398
4 Hardware Trojans in Microcircuits
to cause system malfunctions and information leakage. Case study 2 considers the
design techniques to mount Trojans in gate-level netlists hardened by a ring oscillator
network and demonstrate the Trojans’ ability to bypass detection of the hardening
mechanism.
In particular, this chapter presents a novel approach to the design of hardware
Trojans in an embedded processor that target covert channels of secret information
leak from the processor [244]. Such hardware Trojans can be triggered by any intruder
who makes relevant modifications in the applied operating software or input data. In
this case, secret information can be leaked either through standard processor ports
as logic (digital) values or through side channels (e.g., supply current).
Today there are known innovative approaches to designing and placing hardware
Trojans in a gate-level circuit netlist in order to effectively evade the existing protection mechanisms. It is possible to show how “smart” design of Trojan trigger/payload
circuits can lead to ultra-low delay/power overhead, thus bypassing the defence
mechanisms based on analysis of side channels (back doors).
A detailed systematization of hardware Trojans and their detection mechanisms
is considered above and presented in [17]. A common classification of hardware
Trojans [140, 246] is based on the activation mechanism (referred to as Trojan
trigger) and the effect on the circuit functionality (referred to as Trojan payload).
Hardware Trojans can be both combinationally and sequentially triggered. Typically,
an intruder chooses an extremely rare activation condition so that it is highly unlikely
for the hardware Trojan to trigger during conventional manufacturing tests. On the
other hand, sequentially triggered hardware Trojans (so-called “time bombs”) are
activated by the occurrence of a sequence of rare events or after a period of continuous
operation. The output of the Trojan circuit can maliciously affect the functionality
of the circuit by changing the logic values at its internal nodes (payload).
Other known types of Trojan Horses with passive payload are employed to organize a leak of the secret key used in cryptographic hardware by aiding in side-channel
attacks. Such classification of hardware Trojans designed for information leakage is
presented in [245].
4.10.1 Design of Sequential Hardware Trojans
To prevent hardware Trojans from being detected during conventional postsilicon
validation procedures, researchers suppose that “smart” attackers design hardware
Trojans which are stealthy in nature. Typically, attackers insert such hardware Trojans
which can be triggered only in certain rare conditions. Hardware Trojan circuits can
either be combinational or sequential [158]. Combinational hardware Trojans are
triggered on the occurrence of rare logic values in one or more internal nodes, while
a sequential hardware Trojan is triggered after a sequence of rare events during a long
period of operation, acting as a time bomb. Generally, sequential hardware Trojans
can be designed to be exponentially harder to detect than combinational hardware
4 Hardware Trojans in Microcircuits
to cause system malfunctions and information leakage. Case study 2 considers the
design techniques to mount Trojans in gate-level netlists hardened by a ring oscillator
network and demonstrate the Trojans’ ability to bypass detection of the hardening
mechanism.
In particular, this chapter presents a novel approach to the design of hardware
Trojans in an embedded processor that target covert channels of secret information
leak from the processor [244]. Such hardware Trojans can be triggered by any intruder
who makes relevant modifications in the applied operating software or input data. In
this case, secret information can be leaked either through standard processor ports
as logic (digital) values or through side channels (e.g., supply current).
Today there are known innovative approaches to designing and placing hardware
Trojans in a gate-level circuit netlist in order to effectively evade the existing protection mechanisms. It is possible to show how “smart” design of Trojan trigger/payload
circuits can lead to ultra-low delay/power overhead, thus bypassing the defence
mechanisms based on analysis of side channels (back doors).
A detailed systematization of hardware Trojans and their detection mechanisms
is considered above and presented in [17]. A common classification of hardware
Trojans [140, 246] is based on the activation mechanism (referred to as Trojan
trigger) and the effect on the circuit functionality (referred to as Trojan payload).
Hardware Trojans can be both combinationally and sequentially triggered. Typically,
an intruder chooses an extremely rare activation condition so that it is highly unlikely
for the hardware Trojan to trigger during conventional manufacturing tests. On the
other hand, sequentially triggered hardware Trojans (so-called “time bombs”) are
activated by the occurrence of a sequence of rare events or after a period of continuous
operation. The output of the Trojan circuit can maliciously affect the functionality
of the circuit by changing the logic values at its internal nodes (payload).
Other known types of Trojan Horses with passive payload are employed to organize a leak of the secret key used in cryptographic hardware by aiding in side-channel
attacks. Such classification of hardware Trojans designed for information leakage is
presented in [245].
4.10.1 Design of Sequential Hardware Trojans
To prevent hardware Trojans from being detected during conventional postsilicon
validation procedures, researchers suppose that “smart” attackers design hardware
Trojans which are stealthy in nature. Typically, attackers insert such hardware Trojans
which can be triggered only in certain rare conditions. Hardware Trojan circuits can
either be combinational or sequential [158]. Combinational hardware Trojans are
triggered on the occurrence of rare logic values in one or more internal nodes, while
a sequential hardware Trojan is triggered after a sequence of rare events during a long
period of operation, acting as a time bomb. Generally, sequential hardware Trojans
can be designed to be exponentially harder to detect than combinational hardware
