vix.ing · top · new · best · stats · spec

RF-Trojan: Leaking Kernel Data Using Register File Trojan

2019/04/15 by Mohammad Nasim Imtiaz Khan, Khan, Mohammad Nasim Imtiaz, Asmit De +3 · 1 voice
Computer Science · Engineering · #Advanced Memory and Neural Computing #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Physical Unclonable Functions (PUFs) and Hardware Security #Security and Verification in Computing #cs.CR

paper · pdf · doi:10.48550/arxiv.1904.07144

openalex publication_date 2019/04/15 · arxiv published 2019/04/15 · arxiv updated 2019/04/15 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Register Files (RFs) are the most frequently accessed memories in a microprocessor for fast and efficient computation and control logic. Segment registers and control registers are especially critical for maintaining the CPU mode of execution that determinesthe access privileges. In this work, we explore the vulnerabilities in RF and propose a class of hardware Trojans which can inject faults during read or retention mode. The Trojan trigger is activated if one pre-selected address of L1 data-cache is hammered for certain number of times. The trigger evades post-silicon test since the required number of hammering to trigger is significantly high even under process and temperature variation. Once activated, the trigger can deliver payloads to cause Bitcell Corruption (BC) and inject read error by Read Port (RP) and Local Bitline (LBL). We model the Trojan in GEM5 architectural simulator performing a privilege escalation. We propose countermeasures such as read verification leveraging multiport feature, securing control and segment registers by hashing and L1 address obfuscation.

Citations

Discussions

Related