306
4 Hardware Trojans in Microcircuits
these functions are disclosed to certain consumers “trusted by someone,” but this is
a whole different story.
To be fair, it should be noted that even though they have no specialized DPA
countermeasures, ProASIC3 microcircuits are still two orders of magnitude (more
than 100 times) more resistant (in terms of time) to such pirate attacks with the DPA
method than unprotected standard commercial industrial microcontrollers, such as
PIC, AVR, MC68HC, MSP430, etc. This clearly makes all possible attacks aimed at
ProASIC3 chips a complex task.
This is exemplified by Fig. 4.20, which displays the result obtained by comparing
separate waveforms taken for various input data. The data averaged by n = 4.096
sweeps provide such low-noise result; it can be processed in just a few minutes
(Fig. 4.19b). As can be seen from various waveforms, the measurement noise masks
the basic useful signals with SNR below −20 dB. FFT sweep frequency has no
characteristic peaks (Fig. 4.20a); therefore, any digital filtration of the final data will
not achieve the significant improvement of the DPA results required by customers.
As shown in the work [110], the experts used various types of DPA equipment
to extract Passkey; however, they failed to acquire a single bit of information during
2 weeks of using a DPA device designed specifically for this purpose (oscilloscope
with special probe and PC with MATLAB). Although it need to be said that the
waveform obtained with the help of the DPA method was evaluated by those authors
in terms of many functions, including memory access, AES, Passkey process, etc.
As demonstrated by the authors of [110], even unprotected implementation of AES
coding requires taking at least 256 waveforms processed by special methods in order
to reduce their size and ensure reliable correlation with the key bits (Fig. 4.20).
However, the applied PEA approach ultimately allowed them to determine the key
bits. Effectiveness of the PEA method is ensured in terms of many factors. As we
know, the most important factor is the choice of the used frequency range; however,
the cost of such equipment used to collect and process such data after announcement
of the corresponding tenders may be significantly lower. Clearly, it also influences
the length of analysis and theoretically allows for real-time analysis. Figure 4.21
shows [110] that the time of detection of such hardware Trojan can be significantly
reduced from theoretical months to 1 or 2 weeks of analysis.
It must be that the authors of the work [110] at first actually analyzed all known
active commands of the standard JTAG port at the maximum power consumption
limit. Figure 4.21a shows the identification of AES and the Passkey verification
sweep, while Fig. 4.21b displays array verification sweeps and Flash FROM read
commands. With JTAG command analysis, one function requested a 128-bit key
with similar low leakage DPA resistance properties like Passkey. Given the unstable
internal clock and high noise from other parts of the scheme, verification of access
to Passkey and deliberately embedded backdoors showed the presence of leakage
through side channels, which was reduced compared to the AES operation (Fig. 4.22).
This was probably achieved due to the fact that the developers used a properly
organized IC instead of standard components of the CMOS library. The detected
leakage signal has an extended spectrum with separate uncharacteristic peaks in
the frequency domain, which makes narrowband filtering useless. The authors of
4 Hardware Trojans in Microcircuits
these functions are disclosed to certain consumers “trusted by someone,” but this is
a whole different story.
To be fair, it should be noted that even though they have no specialized DPA
countermeasures, ProASIC3 microcircuits are still two orders of magnitude (more
than 100 times) more resistant (in terms of time) to such pirate attacks with the DPA
method than unprotected standard commercial industrial microcontrollers, such as
PIC, AVR, MC68HC, MSP430, etc. This clearly makes all possible attacks aimed at
ProASIC3 chips a complex task.
This is exemplified by Fig. 4.20, which displays the result obtained by comparing
separate waveforms taken for various input data. The data averaged by n = 4.096
sweeps provide such low-noise result; it can be processed in just a few minutes
(Fig. 4.19b). As can be seen from various waveforms, the measurement noise masks
the basic useful signals with SNR below −20 dB. FFT sweep frequency has no
characteristic peaks (Fig. 4.20a); therefore, any digital filtration of the final data will
not achieve the significant improvement of the DPA results required by customers.
As shown in the work [110], the experts used various types of DPA equipment
to extract Passkey; however, they failed to acquire a single bit of information during
2 weeks of using a DPA device designed specifically for this purpose (oscilloscope
with special probe and PC with MATLAB). Although it need to be said that the
waveform obtained with the help of the DPA method was evaluated by those authors
in terms of many functions, including memory access, AES, Passkey process, etc.
As demonstrated by the authors of [110], even unprotected implementation of AES
coding requires taking at least 256 waveforms processed by special methods in order
to reduce their size and ensure reliable correlation with the key bits (Fig. 4.20).
However, the applied PEA approach ultimately allowed them to determine the key
bits. Effectiveness of the PEA method is ensured in terms of many factors. As we
know, the most important factor is the choice of the used frequency range; however,
the cost of such equipment used to collect and process such data after announcement
of the corresponding tenders may be significantly lower. Clearly, it also influences
the length of analysis and theoretically allows for real-time analysis. Figure 4.21
shows [110] that the time of detection of such hardware Trojan can be significantly
reduced from theoretical months to 1 or 2 weeks of analysis.
It must be that the authors of the work [110] at first actually analyzed all known
active commands of the standard JTAG port at the maximum power consumption
limit. Figure 4.21a shows the identification of AES and the Passkey verification
sweep, while Fig. 4.21b displays array verification sweeps and Flash FROM read
commands. With JTAG command analysis, one function requested a 128-bit key
with similar low leakage DPA resistance properties like Passkey. Given the unstable
internal clock and high noise from other parts of the scheme, verification of access
to Passkey and deliberately embedded backdoors showed the presence of leakage
through side channels, which was reduced compared to the AES operation (Fig. 4.22).
This was probably achieved due to the fact that the developers used a properly
organized IC instead of standard components of the CMOS library. The detected
leakage signal has an extended spectrum with separate uncharacteristic peaks in
the frequency domain, which makes narrowband filtering useless. The authors of
