392
4 Hardware Trojans in Microcircuits
storage and transformation of the key in order to transmit it in a bit-by-bit way. Even
in this case, the area overhead still remains well below 0.4% of the digital part of the
chip, and in the worst-case scenario (when the key forms a sequence of alternate “0”
and “1”), the caused increase in power is 0.25%.
Let’s consider the process of secret information extraction. Figures 4.56 a and b
show the transmission power wave form of a Type-I and a Type-II trojan-infested
chip, respectively, when the stolen key bit transmitted along with the legitimate signal
is “1”, as well as when it is “0”. Similarly, in the Type-II trojan-infected chip, the
difference in the stolen key bit value is reflected as a difference of 120 μW in the
maximum amplitude. Similarly, in the Type-II trojan-infected chip, the difference
in the stolen key bit value is reflected as a 0.4 GHz difference in the frequency.
Both of these differences are well within the margins allowed for process variations
and operating condition fluctuations and would not raise any suspicion. While the
attacker does not know in advance the exact amplitude or frequency levels in each of
the two cases, but the fact that this difference is always present, suffices for extracting
the secret key. All the attacker needs to do is listen to the wireless channel to observe
these two different amplitude or frequency levels which correspond to a stolen key
bit of “1” and a stolen key bit of “0”, respectively. Once these two levels are known,
listening to 56 consecutive transmission blocks reveals a rotated version of the 56 bits
of the encryption key. Using this information, the attacker needs at most 56 attempts
(i.e., all rotations of the extracted 56 bits) to decrypt the transmitted ciphertext.
4.9.2 Basic Methods of Trojan Detection
As seen above, the mechanism through which the two hardware trojans create a leak
of secret information over the wireless channel allows them to evade detection not
only by traditional manufacturing testing but also from previously considered Trojan
detection methods.
Functional, structural, and enhanced testing is considered in work [237]. These
examples of hardware Trojans do not alter the functionality of the digital part of
the circuit. In normal operation, the enhanced scan flip-flops that hold the key bits
are loaded appropriately. Numerous randomly generated functional test vectors are
simulated by these Trojan writers to verify the correctness of the produced ciphertext.
In test mode, the scan chain also operates as expected. To demonstrate that structural
tests do not detect these hardware Trojans, a standard industrial ATPG tool (automatic
test program generation) is used to generate test vectors for all stuck-at and delay
faults in the Trojan-free circuit. These tests are simulated on two Trojan-infested
circuits. As expected, all tests passed. Enhancing the test set with further vectors
that exercise rare events is also ineffective [234], since the hardware Trojans do not
affect the digital functionality. The analog portion is not modified, and therefore it
also passes the traditional specification-based analog/RF test.
System-level tests examining the parameters of the wireless transmission also fail
to expose the hardware Trojans, since the structure added by the leaked information
4 Hardware Trojans in Microcircuits
storage and transformation of the key in order to transmit it in a bit-by-bit way. Even
in this case, the area overhead still remains well below 0.4% of the digital part of the
chip, and in the worst-case scenario (when the key forms a sequence of alternate “0”
and “1”), the caused increase in power is 0.25%.
Let’s consider the process of secret information extraction. Figures 4.56 a and b
show the transmission power wave form of a Type-I and a Type-II trojan-infested
chip, respectively, when the stolen key bit transmitted along with the legitimate signal
is “1”, as well as when it is “0”. Similarly, in the Type-II trojan-infected chip, the
difference in the stolen key bit value is reflected as a difference of 120 μW in the
maximum amplitude. Similarly, in the Type-II trojan-infected chip, the difference
in the stolen key bit value is reflected as a 0.4 GHz difference in the frequency.
Both of these differences are well within the margins allowed for process variations
and operating condition fluctuations and would not raise any suspicion. While the
attacker does not know in advance the exact amplitude or frequency levels in each of
the two cases, but the fact that this difference is always present, suffices for extracting
the secret key. All the attacker needs to do is listen to the wireless channel to observe
these two different amplitude or frequency levels which correspond to a stolen key
bit of “1” and a stolen key bit of “0”, respectively. Once these two levels are known,
listening to 56 consecutive transmission blocks reveals a rotated version of the 56 bits
of the encryption key. Using this information, the attacker needs at most 56 attempts
(i.e., all rotations of the extracted 56 bits) to decrypt the transmitted ciphertext.
4.9.2 Basic Methods of Trojan Detection
As seen above, the mechanism through which the two hardware trojans create a leak
of secret information over the wireless channel allows them to evade detection not
only by traditional manufacturing testing but also from previously considered Trojan
detection methods.
Functional, structural, and enhanced testing is considered in work [237]. These
examples of hardware Trojans do not alter the functionality of the digital part of
the circuit. In normal operation, the enhanced scan flip-flops that hold the key bits
are loaded appropriately. Numerous randomly generated functional test vectors are
simulated by these Trojan writers to verify the correctness of the produced ciphertext.
In test mode, the scan chain also operates as expected. To demonstrate that structural
tests do not detect these hardware Trojans, a standard industrial ATPG tool (automatic
test program generation) is used to generate test vectors for all stuck-at and delay
faults in the Trojan-free circuit. These tests are simulated on two Trojan-infested
circuits. As expected, all tests passed. Enhancing the test set with further vectors
that exercise rare events is also ineffective [234], since the hardware Trojans do not
affect the digital functionality. The analog portion is not modified, and therefore it
also passes the traditional specification-based analog/RF test.
System-level tests examining the parameters of the wireless transmission also fail
to expose the hardware Trojans, since the structure added by the leaked information
