{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T15:52:09Z","timestamp":1784389929241,"version":"3.55.0"},"reference-count":48,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2019,8,10]],"date-time":"2019-08-10T00:00:00Z","timestamp":1565395200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JSAN"],"abstract":"<jats:p>Security of IoT devices is getting a lot of attention from researchers as they are becoming prevalent everywhere. However, implementation of hardware security in these devices has been overlooked, and many researches have mainly focused on software, network, and cloud security. A deeper understanding of hardware Trojans (HTs) and protection against them is of utmost importance right now as they are the prime threat to the hardware. This paper emphasizes the need for a secure hardware-level foundation for security of these devices, as depending on software security alone is not adequate enough. These devices must be protected against sophisticated attacks, especially if the groundwork for the attacks is already laid in devices during design or manufacturing process, such as with HTs. This paper will discuss the stealthy nature of these HT, highlight HT taxonomy and insertion methods, and provide countermeasures.<\/jats:p>","DOI":"10.3390\/jsan8030042","type":"journal-article","created":{"date-parts":[[2019,8,12]],"date-time":"2019-08-12T06:38:02Z","timestamp":1565591882000},"page":"42","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":94,"title":["Hardware Security in IoT Devices with Emphasis on Hardware Trojans"],"prefix":"10.3390","volume":"8","author":[{"given":"Simranjeet","family":"Sidhu","sequence":"first","affiliation":[{"name":"Fordham Center for Cybersecurity, Fordham University, New York, NY 10023, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9805-1740","authenticated-orcid":false,"given":"Bassam J.","family":"Mohd","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Hashemite University, Zarqa 13115, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8952-1499","authenticated-orcid":false,"given":"Thaier","family":"Hayajneh","sequence":"additional","affiliation":[{"name":"Fordham Center for Cybersecurity, Fordham University, New York, NY 10023, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2019,8,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"410","DOI":"10.1109\/JIOT.2018.2854714","article-title":"Secured Data Collection with Hardware-Based Ciphers for IoT-Based Healthcare","volume":"6","author":"Tao","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_2","unstructured":"(2019, March 09). Health IT Security. Available online: https:\/\/healthitsecurity.com\/news\/healthcare-ransomware-medical-device-security-key-2018-trends."},{"key":"ref_3","first-page":"155","article-title":"Security and privacy in the internet of things","volume":"2","author":"Maple","year":"2017","journal-title":"J. Cyber Policy Issue 2 Internet Things"},{"key":"ref_4","first-page":"e1521","article-title":"A security survey of middleware for the Internet of Things","volume":"3","author":"Fremantle","year":"2015","journal-title":"Peer J."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"35966","DOI":"10.1109\/ACCESS.2018.2848586","article-title":"Lightweight Block Ciphers for IoT: Energy Optimization and Survivability Techniques","volume":"6","author":"Hayajneh","year":"2018","journal-title":"IEEE Access"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1016\/j.jnca.2015.09.001","article-title":"A survey on lightweight block ciphers for low-resource devices: Comparative study and open issues","volume":"58","author":"Bassam","year":"2015","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2200","DOI":"10.1002\/sec.1479","article-title":"Modeling and optimization of the lightweight HIGHT block cipher design with FPGA implementation","volume":"9","author":"Bassam","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_8","first-page":"510","article-title":"Hardware Design and Modeling of Lightweight Block Ciphers for Secure Communications","volume":"83","author":"Hayajneh","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Gusmeroli, S., Piccione, S., and Rotondi, D. (2012, January 4\u20136). IoT Access Control Issues: A Capability Based Approach. Proceedings of the 6th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS-2012), Palermo, Italy.","DOI":"10.1109\/IMIS.2012.38"},{"key":"ref_10","unstructured":"(2019, March 04). University of Cincinnati. Available online: http:\/\/gauss.ececs.uc.edu\/Courses\/c6056\/pdf\/hardware.pdf."