Author:
Bozzato Claudio,Focardi Riccardo,Palmarini Francesco
Abstract
Voltage fault injection is a powerful active side channel attack that modifies the execution-flow of a device by creating disturbances on the power supply line. The attack typically aims at skipping security checks or generating side-channels that gradually leak sensitive data, including the firmware code. In this paper we propose a new voltage fault injection technique that generates fully arbitrary voltage glitch waveforms using off-the-shelf and low cost equipment. To show the effectiveness of our setup, we present new, unpublished firmware extraction attacks on six microcontrollers from three major manufacturers: STMicroelectronics, Texas Instruments and Renesas Electronics that, in 2016 declared a market of $1.5 billion, $800 million and $2.5 billion on units sold, respectively. Among the presented attacks, the most challenging ones exploit multiple vulnerabilities and inject over one million glitches, heavily leveraging on the performance and repeatability of the new proposed technique. We perform a thorough evaluation of arbitrary glitch waveforms by comparing the attack performance against two other major V-FI techniques in the literature. Along a responsible disclosure policy, all the vulnerabilities have been timely reported to the manufacturers.
Publisher
Universitatsbibliothek der Ruhr-Universitat Bochum
Subject
General Earth and Planetary Sciences,General Environmental Science
Cited by
42 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Keyless Entry: Breaking and Entering eMMC RPMB with EMFI;Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks;2024-05-27
2. Practical Aspects of Physical Attacks;Cryptography and Embedded Systems Security;2024
3. Blockchain-based Runtime Attestation against Physical Fault Injection Attacks on Edge Devices;Proceedings of the Eighth ACM/IEEE Symposium on Edge Computing;2023-12-06
4. Enabling Lattice-Based Post-Quantum Cryptography on the OpenTitan Platform;Proceedings of the 2023 Workshop on Attacks and Solutions in Hardware Security;2023-11-26
5. Investigation of Voltage Fault Injection Attacks on NN Inference Utilizing NVM Based Weight Storage;2023 IEEE Asia Pacific Conference on Circuits and Systems (APCCAS);2023-11-19