Exploiting the Analog Properties of Digital Circuits for Malicious Hardware.
While the move to smaller transistors has been a boon for performance it has dramatically increased the cost to fabricate chips using those smaller transistors. This forces the vast majority of chip design companies to trust a third party--often overseas--to fabricate their design. To guard against...
| Publicado en: | Communications of the ACM Vol. 60; no. 9; pp. 83 - 92 |
|---|---|
| Autores principales: | , , , , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Sep2017
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=124886441&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 124886441 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Sep2017 vid: 60 iid: 9 pid: 68 pub: Association for Computing Machinery artinfo: ui: 124886441 10.1145/3068776 ppf: 83 ppct: 9 formats: tig: atl: Exploiting the Analog Properties of Digital Circuits for Malicious Hardware. aug: au: Yang, Kaiyuan Hicks, Matthew Dong, Qing Austin, Todd Sylvester, Dennis affil: Dept. of ECE, Rice University, Houston, TX Dept. of CS, Virginia Tech, Blacksburg, VA Department of EECS, University of Michigan, Ann Arbor, MI su: Hardware Trojans (Computers) Digital electronics Analog computer circuits Transistor design & construction Fabrication (Manufacturing) sug: subj: Hardware Trojans (Computers) Digital electronics Analog computer circuits Transistor design & construction Fabrication (Manufacturing) ab: While the move to smaller transistors has been a boon for performance it has dramatically increased the cost to fabricate chips using those smaller transistors. This forces the vast majority of chip design companies to trust a third party--often overseas--to fabricate their design. To guard against shipping chips with errors (intentional or otherwise) chip design companies rely on post-fabrication testing. Unfortunately, this type of testing leaves the door open to malicious modifications since attackers can craft attack triggers requiring a sequence of unlikely events, which will never be encountered by even the most diligent tester. In this paper, we show how a fabrication-time attacker can leverage analog circuits to create a hardware attack that is small (i.e., requires as little as one gate) and stealthy (i.e., requires an unlikely trigger sequence before affecting a chip's functionality). In the open spaces of an already placed and routed design, we construct a circuit that uses capacitors to siphon charge from nearby wires as they transit between digital values. When the capacitors are fully charged, they deploy an attack that forces a victim flip-flop to a desired value. We weaponize this attack into a remotely controllable privilege escalation by attaching the capacitor to a controllable wire and by selecting a victim flip-flop that holds the privilege bit for our processor. We implement this attack in an OR1200 processor and fabricate a chip. Experimental results show that the purposed attack works. It eludes activation by a diverse set of benchmarks and evades known defenses. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2017 holdings: @attributes: islocal: N |
|---|