4.8 Peculiarities of the Introduction …
375
The main distinguishing characteristic of a hardware Trojan is its activation on a
very rare combination of different events, in order not to be detected while passing
standard tests for operation [227–229, 49]. In RFID systems, it is common practice
for detecting any error in a system failure or malfunction which is system condition
monitoring, and such monitoring is able to detect every rare command or every alien
sequence from among the commands corresponding to the conditions of launching
a hardware Trojan. This makes it much more difficult for attackers to design the
triggering mechanism because it forces it to bypass functional testing (i.e., system
testing conducted by a system integrator) and real-time performance monitoring.
Modern “advanced” effective methods for detecting hardware Trojans are based on
the analysis of so-called side channels, i.e., on measurements of the parameters
of dynamic power consumption or variations in signal delay time values, followed
by comparison of the results thus obtained with similar results obtained using the
reference, obviously safe “golden” sample of the same RFID circuit [230]. In this
section, we will consider a variation of the situation when a hardware Trojan was
introduced during the design stage, therefore there is no such “golden model” and
therefore these methods are unacceptable. Hardware Trojans, discussed later in this
section, should avoid possible detection during the following control procedures:
• The stage of standard circuit verification and the stage of RFID device functional
testing;
• Real-time RFID system monitoring.
Standard manufacturing performance monitoring conducted on RFID tags shown
in Fig. 4.45a. Normally such tests are based on EPC commands that are sent between
the tag and the reader. Thus, the Query command usually initiates a communication
Fig. 4.45 Example of the tag-reader communication system operation
375
The main distinguishing characteristic of a hardware Trojan is its activation on a
very rare combination of different events, in order not to be detected while passing
standard tests for operation [227–229, 49]. In RFID systems, it is common practice
for detecting any error in a system failure or malfunction which is system condition
monitoring, and such monitoring is able to detect every rare command or every alien
sequence from among the commands corresponding to the conditions of launching
a hardware Trojan. This makes it much more difficult for attackers to design the
triggering mechanism because it forces it to bypass functional testing (i.e., system
testing conducted by a system integrator) and real-time performance monitoring.
Modern “advanced” effective methods for detecting hardware Trojans are based on
the analysis of so-called side channels, i.e., on measurements of the parameters
of dynamic power consumption or variations in signal delay time values, followed
by comparison of the results thus obtained with similar results obtained using the
reference, obviously safe “golden” sample of the same RFID circuit [230]. In this
section, we will consider a variation of the situation when a hardware Trojan was
introduced during the design stage, therefore there is no such “golden model” and
therefore these methods are unacceptable. Hardware Trojans, discussed later in this
section, should avoid possible detection during the following control procedures:
• The stage of standard circuit verification and the stage of RFID device functional
testing;
• Real-time RFID system monitoring.
Standard manufacturing performance monitoring conducted on RFID tags shown
in Fig. 4.45a. Normally such tests are based on EPC commands that are sent between
the tag and the reader. Thus, the Query command usually initiates a communication
Fig. 4.45 Example of the tag-reader communication system operation
