Searcharxiv⌕ Search

arXiv subjects

Kolja Dorschel

Publications and source records attributed to Kolja Dorschel.

2 recordsLinked to original sources

SoK: From Silicon to Netlist and Beyond $-$ Two Decades of Hardware Reverse Engineering Research

Hardware serves as the root of trust in modern computing systems, making Hardware Reverse Engineering (HRE) essential for security assurance$-$from design verification and supply-chain integrity to vulnerability discovery. We scope HRE to netlist recovery and its subsequent analysis, spanning the three subdomains of Integrated Circuit (IC), Field-Programmable Gate Array (FPGA), and netlist reverse engineering. These subdomains differ in their methodologies, but share core processes and are shaped by common requirements and legal constraints of the same stakeholders. Despite an increasing number of publications, the field lacks a systematic understanding of how these obstacles have stunted the research ecosystem. To address this gap, we present the first large-scale Systematization of Knowledge (SoK) of the HRE workflow, analyzing 187 peer-reviewed publications. Across all three subdomains, we identify eleven concrete technical challenges$-$from a widening gap between academic research and modern semiconductor technology nodes to overly idealized assumptions in netlist analysis$-$and propose actionable directions for each. A retrospective evaluation of all 30 published artifacts reveals that key results could be reproduced for only seven, a mere 4 % of all 187 papers in our corpus, confirming a systemic reproducibility crisis. We trace both the technical and reproducibility challenges to three structural barriers that recur across all subdomains: scarce reusable artifacts, missing benchmarks, and unresolved legal constraints on data sharing and collaboration. Based on these findings, we derive stakeholder-specific recommendations for academia, industry, and government to transition HRE from isolated research silos toward a collaborative discipline capable of assuring increasingly complex, global hardware supply chains.

cs.CR↗

Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell Libraries

At S&P 2023, Puschner et al. made a valuable dataset for hardware Trojan detection research publicly available. It contains a complete set of Scanning Electron Microscope (SEM) images of four different digital Integrated Circuits (ICs) fabricated at progressively smaller semiconductor technology nodes. Puschner et al. reported preliminary evidence that feature sizes affect Trojan detection performance, but they were unable to disentangle effects caused by insertion strategies or by degrading image quality from those intrinsic to the underlying standard cell libraries. Distinguishing those causes, however, is crucial to understand whether improved tooling (e.g., higher resolution imaging equipment) can remove the observed technology bias, or whether susceptibility to stealthy hardware Trojans is indeed an inherent property of a cell library. In this work, we dive deep into the S&P 2023 dataset to answer these questions. We devise alternative metrics to those of Puschner et al., in order to assess and compare the potential susceptibility of standard cell libraries more meaningfully. We find clear differences between the evaluated process nodes. However, in all cases we identify cells that implement distinct logic functions yet are visually indistinguishable in backside SEM images. We exploit this property to construct stealthy, standard-cell-based hardware Trojans and present a concrete case study: a privilege-escalation backdoor in an Ibex RISCV core. Our results demonstrate that cell libraries can - and should - be evaluated for their potential "Trojanizability", and we recommend practical defenses.

cs.CR↗