Industries · Defense

Defense

Chips that must be trusted, export-controlled and kept in service for decades.

Counterfeit-part cases in a 2012 Senate inquiry
1,800+
Suspect counterfeit parts in those cases
Over 1 million
Weapons-system electronics obsolete before fielding (DSB, 2017)
≈70%
Cost of one custom IC design, upper end (DARPA)
Up to $100M

At a glance

Where the flow bends

  1. 01Specification

    Before anyone draws a circuit, lawyers and engineers decide who is allowed to see the design and which factories may build it.

    The spec adds an export classification (ITAR or EAR), a trust requirement (must it go through DMEA-accredited suppliers?), and a support life measured in decades, with a plan for parts going out of production.

    Classify early: an ASIC programmed for a USML defense article is itself USML Category XI(c)(1), so the RTL, netlists and GDS are ITAR technical data. Write the DoDI 5200.44 trust path, the DMSMS strategy and the threat model (IP, tools, fab, assembly, distribution) into the spec.

  2. 02Architecture

    Teams choose between a reprogrammable chip bought off the shelf and a custom chip, and they wall off the parts that hold secrets.

    FPGA versus ASIC is a central decision: FPGAs avoid custom-chip cost and allow field updates; ASICs win on power and size. Security functions often live in their own partition.

    Trade NRE, volume, SWaP and supply-chain exposure. Programs like DARPA AISS formalize a split between an application partition and a security partition sized against side-channel, reverse-engineering, supply-chain and malicious-hardware threats.

  3. 03RTL design

    Engineers check where every borrowed building block came from, because a hidden extra circuit could be slipped in.

    Third-party IP gets provenance review. Encrypted IP blocks are a concern because you must trust a supplier you cannot inspect.

    Prefer IP with source visibility, track every block’s origin, and treat encrypted or “locked” IP as an unverified dependency in the threat model.

  4. 04Verification

    Testers look for circuits that do nothing in normal use but could wake up on a secret signal.

    On top of functional checks, teams hunt for hardware Trojans: rarely-activated logic, unexplained state, and paths to outputs that the spec doesn’t call for.

    Add Trojan-focused analysis: rare-condition coverage, unused-logic review, formal checks that no unexpected path reaches a sensitive output, and golden-model comparison. Post-silicon, side-channel fingerprinting and destructive reverse engineering of samples complement pre-silicon work.

  5. 05Logic synthesis

    Some designs add a secret “key” to the circuit, so a stolen copy doesn’t work without it.

    Logic locking inserts key-controlled gates into the netlist. With the wrong key, the chip computes wrong answers.

    Locking costs area and timing and has a poor security record: the SAT attack broke the early XOR/XNOR schemes, and later schemes remain an attack-and-defense cycle. Treat it as one layer among several.

  6. 11Routing

    A design can be split so that one factory makes the bottom layers and a trusted factory adds the top wiring.

    Split manufacturing hides the upper metal connections from the untrusted foundry that builds the transistors and lower metal.

    Plain placement and routing leave hints (neighboring pins tend to connect), so proximity attacks can recover many hidden connections. Defenses perturb placement, lift sensitive wires to the BEOL, or obfuscate layout, each at a PPA cost.

  7. 13GDS & tapeout

    The finished design goes to an approved factory, and every handoff is tracked like evidence.

    GDS is shipped to a DMEA-accredited trusted supplier with an unbroken chain of custody. Mask, fab, packaging and test may each need accreditation.

    Plan the tapeout around accredited mask, foundry, post-processing, packaging and test sources, controlled data transfer for ITAR technical data, and lifetime-buy or re-fab options for when the process or package goes away.

A chip in a radar or a missile has to do its job and nothing else, often for twenty or thirty years. The military also has to be sure that nobody added a hidden circuit, that the design didn’t leak to the wrong country, and that the parts on the shelf are real.

So defense chip design follows the same steps as any other chip, with an extra question at every step: who touched this, and can we prove it? The Defense Department runs a program so sensitive chips go only through approved companies. Export laws such as decide who may even look at the design files.

The Spec→GDS flow is unchanged in shape. What changes is that every file it produces is controlled. DoD Instruction 5200.44 requires that integrated circuits custom-designed or tailored for a military end use be procured from a accredited by the Defense Microelectronics Activity (DMEA). DMEA accredits suppliers of IC design, aggregation, brokering, mask making, fabrication, post-processing, packaging/assembly and test.

Export control reaches the design data itself. The U.S. Munitions List covers “Application Specific Integrated Circuits (ASICs) and Programmable Logic Devices (PLD) programmed for defense articles,” and defines an ASIC as a chip built for a specific function “regardless of number of customers.” ASICs programmed for the less sensitive “600 series” military items fall under the Commerce Department’s instead, as ECCN 3A611.f. Showing that RTL or GDS to a foreign national inside the U.S. is a .

