4.9 Hardware Trojans in Wireless Cryptographic ICs
397
the authors’ view, as at the date of this book, this is the first attempt to apply such
methods toward hardware Trojan detection in wireless cryptographic ICs.
Thus, the attacks of hardware Trojans targeting the wireless ICs represent a real
threat, they can hack applications where such chips are used. Although these hardware
Trojans openly transmit sensitive information, such as an encryption key, through
an additional structure that is carefully hidden within the limits of legitimate data
transfer, routine manufacturing testing and existing methods of hardware Trojans
detection fail to detect them. Even if this added structure is known only to the attacker,
its explicit presence provides a basis for the hardware Trojan detection method, which
was, in particular, applied to cryptographic ICs. Statistical analysis of various data
transmission parameters for a wireless cryptographic IC can effectively detect the
chips which generate an additional leak of information.
In conclusion, it should be noted that despite the fact that the authors [237]
reviewed only one cryptographic wireless microchip and only two options of hardware Trojans, this work shows the direction of additional research with more complex
cryptographic microchips and with more sophisticated designs of Trojans.
4.10 Techniques for Hardware Trojan Design
Due to the global outsourcing of manufacturing services in other countries, a specific
security problem arises related to the manufacture of integrated circuits (ICs), that
is, the possibility of introducing malicious modifications at the manufacturing stage
when producing chips at an untrusted factory [244]. Such malicious hardware modifications, also referred to as hardware Trojans, can give rise to undesired functional
behavior of a chip, or provide covert channels or back doors through which sensitive
information, e.g., cryptographic keys, can be leaked [245]. These ICs can also become
targets of deliberate manipulations in order to cause poor performance or failures in
the system operation. In addition to violations of functional stability of conventional
consumer electronics, hardware Trojans can lead to disastrous consequences during
the operation of applications with strict requirements for information security, e.g.,
in military structures, communications, and national infrastructure [158].
In this section, we first consider the most well-known methods for designing
hardware Trojans from two perspectives: (1) designing such sequential hardware
Trojans to avoid their detection, based on logical control methods and (2) design
methods at the circuit level to minimize the “fingerprint” of the hardware Trojan in
a covert channel [244]. Consideration will be given to the feasibility of installing
hardware Trojans in SRAM arrays in the topological layout. These aspects correspond to different stages during IC development, i.e., front-end functional design
phase, synthesized gate-level netlist, and GDSII files in the chip foundries. Two case
studies are provided in this chapter to demonstrate the effectiveness of the proposed
techniques and design considerations in two scenarios. Particularly, in case study 1,
we implement RTL-level hardware Trojans in 8051 embedded processor, including
multiple design variations that take into account different hardware vulnerability
Précédent

- 416/839

Suivant