{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T10:40:42Z","timestamp":1779878442336,"version":"3.53.1"},"reference-count":24,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2024,5,3]],"date-time":"2024-05-03T00:00:00Z","timestamp":1714694400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"crossref","award":["FA8650-18-1-7821"],"award-info":[{"award-number":["FA8650-18-1-7821"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2024,5,31]]},"abstract":"<jats:p>\n            Due to the inclination towards a fab-less model of integrated circuit (IC) manufacturing, several untrusted entities get white-box access to the proprietary intellectual property (IP) blocks from diverse vendors. To this end, the untrusted entities pose security-breach threats in the form of piracy, cloning, and reverse-engineering, sometimes threatening national security. Hardware obfuscation is a prominent countermeasure against such issues. Obfuscation allows for preventing the usage of the IP blocks without authorization from the IP owners. Due to finite state machine (FSM) transformation-based hardware obfuscation, the design\u2019s FSM gets transformed to make it difficult for an attacker to reverse-engineer the design. A secret key needs to be applied to make the FSM functional, thus preventing the usage of the IP for unintended purposes. Although several hardware obfuscation techniques have been proposed, due to the inability to analyze the techniques from the attackers\u2019 standpoint, numerous vulnerabilities inherent to the obfuscation methods go undetected unless a true adversary discovers them. In this article, we present a collaborative approach between two entities\u2014one acting as an attacker or\n            <jats:italic>red team<\/jats:italic>\n            and another as a defender or\n            <jats:italic>blue team<\/jats:italic>\n            , the first systematic approach to replicate the real attacker-defender scenario in the hardware security domain, which in return strengthens the FSM transformation-based obfuscation technique. The\n            <jats:italic>blue team<\/jats:italic>\n            transforms the underlying FSM of a gate-level netlist using state space obfuscation. The\n            <jats:italic>red team<\/jats:italic>\n            plays the role of an adversary or evaluator and tries to unlock the design by extracting the unlocking key or recovering the obfuscation circuitries. As the key outcome of this red team\u2013blue team effort, a robust state space obfuscation methodology is evolved showing security promises.\n          <\/jats:p>","DOI":"10.1145\/3640461","type":"journal-article","created":{"date-parts":[[2024,3,5]],"date-time":"2024-03-05T12:10:11Z","timestamp":1709640611000},"page":"1-18","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Security Evaluation of State Space Obfuscation of Hardware IP through a Red Team-Blue Team Practice"],"prefix":"10.1145","volume":"29","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7397-7785","authenticated-orcid":false,"given":"Md Moshiur","family":"Rahman","sequence":"first","affiliation":[{"name":"Electrical and Computer Engineering Department, University of Florida, Gainesville, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0476-7985","authenticated-orcid":false,"given":"Jim","family":"Geist","sequence":"additional","affiliation":[{"name":"Computer Science Department, University of Central Florida, Orlando, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3661-746X","authenticated-orcid":false,"given":"Daniel","family":"Xing","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, University of Maryland, College Park, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8213-582X","authenticated-orcid":false,"given":"Yuntao","family":"Liu","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, University of Maryland, College Park, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5445-904X","authenticated-orcid":false,"given":"Ankur","family":"Srivastava","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, University of Maryland, College Park, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1001-4789","authenticated-orcid":false,"given":"Travis","family":"Meade","sequence":"additional","affiliation":[{"name":"Computer Science Department, University of Central Florida, Orlando, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8791-0597","authenticated-orcid":false,"given":"Yier","family":"Jin","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, University of Florida, Gainesville, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6082-6961","authenticated-orcid":false,"given":"Swarup","family":"Bhunia","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, University of Florida, Gainesville, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,5,3]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"291","volume-title":"USENIX Security Symposium","author":"Alkabani Yousra","year":"2007","unstructured":"Yousra Alkabani and Farinaz Koushanfar. 