4.2 Description of the First Documented Facts …
313
specially developed for this purpose. Such hardware Trojans may be based on the
following physical degradation phenomena: the effect of hot electrons (HCI), the
electrical breakdown of the gate dielectric, the effect of temperature instability under
reverse bias in the p-MOS transistor (NBTI effect), and the effect of electromigration.
According to our classification, they can be attributed to permanent active Trojans
of the DoS (denial of service) type, which inevitably lead either to gradual degradation of working parameters or to premature failures of integrated circuits and circuit
components.
4.2.5.2 Hardware Trojans in Intel Processors
As early as in 1995, the Ministry of Defence of the USA first publicly expressed
concern that in case of a sufficient technical training of enemy specialists, there is a
danger of these specialists performing hidden (unauthorized) modification of any chip
designed by American electronic companies for the needs of the American military.
Such modified chip will operate in critical nodes of military and space systems, while
the introduced Trojan (hardware implant) will remain unnoticed, undermining the
defensive capacity of the country on the very fundamental level. For a long time, this
hazard has remained purely hypothetical; however, another international group of
researchers was able to implement it on a physical level and for the first time openly
publish the results of their study of one of the absolute leaders of the semiconductor
industry—the international corporation Intel.
For example, Georg T. Becker from the Massachusetts State University together
with colleagues from Switzerland and Germany created (within the framework of
proving the concept) two custom versions of a hardware-level Trojan, which interrupted operation of the pseudo-random number generator (PRNG) in the cryptographic unit of Intel processors employing the IvyBridge architecture. The cryptographic keys created with the help of such modified PRNG will be easily predictable
for any encryption system.
Presence of such hardware implant cannot be identified by specially designed
embedded tests or visual examination of the processor chip layout. How could this
happen? In order to answer this question, it is necessary to go back to the history of
creation of a hardware PRNG and examine the basic principles of its work.
When creating standard cryptographic systems of this level, it is necessary to
eliminate the possibility of quick password guessing by any intruder. Their length
and the degree of unpredictability directly influence the number of options that the
attacker would need to go through. Key length can always be set directly; however,
ensuring uniqueness of options of these keys is much more difficult. For this purpose,
cryptography specialists usually use random numbers during creation of keys.
It is believed by cybersecurity specialists that program algorithms only cannot
ensure a truly random stream of numbers with their even chaotic distribution over
the entire indicated multitude. They will always have a great frequency of occurrence
in some parts of the range and remain predictable to some extent. Therefore, most
313
specially developed for this purpose. Such hardware Trojans may be based on the
following physical degradation phenomena: the effect of hot electrons (HCI), the
electrical breakdown of the gate dielectric, the effect of temperature instability under
reverse bias in the p-MOS transistor (NBTI effect), and the effect of electromigration.
According to our classification, they can be attributed to permanent active Trojans
of the DoS (denial of service) type, which inevitably lead either to gradual degradation of working parameters or to premature failures of integrated circuits and circuit
components.
4.2.5.2 Hardware Trojans in Intel Processors
As early as in 1995, the Ministry of Defence of the USA first publicly expressed
concern that in case of a sufficient technical training of enemy specialists, there is a
danger of these specialists performing hidden (unauthorized) modification of any chip
designed by American electronic companies for the needs of the American military.
Such modified chip will operate in critical nodes of military and space systems, while
the introduced Trojan (hardware implant) will remain unnoticed, undermining the
defensive capacity of the country on the very fundamental level. For a long time, this
hazard has remained purely hypothetical; however, another international group of
researchers was able to implement it on a physical level and for the first time openly
publish the results of their study of one of the absolute leaders of the semiconductor
industry—the international corporation Intel.
For example, Georg T. Becker from the Massachusetts State University together
with colleagues from Switzerland and Germany created (within the framework of
proving the concept) two custom versions of a hardware-level Trojan, which interrupted operation of the pseudo-random number generator (PRNG) in the cryptographic unit of Intel processors employing the IvyBridge architecture. The cryptographic keys created with the help of such modified PRNG will be easily predictable
for any encryption system.
Presence of such hardware implant cannot be identified by specially designed
embedded tests or visual examination of the processor chip layout. How could this
happen? In order to answer this question, it is necessary to go back to the history of
creation of a hardware PRNG and examine the basic principles of its work.
When creating standard cryptographic systems of this level, it is necessary to
eliminate the possibility of quick password guessing by any intruder. Their length
and the degree of unpredictability directly influence the number of options that the
attacker would need to go through. Key length can always be set directly; however,
ensuring uniqueness of options of these keys is much more difficult. For this purpose,
cryptography specialists usually use random numbers during creation of keys.
It is believed by cybersecurity specialists that program algorithms only cannot
ensure a truly random stream of numbers with their even chaotic distribution over
the entire indicated multitude. They will always have a great frequency of occurrence
in some parts of the range and remain predictable to some extent. Therefore, most
