278
4 Hardware Trojans in Microcircuits
systems, communication and navigation systems, etc.) [1–109]. Let us consider the
classification of models of Trojan activation in microcircuits, protection methods,
and Trojan identification features, as well as the main mechanisms of attacks on
electronic equipment.
Until certain moment, all algorithms, secret cryptographic basic mechanisms,
and protocols usually relied on the principle of unconditional trust to the main used
hardware base in order to ensure a high level of protection of electronic products
during implementation and further operation in real conditions. Security provision
methods widely used by developers used to assume that the hardware platforms
used as bases for their implementation are failsafe from various external attacks.
Unfortunately, as demonstrated by the following examples, this assumption is no
longer true today.
For example, the company Quo Vadis Labs was one of the first in the world
to report detected hardware Trojans in the microcircuit that is widely used in the
systems used for management of weapons, nuclear power industry facilities, and
public transport in USA and around the world [2]. As the journalists discovered
later, annual reports of the Ministry of Defence of the USA for 2005 showed that
rogue microelectronic devices back then were already widely used in computers,
communication systems, car systems, control systems, and even defence systems
[3, 4]. In order to prove the gravity of this new problem, so-called “white hackers”
have convincingly demonstrated that by means of imitating communication signals
between a parking payment card and the reader of the payment sensor one can easily
increase the amount of payment withdrawn from this card [5]. The demonstration
performed at the specialized conference Black Hat 2012 persuaded everybody in the
vulnerability of the existing security system even in key cards [6]. The attacker used
only a small area of the key code field, using a cryptographic algorithm built into the
key card to affect Description of the first documented facts the main key.
However, in addition to these “domestic” usages of microcircuits, there is a wide
range of their application in industry, defence, and space equipment.
Figure 4.1 shows a simplified principle of organization of such unauthorized
channels for control of military-purpose radioelectronic systems, using infected
microcircuits with illegally embedded hardware Trojans including radio frequency
units.
Today, microcontrollers are widely used in embedded systems; they employ socalled fusible bits to prevent unauthorized users from reading or modifying certain
sections in memory. However, any reverse-engineering specialist today can find and
neutralize these specific fusible bits and gain access for reading and even subsequent
modification of the contents of their memory [7].
Intruders can inject hardware Trojans, which don’t require direct external control
via radio channel, into microcontrollers. These hardware Trojans belong to the class
of so-called time bombs. Figures 4.2 and 4.3 demonstrate graphic explanation of the
principle of their operation. In this case, the Trojan circuit contains a small number
of elements (transistors) forming a counter, a basic state machine, a data comparator,
and a number of additional conductors and transistors ensuring electrical connection
of this parasite to critical blocks of the attacked microcircuit.
Précédent

- 297/839

Suivant