4.9 Hardware Trojans in Wireless Cryptographic ICs
393
is hidden within the margins allowed for process variations. To demonstrate this,
we measured the transmission power of 200 genuine (i.e., Trojan-free) chips, 100
chips infested with a Type-I hardware Trojan and 100 chips infested with a TypeII hardware Trojan. All these chips were designed using Monte Carlo SPICE-level
simulation assuming 5% process variations on all circuit parameters. Figure 4.57a
shows a plot of the chip transmission power in the transmitting mode when a “1”
is transmitted by half of these Trojan-free chips, as well as the μ ± 3σ envelope of
the transmission power when a “1” is transmitted by the other half of these Trojanfree chips. Figure 4.57b, c shows changes in the transmission power when a “1” is
transmitted by the Type-I and Type-II Trojan-infested chips, respectively. Evidently,
by analyzing any one of these transmission power plots, it is not possible to distinguish
whether a signal comes from a Trojan-free or a Trojan-infested chip.
Also, the hardware Trojan detection method based on local current traces was
tested [236, 240]. This test strategy detects anomalies introduced by the Trojan in
the currents measured at the power ports and takes into account process and operating
condition variations. The authors demonstrate that their method can detect Trojans of
size as small as 2% of the power grid. In order to implement this method in the design,
the chip needs to be divided into at least 20 power grids with at least 30 uniformly
located power ports. The availability of these power ports is a serious obstacle to
implementing this method. Furthermore, a capable attacker would probably observe
the existence of these power ports and could possibly invent countermeasures to
prevent the injected hardware Trojans from becoming visible through these ports.
In [235], the authors use global power consumption traces to find the difference
between Trojan-free and Trojan-infested chips. The method employs statistical analysis of the eigenvalue spectrum and can effectively detect hardware Trojans occupying 0.12% of the total circuit area, assuming process variation in the order of 5%.
But when the hardware Trojan area is reduced to only 0.01% and the process variation is increased to 7.5%, false alarms start to appear. Considering the very low area
overhead of the hardware Trojans (0.02%) and based on the limitations outlined in
[235], it is unlikely that statistical analysis of the total power consumption will detect
them. Indeed, even when this method is applied to the power traces of the digital
part only (mixed-signal SoCs typically have separate power ports for the analog and
the digital parts), wherein the hardware Trojans are hidden, it was not possible to
effectively distinguish between Trojan-free and Trojan-infested chips in any eigenvalue sub-space. Nevertheless, as mentioned in [235], other parameters may still
prove effective. In fact, the solution used in the following section employs a similar
statistical analysis of the wireless transmission power.
A similar statistical method utilizes path delay fingerprints to differentiate Trojanfree from Trojan-infested chips [236]. While the experimental examples of hardware
Trojans under consideration add some delay to a small number of paths in the digital
part of the circuit, the impact is too small to be observed. Even if those paths related to
the encryption key are checked, the complexity of the pipelined encryption circuitry
provides enough margin to hide the added delay. To verify this, the Trojan detection
based on path delay method was applied assuming process variations in the range of
Précédent

- 412/839

Suivant