The threat of hardware Trojans (HTs) and their detection is a widely studied field. While the effort for inserting a Trojan into an application-specific integrated circuit (ASIC) can be considered relatively high, especially when trusting the chip manufacturer, programmable hardware is vulnerable to Trojan insertion even after the product has been shipped or during usage. At the same time, detecting dormant HTs with small or zero-overhead triggers and payloads on these platforms is still a challenging task, as the Trojan might not get activated during the chip verification using logical testing or physical measurements. In this work, we present a novel Trojan detection approach based on a technique known from integrated circuit (IC) failure analysis, capable of detecting virtually all classes of dormant Trojans. Using laser logic state imaging (LLSI), we show how supply voltage modulations can awaken inactive Trojans, making them detectable using laser voltage imaging techniques. Therefore, our technique does not require triggering the Trojan. To support our claims, we present three case studies on 28 and 20 SRAM- and flash-based field-programmable gate arrays (FPGAs). We demonstrate how to detect with high confidence small changes in sequential and combinatorial logic as well as in the routing configuration of FPGAs in a non-invasive manner. Finally, we discuss the practical applicability of our approach on dormant analog Trojans in ASICs.
翻译:硬件木马(HT)的威胁及其检测是一个广泛研究的领域。虽然将木马植入专用集成电路(ASIC)的难度被认为较高(尤其是在信任芯片制造商的情况下),但可编程硬件即使在产品发货后或使用期间也易受木马植入的攻击。同时,在这类平台上检测具有小型或零开销触发器和有效载荷的休眠木马仍是一项具有挑战性的任务,因为木马可能不会在利用逻辑测试或物理测量的芯片验证过程中被激活。本文提出了一种基于集成电路(IC)故障分析技术的新型木马检测方法,能够检测几乎所有类型的休眠木马。通过使用激光逻辑状态成像(LLSI),我们展示了电源电压调制如何唤醒非活跃木马,使其可通过激光电压成像技术被检测到。因此,我们的技术无需触发木马。为支持上述观点,我们基于28纳米和20纳米的SRAM及闪存型现场可编程门阵列(FPGA)开展了三项案例研究,展示了如何以高置信度非侵入式检测FPGA中时序逻辑、组合逻辑及路由配置的微小变化。最后,我们讨论了该方法在ASIC中休眠模拟木马检测方面的实际适用性。