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1283","DOI":"10.1109\/JPROC.2014.2335155","article-title":"A Primer on Hardware Security: Models, Methods, and Metrics","volume":"102","author":"Rostami","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1384","DOI":"10.1109\/TCAD.2017.2753201","article-title":"Potential Trigger Detection for Hardware Trojans","volume":"37","author":"Zou","year":"2018","journal-title":"IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1007\/s41635-018-0037-2","article-title":"Surveying the Hardware Trojan Threat Landscape for the Internet-of-Things","volume":"2","author":"Venugopalan","year":"2018","journal-title":"J. Hardw. Syst. Secur."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Wang, X., Salmani, H., Tehranipoor, M., and Plusquellic, J. (2008, January 1\u20133). Hardware Trojan Detection and Isolation Using Current Integration and Localized Current Analysis. Proceedings of the IEEE International Symposium on Defect and Fault Tolerance of VLSI Systems, Boston, MA, USA.","DOI":"10.1109\/DFT.2008.61"},{"key":"ref_15","unstructured":"Kounelis, F., Sklavos, N., and Kitsos, P. (September, January 30). Run-Time Effect by Inserting Hardware Trojans, in Combinational Circuits. Proceedings of the Euromicro Conference on Digital System Design (DSD), Vienna, Austria."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Koley, S., and Ghosal, P. (2015, January 10\u201314). Addressing Hardware Security Challenges in Internet of Things: Recent Trends and Possible Solutions. Proceedings of the 12th IEEE International Conference on Advanced and Trusted Computing (UIC-ATC-ScalCom-CBDCom-IoP), Beijing, China.","DOI":"10.1109\/UIC-ATC-ScalCom-CBDCom-IoP.2015.105"},{"key":"ref_17","unstructured":"Wang, X., Tehranipoor, M., and Plusquellic, J. (2008, January 9). Detecting Malicious Inclusions in Secure Hardware: Challenges and Solutions. Proceedings of the IEEE International Workshop on Hardware-Oriented Security and Trust (HOST), Anaheim, CA, USA."},{"key":"ref_18","unstructured":"Bhunia, S., Narasimhan, S., and Chakraborty, R. (2009, January 4\u20136). Hardware Trojan: Threats and emerging solutions. Proceedings of the 2009 IEEE International High Level Design Validation and Test Workshop, San Francisco, CA, USA."},{"key":"ref_19","unstructured":"Kumar, S., and Mahapatra, K. (2017, January 20). How to Protect Your Device from Hardware Trojans. Proceedings of the Real World IoT Security Conference, Bangalore, India."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1229","DOI":"10.1109\/JPROC.2014.2334493","article-title":"Hardware Trojan Attacks: Threat Analysis and Countermeasures","volume":"102","author":"Bhunia","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Yang, K., Hicks, M., Dong, Q., Austin, T., and Sylvester, D. (2016, January 22\u201326). A2: Analog Malicious Hardware. Proceedings of the IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.10"},{"key":"ref_22","unstructured":"Wang, X. (2014). Hardware Trojan Attacks: Threat Analysis and Low-Cost Countermeasures through Golden-Free Detection and Secure Design. [Master\u2019s Thesis, Case Western Reserve University]."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Jin, Y., Kupp, N., and Makris, Y. (2009, January 27). Experiences in Hardware Trojan Design and Implementation. Proceedings of the IEEE International Workshop on Hardware-Oriented Security and Trust (HOST), San Francisco, CA, USA.","DOI":"10.1109\/HST.2009.5224971"},{"key":"ref_24","first-page":"6","article-title":"Hardware Trojans: Lessons Learned after One Decade of Research","volume":"22","author":"Xiao","year":"2016","journal-title":"J. ACM Trans. Des. Autom. Electron. Syst. (TODAES)"},{"key":"ref_25","unstructured":"(2019, March 04). Chip Design. Available online: http:\/\/eecatalog.com\/chipdesign\/2018\/10\/04\/iot-security-starts-with-threat-modeling-and-security-analysis\/."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Pammu, A., Chong, K., Ho, W., and Gwee, B. (2016, January 25\u201328). Interceptive Side Channel Attack on AES-128 Wireless Communications for IoT Applications. Proceedings of the IEEE Asia Pacific Conference on Circuits and Systems (APCCAS), Jeju, Korea.","DOI":"10.1109\/APCCAS.2016.7804081"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1109\/COMST.2017.2779824","article-title":"Systematic Classification of Side-Channel Attacks: A Case Study for Mobile Devices","volume":"20","author":"Spreitzer","year":"2018","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"ref_28","first-page":"444","article-title":"RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis","volume":"Volume 3552","author":"Genkin","year":"2014","journal-title":"Annual Cryptology Conference"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Breier, J., and He, W. (2015, January 21\u201325). Multiple Fault Attack on PRESENT with a Hardware Trojan Implementation in FPGA. Proceedings of the IEEE International Workshop on Secure Internet of Things (SIoT), Vienna, Austria.","DOI":"10.1109\/SIOT.2015.15"},{"key":"ref_30","unstructured":"(2019, March 02). Search Security. Available online: https:\/\/searchsecurity.techtarget.com\/definition\/differential-power-analysis-DPA."