{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:25:21Z","timestamp":1750220721991,"version":"3.41.0"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2020,6,23]],"date-time":"2020-06-23T00:00:00Z","timestamp":1592870400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2020,7,31]]},"abstract":"<jats:p>\n            A hardware Trojan is a malicious modification to an integrated circuit (IC) made by untrusted third-party vendors, fabrication facilities, or rogue designers. Although existing hardware Trojans are designed to be stealthy, they can, in theory, be detected by post-manufacturing and acceptance tests due to their physical connections to IC logic. Manufacturing tests can potentially trigger the Trojan and propagate its payload to an output. Even if the Trojan is not triggered, the physical connections to the IC can enable detection due to additional side-channel activity (e.g., power consumption). In this article, we propose a novel hardware Trojan design, called\n            <jats:italic>Soft-HaT<\/jats:italic>\n            , which only becomes physically connected to other IC logic after activation by a software program. Using an electrically programmable fuse (E-fuse), the hardware can be \u201cre-programmed\u201d remotely. We illustrate how Soft-HaT can be used for offensive applications in system-on-chips. Examples of Soft-HaT attacks are demonstrated on an open source system-on-chip (OrpSoC) and implemented in Virtex-7 FPGA to show their efficacy in terms of stealthiness.\n          <\/jats:p>","DOI":"10.1145\/3396521","type":"journal-article","created":{"date-parts":[[2020,6,23]],"date-time":"2020-06-23T19:54:37Z","timestamp":1592942077000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Soft-HaT"],"prefix":"10.1145","volume":"25","author":[{"given":"Md Mahbub","family":"Alam","sequence":"first","affiliation":[{"name":"University of Florida, Gainesville, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adib","family":"Nahiyan","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mehdi","family":"Sadi","sequence":"additional","affiliation":[{"name":"Auburn University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Domenic","family":"Forte","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Tehranipoor","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,6,23]]},"reference":[{"volume-title":"Retrieved","year":"2016","author":"Engineering Semiconductor","key":"e_1_2_1_1_1"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2010.2061228"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.36"},{"volume-title":"Proceedings of the 2019 Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC\u201919)","author":"Alam M. M.","key":"e_1_2_1_4_1"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.mejo.2005.12.013"},{"key":"e_1_2_1_6_1","first-page":"539","article-title":"Run-time firmware authentication","volume":"7","author":"Balard Eric","year":"2009","journal-title":"US Patent"},{"volume-title":"Proceedings of the 2009 22nd International Conference on VLSI Design. IEEE","author":"Banga Mainak","key":"e_1_2_1_7_1"},{"volume-title":"Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems. 197--214","author":"Becker Georg T.","key":"e_1_2_1_9_1"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2013.15"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2334493"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/HLDVT.2009.5340158"},{"volume-title":"MERO: A statistical approach for hardware Trojan detection. In Cryptographic Hardware and Embedded Systems\u2014CHES","year":"2009","author":"Chakraborty Rajat Subhra","key":"e_1_2_1_13_1"},{"key":"e_1_2_1_14_1","first-page":"724","article-title":"Implementing enhanced security features in an ASIC using eFuses","volume":"7","author":"Deskin Brian P.","year":"2010","journal-title":"US Patent"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASPDAC.2017.7858388"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/4.661206"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2017.2727985"},{"volume-title":"Patterson","year":"2011","author":"Hennessy John L.","key":"e_1_2_1_18_1"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10836-016-5632-y"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2018.8383914"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1369-7021(06)71540-1"},{"volume-title":"n.d. Home Page. Retrieved","year":"2020","author":"Insights IC","key":"e_1_2_1_22_1"},{"volume-title":"Proceedings of the 2008 IEEE International Workshop on Hardware-Oriented Security and Trust (HOST\u201908)","year":"2008","author":"Jin Yier","key":"e_1_2_1_23_1"},{"key":"e_1_2_1_24_1","first-page":"060","article-title":"Secure end-of-life handling of electronic devices","volume":"8","author":"Johansson Petri Mikael","year":"2011","journal-title":"US Patent"},{"volume-title":"The Hardware Trojan War: Attacks, Myths, and Defenses","author":"Rajesh J. S.","key":"e_1_2_1_25_1"},{"key":"e_1_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Paul Kocher Daniel Genkin Daniel Gruss Werner Haas Mike Hamburg Moritz Lipp Stefan Mangard Thomas Prescher Michael Schwarz and Yuval Yarom. 