4.11 Analytical Review of Basic Techniques …
417
4.11.2 Basic Trojan Detection Techniques in IC After Being
Manufactured in Mass Production
Here, all detection techniques can be classified into two large major categories:
destructive and non-destructive methods (Fig. 4.68). Destructive methods typically
use destructive reverse-engineering techniques to depackage an IC and obtain images
of each layer in order to reconstruct their active structure and perform design-fortrust validation of the end product. The method of destructive reverse engineering
allows with high degree of accuracy to identify the fact of presence (or absence) of
any malicious modification in the IC, but now this method is expensive and could
take at least a few months to analyze the ICs even of reasonable complexity.
In addition, this method of destructive analysis allows to obtain information
only about this one specific sample of the IC, which is no longer to be used after
verification.
Hence, in general, destructive approaches are considered impractical for Trojan
detection. However, destructive reverse engineering on a limited number of samples
can be attractive in order to obtain the characteristics of a so-called reference model
of the IC. Reputable Trojan hunters Bao et al. [267] propose to adapt a well-studied
theoretical machine-learning method (so-called one-class support vector machine)
to identify Trojan-free ICs using a “golden” reference model.
As discussed above, non-destructive techniques try to authenticate fabricated
ICs from untrusted foundry through specifically developed functional tests or using
various methods for analysis of side-channel signals.
Another approach to analysis is the use of functional tests.
When carrying out a series of special functional tests, an attempt is made to
activate (to start “sleeping” Trojans) by affecting the IC with a number of special
test vectors and comparing the responses with the correct results. While at first
glance this method is similar to standard stages of manufacturing tests for detection
of conventional manufacturing defects using functional/structural/random/standard
patterns, it is totally insufficient for reliable detection of hardware Trojans inserted
in the IC [268]. After all, it was known more than 10 years ago that intruders can
design Trojans that are activated under very rare conditions, so they can go undetected under structural and functional tests during the manufacturing test process.
Reputable Trojan hunter Banga and Hsiao [153] and their industry peers Chakraborty
et al. [140, 158] developed methods of test pattern generation to trigger such rarely
activated nets and improve the possibility of observing the Trojan’s effects from
primary outputs. However, due to the numerous logical states in the modern IC, it
is economically unjustified to enumerate all states of a real design. Additionally,
instead of changing the functionality of the original circuit [269], a Trojan inserted
in the IC can transmit information (e.g., with an antenna integrated in the chip) or
modify the IC specification. Functional tests fail to detect these kinds of Trojans.
Analysis of the information received through the side channels allows detecting
the Trojans embedded in the IC by measuring such parameters as the time delay of the
signal transmission from the IC input to the output [270, 271], a change in dynamic
417
4.11.2 Basic Trojan Detection Techniques in IC After Being
Manufactured in Mass Production
Here, all detection techniques can be classified into two large major categories:
destructive and non-destructive methods (Fig. 4.68). Destructive methods typically
use destructive reverse-engineering techniques to depackage an IC and obtain images
of each layer in order to reconstruct their active structure and perform design-fortrust validation of the end product. The method of destructive reverse engineering
allows with high degree of accuracy to identify the fact of presence (or absence) of
any malicious modification in the IC, but now this method is expensive and could
take at least a few months to analyze the ICs even of reasonable complexity.
In addition, this method of destructive analysis allows to obtain information
only about this one specific sample of the IC, which is no longer to be used after
verification.
Hence, in general, destructive approaches are considered impractical for Trojan
detection. However, destructive reverse engineering on a limited number of samples
can be attractive in order to obtain the characteristics of a so-called reference model
of the IC. Reputable Trojan hunters Bao et al. [267] propose to adapt a well-studied
theoretical machine-learning method (so-called one-class support vector machine)
to identify Trojan-free ICs using a “golden” reference model.
As discussed above, non-destructive techniques try to authenticate fabricated
ICs from untrusted foundry through specifically developed functional tests or using
various methods for analysis of side-channel signals.
Another approach to analysis is the use of functional tests.
When carrying out a series of special functional tests, an attempt is made to
activate (to start “sleeping” Trojans) by affecting the IC with a number of special
test vectors and comparing the responses with the correct results. While at first
glance this method is similar to standard stages of manufacturing tests for detection
of conventional manufacturing defects using functional/structural/random/standard
patterns, it is totally insufficient for reliable detection of hardware Trojans inserted
in the IC [268]. After all, it was known more than 10 years ago that intruders can
design Trojans that are activated under very rare conditions, so they can go undetected under structural and functional tests during the manufacturing test process.
Reputable Trojan hunter Banga and Hsiao [153] and their industry peers Chakraborty
et al. [140, 158] developed methods of test pattern generation to trigger such rarely
activated nets and improve the possibility of observing the Trojan’s effects from
primary outputs. However, due to the numerous logical states in the modern IC, it
is economically unjustified to enumerate all states of a real design. Additionally,
instead of changing the functionality of the original circuit [269], a Trojan inserted
in the IC can transmit information (e.g., with an antenna integrated in the chip) or
modify the IC specification. Functional tests fail to detect these kinds of Trojans.
Analysis of the information received through the side channels allows detecting
the Trojans embedded in the IC by measuring such parameters as the time delay of the
signal transmission from the IC input to the output [270, 271], a change in dynamic
