On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAs
Shahin Tajik, Heiko Lohrke, Jean-Pierre Seifert, Christian Boit
摘要
Modern Integrated Circuits (ICs) employ several classes of countermeasures to mitigate physical attacks. Recently, a powerful semiinvasive attack relying on optical contactless probing has been introduced, which can assist the attacker in circumventing the integrated countermeasures and probe the secret data on a chip. This attack can be mounted using IC debug tools from the backside of the chip. The first published attack based on this technique was conducted against a proof-of-concept hardware implementation on a Field Programmable Gate Array (FPGA). Therefore, the success of optical probing techniques against a real commercial device without any knowledge of the hardware implementation is still questionable. The aim of this work is to assess the threat of optical contactless probing in a real attack scenario. To this end, we conduct an optical probing attack against the bitstream encryption feature of a common FPGA. We demonstrate that the adversary is able to extract the plaintext data containing sensitive design information and intellectual property (IP). In contrast to previous optical attacks from the IC backside, our attack does not require any device preparation or silicon polishing, which makes it a non-invasive attack. Additionally, we debunk the myth that small technology sizes are unsusceptible to optical attacks, as we use an optical resolution of about 1 µm to successfully attack a 28 nm device. Based on our time measurements, an attacker needs less than 10 working days to conduct the optical analysis and reverse-engineer the security-related parts of the hardware. Finally, we propose and discuss potential countermeasures, which could make the attack more challenging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 被引用 301 次
- Real-World Snapshots vs. Theory: Questioning the t-Probing Security ModelThilo Krachenfels, Fatemeh Ganji, Amir Moradi, Shahin Tajik 等S&P 2021 · 被引用 42 次
- Automatic Extraction of Secrets from the Transistor Jungle using Laser-Assisted Side-Channel AttacksThilo Krachenfels, Tuba Kiyan, Shahin Tajik, Jean-Pierre SeifertUSENIX Security 2021 · 被引用 40 次
- Does logic locking work with EDA tools?Zhaokun Han, Muhammad Yasin, Jeyavijayan (JV) RajendranUSENIX Security 2021 · 被引用 35 次
- Chypnosis: Undervolting-based Static Side-channel AttacksKyle Mitard, Saleh Khalaj Monfared, Fatemeh Khojasteh Dana, Robert Dumitru 等S&P 2026 · 被引用 1 次
相关 Paper
- The Unpatchable Silicon: A Full Break of the Bitstream Encryption of Xilinx 7-Series FPGAsMaik Ender, Amir Moradi, Christof PaarUSENIX Security 2020
- FuncTeller: How Well Does eFPGA Hide Functionality?Zhaokun Han, Mohammed Shayan, Aneesh Dixit, Mustafa M. Shihab 等USENIX Security 2023
- Stealing Maggie's Secrets-On the Challenges of IP Theft Through FPGA Reverse EngineeringSimon Klix, Nils Albartus, Julian Speith, Paul Staat 等CCS 2024 · 被引用 5 次
- ROPAD: A Fully Digital Highly Predictive Ring Oscillator Probing Attempt DetectorSeyed Hamidreza Moghadas, Michael PehlDAC 2020 · 被引用 1 次
- Side-Channel-Assisted Reverse-Engineering of Encrypted DNN Hardware Accelerator IP and Attack Surface ExplorationCheng Gongye, Yukui Luo, Xiaolin Xu, Yunsi FeiS&P 2024 · 被引用 25 次
