Jinn: Hijacking Safe Programs with Trojans
Komail Dharsee, John Criswell
摘要
Untrusted hardware supply chains enable malicious, powerful, and permanent alterations to processors known as hardware trojans. Such hardware trojans can undermine any softwareenforced security policies deployed on top of the hardware. Existing defenses target a select set of hardware components, specifically those that implement hardware-enforced security mechanisms such as cryptographic cores, user/kernel privilege isolation, and memory protections. We observe that computing systems exercise general purpose processor logic to implement software-enforced security policies. This makes general purpose logic security critical since tampering with it could violate software-based security policies. Leveraging this insight, we develop a novel class of hardware trojans, which we dub Jinn trojans, that corrupt general-purpose hardware and can hide in many places within a processor to enable flexible and powerful high level attacks. Jinn trojans deactivate compiler-based securityenforcement mechanisms, making type-safe software vulnerable to memory-safety attacks by compromising a single bit of architectural state. We show that Jinn trojans are effective even when planted in general purpose hardware, disjoint from any hardware-enforced security components. We show that protecting hardware-enforced security logic is insufficient to keep a system secure from hardware trojans.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Improving the Ability of Thermal Radiation Based Hardware Trojan DetectionTing Su, Yaohua Wang, Shi Xu, Lusi Zhang 等USENIX Security 2024 · 被引用 5 次
- Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell LibrariesKolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos 等S&P 2026
它引用的顶会 Paper3
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin 等S&P 2016 · 被引用 242 次
- ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2020 · 被引用 35 次
- Bomberman: Defining and Defeating Hardware Ticking Timebombs at Design-timeTimothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew HicksS&P 2021 · 被引用 14 次
相关 Paper
- On the Design and Misuse of Microcoded (Embedded) Processors - A Cautionary NoteNils Albartus, Clemens Nasenberg, Florian Stolz, Marc Fyrbiak 等USENIX Security 2021
- Rethinking IC Layout Vulnerability: Simulation-Based Hardware Trojan Threat Assessment with High FidelityXinming Wei, Jiaxi Zhang, Guojie LuoS&P 2024 · 被引用 7 次
- GDSII-Guard: ECO Anti-Trojan Optimization with Exploratory Timing-Security Trade-OffsXinming Wei, Jiaxi Zhang, Guojie LuoDAC 2023 · 被引用 9 次
- Private Circuits III: Hardware Trojan-Resilience via Testing AmplificationStefan Dziembowski, Sebastian Faust, François-Xavier StandaertCCS 2016 · 被引用 27 次
- HAMLOCK: HArdware-Model LOgically Combined attacKSanskar Amgain, Daniel Lobo, Atri Chatterjee, Swarup Bhunia 等USENIX Security 2026
