USENIX Security2021Top-tier venue
Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel Attacks
Thilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre Seifert
Abstract
The security of modern electronic devices relies on secret keys stored on secure hardware modules as the root-of-trust (RoT). Extracting those keys would break the security of the entire system. As shown before, sophisticated side-channel analysis (SCA) attacks, using chip failure analysis (FA) techniques, can extract data from on-chip memory cells. However, since the chip's layout is unknown to the adversary in practice, secret key localization and reverse engineering are onerous tasks. Consequently, hardware vendors commonly believe that the ever-growing physical complexity of the integrated circuit (IC) designs can be a natural barrier against potential adversaries. In this work, we present a novel approach that can extract the secret key without any knowledge of the IC's layout, and independent from the employed memory technology as key storage. We automate the -- traditionally very labor-intensive -- reverse engineering and data extraction process. To that end, we demonstrate that black-box measurements captured using laser-assisted SCA techniques from a training device with known key can be used to profile the device for a later key prediction on other victim devices with unknown keys. To showcase the potential of our approach, we target keys on three different hardware platforms, which are utilized as RoT in different products.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6cf4b583-a3fa-4636-9069-1901f354c5c4Cited by top-tier papers4
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- LeakyOhm: Secret Bits Extraction using Impedance AnalysisSaleh Khalaj Monfared, Tahoura Mosavirik, Shahin TajikCCS 2023 · 13 citations
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru et al.S&P 2026 · 1 citation
- On Borrowed Time - Preventing Static Side-Channel AnalysisRobert Dumitru, Thorben Moos, Andrew Wabnitz, Yuval YaromNDSS 2025
Builds on2
- On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAsShahin Tajik, Heiko Lohrke, Jean-Pierre Seifert, Christian BoitCCS 2017 · 116 citations
- Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelThilo Krachenfels, Fatemeh Ganji, Amir Moradi, Shahin Tajik et al.S&P 2021 · 42 citations
Related papers
- Interpreting Emergent Features in Deep Learning-based Side-channel AnalysisSengim Karayalcin, Marina Krcek, Stjepan PicekNeurIPS 2025
- Breaking the Blindfold: Deep Learning-based Blind Side-channel AnalysisAzade Rezaeezade, Trevor Yap, Dirmanto Jap, Shivam Bhasin et al.USENIX Security 2025
- Deep Learning Multi-Channel Fusion Attack Against Side-Channel Protected HardwareBenjamin Hettwer, Daniel Fennes, Sebastien Leger, Jan Richter-Brockmann et al.DAC 2020 · 11 citations
- Efficient and Generic Microarchitectural Hash-Function RecoveryLukas Gerlach, Simon Schwarz, Nicolas Faroß, Michael SchwarzS&P 2024 · 14 citations
- TPM-FAIL: TPM meets Timing and Lattice AttacksDaniel Moghimi, Berk Sunar, Thomas Eisenbarth, Nadia HeningerUSENIX Security 2020
