TrojanZero: Switching Activity-Aware Design of Undetectable Hardware Trojans with Zero Power and Area Footprint
Conventional Hardware Trojan (HT) detection techniques are based on the\nvalidation of integrated circuits to determine changes in their functionality,\nand on non-invasive side-channel analysis to identify the variations in their\nphysical parameters. In particular, almost all the proposed side-channel\npower-based detection techniques presume that HTs are detectable because they\nonly add gates to the original circuit with a noticeable increase in power\nconsumption. This paper demonstrates how undetectable HTs can be realized with\nzero impact on the power and area footprint of the original circuit. Towards\nthis, we propose a novel concept of TrojanZero and a systematic methodology for\ndesigning undetectable HTs in the circuits, which conceals their existence by\ngate-level modifications. The crux is to salvage the cost of the HT from the\noriginal circuit without being detected using standard testing techniques. Our\nmethodology leverages the knowledge of transition probabilities of the circuit\nnodes to identify and safely remove expendable gates, and embeds malicious\ncircuitry at the appropriate locations with zero power and area overheads when\ncompared to the original circuit. We synthesize these designs and then embed in\nmultiple ISCAS85 benchmarks using a 65nm technology library, and perform a\ncomprehensive power and area characterization. Our experimental results\ndemonstrate that the proposed TrojanZero designs are undetectable by the\nstate-of-the-art power-based detection methods.\n