360
4 Hardware Trojans in Microcircuits
Fig. 4.35 RS232 message format
communication with other devices. The first Trojan uses a feature of the structure of
the message code, starting with a key pointer, which is used to decrypt the message.
The key code is determined by the Dip switches located on the physical board, adding
some changes to the control key. The key pointer is accompanied by encrypted text,
the original message being encrypted using the AES-128 algorithm along with the
individual key. The message ends with an end sequence made up of 14 bytes 0xFF.
The application used to decrypt messages on the receiving end, encVerifier, was
provided by the contest organizers. It uses a key pointer to recognize the encryption
key and, therefore, the decryption key. The encVerifier program reads the ciphertext
using an end sequence to determine the variable length. The source code for the
encVerifier program checks for five bytes of 0xFF in the last available segment of
eight bytes. Then it forms a loop through the data from the last read byte to the first
read byte in a sequence of eight bytes and increments the counter for each byte of
the observed 0xFF. If at least five non-consecutive 0xFF bytes are read in the last
segment of eight bytes, the encVerifier program decrypts the message and displays
it on the screen.
Using this message structure, specifically the terminal sequence, makes it possible
to conduct two attacks. The first attack places the information after the transmission
of the terminal sequence, but also in the original message. This attack is flexible
in terms of information and amount of information transmitted. So, the authors
[156] decided to leak information on the full key at the end of a single message.
The encVerifier program does not notice the redundant information contained in the
RS232 data stream, since it stops reading from the data stream after detecting the
terminal sequence. The malicious program that monitors the data stream will be able
to read after the terminal sequence and will receive additional data at the end of the
message.
After the Trojan is activated, the end sequence is completed with “redundant”
data. Using the original encVerifier, program creates the expected output, because it
ignores the added information. However, the encVerifier malicious program ignores
the encrypted message and recovers the stolen key.
Organization of information leakage through the channel end sequence
RS232 (second version)
The second malicious program on the terminal sequence uses the structural feature of
the number of bytes of the terminal sequence. Since the ciphertext can be of variable
length and the encVerifier program checks for 5 bytes of 0xFF in the last segment of 8
4 Hardware Trojans in Microcircuits
Fig. 4.35 RS232 message format
communication with other devices. The first Trojan uses a feature of the structure of
the message code, starting with a key pointer, which is used to decrypt the message.
The key code is determined by the Dip switches located on the physical board, adding
some changes to the control key. The key pointer is accompanied by encrypted text,
the original message being encrypted using the AES-128 algorithm along with the
individual key. The message ends with an end sequence made up of 14 bytes 0xFF.
The application used to decrypt messages on the receiving end, encVerifier, was
provided by the contest organizers. It uses a key pointer to recognize the encryption
key and, therefore, the decryption key. The encVerifier program reads the ciphertext
using an end sequence to determine the variable length. The source code for the
encVerifier program checks for five bytes of 0xFF in the last available segment of
eight bytes. Then it forms a loop through the data from the last read byte to the first
read byte in a sequence of eight bytes and increments the counter for each byte of
the observed 0xFF. If at least five non-consecutive 0xFF bytes are read in the last
segment of eight bytes, the encVerifier program decrypts the message and displays
it on the screen.
Using this message structure, specifically the terminal sequence, makes it possible
to conduct two attacks. The first attack places the information after the transmission
of the terminal sequence, but also in the original message. This attack is flexible
in terms of information and amount of information transmitted. So, the authors
[156] decided to leak information on the full key at the end of a single message.
The encVerifier program does not notice the redundant information contained in the
RS232 data stream, since it stops reading from the data stream after detecting the
terminal sequence. The malicious program that monitors the data stream will be able
to read after the terminal sequence and will receive additional data at the end of the
message.
After the Trojan is activated, the end sequence is completed with “redundant”
data. Using the original encVerifier, program creates the expected output, because it
ignores the added information. However, the encVerifier malicious program ignores
the encrypted message and recovers the stolen key.
Organization of information leakage through the channel end sequence
RS232 (second version)
The second malicious program on the terminal sequence uses the structural feature of
the number of bytes of the terminal sequence. Since the ciphertext can be of variable
length and the encVerifier program checks for 5 bytes of 0xFF in the last segment of 8
