191
Bypassing Secure Boot using Fault Injection Niek Timmers [email protected] (@tieknimmers) Albert Spruyt [email protected] November 4, 2016

Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers [email protected] (@tieknimmers)Albert Spruyt [email protected]

  • Upload
    others

  • View
    26

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Bypassing Secure Boot using Fault Injection

Niek [email protected]

(@tieknimmers)

Albert [email protected]

November 4, 2016

Page 2: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

What are the contents of this talk?

Keywords – fault injection, secure boot, bypasses, mitigations,practicalities, best practices, demo(s) ...

Page 3: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Who are we?Albert & Niek

• (Senior) Security Analysts at Riscure• Security testing of different products and technologies

Riscure• Services (Security Test Lab)

• Hardware / Software / Crypto• Embedded systems / Smart cards

• Tools• Side channel analysis (passive)• Fault injection (active)

• Offices• Delft, The Netherlands / San Francisco, USA

Combining services and tools for fun and profit!

Page 4: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Who are we?Albert & Niek

• (Senior) Security Analysts at Riscure• Security testing of different products and technologies

Riscure• Services (Security Test Lab)

• Hardware / Software / Crypto• Embedded systems / Smart cards

• Tools• Side channel analysis (passive)• Fault injection (active)

• Offices• Delft, The Netherlands / San Francisco, USA

Combining services and tools for fun and profit!

Page 5: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Who are we?Albert & Niek

• (Senior) Security Analysts at Riscure• Security testing of different products and technologies

Riscure• Services (Security Test Lab)

• Hardware / Software / Crypto• Embedded systems / Smart cards

• Tools• Side channel analysis (passive)• Fault injection (active)

• Offices• Delft, The Netherlands / San Francisco, USA

Combining services and tools for fun and profit!

Page 6: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – A definition...

”Introducing faults in a target to alter its intended behavior.”

...if( key_is_correct ) <-- Glitch here!{

open_door();}else{

keep_door_closed();}...

How can we introduce these faults?

Page 7: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – A definition...

”Introducing faults in a target to alter its intended behavior.”

...if( key_is_correct ) <-- Glitch here!{open_door();

}else{keep_door_closed();

}...

How can we introduce these faults?

Page 8: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – A definition...

”Introducing faults in a target to alter its intended behavior.”

...if( key_is_correct ) <-- Glitch here!{open_door();

}else{keep_door_closed();

}...

How can we introduce these faults?

Page 9: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – A definition...

”Introducing faults in a target to alter its intended behavior.”

...if( key_is_correct ) <-- Glitch here!{open_door();

}else{keep_door_closed();

}...

How can we introduce these faults?

Page 10: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault injection techniques1

clock voltage e-magnetic laser

Remark• All techniques introduce faults externally

1The Sorcerers Apprentice Guide to Fault Attacks. – Bar-El et al., 2004

Page 11: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault injection techniques1

clock voltage e-magnetic laser

Remark• All techniques introduce faults externally

1The Sorcerers Apprentice Guide to Fault Attacks. – Bar-El et al., 2004

Page 12: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Voltage fault injection

• Pull the voltage down at the right moment• Not ’too soft’ ; Not ’too hard’

Source: http://www.limited-entropy.com/fault-injection-techniques/

Page 13: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault models

Faults that affect hardware• Registers• Buses

Faults that affect hardware that does software2 3 4

• Instruction corruption• Data corruption

The true fault model is hard to predict or prove!

2Fault Model Analysis of Laser-Induced Faults in SRAM Memory Cells – Roscian et. al., 2015

3High Precision Fault Injections on the Instruction Cache of ARMv7-M Architectures – Riviere et al., 2015

4Formal verification of a software countermeasure against instruction skip attacks – Moro et. al., 2014

Page 14: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault models

Faults that affect hardware• Registers• Buses

Faults that affect hardware that does software2 3 4

• Instruction corruption• Data corruption

The true fault model is hard to predict or prove!

2Fault Model Analysis of Laser-Induced Faults in SRAM Memory Cells – Roscian et. al., 2015

3High Precision Fault Injections on the Instruction Cache of ARMv7-M Architectures – Riviere et al., 2015

4Formal verification of a software countermeasure against instruction skip attacks – Moro et. al., 2014

Page 15: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault models

Faults that affect hardware• Registers• Buses

Faults that affect hardware that does software2 3 4

• Instruction corruption• Data corruption

The true fault model is hard to predict or prove!

