352
4 Hardware Trojans in Microcircuits
4.7.1.2 Terminology of Supply Chain Vulnerabilities
The problems that arise from the analysis of the IC supply chain were divided by
the authors of the project into three main categories: “Measurement”, “Theft”, and
“Trust”. Each of these categories generally concerns the production of surplus ICs
over the supply request, unauthorized access to information, including IP, interference
with ICs obtained from production. The 2008 CSAW competition focused on the
category of confidence, but other categories (measurements and theft) also produced
interesting results, which we considered necessary to cite here.
Trust
As the trend of fabless (without production) of semiconductor companies keeps
growing, this category (trust) passes into the hands production facilities. Failures of
modern military equipment around the world bring this category (trust) to the most
important place, since they are usually connected, as the military calls it, with the
hidden kill switch [198]. Kill switch, in our terms a hardware Trojan, allows you to
perform remote breach or interruption of the normal functioning of an IC in military
equipment. Other reports from the military men confirm that some manufacturers of
chips deliberately install kill switches in separate ICs in order to block the device if
it falls into “unclean hands” [198].
The US Department of Defense assessed this threat through the implementation of various initiatives rather late. For example, in February 2005, the so-called
defense science commission released a report called Task Force on High Performance
Microchip Supply [199] in public sources, which assessed the long-term trust and
security in the microcircuits used by the US government. Their conclusion: “Immediate action recommended.” In accordance with this report, a number of special
programs were then launched (DARPA initiative, trust in integrated circuits) [200] to
ensure greater security in the supply chain. The DARPA program is divided into three
phases with industrial and government support at each stage. Phases gave an estimation of the level of confidence in the ASIC design, in doubtful foundry production and
in the FPGA design, respectively. An independent attempt with similar intentions,
the NSA’s Safe Foundry Manufacturing Program [201], established certain standards
of trust that must be established before the plant can obtain an approval certificate
from the US Department of Defense.
The trust category can be divided into three areas according to its functionality as
follows:
1. Corruption of user plans: Affecting the operation of the device, either making its
function incorrect or completely stopping the operation. This form of attack is
called DOS (denial of service) when a certain subset of functions do not work as
planned.
2. Acquiring additional knowledge: Leakage of classified information that was not
originally intended to be extracted from the device. This area includes the ability
to pick up plaintext messages, the key used to decrypt these messages, or any
4 Hardware Trojans in Microcircuits
4.7.1.2 Terminology of Supply Chain Vulnerabilities
The problems that arise from the analysis of the IC supply chain were divided by
the authors of the project into three main categories: “Measurement”, “Theft”, and
“Trust”. Each of these categories generally concerns the production of surplus ICs
over the supply request, unauthorized access to information, including IP, interference
with ICs obtained from production. The 2008 CSAW competition focused on the
category of confidence, but other categories (measurements and theft) also produced
interesting results, which we considered necessary to cite here.
Trust
As the trend of fabless (without production) of semiconductor companies keeps
growing, this category (trust) passes into the hands production facilities. Failures of
modern military equipment around the world bring this category (trust) to the most
important place, since they are usually connected, as the military calls it, with the
hidden kill switch [198]. Kill switch, in our terms a hardware Trojan, allows you to
perform remote breach or interruption of the normal functioning of an IC in military
equipment. Other reports from the military men confirm that some manufacturers of
chips deliberately install kill switches in separate ICs in order to block the device if
it falls into “unclean hands” [198].
The US Department of Defense assessed this threat through the implementation of various initiatives rather late. For example, in February 2005, the so-called
defense science commission released a report called Task Force on High Performance
Microchip Supply [199] in public sources, which assessed the long-term trust and
security in the microcircuits used by the US government. Their conclusion: “Immediate action recommended.” In accordance with this report, a number of special
programs were then launched (DARPA initiative, trust in integrated circuits) [200] to
ensure greater security in the supply chain. The DARPA program is divided into three
phases with industrial and government support at each stage. Phases gave an estimation of the level of confidence in the ASIC design, in doubtful foundry production and
in the FPGA design, respectively. An independent attempt with similar intentions,
the NSA’s Safe Foundry Manufacturing Program [201], established certain standards
of trust that must be established before the plant can obtain an approval certificate
from the US Department of Defense.
The trust category can be divided into three areas according to its functionality as
follows:
1. Corruption of user plans: Affecting the operation of the device, either making its
function incorrect or completely stopping the operation. This form of attack is
called DOS (denial of service) when a certain subset of functions do not work as
planned.
2. Acquiring additional knowledge: Leakage of classified information that was not
originally intended to be extracted from the device. This area includes the ability
to pick up plaintext messages, the key used to decrypt these messages, or any
