System-on-chip security architecture is a critical, complex, and time-consuming activity, consuming months of effort. Furthermore, the architectural design can include subtle errors that compromise the security of the entire system. In this paper, we develop a security engine infrastructure, SEnTry , for systematically creating security architectures for protecting SoC designs against a variety of security subversions. SEnTry provides a plug-and-play, configurable subsystem composed of custom IPs that can be integrated into the platform to derive different security primitives. We develop an instance of SEnTry for supply-chain attacks. We discuss the spectrum of challenges involved in developing a unified architecture for systematic protection against the variety of attacks involved and the SEnTry approach to addressing them. We provide several case studies to demonstrate SEnTry design and perform extensive experiments to evaluate its overhead on multiple ASIC technologies. Our experiments suggest that SEnTry incurs minimal overhead in area and power consumption.
Raj et al. (2026) studied this question.