356
4 Hardware Trojans in Microcircuits
• Theft. The attacker has access to all the levels in the process of working with
CAD tools and can steal any information that is present in IP.
Protection: Due to expense constraints, the design center cannot develop all CAD
tools on its own, there is an objective dependence on CAD program developers. It
is necessary to establish a level of trust with developers of CAD tools, to establish a
holistic security policy in order to prevent interference with CAD tools in the design
center.
4.7.2.3 Attacking at the Manufacturing Stage
An attacker in production is usually external to an IP developer, since contract manufacturing in the world produces many ICs. After the IP developer creates, synthesizes,
places, and traces his project, a physical topology geometry file is created, which is
an exact IC template. In a horizontal business model, the plant receives a complete
design along with its specification.
What is obtained:
• Trust. Foundries necessarily analyze the geometry of the topological level and the
mask, which gives them the opportunity to add or remove components of each
IC through the modification of topological geometry. Alternatively, after creating
an IC, the selective number of the IC can be modified using a focused ion beam
(FIB).
• Measurement. The plant produces high-volume ICs, and if production is initiated,
the creation of additional ICs beyond the purchase order is inexpensive and trivial.
The non-recurring expenses of designing an IC developer are the most expensive
part of the process. The current practice of making ICs does not use any measures
to limit the number of ICs created by foundries beyond the use of contractual
agreements.
• Theft. Having the geometry of the topological level of the design as a whole, it
is practically possible, although difficult, for the reverse-engineering specialist to
restore the netlist or even further to HDL.
Protection: Over the past 10 years, significant research has been conducted in each
of these three areas. For the measurements, both passive and active programs were
investigated, which leave the manufactured IC in a locked state and can measure the
number of activated ones instead of the number of manufactured ones. Theft can be
controlled by one of the signature-tagging methods discussed earlier. Ultimately, the
reliability of an IC is ensured either by the security structure within which the IC is
created or by means of verification after manufacture.
Précédent

- 375/839

Suivant