422
4 Hardware Trojans in Microcircuits
design. The methods of Trojan detection and recovery at runtime acting as “the last
line of defense” are required especially for microchips of mission-critical application
(military and space). Some papers of Trojan hunters describe a distributed software
scheduling protocol to achieve a Trojan-activation-tolerant trustworthy computing
system in a multi-core processor [300, 290]. Concurrent error detection (CED) techniques can be adapted to detect so-called malicious outputs generated by the Trojans
that have been inserted in the system [301, 71]. In addition, Reece et al. [302] and
Rajendran et al. [71] propose to use a diverse set of third-party purchased IP (3PIP)
elements to prevent Trojan’s attack. In particular, the technique proposed by Reece
et al. [302] involves the circuit integrity verification via comparison of a few such
third-party elements (3PIP) with another untrusted design of the IC performing a
similar function. A bit more complicated method is proposed by reputable “Trojan
hunters” [71]: This method uses the restriction of operation distribution between
the gates made by different IC manufacturers to prevent collusions between several
manufacturers in order to carry out malicious acts. To study the mechanism of this
interesting method of dealing with hardware Trojans in chips, the authors recommend
readers to refer to the quoted source—they will not be disappointed.
Finally, in order to put such design-for-trust methods into practice that require
additional gates to be added to the IC design at the design stage, the maximum value
of the IC area and performance limitations are the main difficulties. As the size of a
circuit increases, the number of such nets/gates with low controllability/observability
will increase the complexity of data processing and reduce the IC productivity. Thus,
the design-for-trust techniques for facilitating Trojan detection are still difficult to
apply to “large” circuits that contain millions of gates. As noted above, the preventive design-for-trust techniques need to insert additional gates (logic obfuscation)
or modify the original standard cells (camouflaging), which could degrade the chip
performance significantly and affect their acceptability in high-performance equipment. In addition, it is expressly understood that the use of abovementioned additional
functional filler cells also increases power leakage.
Split manufacturing for trust. When implementing one of projects DARPA in
2011, split manufacturing has been proposed as an approach to enable the use of stateof-the-art semiconductor foundries while minimizing the risks to an IC design. This
method involves the project division into two stages: FEOL (formation of transistor
structures on a semiconductor wafer) and BEOL (formation of the interconnections
and interlayer wiring) portions for fabrication by different foundries. An untrusted
foundry (unverified previously) performs higher cost stage of FEOL, and then wafers
are transferred to a trusted foundry for lower cost stage of BEOL. The untrusted
foundry does not have the access to the layers in BEOL and thus cannot identify the
“safe” places within a circuit to insert Trojans.
Existing split manufacturing processes rely on either 2D integration [55, 303,
304], 2.5D integration [Xie et al. 305], or 3D integration [306]. The 2.5D integration first splits a design into two chips fabricated by the untrusted foundry and then
inserts a silicon interposer containing interchip connections between the chip and
package substrate [305]. Therefore, a portion of interconnections could be hidden in
the interposer that is fabricated in the trusted foundry. In essence, it is a variant of 2D
Précédent

- 441/839

Suivant