USENIX Security2023Top-tier venue
Jinn: Hijacking Safe Programs with Trojans
Komail Dharsee, John Criswell
Abstract
Untrusted hardware supply chains enable malicious, powerful, and permanent alterations to processors known as hardware trojans. Such hardware trojans can undermine any softwareenforced security policies deployed on top of the hardware. Existing defenses target a select set of hardware components, specifically those that implement hardware-enforced security mechanisms such as cryptographic cores, user/kernel privilege isolation, and memory protections. We observe that computing systems exercise general purpose processor logic to implement software-enforced security policies. This makes general purpose logic security critical since tampering with it could violate software-based security policies. Leveraging this insight, we develop a novel class of hardware trojans, which we dub Jinn trojans, that corrupt general-purpose hardware and can hide in many places within a processor to enable flexible and powerful high level attacks. Jinn trojans deactivate compiler-based securityenforcement mechanisms, making type-safe software vulnerable to memory-safety attacks by compromising a single bit of architectural state. We show that Jinn trojans are effective even when planted in general purpose hardware, disjoint from any hardware-enforced security components. We show that protecting hardware-enforced security logic is insufficient to keep a system secure from hardware trojans.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f6b8439-08d0-4b64-9563-244d34374565Cited by top-tier papers2
- Improving the Ability of Thermal Radiation Based Hardware Trojan DetectionTing Su, Yaohua Wang, Shi Xu, Lusi Zhang et al.USENIX Security 2024 · 5 citations
- Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell LibrariesKolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos et al.S&P 2026
Builds on3
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin et al.S&P 2016 · 242 citations
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 35 citations
- Bomberman: Defining and Defeating Hardware Ticking Timebombs at Design-timeTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2021 · 14 citations
Related papers
- On the Design and Misuse of Microcoded (Embedded) Processors - A Cautionary NoteNils Albartus, Clemens Nasenberg, Florian Stolz, Marc Fyrbiak et al.USENIX Security 2021
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 7 citations
- GDSII-Guard: ECO Anti-Trojan Optimization with Exploratory Timing-Security Trade-OffsXinming Wei, Jiaxi Zhang, Guojie LuoDAC 2023 · 9 citations
- Private Circuits III: Hardware Trojan-Resilience via Testing AmplificationStefan Dziembowski, Sebastian Faust, François-Xavier StandaertCCS 2016 · 27 citations
- HAMLOCK: HArdware-Model LOgically Combined attacKSanskar Amgain, Daniel Lobo, Atri Chatterjee, Swarup Bhunia et al.USENIX Security 2026
