ConceptioArchivearXiv CS
arXiv CSopen access

Implementing Homomorphic Encryption-Based Logic Locking in System-on-Chip Designs

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021

1

Implementing Homomorphic Encryption-Based Logic Locking in System-on-Chip Designs

arXiv:2607.28542v1 [cs.CR] 30 Jul 2026

Ye Ziyang, Student Member, IEEE, Makoto Ikeda, Senior Member, IEEE

Abstract—This study presents a logic locking scheme based on the binary Ring Learning With Errors algorithm, implemented in a RISC-V System-on-Chip design. Unlike traditional logic locking methods that require providing users with raw locking parameters, the proposed approach secures critical logic paths in the privilege switching process without exposing these sensitive parameters. The implemented locking module itself consumes 3519 Look-Up Tables and 2645 Registers, leading to an overall overhead of 6.0% in Look-Up Tables and 6.9% in Registers compared to the baseline system. The unlock process requires about 2.6µs, introducing moderate performance impact, primarily affecting system-level operations while preserving user-level computational efficiency. Index Terms—Hardware security, cryptography, logic locking, homomorphic encryption, learning with errors.

I. I NTRODUCTION

H

ARDWARE security has become increasingly vital in critical infrastructure and everyday life. The integrity of hardware components fundamentally influences the security of entire computing ecosystems, playing a crucial role in safeguarding sensitive data, personal privacy, and proprietary information. Currently, reverse engineering techniques [1] pose significant challenges to the integrity of digital circuits. Upon successful reverse engineering of a circuit, adversaries can execute malicious modifications, potentially compromising its intended functionality and security properties. Logic locking has emerged as a promising countermeasure to these vulnerabilities. Traditional logic locking techniques, while widely adopted for hardware security, face two significant challenges. First, existing logic locking methods, such as [2], utilize identical parameters for both locking and unlocking operations, making them susceptible to parameter leakage and potentially exposing the original circuit design to malicious actors. Second, the emergence of quantum computing threatens the fundamental security assumptions of current logic locking methods, particularly those based on Boolean satisfiability (SAT) problems. Recent advances in quantum SAT algorithms [3] have demonstrated the potential to reduce SAT problem complexity to e0.7n , significantly undermining the computational security of traditional logic locking approaches. These challenges create an urgent need for more robust hardware security solutions that can withstand both contemporary and future threats. The authors are with the Department of Electrical Engineering and Information Systems, Graduate School of Engineering, The University of Tokyo, Tokyo, Japan (email: [email protected]; [email protected]).

To address these challenges, we propose a novel approach that integrates homomorphic encryption, specifically the binary Ring Learning With Errors (bin-RLWE) scheme [4], with logic locking techniques. Our solution focuses on securing the privilege switching process in RISC-V-based SoC designs, implementing encryption operations in critical logic paths while maintaining system functionality. We implement and evaluate our approach on a RISC-V SoC based on the Rocket-Chip generator [5], providing detailed analysis of area overhead, performance impact, and security implications. The key contributions of this work include: • A logic locking scheme that prevents parameter leakage through homomorphic encryption. • An implementation of lattice-based cryptography in hardware security, providing potential quantum resistance. • Experimental validation demonstrating the impact on the system performance. The structure of this paper is as follows: Section 2 provides essential background information and a discussion of related work in the domains of logic locking and homomorphic encryption. Section 3 presents a detailed description of the proposed bin-RLWE-based logic locking scheme. Section 4 elucidates the experimental setup and analyzes the results obtained. Section 5 offers a comparison with related works and a discussion of the findings. Finally, Section 6 concludes the paper. II. BACKGROUND AND R ELATED W ORKS A. Logic Locking Logic locking is a hardware security technique designed to protect integrated circuit designs from unauthorized reproduction and tampering. The fundamental principle involves modifying the original circuit design through the insertion of specific locking structures, thereby ensuring that the circuit only functions correctly when provided with the appropriate key. Logic locking typically entails the insertion of additional logic gates (e.g., XOR or XNOR) at strategic points within the circuit, rendering correct functionality dependent on a key input. Figure 1 illustrates a basic implementation of logic locking, where K0 = 0, K1 = 1 represents the correct key. While these techniques have demonstrated promise, they face several significant challenges. The insertion of locking structures frequently results in increased silicon area and

