4.6 Methods of Detecting Hardware Trojans …
343
If a part of the contour remains unused during the entire test period, it is considered
that such a part can relate to the contour of the Trojan (which, by definition, should
not be detected during the functional tests and therefore remains inactive).
Authoritative researchers Vaksman and Setkhumadkhavan [184] represent a peculiar approach to combat Trojans in the process of execution, especially effective
for microprocessors. The assumption is that the malicious function is implemented
during the development phase by malicious developers. Within the framework of the
approach, the following initial conditions were determined:
(1) The number of malicious developers is small;
(2) The activities of malicious developers go unnoticed;
(3) Attackers need new resources to bypass the security system;
(4) The protective system is activated by a trigger;
(5) ROMs written at the design stage contain correct data (microcode).
Two types of workarounds perform the function of a Trojan model: the socalled emitter (data transmission) and the corrupt (data change). The second type
is extremely difficult to detect, since their operations are often difficult to distinguish
from normal operations. The proposed measure to prevent hardware bypass is to use
a SoC monitoring system consisting of four elements: a predictor, a reacting device,
a target, and a monitor.
Here, a Trojan is detected if the result of a unit in question does not match the
prediction results of the predictor. The detection principle is based on the simple and
sensible assumption that the tracked device never communicates with the tracking
device; therefore, the attacker developer of the malicious device X can in no way
affect the device that tracks the operation of the device X.
4.6.2.9 Development of Third-Party Analysis Methods
Authoritative researchers Du et al. [163] suggest using a different third-party analysisbased approach to detect hardware Trojans. The power consumption of a specific fragment of one information system is compared with the power consumption of the same
fragment of another similar information system. The cause of the detected difference
in the levels of power consumption values may be a Trojan. This technology is called
“self-reference” (a separate paragraph will be devoted to its consideration in Chap. 6).
Narasmihan et al. [175] share a scheme in which various compartments are stimulated through appropriate tests. The transient current (I DDT ) and maximum frequency
(f max ) are determined by using a third-party channel analysis. Since I DDT and f max
are linearly dependent, and f max is not subject to change, a Trojan can be detected if
the fact of increasing the I DDr value is fixed.
To identify the most minimal theoretically detectable Trojan, Rad et al. [179]
use a transient signal spectrum sensitivity analysis along the supply circuit. The
minimal detectable Trojan can basically consist of a single logical element, but this
Trojan in any case responds to the test sequence. It is shown that if the measurement
Précédent

- 362/839

Suivant