316
4 Hardware Trojans in Microcircuits
□ n-well р-well nimpurity р-impurity
Active area Щ
Polysilicon Ц
Contact Ц Metal 1
n-well p-well nimpurity p-impurity
Active area И
Polysilicon Ц
Contact Ц Metal 1
a) Original
b) Trojan
Fig. 4.23 Layout drafts of a cryptographic unit fragment: source (a) and infected (b)
The local change in the specific electrical conductivity of one of the transistor
regions underlying this hardware implant was implemented in two versions:
(1) Standard digital postprocessing of signals from Intel Secure Key.
(2) Utilization on the bit channel (technical data leakage channel) using the table
bit stuffing method (Substitution-box).
The latter method is more versatile and can be used on other processor chips with
minor changes.
The possibility of using the built-in PRN through the RdRand first appeared in the
Intel processors of the Ivy Bridge architecture. Intel has written detailed tutorials for
programmers. They contain information about the methods of optimal implementation of cryptographic algorithms and provide reference to the description of the
principles of secure key. For a long time, efforts of security experts were aimed at
detecting vulnerabilities in the software section only. Therefore, covert interference
in Intel chips on the hardware level, which was documented for the first time, turned
out to be much more dangerous and perfectly real in practice.
To sum it all up, there are reliable (documented) facts of introduction of Trojans
into typical microcircuits of the largest companies (Actel and Intel); therefore, it is
necessary to consider all possible consequences of this new threat.
4 Hardware Trojans in Microcircuits
□ n-well р-well nimpurity р-impurity
Active area Щ
Polysilicon Ц
Contact Ц Metal 1
n-well p-well nimpurity p-impurity
Active area И
Polysilicon Ц
Contact Ц Metal 1
a) Original
b) Trojan
Fig. 4.23 Layout drafts of a cryptographic unit fragment: source (a) and infected (b)
The local change in the specific electrical conductivity of one of the transistor
regions underlying this hardware implant was implemented in two versions:
(1) Standard digital postprocessing of signals from Intel Secure Key.
(2) Utilization on the bit channel (technical data leakage channel) using the table
bit stuffing method (Substitution-box).
The latter method is more versatile and can be used on other processor chips with
minor changes.
The possibility of using the built-in PRN through the RdRand first appeared in the
Intel processors of the Ivy Bridge architecture. Intel has written detailed tutorials for
programmers. They contain information about the methods of optimal implementation of cryptographic algorithms and provide reference to the description of the
principles of secure key. For a long time, efforts of security experts were aimed at
detecting vulnerabilities in the software section only. Therefore, covert interference
in Intel chips on the hardware level, which was documented for the first time, turned
out to be much more dangerous and perfectly real in practice.
To sum it all up, there are reliable (documented) facts of introduction of Trojans
into typical microcircuits of the largest companies (Actel and Intel); therefore, it is
necessary to consider all possible consequences of this new threat.
