386
4 Hardware Trojans in Microcircuits
the Trojans are already active. Moreover, these hardware Trojans control both the
entire system, which contains secret information, and its specific subsystem, which
controls the wireless transmission process, and they synchronously manipulate only
the parametric space, without violating any functional specification of the microcircuit. It is known that for digital cryptographic microcircuits, similar attackers have
developed similar hardware Trojans aimed at organizing the leakage of secret keys
through special side channels [238, 239].
It should be noted that the work [237] is actually the first research applicable to
studying hardware Trojans in the field of cryptographic SoC (system-on-chip).
Using the original method for analyzing the detection of wireless cryptographic
microcircuit Trojans and experimental hardware Trojans variations that were specifically designed by the authors-developers for “hacking” the cryptographic protection
of a microcircuit, the authors [237] proposed three key solutions dealing with the
complexity of attacks, difficulty of detection, and possible solution.
Specialists in combating various types of hardware Trojans argue that a small
modification of the digital part of a wireless cryptographic chip is quite enough
to meet all the necessary conditions for organizing the leakage of completely secret
information without changing the schematic solutions of the analog part. The vulnerability of such chips depends on the fact that they transmit a variety of data on publicly
available wireless channels. However, the only place vulnerable in this area is the
analog nature of wireless communication; as a result, other parameters came to light
(for example, amplitude, frequency, and phase of a signal). Of course, hardware
Trojans can hide additional information within tolerance boxes for such constant
values and covertly transmit them. Even if such a data transmission meets all technical requirements and is completely legitimate, an attacker who knows the structure
of the additional information will be able to retrieve it.
Avoidance of detection by production testing methods is trivial. The operation of
the digital part of a chip in the normal way and in the testing mode cannot reveal
a Trojan: due to the fact that the analog part of a chip usually remains intact by
an attacker, all tests of the analog part and the RF specification will be carried out.
In addition, since the stolen information is hidden within the allowed transmission
specification limits, standard system-level functional tests will also be carried out.
Moreover, the existing methods of generating and verifying the characteristics using
side channels fail when trying to detect hardware Trojans in wireless cryptographic
ICs.
Despite the fact that hardware Trojans can be hidden alongside the chaotic variation of process parameters of the manufacturing process of a wireless cryptographic
chip and may not be detected by any methods that have been discussed up to now,
they can nevertheless be detected. Effective hardware Trojans are required to have
a certain impact on the data transmission process, which is an attacker’s tool for
stealing a secret key. Although the defender is usually not aware of such a structure,
it may be sufficient to conduct an in-depth statistical analysis of all these parameters
in order to identify a hardware Trojan. Since an attacker usually does not know what
statistics will be collected or how they will be analyzed, it is difficult to protect against
this method. In other words, the element of surprise of an attacker who “fiddles” with
4 Hardware Trojans in Microcircuits
the Trojans are already active. Moreover, these hardware Trojans control both the
entire system, which contains secret information, and its specific subsystem, which
controls the wireless transmission process, and they synchronously manipulate only
the parametric space, without violating any functional specification of the microcircuit. It is known that for digital cryptographic microcircuits, similar attackers have
developed similar hardware Trojans aimed at organizing the leakage of secret keys
through special side channels [238, 239].
It should be noted that the work [237] is actually the first research applicable to
studying hardware Trojans in the field of cryptographic SoC (system-on-chip).
Using the original method for analyzing the detection of wireless cryptographic
microcircuit Trojans and experimental hardware Trojans variations that were specifically designed by the authors-developers for “hacking” the cryptographic protection
of a microcircuit, the authors [237] proposed three key solutions dealing with the
complexity of attacks, difficulty of detection, and possible solution.
Specialists in combating various types of hardware Trojans argue that a small
modification of the digital part of a wireless cryptographic chip is quite enough
to meet all the necessary conditions for organizing the leakage of completely secret
information without changing the schematic solutions of the analog part. The vulnerability of such chips depends on the fact that they transmit a variety of data on publicly
available wireless channels. However, the only place vulnerable in this area is the
analog nature of wireless communication; as a result, other parameters came to light
(for example, amplitude, frequency, and phase of a signal). Of course, hardware
Trojans can hide additional information within tolerance boxes for such constant
values and covertly transmit them. Even if such a data transmission meets all technical requirements and is completely legitimate, an attacker who knows the structure
of the additional information will be able to retrieve it.
Avoidance of detection by production testing methods is trivial. The operation of
the digital part of a chip in the normal way and in the testing mode cannot reveal
a Trojan: due to the fact that the analog part of a chip usually remains intact by
an attacker, all tests of the analog part and the RF specification will be carried out.
In addition, since the stolen information is hidden within the allowed transmission
specification limits, standard system-level functional tests will also be carried out.
Moreover, the existing methods of generating and verifying the characteristics using
side channels fail when trying to detect hardware Trojans in wireless cryptographic
ICs.
Despite the fact that hardware Trojans can be hidden alongside the chaotic variation of process parameters of the manufacturing process of a wireless cryptographic
chip and may not be detected by any methods that have been discussed up to now,
they can nevertheless be detected. Effective hardware Trojans are required to have
a certain impact on the data transmission process, which is an attacker’s tool for
stealing a secret key. Although the defender is usually not aware of such a structure,
it may be sufficient to conduct an in-depth statistical analysis of all these parameters
in order to identify a hardware Trojan. Since an attacker usually does not know what
statistics will be collected or how they will be analyzed, it is difficult to protect against
this method. In other words, the element of surprise of an attacker who “fiddles” with
