Static side-channel attack: generator freeze

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
913
Deposit
0$
Static side-channel attacks: why you need to stop a clock generator
Classic dynamic side-channel attacks - DPA (Differential Power Analysis) and CPA (Correlation Power Analysis) - operate transition processes in the circuit during computing. Each clock of operation of the cryptographic module creates measurable fluctuations of the power consumption or electromagnetic radiation. For a successful DPA, thousands of tracks are needed - many measurements of one operation with different input data. The Hamming weight/Hamming distance model describes the correlation between the processed intermediate value and the observed side signal. The area is well-studied, the countermeasures are developed - and that is why the attackers are looking for bypasses.



Static side-channel attacks work fundamentally differently. Instead of observing the transition processes, the attacker reads the state of the data already stored in the registers (flip-flops) and SRAM cells. This class includes:



Static Power Analysis - measurement of static leakage current, depending on saved bits
Laser Logic State Imaging (LLSI) - irradiation of the chip with a near-closed IR laser and analysis of modulated reflection from transistors depending on the logical state
Impedance Analysis (IA) - stimulation of the chip by microwave radiation and analysis of the impedance dependent on the state of the cells
Thermal Laser Stimulation (TLS) - reading the state through thermoinduced currents
The critical limitation of all static attacks is time. Reading the state of one register by order exceeds the clock period. At a working frequency of 100 MHz, the period is 10 ns, while LLSI scanning of a single pixel takes microseconds. If the clock generator continues to work, the data in the registers changes faster than the attacker has time to read them. Hence the first prerequisite: freezing the clock generator of the chip.



For backscatter attacks (LLSI, IA) there is a second condition: modulation of the power voltage to create a detectable reflected signal. The attacker supplies a variable voltage to the VCC and measures how the reflection of the laser or microwaves changes depending on the state of the transistor. With a working cloke, the scheme's own switching masks the modulation. Generator stop - enabler of the entire class of static attacks.

Backscatter attacks give a higher signal/noise ratio (SNR), and in some cases, the extraction of a secret for a single track. This makes randomizing countermeasures (masking) ineffective, which work only with multiple measurements. Masking was designed against DPA. Against single-trace it is useless.

Brownout-hibernation: physics Chypnosis



Voltage thresholds: logic vs data retention
Each digital chip operates in a certain range of voltages. Below the nominal threshold (V<sub>NOM</sub>) logical elements begin to crash. But there is an intermediate zone - between the logical switch threshold (V<sub>STOP</sub>) and the data retention threshold (V<sub>RET</sub>). This is the zone operated by Chypnosis.



With a rapid decrease in VCC below V<sub>STOP</sub>, but above V<sub>RET</sub>, there is a brownout-state - "hibernation" of the chip:



Clock buffers stop switching - the generator actually stops, although not physically disabled
The final machines (FSM) in sensors and controllers freeze in the current state
Flip-flops and SRAM continue to hold data from residual charge and subthreshold currents
Not to be confused with data remanence (cold boot attack): with brownout chip remains fed. The data does not degrade - they persist indefinitely while the voltage is higher than V<sub>RET</sub>. The attacker receives an unlimited temporary window for reading. Even an hour, even a day.

The rate of voltage slump as a weapon
Protective mechanisms include voltage sensors and clock speeds. When an anomaly is detected, they start the procedure of cleaning secret data (dapita). But the sensors are digital circuits on the same food. And here begins the most interesting.



If the tension drops quickly enough, the sensors enter the brownout earlier than they have time to work out the cleaning procedure:



Sensor detects voltage drop
The sensor FSM begins to process the alarm
Brownout freezes FSM sensor before wipe signal reaches registers
Beautiful irony: Protective sensors become part of the vulnerability. Detect the attack, but do not have time to react to it. The guard noticed the thief, opened his mouth - and fell asleep. The study describes in detail the relationship between the voltage decline rate and the frequency of the clock generator (section "Voltage Falling Time vs Clock Frequency" of the original publication), which is critical for the selection of attack parameters on a particular chip.

The attack is sometimes referred to under the inaccurate name "Chypothermia" (chip + hypothermia), but the original name is Chypnosis (chip + hypnosis). Not cooling, but immersion in sleep.

