4.4 Methods of Implementation of Hardware Trojans …
327
the system or distributed across several components, such as the processor, memory,
I/O circuits, power sources, or synchronization circuits. The feature of localization is
determined by the complexity of a specific IC project, the difficulty of introduction,
and the final effect that a hardware Trojan should cause. And for this we need to
know all the possible mechanisms of the operation of hardware Trojans. Below using
highlights we will try to briefly consider the consequences that can be expected from
their introduction, and to characterize the typical threats associated with hardware
Trojans in application-specific microcircuits.
It should be noted that hardware Trojans are relatively new threats to cybersecurity, however they significantly expand opportunities for attacking information
systems. Previously, attacks were limited to software only, focusing on weaknesses
of software. Security tools for specific software were developed on the basis of
the authenticity of hardware; therefore, generally accepted approaches to software
protection today are unable to provide security from hardware Trojans. From this
point of view, hardware Trojans represent a rather complicated security problem.
Trojans can be implemented not only in application-specific ICs (ASIC) (although
in most cases they are designed for this purpose), but also in commercial off-the-shelf
(COTS) electronic components, these are microprocessors, digital signal processors,
or as software changes in FPGA firmware. Considering the fact that changes are
made to the lowest hierarchical level of a system, mechanisms and types of violating
action may be of the most diverse nature. In general, these effects can be conditionally
classified as changes in functionality, specification changes, information leakage, or
denial of service. Specific hardware Trojans can implement either any one of these
violating actions or their combinations.
Hardware Trojans, changing the IC functionality through the introduction of an
additional logical circuit or by turning off a part of the existing logical circuit directly
threaten the integrity and security of an information system. Data changes in memory,
effects on computational operations or on a communication channel are typical targets
of the introduction in question. Functional modifications can be very diverse; the
effects of this class of hardware Trojans are limited only by the resources of a system,
imagination, and “skill” (qualification) of an attacker. For example, in [140], there
is a scenario in which a relatively simple destructive hardware Trojan may insert an
error into an algorithm based on the well-known Chinese remainder theorem when
calculating a public key cryptographic algorithm (RSA), which ultimately leads to a
compromised RSA-key.
An example of modification is given in [141], as a result of which the error
detection module receives input signals that are to be rejected according to the
specification. These signals can be used by an attacker to organize an attack.
Natural errors of IC developers, such as Pentium FDIV bug (an error affecting the
floating point unit in the original Intel Pentium processors released in 1994), can be
reproduced by a hardware Trojan, and selectively can be used to prevent its detection.
In some cases, special hardware Trojans can be developed to enable changes in the
order of execution of CPU instructions, for organizing data leakage through side
channels, for changing the contents of programmable read-only memory (PROM),
which is most dangerous for application-specific microcircuits.
327
the system or distributed across several components, such as the processor, memory,
I/O circuits, power sources, or synchronization circuits. The feature of localization is
determined by the complexity of a specific IC project, the difficulty of introduction,
and the final effect that a hardware Trojan should cause. And for this we need to
know all the possible mechanisms of the operation of hardware Trojans. Below using
highlights we will try to briefly consider the consequences that can be expected from
their introduction, and to characterize the typical threats associated with hardware
Trojans in application-specific microcircuits.
It should be noted that hardware Trojans are relatively new threats to cybersecurity, however they significantly expand opportunities for attacking information
systems. Previously, attacks were limited to software only, focusing on weaknesses
of software. Security tools for specific software were developed on the basis of
the authenticity of hardware; therefore, generally accepted approaches to software
protection today are unable to provide security from hardware Trojans. From this
point of view, hardware Trojans represent a rather complicated security problem.
Trojans can be implemented not only in application-specific ICs (ASIC) (although
in most cases they are designed for this purpose), but also in commercial off-the-shelf
(COTS) electronic components, these are microprocessors, digital signal processors,
or as software changes in FPGA firmware. Considering the fact that changes are
made to the lowest hierarchical level of a system, mechanisms and types of violating
action may be of the most diverse nature. In general, these effects can be conditionally
classified as changes in functionality, specification changes, information leakage, or
denial of service. Specific hardware Trojans can implement either any one of these
violating actions or their combinations.
Hardware Trojans, changing the IC functionality through the introduction of an
additional logical circuit or by turning off a part of the existing logical circuit directly
threaten the integrity and security of an information system. Data changes in memory,
effects on computational operations or on a communication channel are typical targets
of the introduction in question. Functional modifications can be very diverse; the
effects of this class of hardware Trojans are limited only by the resources of a system,
imagination, and “skill” (qualification) of an attacker. For example, in [140], there
is a scenario in which a relatively simple destructive hardware Trojan may insert an
error into an algorithm based on the well-known Chinese remainder theorem when
calculating a public key cryptographic algorithm (RSA), which ultimately leads to a
compromised RSA-key.
An example of modification is given in [141], as a result of which the error
detection module receives input signals that are to be rejected according to the
specification. These signals can be used by an attacker to organize an attack.
Natural errors of IC developers, such as Pentium FDIV bug (an error affecting the
floating point unit in the original Intel Pentium processors released in 1994), can be
reproduced by a hardware Trojan, and selectively can be used to prevent its detection.
In some cases, special hardware Trojans can be developed to enable changes in the
order of execution of CPU instructions, for organizing data leakage through side
channels, for changing the contents of programmable read-only memory (PROM),
which is most dangerous for application-specific microcircuits.
