296
4 Hardware Trojans in Microcircuits
of such methods of analysis of side channels largely depends on sensitivity of the
equipment used by experts.
One of the most widely used approaches to identification of Trojans and other
defects deliberately embedded by intruders is the utilization of various methods of
differential power analysis (DPA) designed to identify anomalies in the process of
device functioning. In modern microelectronic devices, such as FPGAs, it is nearly
impossible to identify embedded hardware Trojans or defects using DPA methods
unless special probe equipment is used, which helps to detect even the most insignificant changes in device operation and is able to find even the smallest changes below
the noise level in standard DPA settings.
As even novice security experts know, a mistake detected in embedded FGPA software can always be fixed by updating software. However, if the Trojan is embedded
in the silicon material of the microcircuit, it is impossible to eliminate such defects;
the only way here is to withdraw all such identified silicon chips, as was the case
with the defects identified in such common device as CPU [3]. Such operation is
very expensive and can seriously affect reputation (which actually happened) and
profits of the manufacture if the fact of Trojan detection is publicly announced.
It is obvious that if a potential intruder controls the microcircuit of the FGPA
in such manner, he can severely damage the device. For instance, the intruder can
actually physically destroy FGPA by loading a special malicious bit code that can
generate high current capable of locally burning out the chip from the inside. It is
obvious for experts that by using such defects, the intruder can remove any IP block
from the device and implement changes in the chip software based on the results of
its examination—for example, introducing new Trojans into the computing system.
This will clearly provide an even wider range of possibilities for the intruder to
undertake more complex attacks during further stages of external management of
the infected electronic system.
If the key is known, malicious commands can be embedded in the worm for
scanning at the standard JTAG channel, for organization of any attack unexpected by
legal users and for remote reprogramming of the software. This possibility must not
be ruled out, as the manufacturer has specifically designed channels of such remote
access not only for ProASIC3, but for a number of other Flash FPGA devices as
well. Let us cite the manual provided by the manufacturer once again: RT ProASIC3
devices with AES-based security provide a high level of protection for remote field
updates over public networks such as the Internet, and are designed to ensure that
valuable IP remains out of the hands of system overbuilders, system cloners, and IP
thieves. The content of the information field of the programmable device cannot be
extracted, which is ensured by checking the safety of the microcircuit design using
special tests.
In order to ensure better understanding of the essence of the examined problem,
let us take a brief look at the standard possibilities of organization of access to the
chip as exemplified by specific FGPA microcircuit.
4 Hardware Trojans in Microcircuits
of such methods of analysis of side channels largely depends on sensitivity of the
equipment used by experts.
One of the most widely used approaches to identification of Trojans and other
defects deliberately embedded by intruders is the utilization of various methods of
differential power analysis (DPA) designed to identify anomalies in the process of
device functioning. In modern microelectronic devices, such as FPGAs, it is nearly
impossible to identify embedded hardware Trojans or defects using DPA methods
unless special probe equipment is used, which helps to detect even the most insignificant changes in device operation and is able to find even the smallest changes below
the noise level in standard DPA settings.
As even novice security experts know, a mistake detected in embedded FGPA software can always be fixed by updating software. However, if the Trojan is embedded
in the silicon material of the microcircuit, it is impossible to eliminate such defects;
the only way here is to withdraw all such identified silicon chips, as was the case
with the defects identified in such common device as CPU [3]. Such operation is
very expensive and can seriously affect reputation (which actually happened) and
profits of the manufacture if the fact of Trojan detection is publicly announced.
It is obvious that if a potential intruder controls the microcircuit of the FGPA
in such manner, he can severely damage the device. For instance, the intruder can
actually physically destroy FGPA by loading a special malicious bit code that can
generate high current capable of locally burning out the chip from the inside. It is
obvious for experts that by using such defects, the intruder can remove any IP block
from the device and implement changes in the chip software based on the results of
its examination—for example, introducing new Trojans into the computing system.
This will clearly provide an even wider range of possibilities for the intruder to
undertake more complex attacks during further stages of external management of
the infected electronic system.
If the key is known, malicious commands can be embedded in the worm for
scanning at the standard JTAG channel, for organization of any attack unexpected by
legal users and for remote reprogramming of the software. This possibility must not
be ruled out, as the manufacturer has specifically designed channels of such remote
access not only for ProASIC3, but for a number of other Flash FPGA devices as
well. Let us cite the manual provided by the manufacturer once again: RT ProASIC3
devices with AES-based security provide a high level of protection for remote field
updates over public networks such as the Internet, and are designed to ensure that
valuable IP remains out of the hands of system overbuilders, system cloners, and IP
thieves. The content of the information field of the programmable device cannot be
extracted, which is ensured by checking the safety of the microcircuit design using
special tests.
In order to ensure better understanding of the essence of the examined problem,
let us take a brief look at the standard possibilities of organization of access to the
chip as exemplified by specific FGPA microcircuit.
