4.10 Techniques for Hardware Trojan Design
403
Table 4.4 Area/power overhead of sequential hardware Trojans of same functionality but varying
implementations
Design/Overhead
Area (%)
Power (%)
Sequential (%)
Combinational (%)
Overall (%)
Original circuit with
hardware Trojan 1
8.1
4.3
5.4
3.5
Original circuit with
hardware Trojan 2
0
3.4
2.3
1.2
Original circuit with
hardware Trojan 3
0
0.8
0.6
0.4
hardware Trojan. Such sequential elements sharing benefits the attackers in both
minimizing the area and power overhead, since only the next state logic is modified,
as well as in protecting the hardware Trojan from approaches based on formal logic
verification. To further reduce the area/power overhead, the Trojan can be carefully
designed to reuse the combinational logic of the original circuit. For example, the
hardware Trojan state machine in Fig. 4.61 reuses the transition conditions of the
original FSM, whose consecutive occurrence is an extremely rare event in state S.
Table 4.4 demonstrates the area/power overhead due to a sequential Trojan with the
same functionality yet different implementations. In particular, the hardware Trojan
of type 1 is implemented with extra state elements; the hardware Trojan of type 2
reuses the existing X-states without sharing the next state logic; and the hardware
Trojan of type 3 reuses both state elements and next stage logic, by exploiting existing
rare conditions in the combinational logic. For example, in a microprocessor, it is not
difficult to find such rare conditions in the memory controller or arithmetic logical
unit (ALU). The power overhead is mainly caused by the leakage power of the
sequential hardware Trojans, because dynamic power due to the hardware Trojans
is negligible due to their low switching activity.
4.10.1.4 Case Studies of Design of Hardware Trojans Which Can Be
Used in Software of the Embedded Processor
Hardware Trojans can be designed to support general attacks with variable payload
effect defined by the malicious software. However, such Trojans are more suitable for general-purpose processors or complex embedded processors that already
have security features supported with relevant hardware, where various attacks can
be performed based on corrupting the security features (e.g., privacy mechanism)
through the Trojan-induced “back door.” In work [244], as a study subject, the authors
chose a simple 8051 microcontroller without any security features and dedicated to
perform an encryption function. Therefore, the authors focus on designing practical
Trojan attacks which both exploit the features of a processor and explore possible
vulnerabilities of an encryption system. In particular, the hardware Trojans were
Précédent

- 422/839

Suivant