International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Through the Looking-Glass: Sensitive Data Extraction by Optical Probing of Scan Chains

Authors:
Tuba Kiyan
Lars Renkes
Marvin Sass
Antonio Saavedra
Norbert Herfurth
Elham Amini
Jean-Pierre Seifert
Download:
DOI: 10.46586/tches.v2024.i4.541-568
URL: https://tches.iacr.org/index.php/TCHES/article/view/11802
Search ePrint
Search Google
Abstract: There is an imminent trade-off between an Integrated Circuit (IC)’s testability and its physical security. While Design for Test (DfT) techniques, such as scan chains make the circuit’s physical behavior at runtime observable and easy to control, these techniques form a lucrative class of attack vectors with the potential to compromise the entire security architecture of the Device under Test (DuT). Moreover, with the rapid development of more complex technologies, the need for integration of DfT techniques even intensifies due to the requirement for faster time-to-market of cutting-edge ICs. In this work, we demonstrate that sensitive data can be extracted from the registers once their locations on the chip are identified by exploiting DfT structures and optically probing them — in this case, scan chains, even after the access to test mode is restricted. Furthermore, we show that also an obfuscated scan chain architecture can be fully reconstructed by using tools and techniques encountered in the Failure Analysis (FA) domain.
BibTeX
@article{tches-2024-34475,
  title={Through the Looking-Glass: Sensitive Data Extraction by Optical Probing of Scan Chains},
  journal={IACR Transactions on Cryptographic Hardware and Embedded Systems},
  publisher={Ruhr-Universität Bochum},
  volume={2024},
  pages={541-568},
  url={https://tches.iacr.org/index.php/TCHES/article/view/11802},
  doi={10.46586/tches.v2024.i4.541-568},
  author={Tuba Kiyan and Lars Renkes and Marvin Sass and Antonio Saavedra and Norbert Herfurth and Elham Amini and Jean-Pierre Seifert},
  year=2024
}