4.7 Case Study of the Development …
349
the NYU Polytechnic Institute. This project was implemented in the form of a task
for hardware cracking of a specific Alpha device.
A team of researchers proposed a scenario as close as possible to reality in which
the government group was tasked with designing and testing a new cryptographic
device, code-named Alpha. The Alpha device, according to the scenario, should be
used in the global command and control system of the US Army, allowing soldiers
to reliably transmit messages to other soldiers and command centers. Under the
conditions of problem, this Alpha device returned from the manufacturer and is
pending authorization from the expert group for shipment and delivery to the military.
From a testing and verification point of view, when the features of the device’s security
are discussed, various complex questions arise that need to be answered; first of all,
how confident is the team that Alpha is ready? Even if during tests the requirements
for functioning are met, can we be sure that there is no additional logic that is hidden
from the tests? How much can you trust the design chain? What to do if something
malicious was added to the chain?
At the Embedded Systems Challenge, part CSAW2008, at the NYU Polytechnic
Institute, the corresponding exact scenario was presented. Several student teams from
leading universities in the United States were assigned the role of hardware hackers
who were able to gain access to the original HDL code for the designed Alpha device.
With this source code in hand, each team had only 1 month to develop and implement
the maximum number of hardware Trojans that could not be detected. By the term
“hardware Trojan” here was meant a malicious modification made to a circuit, which
games the security system of the original construct. The Alpha device with embedded
Trojans then had to go through the entire standard set of functional tests, use the same
reference power supply, maintain the usual memory configuration, go through the
standard test production code verification, and not be detected by a regular user.
Given these requirements, a team of researchers from the Iowa State University
developed a whole series of such hardware Trojans and performed an experimental
implementation to test their effectiveness using the FPGA fee provided to all the
contestants by the organizers. Some details of this competition should be noted.
This competition (CSAW Embedded Systems Challenge) began in September
2008 and ended a month later in New York. Each team received its own BASYS
[196] debug board, containing the Xilinx Spartan FPGA along with main peripheral
I/O units. Figure 4.33 shows the wiring diagram and photograph of the experimental
plant used. To work with the Alpha type design, it was necessary to use a PS/2
keyboard connected to a standard data input card and a standard serial connection
VGA monitor for data output. Four other buttons were designed to change the state
of the system. Xilinx ISE 10.1 was used as a specific development environment
for the mixed-mode HDL code, as well as for generating the FPGA binary data
stream, while Model SE 6.3 was used for modeling. In addition, this team used
standard equipment—an oscillograph, a power source, a multimeter, a thermometer,
and custom circuits to verify the functioning of each developed version of a Trojan.
In the normal operation of the Alpha device, all messages are displayed in plaintext
on the VGA monitor display. Pressing a special encryption button on the board
ensures that the message is sent via an AES-128 encryption unit with a key selected
Précédent

- 368/839

Suivant