370
4 Hardware Trojans in Microcircuits
Hardware Trojans Using LEDs on a Keyboard: A Trojan on an LED keyboard is
similar to data transmission LEDs, but complies with a different protocol. Since the
data transmission process between the keyboard and the head unit of the system is
relatively slow, it is usually impossible to make the keyboard LED flicker at a speed
fast enough to be invisible to the eye, as the previous LED Trojan does. Instead,
an attacker can use a different circuit, where one of the LEDs remains lighted most
of the time and then turns off for a moment and turns on again quickly. This could
theoretically be used to transmit data where light signals sampled at specific time
intervals transmit binary data. Preliminary studies of the team [156] showed that
keyboard LEDs can be made to flicker in such a way that it is almost impossible
to notice even when closely examined by an uninitiated operator, if you do not
specifically pay particular attention to such LEDs.
Blinking cursor-type hardware Trojan
Like the LED-based Trojans described above, the well-known standard cursor on
a VGA screen always blinks with a predetermined frequency. Experts [156] have
shown that even a small change in this frequency can create a code for leaking any
information. By changing the frequency at which this cursor is blinking, you can
easily remove the key, while remaining completely invisible to the user. Of course,
such an attack would require access to the device by either completely capturing
the Alpha device, or finding the malicious user in close proximity to the device.
Using this Trojan makes it much easier to restore the key, since it does not require
physical access to the FPGA (for example, to retrieve temperature information), since
a standard VGA monitor is always an external device that is intended to be always
visible to the user.
Hardware Trojan based on VGA sync signals: The standard vertical and horizontal sync signals produced by the BASYS VGA controller, in their operation
diagrams, create a small time interval where there is no signal. This time interval
can theoretically be used by the attacker to hide data in this VGA signal in such a
way that it does not have a visible effect on the visual display of output data on the
monitor screen. To retrieve the information necessary for an attacker from this small
time interval, in order to replay the key, you only need a specialized decoder circuit
that has quick access to the VGA signal.
Changing a Stream of Binary Information on the ROM
A chip of a standard Cypress processor on a BASYS board implements the usual USB
protocol and contains a programmable microcontroller. This Cypress processor uses
built-in electrically reprogrammed EPROM memory, which is used to save the userdefined FPGA configuration, since the user can program the FPGA only through the
USB port. A hardware Trojan implemented on a Cypress chip using such a built-in
microcontroller, according to the specification, can erase the previous contents of the
EPROM memory not immediately, but only after a certain time delay, thus causing
a DoS attack, which can be rejected only by reprogramming the entire board. To
implement such a hardware Trojan on a Cypress chip, the initial original firmware
should be unloaded via a standard USB port and stored in the EPROM. It should be
4 Hardware Trojans in Microcircuits
Hardware Trojans Using LEDs on a Keyboard: A Trojan on an LED keyboard is
similar to data transmission LEDs, but complies with a different protocol. Since the
data transmission process between the keyboard and the head unit of the system is
relatively slow, it is usually impossible to make the keyboard LED flicker at a speed
fast enough to be invisible to the eye, as the previous LED Trojan does. Instead,
an attacker can use a different circuit, where one of the LEDs remains lighted most
of the time and then turns off for a moment and turns on again quickly. This could
theoretically be used to transmit data where light signals sampled at specific time
intervals transmit binary data. Preliminary studies of the team [156] showed that
keyboard LEDs can be made to flicker in such a way that it is almost impossible
to notice even when closely examined by an uninitiated operator, if you do not
specifically pay particular attention to such LEDs.
Blinking cursor-type hardware Trojan
Like the LED-based Trojans described above, the well-known standard cursor on
a VGA screen always blinks with a predetermined frequency. Experts [156] have
shown that even a small change in this frequency can create a code for leaking any
information. By changing the frequency at which this cursor is blinking, you can
easily remove the key, while remaining completely invisible to the user. Of course,
such an attack would require access to the device by either completely capturing
the Alpha device, or finding the malicious user in close proximity to the device.
Using this Trojan makes it much easier to restore the key, since it does not require
physical access to the FPGA (for example, to retrieve temperature information), since
a standard VGA monitor is always an external device that is intended to be always
visible to the user.
Hardware Trojan based on VGA sync signals: The standard vertical and horizontal sync signals produced by the BASYS VGA controller, in their operation
diagrams, create a small time interval where there is no signal. This time interval
can theoretically be used by the attacker to hide data in this VGA signal in such a
way that it does not have a visible effect on the visual display of output data on the
monitor screen. To retrieve the information necessary for an attacker from this small
time interval, in order to replay the key, you only need a specialized decoder circuit
that has quick access to the VGA signal.
Changing a Stream of Binary Information on the ROM
A chip of a standard Cypress processor on a BASYS board implements the usual USB
protocol and contains a programmable microcontroller. This Cypress processor uses
built-in electrically reprogrammed EPROM memory, which is used to save the userdefined FPGA configuration, since the user can program the FPGA only through the
USB port. A hardware Trojan implemented on a Cypress chip using such a built-in
microcontroller, according to the specification, can erase the previous contents of the
EPROM memory not immediately, but only after a certain time delay, thus causing
a DoS attack, which can be rejected only by reprogramming the entire board. To
implement such a hardware Trojan on a Cypress chip, the initial original firmware
should be unloaded via a standard USB port and stored in the EPROM. It should be
