节点文献

硬件木马电路设计与检测

Design and Detection of Hardware Trojan Horse

【作者】 黄哲

【导师】 姚若河;

【作者基本信息】 华南理工大学 , 微电子学与固体电子学, 2016, 硕士

【摘要】 集成电路设计、生产的各个流程都有可能受到硬件木马电路的攻击,从而给使用这些芯片的系统造成安全隐患,研究硬件木马电路的设计与检测,对于保证芯片的安全运行具有重要意义。本文针对硬件木马电路的设计与检测进行了研究。首先,对硬件木马电路的历史、电路分类、检测方法进行系统的学习和归纳。其次,对硬件木马电路的设计方法进行了研究,了解硬件木马的运行机制,为提出更有效的硬件木马电路检测方法提供了有益的参考和木马样本。最后,提出了一种在电路设计阶段就介入的硬件木马检测流程。本文的主要内容包括:首先,针对计数器触发电路存在的可控性低,隐蔽性差,触发不灵活的特点,本文提出一种基于可逆计数器的硬件木马触发电路,该电路采用外部脉冲进行触发,如果在触发过程中出现意外情况,造成本次触发失败,可逆计数器会逆向计数,直至返回初始状态,等待下一次触发,从而使触发电路具有更好的可控性以及抗干扰性能。针对该电路进行了电路仿真以及性能分析,结果表明,与32位计数器型触发电路相比,本设计占用更少的硬件资源,隐蔽性更强,可控性更高。然后,以一个AES加密电路为目标,结合故障攻击原理,设计了一个只需要四个门电路的硬件木马电路。当该电路被激活时,会造成加密出错,并输出错误密文。通过收集,分析两对正确/错误密文对,可以破解得到AES加密第十轮轮密钥。本文在AES加密电路的门级网表完成了木马电路的植入,对木马电路及密钥破解进行了仿真验证。结果表明,利用该硬件木马可以正确实现破解AES加密第十轮轮密钥的功能。最后,提出了一种基于环形振荡器的硬件木马检测方法。完整的检测流程包括设计修改、数据收集和木马检测三个阶段。对检测流程及环形振荡器的配置方法进行了详细描述。文章以ISCAS-85测试电路集中的C432电路为目标电路,对该检测流程进行了验证。结果表明,该检测方法可以在存在一定程度的工艺偏差的情况下,将被植入到目标电路中的硬件木马样本检测出来。

【Abstract】 The design and fabricate process of integrated circuit may be attacked by a hardware Trojan horse, which will bring potential security problems to the system using these ICs. This paper focuses on the design and detection of hardware Trojan horse, which has a significant meaning for integrated circuit. Firstly, the history, classification and detection of hardware Trojan are concluded. Secondly, the design methods of hardware Trojan are studied in detail, which will be very helpful to design a more effective hardware Trojan detection method. Finally, a new hardware Trojan detection strategy is proposed.The main contents of this paper include:1. For the low controllability disadvantage of the trigger circuit using a counter, this paper proposes a new trigger circuit based on up/down counter. The proposed circuit uses an external pulse as the trigger signal. If the trigger process fails due to some unexpected factors, the up/down counter will count in the reverse direction until it reaches the initial state. Then the trigger circuit will wait for the next trigger. This will improve the controllability and the anti-interference performance of the trigger circuit.2.Using an AES circuit as target circuit, a hardware Trojan inserted on the gate level based on fault attack is designed. This Trojan circuit occupies only four XOR gates. When it is triggered, an error occurs and the AES circuit outputs an error ciphertext. Using two pairs of correct/error ciphertext, the tenth round key can be cracked. Circuit simulation is performed and the round key is cracked by a matlab program.3. A hardware Trojan detection strategy based on ring oscillator is proposed. The whole detection process includes changing design, collecting data and detecting Trojan. The detection process and the configuration of ring oscillator have been described in detail. A python program is designed to analyze and change the circuit netlist. This paper uses the ISCAS-85:C432 circuit as the target circuit and performs simulation of the whole detection process on it. The simulation results prove the effectiveness of this detection strategy.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络