4.6 Methods of Detecting Hardware Trojans …
341
The formation of optimal testing plans (test patterns) should also increase the
probability of detection when conducting logical tests. Chakrabori et al. [157] represent an approach to the multiple initiation of the so-called rare logical positions in
order to activate the potential state of a trigger. Such rare positions are determined
by using the statistical method.
Salmani et al. [155] increase the likelihood of state changes (start-up circuit) by
inserting a special false trigger into the basic design. Also, false triggers are performed
as “scanning” triggers to preserve the original functionality. The researchers Banga
and Hsiao [194] present an approach, primarily allowing to determine signals that
are easily activated during a functional test. These signals are subsequently ignored
during tests for Trojans that are difficult to detect. With the help of the remaining
signals, a formal check is performed. All detected Trojans are subsequently isolated.
4.6.2.4 Using Characterization of Logical Elements for Detecting
Trojans
In general, the analysis of third-party channels should ensure the detection of deviations from the expected behavior of a microcircuit caused by hardware Trojans. Since
the task of Trojans is precisely to be undetected during the functional testing process,
it is assumed that the impact of the Trojan is minimal compared to the overall system
activity.
This is a big problem for their detection, since the impact of the natural changes
of the process (manufacturing tolerance) will be almost as serious as the impact of
the Trojan.
The approach of characterizing logical elements is to attempt the characterization
of each individual logical element of an integrated circuit. In this case, performance
levels, switching power, and leakage current are used for characterization. Scale
factors are calculated to take into account natural manufacturing tolerances in the
process that cannot be avoided during production. If the test results of an integrated
microcircuit are too different from the calculated characteristics, then there is a high
probability of introducing a hardware Trojan into this microcircuit, for the detection
of which other methods and approaches are required [176, 177].
4.6.2.5 Using Special Bus Architectures Protected from Trojans
The Trojans that have been introduced in the hardware of the attacked system can
also be detected using the operating system. The work [156] proposes an approach
in which the hardware security system monitors access from the CPU to the memory
data bus and performs a viability test. The stopwatch starts whenever the tracker
detects a specific pseudo-random memory access procedure initiated by the operating system. If stopwatch time expires, a DoS attack is detected (a denial-ofservice attack). In addition, the operating system periodically checks the activation
of memory protection in order to prevent attacks of “increasing priority.”
341
The formation of optimal testing plans (test patterns) should also increase the
probability of detection when conducting logical tests. Chakrabori et al. [157] represent an approach to the multiple initiation of the so-called rare logical positions in
order to activate the potential state of a trigger. Such rare positions are determined
by using the statistical method.
Salmani et al. [155] increase the likelihood of state changes (start-up circuit) by
inserting a special false trigger into the basic design. Also, false triggers are performed
as “scanning” triggers to preserve the original functionality. The researchers Banga
and Hsiao [194] present an approach, primarily allowing to determine signals that
are easily activated during a functional test. These signals are subsequently ignored
during tests for Trojans that are difficult to detect. With the help of the remaining
signals, a formal check is performed. All detected Trojans are subsequently isolated.
4.6.2.4 Using Characterization of Logical Elements for Detecting
Trojans
In general, the analysis of third-party channels should ensure the detection of deviations from the expected behavior of a microcircuit caused by hardware Trojans. Since
the task of Trojans is precisely to be undetected during the functional testing process,
it is assumed that the impact of the Trojan is minimal compared to the overall system
activity.
This is a big problem for their detection, since the impact of the natural changes
of the process (manufacturing tolerance) will be almost as serious as the impact of
the Trojan.
The approach of characterizing logical elements is to attempt the characterization
of each individual logical element of an integrated circuit. In this case, performance
levels, switching power, and leakage current are used for characterization. Scale
factors are calculated to take into account natural manufacturing tolerances in the
process that cannot be avoided during production. If the test results of an integrated
microcircuit are too different from the calculated characteristics, then there is a high
probability of introducing a hardware Trojan into this microcircuit, for the detection
of which other methods and approaches are required [176, 177].
4.6.2.5 Using Special Bus Architectures Protected from Trojans
The Trojans that have been introduced in the hardware of the attacked system can
also be detected using the operating system. The work [156] proposes an approach
in which the hardware security system monitors access from the CPU to the memory
data bus and performs a viability test. The stopwatch starts whenever the tracker
detects a specific pseudo-random memory access procedure initiated by the operating system. If stopwatch time expires, a DoS attack is detected (a denial-ofservice attack). In addition, the operating system periodically checks the activation
of memory protection in order to prevent attacks of “increasing priority.”
