2021/08/13 by Otto Bittner, Bittner, Otto, Thilo Krachenfels +6 · 1 voice
Computer Science · Engineering · #Cryptography and Security (cs.CR) #Electrostatic Discharge in Electronics #FOS: Computer and information sciences #Integrated Circuits and Semiconductor Failure Analysis #Physical Unclonable Functions (PUFs) and Hardware Security #cs.CR
paper · pdf · doi:10.48550/arxiv.2108.06131
openalex publication_date 2021/08/13 · arxiv published 2021/08/13 · arxiv updated 2021/08/16 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28
Voltage fault injection (FI) is a well-known attack technique that can be\nused to force faulty behavior in processors during their operation. Glitching\nthe supply voltage can cause data value corruption, skip security checks, or\nenable protected code paths. At the same time, modern systems on a chip (SoCs)\nare used in security-critical applications, such as self-driving cars and\nautonomous machines. Since these embedded devices are often physically\naccessible by attackers, vendors must consider device tampering in their threat\nmodels. However, while the threat of voltage FI is known since the early 2000s,\nit seems as if vendors still forget to integrate countermeasures. This work\nshows how the entire boot security of an Nvidia SoC, used in Tesla's autopilot\nand Mercedes-Benz's infotainment system, can be circumvented using voltage FI.\nWe uncover a hidden bootloader that is only available to the manufacturer for\ntesting purposes and disabled by fuses in shipped products. We demonstrate how\nto re-enable this bootloader using FI to gain code execution with the highest\nprivileges, enabling us to extract the bootloader's firmware and decryption\nkeys used in later boot stages. Using a hardware implant, an adversary might\nmisuse the hidden bootloader to bypass trusted code execution even during the\nsystem's regular operation.\n