374
4 Hardware Trojans in Microcircuits
Hardware Trojans can be inserted into a circuit either at the design stage or at the
manufacturing stage. Due to the globalization of the world economy, manufacturers
are now spread around the world in order to minimize production costs. This creates
prerequisites for attackers inside these foundries to add malicious circuits, i.e., ICs
may be unauthorized modified [225]. Malicious circuits can also be added at the
design phase. This can be done intentionally by the chip developer in order to get
benefits from the future use of the circuit, either by a malicious developer or by unfair
subcontractors (suppliers of IP blocks, design tools) [140].
In this section, we discuss hardware Trojans introduced at the design stage by
malicious developers. Later, such Trojans can be used to attack the system or to obtain
important information. This gives a significant advantage to the chip supplier over
the system developer. In particular, we will consider hardware Trojans inside EPC
C1G2 tags, including a design analysis and methods for implementing the hardware
triggering mechanism. The triggering mechanism is a key element for such Trojans,
since Trojans must be inactive while the system developer is testing his application,
and the Trojan must be activated in such a way that it is not detected by the system
application.
4.8.2 EPC C1G2 RF Tags and Hardware Trojans
EPC Gen2 Passive Tag Architecture
As is known [225], RFID is one of the varieties of modern wireless technology,
which allows for the implementation of automated wireless remote detection and
identification (recognition) of objects. The main components of such an RFID system
are radio frequency tags (transponders), which are attached to objects of our interest,
and readers, which automatically remotely establish a prompt communication with
tags, in order to enable identification. The most common passive RFID tags have
two main functional modules: analog interface module and digital internal module.
The analog module accepts an incoming RF signal in order to formulate the supply
voltage Vdd for a digital module, to process input data and to generate a sync signal
for the digital module [226]. The direct transmission RFID channel decodes the
demodulated signal, generates the signal sequences requested by the reader, controls
access to the memory unit, and provides information that will be transmitted over
the air to the reader [226].
Hardware Trojans in EPC Gen2 RFID Tags: A hardware Trojan embeddedinside
such RFID transponder tags can either create an unwanted channel for important
information leakage, gaining unauthorized access to this information in order to
modify (change it in an appropriate way for the attacker) or delete (destroy) it. For
example, an RFID tag has protected memory, and the hardware Trojan function may
be an imperceptible transmission of the password of each tag to a reader controlled
by an attacker.
Précédent

- 393/839

Suivant