The Risk of Outsourcing: Hidden SCA Trojans in Third-Party IP-Cores Threaten Cryptographic ICs

The Risk of Outsourcing: Hidden SCA Trojans in Third-Party IP-Cores Threaten Cryptographic ICs
复制标题

DOI:
10.1109/ets48528.2020.9131594
复制
发表时间:
2020-05
期刊:
2020 IEEE European Test Symposium (ETS)
影响因子:
--
通讯作者:
David Knichel;Thorben Moos;A. Moradi
David Knichel;Thorben Moos;A. Moradi
中科院分区:
其他
文献类型:
--
作者:
David Knichel;Thorben Moos;A. Moradi

文献摘要

相似文献

侧信道分析(SCA)攻击——尤其是功率分析——是提取存储在加密设备中并由其处理的秘密的强大方法。近年来,研究人员对利用片上测量设备远程执行此类SCA攻击表现出了兴趣。结果表明,简单的电压监测传感器可以由数字元件构成,并置于多租户fpga上,对邻近的加密协处理器进行远程攻击。类似的威胁是将第三方ip核毫无防备地集成到IC设计中。即使获得的ip核的功能本身不是安全关键,它也可能包含片上传感器作为特洛伊木马,可以窃听整个设备的加密操作。与迄今为止文献中报道的所有基于fpga的调查相反,我们首次在基于asic的案例研究中研究了这种片上传感器作为信息泄漏源的效率。为此,除了加密核心(轻量级分组密码PRESENT)外,我们还在40 nm商用标准单元库制造的ASIC上设计并实现了电压监测传感器。尽管传感器和PRESENT核心之间存在物理距离,但我们展示了通过处理传感器的输出完全恢复PRESENT核心密钥的可能性。我们的研究结果表明,这种传感器的隐藏插入-例如由恶意的第三方IP-Core供应商-可能危及处理敏感信息的嵌入式系统的安全,即使设备不能被对手物理访问。
Side-channel analysis (SCA) attacks - especially power analysis - are powerful ways to extract the secrets stored in and processed by cryptographic devices. In recent years, researchers have shown interest in utilizing on-chip measurement facilities to perform such SCA attacks remotely. It was shown that simple voltage-monitoring sensors can be constructed from digital elements and put on multi-tenant FPGAs to perform remote attacks on neighbouring cryptographic co-processors. A similar threat is the unsuspecting integration of third-party IP-Cores into an IC design. Even if the function of an acquired IP-Core is not security critical by itself, it may contain an on-chip sensor as a Trojan that can eavesdrop on cryptographic operations across the whole device. In contrast to all FPGA-based investigations reported in the literature so far, we examine the efficiency of such on-chip sensors as a source of information leakage in an ASIC-based case study for the first time. To this end, in addition to a cryptographic core (lightweight block cipher PRESENT) we designed and implemented a voltage-monitoring sensor on an ASIC fabricated by a 40 nm commercial standard cell library. Despite the physical distance between the sensor and the PRESENT core, we show the possibility of fully recovering the secret key of the PRESENT core by processing the sensor's output. Our results imply that the hidden insertion of such a sensor - for example by a malicious third party IP-Core vendor - can endanger the security of embedded systems which deal with sensitive information, even if the device cannot be physically accessed by the adversary.