326
4 Hardware Trojans in Microcircuits
provide support for subsequent software attacks of a higher level. Targeted attacks
include the following attacks:
• Altering an information bit impairing integrity of the stored data;
• Reducing functionality of cryptographic kernels;
• Attacks causing leakage of confidential information.
The system can be simultaneously infected with several hardware Trojans that
undermine its security by joint actions.
In order to ensure complete understanding of the effect of hardware Trojans on
systems and development of methods of their detection, it is necessary to study
the mechanisms of altering information during introduction of Trojans, as well as
different possible activation mechanisms. Therefore, studies of the possible dangers
posed by Trojans, development of their design and introduction methods and activation mechanisms comprise an integral part of operation in searching ways of
preventing introduction, identifying and combating hardware implants in order to
ensure safety of the used ICs.
IC development and production process, as a rule, includes such stages as IC specification, development, production, testing, and assembly. Today, they also need to
be considered as stages during which an intruder can introduce a hardware implant.
During the stage of specification (preparation of technical assignment), specifications
of the system are determined, including applied IC models and supposed functionality. After this state, characteristics of the system are implemented during the design
stage in a certain target constructive and technological basis taking into account functional and physical limitations. At the IC production stage, a set of photo masks is
manufactured, and the cycle of manufacturing IC crystals on silicon wafers is carried
out, followed by checking their functional and physical characteristics. After that,
wafers are cut into chips and packaged; ICs that are ready for operation are tested and
accepted. Figure 4.28 shows the main stage of IC development and the corresponding
estimates of the hardware Trojan introduction hazard levels [140].
Relatively impenetrable from the point of view of possible penetration of hardware
Trojans are only the stages of specification and testing in package, as well as the stages
of testing and acceptance. All other stages are basically vulnerable to introduction
of hardware Trojans, and the levels of IC security during them are determined by
those co-performers who ensure IC production and testing, as well as by suppliers
of development tools, IP blocks, and libraries. In order to ensure and verify high
security level, each project manager has to adopt and carry out the special program
of measures, the form of which has been approved by the Ministry of Defence of the
USA [137]. Even though the stages identified above as safe can also be subjected to
influence of an intruder, e.g. setting of a hardware implant is possible even during
IC delivery or testing. Therefore, the complete cycle of IC designing and production
needs to be comprehensively studied with examination of strategies of effective
prevention of Trojan introduction and technologies for their detection. This is the
main goal of the above programs designed to ensure data safety.
Trojans can be introduced into any elements of an information system. As stated
above many times, localization of a Trojan can be limited by a separate element of
4 Hardware Trojans in Microcircuits
provide support for subsequent software attacks of a higher level. Targeted attacks
include the following attacks:
• Altering an information bit impairing integrity of the stored data;
• Reducing functionality of cryptographic kernels;
• Attacks causing leakage of confidential information.
The system can be simultaneously infected with several hardware Trojans that
undermine its security by joint actions.
In order to ensure complete understanding of the effect of hardware Trojans on
systems and development of methods of their detection, it is necessary to study
the mechanisms of altering information during introduction of Trojans, as well as
different possible activation mechanisms. Therefore, studies of the possible dangers
posed by Trojans, development of their design and introduction methods and activation mechanisms comprise an integral part of operation in searching ways of
preventing introduction, identifying and combating hardware implants in order to
ensure safety of the used ICs.
IC development and production process, as a rule, includes such stages as IC specification, development, production, testing, and assembly. Today, they also need to
be considered as stages during which an intruder can introduce a hardware implant.
During the stage of specification (preparation of technical assignment), specifications
of the system are determined, including applied IC models and supposed functionality. After this state, characteristics of the system are implemented during the design
stage in a certain target constructive and technological basis taking into account functional and physical limitations. At the IC production stage, a set of photo masks is
manufactured, and the cycle of manufacturing IC crystals on silicon wafers is carried
out, followed by checking their functional and physical characteristics. After that,
wafers are cut into chips and packaged; ICs that are ready for operation are tested and
accepted. Figure 4.28 shows the main stage of IC development and the corresponding
estimates of the hardware Trojan introduction hazard levels [140].
Relatively impenetrable from the point of view of possible penetration of hardware
Trojans are only the stages of specification and testing in package, as well as the stages
of testing and acceptance. All other stages are basically vulnerable to introduction
of hardware Trojans, and the levels of IC security during them are determined by
those co-performers who ensure IC production and testing, as well as by suppliers
of development tools, IP blocks, and libraries. In order to ensure and verify high
security level, each project manager has to adopt and carry out the special program
of measures, the form of which has been approved by the Ministry of Defence of the
USA [137]. Even though the stages identified above as safe can also be subjected to
influence of an intruder, e.g. setting of a hardware implant is possible even during
IC delivery or testing. Therefore, the complete cycle of IC designing and production
needs to be comprehensively studied with examination of strategies of effective
prevention of Trojan introduction and technologies for their detection. This is the
main goal of the above programs designed to ensure data safety.
Trojans can be introduced into any elements of an information system. As stated
above many times, localization of a Trojan can be limited by a separate element of
