4.11 Analytical Review of Basic Techniques …
425
Model D is untrusted off-the-shelf components. An increasing number of devices
and systems of commercial and military applications make use of commercial offthe-shelf (COTS) components. COTS refers to a product available off-the-shelf and
not requiring custom development before being put into a system. These components are designed for specific applications. Generally, COTS products are typically
less expensive compared to custom-designed products, readily available, and userfriendly. However, in the case of this type of components, none of the stages of their
development is reliable.
Model E is an untrusted design. This model assumes that the entire IC supply
chain is untrusted except the foundry. What customers know is that the foundry has a
very good reputation and the manufacturing process is reliable, but they do not trust
the design company and are unsure if the design contains any hardware Trojans. For
example, a product can be developed in an unfriendly foreign country. It should be
pointed out that this model may also be applicable to cloned ICs available in the
market. After reverse engineering a safe (i.e., Trojan-free) IC, a counterfeiter may
insert a Trojan into the original design.
Model F is an untrusted sun contractor. This model is a combination of threats
in models A and B. It can be applied to most fabless IC design companies, such
as Qualcomm, Apple, and Xilinx. Such design companies integrate some IP-cores
from third-party vendors into their SoC designs and fabricate these chips in untrusted
third-party foundries.
Model G is an untrusted system integrator and foundry. Some semiconductor
companies also offer both design and fabrication of application-specific integrated
circuit (ASIC). The customers can purchase certain IP-cores for SoC. The chips will
be delivered to customers after fabrication, testing, and packaging. Some companies own fabrication facilities and design teams. Such companies also provide the
specialty foundry services for chip design and manufacturing.
4.11.4.2 Relationships Between Previous Research and Attack Models
A hardware Trojan attack or countermeasures should be applicable to one or more
of the aforementioned attack models/scenarios. These attacks occur at the untrusted
stages of IC fabrication, while the principal countermeasures should be performed
at the design stage. Trojan attacks can be categorized using the abovementioned
attack models. Here we consider only the classification of countermeasure techniques
relevant to their attack models which is most fully presented in [259].
The relationships between countermeasures and attack models are illustrated by
the authors of paper [259] in Fig. 4.68 (by the letters within brackets for each countermeasure). In hardware Trojan detection, presilicon detection techniques are used
to help SoC developers and design engineers to validate third-party IP (3PIP) cores
and their final designs, since hardware Trojans could be added into 3PIP cores by
untrusted IP vendors (Model A), designs by untrusted EDA tools or rogue employees
(Model C), or both (Model E). In addition, presilicon detection techniques can
partially address attacks for Model F. The postsilicon Trojan detection techniques
425
Model D is untrusted off-the-shelf components. An increasing number of devices
and systems of commercial and military applications make use of commercial offthe-shelf (COTS) components. COTS refers to a product available off-the-shelf and
not requiring custom development before being put into a system. These components are designed for specific applications. Generally, COTS products are typically
less expensive compared to custom-designed products, readily available, and userfriendly. However, in the case of this type of components, none of the stages of their
development is reliable.
Model E is an untrusted design. This model assumes that the entire IC supply
chain is untrusted except the foundry. What customers know is that the foundry has a
very good reputation and the manufacturing process is reliable, but they do not trust
the design company and are unsure if the design contains any hardware Trojans. For
example, a product can be developed in an unfriendly foreign country. It should be
pointed out that this model may also be applicable to cloned ICs available in the
market. After reverse engineering a safe (i.e., Trojan-free) IC, a counterfeiter may
insert a Trojan into the original design.
Model F is an untrusted sun contractor. This model is a combination of threats
in models A and B. It can be applied to most fabless IC design companies, such
as Qualcomm, Apple, and Xilinx. Such design companies integrate some IP-cores
from third-party vendors into their SoC designs and fabricate these chips in untrusted
third-party foundries.
Model G is an untrusted system integrator and foundry. Some semiconductor
companies also offer both design and fabrication of application-specific integrated
circuit (ASIC). The customers can purchase certain IP-cores for SoC. The chips will
be delivered to customers after fabrication, testing, and packaging. Some companies own fabrication facilities and design teams. Such companies also provide the
specialty foundry services for chip design and manufacturing.
4.11.4.2 Relationships Between Previous Research and Attack Models
A hardware Trojan attack or countermeasures should be applicable to one or more
of the aforementioned attack models/scenarios. These attacks occur at the untrusted
stages of IC fabrication, while the principal countermeasures should be performed
at the design stage. Trojan attacks can be categorized using the abovementioned
attack models. Here we consider only the classification of countermeasure techniques
relevant to their attack models which is most fully presented in [259].
The relationships between countermeasures and attack models are illustrated by
the authors of paper [259] in Fig. 4.68 (by the letters within brackets for each countermeasure). In hardware Trojan detection, presilicon detection techniques are used
to help SoC developers and design engineers to validate third-party IP (3PIP) cores
and their final designs, since hardware Trojans could be added into 3PIP cores by
untrusted IP vendors (Model A), designs by untrusted EDA tools or rogue employees
(Model C), or both (Model E). In addition, presilicon detection techniques can
partially address attacks for Model F. The postsilicon Trojan detection techniques