2007. Active hardware metering for intellectual property protection and security. In USENIX Security Symposium. 291\u2013306."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2019.8740844"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2009.2028166"},{"key":"e_1_3_1_5_2","volume-title":"Cybersecurity??? Attack and Defense Strategies: Infrastructure Security with Red Team and Blue Team Tactics","author":"Diogenes Yuri","year":"2018","unstructured":"Yuri Diogenes and Erdal Ozkaya. 2018. Cybersecurity??? Attack and Defense Strategies: Infrastructure Security with Red Team and Blue Team Tactics. Packt Publishing Ltd."},{"issue":"2","key":"e_1_3_1_6_2","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1109\/TCAD.2017.2697960","article-title":"Novel dynamic state-deflection method for gate-level design obfuscation","volume":"37","author":"Dofe Jaya","year":"2017","unstructured":"Jaya Dofe and Qiaoyan Yu. 2017. Novel dynamic state-deflection method for gate-level design obfuscation. IEEE Trans. Comput.-aid. Des. Integ. Circ. Syst. 37, 2 (2017), 273\u2013285.","journal-title":"IEEE Trans. Comput.-aid. Des. Integ. Circ. Syst."},{"key":"e_1_3_1_7_2","doi-asserted-by":"crossref","unstructured":"Marc Fyrbiak et\u00a0al. 2018. On the difficulty of FSM-based hardware obfuscation. IACR Transactions on Cryptographic Hardware and Embedded Systems (2018) 293\u2013330.","DOI":"10.46586\/tches.v2018.i3.293-330"},{"key":"e_1_3_1_8_2","first-page":"1","volume-title":"57th ACM\/IEEE Design Automation Conference (DAC\u201920)","author":"Geist J.","year":"2020","unstructured":"J. Geist, T. Meade, S. Zhang, and Y. Jin. 2020. RELIC-FUN: Logic identification through functional signal comparisons. In 57th ACM\/IEEE Design Automation Conference (DAC\u201920). 1\u20136."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1613\/jair.1638"},{"key":"e_1_3_1_10_2","first-page":"263","volume-title":"22nd International Symposium on Fault-Tolerant Computing (FTCS\u201922)","author":"Kajihara Seiji","year":"1992","unstructured":"Seiji Kajihara, Haruko Shiba, and Kozo Kinoshita. 1992. Removal of redundancy in logic circuits under classification of undetectable faults. In 22nd International Symposium on Fault-Tolerant Computing (FTCS\u201922). IEEE, 263\u2013270."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116261"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2001.932214"},{"key":"e_1_3_1_13_2","first-page":"67","volume-title":"IEEE International Symposium on Hardware-Oriented Security and Trust (HOST\u201913)","author":"Li Wenchao","year":"2013","unstructured":"Wenchao Li, Adria Gascon, Pramod Subramanyan, Wei Yang Tan, Ashish Tiwari, Sharad Malik, Natarajan Shankar, and Sanjit A. Seshia. 2013. WordRev: Finding word-level structures in a sea of bit-level gates. In IEEE International Symposium on Hardware-Oriented Security and Trust (HOST\u201913). IEEE, 67\u201374."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203757"},{"key":"e_1_3_1_15_2","volume-title":"IEEE International Symposium on Circuits and Systems (ISCAS\u201916)","author":"Meade Travis","year":"2016","unstructured":"Travis Meade, Yier Jin, Mark Tehranipoor, and Shaojie Zhang. 2016. Gate-level netlist reverse engineering for hardware security: Control logic register identification. In IEEE International Symposium on Circuits and Systems (ISCAS\u201916). IEEE."},{"key":"e_1_3_1_16_2","first-page":"90","volume-title":"24th Asia and South Pacific Design Automation Conference (ASP-DAC\u201919)","author":"Meade Travis","year":"2019","unstructured":"Travis Meade, Jason Portillo, Shaojie Zhang, and Yier Jin. 2019. NETA: When IP fails, secrets leak. In 24th Asia and South Pacific Design Automation Conference (ASP-DAC\u201919). IEEE, 90\u201395."