4.8 Peculiarities of the Introduction …
381
4.8.4 Experimental Results
A. Results of practical implementation
The various triggering mechanisms discussed above were studied using an
EPCG2tags emulator based on the FPGA described in [232].
Table 4.3 shows the additional cost of the chip area for the development of each of
the triggering mechanisms. The first two triggering mechanisms (single command
+ finite state machine, command cycle + finite state machine) were excluded from
consideration due to their ease of detection. Then there are triggering mechanisms
3, 4, 5, and 6 with a different number of elements, which use modifications of either
the command parameters or the CRC frame.
B. Experimental tests
In experimental tests, once every triggering mechanism was modeled using software
and implemented on an FPGA, it was necessarily tested using real instruments. In
order to test the design, it was necessary to add the analog part of a passive RFID
tag to the digital part implemented in an FPGA (Fig. 4.50a). Also, to eliminate the
influence of other external radiation, an anechoic chamber was used, where an FPGA
with an external interface was placed for testing (Fig. 4.50b).
To test the correctness of every triggering mechanism, a special test RFID environment was created. It was mainly created by a vector modulator, the mode of operation of instruments was controlled by a spectrum analyzer and software (Fig. 4.50c).
Figure 4.50 g shows the response of a tag to a specific command used to assess
the correctness of the mode of operation of the tag. The validation of operation was
performed using two main criteria. The first criterion was to verify that the triggering
mechanism does not modify the normal operation mode of the tag. This is important
to ensure that the tag can work as expected, at a time when the triggering mechanism
is not turned on. On the other hand, all Trojans were tested in order to show that they
are activated only when the corresponding frame has been sent. All the proposed
mechanisms successfully passed the tests.
Table 4.3 Area costs of triggering mechanisms
Triggering mechanisms
One
command
+ FSM
Command
cycle +
FSM
Modification
param. of
the specific
CRC
Modif.
CRC
Specific
commands,
specific
param.
Modif.
CRC. ALL
commands,
specific
param.
Modif.
CRC.
Specific
commands,
all param.
Rare
sequential
commands
Register 1
10
4
4
5
39
5
Trigger 2
14
6
6
6
41
9
4-LUT 2
13
10
10
14
78
21
381
4.8.4 Experimental Results
A. Results of practical implementation
The various triggering mechanisms discussed above were studied using an
EPCG2tags emulator based on the FPGA described in [232].
Table 4.3 shows the additional cost of the chip area for the development of each of
the triggering mechanisms. The first two triggering mechanisms (single command
+ finite state machine, command cycle + finite state machine) were excluded from
consideration due to their ease of detection. Then there are triggering mechanisms
3, 4, 5, and 6 with a different number of elements, which use modifications of either
the command parameters or the CRC frame.
B. Experimental tests
In experimental tests, once every triggering mechanism was modeled using software
and implemented on an FPGA, it was necessarily tested using real instruments. In
order to test the design, it was necessary to add the analog part of a passive RFID
tag to the digital part implemented in an FPGA (Fig. 4.50a). Also, to eliminate the
influence of other external radiation, an anechoic chamber was used, where an FPGA
with an external interface was placed for testing (Fig. 4.50b).
To test the correctness of every triggering mechanism, a special test RFID environment was created. It was mainly created by a vector modulator, the mode of operation of instruments was controlled by a spectrum analyzer and software (Fig. 4.50c).
Figure 4.50 g shows the response of a tag to a specific command used to assess
the correctness of the mode of operation of the tag. The validation of operation was
performed using two main criteria. The first criterion was to verify that the triggering
mechanism does not modify the normal operation mode of the tag. This is important
to ensure that the tag can work as expected, at a time when the triggering mechanism
is not turned on. On the other hand, all Trojans were tested in order to show that they
are activated only when the corresponding frame has been sent. All the proposed
mechanisms successfully passed the tests.
Table 4.3 Area costs of triggering mechanisms
Triggering mechanisms
One
command
+ FSM
Command
cycle +
FSM
Modification
param. of
the specific
CRC
Modif.
CRC
Specific
commands,
specific
param.
Modif.
CRC. ALL
commands,
specific
param.
Modif.
CRC.
Specific
commands,
all param.
Rare
sequential
commands
Register 1
10
4
4
5
39
5
Trigger 2
14
6
6
6
41
9
4-LUT 2
13
10
10
14
78
21
