4.6 Methods of Detecting Hardware Trojans …
347
themselves are divided into two groups: with high and low probability of inclusion.
A false scan trigger is connected to networks with a low switching probability to
increase the likelihood of a transition. A network with logic prone to zero is followed
by a scan trigger, which inverts the output of the network (in test setting) to the value
of logic 1 if necessary. The converse is also of networks with logic prone to one.
4.6.2.16 Neutralization of Introduced Trojans
Researchers of Trojans problems Waksman and Sethumadhavan [185] present an
approach to neutralize (avoid) the introduced Trojans by preventing the occurrence
of trigger conditions for digital deterministic triggers.
Here, unreliable data is monitored and used not within its own functional groups,
but only at their input and output points. The idea is that the data is encrypted and
hidden in a controlled manner, so that the Trojan’s trigger cannot detect the trigger
condition programmed by the attacker, and therefore the activation of the Trojan will
never occur. The following types of triggers are considered: (1) countdown bomb;
(2) point cheat code; (3) sequence cheat code.
A “countdown bomb” is just an ordinary time-controlled trigger that is activated
after a certain number of time cycles N have been implemented. The number of
such time cycles is usually determined using a counter. If the counter constantly
reboots before reaching the N state, the Trojan will never be activated. This result
can be achieved by periodically rebooting the entire digital system. The reset interval
shall be shorter than the test period T required in the framework of the mandatory
functional tests. If an attacker wants to achieve a bomb countdown activation, such
activation should occur within N time cycles. However, if N < T, the Trojan will be
activated and detected during functional tests.
Trojan triggers, which are based on the introduction of Trojans, can be divided
into two large groups: point cheat codes and sequence cheat codes. Point triggers are
activated when a certain rare value is applied to a tracked interface. To prevent the
acquisition of data on the application of a rare value to the input of the affected functional unit, the value is encoded in such a way that it ceases to meet the conditions of
the trigger. Simple encryption methods include, for example, XOR, PUF, or random
values. This approach is useful for non-computational units, for example, embedded
memory modules. To protect computational units (for example, ALU), homomorphic
functions proposed by the authors are used. Such homomorphic functions comply
with the following rule: (fg(x), g(y)) = g(fx, y). Here is an example of a homomorphic
function: x
2 y
2
= (xy)
2 . If we assume that the computational function is squaring, the
unreliable value of x to be processed will be multiplied by a random value of y before
squaring. To obtain a valid result, the value obtained from the functional unit should
be divided by y
2 .
The last class of triggers, the so-called sequence cheat codes, is neutralized by
setting up encrypted false loads. Encryption is achieved by a simple swap. If this is
not possible, then false “loads” can be entered into the data stream. It is necessary
to determine the maximum number of n bits, which will then be used as a valid
347
themselves are divided into two groups: with high and low probability of inclusion.
A false scan trigger is connected to networks with a low switching probability to
increase the likelihood of a transition. A network with logic prone to zero is followed
by a scan trigger, which inverts the output of the network (in test setting) to the value
of logic 1 if necessary. The converse is also of networks with logic prone to one.
4.6.2.16 Neutralization of Introduced Trojans
Researchers of Trojans problems Waksman and Sethumadhavan [185] present an
approach to neutralize (avoid) the introduced Trojans by preventing the occurrence
of trigger conditions for digital deterministic triggers.
Here, unreliable data is monitored and used not within its own functional groups,
but only at their input and output points. The idea is that the data is encrypted and
hidden in a controlled manner, so that the Trojan’s trigger cannot detect the trigger
condition programmed by the attacker, and therefore the activation of the Trojan will
never occur. The following types of triggers are considered: (1) countdown bomb;
(2) point cheat code; (3) sequence cheat code.
A “countdown bomb” is just an ordinary time-controlled trigger that is activated
after a certain number of time cycles N have been implemented. The number of
such time cycles is usually determined using a counter. If the counter constantly
reboots before reaching the N state, the Trojan will never be activated. This result
can be achieved by periodically rebooting the entire digital system. The reset interval
shall be shorter than the test period T required in the framework of the mandatory
functional tests. If an attacker wants to achieve a bomb countdown activation, such
activation should occur within N time cycles. However, if N < T, the Trojan will be
activated and detected during functional tests.
Trojan triggers, which are based on the introduction of Trojans, can be divided
into two large groups: point cheat codes and sequence cheat codes. Point triggers are
activated when a certain rare value is applied to a tracked interface. To prevent the
acquisition of data on the application of a rare value to the input of the affected functional unit, the value is encoded in such a way that it ceases to meet the conditions of
the trigger. Simple encryption methods include, for example, XOR, PUF, or random
values. This approach is useful for non-computational units, for example, embedded
memory modules. To protect computational units (for example, ALU), homomorphic
functions proposed by the authors are used. Such homomorphic functions comply
with the following rule: (fg(x), g(y)) = g(fx, y). Here is an example of a homomorphic
function: x
2 y
2
= (xy)
2 . If we assume that the computational function is squaring, the
unreliable value of x to be processed will be multiplied by a random value of y before
squaring. To obtain a valid result, the value obtained from the functional unit should
be divided by y
2 .
The last class of triggers, the so-called sequence cheat codes, is neutralized by
setting up encrypted false loads. Encryption is achieved by a simple swap. If this is
not possible, then false “loads” can be entered into the data stream. It is necessary
to determine the maximum number of n bits, which will then be used as a valid
