338
4 Hardware Trojans in Microcircuits
excluded: the microcircuit manufacturer can reproduce the design so that it includes
a certain schematics at the physical level.
The evolution of methods for detecting hardware Trojans should be considered
“in conjunction” with the evolution of Trojans themselves. It is absolutely clear that
in most cases the methods of detecting the first hardware Trojans cannot be applied
to their later sophisticated structures, but there are a number of features common to
all generations of these malware. For example, to accomplish their tasks, hardware
Trojans should undergo functional tests, while remaining unnoticed they still include
two basic mechanisms: a trigger and useful load.
A trigger activates a charge under certain conditions, for example, in case of a
rare event (occurrence of a set of bits 0x3745 in the data line), after a certain time
interval (for example, 10,000 s) or at a certain state of the environment (for example,
if the temperature is 65 °C). The most important requirement for the trigger start-up
condition is that it is not detected (failed) during functional tests, which are the most
important elements of the hardware production process. Otherwise, the trigger can
trigger the Trojan during testing, making it easier to detect.
The useful load mechanism performs the actual target function of the Trojan.
Such a function, for example, may consist in a complete shutdown of the hardware
system, interception of sensitive data (for example, a cryptographic key), or remote
control of the hardware system (which corresponds to the creation of a workaround
in the operation of the hardware).
As will be clear from the following overview, this problem is extremely
multifaceted and illustrates a wide range of possible attack vectors.
Experts considered many options for threats against infrastructure components.
For example, Jean and Macris demonstrate that there is a potential for the leakage
of a cryptographic key of a wireless device via a wireless channel [165]. Depending
on each key bit, the wireless signal varies within tolerance levels. In this case, it is
enough for an attacker to be within the range of the wireless device, record the signal,
and perform statistical analysis to obtain the key. Subsequently, the attacker will be
able to use this key for authorization and use the device as usual, which will allow
him to undermine the operation of the entire system to which the device belongs.
It has been shown [173] that by modulating the signal from the device power
supply, an imperceptible leakage of any data can be organized. In this case, it is
problematic to detect this hidden data transmission, since the signal is modulated by
means of multiple transmission with code division, i.e., using the so-called distributed
spectrum technology. Therefore, without knowing the correct code, the hidden signal
cannot be detected, since it is indistinguishable from noise. To obtain confidential
data (for example, a cryptographic key), an attacker should de-energize the device
being attacked and demodulate it by combining it with the necessary code.
A malicious processor with introduced hardware that allows an attacker to conduct
massive attacks at the software level was created in work [168]. This malicious
processor describes the mechanisms that allow illegally logging into the operating
system as an administrative user without using a password. That way, the attacker
can gain broad access to the infrastructure component. The introduction of such a
4 Hardware Trojans in Microcircuits
excluded: the microcircuit manufacturer can reproduce the design so that it includes
a certain schematics at the physical level.
The evolution of methods for detecting hardware Trojans should be considered
“in conjunction” with the evolution of Trojans themselves. It is absolutely clear that
in most cases the methods of detecting the first hardware Trojans cannot be applied
to their later sophisticated structures, but there are a number of features common to
all generations of these malware. For example, to accomplish their tasks, hardware
Trojans should undergo functional tests, while remaining unnoticed they still include
two basic mechanisms: a trigger and useful load.
A trigger activates a charge under certain conditions, for example, in case of a
rare event (occurrence of a set of bits 0x3745 in the data line), after a certain time
interval (for example, 10,000 s) or at a certain state of the environment (for example,
if the temperature is 65 °C). The most important requirement for the trigger start-up
condition is that it is not detected (failed) during functional tests, which are the most
important elements of the hardware production process. Otherwise, the trigger can
trigger the Trojan during testing, making it easier to detect.
The useful load mechanism performs the actual target function of the Trojan.
Such a function, for example, may consist in a complete shutdown of the hardware
system, interception of sensitive data (for example, a cryptographic key), or remote
control of the hardware system (which corresponds to the creation of a workaround
in the operation of the hardware).
As will be clear from the following overview, this problem is extremely
multifaceted and illustrates a wide range of possible attack vectors.
Experts considered many options for threats against infrastructure components.
For example, Jean and Macris demonstrate that there is a potential for the leakage
of a cryptographic key of a wireless device via a wireless channel [165]. Depending
on each key bit, the wireless signal varies within tolerance levels. In this case, it is
enough for an attacker to be within the range of the wireless device, record the signal,
and perform statistical analysis to obtain the key. Subsequently, the attacker will be
able to use this key for authorization and use the device as usual, which will allow
him to undermine the operation of the entire system to which the device belongs.
It has been shown [173] that by modulating the signal from the device power
supply, an imperceptible leakage of any data can be organized. In this case, it is
problematic to detect this hidden data transmission, since the signal is modulated by
means of multiple transmission with code division, i.e., using the so-called distributed
spectrum technology. Therefore, without knowing the correct code, the hidden signal
cannot be detected, since it is indistinguishable from noise. To obtain confidential
data (for example, a cryptographic key), an attacker should de-energize the device
being attacked and demodulate it by combining it with the necessary code.
A malicious processor with introduced hardware that allows an attacker to conduct
massive attacks at the software level was created in work [168]. This malicious
processor describes the mechanisms that allow illegally logging into the operating
system as an administrative user without using a password. That way, the attacker
can gain broad access to the infrastructure component. The introduction of such a