2Fault Model Analysis of Laser-Induced Faults in SRAM Memory Cells – Roscian et. al., 2015

3High Precision Fault Injections on the Instruction Cache of ARMv7-M Architectures – Riviere et al., 2015

4Formal verification of a software countermeasure against instruction skip attacks – Moro et. al., 2014

Page 16: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault models

Faults that affect hardware• Registers• Buses

Faults that affect hardware that does software2 3 4

• Instruction corruption• Data corruption

The true fault model is hard to predict or prove!

2Fault Model Analysis of Laser-Induced Faults in SRAM Memory Cells – Roscian et. al., 2015

3High Precision Fault Injections on the Instruction Cache of ARMv7-M Architectures – Riviere et al., 2015

4Formal verification of a software countermeasure against instruction skip attacks – Moro et. al., 2014

Page 17: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 18: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 19: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 20: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 21: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 22: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 23: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Models – ”Our” choice ...

When presented with code: instruction corruption.

Simple (MIPS)

addi $t1, $t1, 8 00100001001010010000000000001000addi $t1, $t1, 0 00100001001010010000000000000000

Complex (ARM)

ldr w1, [sp, #0x8] 10111001010000000000101111100001str w7, [sp, #0x20] 10111001000000000010001111100111

Remarks• Limited control over which bit(s) will be corrupted• May or may not be the true fault model• Other fault model behavior covered

Page 24: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why is there Secure Boot?

Remarks• Integrity and confidentiality of flash contents are not assured!• A mechanism is required for this assurance: secure boot

Page 25: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why is there Secure Boot?

Remarks• Integrity and confidentiality of flash contents are not assured!• A mechanism is required for this assurance: secure boot

Page 26: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why is there Secure Boot?

Remarks• Integrity and confidentiality of flash contents are not assured!• A mechanism is required for this assurance: secure boot

Page 27: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why is there Secure Boot?

Remarks• Integrity and confidentiality of flash contents are not assured!• A mechanism is required for this assurance: secure boot

Page 28: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why is there Secure Boot?

Remarks• Integrity and confidentiality of flash contents are not assured!• A mechanism is required for this assurance: secure boot

Page 29: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Generic Design

• Assures integrity (and confidentiality) of flash contents• The chain of trust is similar to PKI5 found in browsers• One root of trust composed of immutable code and key5

Public Key Infrastructure

Page 30: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Generic Design

• Assures integrity (and confidentiality) of flash contents• The chain of trust is similar to PKI5 found in browsers• One root of trust composed of immutable code and key5

Public Key Infrastructure

Page 31: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Generic Design

• Assures integrity (and confidentiality) of flash contents• The chain of trust is similar to PKI5 found in browsers• One root of trust composed of immutable code and key5

Public Key Infrastructure

Page 32: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Generic Design

• Assures integrity (and confidentiality) of flash contents• The chain of trust is similar to PKI5 found in browsers• One root of trust composed of immutable code and key5

Public Key Infrastructure

Page 33: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – In reality ...

Source: http://community.arm.com/docs/DOC-9306

Page 34: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – In reality ...

Source: http://community.arm.com/docs/DOC-9306

Page 35: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 36: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 37: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 38: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 39: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 40: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 41: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why use a hardware attack?

”Logical issues exist in secure boot implementations!!?”

Bootloader vulnerabilities• S5L8920 (iPhone)6

• Amlogic S9057

However• Small code base results in a small logical attack surface• Implementations without vulnerabililties likely exist

Other attack(s) must be used when not logically flawed!

6https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow

7http://www.fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html

Page 42: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why (not) fault injection on secure boot?

Cons• Invasive• Physical access• Expensive

Pros• No logical vulnerability required• Typical targets not properly protected

Especially relevant when assets are not available after boot!

Page 43: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why (not) fault injection on secure boot?

Cons• Invasive• Physical access• Expensive

Pros• No logical vulnerability required• Typical targets not properly protected

Especially relevant when assets are not available after boot!

Page 44: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why (not) fault injection on secure boot?

Cons• Invasive• Physical access• Expensive

Pros• No logical vulnerability required• Typical targets not properly protected

Especially relevant when assets are not available after boot!

Page 45: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Why (not) fault injection on secure boot?

Cons• Invasive• Physical access• Expensive

Pros• No logical vulnerability required• Typical targets not properly protected

Especially relevant when assets are not available after boot!