DMEA defines trust as confidence built by “assessing the integrity of the people and processes used to design, generate, manufacture and distribute” critical components. A trusted source must provide chain of custody, avoid supply disruption, prevent tampering, and protect parts from reverse engineering. The National Academies list the design-phase exposures as third-party IP, protection of critical design information, and dependence on CAD tools; encrypted IP means “the user must trust the provider.”

The accredited path does not cover every node or package a program wants, so design-side techniques fill gaps: , , Trojan-focused verification and security partitions. None of them replaces a trusted flow; each narrows what an untrusted party can learn or change.

Four pressures shape a defense chip:

  • Secrets. The design is controlled technology, so it can only be shared with approved people.
  • Sabotage. Someone could slip a into the design or the factory.
  • Fakes. A 2012 Senate investigation found more than 1,800 cases of suspect , totaling over a million parts, in the military supply chain.
  • Time. Systems stay in service so long that the chips inside go out of production first.

Trojans. A Trojan is usually a trigger that fires under a rare condition plus a payload that leaks data, alters function or denies service. It can be inserted at design time, during fabrication, or through third-party IP cores, and detection methods include logic testing for rare activation conditions, side-channel analysis, and reverse engineering against a golden reference.

Counterfeits. Counterfeiters recycle discarded ICs, alter them and resell them; the parts may not meet spec. DARPA’s SHIELD program aimed to make this uneconomic with a 100 µm × 100 µm encrypted “dielet” inserted into the package as a hardware root of trust.

Obsolescence. A 2017 Defense Science Board report, quoted by the National Academies, found that about 70 percent of the electronics in a weapons system are obsolete or out of production before the system is fielded. This problem is managed as .

Low volume and high cost. DARPA notes that a custom IC can cost up to $100 million and take more than two years, which pushes DoD toward general-purpose parts plus software, at a price in power and weight.

The FPGA-versus-ASIC decision sits where these pressures meet. An avoids mask NRE and can be updated in the field, and the National Academies report FPGAs in F-35 radar, communication and navigation systems. But an FPGA is a commercial part from a global supply chain, and the same report flags public contract announcements naming specific FPGA buys as poor operational security. An ASIC wins when power and size matter on small platforms, which is the case CRAFT set out to make affordable.

Design productivity is itself a security issue. DARPA’s IDEA program cites DoD hardware design cycles two to three times longer than commercial ones, and targeted a compiler that goes from source to GDSII with no human in the loop in under 24 hours. Short design cycles help with obsolescence too: a design that can be re-run through an automated flow on a new process is easier to sustain than one tied to a dead node.

Radiation overlaps with defense for systems that fly high or must survive nuclear environments. Those requirements follow the methods on the Space page and add hardening targets to the spec.

Most steps look the same as a commercial chip. The differences are in who may work on it, what extra checks happen, and where it is built. Before design starts, the team decides the export rules and the approved factories. During design, engineers check every borrowed block and hunt for circuits that don’t belong. Some designs are locked with a secret key or split between two factories. At tapeout the files go only to an approved factory, with every transfer logged.

StageDefense addition
SpecExport classification (ITAR/EAR), trust requirement, decades-long support plan
ArchitectureFPGA vs ASIC; separate security partition
RTLProvenance review of third-party IP
VerificationTrojan hunting: rare triggers, unexplained logic
SynthesisOptional logic locking with key gates
Placement / routingOptional split manufacturing (FEOL/BEOL)
TapeoutGDS to an accredited trusted supplier with chain of custody

DARPA’s AISS program framed the architecture step as two partitions, an application processor and a security partition, built to resist four attack surfaces: side channels, reverse engineering, supply-chain attacks and malicious hardware.

Logic locking, in its simplest form, inserts an XOR gate wired to a secret key input; with the wrong key, some outputs are wrong. Split manufacturing sends the transistors and lower metal layers to a high-end foundry and the upper metal layers to a trusted one, so the first never sees the full wiring.

Logic locking. The first scheme (Roy et al., 2008) added random XOR/XNOR key gates. The SAT attack of Subramanyan et al. uses a working chip as an oracle and a SAT solver to prune the key space with distinguishing inputs, and it broke early schemes; much later work is a response to it. Key gates also land on timing paths, so locking must be inserted before final timing closure and checked in equivalence with the key applied.

Split manufacturing. Placement and routing heuristics leave clues, since connected cells tend to sit close together, and proximity attacks use them to infer hidden BEOL connections. Defenses fall into proximity perturbation, wire lifting and layout obfuscation. The literature disagrees sharply on how much an attacker recovers, from near-perfect netlist reconstruction to marginal success. Practically, the split layer sets a routing constraint: sensitive nets must be lifted above it, which costs vias, congestion and timing.

