380
4 Hardware Trojans in Microcircuits
(a) Specific command, specific parameters
The first possibility is a modification of frame CRC data in order to activate the
triggering of an HT when a specific incorrect redundant CRC code arrives at the tag.
For example, we can select the Query command with all its defined parameters (data
speed, session, selection, addressee, etc.). For example, a CRC5 is calculated with
a modified target bit. Ultimately, this CRC5 replaces the original value in a frame.
As soon as a frame is decoded by a tag, an incorrect CRC5 activates a Trojan block,
although the tag “discards” the frame.
The implementation of this Trojan suggests that adding a very small number of
elements to the original design will be very difficult to detect, so this will be a very
good option. The introduction of this type of Trojan only affects the block of the
command decoder.
(b) Specific command, all parameters
The limitation of the previous option is that it can be developed only for a specific
command, and therefore the triggering mechanism is quite simple. Line monitoring
can easily detect this mechanism. For example, if a frame command that activates a
trigger is Acknowledge, then in order to activate the trigger, you need to send such
a command. However, this command is very specific, and sending this command in
the middle of a message can easily arouse suspicion of the operator monitoring the
system.
This problem can be solved by organizing the triggering using a single command
(for example, Query), but using a usual rule for modifying parameters. For example,
you can add CRC commands to a frame, plus parameters, plus the date/number
chosen by the attacker, as shown in Fig. 4.49.
In this case, when the frame arrives at the tag and the result of the CRC check
is incorrect, it should be noted that the command + parameters can be modified.
Therefore, during a new check, a CRC number, called data, will be added to the
command + parameters. If the new CRC result is correct, then the Trojan will be
enabled.
However, this implementation assumes a greater number of logical elements used,
but it is more reliable than previous approaches. In this case, attackers will need to
modify the command decoder structure, as well as CRC5 and CRC16 blocks.
Fig. 4.49 CRC calculation
Précédent

- 399/839

Suivant