302
4 Hardware Trojans in Microcircuits
Fig. 4.17 Main components
of the analysis workstation:
control board (a), DPA
analysis circuit (b)
with the help of standard DPA methods. Implementation of this approach helped
the authors of [110] precisely separate commands with different functions. DPA is
clearly a good approach for finding specific commands; however, it doesn’t really
help ordinary specialists to understand their functions, since it is usually hindered by
ever-present noise of the standard measuring equipment—the so-called measurement
noise.
According to the contents of works [116, 119–123], during the microcircuit analysis with the help of the PEA technology methods, the researchers were mainly
focused on the attempts to achieve the best signal-to-noise ratio (SNR) in order to
better understand specific functions of each detected unidentified command. During
this process, it was discovered that certain similar operations had already been known,
and certain specific DPA-like protection methods had been designed for them. For
example, the Passkey protocol in the specification for this microcircuit declares a
completely different level of security at the top level of the AES hierarchy of the
coding system in ProASIC3 designed to prevent all possible attempts of IP cloning
undertaken by any intruders. It should be noted that certain DPA countermeasures
found by the authors in the previously cited [110] in relation to Passkey protection
methods include highly efficient compensation of such EM leaks and high noise level
due to SNR below −20 dB.
Précédent

- 321/839

Suivant