362
4 Hardware Trojans in Microcircuits
additional arbitrary information. In the last figure, each case gives the encVerifier
program a sufficient amount of 0xFF bytes for the program to complete correctly,
but it also allows you to successfully embed 5 bytes of arbitrary information into the
data stream.
Following the use of the AES-128 encryption scheme, the ciphertext always goes
in blocks of 16 bytes. These 16 bytes plus 1 byte of the key pointer and 14 bytes of
0xFF for the terminal sequence result in a message length of (16n + 14 + 1) bytes,
where n is the number of encrypted blocks. This means that data transmissions will
always fall into the eighth variation in Figs. 4.36 and 4.37. Instead of 5 bytes for
option three, the first 9 bytes out of 14 bytes 0xFF can be used to store information,
along with the last 5 bytes containing 0xFF. This method is more secretive than the
Trojan described above, since the 5 bytes of the added data turn out to be part of the
ciphertext, and not the extension at the end of the original message. But the headline
is that both of these Trojans are “invisible” to the original encVerifier program and
allow this program to work correctly in each case.
The encVerifier program correctly decodes messages because the modified
message still follows the message format, including the correct number of stop bytes.
Using the modified encVerifier program, which is aware of the message decryption,
you can recover bytes with information leakage.
It uses different data transmission speeds on the RS232 channel (type 3 Trojan).
The third type of attack on the RS232 port uses a different approach; here, instead
of the message structure, the protocol itself is used. The standard RS232 protocol uses
a single data wire for transmission. When the line is on hold, it is characterized by
the state of a label representing a negative voltage, a logical “1.” Similarly, a logical
“0” is a pause state during which the up line is charged to a positive voltage. The
RS232 specification permits the use of various combinations of data transmission
speeds, data bits in each package, number of stop bits, and parity check bits along
with various other extensions. The Alpha device uses 9600 baud transmission at 8
bits of data in each package, start and stop bits in accordance with Fig. 4.38. A start
bit should go from a label to a pause so that the receiver recognizes the start event
of an asynchronous transmission. If the receiver recognizes this state, you can begin
sampling subsequent data bits at a consistent data transmission speed to receive all
the data from the package.
For example, the Alpha board and the data receiver are currently receiving 9600
baud, but both devices are able to send and receive data at faster speeds. This third
type Trojan equips packages that are transmitted at a higher frequency, but when
Fig. 4.38 The structure of the correct RS232 message. Data bits are shown in general terms, but
will be either a logical one or logical zero
4 Hardware Trojans in Microcircuits
additional arbitrary information. In the last figure, each case gives the encVerifier
program a sufficient amount of 0xFF bytes for the program to complete correctly,
but it also allows you to successfully embed 5 bytes of arbitrary information into the
data stream.
Following the use of the AES-128 encryption scheme, the ciphertext always goes
in blocks of 16 bytes. These 16 bytes plus 1 byte of the key pointer and 14 bytes of
0xFF for the terminal sequence result in a message length of (16n + 14 + 1) bytes,
where n is the number of encrypted blocks. This means that data transmissions will
always fall into the eighth variation in Figs. 4.36 and 4.37. Instead of 5 bytes for
option three, the first 9 bytes out of 14 bytes 0xFF can be used to store information,
along with the last 5 bytes containing 0xFF. This method is more secretive than the
Trojan described above, since the 5 bytes of the added data turn out to be part of the
ciphertext, and not the extension at the end of the original message. But the headline
is that both of these Trojans are “invisible” to the original encVerifier program and
allow this program to work correctly in each case.
The encVerifier program correctly decodes messages because the modified
message still follows the message format, including the correct number of stop bytes.
Using the modified encVerifier program, which is aware of the message decryption,
you can recover bytes with information leakage.
It uses different data transmission speeds on the RS232 channel (type 3 Trojan).
The third type of attack on the RS232 port uses a different approach; here, instead
of the message structure, the protocol itself is used. The standard RS232 protocol uses
a single data wire for transmission. When the line is on hold, it is characterized by
the state of a label representing a negative voltage, a logical “1.” Similarly, a logical
“0” is a pause state during which the up line is charged to a positive voltage. The
RS232 specification permits the use of various combinations of data transmission
speeds, data bits in each package, number of stop bits, and parity check bits along
with various other extensions. The Alpha device uses 9600 baud transmission at 8
bits of data in each package, start and stop bits in accordance with Fig. 4.38. A start
bit should go from a label to a pause so that the receiver recognizes the start event
of an asynchronous transmission. If the receiver recognizes this state, you can begin
sampling subsequent data bits at a consistent data transmission speed to receive all
the data from the package.
For example, the Alpha board and the data receiver are currently receiving 9600
baud, but both devices are able to send and receive data at faster speeds. This third
type Trojan equips packages that are transmitted at a higher frequency, but when
Fig. 4.38 The structure of the correct RS232 message. Data bits are shown in general terms, but
will be either a logical one or logical zero