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Lin, L., Kasper, M., Guneysu, T., Paar, C., and Burleson, W. (2009, January 6\u20139). Trojan Side-Channels: Lightweight Hardware Trojans through Side-Channel Engineering. Proceedings of the 11th International Workshop on Cryptographic Hardware and Embedded Systems CHES, Lausanne, Switzerland.","DOI":"10.1007\/978-3-642-04138-9_27"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Ender, M., Ghandali, S., Moradi, A., and Paar, C. (2017, January 3\u20137). The First Thorough Side-Channel Hardware Trojan. Proceedings of the International Conference on the Theory and Application of Cryptology and Information Security, Hong Kong, China.","DOI":"10.1007\/978-3-319-70694-8_26"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Chen, H., Wang, T., Zhang, F., Zhao, X., He, W., Xu, L., and Ma, Y. (2017). Stealthy Hardware Trojan Based Algebraic Fault Analysis of HIGHT Block Cipher. Secur. Commun. Netw.","DOI":"10.1155\/2017\/8051728"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Agrawal, D., Baktir, S., Karakoyunlu, D., Rohatgi, P., and Sunar, B. (2007, January 20\u201323). Trojan Detection using IC Fingerprinting. Proceedings of the IEEE Symposium on Security and Privacy (SP\u201907), Berkeley, CA, USA.","DOI":"10.1109\/SP.2007.36"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1850138","DOI":"10.1142\/S0218126618501384","article-title":"A Side-Channel Analysis for Hardware Trojan Detection Based on Path Delay Measurement","volume":"27","author":"Amelian","year":"2018","journal-title":"J. Circuits Syst. Comput."},{"key":"ref_36","first-page":"7","article-title":"Malicious Hardware Detection and Design for Trust: An Analysis","volume":"84","author":"Ranjani","year":"2017","journal-title":"Elektrotehniski Vestn."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Guo, X., Dutta, R., and Jin, Y. (2015, January 8\u201312). Pre-silicon security verification and validation: A formal perspective. Proceedings of the 52nd Annual Design Automation Conference, San Francisco, CA, USA.","DOI":"10.1145\/2744769.2747939"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Rooney, C., Seeam, A., and Bellekens, X. (2018). Creation and Detection of Hardware Trojans Using Non-Invasive Off-The-Shelf Technologies. Electronics, 7.","DOI":"10.3390\/electronics7070124"},{"key":"ref_39","first-page":"426","article-title":"A Survey of Hardware Trojan Threat and Defense","volume":"55","author":"Li","year":"2016","journal-title":"Integr. J."},{"key":"ref_40","unstructured":"(2019, April 09). Allerin. Available online: https:\/\/www.allerin.com\/blog\/authentication-and-device-identification-in-iot-security."},{"key":"ref_41","unstructured":"(2019, April 15). Utimaco. Available online: https:\/\/hsm.utimaco.com\/solutions\/applications\/key-injection\/."},{"key":"ref_42","unstructured":"Bajikar, S. (2002). Trusted Platform Module (TPM) Based Security on Notebook PCs\u2014White Paper, Mobile Platforms Group Intel Corporation."},{"key":"ref_43","unstructured":"(2019, April 09). Synopsys. Available online: https:\/\/www.synopsys.com\/designware-ip\/technical-bulletin\/understanding-hardware-roots-of-trust-2017q4.html."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1016\/j.jpdc.2018.04.007","article-title":"A PUF-based hardware mutual authentication protocol","volume":"119","author":"Barbareschi","year":"2018","journal-title":"J. Parallel Distrib. Comput."},{"key":"ref_45","first-page":"1","article-title":"A PUF-Based Secure Communication Protocol for IoT","volume":"16","author":"Chatterjee","year":"2017","journal-title":"ACM Trans. Embed. Comput. Syst."},{"key":"ref_46","unstructured":"Zhang, J. (2019, April 15). Physical Unclonable Function-Based Key Sharing for IoT Security. Available online: https:\/\/arxiv.org\/pdf\/1807.10884.pdf."},{"key":"ref_47","unstructured":"Mattoon, D. (2017, January 8\u201310). DICE: Foundational Trust for IoT. Proceedings of the Microsoft Flash Memory Summit, Santa Clara, CA, USA."},{"key":"ref_48","unstructured":"(2019, April 15). Electronic Design. Available online: https:\/\/www.electronicdesign.com\/embedded-revolution\/roundtable-qa-device-identity-composition-engine-dice."}],"container-title":["Journal of Sensor and Actuator Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2224-2708\/8\/3\/42\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:10:07Z","timestamp":1760188207000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2224-2708\/8\/3\/42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,8,10]]},"references-count":48,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2019,9]]}},"alternative-id":["jsan8030042"],"URL":"https:\/\/doi.org\/10.3390\/jsan8030042","relation":{},"ISSN":["2224-2708"],"issn-type":[{"value":"2224-2708","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,8,10]]}}}