The US wants YOU to help verify chip integrity

The US government’s intelligence community research arm, the Intelligence Advanced Research Projects Agency or IARPA, is responsible for verifying the integrity of chips procured by the government and destined for mission critical national security applications. They are well aware that foreign suppliers can adulterate the supply of mission critical chips in various ways, including designing chips for premature failure or with backdoors which would allow them to be disabled in-system at a future time by a foreign power for its stategic purposes.

Now IARPA is looking for proposals from serious hackers and reverse engineers to help them with their Trusted Integrated Circuit (TIC) program. They are hosting a Proposers’ Day Conference for the TIC Program on July 27, 2011 in anticipation of the release of a new solicitation in support of the program. The Conference will be held from 8:30 am to 3:30 pm in the Washington, D.C., metropolitan area. The purpose of the conference will be to provide information on the TIC Program, to address questions from potential proposers, and to provide a forum for potential proposers to present their capabilities for teaming opportunities.

You can read the US government’s announcement regarding this program here.

Via Wired.

Join the Conversation

7 Comments

  1. So hackers are useful because the free market can not be trusted??

    but to hack or reverse engineer in most cases can lead to legal action… pass!

  2. I find this stupid, with the resorces the US gov has, they can easily open every chip they buy and scan every semicondictor in ther with high power microscopes, and get full schematics, that can be checked for back doors.

  3. @arakis

    What a waste, with their resources they could easily manufacture their own chips for cheaper than checking the ones from China. Heck, I have limited resources and I *might* be close to making my own chips.

  4. I’m pretty sure it is not feasible to check any significant numbers of ICs directly, even for the US Gov’t. Reverse-engineering one complete CPU might be the work of several people for some months, or more. I suspect that a complete check for backdoors in a complex system is infeasible. Consider, for example, Windows (any version), and the history of viruses and trojans. Probably just design oversights, instead of intentional backdoors, but the end result is similar.

  5. Derrrrrr,
    They are just trying to grab a list of the top chip hackers and ideas, a bit like setting a challenge for programmer morons to hack a computer system.
    Quickest way to grab intel on the hackers ability, and who they need to keep an eye on.
    There are more than enough research papers written by professors & Dr’s on this subject.

  6. I think that everyone thinks that this one is clear cut. If you can’t trust your supply chain, or your design chain, you have to own it yourself. COTS parts are great for everything but when you really, really can’t trust anyone else.

    I think that they’d be better off licensing designs from someone that they kind-of trust, and do their own independent verification, test and to use a captive manufacturer to produce what they need. And maybe that’s not even enough if you’re ultra-paranoid. After all, it only takes one well-placed trace, or spurious assignment, to compromise a design, especially if you (don’t) know what you’re doing.

  7. It’s so interesting looking back at this pre-Snowden-NSA-leaks article and the comments section.

    I wonder if they were simply checking their own work.

    *snicker*

    (also, thanks for not closing comments after a period of time, like some, more idiotic sites.)

Leave a comment

Your email address will not be published. Required fields are marked *

Notify me of followup comments via e-mail. You can also subscribe without commenting.