4.9 Hardware Trojans in Wireless Cryptographic ICs
391
Time, s
b)
Time, s
х10
-7
а)
х10
-7
Difference in
amplitudes =
120 μW
Difference in
frequencies = 0.4
GHz
stolen key bit = 0
stolen key bit = 1
stolen key bit = 0
stolen key bit = 1
μW
μW
Tr
an
sm
iss
ion
po
we
r,
μ
W
Tr
an
sm
iss
ion
po
we
r,
μ
W
Fig. 4.56 Difference in transmission by the trojan-infected circuit of type-I depending on the bit
value of the stolen key (a), and difference in transmission by the trojan-infected circuit of type-II
depending on the bit value of the stolen key (b)
frequency. Figure 4.56b shows the corresponding impact on the signal transmitted
by the experimental circuit shown in Fig. 4.56.
In this case, the frequency increases from 4.8 GHz to 5.2 GHz but the amplitude
remains at 1105 μW. In both cases, when the stolen key bit is “0”, no change occurs
in the transmitted signal.
The overall area overhead incurred by each of these trojans is around 0.02% of
the digital part of the chip. Figure 4.56 assumes that the storage elements holding
the secret key are enhanced scan flip-flops which are connected in sequence and are
already present in the design for structure-based industry testing. If this is not the
case, a separate 56-bit rotator needs to be added. It is made of simple latches for
Précédent

- 410/839

Suivant