USENIX Security2025Top-tier venue
SoK: A Security Architect's View of Printed Circuit Board Attacks
Jacob Harrison, Nathan Jessurun, Mark Tehranipoor
Abstract
Many recent papers have proposed novel electrical measurements or physical inspection technologies for defending printed circuit boards (PCBs) and printed circuit board assemblies (PCBAs) against tampering. As motivation, these papers frequently cite Bloomberg News'"The Big Hack", video game modchips, and"interdiction attacks"on IT equipment. We find this trend concerning for two reasons. First, implementation errors and security architecture are rarely discussed in recent PCBA security research, even though they were the root causes of these commonly-cited attacks and most other attacks that have occurred or been proposed by researchers. This suggests that the attacks may be poorly understood. Second, if we assume that novel countermeasures and validation methodologies are tailored to these oft-cited attacks, then significant recent work has focused on attacks that can already be mitigated instead of on open problems. We write this SoK to address these concerns. We explain which tampering threats can be mitigated by PCBA security architecture. Then, we enumerate assumptions that security architecture depends on. We compare and contrast assurances achieved by security architecture vs. by recently-proposed electrical or inspection-based tamper detection. Finally, we review over fifty PCBA attacks to show how most can be prevented by proper architecture and careful implementation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d38ac04-cb74-4c9e-9006-e802e83bd1b9Builds on5
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz et al.CCS 2017 · 98 citations
- Hard Drive of Hearing: Disks that Eavesdrop with a Synthesized MicrophoneAndrew Kwong, Wenyuan Xu, Kevin FuS&P 2019 · 63 citations
- A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and BeyondZhenyu Xu, Thomas Mauldin, Zheyi Yao, Shuyi Pei et al.ISCA 2020 · 23 citations
- VIPR-PCB: a machine learning based golden-free PCB assurance frameworkAritra Bhattacharyay, Prabuddha Chakraborty, Jonathan Cruz, Swarup BhuniaDAC 2022 · 2 citations
- PCSPOOF: Compromising the Safety of Time-Triggered EthernetAndrew D. Loveless, Linh Thi Xuan Phan, Ronald G. Dreslinski, Baris KasikciS&P 2023
Related papers
- An In-Depth Analysis of Disassembly on Full-Scale x86/x64 BinariesDennis Andriesse, Xi Chen, Victor van der Veen, Asia Slowinska et al.USENIX Security 2016 · 162 citations
- SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for SecuritySanjeev Das, Jan Werner, Manos Antonakakis, Michalis Polychronakis et al.S&P 2019 · 163 citations
- Volttack: Control IoT Devices by Manipulating Power Supply VoltageKai Wang, Shilin Xiao, Xiaoyu Ji, Chen Yan et al.S&P 2023
- A Resource Binding Approach to Logic ObfuscationMichael Zuzak, Yuntao Liu, Ankur SrivastavaDAC 2021 · 15 citations
- PowerRadio: Manipulate Sensor Measurement via Power GND RadiationYan Jiang, Xiaoyu Ji, Yancheng Jiang, Kai Wang et al.NDSS 2025
