432
4 Hardware Trojans in Microcircuits
impossible to generate a golden design because they are close to the end of the design
phase. Therefore, we can claim that a golden design is definitely not available for
models C, D, E, and G.
A golden IC is a fabricated component with genuine functionality. A golden
IC is required for most postsilicon detection techniques, specifically side-channel
methods. Most side-channel techniques require a golden IC as golden references for
comparing various side-channel information, including delay, power, temperature,
electromagnetic radiation, and so forth. One of requirements for the golden IC determination is that the design sent for fabrication must be trusted. This only occurs
for models B and F. If a golden design is available, a few methods can be able to
create a golden IC. The most simple way is doing a complete reverse engineering
(re-engineering) for a batch of manufactured ICs to identify golden ICs based on
information of golden design. Both non-destructive and destructive techniques of
reverse engineering can be used too.
Non-destructive reverse engineering does not destroy the IC under investigation,
while destructive reverse engineering can ensure a better resolution. Both types of
reverse engineering are an expensive and time-consuming procedure, which incurs
considerable expenses. Another approach is manufacturing a small quantity of ICs in
another foundry that is trusted. These ICs can be considered as golden ICs. However,
the design can be changed if it is fabricated in different foundries because of a different
standard cell library applied. It definitely results in different side-channel signals.
Moreover, even for the same IC design, different foundries use different process
technologies that can lead to variabilities in physical characteristics. Therefore, the
separately fabricated ICs are hard to be used as golden ICs for the analysis of sidechannel signals.
A few Trojan detection techniques without the requirement of the golden model
have been developed by researchers. So, authors [247] proposed a temporal selfreferencing approach that compares the current signature of a chip at two different
time windows to completely eliminate the effect of process noise, but this technique
has a few weaknesses. It only works for sequential Trojans that have different states
in their finite state machines, and changing the Trojan’s state is another challenge
when testing. Finally, Liu et al. [291] utilize on-chip process control monitors to
capture process variations for each IC and then statistically construct a trusted region
for Trojan detection by analyzing side channels. Other experts tried to establish a
relationship among side-channel signals in the IC using gate-level characterization
and then calculated an estimated value of a side-channel signal from other measured
signals. Then, the calculated value was compared with the actual measured value.
Although these techniques eliminate the requirement of golden IC by modeling, the
effectiveness is highly dependent on the accuracy of the model and thus impacts
the confidence level of Trojan detection. Therefore, the golden model is still a great
challenge for detection techniques.
Précédent

- 451/839

Suivant