0000–0000/00$00.00 © 2021 IEEE

JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021

2

III. P ROPOSED M ETHOD : L OGIC L OCKING BASED ON H OMOMORPHIC E NCRYPTION This study presents an approach that integrates homomorphic encryption technology with logic locking, applying it to the privilege switching process of SoC designs. This method enhances hardware security by introducing encryption operations in critical logic paths. The core concept leverages the unique characteristics of homomorphic encryption to perform operations on encrypted data without full decryption, thereby preserving the confidentiality of critical logic.

Fig. 1. Basic example of combinational logic locking: a 2:1 selector with logic locking implemented through inserted XOR and XNOR gates, where the key is K0 = 0, K1 = 1.

power consumption, particularly in complex circuits. Moreover, the development of attack methods, such as SAT-based attacks [6] and side-channel analysis [7], has exposed vulnerabilities in many logic locking schemes. A critical concern with traditional logic locking is the potential for complete design recovery if the unlock key is compromised. This risk is particularly unacceptable in highly sensitive applications. Furthermore, the security of many logic locking schemes relies on the computational difficulty of solving SAT problems, which may be vulnerable to efficient solving algorithms in a quantum computing environment [3], [8], [9]. B. Homomorphic Encryption Homomorphic encryption is a cryptographic paradigm that enables computations to be performed on encrypted data without requiring decryption, thus preserving data privacy during processing. The concept was initially proposed by Rivest, Adleman, and Dertouzos in 1978 [10]. However, it was not until 2009 that Craig Gentry introduced the first feasible fully homomorphic encryption (FHE) scheme based on ideal lattices [11]. Lattice-based homomorphic encryption schemes, particularly those based on the Ring Learning with Errors (RLWE) problem, have gained prominence due to their efficiency and potential resistance to quantum attacks. The bin-RLWE scheme, a variant of RLWE-based encryption, offers reduced computational and storage overhead through binarized noise and lower sampling depth [4]. The integration of homomorphic encryption techniques with hardware security measures presents a promising opportunity to address the vulnerabilities of traditional logic locking while leveraging the privacy-preserving properties of encrypted computation. This approach forms the foundation of our proposed bin-RLWE-based logic locking scheme, which aims to provide protection against both key leakage and potential quantum attacks.

A. Implementation Overview In our implementation, we identify and split a critical logic cone within the SoC’s privilege switching logic to obtain intermediate input/output. We then selectively flip certain bits of the original intermediate output, with these flipped bits constituting the key K. The modified intermediate output is subsequently directed to an encryption path, which encodes and encrypts the data into the ciphertext domain. The encrypted data is then transmitted to a decryption path, while a software control interface inputs the encrypted key Kenc (the ciphertext domain representation of K) to the module. A homomorphic XOR operation is performed, combining Kenc with the encrypted intermediate value. Finally, the decryption result yields the original intermediate input, which is then reconnected to the logic cone. Figure 2 illustrates the overall logic diagram of this process. Notably, our implementation employs shift convolution for polynomial multiplication operations, achieving compact area utilization for smaller polynomial lengths. This approach establishes a linear correlation between latency and polynomial length. B. Homomorphic Encryption Algorithm We selected the bin-RLWE algorithm as the foundation for our homomorphic encryption scheme. To accommodate the

Fig. 2. Proposed homomorphic encryption-based logic locking implementing procedure and architecture: the integration of the logic locking module is at a middle point of the processor privilege switching logic, with resource sharing between encryption and decryption paths.

JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021

constraints of hardware implementation, we have optimized the algorithm by modifying the parameters. We decreased the ciphertext length to minimize computation cycles and hardware resource consumption. The bit depth of the ciphertext domain is reduced to strike a balance between security and error rate. A notable characteristic of bin-RLWE is its use of a binary distribution (0 and 1) for noise values. The noise strength is determined by the depth of the ciphertext domain, with shallower depths resulting in stronger noise, higher error rates, and increased security. While shortening the ciphertext length reduces the difficulty of potential attacks, it significantly decreases computation cycles and hardware overhead. C. Encryption and Decryption Process Algorithm 1 delineates the overall procedure for our homomorphic encryption-based logic locking scheme. Following homomorphic computation, the result obtained is the original intermediate input with added noise. When the noise strength remains below a certain threshold, the decryption result maintains the correctness of the original logic. Due to the reduction in the bit depth of the ciphertext domain, we observed an increase in the error rate. To mitigate this, our current implementation incorporates XOR check codes. We add Error-Correcting Codes (ECC) to the result after flipping the original output and verify the decryption result. If the verification fails, the encryption process is repeated. Future iterations will introduce more robust ECCs to enhance performance and reliability. D. Key Management and Security Features In our implementation of Algorithm 1, we employ a twopart approach for Keydec : One part is stored in tamper-proof memory burned into the chip by the provider, while the other part is generated by hardware at power-up to prevent replay attacks. The use of tamper-proof memory prevents physical attacks from extracting Keydec , which could otherwise enable attackers to decrypt Kenc . Upon power-up, the system queries the key provider, supplying the chip number and a power-up-specific random number. The key provider retrieves the corresponding pre-burned content using the chip number and combines it with the random number to create Keydec . Subsequently, Keyenc is derived from Keydec , and the locking parameter is encrypted using Keyenc before being returned to the chip. During the decryption process, the chip only needs to provide the encrypted locking parameter post-locking, thereby preventing leakage of the original encrypted parameter. The implementation of step (5) in Algorithm 1 is achieved by directly modifying the chip’s logic netlist. While we position the addition of the locking parameter K before the encryption and decryption process in our current implementation, alternative placements—either after the process or simultaneously before and after—are also feasible. E. Hardware and Software Integration For the hardware implementation, we have developed a Pseudo-Random Number Generator (PRNG) based on Linear

3

Algorithm 1 Homomorphic Encryption-based Logic Locking Parameters: n: Number of bits in input and output q: Modulus of the ring Input: K: Locking parameter determined by the chip designer Oorigin : Original intermediate output Output: Iorigin : Original intermediate input Variables: Keydec : Decryption key Keyenc0,1 : First and second part of the encryption key Olock : Locked intermediate output Oenc : Locked and encrypted intermediate output Kenc : Encrypted locking parameter Tmid : Intermediate temporary variable $ ei ← {0, 1}n , for i ∈ {0, 1, 2, 3, 4, 5, 6, 7} Functions: E XTEND: Extend from binary to ring R EDUCE: Reduce from ring to binary K EY PAIR G ENERATION Keydec ← e0 (1) $ (2) a1 ← Znq a0 ← −(e1 + a1 · Keydec ) (3) (Keyenc0 , Keyenc1 ) ← (a0 , a1 ) (4) E NCRYPTION Olock ← E XTEND(Oorigin ⊕ K) (5) Oenc0 ← Olock + Keyenc0 · e2 + e3 (6) Oenc1 ← Keyenc1 · e2 + e4 (7) L OCKING PARAMETER E NCRYPTION Kenc0 ← E XTEND(K) + Keyenc0 · e5 + e6 (8) Kenc1 ← Keyenc1 · e5 + e7 (9) D ECRYPTION Tmid0 ← Oenc0 + Kenc0 (10) Tmid1 ← Oenc1 + Kenc1 (11) Odec ← Tmid0 + Tmid1 · Keydec (12) Iorigin ← R EDUCE(Odec ) (13) O UTPUT Odec = Tmid0 + Tmid1 · Keydec = (Oenc0 + Kenc0 ) + (Oenc1 + Kenc1 ) · Keydec = (Olock + a0 · e2 + e3 + E XTEND(K) + a0 · e5 + e6 ) + (a1 · e2 + e4 + a1 · e5 + e7 ) · e0 = (Olock + E XTEND(K)) − (e2 + e5 ) · e1 + (e4 + e7 ) · e 0 + e 3 + e 6 N OISE = −(e2 + e5 ) · e1 + (e4 + e7 ) · e0 + e3 + e6 R EDUCE(Olock + E XTEND(K)) = Oorigin ⊕ K ⊕ K = Oorigin

JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021

Feedback Shift Registers (LFSR) for homomorphic encryption. On the software side, we have modified the Linux kernel’s interrupt and exception handling code to interact with the logic locking module at the entry point. This interaction includes key writing and waiting for the privilege level switch to complete. These modifications were necessary to accommodate the additional clock cycles required for the encryption and decryption process, which would otherwise disrupt the standard operation of the Linux kernel. In our modified system, when an interrupt occurs, the processor maintains a low privilege level upon entering the interrupt handling function. The system only transitions to a high privilege level after the key is written via the logic lock handler and the related logic operations are completed. IV. E XPERIMENTAL D ESIGN AND R ESULTS A. Experimental Setup Our experimental platform utilized Xilinx’s XC7K160T FPGA for implementing and testing our proposed logic locking method. The SoC design operated within a GNU/Linux environment, specifically kernel version 6.1.6, with GCC version 14.2.0 serving as the compilation environment. The SoC design based on RocketChip 1.6.0 [5] and Chipyard 1.11.0 [12] was shown in Figure 4. B. Performance Evaluation Methodology To assess the impact of our proposed method on system performance, we employed the BYTE UNIX Benchmarks (Version 5.1.3) [13] as our evaluation tool. This benchmark suite encompasses a series of system-level performance tests, offering a comprehensive reflection of various aspects of operating system performance. We used the benchmark’s Index Score as our performance indicator, which measures performance relative to a baseline Sun SPARCstation 20 Workstation SM61. C. Performance Results and Analysis The experimental results, as illustrated in Figure 3, revealed several noteworthy performance changes:

Fig. 3. Performance comparison of Unixbench: baseline vs. locked implementation.

4

1. System Call Performance: We observed a significant decrease in system call performance, primarily attributed to the additional encryption and decryption processes triggered by privilege level switching during system calls. Specifically, the System Call Overhead Index decreased from 28.9 to 19.4, representing a substantial 32.9% reduction. 2. File Operations: Operations involving privilege level switching, such as file copying, exhibited varying degrees of performance decline. Depending on the specific file copying pattern, performance decreased to between 94.6% and 97.7% of the original speed. 3. Pipe Operations: Pipe Throughput decreased to 91.3% of its original value, indicating a moderate impact on interprocess communication efficiency. 4. Computational Performance: Notably, general computational performance, as indicated by Dhrystone and Whetstone test results, remained largely unaffected by our proposed method. This observation suggests that our approach primarily impacts system-level operations while having minimal effect on user-level computational tasks. D. Security Analysis The security of our method is based on the bin-RLWE algorithm, which employs binary noise instead of Gaussian noise. This approach renders our method average-case safe rather than worst-case safe [14]. The original bin-RLWE parameters (n=256, bitdepth=8 & q=256) provide a security level of 84 bits [4]. According to the primal attack estimator in [15], our current implementation—employing parameters of n=54, bitdepth=7 & q=128 —results in a diminished security level of 41 bits. However, it is important to note that the primal attack estimator assumes an infinite number of Keyenc samples for a single Keydec . When the number of samples is limited, the attack difficulty increases significantly [18]. Since our scheme generates Keydec at each power-up, and for each corresponding Keydec only one Keyenc is generated, from an LWE perspective, it is impossible to obtain an exact solution. A key advantage of our method over traditional logic locking approaches is that users can only access ciphertext-domain locking parameters, with the original locking parameters never exposed. This characteristic significantly enhances system security by eliminating the possibility of users recovering the

Fig. 4. Block Diagram of SoC Architecture.

