4.6 Methods of Detecting Hardware Trojans …
345
considered as an independent element of this circuit (i.e., a segment). The characterization of logical elements in combination with thermal conditioning applied to the
segment provides information on the presence of a Trojan. A subsequent identification mechanism, based on the principle of assumption and confirmation, provides
information on the type and input pins of all existing Trojans.
4.6.2.12 Data Leakage Through Trojans
Jean and Macris [165] developed and demonstrated an attack method, the task of
which is to organize the leakage of a key of an advanced encryption standard (AES).
This goal is achieved by manipulating the transmission signal of the wireless link
within its acceptable level. This work, in our opinion, is the first type of attack
presented in the analog domain.
With the help of an external protective core, Das et al. [161] propose an approach
to preventing data leakages through the data bus caused by hardware Trojans. The
control device here monitors the behavior of the main memory access buses by
comparing the results of each access operation with its simulated version. If access
operations are the same in this case, the access will be approved by the security
device; otherwise, access will be denied. The emulation of memory access operations
is performed in software applications executed in the system.
4.6.2.13 Multi-Level Attack Models
One of the types of such a completely new class of attacks on cryptographic algorithms was introduced by Ali et al. [22]. These so-called multi-level attacks are based
on the interaction (synchronization of actions) of several individuals or several teams
of attackers involved in the development of hardware and its production process.
The authors present a concrete example of such an attack in which the secret key
of hardware AES algorithm execution is transmitted over a hidden channel of the
power source.
The authors suggest a link between the developer and the operator of cryptographic
hardware. The developer installs a malicious microcircuit in the original circuit. After
the production cycle is completed, the operator is able to read the secret key. It is
shown that cooperation between these two parties is necessary, because, otherwise,
the operator, who is not familiar with the technology used, will not be able to read
the key. It is clear that such operations can be carried out only by efforts and methods
of the relevant special services.
4.6.2.14 Using Combined Methods of Third-Party Channel Analysis
It should be noted that the first approach to combining the capabilities of various
methods of analysis via third-party channels was presented by Kushanfar and
Précédent

- 364/839

Suivant