298
4 Hardware Trojans in Microcircuits
Read
Write, Read, Write
verify, write, verify
Hidden
functions
Programmable gate array (flash cells)
Secret access
Debugging
Flash block
password
AES decryption
Fig. 4.16 Simplified structure of JTAG TAP—security system of the ProASIC3 microcircuit
First, the list generated can always be incomplete, as the basic file STAPL can only be
compiled by the programs used to solve a certain specific task. Second, even though
all such subprograms, functions, and variables are clearly named, some external
commands of the IR levels are not always explained and usually identified by means
of numbers only, which complicates the task of recovery of specific JTAG functions
significantly. This difficulty is further complicated by the sequence of commands:
in modern compound devices, performance of special functions is usually ensured
by a series of data-related commands. Moreover, specialists understand that every
command can be not only of type IR or IR + DR, but it can also be an endless list
of any possible combinations, such as IR + IR, IR + DR + DR, IR + DR + IR +
DR, etc. [114].
At first, search for Trojans can seem like an easy task to a novice researcher; in this
case, he usually knows the architecture and structure of his microcircuits, as well as
the technology of its implementation on silicon that is usually performed by the chip
manufacturer or subcontractor. However, one needs to understand that for an intruder,
there is absolutely no difference between hardware Trojans and embedded production
backdoors, as the intruder seeks, finds, and uses any potential vulnerability in such
silicon chips.
It should be noted that the authors of the work [110] selected the microcircuit
Actel/Microsemi ProASIC3 A3P250 for their studies due to the following obvious
reasons. First of all, in terms of security, this microcircuit is actually promoted
as the device with the highest protection level. Actel, which developed the chips
4 Hardware Trojans in Microcircuits
Read
Write, Read, Write
verify, write, verify
Hidden
functions
Programmable gate array (flash cells)
Secret access
Debugging
Flash block
password
AES decryption
Fig. 4.16 Simplified structure of JTAG TAP—security system of the ProASIC3 microcircuit
First, the list generated can always be incomplete, as the basic file STAPL can only be
compiled by the programs used to solve a certain specific task. Second, even though
all such subprograms, functions, and variables are clearly named, some external
commands of the IR levels are not always explained and usually identified by means
of numbers only, which complicates the task of recovery of specific JTAG functions
significantly. This difficulty is further complicated by the sequence of commands:
in modern compound devices, performance of special functions is usually ensured
by a series of data-related commands. Moreover, specialists understand that every
command can be not only of type IR or IR + DR, but it can also be an endless list
of any possible combinations, such as IR + IR, IR + DR + DR, IR + DR + IR +
DR, etc. [114].
At first, search for Trojans can seem like an easy task to a novice researcher; in this
case, he usually knows the architecture and structure of his microcircuits, as well as
the technology of its implementation on silicon that is usually performed by the chip
manufacturer or subcontractor. However, one needs to understand that for an intruder,
there is absolutely no difference between hardware Trojans and embedded production
backdoors, as the intruder seeks, finds, and uses any potential vulnerability in such
silicon chips.
It should be noted that the authors of the work [110] selected the microcircuit
Actel/Microsemi ProASIC3 A3P250 for their studies due to the following obvious
reasons. First of all, in terms of security, this microcircuit is actually promoted
as the device with the highest protection level. Actel, which developed the chips