Page 46: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Typical assets

Secure code• Boot code (ROM8)

Secrets• Keys (for boot code decryption)

Secure hardware• Cryptographic engines

8Read Only Memory

Page 47: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Typical assets

Secure code• Boot code (ROM8)

Secrets• Keys (for boot code decryption)

Secure hardware• Cryptographic engines

8Read Only Memory

Page 48: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Typical assets

Secure code• Boot code (ROM8)

Secrets• Keys (for boot code decryption)

Secure hardware• Cryptographic engines

8Read Only Memory

Page 49: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Typical assets

Secure code• Boot code (ROM8)

Secrets• Keys (for boot code decryption)

Secure hardware• Cryptographic engines

8Read Only Memory

Page 50: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Intermezzo

Page 51: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Tooling

Micah posted a very nice video using the ChipWhisperer-Lite9

By NewAE Technology Inc.10

9https://www.youtube.com/watch?v=TeCQatNcF20

10https://wiki.newae.com/CW1173_ChipWhisperer-Lite

Page 52: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Tooling

Micah posted a very nice video using the ChipWhisperer-Lite9

By NewAE Technology Inc.10

9https://www.youtube.com/watch?v=TeCQatNcF20

10https://wiki.newae.com/CW1173_ChipWhisperer-Lite

Page 53: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Setup

Target• Digilent Zybo (Xilinx Zynq-7010 System-on-Chip)• ARM Cortex-A9 (AArch32)

Page 54: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Setup

Target• Digilent Zybo (Xilinx Zynq-7010 System-on-Chip)• ARM Cortex-A9 (AArch32)

Page 55: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Setup

Page 56: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Characterization – Test application11

asm volatile

(..."add r1, r1, #1;"

"add r1, r1, #1;"

< repeat > <-- glitch here"add r1, r1, #1;"

"add r1, r1, #1;"

...);

Remarks• Full control over the target• Increasing a counter using ADD instructions• Send counter back using the serial interface

11Implemented as an U-Boot command

Page 57: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Characterization – Possible responses

Expected: ’too soft’counter = 00010000

Mute: ’too hard’counter =

Success: ’$$$’counter = 00009999counter = 00010015counter = 00008687

Remarks• Glitching ’too hard’ may damage the target permanently

Page 58: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Characterization – Possible responses

Expected: ’too soft’counter = 00010000

Mute: ’too hard’counter =

Success: ’$$$’counter = 00009999counter = 00010015counter = 00008687

Remarks• Glitching ’too hard’ may damage the target permanently

Page 59: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Characterization – Possible responses

Expected: ’too soft’counter = 00010000

Mute: ’too hard’counter =

Success: ’$$$’counter = 00009999counter = 00010015counter = 00008687

Remarks• Glitching ’too hard’ may damage the target permanently

Page 60: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Characterization – Possible responses

Expected: ’too soft’counter = 00010000

Mute: ’too hard’counter =

Success: ’$$$’counter = 00009999counter = 00010015counter = 00008687

Remarks• Glitching ’too hard’ may damage the target permanently

Page 61: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Characterization – Possible responses

Expected: ’too soft’counter = 00010000

Mute: ’too hard’counter =

Success: ’$$$’counter = 00009999counter = 00010015counter = 00008687

Remarks• Glitching ’too hard’ may damage the target permanently

Page 62: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 1PARAMETER SEARCH

Glitch parameters• Randomize glitch delay within the attack window• Randomize the glitch voltage• Randomize the glitch length

Page 63: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 1PARAMETER SEARCH

Glitch parameters• Randomize glitch delay within the attack window• Randomize the glitch voltage• Randomize the glitch length

Page 64: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 1PARAMETER SEARCH

Glitch parameters• Randomize glitch delay within the attack window• Randomize the glitch voltage• Randomize the glitch length

Page 65: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 1PARAMETER SEARCH

Glitch parameters• Randomize glitch delay within the attack window• Randomize the glitch voltage• Randomize the glitch length

Page 66: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

That was the introduction ...

... let’s bypass secure boot: The Classics!

Page 67: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

That was the introduction ...

... let’s bypass secure boot: The Classics!

Page 68: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

• Applicable to all secure boot implementations• Bypass of authentication

if( memcmp( p, hash, hashlen ) != 0 )return( MBEDTLS_ERR_RSA_VERIFY_FAILED );

p += hashlen;

if( p != end )return( MBEDTLS_ERR_RSA_VERIFY_FAILED );

return( 0 );

Source: https://tls.mbed.org/

Page 69: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

• Applicable to all secure boot implementations• Bypass of authentication

if( memcmp( p, hash, hashlen ) != 0 )return( MBEDTLS_ERR_RSA_VERIFY_FAILED );

p += hashlen;

if( p != end )return( MBEDTLS_ERR_RSA_VERIFY_FAILED );

return( 0 );

Source: https://tls.mbed.org/

Page 70: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

• Applicable to all secure boot implementations• Bypass of authentication

if( memcmp( p, hash, hashlen ) != 0 )return( MBEDTLS_ERR_RSA_VERIFY_FAILED );

p += hashlen;

if( p != end )return( MBEDTLS_ERR_RSA_VERIFY_FAILED );

return( 0 );

Source: https://tls.mbed.org/

Page 71: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

Multiple locations bypass the check with a single fault!

