294
4 Hardware Trojans in Microcircuits
It goes without saying that the presence of this object “Trojan” in the source description of embedded software loaded by the developer to the chip was not planned by
the developer.
Using the new method of pipeline emission analysis (PEA) and state-of-theart analytical equipment, the authors [110] managed to find the special secret key
designed for activation of this “embedded” defect and hacked other standard security
keys such as AES and Passkey. Thus, this became the first documented confirmation
of the fact that any intruder can extract all data that are not intended for third-party
users from a chip, reprogram the initial cryptography, and ultimately acquire these
keys. Availability of these keys provides unauthorized access to non-encrypted data
stream and helps change certain electrical parameters of the microcircuit or even
damage it. Generally, this means that any similar microelectronic device is fully
open for intellectual property (IP) theft, various forms of fraud, reprogramming of
the basic device functions, as well as for reverse engineering of the design, which
helps to introduce any new “embedded defect” (hardware Trojan) into the modified
design.
As demonstrated in [3], globalization of the semiconductor production process
causes specific integrated circuits to become vulnerable to malicious activities in
the form of introduction of hardware Trojans and other similar deliberately installed
pseudo-defects. For example, the intruder can introduce such Trojans into the design
during microcircuit production stage, very slightly changing one or several templates
at fabrication or production plant. Such action can also be carried out inside any
original IP modules or functional blocks of a third party used in the IC design.
From the intruder’s point of view, the difference between such hardware Trojans
and regular production defects is not that big, since such microelectronic devices are
usually analyzed by the end user only as black boxes with limited information of
test sets usually provided to the microcircuit manufacturer by the developer. In such
cases, without a special complex investigation it is virtually impossible to establish
the very fact of intrusion, let alone the party who introduced such undocumented
functions into the IC and the process stage during which it happened.
However, the authors [110] decided to perform a detailed examination of the
microcircuit Actel/Microsemi ProASIC3 A3P250 due to its widely declared security characteristics and a wide range of application fields in military and industrial
systems. According to the manufacturer, these chips are “low power consuming
devices, which are unique in terms of reprogramming and fully resistant to both
invasive and non-invasive attacks on intellectual property (IP) objects embedded
into microcircuits.”
After implementing an entire range of extremely complicated studies, the authors
[110] use real technical actions to demonstrate how a deliberately embedded hardware Trojan and its generated additional functions can be detected even in this “highly
protected” chip Actel/Microsemi ProASIC3 Flash FPGA by Actel—the company
that promotes these chips as “providing one of the highest security levels in the
industry.” These FPGAs are indeed unique due to their low power, they operate in
the optimal energy consumption mode and are fairly reliable in terms of their internal
organization, since all the confidential data of the configuration are stored outside the
4 Hardware Trojans in Microcircuits
It goes without saying that the presence of this object “Trojan” in the source description of embedded software loaded by the developer to the chip was not planned by
the developer.
Using the new method of pipeline emission analysis (PEA) and state-of-theart analytical equipment, the authors [110] managed to find the special secret key
designed for activation of this “embedded” defect and hacked other standard security
keys such as AES and Passkey. Thus, this became the first documented confirmation
of the fact that any intruder can extract all data that are not intended for third-party
users from a chip, reprogram the initial cryptography, and ultimately acquire these
keys. Availability of these keys provides unauthorized access to non-encrypted data
stream and helps change certain electrical parameters of the microcircuit or even
damage it. Generally, this means that any similar microelectronic device is fully
open for intellectual property (IP) theft, various forms of fraud, reprogramming of
the basic device functions, as well as for reverse engineering of the design, which
helps to introduce any new “embedded defect” (hardware Trojan) into the modified
design.
As demonstrated in [3], globalization of the semiconductor production process
causes specific integrated circuits to become vulnerable to malicious activities in
the form of introduction of hardware Trojans and other similar deliberately installed
pseudo-defects. For example, the intruder can introduce such Trojans into the design
during microcircuit production stage, very slightly changing one or several templates
at fabrication or production plant. Such action can also be carried out inside any
original IP modules or functional blocks of a third party used in the IC design.
From the intruder’s point of view, the difference between such hardware Trojans
and regular production defects is not that big, since such microelectronic devices are
usually analyzed by the end user only as black boxes with limited information of
test sets usually provided to the microcircuit manufacturer by the developer. In such
cases, without a special complex investigation it is virtually impossible to establish
the very fact of intrusion, let alone the party who introduced such undocumented
functions into the IC and the process stage during which it happened.
However, the authors [110] decided to perform a detailed examination of the
microcircuit Actel/Microsemi ProASIC3 A3P250 due to its widely declared security characteristics and a wide range of application fields in military and industrial
systems. According to the manufacturer, these chips are “low power consuming
devices, which are unique in terms of reprogramming and fully resistant to both
invasive and non-invasive attacks on intellectual property (IP) objects embedded
into microcircuits.”
After implementing an entire range of extremely complicated studies, the authors
[110] use real technical actions to demonstrate how a deliberately embedded hardware Trojan and its generated additional functions can be detected even in this “highly
protected” chip Actel/Microsemi ProASIC3 Flash FPGA by Actel—the company
that promotes these chips as “providing one of the highest security levels in the
industry.” These FPGAs are indeed unique due to their low power, they operate in
the optimal energy consumption mode and are fairly reliable in terms of their internal
organization, since all the confidential data of the configuration are stored outside the
