4.11 Analytical Review of Basic Techniques …
427
29.81% and 13.66%, respectively. The contribution percentages for these four threat
models are reasonable, because more and more fabless semiconductor companies
need to use third-party IP-cores made by potentially untrusted IP vendors (model
A), third-party design tools (EDA) from untrusted EDA companies (model C), as
well as outsource the IC fabrication to third-party foundries (model B). The remaining
threat models (D, E, and G) are nearly unstudied as of the date of this book published.
However, we argue that all models except for model D can form an integral part of
other models.
The untrusted design model (E) is similar to the untrusted SoC developer model
(C). The only difference is that IP-cores from third-party vendors are trusted in
the untrusted SoC developer model, while third-party IP-cores are considered to be
untrusted for the untrusted design model (E). Since the system integrator is untrusted
for both threat models, the trusted IP-cores in model C can still be modified during
system integration. Actually, these two threat models can be merged and considered
as one threat model. In the model, all design information is available to a trusted
foundry, which provides opportunities to inspect the design and detect malicious
functionality before manufacturing the chips.
Moreover, the untrusted system integrator and foundry model (G) is similar to the
model of commercial off-the-shelf components (D). For the same reason that Trojans
can be potentially inserted during the system integration process at an untrusted SoC
design company, trusted IP-cores are not trusted anymore after the system integration.
Thus, techniques for the model of commercial off-the-shelf components can also be
used for the untrusted system integrator and foundry model. To summarize, it should
be pointed out that among these three unstudied threat models, only the threat model
of commercial off-the-shelf components (D) really deserves more attention. This
topic will be further discussed in one of sections below.
In this section, all publications [259] are classified into three categories: survey
(that summarizes the existing techniques), Trojan structure, and countermeasures.
Figure 4.69a plots the published paper count by year.
The blue curve denotes the overall publications on hardware Trojan issue, which
has gone up steadily since 2007. The publication count grows significantly in 2010,
2011, and 2013. It is also reasonable to exclude survey papers from the total quantity
Paper No.
Excluding survey paper
Overview
Trojan structure
Countermeasures
Year
Co
unt
General trends in Trojan research
Classified trends in Trojan research
Fig. 4.69 Trends in hardware Trojan research [259]
427
29.81% and 13.66%, respectively. The contribution percentages for these four threat
models are reasonable, because more and more fabless semiconductor companies
need to use third-party IP-cores made by potentially untrusted IP vendors (model
A), third-party design tools (EDA) from untrusted EDA companies (model C), as
well as outsource the IC fabrication to third-party foundries (model B). The remaining
threat models (D, E, and G) are nearly unstudied as of the date of this book published.
However, we argue that all models except for model D can form an integral part of
other models.
The untrusted design model (E) is similar to the untrusted SoC developer model
(C). The only difference is that IP-cores from third-party vendors are trusted in
the untrusted SoC developer model, while third-party IP-cores are considered to be
untrusted for the untrusted design model (E). Since the system integrator is untrusted
for both threat models, the trusted IP-cores in model C can still be modified during
system integration. Actually, these two threat models can be merged and considered
as one threat model. In the model, all design information is available to a trusted
foundry, which provides opportunities to inspect the design and detect malicious
functionality before manufacturing the chips.
Moreover, the untrusted system integrator and foundry model (G) is similar to the
model of commercial off-the-shelf components (D). For the same reason that Trojans
can be potentially inserted during the system integration process at an untrusted SoC
design company, trusted IP-cores are not trusted anymore after the system integration.
Thus, techniques for the model of commercial off-the-shelf components can also be
used for the untrusted system integrator and foundry model. To summarize, it should
be pointed out that among these three unstudied threat models, only the threat model
of commercial off-the-shelf components (D) really deserves more attention. This
topic will be further discussed in one of sections below.
In this section, all publications [259] are classified into three categories: survey
(that summarizes the existing techniques), Trojan structure, and countermeasures.
Figure 4.69a plots the published paper count by year.
The blue curve denotes the overall publications on hardware Trojan issue, which
has gone up steadily since 2007. The publication count grows significantly in 2010,
2011, and 2013. It is also reasonable to exclude survey papers from the total quantity
Paper No.
Excluding survey paper
Overview
Trojan structure
Countermeasures
Year
Co
unt
General trends in Trojan research
Classified trends in Trojan research
Fig. 4.69 Trends in hardware Trojan research [259]