Page 72: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

Multiple locations bypass the check with a single fault!

Page 73: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

Multiple locations bypass the check with a single fault!

Page 74: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

Multiple locations bypass the check with a single fault!

Page 75: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 00: Hash comparison

Multiple locations bypass the check with a single fault!

Page 76: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 01: Signature check call

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {/* do not boot up the image */

no_boot();} else {

/* boot up the image */

boot();}

Remarks• Bypasses can happen on all levels• Inside functions, inside the calling functions, etc.

Page 77: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 01: Signature check call

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {/* do not boot up the image */

no_boot();} else {

/* boot up the image */

boot();}

Remarks• Bypasses can happen on all levels• Inside functions, inside the calling functions, etc.

Page 78: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 01: Signature check call

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {/* do not boot up the image */

no_boot();} else {

/* boot up the image */

boot();}

Remarks• Bypasses can happen on all levels• Inside functions, inside the calling functions, etc.

Page 79: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

• What to do when the signature verification fails?• Enter an infinite loop!

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {

/* do not boot up the image */

while(1);

} else {

/* boot up the image */

boot();}

Page 80: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

• What to do when the signature verification fails?• Enter an infinite loop!

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {

/* do not boot up the image */

while(1);

} else {

/* boot up the image */

boot();}

Page 81: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

• What to do when the signature verification fails?• Enter an infinite loop!

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {

/* do not boot up the image */

while(1);

} else {

/* boot up the image */

boot();}

Page 82: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

• What to do when the signature verification fails?• Enter an infinite loop!

/* glitch here */

if(mbedtls_pk_verify(&k, SHA256, h, hs, s, ss)) {

/* do not boot up the image */

while(1);

} else {

/* boot up the image */

boot();}

Page 83: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

Remarks• Timing is not an issue!• Classic smart card attack 12

• Better to reset or wipe keys

12https://en.wikipedia.org/wiki/Unlooper

Page 84: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

Remarks• Timing is not an issue!• Classic smart card attack 12

• Better to reset or wipe keys

12https://en.wikipedia.org/wiki/Unlooper

Page 85: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

Remarks• Timing is not an issue!• Classic smart card attack 12

• Better to reset or wipe keys

12https://en.wikipedia.org/wiki/Unlooper

Page 86: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

Remarks• Timing is not an issue!• Classic smart card attack 12

• Better to reset or wipe keys

12https://en.wikipedia.org/wiki/Unlooper

Page 87: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 02: Infinite loop

Remarks• Timing is not an issue!• Classic smart card attack 12

• Better to reset or wipe keys

12https://en.wikipedia.org/wiki/Unlooper

Page 88: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Classic Bypass 03: Secure boot enable

• Secure boot often enabled/disabled based on OTP13 bit• No secure boot during development; secure boot in the field• Typically just after the CPU comes out of reset

13One-Time-Programmable memory

Page 89: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Mitigations

Hardware countermeasures 14 15

• Detect the glitch or fault

Software countermeasures 16

• Lower the probability of a successful fault• Do not address the root cause

You can lower the probability but not rule it out!

14The Sorcerers Apprentice Guide to Fault Attacks – Bar-El et al., 2004

15The Fault Attack Jungle - A Classification Model to Guide You – Verbauwhede et al., 2011

16Secure Application Programming in the Presence of Side Channel Attacks – Witteman

Page 90: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Mitigations

Hardware countermeasures 14 15

• Detect the glitch or fault

Software countermeasures 16

• Lower the probability of a successful fault• Do not address the root cause

You can lower the probability but not rule it out!

14The Sorcerers Apprentice Guide to Fault Attacks – Bar-El et al., 2004

15The Fault Attack Jungle - A Classification Model to Guide You – Verbauwhede et al., 2011

16Secure Application Programming in the Presence of Side Channel Attacks – Witteman

Page 91: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Mitigations

Hardware countermeasures 14 15

• Detect the glitch or fault

Software countermeasures 16

• Lower the probability of a successful fault• Do not address the root cause

You can lower the probability but not rule it out!

