4 ms·
Open ASIC IP cores and firmwares are a must-have. Without independently-verifiable silicon, there's no telling was is or isn't there.
by trapperkeeper74 9y ago
Open ASIC IP cores and firmwares are a must-have. Without independently-verifiable silicon, there's no telling was is or isn't there.
- pjc50 9y agoFinancing this is the real problem. Open source software relies on volunteer labour and the small costs of donated hosting, hardware etc. Open source hardware does not have nearly enough demand to fund it and cannot protect its revenue stream from competitors.
- exikyut 9y agoTotally agree. My question is, how do you verify the fabs are trustworthy? Genuinely curious - I'm actually trying to answer this myself at the moment. The best I've come up with is, go to >2 fabs, have them deliver wafers but not saw them, scan and compare the wafers using trusted equipment, then take the wafers back to the fab for sawing. The last step is the biggest issue; you could be bait-and-switched. Sawing doesn't sound as expensive as actual photolithography/etching kit, but I suspect it would still be prohibitive for most. Thing is, you could tamper with a small number of chips on the wafer image in such a way that a quick but unlikely interaction with the end device would easily spot the tampered units. Then it would be a simple matter to insert a "picker" into somewhere in the manufacturing/shipping logistics to find the tampered device(s) and reroute them.
- pjc50 9y agoIt's much harder for the fab to backdoor things than any other stage, and it also takes time for them to prepare such an attack once they have your GDSII files. So it would show up as a manufacturing delay. For anything other than milspec this probably isn't worth worrying about at this time. Also, I'm not 100% sure that two fabs would actually produce optically identical chips; would there be process differences?
- exikyut 9y agoArg. I'm actually considering the problem of a secure design that's secure both through being transparently open source, and by using a super-simple architecture. And unfortunately these two properties mean that a) well, everyone has the GDSII, and b) the architecture is super-easy to hack. It makes perfect sense that a fab would need time to mount an attack on a closed and complex design though. Very good point about process differences. That totally makes sense, and would likely require human verification to handle, which for big chips would be, at the very least, hilariously expensive.
- pjc50 9y agohttp://sharps.org/wp-content/uploads/BECKER-CHES.pdf http://sharps.org/wp-content/uploads/BECKER-CHES.pdf is probably the state of the art here. It's basically undetectable. "Instead of adding additional cir- cuitry to the target design, we insert our hardware Trojans by changing the dopant polarity of existing transistors. Since the modified circuit ap- pears legitimate on all wiring layers (including all metal and polysilicon), our family of Trojans is resistant to most detection techniques, includ- ing fine-grain optical inspection and checking against “golden chips”. We demonstrate the effectiveness of our approach by inserting Trojans into two designs — a digital post-processing derived from Intel’s cryp- tographically secure RNG design used in the Ivy Bridge processors and a side-channel resistant SBox implementation — and by exploring their detectability and their effects on security"
- exikyut 9y ago* Sound of groaning * Thanks. But ugh. That is both absolutely amazing and... well, what did I expect. Of course there are going to be process attacks :) Hmmm. I guess the only defenses against this are - trying to design the layout to get good "route coverage" via test routines (sounds hard) - aiming for super-simple designs that make it difficult to constructively alter the design (pathological simplicity is one part of my idea; yet to determine viability) - trusting the fab (ha!) I wonder if using a huge process like ~30nm (or even bigger) would mitigate at all. Edit: Small work fixes, added sentence
- neltnerb 9y agoTrustworthy in what sense? That they are delivering on spec, or that they aren't stealing your IP? For the prior, I imagine going there and observing QC procedures is the only hope. For the latter, I imagine it involves keeping discrete critical components isolated -- firmware from silicon (and beyond), using different factories so that neither independently has a functional device.
- exikyut 9y agoTrustworthy in the context of a "secure as possible" open-source design. Knowing that the layout I shipped is what I got back with no modifications. Unfortunately my idea would have both the layout and the (OTP-fused) firmware fully open. I'm learning a lot about the challenges of "transparent security" as opposed to security by obscurity...