4.10 Techniques for Hardware Trojan Design
401
on both the first counter state and rare internal events. A particular example is
shown in Fig. 4.60c: whenever the first counter achieves its maximum value of
2k1 − 1, if both signals p and q happen to be at their rare value of logic 1, the
second counter will be updated.
(4) FSM-based hardware Trojan: The counter-based hardware Trojans can be
generalized to FSM-based Trojans, which contain a sequential and combinational part, with the inputs being derived from rare circuit conditions. The
advantage of the FSM-based hardware Trojans is that they can be designed in
such a way that they can reuse both combinational logic and flip-flops (FF)
of the original circuit for FSM hosting. Moreover, unlike counters which are
unidirectional, the FSM-based Trojan can have state transitions leading back
to the initial state, thus causing the final Trojan state to be reached only if the
entire state sequence is satisfied in consecutive clock cycles.
4.10.1.2 Expected Time-to-Trigger
The time it takes for the inserted Trojan to get activated (time-to-trigger) is not
deterministic (except for free-running counter whose trigger is independent of the
circuit condition) because the working load of the IC can vary. It depends on the
actual Boolean logic used as state transition function, which is performed on the
basis of the actual sequence of input vectors applied to the circuit.
To estimate the expected time of Trojan activation T mean , it is understood that the
Trojan passes through a sequence of states S 1 , S 2 … S N before getting activated, as
shown in Fig. 4.61. By assuming that the probability of the Trojan state transition
from state S. — v S. is given by r 1 < i< (N + 1), where N = 2 k − 2 i k is the number
of state elements. This is essentially a Markov process, where r depends only on the
present state £ g−1 . For simplicity, assume that the inactive Trojan stays at its present
state for all input state space conditions except the unique condition that causes a
state transition. Once in state S, the probability of the hardware Trojan staying in
state S is 1 − r. Hence, on average, the number of cycles when the Trojan spends in
state S is
Fig. 4.61 State diagram of a sequential hardware Trojan with sequential and combinational logic
sharing with original circuit
Précédent

- 420/839

Suivant