14The Sorcerers Apprentice Guide to Fault Attacks – Bar-El et al., 2004

15The Fault Attack Jungle - A Classification Model to Guide You – Verbauwhede et al., 2011

16Secure Application Programming in the Presence of Side Channel Attacks – Witteman

Page 92: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Mitigations

Hardware countermeasures 14 15

• Detect the glitch or fault

Software countermeasures 16

• Lower the probability of a successful fault• Do not address the root cause

You can lower the probability but not rule it out!

14The Sorcerers Apprentice Guide to Fault Attacks – Bar-El et al., 2004

15The Fault Attack Jungle - A Classification Model to Guide You – Verbauwhede et al., 2011

16Secure Application Programming in the Presence of Side Channel Attacks – Witteman

Page 93: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Mitigations

Hardware countermeasures 14 15

• Detect the glitch or fault

Software countermeasures 16

• Lower the probability of a successful fault• Do not address the root cause

You can lower the probability but not rule it out!

14The Sorcerers Apprentice Guide to Fault Attacks – Bar-El et al., 2004

15The Fault Attack Jungle - A Classification Model to Guide You – Verbauwhede et al., 2011

16Secure Application Programming in the Presence of Side Channel Attacks – Witteman

Page 94: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Fault Injection – Mitigations

Hardware countermeasures 14 15

• Detect the glitch or fault

Software countermeasures 16

• Lower the probability of a successful fault• Do not address the root cause

You can lower the probability but not rule it out!

14The Sorcerers Apprentice Guide to Fault Attacks – Bar-El et al., 2004

15The Fault Attack Jungle - A Classification Model to Guide You – Verbauwhede et al., 2011

16Secure Application Programming in the Presence of Side Channel Attacks – Witteman

Page 95: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler optimizations

Why?• ROM memory size is limited• Compiler optimizations decrease code size

Compiler optimizes out intended code!

Page 96: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler optimizations

Why?• ROM memory size is limited• Compiler optimizations decrease code size

Compiler optimizes out intended code!

Page 97: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler optimizations

Why?• ROM memory size is limited• Compiler optimizations decrease code size

Compiler optimizes out intended code!

Page 98: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimization’ – Double check

Example of a double check

unsigned int compare(char * input, int len){

if(memcmp(password, input, len) == 0) <-- 1st{

if(memcmp(password, input, len) == 0) <-- 2nd{

return TRUE;}

}return FALSE;

}

Page 99: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimization’ – Double check

Compiled without optimizations

Page 100: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimization’ – Double check

Compiled with optimizations

Page 101: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimizations’ – Best practices

• Your compiler is smarter than you

• Use ’volatile’ to prevent compiler problems

• Read the output of the compiler!

Page 102: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimizations’ – Best practices

• Your compiler is smarter than you

• Use ’volatile’ to prevent compiler problems

• Read the output of the compiler!

Page 103: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimizations’ – Best practices

• Your compiler is smarter than you

• Use ’volatile’ to prevent compiler problems

• Read the output of the compiler!

Page 104: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimizations’ – Best practices

• Your compiler is smarter than you

• Use ’volatile’ to prevent compiler problems

• Read the output of the compiler!

Page 105: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimization’ – Pointer setup

Example of a double check using ’volatile’

int checkSecureBoot( ){volatile int * otp_secure_boot = OTP_SECURE_BOOT;

if( (*otp_secure_boot >> 7) & 0x1 ){ <-- 1streturn 0;

}else{if( (*otp_secure_boot >> 7) & 0x1 ){ <-- 2nd

return 0;}else{

return 1;}

}}

Page 106: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimization’ – Pointer setup

Compiled with optimizations

Page 107: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Compiler ’optimization’ – Pointer setup

Compiled with optimizations

Page 108: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined Attacks

Those were the classics and their mitigations ..

... the attack surface is larger!17

17All attacks have been performed successfully on multiple targets!

Page 109: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined Attacks

Those were the classics and their mitigations ..

... the attack surface is larger!17

17All attacks have been performed successfully on multiple targets!

Page 110: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

• Introducing logical vulnerabilities using fault injection• Build your own buffer overflow!

• Easy approach: change memcpy the size argument

Before corruption

memcpy(dst, src, 0x1000);

After corruption

memcpy(dst, src, 0xCEE5);

Remark• Works when dedicated hardware is used

(e.g. DMA18 engines)

18Direct Memory Access

Page 111: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

• Introducing logical vulnerabilities using fault injection• Build your own buffer overflow!

