4.7 Case Study of the Development …
355
4.7.2.1 Attacker’s Actions at the Design Stage
A design attacker enters the supply chain at the design stage, between the idea concept
and the moment when the idea is fully materialized in the form of an RTL description.
This attacker has full access to the project files and source code. The attacker is like an
“own” well-informed person who deliberately gained access, although he may also
be a more traditional hacker who gains unauthorized access to a computer system.
What is obtained:
• Trust. If the attacker has access to the project file, he can add components to the
structure or remove components from it. Even without such access, the design
can be analyzed to facilitate a future attack.
• Measurement. With access to the source code, an attacker can create additional
IC to make the ICs if there are enough resources or access to the production line;
• Theft. Since the attacker has access to the entire project and source code, IP theft
is very simple.
Protection: The measures necessary to protect computer systems that store IP
are too numerous to mention here, and are outside the scope of this section, but a
conscious tightening of computer network security can help protect IP. For the same
reasons, protecting IP from those who design is also very difficult. The probability
of adding Trojans can be minimized by careful re-checking of the code, adequate
control, and balance, or by using TRUTH-type tools [221]. TRUTH software analyzes
the HDL source code, identifying potentially unsafe structures that may indicate an
embedded Trojan. Protection against a design attacker requires a holistic security
policy in order to minimize the risk.
4.7.2.2 Attacker at the Stage of Synthesis
An attacker attacking the synthesis usually appears much earlier than IP is actually
synthesized. By gaining unauthorized access to CAD design tools or scripts that
control them, an attacker can modify IP at any level from the preprocessing of HDL
along the entire design flow to creating a netlist (Net + List) [197]. Since the attack
takes place during the synthesis phase inside the design center on a commonly tested
platform, it causes less suspicion and is very difficult to detect because the logic
is built into the construct. Also, with the increasing use of open-source CAD in the
industry, the synthesis attacker can gain unauthorized access to the system by placing
malicious pre-compiled binaries or directly modifying the source code. Ultimately,
automated scripts are vulnerable to several methods against the attacker.
What is obtained:
• Trust. The attacker can add Trojan logic to the design or “spoil” critical logic,
such as a random number generator used to operate a cryptographic device.
• Measurement. By stealing an IP, an attacker can create redundant ICs with the
ability to manufacture them.
355
4.7.2.1 Attacker’s Actions at the Design Stage
A design attacker enters the supply chain at the design stage, between the idea concept
and the moment when the idea is fully materialized in the form of an RTL description.
This attacker has full access to the project files and source code. The attacker is like an
“own” well-informed person who deliberately gained access, although he may also
be a more traditional hacker who gains unauthorized access to a computer system.
What is obtained:
• Trust. If the attacker has access to the project file, he can add components to the
structure or remove components from it. Even without such access, the design
can be analyzed to facilitate a future attack.
• Measurement. With access to the source code, an attacker can create additional
IC to make the ICs if there are enough resources or access to the production line;
• Theft. Since the attacker has access to the entire project and source code, IP theft
is very simple.
Protection: The measures necessary to protect computer systems that store IP
are too numerous to mention here, and are outside the scope of this section, but a
conscious tightening of computer network security can help protect IP. For the same
reasons, protecting IP from those who design is also very difficult. The probability
of adding Trojans can be minimized by careful re-checking of the code, adequate
control, and balance, or by using TRUTH-type tools [221]. TRUTH software analyzes
the HDL source code, identifying potentially unsafe structures that may indicate an
embedded Trojan. Protection against a design attacker requires a holistic security
policy in order to minimize the risk.
4.7.2.2 Attacker at the Stage of Synthesis
An attacker attacking the synthesis usually appears much earlier than IP is actually
synthesized. By gaining unauthorized access to CAD design tools or scripts that
control them, an attacker can modify IP at any level from the preprocessing of HDL
along the entire design flow to creating a netlist (Net + List) [197]. Since the attack
takes place during the synthesis phase inside the design center on a commonly tested
platform, it causes less suspicion and is very difficult to detect because the logic
is built into the construct. Also, with the increasing use of open-source CAD in the
industry, the synthesis attacker can gain unauthorized access to the system by placing
malicious pre-compiled binaries or directly modifying the source code. Ultimately,
automated scripts are vulnerable to several methods against the attacker.
What is obtained:
• Trust. The attacker can add Trojan logic to the design or “spoil” critical logic,
such as a random number generator used to operate a cryptographic device.
• Measurement. By stealing an IP, an attacker can create redundant ICs with the
ability to manufacture them.
