358
4 Hardware Trojans in Microcircuits
requirements imposed by competition, but serve as guidelines. This applies to two
terms—”spatial distance” and “secrecy.”
Spatial distance
After making the Alpha device with the built-in Trojan, this Trojan should do something useful for its creator. The key limitation is the location (distance) of the attacker
when the Trojan is active. The authors of [156] divided their decisions into four categories according to the proximity factor: “physical access,” “close to the device,”
“close to the communication channel,” and “far away.” Physical access means that
an attacker can physically interact with the device. For example, he can capture one
of the Alpha devices used by the consumer, work daily with the device even in the
presence of other users, or have short-term access. “Close to the device” means that
an attacker can come close enough to interact with the device. This may take the
form of some kind of wireless transmission to or from the device, or the ability to
see or listen to the device. Although the distance is uncertain, it only means a class
by spatial arrangement.
“Close to the communication channel” assumes that the interaction with the device
does not occur directly, but rather over a hidden communication channel. An attacker
who is close to the communication channel, even if the device is far away, still has the
ability to interact with it (sending messages over the Internet or via satellites). The
term “far away” means that an attacker does not have access to a Trojan physically or
through any communication channels. Imagine a DoS (denial of service), triggered
by an event that is beyond the control of the attacker: the temperature of the room,
the number of decrypted bits, etc. Therefore, for this competition [156], in discussing
attack scenarios, each solution used different distance limits.
Secrecy
The Trojan must be well hidden in the HDL code before it gets a chance to be
synthesized, and then must permanently remain hidden during the testing and operation stages of the device. The value of a Trojan is directly related to its secrecy, since
a detected Trojan can lead to an attacker. In the context of the competition [156],
the secrecy requirements for the HDL code were defined: it should pass a short code
check, and for the secrecy of the synthesized code it must pass a set of functional tests
using the same reference power, support the use of configuration memory, and be
undetectable by the average user. Although these requirements are largely subjective,
the scoring was left to the discretion of the jury.
It should be noted that the team [156] made considerable efforts to hide the Trojans
in order to pass the code check. The following sections dedicated to the description of
Trojans do not show many of the hidden details, since they mainly deal with specific
connections and modules that are not generalized to other hardware Trojan circuits.
In general, hackers-developers helped to hide various attacks, such as extended bus
widths, change in signal tracing, using naming conventions, decentralizing Trojan
logic, writing misleading comments, using subtleties of the language, etc. Due to the
limited volume of the book, we do not list them.
4 Hardware Trojans in Microcircuits
requirements imposed by competition, but serve as guidelines. This applies to two
terms—”spatial distance” and “secrecy.”
Spatial distance
After making the Alpha device with the built-in Trojan, this Trojan should do something useful for its creator. The key limitation is the location (distance) of the attacker
when the Trojan is active. The authors of [156] divided their decisions into four categories according to the proximity factor: “physical access,” “close to the device,”
“close to the communication channel,” and “far away.” Physical access means that
an attacker can physically interact with the device. For example, he can capture one
of the Alpha devices used by the consumer, work daily with the device even in the
presence of other users, or have short-term access. “Close to the device” means that
an attacker can come close enough to interact with the device. This may take the
form of some kind of wireless transmission to or from the device, or the ability to
see or listen to the device. Although the distance is uncertain, it only means a class
by spatial arrangement.
“Close to the communication channel” assumes that the interaction with the device
does not occur directly, but rather over a hidden communication channel. An attacker
who is close to the communication channel, even if the device is far away, still has the
ability to interact with it (sending messages over the Internet or via satellites). The
term “far away” means that an attacker does not have access to a Trojan physically or
through any communication channels. Imagine a DoS (denial of service), triggered
by an event that is beyond the control of the attacker: the temperature of the room,
the number of decrypted bits, etc. Therefore, for this competition [156], in discussing
attack scenarios, each solution used different distance limits.
Secrecy
The Trojan must be well hidden in the HDL code before it gets a chance to be
synthesized, and then must permanently remain hidden during the testing and operation stages of the device. The value of a Trojan is directly related to its secrecy, since
a detected Trojan can lead to an attacker. In the context of the competition [156],
the secrecy requirements for the HDL code were defined: it should pass a short code
check, and for the secrecy of the synthesized code it must pass a set of functional tests
using the same reference power, support the use of configuration memory, and be
undetectable by the average user. Although these requirements are largely subjective,
the scoring was left to the discretion of the jury.
It should be noted that the team [156] made considerable efforts to hide the Trojans
in order to pass the code check. The following sections dedicated to the description of
Trojans do not show many of the hidden details, since they mainly deal with specific
connections and modules that are not generalized to other hardware Trojan circuits.
In general, hackers-developers helped to hide various attacks, such as extended bus
widths, change in signal tracing, using naming conventions, decentralizing Trojan
logic, writing misleading comments, using subtleties of the language, etc. Due to the
limited volume of the book, we do not list them.
