Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems
Paul Staat, Johannes Tobisch, Christian T. Zenger, Christof Paar
Abstract
A whole range of attacks becomes possible when adversaries gain physical access to computing systems that process or contain sensitive data. Examples include side-channel analysis, bus probing, device cloning, or implanting hardware Trojans. Defending against these kinds of attacks is considered a challenging endeavor, requiring anti-tamper solutions to monitor the physical environment of the system. Current solutions range from simple switches, which detect if a case is opened, to meshes of conducting material that provide more fine-grained detection of integrity violations. However, these solutions suffer from an intricate trade-off between physical security on the one side and reliability, cost, and difficulty to manufacture on the other.In this work, we demonstrate that radio wave propagation in an enclosed system of complex geometry is sensitive against adversarial physical manipulation. We present an anti-tamper radio (ATR) solution as a method for tamper detection, which combines high detection sensitivity and reliability with ease-of-use. ATR constantly monitors the wireless signal propagation behavior within the boundaries of a metal case. Tamper attempts such as insertion of foreign objects, will alter the observed radio signal response, subsequently raising an alarm.The ATR principle is applicable in many computing systems that require physical security such as servers, ATMs, and smart meters. As a case study, we use 19” servers and thoroughly investigate capabilities and limits of the ATR. Using a custom-built automated probing station, we simulate probing attacks by inserting needles with high precision into protected environments. Our experimental results show that our ATR implementation can detect 16mm insertions of needles of diameter as low as 0.1mm under ideal conditions. In the more realistic environment of a running 19” server, we demonstrate reliable detection of 40mm insertions of needles of diameter 1mm for a period of 10 days.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 44823222-4829-4902-b8a0-a8eebc2aaa95Cited by top-tier papers3
- Honeycomb: Secure and Efficient GPU Executions via Static ValidationHaohui Mai, Jiacheng Zhao, Hongren Zheng, Yiyang Zhao et al.OSDI 2023 · 39 citations
- The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security InterfacesSarah Delgado Rodriguez, Maximiliane Windl, Florian Alt, Karola MarkyCHI 2025 · 5 citations
- Demystifying the Security Implications in IoT Device Rental ServicesYi He, Yunchao Guan, Ruoyu Lun, Shangru Song et al.USENIX Security 2024 · 2 citations
Builds on2
- A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and BeyondZhenyu Xu, Thomas Mauldin, Zheyi Yao, Shuyi Pei et al.ISCA 2020 · 23 citations
- The Unpatchable Silicon: A Full Break of the Bitstream Encryption of Xilinx 7-Series FPGAsMaik Ender, Amir Moradi, Christof PaarUSENIX Security 2020
Related papers
- Leveraging EM Side-Channel Information to Detect Rowhammer AttacksZhenkai Zhang, Zihao Zhan, Daniel Balasubramanian, Bo Li et al.S&P 2020 · 51 citations
- PowerRadio: Manipulate Sensor Measurement via Power GND RadiationYan Jiang, Xiaoyu Ji, Yancheng Jiang, Kai Wang et al.NDSS 2025
- Runtime Trust Evaluation and Hardware Trojan Detection Using On-Chip EM SensorsJiaji He, Xiaolong Guo, Haocheng Ma, Yanjiang Liu et al.DAC 2020 · 25 citations
- Talking to the Airgap: Exploiting Radio-Less Embedded Devices as Radio ReceiversPaul Staat, Daniel Davidovich, Christof PaarCCS 2026
- mmEcho: A mmWave-based Acoustic Eavesdropping MethodPengfei Hu, Wenhao Li, Riccardo Spolaor, Xiuzhen ChengS&P 2023