2018. Spectre attacks: Exploiting speculative execution. arXiv:1801.01203.  Paul Kocher Daniel Genkin Daniel Gruss Werner Haas Mike Hamburg Moritz Lipp Stefan Mangard Thomas Prescher Michael Schwarz and Yuval Yarom. 2018. Spectre attacks: Exploiting speculative execution. arXiv:1801.01203.","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/LED.2002.802657"},{"volume-title":"Delay Fault Testing for VLSI Circuits","author":"Krstic Angela","key":"e_1_2_1_28_1"},{"volume-title":"Proceedings of the 2015 Symposium on VLSI Technology (VLSI Technology\u201915)","author":"Kulkarni S. H.","key":"e_1_2_1_29_1"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSSC.2010.2040115"},{"volume-title":"Retrieved","year":"2020","author":"Lincoln Laboratory MIT","key":"e_1_2_1_31_1"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1063\/1.5064385"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1687399.1687425"},{"key":"e_1_2_1_34_1","unstructured":"Moritz Lipp Michael Schwarz Daniel Gruss Thomas Prescher Werner Haas Stefan Mangard Paul Kocher Daniel Genkin Yuval Yarom and Mike Hamburg. 2018. Meltdown. arXiv:1801.01207.  Moritz Lipp Michael Schwarz Daniel Gruss Thomas Prescher Werner Haas Stefan Mangard Paul Kocher Daniel Genkin Yuval Yarom and Mike Hamburg. 2018. Meltdown. arXiv:1801.01207."},{"key":"e_1_2_1_36_1","first-page":"823","article-title":"Programmable low impedance anti-fuse element","volume":"4","author":"Mohsen Amr M.","year":"1989","journal-title":"US Patent"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEST.2017.8242062"},{"volume-title":"Hardware IP Security and Trust","author":"Nahiyan Adib","key":"e_1_2_1_38_1"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897937.2897992"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2011.5954999"},{"key":"e_1_2_1_41_1","first-page":"962","article-title":"Generation of engineering change order (ECO) constraints for use in selecting ECO repair techniques","volume":"7","author":"Oh Nahmsuk","year":"2011","journal-title":"US Patent"},{"volume-title":"n.d. OpenRISC OR1200 Processor. Retrieved","year":"2020","key":"e_1_2_1_42_1"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196094"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.2010.5537869"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2013.6604087"},{"volume-title":"Proceedings of the 2007 IEEE Custom Integrated Circuits Conference. 799--804","author":"Robson N.","key":"e_1_2_1_46_1"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2335155"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/DFT.2013.6653605"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2013.6657085"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-017-0001-6"},{"volume-title":"Proceedings of the 2010 NASA\/ESA Conference on Adaptive Hardware and Systems (AHS\u201910)","author":"Shiyanovskii Yuriy","key":"e_1_2_1_51_1"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2014.6855574"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/81.915390"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44709-3_7"},{"volume-title":"Integrated Reliability Workshop Final Report. IEEE","year":"2008","author":"Tonti William R.","key":"e_1_2_1_55_1"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516654"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/4.663564"},{"volume-title":"H.-S. Philip Wong, S. Simon Wong, and Subhasish Mitra.","year":"2016","author":"Wu Tony F.","key":"e_1_2_1_58_1"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2906147"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/2906147"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2013.6581564"},{"volume-title":"n.d. Virtex-7. Retrieved","year":"2020","key":"e_1_2_1_62_1"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.10"}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3396521","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3396521","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:33:28Z","timestamp":1750199608000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3396521"}},"subtitle":["Software-Based Silicon Reprogramming for Hardware Trojan Implementation"],"short-title":[],"issued":{"date-parts":[[2020,6,23]]},"references-count":61,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,7,31]]}},"alternative-id":["10.1145\/3396521"],"URL":"https:\/\/doi.org\/10.1145\/3396521","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"type":"print","value":"1084-4309"},{"type":"electronic","value":"1557-7309"}],"subject":[],"published":{"date-parts":[[2020,6,23]]},"assertion":[{"value":"2019-08-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-06-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}