4.7 Case Study of the Development …
353
other information that will give a malicious user more extensive knowledge of
the system than it was originally intended.
3. Using advanced features: Use of the instrument to perform a function that was
not originally intended for use. In this attack, the device can function absolutely
correctly, generate correct output data, and even not produce information leakage,
but it can be used in a way that is not provided for by the original specification.
4.7.1.3 Measurement
The second category of problems, “measurements,” deals with the quantity of ICs
produced and with whom they are delivered to. The concept of marking with special
symbols (signatures) is applied to several technologies, including hardware IP [202].
In this case, there is only a partial solution that identifies the IP, not the IC. The
passive method uniquely identifies each IC and registers this identity. Later, suspicious ICs are checked for proper registration. The uniqueness of each device is based
on the production variability (manufacturing tolerances) of thresholds in MOSFET
matrices [203], silicon characteristic spread [204], characteristic spread in delays
[205], and the use of physical unclonable functions (PUFs) [206] and [207, 208].
Another approach, the so-called active measurement, figuratively speaking, “locks”
every IC, until the legitimate IP holder unlocks it. In work [209], each IC generates
its own unique ID. The IC in the user’s system begins to work in the locked state, but
the IP holder, using a unique ID, unlocks the IC. [210] extends this process by adding
copied states to the state machine that requires a similar unlocking mechanism.
4.7.1.4 Theft
Although this category overlaps slightly with measurements, these are not necessarily
equivalents. At the measurement stage, they try to control who produced ICs and
how much, and more generally, the theft of information implies the collection of
information that was not originally intended for dissemination. The production of
such “redundant” ICs by unauthorized users is one of the direct consequences of the
theft of a netlist, but other information (secrets of firmware, IP-cores, algorithms)
can also be the goal.
Many different technologies for the placement of identification marks and signatures add their unique attribute to different IP levels. This signature basically allows
tracking IP throughout the supply chain and, if theft occurs, directly indicates the
point of leakage. The main disadvantage of these methods is that the unique signature does not protect IP from theft, with the exception of “deterrent” methods; more
likely, it provides a certain legal basis for litigation if such an offence is committed.
For example, the authors in [211, 212] marked IP for FPGAs using the remaining
LUTs (conversion tables) for coding information. Specially modified state transition
graphs (STG) were added to the design via [213, 214, 215], which detected unusual
patterns. Expanding this idea, works [216–218] analyze the existing state machine
353
other information that will give a malicious user more extensive knowledge of
the system than it was originally intended.
3. Using advanced features: Use of the instrument to perform a function that was
not originally intended for use. In this attack, the device can function absolutely
correctly, generate correct output data, and even not produce information leakage,
but it can be used in a way that is not provided for by the original specification.
4.7.1.3 Measurement
The second category of problems, “measurements,” deals with the quantity of ICs
produced and with whom they are delivered to. The concept of marking with special
symbols (signatures) is applied to several technologies, including hardware IP [202].
In this case, there is only a partial solution that identifies the IP, not the IC. The
passive method uniquely identifies each IC and registers this identity. Later, suspicious ICs are checked for proper registration. The uniqueness of each device is based
on the production variability (manufacturing tolerances) of thresholds in MOSFET
matrices [203], silicon characteristic spread [204], characteristic spread in delays
[205], and the use of physical unclonable functions (PUFs) [206] and [207, 208].
Another approach, the so-called active measurement, figuratively speaking, “locks”
every IC, until the legitimate IP holder unlocks it. In work [209], each IC generates
its own unique ID. The IC in the user’s system begins to work in the locked state, but
the IP holder, using a unique ID, unlocks the IC. [210] extends this process by adding
copied states to the state machine that requires a similar unlocking mechanism.
4.7.1.4 Theft
Although this category overlaps slightly with measurements, these are not necessarily
equivalents. At the measurement stage, they try to control who produced ICs and
how much, and more generally, the theft of information implies the collection of
information that was not originally intended for dissemination. The production of
such “redundant” ICs by unauthorized users is one of the direct consequences of the
theft of a netlist, but other information (secrets of firmware, IP-cores, algorithms)
can also be the goal.
Many different technologies for the placement of identification marks and signatures add their unique attribute to different IP levels. This signature basically allows
tracking IP throughout the supply chain and, if theft occurs, directly indicates the
point of leakage. The main disadvantage of these methods is that the unique signature does not protect IP from theft, with the exception of “deterrent” methods; more
likely, it provides a certain legal basis for litigation if such an offence is committed.
For example, the authors in [211, 212] marked IP for FPGAs using the remaining
LUTs (conversion tables) for coding information. Specially modified state transition
graphs (STG) were added to the design via [213, 214, 215], which detected unusual
patterns. Expanding this idea, works [216–218] analyze the existing state machine
