314
4 Hardware Trojans in Microcircuits
practically used random number generators are actually pseudo-random, though they
rarely are reliable enough from the point of view of cryptography.
To reduce the predictability effect, any number generator requires a reliable source
of random initial content—the random seed. Usually, its functions are performed by
results of measurement of some chaotic physical processors, for example, fluctuations
of intensity of light oscillations or registration of radio frequency noise. It would be
good to use such random element (as well as the entire hardware PRNG) as portable
or even embedded device.
And Intel has been building such PRNGs into their chips starting from late 1990s.
They used to be analog in nature. Random values were output due to hard-to-predict
physical processes, usually including heat and electromagnetic noises. Analog generators were relatively easy to implement structurally as separate block, but extremely
hard to physically integrate into new microcircuits. As design norms applied to microcircuit production process were reduced, developers needed new lengthy calibration
stages. Moreover, natural decrease in the value of the supply voltage of microcircuits
from 5 to 3 V and even lower inevitably affected the signal-to-noise ratio in such
systems. PRNGs operated constantly and consumed significant amounts of energy,
while their operation speed left much to be desired.
The idea of a completely digital pseudo-random number generator seemed impossible to implement for a long time. This was due to the fact that the state of any
digital circuit is always strictly determined and predictable. How can one introduce
the necessary element of randomness if there are no analog components?
Known attempts to achieve the desired chaos using digital elements only had
been undertaken by Intel engineers from 2008 and achieved success after a couple
of years of active research [125]. The work was first presented in 2010 at VLSI
summer symposium in Honolulu and made a small sensation in modern cryptography.
The first fully digital, fast, and energy-efficient PRNG was implemented in generalpurpose stock-production processors, namely, in processor Core i7-3770K of the
Ivy Bridge architecture with embedded (pseudo-) random number generator. It was
first called Bull Mountain and then renamed as Secure Key for advertising purposes.
This cryptographic unit consists of three basic modules. The first module generates a
stream of random bits at a relatively low speed (3 Gb/s) and the second one estimates
their dispersion and combines them into separate 256-bit blocks that are used as
initial content sources. After performing a series of mathematical procedures in the
third block, a stream of 128-bit random numbers is generated with a higher speed.
Based on these numbers, random numbers are created in case of necessity with the
help of a new instruction (RdRand) and placed in a designated register. These random
numbers have a required length, 16, 32, or 64 bits, and are ultimately transmitted to
the requesting program.
Errors randomly found by users in pseudo-random number generators and later
malicious modifications of these generators caused the users to lose trust in these
previously widely popular cryptographic products and the procedure for their certification (see http://www.computerra.ru/83128/the-vulnerability-of-rsa-implementati
ons-on-smart-cards/).
4 Hardware Trojans in Microcircuits
practically used random number generators are actually pseudo-random, though they
rarely are reliable enough from the point of view of cryptography.
To reduce the predictability effect, any number generator requires a reliable source
of random initial content—the random seed. Usually, its functions are performed by
results of measurement of some chaotic physical processors, for example, fluctuations
of intensity of light oscillations or registration of radio frequency noise. It would be
good to use such random element (as well as the entire hardware PRNG) as portable
or even embedded device.
And Intel has been building such PRNGs into their chips starting from late 1990s.
They used to be analog in nature. Random values were output due to hard-to-predict
physical processes, usually including heat and electromagnetic noises. Analog generators were relatively easy to implement structurally as separate block, but extremely
hard to physically integrate into new microcircuits. As design norms applied to microcircuit production process were reduced, developers needed new lengthy calibration
stages. Moreover, natural decrease in the value of the supply voltage of microcircuits
from 5 to 3 V and even lower inevitably affected the signal-to-noise ratio in such
systems. PRNGs operated constantly and consumed significant amounts of energy,
while their operation speed left much to be desired.
The idea of a completely digital pseudo-random number generator seemed impossible to implement for a long time. This was due to the fact that the state of any
digital circuit is always strictly determined and predictable. How can one introduce
the necessary element of randomness if there are no analog components?
Known attempts to achieve the desired chaos using digital elements only had
been undertaken by Intel engineers from 2008 and achieved success after a couple
of years of active research [125]. The work was first presented in 2010 at VLSI
summer symposium in Honolulu and made a small sensation in modern cryptography.
The first fully digital, fast, and energy-efficient PRNG was implemented in generalpurpose stock-production processors, namely, in processor Core i7-3770K of the
Ivy Bridge architecture with embedded (pseudo-) random number generator. It was
first called Bull Mountain and then renamed as Secure Key for advertising purposes.
This cryptographic unit consists of three basic modules. The first module generates a
stream of random bits at a relatively low speed (3 Gb/s) and the second one estimates
their dispersion and combines them into separate 256-bit blocks that are used as
initial content sources. After performing a series of mathematical procedures in the
third block, a stream of 128-bit random numbers is generated with a higher speed.
Based on these numbers, random numbers are created in case of necessity with the
help of a new instruction (RdRand) and placed in a designated register. These random
numbers have a required length, 16, 32, or 64 bits, and are ultimately transmitted to
the requesting program.
Errors randomly found by users in pseudo-random number generators and later
malicious modifications of these generators caused the users to lose trust in these
previously widely popular cryptographic products and the procedure for their certification (see http://www.computerra.ru/83128/the-vulnerability-of-rsa-implementati
ons-on-smart-cards/).
