300
4 Hardware Trojans in Microcircuits
Table 4.1 Results of analysis of the security levels in the ProASIC3 microcircuit [110]
Region
security
Access
read
Access
verification
Access
write
Block
security
AES-coding Expected
security
Time of
attacks
FROM
(Flash)
Yes
Yes
Yes
Yes
Yes
Medium
Seconds
FPGA
array
No
Yes
Yes
Yes
Yes
High
Days
AES key
No
Yes
Yes
Yes
No
Medium
Seconds
Flash lock
passkey
No
Yes
Yes
Yes
No
Very high Clock
Backdoor
key
No
Yes
Yes
Yes
No
Very high Clock
Permanent
lock
No
No
Yes
No
No
Ultra high Minutes
Table 4.1 generalizes the assessed security provision levels in ProASIC3 microcircuits according to the conclusions from the studies. As we can see from this table,
Passkey offers the best security level for protection from maliciously reprogrammed
chip, while permanent lock shall only be used as the last means of turning a microcircuit into a one-time programmable (OTP) chip. However, even though the mechanism embedded by engineers in the microcircuit is actually capable of providing the
maximum level of protection, the permanent lock still has certain physical “cracks”
in security. It provides a possible side channel for organization of attacks associated
with damage infliction.
Other ways of extracting confidential information from FPGA can be found in
literature. One of these ways was published back in 2010; it used a special type of
optical attack to inflict damage—so-called bumping attacks [119].
Another method used the vulnerability of AES implementation and, in particular,
the message authentication code (MAC) is usually used to protect the encrypted code
encoded by the developer [120].
It is absolutely obvious that such unauthorized “disclosure” of the AES key in
ProASIC3 microcircuits can allow any qualified intruder to extract the IP even
without directly accessing the source code recorded by the microcircuit designer.
Even though regular users usually don’t have access to configuration of the AESencoded bit stream, such verification is technically allowed and can be initiated by
a properly qualified intruder. Such intruder can theoretically easily pass the relevant
identification, record his file of the necessary template configuration, containing, for
example, all zeros and a small number of ones—say, 16 bits in an 832-bit row. As
every student would know, writing 1 over 0 in the flash memory changes nothing,
while writing 0 over 1 changes the actual state of the memory cell. Since each row
of the matrix in production is usually checked in two microseconds, the intruder can
inject the malicious bits for as long as necessary. To understand this point, the reader
needs to know that the authors of this first published study [110] managed to collect
the necessary information from 50 randomly selected samples of A3P250 in a week.
4 Hardware Trojans in Microcircuits
Table 4.1 Results of analysis of the security levels in the ProASIC3 microcircuit [110]
Region
security
Access
read
Access
verification
Access
write
Block
security
AES-coding Expected
security
Time of
attacks
FROM
(Flash)
Yes
Yes
Yes
Yes
Yes
Medium
Seconds
FPGA
array
No
Yes
Yes
Yes
Yes
High
Days
AES key
No
Yes
Yes
Yes
No
Medium
Seconds
Flash lock
passkey
No
Yes
Yes
Yes
No
Very high Clock
Backdoor
key
No
Yes
Yes
Yes
No
Very high Clock
Permanent
lock
No
No
Yes
No
No
Ultra high Minutes
Table 4.1 generalizes the assessed security provision levels in ProASIC3 microcircuits according to the conclusions from the studies. As we can see from this table,
Passkey offers the best security level for protection from maliciously reprogrammed
chip, while permanent lock shall only be used as the last means of turning a microcircuit into a one-time programmable (OTP) chip. However, even though the mechanism embedded by engineers in the microcircuit is actually capable of providing the
maximum level of protection, the permanent lock still has certain physical “cracks”
in security. It provides a possible side channel for organization of attacks associated
with damage infliction.
Other ways of extracting confidential information from FPGA can be found in
literature. One of these ways was published back in 2010; it used a special type of
optical attack to inflict damage—so-called bumping attacks [119].
Another method used the vulnerability of AES implementation and, in particular,
the message authentication code (MAC) is usually used to protect the encrypted code
encoded by the developer [120].
It is absolutely obvious that such unauthorized “disclosure” of the AES key in
ProASIC3 microcircuits can allow any qualified intruder to extract the IP even
without directly accessing the source code recorded by the microcircuit designer.
Even though regular users usually don’t have access to configuration of the AESencoded bit stream, such verification is technically allowed and can be initiated by
a properly qualified intruder. Such intruder can theoretically easily pass the relevant
identification, record his file of the necessary template configuration, containing, for
example, all zeros and a small number of ones—say, 16 bits in an 832-bit row. As
every student would know, writing 1 over 0 in the flash memory changes nothing,
while writing 0 over 1 changes the actual state of the memory cell. Since each row
of the matrix in production is usually checked in two microseconds, the intruder can
inject the malicious bits for as long as necessary. To understand this point, the reader
needs to know that the authors of this first published study [110] managed to collect
the necessary information from 50 randomly selected samples of A3P250 in a week.
