the solution here is to release the schematics, and the resaulting gate-level netlists. People who want to verify designs can use scan/jtag to verify that designs do waht they claim
I am interested to know if I am wrong (it's not uncommon) and if scan chains might solve that too.
A different approach might be to fingerprint different areas of the chip under different inputs - so for example when this bus passes over a million zero words, everything connected to it performs in a unique way that would not work if the chip was physically different to it's schematic?
http://people.umass.edu/gbecker/BeckerChes13.pdf
Ars summary:
http://arstechnica.com/security/2013/09/researchers-can-slip...