292
4 Hardware Trojans in Microcircuits
scenarios related to each specific class of attacks; the middle column generalizes the
possible countermeasures found in literature. The right column of the figure summarizes the methods of effectively countering attacks known at the time of the book’s
publication. Of course, it is necessary to understand that the description of specific
attack scenarios depends on the specific application (the specific goal of the attacker).
Here, the left column shows possible goals of the intruder, while the right column
shows the supposed position of the intruder between the elements of the hardware
security model
It should be noted that the previous version of the article cited here already
appeared in [14]. This article was focused on the analysis of possible scenarios of
hardware attacks. It contained a simplified graphic representation of the main levels
of abstractions of a typical microcircuit design route with qualitative characteristic of
the level of complexity of identifying the hidden defects introduced by the intruder.
For example, at the highest level of hierarchy (system level), two main methods
of attack are possible: change in the work protocol for the hacker’s benefit (change
protocol) and introduction of changes into functional units (constraints).
In terms of complexity, these changes surpass other hacker interventions implemented at the lower (physical) level of representation (lowest level)—changes in
topology (modify layout) and interconnections (modify wiring).
At the same time, the Trojans introduced in the lower representation level (transistor level) are much more difficult to detect than the ones in the high level (RT
level).
4.2 Description of the First Documented Facts of Detection
of Hardware Trojans in Critical Microcircuits
4.2.1 Introduction to the Problem
In the previous section, we examined the main stages of a standard procedure of
designing and manufacturing modern chips for theoretical vulnerability of these
stages to various attacks of agents (intruders). According to this brief analytical
analysis, such danger is obviously present. But how close this theoretical situation
can be to real practice of work of modern microelectronic companies? Who are
these theoretical intruders? Who controls them? What are they after? Could this
situation be another PR stunt in the marketing struggle between power players of the
semiconductor market (something like the popular slogan “Choose our products—
our microcircuits are fully protected from Trojan hazards by special means”)?
To be fair, it has to be said that as of the moment of publication of this book, many
experts still believe that there is no such thing as hardware Trojan; there are only
regular mistakes of microcircuit developers and so-called production backdoors—
firmware means deliberately left in microcircuit designs and used to configure software and eliminate future possible mistakes identified in the process of operation of
Précédent

- 311/839

Suivant