336
4 Hardware Trojans in Microcircuits
Many other known external mechanisms for activating hardware Trojans based
on direct interaction with some target device (“activator”). Also, activation can be
initialized by some “attached” component of the onboard information system, for
example, by additional memory.
Permanently active hardware Trojans
There are also such hardware Trojans in microcircuits that are always active and
cannot be “activated” or “deactivated” by any special trigger mechanism. Hardware
Trojans are also possible, which automatically make “imperceptible” changes to the
specification, functionality, or synchronization system and absolutely do not need a
trigger mechanism. An example of such permanent Trojans is a hardware Trojan that
leaks data through a side channel that reflects the activity of a specific IC.
Such permanently active hardware Trojans may have more “thin” trigger mechanisms. In [145], a variant of such a topology modification is discussed, in which
individual nodes or parts of an IC have a high probability of failure, that is, it can
be said that the trigger mechanism is constantly in operation and leads to a gradual
degradation of operating characteristics of an IC. In the work already mentioned
above [22], some possible modifications in an IC are discussed, as a result of which
it fails after a certain period of operation with a given duration from several months
to a year or even more. Examples of such hardware Trojans are deliberate (ordered
by attackers) changes in the technological process of manufacturing a microcircuit,
leading to a deterioration in the reliability of an IC. The difficulty of their detection
is due to the fact that the changes made in no way explicitly affect the parameters
of an IC, which are within the acceptable limits characteristic of the process. Since
such Trojans are permanently active, they do not have side activation effects, such as
changes in noise characteristics of an IC, changes in the nature of power consumption
or temperature, etc.
It is obvious that such an unauthorized change in the manufacturing process
of a mass-produced microcircuit cannot be performed by any one “unfair process
engineer,” but this procedure can be performed by experts—agents of the “potential
enemy” countries.
It should be noted that the developer of a hardware Trojan simply needs to create
a trigger activation mechanism that will be difficult to detect, since he can use a
huge “state space” of the system into which the trojan is being introduced. This
state space includes all internal nodes of logical circuits, IC inputs and outputs, IC
topology modification, variations of technological processes, and analog effects of
electronics in an IC. Hybrid mechanisms combining some or all of the known trigger
principles make it more difficult to detect hardware Trojans.
The general opinion of researchers today is that permanent hardware Trojans
are much more difficult to detect than complex structures of trigger mechanisms to
prevent accidental activation or activation during testing.
In conclusion of this section, it should be noted that technically the task of introducing hardware into the information system and then activating hardware Trojans at
the right moment becomes easier with increasing state space, increasing parallelism
of calculations, increasing internal wiring, and increasing the number of inputs and
4 Hardware Trojans in Microcircuits
Many other known external mechanisms for activating hardware Trojans based
on direct interaction with some target device (“activator”). Also, activation can be
initialized by some “attached” component of the onboard information system, for
example, by additional memory.
Permanently active hardware Trojans
There are also such hardware Trojans in microcircuits that are always active and
cannot be “activated” or “deactivated” by any special trigger mechanism. Hardware
Trojans are also possible, which automatically make “imperceptible” changes to the
specification, functionality, or synchronization system and absolutely do not need a
trigger mechanism. An example of such permanent Trojans is a hardware Trojan that
leaks data through a side channel that reflects the activity of a specific IC.
Such permanently active hardware Trojans may have more “thin” trigger mechanisms. In [145], a variant of such a topology modification is discussed, in which
individual nodes or parts of an IC have a high probability of failure, that is, it can
be said that the trigger mechanism is constantly in operation and leads to a gradual
degradation of operating characteristics of an IC. In the work already mentioned
above [22], some possible modifications in an IC are discussed, as a result of which
it fails after a certain period of operation with a given duration from several months
to a year or even more. Examples of such hardware Trojans are deliberate (ordered
by attackers) changes in the technological process of manufacturing a microcircuit,
leading to a deterioration in the reliability of an IC. The difficulty of their detection
is due to the fact that the changes made in no way explicitly affect the parameters
of an IC, which are within the acceptable limits characteristic of the process. Since
such Trojans are permanently active, they do not have side activation effects, such as
changes in noise characteristics of an IC, changes in the nature of power consumption
or temperature, etc.
It is obvious that such an unauthorized change in the manufacturing process
of a mass-produced microcircuit cannot be performed by any one “unfair process
engineer,” but this procedure can be performed by experts—agents of the “potential
enemy” countries.
It should be noted that the developer of a hardware Trojan simply needs to create
a trigger activation mechanism that will be difficult to detect, since he can use a
huge “state space” of the system into which the trojan is being introduced. This
state space includes all internal nodes of logical circuits, IC inputs and outputs, IC
topology modification, variations of technological processes, and analog effects of
electronics in an IC. Hybrid mechanisms combining some or all of the known trigger
principles make it more difficult to detect hardware Trojans.
The general opinion of researchers today is that permanent hardware Trojans
are much more difficult to detect than complex structures of trigger mechanisms to
prevent accidental activation or activation during testing.
In conclusion of this section, it should be noted that technically the task of introducing hardware into the information system and then activating hardware Trojans at
the right moment becomes easier with increasing state space, increasing parallelism
of calculations, increasing internal wiring, and increasing the number of inputs and
