<?xml version="1.0" encoding="UTF-8"?>

<modsCollection xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd">
<mods version="3.3">

<genre>conference paper</genre>

<titleInfo><title>Malicious Routing: Circumventing Bitstream-level Verification for FPGAs</title></titleInfo>


<note type="publicationStatus">published</note>



<name type="personal">
  <namePart type="given">Qazi Arbab</namePart>
  <namePart type="family">Ahmed</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">72764</identifier><description xsi:type="identifierDefinition" type="orcid">0000-0002-1837-2254</description></name>
<name type="personal">
  <namePart type="given">Tobias</namePart>
  <namePart type="family">Wiersema</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">3118</identifier></name>
<name type="personal">
  <namePart type="given">Marco</namePart>
  <namePart type="family">Platzner</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">398</identifier></name>







<name type="corporate">
  <namePart></namePart>
  <identifier type="local">78</identifier>
  <role>
    <roleTerm type="text">department</roleTerm>
  </role>
</name>



<name type="conference">
  <namePart>Design, Automation and Test in Europe Conference (DATE&apos;21)</namePart>
</name>



<name type="corporate">
  <namePart>SFB 901 - Subproject B4</namePart>
  <role><roleTerm type="text">project</roleTerm></role>
</name>
<name type="corporate">
  <namePart>SFB 901 - Project Area B</namePart>
  <role><roleTerm type="text">project</roleTerm></role>
</name>
<name type="corporate">
  <namePart>SFB 901</namePart>
  <role><roleTerm type="text">project</roleTerm></role>
</name>



<abstract lang="eng">The battle of developing hardware Trojans and corresponding countermeasures has taken adversaries towards ingenious ways of compromising hardware designs by circumventing even advanced testing and verification methods. Besides conventional methods of inserting Trojans into a design by a malicious entity, the design flow for field-programmable gate arrays (FPGAs) can also be surreptitiously compromised to assist the attacker to perform a successful malfunctioning or information leakage attack. The advanced stealthy malicious look-up-table (LUT) attack activates a Trojan only when generating the FPGA bitstream and can thus not be detected by register transfer and gate level testing and verification. However, also this attack was recently revealed by a bitstream-level proof-carrying hardware (PCH) approach. In this paper, we present a novel attack that leverages malicious routing of the inserted Trojan circuit to acquire a dormant state even in the generated and transmitted bitstream. The Trojan&apos;s payload is connected to primary inputs/outputs of the FPGA via a programmable interconnect point (PIP). The Trojan is detached from inputs/outputs during place-and-route and re-connected only when the FPGA is being programmed, thus activating the Trojan circuit without any need for a trigger logic. Since the Trojan is injected in a post-synthesis step and remains unconnected in the bitstream, the presented attack can currently neither be prevented by conventional testing and verification methods nor by recent bitstream-level verification techniques.</abstract>

<relatedItem type="constituent">
  <location>
    <url displayLabel="1812.pdf">https://ris.uni-paderborn.de/download/20681/44752/1812.pdf</url>
  </location>
  <physicalDescription><internetMediaType>application/pdf</internetMediaType></physicalDescription>
</relatedItem>
<originInfo><publisher>2021 Design, Automation and Test in Europe Conference (DATE)</publisher><dateIssued encoding="w3cdtf">2021</dateIssued><place><placeTerm type="text">Alpexpo | Grenoble, France</placeTerm></place>
</originInfo>
<language><languageTerm authority="iso639-2b" type="code">eng</languageTerm>
</language>



<relatedItem type="host"><titleInfo><title>2021 Design, Automation &amp; Test in Europe Conference &amp; Exhibition (DATE)</title></titleInfo><identifier type="doi">10.23919/DATE51398.2021.9474026</identifier>
<part>
</part>
</relatedItem>


