304
4 Hardware Trojans in Microcircuits
generator of the rising edge generated test sequences in accordance to the simple
software algorithm developed by the authors. One part of the algorithm was fixed
and the other one could change depending on the order conditions.
If we tried to explain all the occurring analysis processes to an electronics college
student, it would all look very simple: since the DUT protocol performs a very specific
operation requested by the customer, its implementation results in the contents of this
information requested by the intruder actually leaking through side channels as a side
effect (unrecorded by the microcircuit specification). Responses from such technical
side channels can be registered by special sensors designed to monitor each specific
type of information activity via such side channels. Specialized sensors convert these
signals in the analog form; after that, the signals are automatically transformed into
a series of more understandable digital images and sent to the organizer of the attack
via special channels.
4.2.4 Analysis of the Results of the Control Experiment
for Identification of a Hardware Trojan
in the Special-Purpose Microcircuit ProASIC3
Analysis of publicly available literary sources dedicated to official documentation of
presence of hardware Trojans in special-purpose microcircuits can help us draw the
following extremely interesting conclusions.
For example, the method of scanning the field of commands of the JTAG protocol
for unidentified commands by checking the contents of the DR register [110], which
is widely used in practice by microcircuit manufacturers, brought some extremely
interesting and enlightening results. Reputable researches have indeed created many
different commands that can be used to control the standard DR register, the implementation of which was performed with the help of special codes with the length
different from the one typically used by a regular JTAG device. Figure 4.19a, which
shows certain results of analysis of registers obtained from the analysis in the STAPL
file (Fig. 4.18b) clearly demonstrates that certain standard registers would be impossible to update (by recording new data). Most of these registered represented readonly memory, including the FROW fragment mentioned in the STAPL file. The work
[110] demonstrates that only three bits of all the ones read by experts provided access
to the standard eight bits. The authors of [110] also determined that all these hidden
and non-updated registers were somehow miraculously inserted into certain areas
in the FROW memory. However, we know that each separate chip of the ProASIC3
microcircuit has its own unique digital data, which are saved both in the FROW
memory and in special hidden registers.
The authors of [119] have concluded that the analyzed standard ProASIC3 chips
contain certain functions hidden from their owners, which are not usually communicated to every regular consumer of microcircuits, and that this is “very bad.” Perhaps,
4 Hardware Trojans in Microcircuits
generator of the rising edge generated test sequences in accordance to the simple
software algorithm developed by the authors. One part of the algorithm was fixed
and the other one could change depending on the order conditions.
If we tried to explain all the occurring analysis processes to an electronics college
student, it would all look very simple: since the DUT protocol performs a very specific
operation requested by the customer, its implementation results in the contents of this
information requested by the intruder actually leaking through side channels as a side
effect (unrecorded by the microcircuit specification). Responses from such technical
side channels can be registered by special sensors designed to monitor each specific
type of information activity via such side channels. Specialized sensors convert these
signals in the analog form; after that, the signals are automatically transformed into
a series of more understandable digital images and sent to the organizer of the attack
via special channels.
4.2.4 Analysis of the Results of the Control Experiment
for Identification of a Hardware Trojan
in the Special-Purpose Microcircuit ProASIC3
Analysis of publicly available literary sources dedicated to official documentation of
presence of hardware Trojans in special-purpose microcircuits can help us draw the
following extremely interesting conclusions.
For example, the method of scanning the field of commands of the JTAG protocol
for unidentified commands by checking the contents of the DR register [110], which
is widely used in practice by microcircuit manufacturers, brought some extremely
interesting and enlightening results. Reputable researches have indeed created many
different commands that can be used to control the standard DR register, the implementation of which was performed with the help of special codes with the length
different from the one typically used by a regular JTAG device. Figure 4.19a, which
shows certain results of analysis of registers obtained from the analysis in the STAPL
file (Fig. 4.18b) clearly demonstrates that certain standard registers would be impossible to update (by recording new data). Most of these registered represented readonly memory, including the FROW fragment mentioned in the STAPL file. The work
[110] demonstrates that only three bits of all the ones read by experts provided access
to the standard eight bits. The authors of [110] also determined that all these hidden
and non-updated registers were somehow miraculously inserted into certain areas
in the FROW memory. However, we know that each separate chip of the ProASIC3
microcircuit has its own unique digital data, which are saved both in the FROW
memory and in special hidden registers.
The authors of [119] have concluded that the analyzed standard ProASIC3 chips
contain certain functions hidden from their owners, which are not usually communicated to every regular consumer of microcircuits, and that this is “very bad.” Perhaps,
