当前位置:首页 > 报告详情

解码电磁干扰攻击:从 GigaDevice GD32F407 故障中吸取的教训.pdf

上传人: 竿*** 编号:981595 2025-11-29 50页 6.04MB

1、#BHEU BlackHatEventsDecoding EMDecoding EM-FI Attacks:FI Attacks:Lessons Learned from Glitching Lessons Learned from Glitching the GigaDevice GD32F407the GigaDevice GD32F407Jonathan Andersson&Thanos Kaliyanakis#BHEU BlackHatEventsJonathan AnderssonSr.ManagerAdvanced Security Research GroupTrend Micr

2、o ZDIThanos KaliyanakisVulnerability Researcher Advanced Security Research GroupTrend Micro ZDI#BHEU BlackHatEventsInformation Classification:GeneralAgendaIntroduction&BackgroundThe RigGetting StartedThe AttackCalibrationPerfecting the GlitchAttack ResultsMitigationsConclusions#BHEU BlackHatEventsIn

3、troduction&BackgroundIntroduction&Background#BHEU BlackHatEventsInformation Classification:GeneralIntroductionWhy the GD32F407?Why fault injection?Why EM-FI?Autel MaxiCharger#BHEU BlackHatEventsInformation Classification:GeneralGigaDevice vs STMicro-32F407 John McMasterST32F407 GD32F407#BHEU BlackHa

4、tEventsInformation Classification:GeneralRead Out Protection LevelsNone/RDP 0No restrictionsLow/RDP 1Flash accessible only in flash boot modeFlash disabled when SWD attachedCan be reverted to None/RDP 0 but flash gets erasedHigh/RDP 2SWD cannot attachOnly flash mode boot allowedNo reversion back to

5、lower security levels possibleLock by Puspa Kusuma CC BY 3.0/blue with shadow#BHEU BlackHatEventsThe RigThe Rig#BHEU BlackHatEventsInformation Classification:GeneralThe Rig($600 USD)ChipSHOUTER PicoEMP with firmware additionsManaged USB hub with individual power controlXYZ table(G-Code)Programmable

6、power supplySWD debugger(OpenOCD/GDB)USB to serial(console)3D printed parts(PicoEMP&PCB mounts)Custom python code driving the rig#BHEU BlackHatEventsInformation Classification:GeneralThe Rig#BHEU BlackHatEventsInformation Classification:GeneralThe Rig Purchase Links XYZ Table$137SWD Debugger$10Manag

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据《Decoding EM-FI Attacks: Lessons Learned from Glitching the GigaDevice GD32F407》的内容,以下是全文关键点的概括: 1. **研究背景**:针对GigaDevice GD32F407微控制器进行电磁故障注入(EM-FI)攻击研究。 2. **攻击工具**:使用ChipSHOUTER PicoEMP进行电磁脉冲攻击,配合XYZ表、可编程电源和SWD调试器。 3. **攻击方法**:通过触发微控制器中的故障,绕过安全保护,如读取保护(RDP)。 4. **攻击结果**:成功绕过RDP1保护,提取固件,并观察到SRAM内容在硬件复位后保持持久。 5. **优化策略**:通过优化脉冲功率、电压和延迟,提高攻击的成功率和效率。 6. **结论**:EM-FI攻击是可行的,需要通过优化和调整参数来提高成功率。 7. **缓解措施**:建议使用旧版本的调试工具和固件,以及考虑其他安全措施。
EM-FI攻击揭秘" "如何轻松绕过GD32F407的安全防护?" 破解芯片安全性的秘密武器!"
客服
商务合作
小程序
服务号
折叠