🤖 AI Summary
This work addresses the limitations of hardware reverse engineering in accounting for physical design decisions, particularly the difficulty of inferring design intent from clock networks. To this end, it proposes a placement-aware clock network recovery method that constructs a four-stage pipeline integrating gate-level netlists with layout information extracted from scanning electron microscopy (SEM) images. This approach achieves, for the first time, the recovery of clock distribution networks from manufactured chips to infer underlying design intent. Experimental evaluations on chips fabricated in a 450nm process node demonstrate the successful reconstruction of clock topologies and delay characteristics, enabling the quantification of critical metrics such as clock skew. By bridging this gap in the reverse analysis of physical designs, the study advances the state of the art in hardware security. All associated algorithms have been released as open source.
📝 Abstract
Hardware reverse engineering supports competitive analysis and hardware assurance by recovering information about an integrated circuit (IC) from its physical implementation. While existing techniques primarily recover the gate-level netlist, which represents logical functionality, they often overlook physical design decisions such as placement, routing, delay insertion, and interconnect optimization. The clock distribution network encapsulates many of these decisions; however, no prior published work has recovered this network from a fabricated IC to infer design intent. We present a layout-aware methodology that recovers and analyzes the clock distribution network by integrating a recovered gate-level netlist with layout information extracted from scanning electron microscope imagery. Our four-phase pipeline recovers clock-tree topology, buffering, gating and switching, interconnect delay, and crosstalk-mitigation measures. We demonstrate our methodology on a commercial 450 nm IC, recovering a global H-tree backbone with local X-tree-like branching, identifying an independent clock tree and global clock gating, quantifying latency, skew, and routing lengths, and confirming the absence of dedicated crosstalk mitigation. Together, these findings let us reason about the designer's intent. To encourage further research and support reproducibility, we release our clock tree recovery algorithm as open source.