Stealthy dopant-level hardware Trojans: extended version

Stealthy dopant-level hardware Trojans: extended version
复制标题

DOI:
10.1007/s13389-013-0068-0
复制
发表时间:
2014-04-01
影响因子:
1.9
通讯作者:
Burleson, Wayne P.
Burleson, Wayne P.
中科院分区:
计算机科学4区
文献类型:
--
作者:
Becker, Georg T.;Regazzoni, Francesco;Burleson, Wayne P.

文献摘要

被引文献

相似文献

近年来,硬件木马引起了政府、工业界和科学界的关注。主要关注之一是集成电路,例如,对于军事或关键基础设施应用,可能在制造过程中被恶意操纵,而制造过程通常在国外进行。然而,由于在实践中还没有报告的硬件木马,所以很少有人知道这样的木马是什么样子的,以及在实践中实现一个木马的难度有多大。在本文中,我们提出了一个非常隐秘的方法来实现低于门级的硬件木马,我们评估其对目标设备的安全性的影响。我们没有在目标设计中添加额外的电路,而是通过改变现有晶体管的掺杂剂极性来插入硬件木马。由于修改后的电路在所有布线层(包括所有金属和多晶硅)上都是合法的,因此我们的特洛伊木马家族可以抵抗大多数检测技术,包括细粒度光学检测和“黄金芯片”检查。我们证明了我们的方法的有效性,通过插入木马程序到两个设计-一个数字后处理来自英特尔的加密安全的RNG设计中使用的常春藤桥处理器和一个侧通道抗SBox实现-并通过探索其可检测性和它们对安全的影响。
In recent years, hardware Trojans have drawn the attention of governments and industry aswell as the scientific community. One of the main concerns is that integrated circuits, e.g., for military or critical-infrastructure applications, could be maliciously manipulated during the manufacturing process, which often takes place abroad. However, since there have been no reported hardware Trojans in practice yet, little is known about how such a Trojan would look like and how difficult it would be in practice to implement one. In this paper we propose an extremely stealthy approach for implementing hardware Trojans below the gate level, and we evaluate their impact on the security of the target device. Instead of adding additional circuitry to the target design, we insert our hardware Trojans by changing the dopant polarity of existing transistors. Since the modified circuit appears legitimate on all wiring layers (including all metal and polysilicon), our family of Trojans is resistant to most detection techniques, including fine-grain optical inspection and checking against "golden chips". We demonstrate the effectiveness of our approach by inserting Trojans into two designs-a digital post-processing derived from Intel's cryptographically secure RNG design used in the Ivy Bridge processors and a side-channel resistant SBox implementation-and by exploring their detectability and their effects on security.