4.9 Hardware Trojans in Wireless Cryptographic ICs
389
a transistor of 5%, operates at a frequency of 4.8 GHz, and includes five peaks with
an amplitude greater than 300 μW with the highest measured value at 1114 μW.
Two alternative hardware Trojans that can be installed in an infected circuit were
used in work [237]. Through simple modifications only on the digital part of a
chip, these hardware Trojans create a leakage of the encryption key, hiding it within
the acceptable amplitudes or frequencies of the wireless transmission due to the
variability of the technological process; in doing so, they ensure that the circuit
continues to meet all of its performance specifications.
The principle of operation of these Trojans is simple: at a time, extract 1 bit from
the 56-bit encryption key that is stored in the DES core, and organize the leakage
of this information, hiding it in one 64-bit block of transmitted data. After only 56
ciphertext blocks are transmitted, the full key will be completely transmitted, thus
creating a leakage of encrypted information.
Each of such hardware Trojan includes two modifications. The first modification
(see Fig. 4.55a) is common to both Trojans and serves to extract the encryption
key from the DES core. The second modification (see Fig. 4.55b) is different for
each of the Trojans and is aimed at manipulating the amplitude or frequency of the
transmission in order to create a key leakage through a wireless channel.
The key extraction process uses the ability of the modified scan triggers to store 2
bits, one in the D-trigger and one in the next latch so that successive vectors can be
given in order to detect faults by delay when a circuit is in test mode. However, during
normal operation, latches are transparent, essentially holding the same information
as D-triggers. In the experimental scheme, the 56-bit encryption key is stored in a
sequence of 56 upgraded scan triggers that are serially connected in a scan chain, as
shown in the upper part of Fig. 4.55a. The basic idea for extracting the secret key is
to store it only in the latches of the upgraded scan triggers and reuse the D-triggers to
create a 56-bit block. Initially, when a user loads a key, triggers and latches contain
correct bits. Then, each time a data block is transmitted, the last bit of this block
is extracted and hidden in the transmitted data, while the rotating block shifts their
contents by one position. We emphasize that only D-triggers of a block of upgraded
scan triggers contain a distorted version of a key, while the following latches keep
holding the correct version so that the ciphertext is created correctly. For this purpose,
a simple control logic, consisting of several gates, shown in Fig. 4.55a at the bottom
is sufficient.
The modified circuit for transferring the key takes the stolen bit and modifies the
transmission signal in one of two ways. The first option (type-I), shown on the left in
Fig. 4.55b, manipulates the transmission amplitude; when the stolen key bit is “1”, an
additional driver strengthens the legitimate transmission signal before it reaches the
gating generator, thereby slightly increasing the transmission amplitude. Figure 4.55a
shows the corresponding impact on the signal transmitted by the experimental circuit
shown in figure. In this case, the amplitude increases from 1114 μW to 1235 μW
but the frequency remains at 4.8 GHz. The second option (type-II), shown on the
right side of Fig. 4.56b, manipulates the transmission frequency; when the stolen
key bit is “1”, the original buffer is bypassed and an alternative buffer is used to
delay the output of the pulse generator, thereby slightly increasing the transmission
389
a transistor of 5%, operates at a frequency of 4.8 GHz, and includes five peaks with
an amplitude greater than 300 μW with the highest measured value at 1114 μW.
Two alternative hardware Trojans that can be installed in an infected circuit were
used in work [237]. Through simple modifications only on the digital part of a
chip, these hardware Trojans create a leakage of the encryption key, hiding it within
the acceptable amplitudes or frequencies of the wireless transmission due to the
variability of the technological process; in doing so, they ensure that the circuit
continues to meet all of its performance specifications.
The principle of operation of these Trojans is simple: at a time, extract 1 bit from
the 56-bit encryption key that is stored in the DES core, and organize the leakage
of this information, hiding it in one 64-bit block of transmitted data. After only 56
ciphertext blocks are transmitted, the full key will be completely transmitted, thus
creating a leakage of encrypted information.
Each of such hardware Trojan includes two modifications. The first modification
(see Fig. 4.55a) is common to both Trojans and serves to extract the encryption
key from the DES core. The second modification (see Fig. 4.55b) is different for
each of the Trojans and is aimed at manipulating the amplitude or frequency of the
transmission in order to create a key leakage through a wireless channel.
The key extraction process uses the ability of the modified scan triggers to store 2
bits, one in the D-trigger and one in the next latch so that successive vectors can be
given in order to detect faults by delay when a circuit is in test mode. However, during
normal operation, latches are transparent, essentially holding the same information
as D-triggers. In the experimental scheme, the 56-bit encryption key is stored in a
sequence of 56 upgraded scan triggers that are serially connected in a scan chain, as
shown in the upper part of Fig. 4.55a. The basic idea for extracting the secret key is
to store it only in the latches of the upgraded scan triggers and reuse the D-triggers to
create a 56-bit block. Initially, when a user loads a key, triggers and latches contain
correct bits. Then, each time a data block is transmitted, the last bit of this block
is extracted and hidden in the transmitted data, while the rotating block shifts their
contents by one position. We emphasize that only D-triggers of a block of upgraded
scan triggers contain a distorted version of a key, while the following latches keep
holding the correct version so that the ciphertext is created correctly. For this purpose,
a simple control logic, consisting of several gates, shown in Fig. 4.55a at the bottom
is sufficient.
The modified circuit for transferring the key takes the stolen bit and modifies the
transmission signal in one of two ways. The first option (type-I), shown on the left in
Fig. 4.55b, manipulates the transmission amplitude; when the stolen key bit is “1”, an
additional driver strengthens the legitimate transmission signal before it reaches the
gating generator, thereby slightly increasing the transmission amplitude. Figure 4.55a
shows the corresponding impact on the signal transmitted by the experimental circuit
shown in figure. In this case, the amplitude increases from 1114 μW to 1235 μW
but the frequency remains at 4.8 GHz. The second option (type-II), shown on the
right side of Fig. 4.56b, manipulates the transmission frequency; when the stolen
key bit is “1”, the original buffer is bypassed and an alternative buffer is used to
delay the output of the pulse generator, thereby slightly increasing the transmission
