366
4 Hardware Trojans in Microcircuits
tricks compared to simply redirecting this information through unused conclusions,
since many standard verification tests never check for the presence of information
transmitted “through heat.”
An FPGA microcircuit should be able to generate enough heat to be detected
by a temperature sensor, on the order of several degree Fahrenheit. As with most
FPGA devices, the dissipation of static and dynamic currents and, consequently, the
total amount of heat produced are taken into account when assessing the amount of
power. In our use case, since the configuration during operation is unchanged, the
static power always remains very similar to the power of the original and modified
design with heat leakage. Consequently, it is the dynamic power dissipation that
determines most of the changes in the power dissipation value.
The simple formula for estimating dynamic power dissipation is as follows:
Power = CEq × V
2
cc × F, where CEq is the total capacitive load, V cc is the
supply voltage, and F is the switching frequency. In this Trojan, a group of output
pins, switched to 50 MHz, causes additional capacitive loads, controlling the corresponding output pins. As they switch quickly, some amount of excess power is dissipated as compared to the power of the reference construct, causing the FPGA to heat
up a little. To transfer the key, the authors of [156] presented “0” as the temperature
of normal operation and “1” as the temperature during the “heated” operation. The
Trojan’s internal counter allows you to slowly shift key bits (during around 1 min)
and provides sufficient time for the FPGA to change the temperature. By sampling
the temperature of the FPGA at certain time intervals, the attacker can get the key.
In [156], the authors took temperature readings at certain intervals, using a conventional thermocouple connected to a multimeter. Then they processed the results of
these measurements using the previously described transmission scheme. This made
it relatively easy to recover the secret key used to decrypt the message.
FPGA Attack Based on Amplitude-Modulated Data Transmission
As system designers know, the RF signal is generated by modulating the output on the
FPGA. This signal can be used to transmit bits of the secret key. For RF attacks, the
authors of [156] used one of the terminals of the contact panel, since this terminal is
located perpendicular to the plane of the common ground surfaces of the board, which
creates a more efficient equivalent antenna than a simple geometric extension of the
terminal outputs. To test the effectiveness of this attack without using any special
equipment and to demonstrate the capabilities of this attack in distance, this was
done at two different frequencies. One transmission was performed at a frequency
of 1560 kHz and could be received on a conventional receiver with amplitude modulation (AM receiver). Another attack was broadcasting at a frequency of 50 MHz
and required an already specialized HAM-radio-type radio receiver (amateur radio
communication) in order to receive the transmitted signal. The AM transmission has
a very short distance, on the order of inches, compared to the 50 MHz transmission
received at a distance of more than 4 feet. In both cases, touching the output with
even one finger or paper clip increases the transmission range by several orders of
magnitude. Since both of these attacks are approximately the same in terms of their
Précédent

- 385/839

Suivant