404
4 Hardware Trojans in Microcircuits
Fig. 4.62 Various trigger conditions for the hardware Trojan inserted in a standard microchip
implemented which can be used in such architectures, cause a leak of program intellectual property items, steal the encryption key of the cryptosystem, and even lead
to system malfunction (Fig. 4.62). The Trojan trigger mechanism makes use of both
the additional instructions being executed by the intruder and the data, being used
by the processor [247].
4.10.1.5 Trojan Trigger Conditions
The simplest circuit-engineering solution of Trojan is an always-on Trojan without
requiring any triggering condition to start malfunctioning. Though causing less overhead, it is likely to get detected during post-manufacturing testing. It can be detected
as a defect (malfunction). To circumvent this, it has been proposed to make the Trojan
trigger condition either controllable externally by an attacker or to use rare conditions
in the internal circuitry to activate the Trojan [248]. Here it is possible to use any
easily perceptible test control signal to disable the hardware Trojan in the test mode.
For example, if the microchip design has a scan chain which is enabled by a special
signal of test control (TC) start, it can be used to disable the hardware Trojan.
Of course, the Trojan trigger conditions can be more complex in the attacked
processor. The technical solution of the “combined” attack proposed in [249] is
interesting. Here, the hardware Trojan serves as a supporting hardware platform for
“software-triggered Trojan.” It means that “loopholes” in the hardware Trojans can
be used by software codes to trigger the hardware Trojan. Theoretically, one of three
options can be used to determine the conditions for triggering a hardware Trojan:
specific sequence of instructions, specific sequence of data, and combinations of
sequences of instructions and data, where the data can be obtained from main memory
or I/O. In this case, the attacker can easily control the process of the hardware Trojan
triggering. At the same time, this process is “flexible,” since many instructions or data
4 Hardware Trojans in Microcircuits
Fig. 4.62 Various trigger conditions for the hardware Trojan inserted in a standard microchip
implemented which can be used in such architectures, cause a leak of program intellectual property items, steal the encryption key of the cryptosystem, and even lead
to system malfunction (Fig. 4.62). The Trojan trigger mechanism makes use of both
the additional instructions being executed by the intruder and the data, being used
by the processor [247].
4.10.1.5 Trojan Trigger Conditions
The simplest circuit-engineering solution of Trojan is an always-on Trojan without
requiring any triggering condition to start malfunctioning. Though causing less overhead, it is likely to get detected during post-manufacturing testing. It can be detected
as a defect (malfunction). To circumvent this, it has been proposed to make the Trojan
trigger condition either controllable externally by an attacker or to use rare conditions
in the internal circuitry to activate the Trojan [248]. Here it is possible to use any
easily perceptible test control signal to disable the hardware Trojan in the test mode.
For example, if the microchip design has a scan chain which is enabled by a special
signal of test control (TC) start, it can be used to disable the hardware Trojan.
Of course, the Trojan trigger conditions can be more complex in the attacked
processor. The technical solution of the “combined” attack proposed in [249] is
interesting. Here, the hardware Trojan serves as a supporting hardware platform for
“software-triggered Trojan.” It means that “loopholes” in the hardware Trojans can
be used by software codes to trigger the hardware Trojan. Theoretically, one of three
options can be used to determine the conditions for triggering a hardware Trojan:
specific sequence of instructions, specific sequence of data, and combinations of
sequences of instructions and data, where the data can be obtained from main memory
or I/O. In this case, the attacker can easily control the process of the hardware Trojan
triggering. At the same time, this process is “flexible,” since many instructions or data
