4.2 Description of the First Documented Facts …
311
electronic system, which ultimately realize the mechanism providing the intruder
with free access to the protected memory regions, as well as with special shadow
mode, which helps the intruder execute a hidden embedded malware program out
of sight of the operator. This paper describes an example of a specific login-focused
attack, which gives the attacker a complete high level of access to the processor. This
attack was implemented with the help of a special malicious modification implemented on the circuit using only 1341 gates (less than 1% of all gates). For the first
time in public literature, the authors presented a specific structure of implementation
of a hardware implant, which can be used (or, perhaps, is already used) as a common
programmable platform for such attacks. The introduction of such modification at
the level of VHDL (integrated circuit hardware description language) is shown; the
simulation and synthesis of integrated circuits for a platform based on the Leon 3
SPARC 40 MHz processor are performed. This exact processor is widely used in
space project of NASA and the European Space Agency. Moreover, there are plans
to utilize it in all serious space projects for the nearest decades. The work examines
the method of detection of such hardware Trojan by analyzing the disturbances in
analog and digital signals caused by it. In particular, it is noted that with this method,
the operating system was able to see the software component of the memory access
component; technically, it is also possible to detect temporary delays of the signal
associated with implementation of such unauthorized modification. Moreover, the
paper [125] demonstrates general approaches aimed at solving the problem of protection of such malicious processors, some of which will be further considered in the
relevant sections of this book.
For the purpose of studying various possible methods of introducing such hardware implants in microcircuits for military and spacecraft applications, annual CSAW
(Cybersecurity Awareness Week) conference is held in the Polytechnic Institute of
the New York University. Within the framework of this conference, team contests in
introducing and detecting embedded hardware systems (embedded system challenge)
are held. For example, in 2008, the organizers (backed by the corresponding special
services) tasked the participants with accessing the FPGA-based over-protected cryptographic device “Alpha” by introducing a set of hardware implants; at the same time,
the device had to be able to pass a standard verification test. Competitors were given
a source HDL code and 1 month for development. Two teams became winners of
the contest: the first one developed a mechanism for secret key data leakage through
I/O channel, while the other team organized a DoS attack. Summarization of the
results of all developments that took part in the contest shows that 90% of all hardware implants were introduced during the IC design (development) stage; 50% of
these circuits were user-activated; and 75% of hardware Trojans were installed in
I/O circuits [3].
The work [118] analyzes the space of design parameters of hardware implants
and suggests a circuit containing less than 50 gates and generating power which can
serve as a side channel for organization of hidden leakage of secret information to the
customer. The technology, which is known as MOLES (malicious off-chip leakage
enabled by side channels), was implemented in a cryptographic IC based on the AES
algorithm and designed using 45 nm manufacturing technology. Using the spread
Précédent

- 330/839

Suivant