},{"key":"e_1_3_1_17_2","first-page":"655","volume-title":"21st Asia and South Pacific Design Automation Conference (ASP-DAC\u201916)","author":"Meade Travis","year":"2016","unstructured":"Travis Meade, Shaojie Zhang, and Yier Jin. 2016. Netlist reverse engineering for high-level functionality reconstruction. In 21st Asia and South Pacific Design Automation Conference (ASP-DAC\u201916). IEEE, 655\u2013660."},{"key":"e_1_3_1_18_2","first-page":"1","volume-title":"IEEE International Symposium on Circuits and Systems (ISCAS\u201917)","author":"Meade Travis","year":"2017","unstructured":"Travis Meade, Zheng Zhao, Shaojie Zhang, David Pan, and Yier Jin. 2017. Revisit sequential logic obfuscation: Attacks and defenses. In IEEE International Symposium on Circuits and Systems (ISCAS\u201917). IEEE, 1\u20134."},{"key":"e_1_3_1_19_2","article-title":"Common Evaluation Platform","author":"Technology Massachusetts Institute of","unstructured":"Massachusetts Institute of Technology. 2022. Common Evaluation Platform. Retrieved from https:\/\/github.com\/mit-ll\/CEP","journal-title":"R"},{"key":"e_1_3_1_20_2","first-page":"1","volume-title":"Asian Hardware Oriented Security and Trust (AsianHOST\u201919)","author":"Portillo Jason","year":"2019","unstructured":"Jason Portillo, Travis Meade, John Hacker, Shaojie Zhang, and Yier Jin. 2019. RERTL: Finite state transducer logic recovery at register transfer level. In Asian Hardware Oriented Security and Trust (AsianHOST\u201919). IEEE, 1\u20136."},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","unstructured":"Md Moshiur Rahman and Swarup Bhunia. 2023. Practical Implementation of robust state-space obfuscation for hardware IP protection. IEEE Transactions on Very Large Scale Integration Systems (VLSI\u201923). DOI:10.36227\/techrxiv.21405075.v1","DOI":"10.36227\/techrxiv.21405075.v1"},{"key":"e_1_3_1_22_2","article-title":"Minisat v1.13-a SAT solver with conflict-clause minimization","author":"S\u00f6rensson Niklas","year":"2005","unstructured":"Niklas S\u00f6rensson and Niklas Een. 2005. Minisat v1.13-a SAT solver with conflict-clause minimization. In International Conference on Theory and Applications of Satisfiability Testing.","journal-title":"International Conference on Theory and Applications of Satisfiability Testing"},{"issue":"1","key":"e_1_3_1_23_2","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1137\/0201010","article-title":"Depth-first search and linear graph algorithms","volume":"2","author":"Tarjan Robert","year":"1972","unstructured":"Robert Tarjan. 1972. Depth-first search and linear graph algorithms. SIAM J. Comput. 2, 1 (1972), 146\u2013160.","journal-title":"SIAM J. Comput."},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","unstructured":"S. Wallat N. Albartus S. Becker M. Hoffmann M. Ender M. Fyrbiak A. Drees S. Maa\u00dfen and C. Paar. 2019. Highway to HAL: open-sourcing the first extendable gate-level netlist reverse engineering framework. In Proceedings of the 16th ACM International Conference on Computing Frontiers. 392\u2013397. DOI:10.1145\/3310273.3323419","DOI":"10.1145\/3310273.3323419"},{"key":"e_1_3_1_25_2","first-page":"1","volume-title":"IFIP\/IEEE International Conference on Very Large Scale Integration (VLSI-SoC\u201917)","author":"Yasin Muhammad","year":"2017","unstructured":"Muhammad Yasin and Ozgur Sinanoglu. 2017. Evolution of logic locking. In IFIP\/IEEE International Conference on Very Large Scale Integration (VLSI-SoC\u201917). IEEE, 1\u20136."}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3640461","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3640461","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:58:18Z","timestamp":1750294698000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3640461"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,3]]},"references-count":24,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2024,5,31]]}},"alternative-id":["10.1145\/3640461"],"URL":"https:\/\/doi.org\/10.1145\/3640461","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"value":"1084-4309","type":"print"},{"value":"1557-7309","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,5,3]]},"assertion":[{"value":"2022-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-12-17","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-05-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}