节点文献

硬件木马电路设计与检测

Design and Detection of Hardware Trojan Horse

【作者】 黄山

【导师】 姚若河;

【作者基本信息】 华南理工大学 , 微电子学与固体电子学, 2017, 硕士

【副题名】针对信息泄露型与功能型木马的研究

【摘要】 集成电路产业链需要CAD工具供应商、IP核供应商、集成电路设计公司和制造公司等多方合作,这种产业链的分离,使得集成电路有可能被恶意的第三方植入硬件木马电路,造成信息泄露或者系统瘫痪。研究硬件木马电路检测,对保障芯片安全具有重要的意义。本文围绕硬件木马电路的设计与检测,设计了两款信息泄露型硬件木马电路,为硬件木马检测的研究提供样本;给出了一个基于冗余的硬件木马检测电路。本文主要研究内容如下:1、以波特率为9600 Baud的RS232电路为目标,设计了一款基于波特率倍频特性的硬件木马电路。该木马电路将发送电路的波特率修改为115200 Baud,对数据传输进行扩展和调控,使发送电路和接收电路在不同波特率下通信,实现信息泄露。植入该木马的RS232电路仍然可以在设计的9600 Baud波特率下正常工作,木马攻击者通过波特率为115200 Baud的接收电路可以成功窃听到泄露信息,木马的隐蔽性较好。2、以RS232电路为目标,设计了一款基于停止位的硬件木马电路。在RS232电路中,当停止位个数超过2个时,接收电路会认为电路处于空闲状态,本设计基于此漏洞,通过调控停止位个数,实现信息泄露。木马攻击者通过监控停止位个数可以成功窃听到泄露信息。该木马对目标电路的改动较小,面积仅增加0.60%,功耗仅增加0.11%,隐蔽性较好。3、结合可信性设计与工作阶段检测的优点,给出了一个基于冗余的硬件木马检测电路。完整的检测流程包括电路分析、设计修改和木马检测三个步骤。该电路通过在设计阶段插入木马检测模块,在芯片正常工作时,实时进行硬件木马电路检测,并将被木马篡改的信号予以恢复。电路以AES-128加密电路作为目标电路,对检测方法和检测流程进行验证,仿真结果表明了检测方法的有效性。

【Abstract】 Integrated circuit industry chain need CAD tool suppliers,IP core suppliers,design companies and manufacturing companies and many other companies to work together.The separation of IC industry chain,make it possible to insert hardware Trojan circuit into the original integrated circuit,which will result in information disclosure or system paralysis.It is very important to study the design and detection of the hardware circuit.This paper focuses on the design and detection of hardware Trojan.Firstly,the designs of two information leakage hardware Trojan circuits are introduced,which provide effective models for the study of Trojan detection.Further,a hardware Trojan detection circuit based on redundancy is proposed.The main contents of this paper are organized as follows:1.Using a RS232 circuit with a 9600 Baud as a target circuit,this paper designs a multiplier baud rate hardware Trojan circuit.This hardware Trojan circuit modifies the baud rate of the transmitting circuit to 115200 Baud,expands and controls the data transmission of RS232 to realize the target of leakage information.The modified RS232 circuit with a differential frequency Trojan can work properly in 9600 Baud,and the attackers can use a RS232 receiving circuit with 115200 Baud to steal the information.It is difficult for the users to find the hardware Trojan.2.Using a RS232 circuit as a target circuit,this paper designs a stop bits hardware Trojan circuit which employs the vulnerability of the RS232 protocol.For RS232 circuit,when the number of stop bits exceeds 2,the receiver will assume that the circuit is idle.This design exploits this vulnerability and modifies the number of stop bits in transmitting circuit to realize the target of information leakage.The attacker can leak information by stop bits.The modification of the target circuit is small,the area is only increased by 0.60%,the power consumption is only increased by 0.11%,and it is difficult to be found by the users.3.This paper proposes a hardware Trojan detection circuit based on redundancy which combines the advantages of credibility design and run-time detection.The whole detection process includes circuit analysis,design modification and Trojan detection.Trojan is detected by the detection module,and the error output can be replaced by a correct output.In this paper,the AES-128 encryption circuit is used as the target circuit to verify the detection method and the detection process.The simulation results show that the method is effective.

【关键词】 硬件木马电路RS232波特率停止位冗余
【Key words】 Hardware Trojan HorseRS232Baud RateStop BitsRedundancy
  • 【分类号】TN407
  • 【被引频次】4
  • 【下载频次】186
节点文献中: