A Game-Theoretic Approach for Testing for Hardware Trojans

A Game-Theoretic Approach for Testing for Hardware Trojans
复制标题

测试硬件木马的博弈论方法

DOI:
10.1109/tmscs.2016.2564963
复制
发表时间:
2016
期刊:
IEEE Transactions on Multi-Scale Computing Systems
影响因子:
--
通讯作者:
K. Kwiat
K. Kwiat
中科院分区:
--
文献类型:
--
作者:
Charles A. Kamhoua;Hong Zhao;Manuel Rodríguez;K. Kwiat

文献摘要

被引文献

相似文献

微电路行业正在见证IC(集成电路)制造的大规模外包,以及在IC设计期间使用第三方IP(知识产权)和COTS(商业现成)工具。这些问题带来了新的安全挑战和威胁。特别是,它为在IC中插入恶意逻辑(通常称为硬件特洛伊木马)带来了多种机会。测试通常用于沿着IC开发生命周期,以验证给定芯片的功能正确性。然而,现代集成电路的复杂性,加上资源和时间的限制,使得详尽的测试通常是不可行的。在本文中,我们提出了一个博弈论的方法来测试数字电路,考虑到智能攻击者负责感染的IC与硬件木马的决策过程。硬件木马的测试被建模为恶意制造商或设计者之间的零和游戏(即,攻击者)想要插入特洛伊木马程序,测试人员(即,防御者),其目标是检测特洛伊人。该游戏导致多个可能的混合策略纳什均衡,允许识别最佳测试集,增加检测和击败数字逻辑中的硬件木马的概率。结果还表明,由防御者测试的木马类的最小数量和对攻击者施加的罚款可以阻止理性以及非理性的攻击者感染木马的电路。
The microcircuit industry is witnessing a massive outsourcing of the fabrication of ICs (Integrated Circuit), as well as the use of third party IP (Intellectual Property) and COTS (Commercial Off-The-Shelf) tools during IC design. These issues raise new security challenges and threats. In particular, it brings up multiple opportunities for the insertion of malicious logic, commonly referred to as a hardware Trojan, in the IC. Testing is typically used along the IC development lifecycle to verify the functional correctness of a given chip. However, the complexity of modern ICs, together with resource and time limitations, makes exhaustive testing commonly unfeasible. In this paper, we propose a game-theoretic approach for testing digital circuits that takes into account the decision-making process of intelligent attackers responsible for the infection of ICs with hardware Trojans. Testing for hardware Trojans is modeled as a zero-sum game between malicious manufacturers or designers (i.e., the attacker) who want to insert Trojans, and testers (i.e., the defender) whose goal is to detect the Trojans. The game results in multiple possible mixed strategy Nash equilibria that allow to identify optimum test sets that increase the probability of detecting and defeating hardware Trojans in digital logic. Results also show that the minimum number of Trojan classes tested by the defender and the fines imposed to the attacker can deter rational as well as irrational attackers from infecting circuits with Trojans.