vix.ing · top · new · best · stats · spec

Side-Channel Hardware Trojan for Provably-Secure SCA-Protected\n Implementations

2019/09/22 by Samaneh Ghandali, Ghandali, Samaneh, Thorben Moos +5
Computer Science · Engineering · #Physical Unclonable Functions (PUFs) and Hardware Security #Cryptographic Implementations and Security #Integrated Circuits and Semiconductor Failure Analysis

paper · pdf · doi:10.48550/arxiv.1910.00737

Abstract

Hardware Trojans have drawn the attention of academia, industry and\ngovernment agencies. Effective detection mechanisms and countermeasures against\nsuch malicious designs can only be developed when there is a deep understanding\nof how hardware Trojans can be built in practice, in particular Trojans\nspecifically designed to avoid detection. In this work, we present a mechanism\nto introduce an extremely stealthy hardware Trojan into cryptographic\nprimitives equipped with provably-secure first-order side-channel\ncountermeasures. Once the Trojan is triggered, the malicious design exhibits\nexploitable side-channel leakage, leading to successful key recovery attacks.\nGenerally, such a Trojan requires neither addition nor removal of any logic\nwhich makes it extremely hard to detect. On ASICs, it can be inserted by subtle\nmanipulations at the sub-transistor level and on FPGAs by changing the routing\nof particular signals, leading to \zero logic overhead. The underlying\nconcept is based on modifying a securely-masked hardware implementation in such\na way that running the device at a particular clock frequency violates one of\nits essential properties, leading to exploitable leakage. We apply our\ntechnique to a Threshold Implementation of the PRESENT block cipher realized in\ntwo different CMOS technologies, and show that triggering the Trojan makes the\nASIC prototypes vulnerable.\n

Related