4.2 Description of the First Documented Facts …
295
device: “As compared to SRAM-based FPGAs, ProASIC cannot be read reversely
by means of JTAG or another method.”
Made using the 0.13 μm process with seven metal layers of interconnects, the chip
under study included 1 913 600 bits of bitstream configuration data. According to
the specifications for this chip, “even without applying any security measures (such
as FlashLock with AES), it is impossible to read information from the programmed
device. The programming algorithm implemented in the IC will load all data and
programming results into the device. The device will use a special embedded circuit
in order to verify correctness of programming.” The cited work [110] shows that there
are, of course, special hidden (non-declared) functions inside the JTAG controller of
this chip, and one of such functions still provides the possibility of secret access to
the internal configuration of the microcircuit. The JTAG controller itself in this case
is an integral part of the silicon structure, just like in all FGPA chips, and cannot be
changed after production of the chip.
Security specialists are well aware that most manufacturers of chips with complex
functionality introduce so-called production backdoors in microcircuits in order to
facilitate the procedure of production testing and debugging. It is also known that such
undocumented commands are often used in JTAG for analysis of causes of microcircuit failures during operation or debugging; however, they were never designed
to ensure security of the circuit. Any technical dictionary provides the following
definition: “Deliberately embedded defect is an undocumented way of accessing a
computer system or data contained in it.” This is exactly what the researchers have
found in the third generation of chips Actel/Microsemi Flash FPGA. It should be
noted that the same approach can be used to detect hardware Trojans with slight
changes in the scanning methods.
In recent years, various methodological approaches to identification of such hardware Trojans have been suggested. In general, they can be divided into three basic
categories. The first one is complete reverse engineering of a chip providing in-depth
analysis of hardware portion of the entire chip. However, this is an extremely expensive, long, and difficult operation, much to client’s disappointment, and it is usually
ineffective if a Trojan is found in a single very small fragment of the chip topology.
The second category consists in an attempt to activate (“wake up”) the Trojan using
special effects (test vectors) and comparing the received responses to the expected
reference responses. This method may also prove ineffective in situations where
the structure of the Trojan ensures its activation only by request from the intruder in
certain unique conditions, which are only known to its creator. It is nearly impossible
to check all states for modern complex microcircuits. Moreover, this approach will
not identify a fairly popular class of Trojans which are designed only to organize side
channels for information leakage instead of controlling the equipment. Finally, the
third category of Trojans utilizes analysis of such side channels to detect Trojans by
analyzing measurements of physical parameters of the circuit, such as magnitude and
dynamics of changes in energy consumption, various forms of electromagnetic radiation emitted by circuits, and temporary analysis. In general, these methods can be
used fairly successfully for reference samples or in integrated circuits to determine
the ways of minimizing differences between samples. However, the effectiveness
295
device: “As compared to SRAM-based FPGAs, ProASIC cannot be read reversely
by means of JTAG or another method.”
Made using the 0.13 μm process with seven metal layers of interconnects, the chip
under study included 1 913 600 bits of bitstream configuration data. According to
the specifications for this chip, “even without applying any security measures (such
as FlashLock with AES), it is impossible to read information from the programmed
device. The programming algorithm implemented in the IC will load all data and
programming results into the device. The device will use a special embedded circuit
in order to verify correctness of programming.” The cited work [110] shows that there
are, of course, special hidden (non-declared) functions inside the JTAG controller of
this chip, and one of such functions still provides the possibility of secret access to
the internal configuration of the microcircuit. The JTAG controller itself in this case
is an integral part of the silicon structure, just like in all FGPA chips, and cannot be
changed after production of the chip.
Security specialists are well aware that most manufacturers of chips with complex
functionality introduce so-called production backdoors in microcircuits in order to
facilitate the procedure of production testing and debugging. It is also known that such
undocumented commands are often used in JTAG for analysis of causes of microcircuit failures during operation or debugging; however, they were never designed
to ensure security of the circuit. Any technical dictionary provides the following
definition: “Deliberately embedded defect is an undocumented way of accessing a
computer system or data contained in it.” This is exactly what the researchers have
found in the third generation of chips Actel/Microsemi Flash FPGA. It should be
noted that the same approach can be used to detect hardware Trojans with slight
changes in the scanning methods.
In recent years, various methodological approaches to identification of such hardware Trojans have been suggested. In general, they can be divided into three basic
categories. The first one is complete reverse engineering of a chip providing in-depth
analysis of hardware portion of the entire chip. However, this is an extremely expensive, long, and difficult operation, much to client’s disappointment, and it is usually
ineffective if a Trojan is found in a single very small fragment of the chip topology.
The second category consists in an attempt to activate (“wake up”) the Trojan using
special effects (test vectors) and comparing the received responses to the expected
reference responses. This method may also prove ineffective in situations where
the structure of the Trojan ensures its activation only by request from the intruder in
certain unique conditions, which are only known to its creator. It is nearly impossible
to check all states for modern complex microcircuits. Moreover, this approach will
not identify a fairly popular class of Trojans which are designed only to organize side
channels for information leakage instead of controlling the equipment. Finally, the
third category of Trojans utilizes analysis of such side channels to detect Trojans by
analyzing measurements of physical parameters of the circuit, such as magnitude and
dynamics of changes in energy consumption, various forms of electromagnetic radiation emitted by circuits, and temporary analysis. In general, these methods can be
used fairly successfully for reference samples or in integrated circuits to determine
the ways of minimizing differences between samples. However, the effectiveness
