisms that can protect FPGA configurations, prevent hardware Trojans, and maintain trust among different stakeholders.
Objectives
The main objectives of the proposed system are:
Implement logic locking techniques using XOR/XNOR gates.
Apply obfuscation methods to hide critical design information.
Protect FPGA designs from reverse engineering and cloning attacks.
Detect and mitigate hardware Trojan threats.
Improve security against replay and side-channel attacks.
Enhance trust and reliability among FPGA manufacturers and users.
Scope of the Project
The study analyzes security challenges across the FPGA supply chain, including vendors, foundries, developers, and end users. It focuses on:
Identifying hardware Trojan vulnerabilities.
Evaluating reverse engineering and cloning risks.
Studying replay and side-channel attacks.
Implementing secure FPGA protection techniques.
Reducing information leakage from FPGA configurations.
Literature Review Summary
Previous research has explored various FPGA security solutions:
Hardware Trojan Detection: Techniques such as Physically Unclonable Functions (PUFs), laser logic state imaging, machine learning-based detection, and runtime monitoring have been proposed to identify malicious modifications.
Logic Locking: XOR/XNOR-based locking and key-gate insertion techniques protect FPGA designs against unauthorized access and SAT-based attacks.
Obfuscation: Multiplexer-based obfuscation and functional stripping approaches make FPGA reverse engineering more difficult.
Machine Learning-Based Security: ML algorithms help identify abnormal circuit behavior and detect potential hardware attacks.
Research shows that combining detection methods with protection mechanisms provides stronger security against modern FPGA threats.
Proposed Methodology
The proposed FPGA camouflage detection system combines hardware attack detection, machine learning-based anomaly detection, and logic locking techniques. The system evaluates FPGA devices under different attack conditions and monitors internal behavior to identify suspicious activities.
The methodology includes:
FPGA Security Testing
Development of test circuits to evaluate FPGA behavior.
Simulation of physical attacks, voltage variations, signal interference, and tampering attempts.
Monitoring voltage and circuit responses to detect anomalies.
Logic Locking and Obfuscation
Protecting critical IP blocks using key-based locking mechanisms.
Preventing unauthorized design access and cloning.
Machine Learning-Based Detection
Monitoring FPGA signals continuously.
Detecting abnormal patterns caused by hardware Trojans or attacks.
Enabling real-time protective responses.
System Modules
1. Reference Clock Generator Module
Generates stable clock signals required for FPGA operation.
Maintains synchronization between system modules.
Uses clock divider and reset control.
2. Test Circuit Generation Module
Creates FPGA test environments.
Includes sweep generators, configurable clock synthesizers, and Digital Phase-Locked Loops (DPLL).
Generates multiple clock conditions for security testing.
3. Attack Pattern Generation Module
Simulates different hardware attacks, including:
Side-channel attacks.
Replay attacks.
Corruption-based attacks.
Evaluates FPGA resistance against threats.
4. Dynamic Pattern Matching Algorithm
Detects abnormal patterns in FPGA operation.
Identifies possible side-channel attacks, replay attacks, and hardware modifications.
5. Integration Module
Combines all system components using a finite state machine.
Controls monitoring, detection, and response operations.
Provides synchronized communication between modules.
Low-power operation with minimal performance overhead.
Reduced dependence on offline verification methods.
Hardware Implementation
The system can be implemented using programmable devices such as the Xilinx XC9572XL CPLD, which provides configurable logic resources for developing FPGA security applications. The design includes programmable logic blocks and programming interfaces for implementing and testing security modules.
Conclusion
Side-channel attacks pose significant threats to System on Chip (SoC) platforms, particularly affecting the operations of FPGAs. The increasing integration of diverse functionalities onto a single silicon platform in modern chip designs has heightened the need for robust security measures, particularly encryption. Any side-channel attacks targeting FPGA devices can compromise the system’s integrity by manipulating logic operations, leading to unintended data leaks from external sources. In the proposed system, specialized test circuits are developed to closely monitor and analyze the impact of side-channel attacks.
The system model features a configurable high-speed clock switching network (HSwNw) that operates with multiple clock sources to simulate various attack scenarios. Additionally, a differential attack generator is integrated to introduce side-channel, corruption, and FPGA replay attacks into the application circuit for testing. The system’s performance is evaluated continuously through a Recurrent Pattern Verification (RPV) Algorithm, which classifies the effects of each attack.
The evaluation includes metrics such as power consumption, latency, and device utilization. Cryptographic principles and protective frameworks are typically employed to secure most SoC platforms, but under induced attacks, a leakage power of 0.009 watts was observed, demonstrating the system’s vulnerability and the importance of countermeasures.
References
[1] Rao Bommana, S. Veeramachaneni, S. Ershad, S. and Srinivas, M. B. (2025) “Mitigating Side Channel Attacks on FPGA through Deep Learning and Dynamic Partial Reconfiguration”, Scientific Reports, vol. 15, Article 13745.
[2] Zoni et al, D. (2025) “An FPGA-Based Open-Source Hardware-Software”, IEEE Transactions on Computers.
[3] Kat-te, S. and Fernandez, K. E. (2025) “SoK: Trusted Execution in SoC-FPGAs,” arXiv preprint.
[4] Sergej Meschkov, Daniel Lammers, Mehdi B. Tahoori, Amir Moradi, (2025) “Design and Implementation of a Physically Secure Open-Source FPGA and Toolchain”, CHES.
[5] Q. Hou, Z. Liu, Z. Yang and C. Yang, (2024) “Hardware Trojan Attacks on Reconfigurable Interconnections of FPGA-Based CNN Accelerators and a PUF-Based Countermeasure”, Micromachines, vol. 15, no. 1, 149.
[6] X. Li, S. Chai, L. Wang and H. Wang, (2023) “A Configurable and Automated Testing Framework for Hardware Trojan Detection in FPGAs”, in Proc. WCNA, LN EE.
[7] Jain, A. Zhou, Z. and Guin, U., (2023) TAAL “Tampering Attack on Any Key-based Logic Locked Circuits”. ACM journals, 26(4), pp.1-22.
[8] Shamsi, K. Meade, M. Li, T. Zhao, Z. Pan, D. Z and Jin, Y. (2023) “Cyclic obfuscation for creating SAT-unresolvable circuits,” in Proc. Great Lakes Symp. VLSI, pp. 173–178.
[9] Ribes, S. Malatesta, F. Garzo, G. and Palumbo, A. (2022) “Machine Learning-Based Classification of Hardware Trojans in FPGAs Implementing RISC-V Cores”.
[10] Ahmed, Q. Wiersema, T. and Platzner, M. (2022) “On the Detection and Circumvention of Bitstream-Level Trojans in FPGAs”, IEEE ISVLSI.