376
4 Hardware Trojans in Microcircuits
system and sets functional control parameters, such as modulation, data transmission
speed, and other communication system parameters [231]. In the course of such
standard functional testing, each group of devices under test is tested while sweeping
various parameters that can activate (launch) hardware Trojans. Real-time system
monitoring is based on the discreet observation of the nature of interaction between
a reader and tags, as shown in Fig. 4.45b.
Then the results of data transmission are assessed in order to detect any “wrong”
mode of operation or an unusual change (degradation) in the performance of the
process. An example of a typical RFID application is a list of tags, which consists
of listing all the tags present in the reader field. Such a list is formed in accordance
with a special protocol in order to eliminate possible errors, and then, once the tag is
added to this list, the reader can contact specifically with one tag to exchange specific
data with it. It is obvious that all these operations must comply with the accepted
standard. Thus, it is possible to control a RFID system by simply discreetly sending
an appropriate command and tracking the sequence of all commands sent by this
reader to detect any “abnormal” system operation.
4.8.3 Triggering Mechanisms of Hardware Trojans in EPC
C1G2 Radio Frequency Tags
In order to develop a triggering mechanism of a hardware Trojan for a passive RFID
tag, it should be considered that this triggering mechanism should not be detected
during the production monitoring of operation and should not manifest itself in
the (system) monitoring of a line. Figure 4.46 shows the primary feature blocks of
the EPC C1G2 RF tag, where the analog high-frequency interface (AFE) and digital
blocks are separately distinguished. Since herein we consider hardware Trojans (HT)
only inside the digital part of a tag, later in this section we will discuss some variations
of Trojans and their triggering mechanisms.
A. Triggering Mechanisms Based on Parametric Changes: The EPC RFID tag
exchange protocol specifies frame parameters for a low-level communication system. Usually, the standard cycle starts with the first clock (preamble)
with synchronizing elements of Delimiter, Tari, RTcal or TRCal type [231]
(Fig. 4.46).
Basically, even this normal command can be used to turn on an HT, and its
triggering mechanism can be added to a tag decoder block, which is responsible for
frame decryption using the pulse-interval encoding (PIE) pulse-width modulation
methods. Durations of synchronization sequences are not fixed, they are variable, as
explained in Fig. 4.47.
Thus, you can use specific numerical values or specific variation ranges of these
parameters to activate an HT. However, in any communication channel, there may
be some kinds of errors in data being sent, which is unavoidable in the very nature of
wireless communication. In addition to considering the probability, it should be noted
4 Hardware Trojans in Microcircuits
system and sets functional control parameters, such as modulation, data transmission
speed, and other communication system parameters [231]. In the course of such
standard functional testing, each group of devices under test is tested while sweeping
various parameters that can activate (launch) hardware Trojans. Real-time system
monitoring is based on the discreet observation of the nature of interaction between
a reader and tags, as shown in Fig. 4.45b.
Then the results of data transmission are assessed in order to detect any “wrong”
mode of operation or an unusual change (degradation) in the performance of the
process. An example of a typical RFID application is a list of tags, which consists
of listing all the tags present in the reader field. Such a list is formed in accordance
with a special protocol in order to eliminate possible errors, and then, once the tag is
added to this list, the reader can contact specifically with one tag to exchange specific
data with it. It is obvious that all these operations must comply with the accepted
standard. Thus, it is possible to control a RFID system by simply discreetly sending
an appropriate command and tracking the sequence of all commands sent by this
reader to detect any “abnormal” system operation.
4.8.3 Triggering Mechanisms of Hardware Trojans in EPC
C1G2 Radio Frequency Tags
In order to develop a triggering mechanism of a hardware Trojan for a passive RFID
tag, it should be considered that this triggering mechanism should not be detected
during the production monitoring of operation and should not manifest itself in
the (system) monitoring of a line. Figure 4.46 shows the primary feature blocks of
the EPC C1G2 RF tag, where the analog high-frequency interface (AFE) and digital
blocks are separately distinguished. Since herein we consider hardware Trojans (HT)
only inside the digital part of a tag, later in this section we will discuss some variations
of Trojans and their triggering mechanisms.
A. Triggering Mechanisms Based on Parametric Changes: The EPC RFID tag
exchange protocol specifies frame parameters for a low-level communication system. Usually, the standard cycle starts with the first clock (preamble)
with synchronizing elements of Delimiter, Tari, RTcal or TRCal type [231]
(Fig. 4.46).
Basically, even this normal command can be used to turn on an HT, and its
triggering mechanism can be added to a tag decoder block, which is responsible for
frame decryption using the pulse-interval encoding (PIE) pulse-width modulation
methods. Durations of synchronization sequences are not fixed, they are variable, as
explained in Fig. 4.47.
Thus, you can use specific numerical values or specific variation ranges of these
parameters to activate an HT. However, in any communication channel, there may
be some kinds of errors in data being sent, which is unavoidable in the very nature of
wireless communication. In addition to considering the probability, it should be noted
