424
4 Hardware Trojans in Microcircuits
Table 4.8 Comprehensive attack models
Model
Description
Third-party vendor of
IP-core (3PIP)
SoC developer
Foundry
A
Untrusted IP-core (3PIP)
vendor
Untrusted
Trusted
Trusted
B
Untrusted foundry
Trusted
Trusted
Untrusted
C
Untrusted design tool
Trusted
Untrusted
Trusted
D
Commercial off-the-shelf
component
Untrusted
Untrusted
Untrusted
E
Untrusted designer
Untrusted
Untrusted
Trusted
F
Fabless SoC designer
Untrusted
Trusted
Untrusted
G
Untrusted SoC developer
with trusted IPs
Trusted
Untrusted
Untrusted
In [259], the characteristics of each model from this table are presented.
So, model A is a functional core made by an untrusted third-party vendor. With
semiconductor scaling at very deep submicron levels, more functions including
digital, analog, mixed-signal, and radio frequency functions originally integrated
on a board level are now being placed on a single-chip substrate (i.e., System-onChip or SoC). It is almost impossible for SoC developers to develop all necessary
IP-cores in house, so they have to purchase some third-party proprietary cores (software for which the software’s publisher retains intellectual property rights) that can
contain inserted hardware Trojans. This threat model is very common today as SoC
chips are widely used.
Model B is an untrusted foundry or fabless designer. Fabless designers outsource
the IC fabrication to third-party foundries with advanced process technologies. An
attacker in such foundry has a real possibility of inserting a Trojan into the IC structure
by manipulating the lithographic masks. These Trojans are implemented in the form
of addition, deletion, or partial malicious modification of the IC gates. Since the
semiconductor foundry has access to all layers of the design, a qualified attacker
can inject either untargeted Trojans to produce random failures or targeted Trojans
(after careful reverse engineering) to create intended malfunctions. This is a difficult
situation for reliable IC design companies who not only wish to push performance
to the edge by using offshore state-of-the-art technologies but also want to guarantee
security for critical applications.
As we have previously stated, the model has been discussed and studied
significantly in academia in the last decade.
Model C is an untrusted SoC developer. Since the complexity of SoC design
has increased significantly, more specialized engineers and tools must be involved
during SoC design. The hardware Trojan threats can be from untrusted third-party
proprietary EDA tools or rogue designers (insider threats).
4 Hardware Trojans in Microcircuits
Table 4.8 Comprehensive attack models
Model
Description
Third-party vendor of
IP-core (3PIP)
SoC developer
Foundry
A
Untrusted IP-core (3PIP)
vendor
Untrusted
Trusted
Trusted
B
Untrusted foundry
Trusted
Trusted
Untrusted
C
Untrusted design tool
Trusted
Untrusted
Trusted
D
Commercial off-the-shelf
component
Untrusted
Untrusted
Untrusted
E
Untrusted designer
Untrusted
Untrusted
Trusted
F
Fabless SoC designer
Untrusted
Trusted
Untrusted
G
Untrusted SoC developer
with trusted IPs
Trusted
Untrusted
Untrusted
In [259], the characteristics of each model from this table are presented.
So, model A is a functional core made by an untrusted third-party vendor. With
semiconductor scaling at very deep submicron levels, more functions including
digital, analog, mixed-signal, and radio frequency functions originally integrated
on a board level are now being placed on a single-chip substrate (i.e., System-onChip or SoC). It is almost impossible for SoC developers to develop all necessary
IP-cores in house, so they have to purchase some third-party proprietary cores (software for which the software’s publisher retains intellectual property rights) that can
contain inserted hardware Trojans. This threat model is very common today as SoC
chips are widely used.
Model B is an untrusted foundry or fabless designer. Fabless designers outsource
the IC fabrication to third-party foundries with advanced process technologies. An
attacker in such foundry has a real possibility of inserting a Trojan into the IC structure
by manipulating the lithographic masks. These Trojans are implemented in the form
of addition, deletion, or partial malicious modification of the IC gates. Since the
semiconductor foundry has access to all layers of the design, a qualified attacker
can inject either untargeted Trojans to produce random failures or targeted Trojans
(after careful reverse engineering) to create intended malfunctions. This is a difficult
situation for reliable IC design companies who not only wish to push performance
to the edge by using offshore state-of-the-art technologies but also want to guarantee
security for critical applications.
As we have previously stated, the model has been discussed and studied
significantly in academia in the last decade.
Model C is an untrusted SoC developer. Since the complexity of SoC design
has increased significantly, more specialized engineers and tools must be involved
during SoC design. The hardware Trojan threats can be from untrusted third-party
proprietary EDA tools or rogue designers (insider threats).
