4.11 Analytical Review of Basic Techniques …
423
integration for split manufacturing. During the 3D integration, a design is split into
two tiers fabricated by different foundries. One tier is stacked on the top of another
tier and the upper tiers are connected with vertical interconnects called TSVs. Given
the manufacturing barriers preventing the industrial use of 3D technique, the 2Dand 2.5D-based split manufacturing techniques are more realistic today. That’s why
Vaidyanathan et al. [303] demonstrated the feasibility of split fabrication after application of metal interconnection level (M1) to the test chips and evaluated the IC
performance. Although this method allows to hide all intercell interconnections and
can significantly complicate the analysis of IC structure, it leads to high manufacturing costs. Additionally, several design techniques have been proposed to enhance a
design’s security with split manufacturing. For example, Imeson et al. [307] present
a special program for identifying critical conductors included in the trusted level
(BEOL) to ensure the security when split at a higher layer. However, the inclusion of
a large number of interconnects in this level adversely affects the speed and power
of the IC.
The method of obfuscated built-in self-authentication (OBISA), which involves
insertion of various dummy elements to the original structure of the IC, can also
be used to increase the complexity of introducing a hardware Trojan during split
manufacturing [308].
4.11.4 Determination of Trojan Attack Models
4.11.4.1 Comprehensive Attack Models
Developing and using precise attack models are critical for achieving progress in
researching the ways to ensure protection against hardware Trojans. By analyzing
certain attack models, one can determine what’s been covered by existing work and
what still needs to be addressed. For example, it makes no practical sense to develop
an unrealistic (impractical) Trojan or countermeasures that are not suitable for a
real useful model of a chip. Hence, before developing a new hardware Trojan or
countermeasure relevant to it, the attacker has to accurately describe the target attack
model. Attack models can act as a guide for those new to hardware Trojans, but
can also be useful even for the more experienced Trojan hunters. Next, we describe
various comprehensive attack models that can be used to understand the current state
of research work, determine research trends, and provide insight for new directions
to develop both the hardware Trojans themselves and countermeasures.
As discussed above, hardware Trojans can be injected at any phase during design
or fabrication by different intruders, which causes the existence of different threat
models. Typically, the entire design and fabrication procedure of an SoC chip can be
divided into three main phases: minimal functional core development, SoC development, and fabrication. Therefore, the potential intruders can be three types of
companies: third-party functional IP-core vendors, SoC developers, and foundries.
Table 4.8 illustrates seven possible attack models (of hardware Trojan insertion).
423
integration for split manufacturing. During the 3D integration, a design is split into
two tiers fabricated by different foundries. One tier is stacked on the top of another
tier and the upper tiers are connected with vertical interconnects called TSVs. Given
the manufacturing barriers preventing the industrial use of 3D technique, the 2Dand 2.5D-based split manufacturing techniques are more realistic today. That’s why
Vaidyanathan et al. [303] demonstrated the feasibility of split fabrication after application of metal interconnection level (M1) to the test chips and evaluated the IC
performance. Although this method allows to hide all intercell interconnections and
can significantly complicate the analysis of IC structure, it leads to high manufacturing costs. Additionally, several design techniques have been proposed to enhance a
design’s security with split manufacturing. For example, Imeson et al. [307] present
a special program for identifying critical conductors included in the trusted level
(BEOL) to ensure the security when split at a higher layer. However, the inclusion of
a large number of interconnects in this level adversely affects the speed and power
of the IC.
The method of obfuscated built-in self-authentication (OBISA), which involves
insertion of various dummy elements to the original structure of the IC, can also
be used to increase the complexity of introducing a hardware Trojan during split
manufacturing [308].
4.11.4 Determination of Trojan Attack Models
4.11.4.1 Comprehensive Attack Models
Developing and using precise attack models are critical for achieving progress in
researching the ways to ensure protection against hardware Trojans. By analyzing
certain attack models, one can determine what’s been covered by existing work and
what still needs to be addressed. For example, it makes no practical sense to develop
an unrealistic (impractical) Trojan or countermeasures that are not suitable for a
real useful model of a chip. Hence, before developing a new hardware Trojan or
countermeasure relevant to it, the attacker has to accurately describe the target attack
model. Attack models can act as a guide for those new to hardware Trojans, but
can also be useful even for the more experienced Trojan hunters. Next, we describe
various comprehensive attack models that can be used to understand the current state
of research work, determine research trends, and provide insight for new directions
to develop both the hardware Trojans themselves and countermeasures.
As discussed above, hardware Trojans can be injected at any phase during design
or fabrication by different intruders, which causes the existence of different threat
models. Typically, the entire design and fabrication procedure of an SoC chip can be
divided into three main phases: minimal functional core development, SoC development, and fabrication. Therefore, the potential intruders can be three types of
companies: third-party functional IP-core vendors, SoC developers, and foundries.
Table 4.8 illustrates seven possible attack models (of hardware Trojan insertion).
