4.9 Hardware Trojans in Wireless Cryptographic ICs
395
5% but it was unable to identify the aggregates of Trojan-free and Trojan-infested
chips.
To extract a stolen key for an attacker, the hardware Trojan must add some form of
changes to the transmitted signal. Typically, these changes correspond to an increase
in the transmission amplitude or frequency, when the bit of the stolen key is 1. While
the structure added to the transmitted signal for the attacker to extract the stolen key
leaves individual transmissions within the acceptable specification boundaries, it
enables the possibility that such hardware Trojans can be detected through statistical
analysis of the transmission parameters.
To demonstrate this principle, as a measurement, the authors [237] used the total
transmission power for broadcasting one block of data (64 bits). For 100 Type-I
Trojan-infected, 100 Type-II Trojan-infected, and half of the 200 Trojan-free circuit
instances which are assessed via Monte Carlo simulation of SPICE-level with 5%
process variations. The total transmission power is measured when transmitting each
of six randomly selected blocks (the same for all circuits). Of course, the Trojaninfested chips also leak one key bit during each of six transmissions, half of which
are set to “1”. All six measurements for all genuine and all Trojan-infested chips
are within the acceptable specification range. Even when a set of three chips are
projected on the six-dimensional space of these measurements, it is impossible to
distinguish them since they fall upon each other.
Though of course, it is difficult to represent this by a plot in six dimensions,
Fig. 4.58a shows a projection of three sets on three of these dimensions. Evidently,
separating the eigenvalues from the Trojan-infested sets in this space is not possible.
It could be argued that the situation is similar for any other subset of three
measurements.
However, running a principal component analysis (PCA) on these measurements
reveals that the structure of the genuine chip data is different than the structure
of the Trojan-infested chip data [241]. Figure 4.58b shows a projection of three
sets on three principal components of the data, clearly revealing that they are separable in this space. Therefore, the trusted boundary is defined as a simple minimum
volume enclosing ellipsoid (http://www.seas.upenn.edu/~nima/papers/Mim_vol_ell
ipse.pdf) which encompasses a set of “genuine” chips. Then, any chip whose footprint on the space of the selected three principal components does not fall within the
trusted boundary will be discarded as suspicious. In the present example, this method
detects all Type-I and Type-II Trojan-infested chips without inadvertently discarding
any genuine chips. To verify this last moment, the authors projected the values of
the remaining 100 Trojan-free circuit instances onto the space of the selected three
principal components, and none of them didn’t fall within the shown ellipsoid.
Therefore, the authors [237] concluded that the statistical analysis is effective with
accurate determination of the cause. The attacker’s arsenal includes the ability to pick
the structure of the leaked information and the ability to hide the effect of the hardware Trojan within the allowed tolerances. On the other hand, the defender’s arsenal
includes the ability to select various measurement methods and use the process of
statistical analysis. Given the small number of transmission parameters (or combinations thereof) wherein the attacker can hide the added structure, as well as the large
395
5% but it was unable to identify the aggregates of Trojan-free and Trojan-infested
chips.
To extract a stolen key for an attacker, the hardware Trojan must add some form of
changes to the transmitted signal. Typically, these changes correspond to an increase
in the transmission amplitude or frequency, when the bit of the stolen key is 1. While
the structure added to the transmitted signal for the attacker to extract the stolen key
leaves individual transmissions within the acceptable specification boundaries, it
enables the possibility that such hardware Trojans can be detected through statistical
analysis of the transmission parameters.
To demonstrate this principle, as a measurement, the authors [237] used the total
transmission power for broadcasting one block of data (64 bits). For 100 Type-I
Trojan-infected, 100 Type-II Trojan-infected, and half of the 200 Trojan-free circuit
instances which are assessed via Monte Carlo simulation of SPICE-level with 5%
process variations. The total transmission power is measured when transmitting each
of six randomly selected blocks (the same for all circuits). Of course, the Trojaninfested chips also leak one key bit during each of six transmissions, half of which
are set to “1”. All six measurements for all genuine and all Trojan-infested chips
are within the acceptable specification range. Even when a set of three chips are
projected on the six-dimensional space of these measurements, it is impossible to
distinguish them since they fall upon each other.
Though of course, it is difficult to represent this by a plot in six dimensions,
Fig. 4.58a shows a projection of three sets on three of these dimensions. Evidently,
separating the eigenvalues from the Trojan-infested sets in this space is not possible.
It could be argued that the situation is similar for any other subset of three
measurements.
However, running a principal component analysis (PCA) on these measurements
reveals that the structure of the genuine chip data is different than the structure
of the Trojan-infested chip data [241]. Figure 4.58b shows a projection of three
sets on three principal components of the data, clearly revealing that they are separable in this space. Therefore, the trusted boundary is defined as a simple minimum
volume enclosing ellipsoid (http://www.seas.upenn.edu/~nima/papers/Mim_vol_ell
ipse.pdf) which encompasses a set of “genuine” chips. Then, any chip whose footprint on the space of the selected three principal components does not fall within the
trusted boundary will be discarded as suspicious. In the present example, this method
detects all Type-I and Type-II Trojan-infested chips without inadvertently discarding
any genuine chips. To verify this last moment, the authors projected the values of
the remaining 100 Trojan-free circuit instances onto the space of the selected three
principal components, and none of them didn’t fall within the shown ellipsoid.
Therefore, the authors [237] concluded that the statistical analysis is effective with
accurate determination of the cause. The attacker’s arsenal includes the ability to pick
the structure of the leaked information and the ability to hide the effect of the hardware Trojan within the allowed tolerances. On the other hand, the defender’s arsenal
includes the ability to select various measurement methods and use the process of
statistical analysis. Given the small number of transmission parameters (or combinations thereof) wherein the attacker can hide the added structure, as well as the large
