4.7 Case Study of the Development …
357
4.7.2.4 Attacker in the Sales Pattern
The attacker in the sales environment enters the supply chain after manufacturing
and assembling an IC into the package. It does not have access to either the original
HDL code or the geometric pattern of the topological level. This type of attacker
is most likely to be associated with the sale of ICs, or with end users. The attacker
probably does not have a set of input/output test vectors, but in return he has a set of
specifications that are supposed to correspond to the IC.
What is obtained:
• Trust. The attacker at this stage is strongly limited in his independence, which
increases the detail of the attack. Instead of being able to deal with individual gates,
it is required to work with refinement at the level of the package or, possibly, at
the level of a component.
• Measurement. In order to copy ICs, it is necessary to perform a reverse design of
the structure in order to restore the netlist using which ICs can be made. This is
considered to be a difficult but achievable task.
• Theft. Information can be stolen using various methods: either by dismantling
the IC or passively analyzing the IC through attacks on the side channels, while
intensively applying both of these methods.
Protection: Despite the difficulties caused by small design rules, many academic and
commercial programs have been implemented to address specific vulnerabilities of
this type. They include protection against package tampering, chemical passivation,
and entanglement against side-channel attacks and much more [222].
Potential hazard model
Before discussing the plan for possible Alpha device attacks, it was necessary to
identify the attacker. Under the conditions of problem, it was assumed that the attacker
has significant resources in time, in finance, and in computing instruments, but these
resources are limited. The attacker is motivated either by making a profit or by
wanting to damage the owner of the device, but the price of the end goal should
outweigh the costs of inserting a Trojan. Under the terms of the competition, the
attacker enters at the design stage and tries to interfere with the operation of the
device in order to subsequently retrieve confidential information. Mole gets access
to the source code and method of accessing the Trojan after it has been modified
(what will happen before production). The attacker’s goal is to modify the source
code for the implementation of the Trojan, which will interfere with the user’s plans,
retrieve confidential information, or perform additional functions.
Limiting conditions
In the context of the CSAW competition, the attacker’s goal formulation allowed for
various particular additions in order that the solutions were flexible and creative;
nevertheless, it was necessary to define some restrictions so that the solutions
found by competing teams could be systematized. These restrictions were not strict
Précédent

- 376/839

Suivant