420
4 Hardware Trojans in Microcircuits
to multiplex two outputs of a dynamic flip-flop (DFF), Q and Q, through a 2-to-1
multiplexer and select either of them. Obviously, this solution extends the state space
of the IC design and significantly increases the possibility of exciting a “sleeping”
Trojan, showing its effects at the microcircuit outputs and subsequent successful
detection of the embedded Trojan [153]. All these approaches are beneficial not only
to functional-test-based detection techniques but also to side-channel-based methods
that need partial activation of Trojan circuitry.
Facilitation of side-channel signal analysis. A number of design methods have
been developed by experts to increase the sensitivity to side-channel signals. So,
Salmani and Tehranipoor [284] proposed to minimize background side-channel
signals by localizing switching activities within one region while minimizing them in
other regions through a scan-cell reordering technique. Additionally, in some cases,
the structures or sensors can be implemented in the IC to provide a higher detection sensitivity compared to conventional measurements. So, ring oscillators [255],
shadow registers [173], and delay elements [285] are located on certain IC nets
for path delay measurements. The use of ring oscillator sensors [286] and transient
current sensors [287, 288] can improve sensitivity to voltage and current fluctuations
caused by Trojans.
Besides, integration of process variation sensors in the IC [289, 290, 291] can
ensure quick calibration of any adequate model (or measurement tool) and minimize
the noise induced by manufacturing variations.
Runtime monitoring. As triggering all types and sizes of Trojans during presilicon
and postsilicon tests imposes certain challenges, special analysis tools can significantly increase the level of consumer trust with respect to resistance of microchips
made by a foreign foundry to hardware Trojan attacks. To implement such a complex
task, both already known and any new methods can be used, including additional
on-chip structures designed to track the behavior of suspicious components in the IC
[157, 292]. Also, for this purpose, methods for analysis of IC operating conditions,
such as transient power [287, 293] and temperature [273], can be applied. Such test
structures can either promptly disable the Trojan-infected areas of the IC or “bypass”
such ICs when detecting any unexplained deviations in the system in order to ensure
reliable operation of critical equipment, even in those cases if it leads to a certain
loss of efficiency. Finally, the “Trojan hunters“ [294] propose to use on-chip analog
neural network inserted in the protected IC that can be trained to distinguish trusted
from untrusted circuit functionality based on experimental measurements obtained
via on-chip measurement acquisition sensors specially inserted in the protected IC.
Another type of approach to the design-for-trust method in the literature is
presented by various so-called preventive approaches that reduce the probability
of hardware Trojan insertion into the IC by attackers. As a rule, to insert such Trojan
(usually the attacker is informed about this action by the customers—secret services
or criminal groups), the attackers themselves need to have a good look through the
project function. It should be noted that usually attackers who do not have direct
access to the technical project at the design stage usually identify the functions of the
circuit by using re-engineering processes (reverse engineering), which we examined
in detail in one of the chapters of this encyclopedia.
4 Hardware Trojans in Microcircuits
to multiplex two outputs of a dynamic flip-flop (DFF), Q and Q, through a 2-to-1
multiplexer and select either of them. Obviously, this solution extends the state space
of the IC design and significantly increases the possibility of exciting a “sleeping”
Trojan, showing its effects at the microcircuit outputs and subsequent successful
detection of the embedded Trojan [153]. All these approaches are beneficial not only
to functional-test-based detection techniques but also to side-channel-based methods
that need partial activation of Trojan circuitry.
Facilitation of side-channel signal analysis. A number of design methods have
been developed by experts to increase the sensitivity to side-channel signals. So,
Salmani and Tehranipoor [284] proposed to minimize background side-channel
signals by localizing switching activities within one region while minimizing them in
other regions through a scan-cell reordering technique. Additionally, in some cases,
the structures or sensors can be implemented in the IC to provide a higher detection sensitivity compared to conventional measurements. So, ring oscillators [255],
shadow registers [173], and delay elements [285] are located on certain IC nets
for path delay measurements. The use of ring oscillator sensors [286] and transient
current sensors [287, 288] can improve sensitivity to voltage and current fluctuations
caused by Trojans.
Besides, integration of process variation sensors in the IC [289, 290, 291] can
ensure quick calibration of any adequate model (or measurement tool) and minimize
the noise induced by manufacturing variations.
Runtime monitoring. As triggering all types and sizes of Trojans during presilicon
and postsilicon tests imposes certain challenges, special analysis tools can significantly increase the level of consumer trust with respect to resistance of microchips
made by a foreign foundry to hardware Trojan attacks. To implement such a complex
task, both already known and any new methods can be used, including additional
on-chip structures designed to track the behavior of suspicious components in the IC
[157, 292]. Also, for this purpose, methods for analysis of IC operating conditions,
such as transient power [287, 293] and temperature [273], can be applied. Such test
structures can either promptly disable the Trojan-infected areas of the IC or “bypass”
such ICs when detecting any unexplained deviations in the system in order to ensure
reliable operation of critical equipment, even in those cases if it leads to a certain
loss of efficiency. Finally, the “Trojan hunters“ [294] propose to use on-chip analog
neural network inserted in the protected IC that can be trained to distinguish trusted
from untrusted circuit functionality based on experimental measurements obtained
via on-chip measurement acquisition sensors specially inserted in the protected IC.
Another type of approach to the design-for-trust method in the literature is
presented by various so-called preventive approaches that reduce the probability
of hardware Trojan insertion into the IC by attackers. As a rule, to insert such Trojan
(usually the attacker is informed about this action by the customers—secret services
or criminal groups), the attackers themselves need to have a good look through the
project function. It should be noted that usually attackers who do not have direct
access to the technical project at the design stage usually identify the functions of the
circuit by using re-engineering processes (reverse engineering), which we examined
in detail in one of the chapters of this encyclopedia.