Bypassing protective sensors
Software clock sensors (Soft IP)
The literature describes the implementations of clock detection freezes in the form of soft IP for FPGA (for example, the work of Farheen et al.). Principle: independent ring oscillator monitors the activity of the main cloak. At the stop - alarm and wipe.

Chypnosis bypasses such sensors trivially: soft IP works on the same voltage of power. With a brownout ring, the oscillator stops generating - the sensor freezes along with the main cloak and does not generate a cleaning signal. Protection and protected - on one food. Classic error.

Hardware sensors (Hard IP)
XADC Xilinx. The AMD Series 7 series contains the built-in XADC - a hardware ADC capable of monitoring the voltage. In the study, Chypnosis XADC was configured as a sensor with an alarm threshold. XADC detected a drop in voltage, but performing the reaction requires the operation of digital logic, which by the time of processing was already in the brownout. Bulletin AMD-SB-8018 confirms: XADC-based monitor monitor monitor "is too slow to and detect/or execute a tamper response to clear memory contents"“works too slowly to detect an attempt to intervene in an unauthorized manner and/or perform a response to it to clean the memory contents”. AMD itself admits - does not have time.



Microchip AT module. For flash-based FPGA, the researchers tested the hardware Anti-Tamper module Microchip. The rapid downturn of tension bypasses his reaction in a similar way.

Alert Handler OpenTitan
OpenTitan is an open root-of-trust design with Alert Handler, a centralized threat handling module. Chypnosis successfully bypasses Alert Handler when implemented on FPGA. The rapid voltage drop freezes the FSM handler until the reaction is completed. Direct demonstration on the real project root-of-trust - not on the training stand.



In the terminology of MITRE ATT&CK, this stage corresponds to the technique Disable Crypto Hardware (T1600.002, Defense Impairment) - the attacker neutralizes the hardware protection of the cryptographic module.

Extracting secrets in a state of hibernation
LLSI on "sleeping" chip
LLSI reads the logical state of the transistors through the reflection of the near IR laser from the back surface of the crystal. The reflectivity of the p-n transition depends on the applied voltage, and therefore on the saved bit. VCC modulation creates a detectable variable reflection.

Within the framework of Chypnosis, it is shown that VCC modulation is possible in a brownout state: the amplitude is small enough not to remove the chip from hibernation and not to "wake up" the sensors. At the output - a complete map of the logical states of the registers of the cryptographic module. All the key, beat the bat.

Impedance Analysis in Brownout
IA uses microwave radiation instead of a laser. The microwave probe stimulates the chip, the reflected signal carries information about the condition of the cells. Advantage over LLSI: no optical access to the back surface of the crystal is necessary - a contact probe on metallization is sufficient. Chypnosis allows you to conduct IA in brownout: data is stable and does not change with time, synchronization with a clock signal is not necessary. The data is just lying and waiting.

Extracting the key for one track
Key result: from the cryptographic module OpenTitan, protected side-channel countermeasures (masking), the secret key for one track (single trace) is extracted. Masking effectively against DPA - randomization of masks works between tacts. But in the frozen state of stroke one, the mask is fixed, and the data are read directly.



I would call it a conceptual knockout for a masking-only strategy. All randomization of intermediate values is based on the assumption that the attacker needs many measurements. Single trace - and the assumption is crumbling.



From the point of view of MITRE ATT&CK, this stage corresponds to Private Keys (T1552.004, Credential Access) - obtaining cryptographic keys from hardware storage.

Affected devices: AMD-SB-8018
Confirmed:



AMD Artix 7-Series FPGA
AMD Kintex 7-Series FPGA
Under the study (AMD is planning updates):



Alveo Card (UltraScale and UltraScale+ based)
Artix UltraScale+ FPGA
Kria SOM
Kintex UltraScale and UltraScale+ FPGA
Spartan-6 FPGA
Spartan UltraScale+ FPGA
Versal Adaptive SoCs
Virtex UltraScale and UltraScale+ FPGA
Zynq UltraScale+ RFSoC and MPSoC
The scale covers almost the entire AMD FPGA portfolio. Considering that Cyphinsis is also demonstrated on Flash-based FPGA (Microchip), the problem is not limited to one vendor. AMD explicitly points out: the attack "is generally applicable to all integrated circuits that do not have an effective reaction to a reduced voltage event." Read: to everyone who didn't think of the brownout as the attack vector.

