334
4 Hardware Trojans in Microcircuits
Sequential Trojan
Trigger
Payload
k-bit counter
Fig. 4.32 Principle of building a sequential logic-based Trojan
Sequential logic-based Trojan activation mechanisms
A sequential logic-based Trojan is also triggered by a specific sequence of events. If
we compare it with “combination” activation, then activation on “sequential” logic
has a much larger “state space,” since the trigger mechanism here can be implemented
using the classical theory of finite automaton. Thus, in [137], it is noted that, since
the finite state automaton provides logical depth, the sequence of events is usually
described by “unlikely” logical quantities and it is much more difficult to detect them
during testing and verification of an IC.
The simplest sequential trigger is the standard synchronous counter circuit
(Fig. 4.32), which is activated after completing a certain number of synchronization
cycles. In [147], such Trojans are rightly called “time-mines.” In [148], different
counters of asynchronous sequences are also discussed, in which at certain events an
increment occurs, for example, an increase in pulse front at the gate output. The same
authors suggest that attackers can use a hybrid activation mechanism, combining
synchronous and asynchronous triggers.
In [144], the so-called sequential cheat codes are discussed. For example, a
sequence of bytes (0xd, 0xe, 0xc, 0xa, 0xf, 0xb, 0xa, 0xd) may lead to the activation of a hardware Trojan during the implementation of eight synchronization
cycles. Moreover, there is no absolute need for these bytes to arrive sequentially;
in fact, they can be arbitrarily far separated in time (days, months, and even years).
Thus, the activation of a hardware Trojan can be achieved by a much more complex
sequence of events.
It is clear that it is not difficult to set the algorithm for triggering a sequential
trigger for any developer of a hardware Trojan. The only problem associated with an
increase in complexity is the power consumed by the Trojan and the number of logic
gates necessary for its implementation. In this regard, experts have proposed internal
sequential activation mechanisms that use known physical and analog effects in an
IC possible for use by intruders. For example, the classic functions for monitoring
microcircuit temperature or power consumption can easily be included in the trigger
4 Hardware Trojans in Microcircuits
Sequential Trojan
Trigger
Payload
k-bit counter
Fig. 4.32 Principle of building a sequential logic-based Trojan
Sequential logic-based Trojan activation mechanisms
A sequential logic-based Trojan is also triggered by a specific sequence of events. If
we compare it with “combination” activation, then activation on “sequential” logic
has a much larger “state space,” since the trigger mechanism here can be implemented
using the classical theory of finite automaton. Thus, in [137], it is noted that, since
the finite state automaton provides logical depth, the sequence of events is usually
described by “unlikely” logical quantities and it is much more difficult to detect them
during testing and verification of an IC.
The simplest sequential trigger is the standard synchronous counter circuit
(Fig. 4.32), which is activated after completing a certain number of synchronization
cycles. In [147], such Trojans are rightly called “time-mines.” In [148], different
counters of asynchronous sequences are also discussed, in which at certain events an
increment occurs, for example, an increase in pulse front at the gate output. The same
authors suggest that attackers can use a hybrid activation mechanism, combining
synchronous and asynchronous triggers.
In [144], the so-called sequential cheat codes are discussed. For example, a
sequence of bytes (0xd, 0xe, 0xc, 0xa, 0xf, 0xb, 0xa, 0xd) may lead to the activation of a hardware Trojan during the implementation of eight synchronization
cycles. Moreover, there is no absolute need for these bytes to arrive sequentially;
in fact, they can be arbitrarily far separated in time (days, months, and even years).
Thus, the activation of a hardware Trojan can be achieved by a much more complex
sequence of events.
It is clear that it is not difficult to set the algorithm for triggering a sequential
trigger for any developer of a hardware Trojan. The only problem associated with an
increase in complexity is the power consumed by the Trojan and the number of logic
gates necessary for its implementation. In this regard, experts have proposed internal
sequential activation mechanisms that use known physical and analog effects in an
IC possible for use by intruders. For example, the classic functions for monitoring
microcircuit temperature or power consumption can easily be included in the trigger
