Key-Recovery Attack on Enhanced PSLL Techniques
IEEE Embedded Systems Letters, 2025

Abstract
Logic locking (LL) is an effective countermeasure that protects integrated circuits (ICs) against hardware-focused threats, such as intellectual property (IP) piracy and unauthorized overproduction in the IC supply chain. One group of LL techniques, called provably secure LL (PSLL) techniques, are prominent for their mathematically proven security guarantees. However, researchers have discovered vulnerabilities of PSLL to structural-test-based attacks. As a result, recent PSLL techniques, such as CAC2.0 and the MaxPO strategy, were designed to enhance the security of naive PSLL architecture against structural attacks. This letter questions the security guarantees of recent PSLL techniques, demonstrating that using point functions to hard-code the protected pattern in a functionality-stripped circuit makes it vulnerable to structural-test-based attacks. We develop a framework utilizing structural analysis and IC testing to recover the secret key with 100% accuracy.
BibTeX
@article{rajabi2025key,
title={Key-Recovery Attack on Enhanced PSLL Techniques},
author={Rajabi, Saeid and Yang, Chengmo and Patnaik, Satwik},
journal={IEEE Embedded Systems Letters},
year={2025},
publisher={IEEE}
}