434
4 Hardware Trojans in Microcircuits
build up a secure system based on untrusted COTS components. The first class of
solutions is to validate a COTS component and make sure it is free of Trojans before
deployment. It is rather challenging to authenticate COTS components because COTS
components are not traceable and their internal detailed design information is usually
unavailable. In most cases, the information available for such components is represented only by official documentation, such as datasheets and specifications. But the
user must make sure that the functions and characteristics of the component exactly
correspond to those specified in the documents. It is possible to perform numerous and
various functional and parametric tests in order to verify whether a COTS component
satisfies all the requirements. However, testing an unknown component is technically
difficult and time-consuming. Additionally, it is impractical to do such an exhaustive
test for a large and complex design. The methods of destructive and non-destructive
reverse engineering can be used to extract a complete netlist and reveal information on the internal structure. Simulations on the generated netlist can accelerate the
validation process. Another way to determine internal properties is structural and
functional analyses which are carried out by connecting to pins. Some functionality
can be identified if the structure has been sufficiently determined by analyzing test
templates in inputs/outputs and model checking [65]. The state of any component
output can also be calculated. If the predicted output is different from its real output,
this mismatch could well be caused by presence of inserted hardware Trojan. The
second approach involves the creation of such a secure architecture that can realize
trusted computations based on untrusted COTS components which can contain hardware Trojans (e.g., the SAFER PATH method [312]). In addition, a number of trustworthy computing methods have been developed to address the issue of an untrusted
third-party IP-core.
4.11.6.2 General Approach to Vulnerability Analysis
As described in above, the existing Trojan detection techniques are not effective
enough. For example, design-for-trust approaches typically require extra circuitry
and thus inevitably lead to an increase in delay and power consumed. Although
many different methods have been developed, developers still need to decide which
countermeasure is more effective for one specific design. The decision to choose a
method is made at the design stage (for example, the inclusion of elements provided
by the design-for-trust method). Information on the most possible hardware Trojans
that can be inserted into the design at certain stages will be very important for developers to improve their designs and incorporate appropriate techniques for detecting
(or preventing) hardware Trojans. However, until today, there has been no comprehensive methodology available to assess the vulnerabilities of a design to hardware
Trojan attacks. It is possible that such methods exist in the closed laboratories of the
secret services, but they are not discussed in public media. Salmani et al. developed
a few of original methodologies to evaluate the testability of internal signals and
determine a circuit’s susceptibility to Trojan insertion at the behavioral level and
4 Hardware Trojans in Microcircuits
build up a secure system based on untrusted COTS components. The first class of
solutions is to validate a COTS component and make sure it is free of Trojans before
deployment. It is rather challenging to authenticate COTS components because COTS
components are not traceable and their internal detailed design information is usually
unavailable. In most cases, the information available for such components is represented only by official documentation, such as datasheets and specifications. But the
user must make sure that the functions and characteristics of the component exactly
correspond to those specified in the documents. It is possible to perform numerous and
various functional and parametric tests in order to verify whether a COTS component
satisfies all the requirements. However, testing an unknown component is technically
difficult and time-consuming. Additionally, it is impractical to do such an exhaustive
test for a large and complex design. The methods of destructive and non-destructive
reverse engineering can be used to extract a complete netlist and reveal information on the internal structure. Simulations on the generated netlist can accelerate the
validation process. Another way to determine internal properties is structural and
functional analyses which are carried out by connecting to pins. Some functionality
can be identified if the structure has been sufficiently determined by analyzing test
templates in inputs/outputs and model checking [65]. The state of any component
output can also be calculated. If the predicted output is different from its real output,
this mismatch could well be caused by presence of inserted hardware Trojan. The
second approach involves the creation of such a secure architecture that can realize
trusted computations based on untrusted COTS components which can contain hardware Trojans (e.g., the SAFER PATH method [312]). In addition, a number of trustworthy computing methods have been developed to address the issue of an untrusted
third-party IP-core.
4.11.6.2 General Approach to Vulnerability Analysis
As described in above, the existing Trojan detection techniques are not effective
enough. For example, design-for-trust approaches typically require extra circuitry
and thus inevitably lead to an increase in delay and power consumed. Although
many different methods have been developed, developers still need to decide which
countermeasure is more effective for one specific design. The decision to choose a
method is made at the design stage (for example, the inclusion of elements provided
by the design-for-trust method). Information on the most possible hardware Trojans
that can be inserted into the design at certain stages will be very important for developers to improve their designs and incorporate appropriate techniques for detecting
(or preventing) hardware Trojans. However, until today, there has been no comprehensive methodology available to assess the vulnerabilities of a design to hardware
Trojan attacks. It is possible that such methods exist in the closed laboratories of the
secret services, but they are not discussed in public media. Salmani et al. developed
a few of original methodologies to evaluate the testability of internal signals and
determine a circuit’s susceptibility to Trojan insertion at the behavioral level and
