Manufacturer turned attacker: Dangers of stealthy trojans via threshold voltage manipulation

Vinay C. Patil, Arunkumar Vijayakumar, Sandip Kumar Kundu · 2017

Applications of Integrated Circuits (ICs) have become pervasive. A striking feature of the contemporary IC industry is that a very large and growing proportion of the IC foundries are now located offshore. While offshoring IC production reduces cost, it also creates a concern that the functionality of the circuits may be compromised by Trojans designed to cause malfunction at a select times. This concern is particularly acute in defense, energy and infrastructure systems. Extensive research has been conducted into detection of Trojans which involve either modification of existing circuitry or addition of extra logic. Some Trojans do not involve addition of logic or modification of physical design - they manipulate existing structures to behave differently. Such Trojans, known as stealthy Trojans, are particularly hard to detect. This work explores utilization of multi-threshold logic and threshold voltage manipulation as an attack vector to introduce stealthy Trojans. Also, a previously unexplored method of using the temperature of the device to, selectively, activate a Trojan is studied. Our work illustrates an attack on a D flip-flop, where we show that the threshold voltages can be manipulated to introduce a permanent stuck-at fault. Further, we show that the manipulation can allow the flipflop to work normally at 25°C while becoming dysfunctional at 60°C. In this paper, we discuss how this feature can be used to compromise the security of cryptographic functions.

Read the paper · More papers on PaperTik