Hardware Trojan Detection via RF Impedance Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting hardware trojans in integrated circuits are inefficient, as they often require destructive reverse engineering or rely on a 'golden-sample' IC, making them time-consuming, expensive, and impractical for large-scale testing, especially in detecting rare trigger conditions.
Innovation Solution
A method using clustering analysis and harmonics-based side-channel evaluation to identify hardware differences, such as malicious modifications, by wirelessly applying RF waveforms and recording backscattering signals, generating clusters based on impedance characteristics, and adjusting cluster numbers to detect hidden hardware modifications with high accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If reverse engineering is used to detect hardware trojans, then detection accuracy is improved, but time consumption and cost increase significantly
Solution Approach 1:
The patent segments the detection process into two stages: (1) a fast screening stage using side-channel analysis to evaluate many ICs quickly, and (2) a detailed reverse engineering stage applied only to suspected ICs. This segmentation reduces overall time consumption while maintaining detection accuracy by avoiding exhaustive reverse engineering of all ICs.
Solution Approach 2:
The patent performs preliminary side-channel evaluation on ICs before applying reverse engineering. This preliminary action identifies suspicious ICs based on impedance characteristics, allowing reverse engineering to be focused only on those cases, thereby reducing time and resource consumption while maintaining detection accuracy.
2Measurement precision
If reverse engineering is used to detect hardware trojans, then detection accuracy is improved, but cost increases significantly
Solution Approach 1:
The patent segments the detection process into two stages: (1) a fast screening stage using side-channel analysis to evaluate many ICs quickly, and (2) a detailed reverse engineering stage applied only to suspected ICs. This segmentation reduces overall time consumption while maintaining detection accuracy by avoiding exhaustive reverse engineering of all ICs.
Solution Approach 2:
The patent performs preliminary side-channel evaluation on ICs before applying reverse engineering. This preliminary action identifies suspicious ICs based on impedance characteristics, allowing reverse engineering to be focused only on those cases, thereby reducing time and resource consumption while maintaining detection accuracy.
3Ease of operation
If side-channel evaluation with gold-sample IC is used, then non-destructive testing is achieved, but applicability is limited when design updates are made
Solution Approach 1:
The patent uses clustering analysis that dynamically adapts to different IC designs. The clustering algorithm learns impedance characteristics from the actual IC population being tested, rather than relying on a fixed gold-sample reference. This dynamic adaptation allows the method to remain effective even when designs are updated, while still providing non-destructive testing.
Solution Approach 2:
The patent creates reference impedance profiles through clustering analysis of normal ICs in the population, effectively generating dynamic reference models without requiring a separate gold-sample IC. These reference profiles are updated based on the actual manufacturing process, making the system adaptable to design changes while maintaining non-destructive testing capability.
4Measurement precision
If conventional hardware function verification is used, then simple trojans are detected, but detection of rare trigger conditions becomes difficult
Solution Approach 1:
The patent replaces conventional functional verification methods with side-channel analysis based on impedance measurements. Instead of attempting to trigger and observe Trojan behavior through functional testing, the method detects Trojans by measuring their impact on the IC's electrical impedance characteristics, which are continuously present and measurable without requiring rare trigger conditions.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach allows for 100% accurate detection of hardware differences as small as 0.19% of the total circuits, reducing the need for extensive testing and enabling the deployment of reverse engineering methods across a large population of ICs, while being tolerant to manufacturing variations.
Implementation Method 1
wirelessly recording a plurality of signals (e.g., backscattering side-signal) of RF waveforms emanating from the plurality of fabricated integrated circuit
Data Source
AI summary
An exemplary method and system are disclosed that can detect the presence or absence hardware differences among fabricated integrated circuits, including those associated with hardware trojans (HT), using cluster-ing-based analysis and/or harmonics-based analysis of side-channel evaluation. The exemplary method and system has been demonstrated to achieve detection of hardware differences as small as 0.19% of the total circuits with 100% accuracy while being tolerant to manufacturing variations among hardware instances.