Chypnosis vs clock glitching vs data remanence
Parameter Clock Glitching (DFA) Data Remanence Chypnosis
Purpose Making errors in calculations Reading residual data after disconnection Freezing the condition for static reading
Food Nominal with short-term deviations Complete shutdown Decrease below V<sub>STOP</sub>, above V<sub>RET</sub>
Clock generator Works (with glitch) Disabled Stops indirectly
Time of data life not applicable Degradation in seconds-minutes Unlimited with VCC > V<sub>RET</sub>
Class of attack Active (fault injection) Passive Passive after active preparation
Masking Partially effective Partially effective Inefficient (single trace)
Type of side-channel DFA - by calculation errors Static data remanence Static backscatter (LLSI/IA)
Chypnosis takes the best from both approaches: working with static data (no need for repeat calculations) and allows you to control the moment of attack. At the same time, the data are not degraded and are available for single-trace extraction - this is not the case with glitching or data remanence.

Countermeasures: What Works and What Doesn't
Why Existing Protections Are Not Coping
Three classes of protection that Chypnosis bypasses:



Clock sensors (soft IP) - freeze along with the main clove
Voltage sensors (hard IP) - detect anomaly, but FSM reactions do not have time to work
Data masking - ineffective against single-trace attacks
Work “On Borrowed Time” (NDSS 2025, R. Dumitru, T. Moos, A. Wabnitz, Y. Yarom) offers the Borrowed Time system for clove stop detection and data cleansing. Chypnosis - direct answer: brownout bypasses Borrowed Time, which is shown experimentally. Borrowed Time protects against stopping the cloak, but not from stopping the cloak through the food drawdown.

Asynchronous discharge: proposed countermeasure
The authors of Chypnosis propose and verify the countermeasure: modification of the clock detection sensor with an asynchronous reset mechanism.



Ring oscillator on partially independent power domain
When stopping the cloke is a signal wipe along the asynchronous path (through hardware latch, not through FSM)
Asynchronous reset does not depend on the clock frequency and can work when the logic is slowed down



Code:


wire ring_osc;
reg [3:0] wdog_cnt;
wire clk_frozen = (wdog_cnt == 4'hF);
always @(posedge ring_osc or negedge rstn)
if (!rstn) wdog_cnt <= 0;
else if (sys_clk_edge) wdog_cnt <= 0;
else wdog_cnt <= wdog_cnt + 1;

assign async_wipe = clk_frozen;

AMD-SB-8018 recommends: "implement a clock monitor in the programmable logic and an asynchronous reset mechanism""to implement in programmable logic the scheme of control of the clock signal and the mechanism of asynchronous discharge". AMD notes that the researchers experimentally verified the effectiveness of the countermeasure, but AMD did not independently confirm it. That is, the authors of the attack offered and checked the fix, and the vendor is still only nodding.

Mapping on MITRE ATT&CK
Phyphonsis stage ATT&CK Technique Tactics
Reconnaissance of hardware platform Hardware (T1592.001), Firmware (T1592.003) Reconnaissance
Definition of the Harvet-Zone Chip System Information Discovery (T1082) Discovery
Neutralization of sensors and protection Disable Crypto Hardware (T1600.002) Defense Impairment
Extraction of cryptographic keys Private Keys (T1552.004) Credential Access
Potential compromising firmware Firmware Corruption (T1495) Impact
Business logic of attack: why the attacker
Chypnosis is not an academic exercise. Three scenarios in which it really hurts:



Extracting IP from FPGA. Companies place proprietary algorithms in FPGA - DSP, network processors, military electronics. The beat-stream is encrypted, the key is stored in the registers. Chypnosis allows you to extract the bitstream encryption key and decrypt the proprietary design. Years of development - for one track.



Compromising root-of-trust. OpenTitan is used for firmware verification and key management. Extracting the key from OpenTitan compromises the entire trust chain: from secure boot to storage encryption. The tree falls from the root.



Attacks on supply chain. When physically accessing the device at the stage of production or maintenance, the attacker extracts the keys without visible traces. Unlike probing, the brownout does not leave physical damage. The device is returned to the customer "as new."



Economy: programmable power supply (several thousand dollars) and standard laboratory equipment. For the IA option, you do not need optical access to the crystal. The entry threshold is significantly lower than for FIB (Focused Ion Beam) or microprobing.
 
Top Bottom