4.4 Methods of Implementation of Hardware Trojans …
325
4.4 Methods of Implementation of Hardware Trojans
into Microcircuits
4.4.1 Introduction to the Problem
The relative simplicity of embedding the hardware Trojans described above in any
modern microcircuit certainly concerns cybersecurity specialists. Analysis of the
above material shows that malicious modifications can be introduced in the hardware
part of an IC both during development phase and during production phase, including
such stages as specification, designing, verification, and production. Moreover, such
hardware Trojan can be implemented even into an already manufactured IC [137].
The situation as of the moment of publication of this book is complicated by the
fact that modern trends in semiconductor industry are characterized by division of
the main stages of IC development and production into substages detailed above;
moreover, these substages are usually performed by several large factories spread
across the world and located mainly in Asia. Attraction of third-party co-performers
is now typical not only of the IC production stage, but for the IC design stage as well:
developers employ third-party software, widely use ready-made standard blocks (IP
blocks) designed by other third parties. IP blocks are often supplied in digital form
and designed by third-party companies specializing in certain technical projects.
Therefore, a hardware Trojan may look like a seemingly insignificant alteration of
a paragraph or a microcircuit specification, or as an additional line in the source
code written in the hardware description language (HDL), or as modification of
the silicon chip structure implemented without knowledge of the customer at the
production plant, for example, by slightly altering the topology of one of millions of
transistors. As noted above, if a change is implemented in a diffusion or implanted
layer, it becomes virtually invisible on the chip [132, 138].
The problem of hardware Trojans is currently comprehensively researched around
the world. We have already mentioned that the New York Polytechnic University
for several years held special contests among specialist teams in introduction and
detection of such introduced special devices [139], which facilitates development
of the technologies of preventing introduction of hardware Trojans and methods of
their detection. In 2007, Defence Advanced Research Project Agency of the USA
(DARPA) initiated a special program to ensure authenticity of the microcircuits used
in the US military systems; to this day, the Agency still funds a number of science
and research centers involved in developing methods and techniques of detection of
hardware Trojans. Most of the other published studies are performed by university
groups and mostly dedicated to the methods of preventing introduction of Trojans
during the IC design stage, as well as methods for detection of Trojans in ICs after
production.
It is clear that if a hardware Trojan has been introduced in the system, it remains
there forever regardless of whether it is on or off. It can potentially affect operation of
the entire system if introduced into any of its component ICs. The effect of hardware
Trojans may vary from simple targeted attacks to complex combined attacks, which
Précédent

- 344/839

Suivant