364
4 Hardware Trojans in Microcircuits
Fig. 4.40 The correct RS232 frame at a data transmission speed of 115,200 baud may look like a
pause bit
faster transmission results in a transmission that corresponds to 10 or 11 of the 12
bits; both of the two variations are accurate enough to be accepted by the final device
without errors at a slower data transmission speed. The modified Alpha transmitter,
presented in [156], operated at a data transmission speed of 115,200 baud, sending
signals that looked absolutely similar to a data transmission speed of 9600 baud, but
with one key bit embedded in each label bit at a data transmission speed of 9600
baud. This allows the encVerifier program to verify (confirm) that the transmission
at 9600 baud contains correct information. But at the same time, it is obvious that a
malicious program that listens at a speed of 115,200 baud can easily extract the key
from the signal.
We can summarize the results obtained above as follows. When this Trojan is
activated, it transmits both signals (both expected data and sensitive data) on the
same data package. The original encVferifier program creates the expected output,
and each of the received bytes is identical to the sent bytes. The malicious program
encVerifier listens to a signal at a data transmission speed of 115,200 baud and returns
the stolen key. The signal at 115,200 baud sets the shape of its bits so that they look
like “1” or “0”, so the 8 bits of data sent at a faster transmission speed should be
all either zeros or ones, except for the information bit embedded in transmission of
ones. With this method of attack, data transmission speed of the stolen information is
exactly the same as that of the original transmission, since only one information bit
gets into the information leakage for every 12 transmitted bits, but data transmission
is 12 times faster. In the transmitted output signal, 8 bits of zeros look like 0x00
and 8 bits of ones look like 0xFF. The 0xFE bytes represent zero in the information
leakage, and the 0xFF bytes in the information leakage represent one.
Organization of denial-of-service-type attacks (DoS Trojan)
The purpose of this attack in [156] was to create a denial of service (DoS), which
sometimes occurs during normal operation of the system, but will pass unnoticed
while testing the device. Such an attack does not require the attacker to make any
spatial approximation to the device, although a closer target object of attack may
help in the process of triggering a Trojan. A DoS attack can be implemented in many
4 Hardware Trojans in Microcircuits
Fig. 4.40 The correct RS232 frame at a data transmission speed of 115,200 baud may look like a
pause bit
faster transmission results in a transmission that corresponds to 10 or 11 of the 12
bits; both of the two variations are accurate enough to be accepted by the final device
without errors at a slower data transmission speed. The modified Alpha transmitter,
presented in [156], operated at a data transmission speed of 115,200 baud, sending
signals that looked absolutely similar to a data transmission speed of 9600 baud, but
with one key bit embedded in each label bit at a data transmission speed of 9600
baud. This allows the encVerifier program to verify (confirm) that the transmission
at 9600 baud contains correct information. But at the same time, it is obvious that a
malicious program that listens at a speed of 115,200 baud can easily extract the key
from the signal.
We can summarize the results obtained above as follows. When this Trojan is
activated, it transmits both signals (both expected data and sensitive data) on the
same data package. The original encVferifier program creates the expected output,
and each of the received bytes is identical to the sent bytes. The malicious program
encVerifier listens to a signal at a data transmission speed of 115,200 baud and returns
the stolen key. The signal at 115,200 baud sets the shape of its bits so that they look
like “1” or “0”, so the 8 bits of data sent at a faster transmission speed should be
all either zeros or ones, except for the information bit embedded in transmission of
ones. With this method of attack, data transmission speed of the stolen information is
exactly the same as that of the original transmission, since only one information bit
gets into the information leakage for every 12 transmitted bits, but data transmission
is 12 times faster. In the transmitted output signal, 8 bits of zeros look like 0x00
and 8 bits of ones look like 0xFF. The 0xFE bytes represent zero in the information
leakage, and the 0xFF bytes in the information leakage represent one.
Organization of denial-of-service-type attacks (DoS Trojan)
The purpose of this attack in [156] was to create a denial of service (DoS), which
sometimes occurs during normal operation of the system, but will pass unnoticed
while testing the device. Such an attack does not require the attacker to make any
spatial approximation to the device, although a closer target object of attack may
help in the process of triggering a Trojan. A DoS attack can be implemented in many
