372
4 Hardware Trojans in Microcircuits
damage to the FPGA. Other attempts were made to write a self-destructive HDL
code, but in the end it was impossible to create a specific Trojan structure in a month
that would disrupt FPGA safe configurations by self-destruction. It is clear that if
the time limit was lifted, this team might have been able to accomplish this.
Saving one bit
Professional microcircuit security experts know that every DoS attack, while maintaining damage to the FPGA, is transient in that the reset operation will reset the
stream of processed binary data, including the Trojan program. Therefore, any hardware Trojan embedded in a system will be forced to “restart” in order to start functioning, which can be very difficult to organize. After all, this will require careful
development of the corresponding design of the triggering mechanism to reinstall
a Trojan to its previous position. But if at least one bit of the modified data can be
stored in Alpha, then this bit can be used to provide the triggering mechanism of this
Trojan and for the corresponding automatic re-installation of the Trojan for each reset
signal. A team of researchers [156] mounted a serious effort to find such an effective
way to store at least one bit of data, but they could not find an effective way. There
was even an attempt to contact the PROM of the FPGA using the equipment of the
Cypress chip itself, which is used to control the USB port and has its own PROM.
But, unfortunately, it was discovered that it was impossible to write the required
commands directly to Cypress PROM, upon the protocol this required a USB device
inserted into a standard USB port of the board in order to change the contents of this
PROM.
Instead of a conclusion on this section, only some obvious conclusions can be
drawn. Thus, hardware Trojans developed by a group of specialists, presented at the
CSAW 2008 conference for consideration by an expert panel of an authoritative jury
in industry and science, can be grouped according to the complexity of hardware
Trojans implementation, ensuring their secrecy from detection, by criteria or power
consumption, novelty, etc.
Table 4.2 shows only the partial results of the effectiveness analysis of the developed technical solutions in terms of the magnitude of their power consumption relative to the reference design. Within the studied window time of 20 min, these values
differed slightly from the same measurement a few minutes earlier. It should be noted
that the above T5 Trojan requires high power values due to the nature of its design.
Table 4.2 Specific changes in power consumption of the system for each introduced Trojan in
comparison with the reference design for each of the system states
Ref mA
T1 A
T3 A
T4 A
T5 A
T6 A
T7 A
T8 A
Reset
146.4
0.4
0.6
0.6
65.4
0.7
0.7
0.8
Init min
156.0
0.3
0.5
0.5
22.8
1.6
0.6
1.0
Init max
185.0
0.4
0.5
0.6
22.5
0.7
0.7
0.7
Encrypt
144.7
0.0
0.0
0.0
0.0
0.0
0.1
0.5
Transmit
153.1
0.4
0.6
0.6
22.2
1.0
0.8
1.2
Précédent

- 391/839

Suivant