4.9 Hardware Trojans in Wireless Cryptographic ICs
385
at changing the operation of the chip logic, or at changing parametric functions and
can be implemented in a localized or distributed way. The term “triggering” refers to
a mechanism that allows you to select malicious added functions; hardware Trojans
can always be physically active or rely on specific events (e.g., input sequence and
elapsed time) to be activated. The useful load describes the way of actual impact
of malicious added functions; hardware Trojans can distort results, cause a denial of
service, or even physically disable a chip.
As we have already noted, among all possible methods of solving the problem of
detecting such Trojans, routine production testing is not suitable, since it is intended
primarily to detect manufacturing defects, but not to detect such malicious hardware
modifications. One option may be destructive reverse engineering, but it becomes
too costly and difficult to organize due to the increasing complexity of chips. In addition, as the name says, it can only be used on a small sample of chips and does not
guarantee at all that the remaining unexamined chips are free of Trojans. Two main
areas can be noted when examining various known methods of detecting Trojans in
detail: extended functional testing, as well as the identification and verification of
characteristic features of so-called side channels. In the first direction, it is usually
assumed that attackers will select rarely occurring events as triggering attack mechanisms, so the idea of recognizing such events and a corresponding improvement in
a set of production tests are popular today [234]. In the second direction, the work of
Agrawal et al. [235] should be noted, since for the first time they demonstrated the
possibility of using statistical analysis to develop effective methods for describing
and applying specific power (current) characteristics of consumption, in order to
distinguish “real” ICs from those infected by a Trojan. Alternatively, earlier work
[22] proposed methods based on the use of characteristic signs of time delays in
circuits, since they introduce certain deviations (anomalies) in measured values of
currents at chip supply ports [236]. Based on these studies, another integral method
subsequently emerged, which uses the principle of dividing a total equivalent power
supply circuit into smaller power supply sections (networks). Its further development
was based on the use of various methods of calibration of the measurement process to
reduce the effects of technological variations in parameters and measurement errors.
However, all these methods were aimed at the level of standard ICs. In this section,
we will discuss wireless cryptographic ICs. Such circuits, of course, contain both a
digital part, which provides the necessary form of encryption, and an analog (radio
frequency, RF) part, which ensures the transmission of coded data through publicly
accessible wireless communication channels.
In [237], it is popularly explained how these embedded hardware Trojans organize
the process of confidential information leakage from wireless cryptographic ICs to
attackers.
To do this, the authors consider such hardware Trojans, the purpose of the useful
load of which is to organize the leakage of secret information (for example, an
encryption key) over a wireless channel so that the attacker can quickly decipher the
encrypted data transmission. The practical value of such hardware Trojans is that an
attacker can only listen in publicly available wireless channels, but he does not have
the ability to control them. Of course, it is important to bear in mind that in this case
Précédent

- 404/839

Suivant