312
4 Hardware Trojans in Microcircuits
spectrum method in development of the MOLES hardware Trojan helped read multibit information based on the power consumption analysis with the sensitivity below
the level of IC’s intrinsic noise, which ensures covert operation of such Trojans. The
authors of [118] claim that this technology is currently the most secure and resistant
to most known methods of detection of hardware Trojans, such as visual control,
performance of functional tests, and detection based on characteristic fingerprint
features of an IC. Even though this scheme employs a very small number of logic
gates, computing power required to recover the read data with a low SNR ratio can
be critically significant, taking into account the variability of characteristics. The
authors of [118] suggested a generalized method for design and implementation of
MOLES based on the classical mathematical apparatus of the detection theory for
analysis of the differential power, which is necessary for extraction of multi-bit keys.
The obtained results are based on modeling extraction of only relatively short keys
(8-bit), which is very far from the practically used keys with great numbers of bits.
Additionally, the authors indicate what specific issues need to be solved for practical
reliable recovery of multi-bit keys based on the analysis of the cryptoprocessor power
consumption.
The work [117] presents the results of a specific targeted experiment with two
simplified hardware implants embedded in RSA-based encryption schemes—a standard algorithm, which was previously considered extremely effective for analyzing
effects associated with side channels. The hardware implants employed a simple
counter, which disconnected the IC from active power supply after reaching a certain
threshold, and an equally simple comparator, which compared the data on the system
bus or register with a certain fixed value determined by customer and introduced
changes corresponding to the malicious intent in the computing process when the
set correspondence was exceeded. Of course, such hardware implants in microcircuits are fairly difficult to find, and they can be easily used to disconnect the main
electrical circuits, steal information, organize “random” and “catastrophic” failures
in the system, compromise integrity or security of the entire information or control
system including such infected IC.
The paper [126] considers an example of another hardware Trojan, the action of
which leads to data leakage from the DES encryption kernel. This circuit extracts
1 bit of a 56-bit key per clock cycle. By hacking 1 bit in every 64-bit block of the
transmitted data, such Trojan will ensure reliable and secure data leakage. After
accumulation of all 56 blocks of the encrypted text, the complete key is transferred
via the previously specified radio channel, thus fully compromising the claimed
encryption. Moreover, the extracted key is usually hidden in the acceptable range of
amplitude or frequency due to the variation of the process parameters, which ensures
full compliance with all developed functional specifications of the IC.
A number of works describe another relatively new type of hardware implants
based on reliability parameters of an IC. These Trojans include easy-to-implement
but extremely dangerous modifications of the process, which enhance degradation
of CMOS IC parameters. Changes in technology may not affect the internal characteristics of the circuit; however, they do affect an increase in the variability of
process parameters; therefore, they are detected only in the course of process tests
Précédent

- 331/839

Suivant