• Easy approach: change memcpy the size argument

Before corruption

memcpy(dst, src, 0x1000);

After corruption

memcpy(dst, src, 0xCEE5);

Remark• Works when dedicated hardware is used

(e.g. DMA18 engines)

18Direct Memory Access

Page 112: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

• Introducing logical vulnerabilities using fault injection• Build your own buffer overflow!

• Easy approach: change memcpy the size argument

Before corruption

memcpy(dst, src, 0x1000);

After corruption

memcpy(dst, src, 0xCEE5);

Remark• Works when dedicated hardware is used

(e.g. DMA18 engines)

18Direct Memory Access

Page 113: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

• Introducing logical vulnerabilities using fault injection• Build your own buffer overflow!

• Easy approach: change memcpy the size argument

Before corruption

memcpy(dst, src, 0x1000);

After corruption

memcpy(dst, src, 0xCEE5);

Remark• Works when dedicated hardware is used

(e.g. DMA18 engines)

18Direct Memory Access

Page 114: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

• Introducing logical vulnerabilities using fault injection• Build your own buffer overflow!

• Easy approach: change memcpy the size argument

Before corruption

memcpy(dst, src, 0x1000);

After corruption

memcpy(dst, src, 0xCEE5);

Remark• Works when dedicated hardware is used

(e.g. DMA18 engines)

18Direct Memory Access

Page 115: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

Remark• Targetting the copy function arguments

Page 116: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

Remark• Targetting the copy function arguments

Page 117: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

Remark• Targetting the copy function arguments

Page 118: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

Remark• Targetting the copy function arguments

Page 119: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

Remark• Targetting the copy function arguments

Page 120: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack – Copy

Remark• Targetting the copy function arguments

Page 121: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM20

• Exploits an ARM32 characteristic• PC19 register is directly accessible by most instructions

Multi-word copy

LDMIA r1!, {r3 - r10}STMIA r0!, {r3 - r10}

Controlling PC using LDMIA

LDMIA r1!,{r3-r10} 11101000101100010000011111111000LDMIA r1!,{r3-r10,PC} 11101000101100011000011111111000

• Variations possible on other architectures; code dependent

19Program Counter

20Controlling PC on ARM using Fault Injection – Timmers et al., 2016

Page 122: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM20

• Exploits an ARM32 characteristic• PC19 register is directly accessible by most instructions

Multi-word copy

LDMIA r1!, {r3 - r10}STMIA r0!, {r3 - r10}

Controlling PC using LDMIA

LDMIA r1!,{r3-r10} 11101000101100010000011111111000LDMIA r1!,{r3-r10,PC} 11101000101100011000011111111000

• Variations possible on other architectures; code dependent

19Program Counter

20Controlling PC on ARM using Fault Injection – Timmers et al., 2016

Page 123: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM20

• Exploits an ARM32 characteristic• PC19 register is directly accessible by most instructions

Multi-word copy

LDMIA r1!, {r3 - r10}STMIA r0!, {r3 - r10}

Controlling PC using LDMIA

LDMIA r1!,{r3-r10} 11101000101100010000011111111000LDMIA r1!,{r3-r10,PC} 11101000101100011000011111111000

• Variations possible on other architectures; code dependent

19Program Counter

20Controlling PC on ARM using Fault Injection – Timmers et al., 2016

Page 124: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM20

• Exploits an ARM32 characteristic• PC19 register is directly accessible by most instructions

Multi-word copy

LDMIA r1!, {r3 - r10}STMIA r0!, {r3 - r10}

Controlling PC using LDMIA

LDMIA r1!,{r3-r10} 11101000101100010000011111111000LDMIA r1!,{r3-r10,PC} 11101000101100011000011111111000

• Variations possible on other architectures; code dependent

19Program Counter

20Controlling PC on ARM using Fault Injection – Timmers et al., 2016

Page 125: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM

Remark• Targetting the copy function arguments

Page 126: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM

Remark• Targetting the copy function arguments

Page 127: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack - Controlling PC on ARM

Remark• Targetting the copy function arguments

Page 128: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attacks - Wild jungle jump21

• Start glitching while/after loadingthe image but before decryption

• Lots of ’magic’ pointers around,which point close to the code

• Get them from: stack, register,memory

• The more magic pointers, thehigher the probability

21Proving the wild jungle jump – Gratchoff, 2015

Page 129: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attacks - Wild jungle jump21

• Start glitching while/after loadingthe image but before decryption

• Lots of ’magic’ pointers around,which point close to the code

• Get them from: stack, register,memory

• The more magic pointers, thehigher the probability

21Proving the wild jungle jump – Gratchoff, 2015

Page 130: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attacks - Wild jungle jump21