<extension>
<bibliographicCitation>
<chicago>Ahmed, Qazi Arbab, Tobias Wiersema, and Marco Platzner. “Malicious Routing: Circumventing Bitstream-Level Verification for FPGAs.” In &lt;i&gt;2021 Design, Automation &amp;#38; Test in Europe Conference &amp;#38; Exhibition (DATE)&lt;/i&gt;. Alpexpo | Grenoble, France: 2021 Design, Automation and Test in Europe Conference (DATE), 2021. &lt;a href=&quot;https://doi.org/10.23919/DATE51398.2021.9474026&quot;&gt;https://doi.org/10.23919/DATE51398.2021.9474026&lt;/a&gt;.</chicago>
<short>Q.A. Ahmed, T. Wiersema, M. Platzner, in: 2021 Design, Automation &amp;#38; Test in Europe Conference &amp;#38; Exhibition (DATE), 2021 Design, Automation and Test in Europe Conference (DATE), Alpexpo | Grenoble, France, 2021.</short>
<apa>Ahmed, Q. A., Wiersema, T., &amp;#38; Platzner, M. (2021). Malicious Routing: Circumventing Bitstream-level Verification for FPGAs. &lt;i&gt;2021 Design, Automation &amp;#38; Test in Europe Conference &amp;#38; Exhibition (DATE)&lt;/i&gt;. Design, Automation and Test in Europe Conference (DATE’21), Alpexpo | Grenoble, France. &lt;a href=&quot;https://doi.org/10.23919/DATE51398.2021.9474026&quot;&gt;https://doi.org/10.23919/DATE51398.2021.9474026&lt;/a&gt;</apa>
<ieee>Q. A. Ahmed, T. Wiersema, and M. Platzner, “Malicious Routing: Circumventing Bitstream-level Verification for FPGAs,” presented at the Design, Automation and Test in Europe Conference (DATE’21), Alpexpo | Grenoble, France, 2021, doi: &lt;a href=&quot;https://doi.org/10.23919/DATE51398.2021.9474026&quot;&gt;10.23919/DATE51398.2021.9474026&lt;/a&gt;.</ieee>
<ama>Ahmed QA, Wiersema T, Platzner M. Malicious Routing: Circumventing Bitstream-level Verification for FPGAs. In: &lt;i&gt;2021 Design, Automation &amp;#38; Test in Europe Conference &amp;#38; Exhibition (DATE)&lt;/i&gt;. 2021 Design, Automation and Test in Europe Conference (DATE); 2021. doi:&lt;a href=&quot;https://doi.org/10.23919/DATE51398.2021.9474026&quot;&gt;10.23919/DATE51398.2021.9474026&lt;/a&gt;</ama>
<bibtex>@inproceedings{Ahmed_Wiersema_Platzner_2021, place={Alpexpo | Grenoble, France}, title={Malicious Routing: Circumventing Bitstream-level Verification for FPGAs}, DOI={&lt;a href=&quot;https://doi.org/10.23919/DATE51398.2021.9474026&quot;&gt;10.23919/DATE51398.2021.9474026&lt;/a&gt;}, booktitle={2021 Design, Automation &amp;#38; Test in Europe Conference &amp;#38; Exhibition (DATE)}, publisher={2021 Design, Automation and Test in Europe Conference (DATE)}, author={Ahmed, Qazi Arbab and Wiersema, Tobias and Platzner, Marco}, year={2021} }</bibtex>
<mla>Ahmed, Qazi Arbab, et al. “Malicious Routing: Circumventing Bitstream-Level Verification for FPGAs.” &lt;i&gt;2021 Design, Automation &amp;#38; Test in Europe Conference &amp;#38; Exhibition (DATE)&lt;/i&gt;, 2021 Design, Automation and Test in Europe Conference (DATE), 2021, doi:&lt;a href=&quot;https://doi.org/10.23919/DATE51398.2021.9474026&quot;&gt;10.23919/DATE51398.2021.9474026&lt;/a&gt;.</mla>
</bibliographicCitation>
</extension>
<recordInfo><recordIdentifier>20681</recordIdentifier><recordCreationDate encoding="w3cdtf">2020-12-07T14:03:00Z</recordCreationDate><recordChangeDate encoding="w3cdtf">2023-05-11T09:16:34Z</recordChangeDate>
</recordInfo>
</mods>
</modsCollection>
