5.1 Brief Review of Basic Techniques for Detection …
459
the special distributed spectrum technology, can already be analyzed by analyzing
numeric values of the supply current through a third-party channel.
5.1.7 Using Special Bus Architectures Protected
from Trojans
The Trojans that have been introduced into complex hardware can also be detected
using the operating system. Bloom et al. [13] propose an approach in which a simple
hardware security system monitors access from the CPU to the memory data bus and
performs a viability test. The stopwatch starts whenever the tracker detects a specific
pseudo-random memory access procedure initiated by the operating system. If stopwatch time expires, a DoS attack is detected (a denial-of-service attack). In addition,
the operating system periodically checks the activation of memory protection in order
to prevent attacks of “increasing priority.”
Kim et al. [26] propose the use of special bus architecture, protected from Trojans,
for System-on-Chips. Such an architecture can detect the very fact of unauthorized
access to the bus. To prevent DoS attacks, the direct allocation of a bus to one of the
nodes is locked by limiting the maximum bus allocation time. These methods will
be discussed in more detail in the following chapter.
5.1.8 Detection of Trojans in Multi-core Architectures
Another approach to detecting Trojans in multi-core systems was proposed by Mcintrier et al. [34]. Within this approach, the operated software is variable while maintaining functional equivalence. This result can be achieved through the use of different
sets of alternative algorithms, with different versions of software running on several
cores. If one of the software versions matches the condition for activating the installed
Trojan, while activating it, the results of the two calculations will be different. That
way, a Trojan can be detected and isolated at runtime. In fact, this method is a development of the majority data transfer method that has been known for more than
half a century, when the information that is completely matched on two of the three
channels is considered true.
5.1.9 Methods of Identification and Software Isolation
of Introduced Trojans
Another interesting method, the so-called BlueChip approach, proposed by Hicks
et al. [21], is based on the use of additional hardware modules. It is designed to make
459
the special distributed spectrum technology, can already be analyzed by analyzing
numeric values of the supply current through a third-party channel.
5.1.7 Using Special Bus Architectures Protected
from Trojans
The Trojans that have been introduced into complex hardware can also be detected
using the operating system. Bloom et al. [13] propose an approach in which a simple
hardware security system monitors access from the CPU to the memory data bus and
performs a viability test. The stopwatch starts whenever the tracker detects a specific
pseudo-random memory access procedure initiated by the operating system. If stopwatch time expires, a DoS attack is detected (a denial-of-service attack). In addition,
the operating system periodically checks the activation of memory protection in order
to prevent attacks of “increasing priority.”
Kim et al. [26] propose the use of special bus architecture, protected from Trojans,
for System-on-Chips. Such an architecture can detect the very fact of unauthorized
access to the bus. To prevent DoS attacks, the direct allocation of a bus to one of the
nodes is locked by limiting the maximum bus allocation time. These methods will
be discussed in more detail in the following chapter.
5.1.8 Detection of Trojans in Multi-core Architectures
Another approach to detecting Trojans in multi-core systems was proposed by Mcintrier et al. [34]. Within this approach, the operated software is variable while maintaining functional equivalence. This result can be achieved through the use of different
sets of alternative algorithms, with different versions of software running on several
cores. If one of the software versions matches the condition for activating the installed
Trojan, while activating it, the results of the two calculations will be different. That
way, a Trojan can be detected and isolated at runtime. In fact, this method is a development of the majority data transfer method that has been known for more than
half a century, when the information that is completely matched on two of the three
channels is considered true.
5.1.9 Methods of Identification and Software Isolation
of Introduced Trojans
Another interesting method, the so-called BlueChip approach, proposed by Hicks
et al. [21], is based on the use of additional hardware modules. It is designed to make