• Start glitching while/after loadingthe image but before decryption

• Lots of ’magic’ pointers around,which point close to the code

• Get them from: stack, register,memory

• The more magic pointers, thehigher the probability

21Proving the wild jungle jump – Gratchoff, 2015

Page 131: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attacks - Wild jungle jump21

• Start glitching while/after loadingthe image but before decryption

• Lots of ’magic’ pointers around,which point close to the code

• Get them from: stack, register,memory

• The more magic pointers, thehigher the probability

21Proving the wild jungle jump – Gratchoff, 2015

Page 132: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attacks - Wild jungle jump21

• Start glitching while/after loadingthe image but before decryption

• Lots of ’magic’ pointers around,which point close to the code

• Get them from: stack, register,memory

• The more magic pointers, thehigher the probability

21Proving the wild jungle jump – Gratchoff, 2015

Page 133: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack(s) – Summary

• Bypass of both authentication and decryption

• Typically little software exploitation mitigation during boot

• Fault injection mitigations in software may not be effective

Page 134: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack(s) – Summary

• Bypass of both authentication and decryption

• Typically little software exploitation mitigation during boot

• Fault injection mitigations in software may not be effective

Page 135: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack(s) – Summary

• Bypass of both authentication and decryption

• Typically little software exploitation mitigation during boot

• Fault injection mitigations in software may not be effective

Page 136: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Combined attack(s) – Summary

• Bypass of both authentication and decryption

• Typically little software exploitation mitigation during boot

• Fault injection mitigations in software may not be effective

Page 137: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

There are some practicalities ...

... which we must overcome!

Page 138: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

There are some practicalities ...

... which we must overcome!

Page 139: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Demo Design

Remark• Stage 2 is invalided by changing the printed string• Stage 1 enters an infinite loop when the signature is invalid

Page 140: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Demo Design

Remark• Stage 2 is invalided by changing the printed string• Stage 1 enters an infinite loop when the signature is invalid

Page 141: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Demo Design

Remark• Stage 2 is invalided by changing the printed string• Stage 1 enters an infinite loop when the signature is invalid

Page 142: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 143: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 144: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 145: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 146: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 147: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 148: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

When to glitch?

• Not possible to use a signal originating from target• Only reference point is power-on reset moment• Use side-channels to obtain more information• Compare behavior between valid image and an invalid image

Page 149: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – ResetValid image

Invalid image

Remark• No difference between a valid and invalid image• Attack window spreads across the entire trace (˜400 ms)

Page 150: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – ResetValid image

Invalid image

Remark• No difference between a valid and invalid image• Attack window spreads across the entire trace (˜400 ms)

Page 151: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – ResetValid image

Invalid image

Remark• No difference between a valid and invalid image• Attack window spreads across the entire trace (˜400 ms)

Page 152: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Flash activityValid image

Invalid image

Remarks• Flash activity 3 not present for the invalid image• Attack window between flash activity 2 and 3 (˜10 ms)

Page 153: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Flash activityValid image

Invalid image

Remarks• Flash activity 3 not present for the invalid image• Attack window between flash activity 2 and 3 (˜10 ms)

Page 154: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Flash activityValid image

Invalid image

Remarks• Flash activity 3 not present for the invalid image• Attack window between flash activity 2 and 3 (˜10 ms)

Page 155: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumption

Remark• Measuring electromagnetic emissions using a probe22

22https://www.langer-emv.de/en/product/rf-passive-30-mhz-3-ghz/35/

rf1-set-near-field-probes-30-mhz-up-to-3-ghz/270

Page 156: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumption

Remark• Measuring electromagnetic emissions using a probe22

22https://www.langer-emv.de/en/product/rf-passive-30-mhz-3-ghz/35/

rf1-set-near-field-probes-30-mhz-up-to-3-ghz/270

Page 157: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumptionValid image

Invalid image

Remarks• Significant difference in the electromagnetic emissions• Attack window reduced significantly (< 1 ms)• Power profile at black arrow is flat: infinite loop

Page 158: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumptionValid image

Invalid image

Remarks• Significant difference in the electromagnetic emissions• Attack window reduced significantly (< 1 ms)• Power profile at black arrow is flat: infinite loop

Page 159: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumptionValid image

Invalid image

Remarks• Significant difference in the electromagnetic emissions• Attack window reduced significantly (< 1 ms)• Power profile at black arrow is flat: infinite loop

