CAPEC Definitions

    CAPEC Definitions / CAPEC-671

    CAPEC-671: Requirements for ASIC Functionality Maliciously Altered

    An adversary with access to functional requirements for an application specific integrated circuit (ASIC), a chip designed/customized for a singular particular use, maliciously alters requirements derived from originating capability needs. In the chip manufacturing process, requirements drive the chip design which, when the chip is fully manufactured, could result in an ASIC which may not meet the user’s needs, contain malicious functionality, or exhibit other anomalous behaviors thereby affecting the intended use of the ASIC.

    Severity:High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Utilize DMEA’s (Defense Microelectronics Activity) Trusted Foundry Program members for acquisition of microelectronic components.

    Ensure that each supplier performing hardware development implements comprehensive, security-focused configuration management including for hardware requirements and design.

    Require that provenance of COTS microelectronic components be known whenever procured.

    Conduct detailed vendor assessment before acquiring COTS hardware.

    Relationships with other CAPECs

    CAPEC-447: Design Alteration

    Prerequisites

    An adversary would need to have access to a foundry’s or chip maker’s requirements management system that stores customer requirements for ASICs, requirements upon which the design of the ASIC is based.

    Related Weaknesses

    No related Weaknesses found.

    CAPEC-671: Requirements for ASIC Functionality Maliciously… | CVE-DB