414
4 Hardware Trojans in Microcircuits
typically outsource fabrication to a third-party foundry, purchase third-party IP-cores,
and/or use electronic design automation (EDA) tools from third-party vendors. The
use of services and products of untrusted (and potentially malicious) third parties
increases the security concerns. Currently, there are a number of principal potential
risks of supply chains: hardware Trojan insertion, reverse engineering, IP piracy,
IC tampering, IC cloning, IC overproduction, and so forth. Among these, hardware
Trojans are arguably the biggest concern and have drawn significant attention of
researchers.
Different works of Trojan researchers offer various classifications. For instance,
Karri et al. [16] and Tehranipoor and Wang [260] suggested the classification of
Trojans based on five different attributes: insertion phase, abstraction level, activation
mechanism, effects, and location. Hardware Trojans are designed to be stealthy that is
a major difference from manufacturing defects that have been extensively researched
for decades. Manufacturing defects are unintentional and random, and their behavior
can be reflected with stuck-at fault, delay fault, and so forth. For hardware Trojans, it
is difficult to create one general model that fits all possible types. Additionally, defects
are only produced routinely (occasionally) during the manufacturing process, while
hardware Trojans could be inserted at any phase of the IC development. Hence, the
hardware Trojan problem is more challenging than only detection of manufacturing
defects.
As discussed above, research on hardware Trojans has grown dramatically over
the past decade and is expected to continue. In this section, we consider the main
achievements and failures of prior work, using materials of work [259], the authors
of which have done a thorough job of generalizing and systematizing the analysis of
hardware Trojans in microchips. The fact that the main results and conclusions of
this work mostly coincide with our results and conclusions will convince our readers
that hardware Trojans in microchips are not a myth. But they pose a real threat that
it’s very difficult to resist.
So, since the publication of the first article by Agrawal et al. on hardware Trojans
in 2007, the study of this topic has seen significant progress. To study the potential
risks of hardware Trojans, various models of hardware Trojans have been developed.
Let us recall that in general, a Trojan contains two basic parts: trigger and malicious
circuit (payload) [24]. A Trojan trigger is an optional function that monitors various
signals and/or a series of events in the circuit. The malicious circuit usually monitors
signals from the original (Trojan-free) circuit and signals (states) at the output of the
trigger. Once the trigger detects an expected event or condition, the malicious circuit
(payload) is activated to perform malicious behavior. Since the trigger is expected
to be activated by the intruder under extremely rare conditions, the malicious circuit
remains inactive most of the time. When this malicious circuit is inactive, the IC acts
like a Trojan-free circuit, making it difficult to detect the Trojan.
The research for hardware Trojan design can be classified into four categories
[259], as shown in Fig. 4.67.
Because mechanisms underlying Trojan trigger and malicious circuits determine
the difficulty of activation and detection, this has motivated researchers to explore
and evaluate new types of such triggers and malicious circuits. For instance, [261]
Précédent

- 433/839

Suivant