Permanent Laser Fault Injection into the Flash Memory of a Microcontroller

Permanent Laser Fault Injection into the Flash Memory of a Microcontroller
复制标题

将永久激光故障注入微控制器的闪存中

DOI:
--
复制
发表时间:
2021
期刊:
IEEE International New Circuits and Systems Conference
影响因子:
--
通讯作者:
Pierre
Pierre
中科院分区:
--
文献类型:
--
作者:
R. Viera;J. Dutertre;Mathieu Dumont;Pierre

文献摘要

被引文献

相似文献

微控制器单元(MCU)的闪存是其攻击面的重要组成部分,因为它包含固件和与安全相关的数据(如密码和密钥)。最近的研究工作报告了使用激光故障注入(LFI)在运行时通过在闪存的读取操作期间锁定闪存来损坏固件(从闪存读取数据也出现故障)。这些故障是在单个位上引起的,遵循位集故障模型,是非永久性的:存储在闪存中的数据保持不变,而只有它们的读取副本被损坏。我们报告了该故障模型在32位MCU的闪存上的扩展。使用LFI,我们能够在其闪存中引入永久性故障。遵循位重置故障模型的单位故障是在闪存写入操作期间引发的。作为概念验证,我们描述了如何使用相对要求不高的设置(光束直径15微米,S脉冲持续时间3微米)使用激光脉冲将32位密码的所有位迭代设置为零。
The Flash memory of a Microcontroller Unit (MCU) is an important part of its attack surface as it contains its firmware and its security related data (e.g. passwords and cryptographic keys). Recent research works report the use of Laser Fault Injections (LFI) to corrupt the firmware at run time by targeting the Flash memory during its read operations (data reads from Flash were also faulted). These faults, induced on a single bit and following a bit-set fault model, were non-permanent: the data stored in Flash stayed unaltered while only their read copies were corrupted. We report an extension of this fault model on the Flash memory of a 32-bit MCU. Using LFI, we were able to induce permanent faults into its Flash. Single bit faults, that followed a bit-reset fault model, were induced during the Flash write operations. As a proof of concept, we describe how we were able to iteratively set to zero all the bits of a 32-bit password using a laser pulse with relatively undemanding settings (15 µm beam diameter, and 3 µs pulse duration).