460
5 Methods of Detecting Hardware Trojans in Microcircuits
andy hardware Trojans installed by an intruder at the design stage harmless during
functioning.
Trojans are artificially isolated by replacing “suspicious” circuits with their software emulation. Detection of such suspicious circuits is performed by identifying
all unused contours in the circuit—a method that allows you to monitor the activity
of the specific contour during functional testing of the microcircuit. If a part of the
contour remains unused during the entire test period, it is considered that such a part
of the circuit can relate to the contour of the Trojan (which, by definition, should not
be detected during the functional tests and therefore remains inactive).
Vaksman and Setkhumadkhavan [45] present another unique approach to combat
Trojans in the process of execution, especially effective for microprocessors. The
assumption is that the malicious function is implemented during the development
phase. Within the framework of the approach, the following initial conditions were
used:
(1) The number of malicious developers is small;
(2) The activities of malicious developers go unnoticed;
(3) Attackers need new resources to bypass the security system;
(4) The protective system is activated by a trigger;
(5) ROMs programmed at the design stage contains correct data (microcode).
Two types of workarounds perform the function of a Trojan model: the so-called
emitter (data transmission) and the corrupter (data change). The second type is
extremely difficult to detect, since their operations are often difficult to distinguish
from normal operations. The proposed measure to prevent hardware bypass is to use
an additional special SoC monitoring system consisting of four elements: a predictor,
a reacting device, a target, and a monitor.
Here, a Trojan is detected if the functioning result of the unit in question does not
match the prediction results of the predictor (template). The detection principle is
based on a simple and logical assumption that the tracked device never connects to
the tracking one; therefore, the intruder.
5.1.10 Application of an Additional Scan Chain
Salmani et al. [43] used special scan chains to increase the probability of detecting
hardware Trojans. The device they intended to use for testing integrated circuits is
usually not related to a particular microcircuit design. The approach involves the use
of an original technical solution in terms location of scan chains over the entire area
of a microcircuit, so that specific areas of the chip can be specifically activated (or
deactivated) during functional testing.
This is supposed to lead to the detection of signs of Trojan activity. It has been
shown [43] that experimental trials actually demonstrate a partial increase in the
activity of Trojans by a factor.
Précédent

- 479/839

Suivant