82
1 Information Weapon: Concepts, Means, Methods …
radioactive substances confinement (particularly, reactor containment dome). In the
process of non-project accident management operational personnel shall use any
available serviceable systems and tools, including project safety systems and supplementary tools and systems, intended expressly for the purposes of severe accidents
management.
The last fifth level of protection of nuclear power plant is constituted by accident
protection measures, including those outside plant site. The main challenge of this
level is mitigating of the accident consequences in terms of decrease in radiological
impact at human population and environment. This protection level is provided due to
accident prevention activities within nuclear power plant’s site and implementation
of the plans of accident prevention activities in the field around nuclear power plant.
Thus, implementation of the defense-in-depth concept afford attaining top goal
of nuclear power plants’ security at operation prevention of failures and accidents
and in case of their occurrence provides tools for accident consequences remedial
and limiting control.
Much to our regret presently all five above listed protection levels of nuclear
power plant are vulnerable in the view of potential Trojan attacks—Trojan software
viruses, but in particular threat of hardware Trojans penetration into microcircuits of
electronic equipment involved at actuation of any protection levels.
As Chaps. 4 and 5 will demonstrate that for attaining their vicious goals at plotting
any attack at nuclear power plant the terrorists may apply basically hardware Trojans
of two types—hardware Trojan of time bomb type and hardware Trojan with external
channel control.
The first hardware Trojan is a low-cost type—its making cost is for two or three
order less as compared to the hardware Trojans of the second type and does not
summon high competency of Trojan designer and there is no need in arranging
technically sophisticated noise-free channel of wireless control.
The most primitive way of getting such unrecoverable (undetectable, actually)
hardware Trojan is under-doping of local area on die surface with just a few transistors
which results in its significant reliability degradation. The fault is irrelevant in terms
of efficiency—there is no way to identify accurately the time of operating (i.e., failure
of these transistors): it may happen after 6 months of operation, and after 1 year and
even after several years. Hardware Trojans “rated” by operation time of similar type
may be created by security services only in possession of substantial funds and
employing nerds highly competent in microelectronics and semiconductor physics.
It is more preferable to introduce a microcircuit charged with such type of Trojan
into electronic equipment of nuclear power plant not into the kit of source equipment
(in fact it is possible as well) but in the process of repair, routine, and maintenance
works, servicing of radioelectronic equipment.
It is possible surely only in case no respective safety assuring activities and
measures appropriate for such situation are in place.
Single time failure principle is the fundamental one among the basic safety principles of nuclear power plants. In compliance with this principle the system should
perform its functions at any initiating event of the accident asking for its operation,
and if the microcircuit is a fault-free one, then if any element of this system fails.
1 Information Weapon: Concepts, Means, Methods …
radioactive substances confinement (particularly, reactor containment dome). In the
process of non-project accident management operational personnel shall use any
available serviceable systems and tools, including project safety systems and supplementary tools and systems, intended expressly for the purposes of severe accidents
management.
The last fifth level of protection of nuclear power plant is constituted by accident
protection measures, including those outside plant site. The main challenge of this
level is mitigating of the accident consequences in terms of decrease in radiological
impact at human population and environment. This protection level is provided due to
accident prevention activities within nuclear power plant’s site and implementation
of the plans of accident prevention activities in the field around nuclear power plant.
Thus, implementation of the defense-in-depth concept afford attaining top goal
of nuclear power plants’ security at operation prevention of failures and accidents
and in case of their occurrence provides tools for accident consequences remedial
and limiting control.
Much to our regret presently all five above listed protection levels of nuclear
power plant are vulnerable in the view of potential Trojan attacks—Trojan software
viruses, but in particular threat of hardware Trojans penetration into microcircuits of
electronic equipment involved at actuation of any protection levels.
As Chaps. 4 and 5 will demonstrate that for attaining their vicious goals at plotting
any attack at nuclear power plant the terrorists may apply basically hardware Trojans
of two types—hardware Trojan of time bomb type and hardware Trojan with external
channel control.
The first hardware Trojan is a low-cost type—its making cost is for two or three
order less as compared to the hardware Trojans of the second type and does not
summon high competency of Trojan designer and there is no need in arranging
technically sophisticated noise-free channel of wireless control.
The most primitive way of getting such unrecoverable (undetectable, actually)
hardware Trojan is under-doping of local area on die surface with just a few transistors
which results in its significant reliability degradation. The fault is irrelevant in terms
of efficiency—there is no way to identify accurately the time of operating (i.e., failure
of these transistors): it may happen after 6 months of operation, and after 1 year and
even after several years. Hardware Trojans “rated” by operation time of similar type
may be created by security services only in possession of substantial funds and
employing nerds highly competent in microelectronics and semiconductor physics.
It is more preferable to introduce a microcircuit charged with such type of Trojan
into electronic equipment of nuclear power plant not into the kit of source equipment
(in fact it is possible as well) but in the process of repair, routine, and maintenance
works, servicing of radioelectronic equipment.
It is possible surely only in case no respective safety assuring activities and
measures appropriate for such situation are in place.
Single time failure principle is the fundamental one among the basic safety principles of nuclear power plants. In compliance with this principle the system should
perform its functions at any initiating event of the accident asking for its operation,
and if the microcircuit is a fault-free one, then if any element of this system fails.