Page 160: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumptionValid image

Invalid image

Remarks• Significant difference in the electromagnetic emissions• Attack window reduced significantly (< 1 ms)• Power profile at black arrow is flat: infinite loop

Page 161: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Boot profiling – Power consumptionValid image

Invalid image

Remarks• Significant difference in the electromagnetic emissions• Attack window reduced significantly (< 1 ms)• Power profile at black arrow is flat: infinite loop

Page 162: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Jitter

Remark• Jitter during boot prevents effective timing (˜150 µs)

Page 163: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Jitter

Remark• Jitter during boot prevents effective timing (˜150 µs)

Page 164: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Jitter

Remark• Jitter during boot prevents effective timing (˜150 µs)

Page 165: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

How to minimize jitter during boot?

• Power-on reset is too early• Use a signal close to the ’glitch moment’

Remark• Using flash activity 2 as a trigger to minimize jitter

Page 166: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

How to minimize jitter during boot?

• Power-on reset is too early• Use a signal close to the ’glitch moment’

Remark• Using flash activity 2 as a trigger to minimize jitter

Page 167: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

How to minimize jitter during boot?

• Power-on reset is too early• Use a signal close to the ’glitch moment’

Remark• Using flash activity 2 as a trigger to minimize jitter

Page 168: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

How to minimize jitter during boot?

• Power-on reset is too early• Use a signal close to the ’glitch moment’

Remark• Using flash activity 2 as a trigger to minimize jitter

Page 169: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

How to minimize jitter during boot?

• Power-on reset is too early• Use a signal close to the ’glitch moment’

Remark• Using flash activity 2 as a trigger to minimize jitter

Page 170: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Glitch Timing – Power consumption

Remarks• Jitter minimized using flash activity as a trigger

Page 171: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Glitch Timing – Power consumption

Remarks• Jitter minimized using flash activity as a trigger

Page 172: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 2BYPASSING SECURE BOOT

Glitch parameter search• Fixed the glitch delay to 300 ms• Fixed the glitch voltage to -2 V• Randomize the glitch length

Page 173: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 2BYPASSING SECURE BOOT

Glitch parameter search• Fixed the glitch delay to 300 ms• Fixed the glitch voltage to -2 V• Randomize the glitch length

Page 174: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 2BYPASSING SECURE BOOT

Glitch parameter search• Fixed the glitch delay to 300 ms• Fixed the glitch voltage to -2 V• Randomize the glitch length

Page 175: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 2BYPASSING SECURE BOOT

Glitch parameter search• Fixed the glitch delay to 300 ms• Fixed the glitch voltage to -2 V• Randomize the glitch length

Page 176: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

DEMO 2BYPASSING SECURE BOOT

Page 177: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 178: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 179: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 180: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 181: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 182: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 183: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 184: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 185: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Secure Boot – Manufacturer Best practices

Minimize attack surface• Authenticate all code and data• Limit functionality in ROM code• Disable memory when not required

Lower the probability• Implement fault injection countermeasures• Implement software exploitation mitigations

Robustness can only be determined using testing!

Page 186: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Conclusion / Sound Bytes

• Today’s standard technology not resistant to fault attacks

• Implementers of secure boot should address fault risks

• Hardware fault injection countermeasures are needed

• Fault injection testing provides assurance on product security

Page 187: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Conclusion / Sound Bytes

• Today’s standard technology not resistant to fault attacks

• Implementers of secure boot should address fault risks

• Hardware fault injection countermeasures are needed

• Fault injection testing provides assurance on product security

Page 188: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Conclusion / Sound Bytes

• Today’s standard technology not resistant to fault attacks

• Implementers of secure boot should address fault risks

• Hardware fault injection countermeasures are needed

• Fault injection testing provides assurance on product security

Page 189: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Conclusion / Sound Bytes

• Today’s standard technology not resistant to fault attacks

• Implementers of secure boot should address fault risks

• Hardware fault injection countermeasures are needed

• Fault injection testing provides assurance on product security

Page 190: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Conclusion / Sound Bytes

• Today’s standard technology not resistant to fault attacks

• Implementers of secure boot should address fault risks

• Hardware fault injection countermeasures are needed

• Fault injection testing provides assurance on product security

Page 191: Bypassing Secure Boot using Fault Injection · 2018-05-11 · Bypassing Secure Boot using Fault Injection Niek Timmers timmers@riscure.com (@tieknimmers)Albert Spruyt spruyt@riscure.com

Niek TimmersSenior Security Analyst

[email protected] (@tieknimmers)

Albert SpruytSenior Security Analyst

[email protected]

www.riscure.com/[email protected]