Hardware Trojans (HTs) are malicious blocks inserted into Systems on Chip (SoC) by untrusted parties in the IC design/manufacturing flow. They have been identified as a realistic threat, among others to the car safety and military. HTs aim to change SoCs’ behavior, ranging from denial of service, decreased reliability, to confidential information leakage. Such attacks lead to multi-billions dollars loss per year for the semiconductor industry. Countermeasures against HTs exist, divided into two categories: detection and prevention. Ten years of research have shown that detection is a very challenging task, knowing the stealthy nature of the threat and the multiple possible forms of HTs. Prevention consists in modifying the design flow to take into account security issues. Despite its potential cost, it represents a more effective way to overcome HT insertion. So-called Design-for-Hardware-Trust (DfHT) methods exist, with various goals and impacts on performance. The MOOSIC project proposes a framework dedicated to security that can be integrated into the conventional IC design flow. The goal is to take into account, as early in the design phase, both countermeasures against HTs and performance, to ensure that the SoC behavior is guaranteed despite untrusted IPs vendors or foundry. Towards this objective, the project envisions to establish and evaluate security properties and then integrate them during synthesis with multi-objective optimization techniques, which will be built on a mathematical modeling of the problem that takes into account both the performance and the HTs‘ effects. It is indeed necessary to find a good compromise between the level of security sought after and performance. The methodology will be validated on industrial use cases. In this way, the SoC will enable cybercrime avoidance without a significant additional cost. The project will be conducted by 2 research laboratories specialized in computer science and SoC design (LIRMM and LIP6), a public institute (CEA) dedicated to technological researches, and the “security science company” (Secure-IC) The project will be divided in 4 scientific work packages: 1. Architecture evaluation in terms of security and proposal of hardware solutions to improve it (LIRMM) 2. Proposal of a complete mathematical modeling of the problem (based on graph theory or mathematical programming) that supports all the constraints and objectives (security, area, frequency, power consumption) as well as optimal resolution strategies for automatic insertion of counter measures (CEA) 3. Proposal of a methodology integrating the model and the proposed hardware solutions (LIP6) 4. Validation on use-cases from the industry (Secure-IC) Cyber security is a major issue of the Internet of Things and the confidence that we can have in these things. Knowing that by 2020, there will be more than 25 billion connected objects in the world, representing an income of more than 4 trillion dollars, realizing that a connected object contains a HT once it is in use would lead not only to a huge cost but would also undermine the viability of whole business sectors. This threat is comes from the fact that, in the race for low cost, designers no longer control all the steps of the design/manufacturing flow and rely on (possibly untrusted) third parties. Taking into account the problem early in the design phase, and thus ensure a certain confidence in the hardware, will have a significant economic impact. In this project, we propose not only to take into account the security aspects in the design phase but also other usual constraints such as delay and power consumption. This represents a great scientific advance. For the time being, the security aspect indeed generally treated independently of the others. This is perfectly relayed by the DEFI 9 “Liberté et sécurité de l’Europe, de ses citoyens et de ses residents” of the ANR Action Plan 2018.
