340
4 Hardware Trojans in Microcircuits
4.6.2 Basic Methods for Detecting Hardware Trojans
4.6.2.1 Analysis of Methods Using Third-Party Channels
In May 2007, Agraval et al. [22] published their work on the method of detecting
functions that were secretly introduced in an IC through a so-called bypass analysis.
The device under consideration (microcircuit) was examined in terms of using various
physical bypass channels, for example, power supply current or time. This work is
the first in a long line of publications on this topic.
At that time, all researchers paid special attention to the analysis via third-party
channels [151, 153, 154, 166, 172, 178, 186], but at the same time other methods
were proposed in the field of logical tests. To increase the success of detection, other
equally effective approaches to an increase of the activation frequency of hardware
Trojans have been proposed [20, 180].
4.6.2.2 Malicious Computer Systems
Authoritative experts King et al. [168] were the first to publish information about
the capabilities and methods of a comprehensive combined attack on software and
hardware. In this attack, a hardware Trojan serves as the basis for an extensive attack,
allowing an attacker to enter the operating system with root privileges by cracking
the security system of the hardware.
For example, New York University held a competition, the purpose of which was
to research various methods of introducing hardware Trojans. The criterion of success
in this competition was the most unobtrusive introduction of a malicious introduction
into the original microcircuit; the possibility of imperceptible information extraction
was also assessed. The works presented at the competition can be found in the
materials [155, 159]; in Chap. 6, we will take a closer look at both this method and
the others listed below in this section.
4.6.2.3 Improving Trojan Detection Performance
To enhance the detection of activation of Trojans, many approaches have been
proposed that should have increased the probability of detection in the course of
functional testing. Thus, the method of minimizing the triggering circuit is used to
reduce the overall activity of the object under study and to provide in this context
the possibility of measuring the (partial) activity of a Trojan in its presence [152].
A change in the supply voltage level on logical circuits inside the microcircuit
design leads to corresponding changes in the logical positions of these circuits.
This measure leads to an inversion of the detection probability—“a Trojan that was
previously difficult to find turns out to be visible” [193].
4 Hardware Trojans in Microcircuits
4.6.2 Basic Methods for Detecting Hardware Trojans
4.6.2.1 Analysis of Methods Using Third-Party Channels
In May 2007, Agraval et al. [22] published their work on the method of detecting
functions that were secretly introduced in an IC through a so-called bypass analysis.
The device under consideration (microcircuit) was examined in terms of using various
physical bypass channels, for example, power supply current or time. This work is
the first in a long line of publications on this topic.
At that time, all researchers paid special attention to the analysis via third-party
channels [151, 153, 154, 166, 172, 178, 186], but at the same time other methods
were proposed in the field of logical tests. To increase the success of detection, other
equally effective approaches to an increase of the activation frequency of hardware
Trojans have been proposed [20, 180].
4.6.2.2 Malicious Computer Systems
Authoritative experts King et al. [168] were the first to publish information about
the capabilities and methods of a comprehensive combined attack on software and
hardware. In this attack, a hardware Trojan serves as the basis for an extensive attack,
allowing an attacker to enter the operating system with root privileges by cracking
the security system of the hardware.
For example, New York University held a competition, the purpose of which was
to research various methods of introducing hardware Trojans. The criterion of success
in this competition was the most unobtrusive introduction of a malicious introduction
into the original microcircuit; the possibility of imperceptible information extraction
was also assessed. The works presented at the competition can be found in the
materials [155, 159]; in Chap. 6, we will take a closer look at both this method and
the others listed below in this section.
4.6.2.3 Improving Trojan Detection Performance
To enhance the detection of activation of Trojans, many approaches have been
proposed that should have increased the probability of detection in the course of
functional testing. Thus, the method of minimizing the triggering circuit is used to
reduce the overall activity of the object under study and to provide in this context
the possibility of measuring the (partial) activity of a Trojan in its presence [152].
A change in the supply voltage level on logical circuits inside the microcircuit
design leads to corresponding changes in the logical positions of these circuits.
This measure leads to an inversion of the detection probability—“a Trojan that was
previously difficult to find turns out to be visible” [193].
