464
5 Methods of Detecting Hardware Trojans in Microcircuits
5.1.16 Methods of Neutralizing Trojans Introduced
into Microcircuits
In [46], authoritative researchers A. Waksman and S. Sethumadhavan present the
approach that helps neutralize the effect of embedded Trojans due to prevention of
the conditions of digital deterministic triggers that can be used to create Trojans.
Here, unreliable data is monitored and used not within its own functional groups,
but only at their specific input and output points. The idea is that the data is encrypted
and hidden in a controlled manner, so that the Trojan’s trigger cannot detect the trigger
condition programmed by the attacker, therefore, the activation of the Trojan will
never occur. The authors examine the following types of embedded Trojans:
(1) Time bomb; (2) Point cheat code-based Trojans; (3) Sequential Trojans.
As demonstrated above, a “countdown bomb” is a simple time controlled trigger
that is activated only after a certain number of time cycles N have been implemented.
The number of such time cycles is usually determined using a counter. If the counter
constantly reboots before reaching the N state, such Trojan will never be activated.
This result can be achieved by periodically artificially rebooting the entire digital
system. In this case, the reset interval shall be shorter than the test period T required
in the framework of the mandatory input or output final functional tests. If an attacker
wants to achieve a bomb countdown activation, such activation should occur within
N time cycles. However, if N < T, the Trojan introduced in the circuit will be forcibly
activated and detected during functional tests.
According to the classification presented by the authors, data-based triggers can
be divided int two large groups: the so-called point cheat codes and sequence cheat
codes. Point triggers are activated if a specific rare value (combination) of the data
transmitted via internal interface is applied. To prevent these rare values from being
supplied to the input of a functional block infected with a Trojan, the rare value
is encoded in such a way that it no longer meets the conditions of the trigger activation. Simple encryption methods include, for example, XOR, PUF, or random
values. This approach is mostily useful for non-computational units, for example,
embedded memory modules. To protect computational units (for example, ALU),
various homomorphic functions proposed by the authors are used. Such homomorphic functions comply with the following basic rule: f (g(x), g(y)) = gfx, y). Here is
an example of a specific homomorphic function: x
2 / = (xy)
2 . If we assume that the
computational function is squaring, the unreliable value of x to be processed will be
multiplied by a random value of y before squaring. To obtain a valid result, the value
obtained by the Trojan from the functional unit shall be divided by y
2 .
The last class of triggers, the so-called sequence cheat codes, is neutralized by
setting up special encrypted false loads. Encryption here is provided by simple data
swapping. If this is not possible, false loads can be entered into the transmitted data
stream. It is necessary to determine the maximum number of n bits, which will then
be used as a valid sequence. After n processed bits, additional false load is used to
avoid the activation of a Trojan.
Précédent

- 483/839

Suivant