384
4 Hardware Trojans in Microcircuits
To study the reliability of the triggering mechanism 5, the same method as for the
triggering mechanism 4 can be used, since the triggering mechanism 4 can usually
be implemented as multiple commands in an EPC protocol.
Let’s summarize the results.
We reviewed the results of studies of hardware Trojans and their triggering
mechanisms for the inactive C1GEN2 RFID tag [233].
The case was considered when Trojans were added to a circuit by a malicious
developer in such a way that such a Trojan could then avoid detection not only
during testing in production, but also during testing by the system integrator, as well
as monitoring the RFID system line while using in specific application.
The proposed [225] triggering mechanisms for a hardware Trojan were based
either on functional sequences (i.e., a reader sends a special set of commands) or on
a small modification of the frame content. It is shown that small modifications of the
frame content can be more effective in order to avoid detection during all the above
tests for operation. However, such a triggering mechanism calls for special attention
in order to avoid its unintentional activation due to radio frequency interference.
Therefore, the authors of [225] suggested that the frame be modified in accordance
with the specific configuration of the device for data integrity check.
In the way of evidence that supports effectiveness of the created approach, the
proposed triggering mechanisms were built into the specialized emulator described
in [232]. This emulator was used to assess the effectiveness and secrecy of triggering
mechanisms in a complex RFID system that works in conjunction with other RFID
tags and uses a standard commercial reader with line monitoring. This is necessary
to check the condition that the infected tag will not interfere with other tags and that
the triggering mechanism will not be detected by monitoring the RFID system line
in real time, which has been proven.
4.9 Hardware Trojans in Wireless Cryptographic ICs
4.9.1 Organization Features of Information Leakage
from Wireless Cryptographically Protected
Microcircuits
As was shown above, chips infected with hardware Trojans may have additional
functions that neither the developer, nor the supplier, nor the customer are aware of
and which the attacker can use after installing the chips into the system at the desired
time. Depending on the field of application, the consequences of such attacks can
stretch from “minor inconveniences” to global disasters.
In the previous sections of this chapter, we have given a fairly complete classification of hardware Trojans based on their physical characteristics, methods of activation, and specific actions. The type of Trojan is associated with the form of attack and
the way in which it is physically organized; hardware Trojans can be aimed either
Précédent

- 403/839

Suivant