JOURNAL OF LATEX CLASS FILES, VOL. 14, NO. 8, AUGUST 2021

TABLE I H ARDWARE R ESOURCE C ONSUMPTION

LUTs Regs BRAMs DSPs

System w/o Locking 56526 35794 25 15

System with Locking 59936 (+6.0%) 38262 (+6.9%) 25 15

Locking Module 3519 2645 0 0

TABLE II C OMPARISON WITH L OGIC L OCKING AND RLWE I MPLEMENTATIONS This This* [2] [16] [17] Area Overhead 6.0%/6.9% 1.43% (n,q,σ) (54,128,-) (201,128,-) - (256,4096,8.35) (256,7681,11.31) LUTs 3519 13497 1974+1698 1381 Regs 2645 10077 2698+1958 1179 Latency 2.6µs 2.5µs 47µs 193µs Original Design Safe ✓ × Security Bits 41 83 84 81 *Independent locking module. Clock frequency: 164MHz. Time for writing Kenc into the locking module is excluded.

original design through locking parameters leakage during tranfer. Furthermore, the lattice-based cryptography underlying bin-RLWE potentially offers resistance against quantum attacks, a feature of increasing importance as we approach the era of quantum computing. To evaluate its resistance against SAT attacks, we locked an n-bits XOR gate using this method while keeping the random numbers fixed, and attempted to solve for Kenc using the attack method in [6]. Our experimental results indicate that the computational complexity generally follows 2.5n·bitdepth . Even with fixed random numbers, the method demonstrates considerable resistance against conventional attacks. E. Resource Utilization The overhead introduced by logic locking is presented in Table I. Due to the interaction cost with the locking module, the overhead attributed to logic locking does not precisely correspond to the module’s resource consumption. V. C OMPARISON AND D ISCUSSION We conducted comparative analyses between our implementation and existing logic locking and RLWE implementations. Table II presents this comparison. While our hardware overhead is relatively higher, to the best of our knowledge, this represents the first lattice-based cryptography implementation in logic locking. Notably, our approach maintains the security of the original design even in cases of decryption key leakage. Compared to other RLWE implementations, we achieved significantly reduced total encryption and decryption latency, minimizing the performance overhead when integrated into processors. For reference, the independently operated locking module demonstrates substantial latency advantage at an equivalent security level when communication overheads are excluded. It’s important to note that while this work focuses on logic locking, it does not restrict speculative execution in processors. Attackers can still potentially leak critical data through cache side-channels by inducing mis-speculation of kernel code operations via user-mode programs.