Trojan-aware verification. Coverage closure should include rare-condition analysis, review of logic that never toggles in regression, and formal checks that no unintended path reaches keys or outputs. Post-silicon, side-channel comparison against known-good parts and destructive reverse engineering of samples close the loop.

Data handling. Because the database is ITAR technical data, the EDA environment itself is in scope: who has accounts, where licenses and compute run, and how GDS travels to the mask shop.

In 2012 the Senate Armed Services Committee published a year-long investigation into fake electronic parts. It found counterfeit parts in the Air Force’s largest cargo plane, in assemblies meant for Special Operations helicopters, and in a Navy surveillance plane. One supplier alone sent about 84,000 suspect parts into the military supply chain.

The lesson for chip designers: a perfect design is useless if a fake part ends up in the socket. That is why defense programs care about where parts come from, and why some chips now carry ways to prove they are genuine.

The committee identified 1,800 cases involving more than a million suspect parts. It tracked well over 100 of those cases back through the supply chain and traced more than 70 percent of the suspect parts to China. Parts from one Shenzhen supplier reached collision-avoidance systems intended for the C-5AMP, C-12 and Global Hawk, and assemblies for the P-3 and the Special Operations A/MH-6M.

Counterfeits cluster where defense and commercial lifecycles diverge. The National Academies describe a commercial supplier that assumes counterfeits only appear after its parts are obsolete, an assumption that fails for “decades-long sustainment cycles.” A defense program buying an old part from a broker is exactly that case.

Design responses work at three levels. First, reduce dependence on parts that will go obsolete: keep RTL portable and documented so the function can be re-implemented, a DMSMS strategy as much as a design one. Second, make authenticity checkable in the field; SHIELD’s dielet combined passive tamper sensors, an encryption engine and near-field power and communication so a probe could verify a part’s provenance against a server. Third, keep custom parts inside the accredited flow, where chain of custody is the control.

The case also shows why “trusted” is a property of the whole lifecycle. A design that passes every Trojan check, built in an accredited fab, can still be defeated twenty years later by a re-marked part from the gray market.

Sources

  1. Trusted Supplier ProgramTrusted Access Program Office · Defense Microelectronics Activity (DMEA), U.S. Department of DefenseDefinition of trust, DoDI 5200.44 requirement, accreditation categories.
  2. 22 CFR § 121.1 The United States Munitions List (Category XI, Military Electronics)Electronic Code of Federal Regulations (eCFR)USML XI(c)(1): ASICs and PLDs programmed for defense articles; ASIC definition.
  3. 22 CFR § 120.50 ExportElectronic Code of Federal Regulations (eCFR)Releasing technical data to a foreign person in the U.S. is a deemed export.
  4. Senate Armed Services Committee Releases Report on Counterfeit Electronic PartsU.S. Senate Committee on Armed Services · U.S. Senate · 20121,800 cases, over 1 million suspect parts, affected platforms.
  5. The Growing Threat to Air Force Mission-Critical Electronics: Lethality at Risk: Unclassified Summary (Discussion of Selected Topics)National Academies of Sciences, Engineering, and Medicine · The National Academies Press · 2019Design-phase threats (third-party IP, CAD tools), FPGA use, obsolescence.
  6. Circuit Realization at Faster Timescales (CRAFT)DARPACustom IC cost and schedule; DoD reliance on general-purpose circuits.
  7. Intelligent Design of Electronic Assets (IDEA)DARPADoD design cycles 2–3× longer than commercial; 24-hour no-human-in-the-loop layout goal.
  8. Supply Chain Hardware Integrity for Electronics Defense (SHIELD)DARPACounterfeit ICs; 100 µm × 100 µm authentication dielet.
  9. Automatic Implementation of Secure Silicon (AISS)DARPASecurity partition, four attack surfaces, automated secure design flow.
  10. A Survey on Split Manufacturing: Attacks, Defenses, and ChallengesTiago D. Perez and Samuel Pagliarini · arXiv · 2020FEOL/BEOL split, proximity attacks, defense categories.
  11. High-Level Approaches to Hardware Security: A TutorialHammond Pearce, Ramesh Karri and Benjamin Tan · arXiv · 2022Logic locking with key gates; the SAT attack.
  12. Hardware Trojans in Chips: A Survey for Detection and PreventionChen Dong, Yi Xu, Ximeng Liu, Fan Zhang, Guorong He and Yuzhong Chen · Sensors (MDPI), via PubMed Central · 2020Trojan structure (trigger, payload), insertion points, detection methods.