5

VI. C ONCLUSION This study presents a novel approach to hardware security by integrating lattice based homomorphic encryption with logic locking techniques in SoC designs. Our implementation on a RISC-V SoC demonstrates the feasibility of this method, offering enhanced protection against key leakage. The experimental results reveal a modest performance impact, primarily affecting system-level operations while maintaining user-level computational performance. The hardware overhead, with increases of 6.0% in LUTs and 6.9% in Regs consumption, represents a reasonable trade-off for the enhanced protection of the original design. R EFERENCES [1] R. S. Rajarathnam, Y. Lin, Y. Jin, and D. Z. Pan, “ReGDS: A Reverse Engineering Framework from GDSII to Gate-level Netlist,” in 2020 IEEE Int. Symp. Hardware Oriented Security and Trust (HOST), 2020, pp. 154– 163. [2] V. S. Rathor, M. Singh, K. S. Sahoo, and S. P. Mohanty, “GateLock: Input-dependent key-based locked gates for SAT resistant logic locking,” IEEE Trans. Very Large Scale Integr. (VLSI) Syst., vol. 32, no. 2, pp. 361–371, Feb. 2024. [3] S. Boulebnane and A. Montanaro, “Solving Boolean satisfiability problems with the quantum approximate optimization algorithm,” PRX Quantum, vol. 5, no. 3, pp. 030348, 2024. [4] J. Buchmann, F. Göpfert, T. Güneysu, T. Oder, and T. Pöppelmann, “High-performance and lightweight lattice-based public-key encryption,” in Proc. 2nd ACM Int. Workshop IoT Privacy, Trust, and Security, 2016, pp. 2–9. [5] K. Asanovic, R. Avizienis, J. Bachrach, S. Beamer, D. Biancolin, C. Celio, H. Cook, D. Dabbelt, J. Hauser, A. Izraelevitz, et al., “The rocket chip generator,” EECS Dept., Univ. California, Berkeley, Tech. Rep. UCB/EECS-2016-17, vol. 4, pp. 6–2, 2016. [6] P. Subramanyan, S. Ray, and S. Malik, “Evaluating the security of logic encryption algorithms,” in 2015 IEEE Int. Symp. Hardware Oriented Security and Trust (HOST), 2015, pp. 137–143. [7] M. Yasin, B. Mazumdar, S. S. Ali, and O. Sinanoglu, “Security analysis of logic encryption against the most effective side-channel attack: DPA,” in 2015 IEEE Int. Symp. Defect and Fault Tolerance in VLSI and Nanotechnology Syst. (DFTS), 2015, pp. 97–102. [8] S. Tan, M. Yu, A. Python, Y. Shang, T. Li, L. Lu, and J. Yin, “HyQSAT: A hybrid approach for 3-SAT problems by integrating quantum annealer with CDCL,” in 2023 IEEE Int. Symp. High-Performance Comput. Architecture (HPCA), 2023, pp. 731–744. [9] A. Alasow and M. Perkowski, “Quantum algorithm for maximum satisfiability,” in 2022 IEEE 52nd Int. Symp. Multiple-Valued Logic (ISMVL), 2022, pp. 27–34. [10] R. L. Rivest, L. Adleman, M. L. Dertouzos, et al., “On data banks and privacy homomorphisms,” Found. Secure Comput., vol. 4, no. 11, pp. 169–180, 1978. [11] C. Gentry, “Fully homomorphic encryption using ideal lattices,” in Proc. 41st Annu. ACM Symp. Theory Comput., 2009, pp. 169–178. [12] UC Berkeley Architecture Research, ucb-bar/chipyard. (Oct. 1, 2024). Scala. Accessed: Oct. 2, 2024. [Online]. Available: https://github.com/ucb-bar/chipyard [13] K. Lucas, kdlucas/byte-unixbench. (Oct. 16, 2024). C. Accessed: Oct. 18, 2024. [Online]. Available: https://github.com/kdlucas/byte-unixbench [14] J. Buchmann, F. Göpfert, R. Player, and T. Wunderer, “On the hardness of LWE with binary error: Revisiting the hybrid lattice-reduction and meet-in-the-middle attack,” in Proc. Int. Conf. Cryptol. Africa, 2016, pp. 24–43. [15] M. R. Albrecht, R. Player, and S. Scott, “On the concrete hardness of Learning with Errors,” Cryptology ePrint Archive, Paper 2015/046, 2015. [16] Y. Yang, Z. Wang, J. Wang, J. Hou, Y. Su, and C. Yang, “A lightweight and efficient encryption/decryption coprocessor for RLWE-based cryptography,” IEEE Trans. Circuits Syst. II, Exp. Briefs, early access, 2024. [17] Y. Zhang, C. Wang, D. E. S. Kundi, A. Khalid, M. O’Neill, and W. Liu, “An efficient and parallel R-LWE cryptoprocessor,” IEEE Trans. Circuits Syst. II, Exp. Briefs, vol. 67, no. 5, pp. 886–890, May 2020. [18] N. Bindel, J. Buchmann, F. Göpfert, and M. Schmidt, “Estimation of the hardness of the learning with errors problem with a restricted number of samples,” J. Math. Cryptol., vol. 13, no. 1, pp. 47–67, 2019.

Record · ID 414031 · SHA-256 347e992d9f33aedd
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.