01 June 2012

Microsemi reacts to ProASIC3 fpga 'backdoor' claim

Two researchers claim to have used a variant of differential power analysis (dpa) to bypass the security settings in Microsemi's ProASIC3 fpgas – whose applications include secure military systems. Using pipeline emission analysis (pea) techniques, the researchers say they have managed to disable all security settings, while reprogramming other features.

In their paper (for more, follow the link below), the researchers claim they were able to detect and analyse a backdoor in ProASIC3 chips. They say this backdoor exists in silicon, rather than in firmware, and leaves devices open to a range of attacks.
The researchers claim that, by using pea techniques, they could discover a 'secret key' which allows access to an internal test mode, through which it is possible to disable all security on the chip. Microsemi has responded, claiming there is no designed feature in ProASIC3 fpgas that would enable user security to be circumvented.
In a statement, the company said the internal test mode could only be accessed by customers entering a passcode. It added that, because the researchers have not been in contact, their claims cannot be verified.
In the past, fpgas have been seen as a potential weak link when it comes to design security because, in many cases, the fpga's program would be loaded from a discrete memory and that data flow is open to abuse. However, more recent designs have addressed this issue through the use of AES encryption.
Nevertheless, Microsemi has acknowledged that fpgas are potentially vulnerable to dpa style attacks. "Microsemi anticipated the increasing threats to silicon device security from dpa type attacks and took action several years ago by licensing the dpa patent portfolio of Cryptography Research," it noted. This technology is said to be a feature of a new fpga range due to be launched shortly by Microsemi.
Meanwhile, it says users have the ability to program fpgas using the highest security setting. By selecting this, the use of any passcode to gain access to any device configuration is disabled.
The research paper does concede that ProASIC3 devices are 'at least 100 times harder to attack using DPA than non protected conventional microcontrollers' and that any attacks on the chips would be 'quite a challenging task'.

Author
Graham Pitcher

Supporting Information

Websites
http://www.cl.cam.ac.uk/~sps32/Silicon_scan_draft.pdf
http://www.microsemi.com

Companies
Microsemi

This material is protected by Findlay Media copyright
See Terms and Conditions.
One-off usage is permitted but bulk copying is not.
For multiple copies contact the sales team.

Do you have any comments about this article?

Add your comments

Name
 
Email
 
Comments
 

Your comments/feedback may be edited prior to publishing. Not all entries will be published.
Please view our Terms and Conditions before leaving a comment.

Related Articles

Compound eye

There are many applications in which motion detection is an important element, ...

Medical sensor warning

Researchers in the US have identified a new security risk in the sensors of ...

Altera buys Enpirion

Altera has signed a definitive agreement to acquire Enpirion, a developer of ...

Plug and play front end

Many industrial sensors have high or wide-ranging analogue output voltages and ...

UK satellite project wraps up

Proving technology in space is not a cheap business. 'Heritage' technology – ...

Focus on: Programmable logic

In the world of programmable logic, the phrase 'ultra low density' stands out ...

Using Linux in medical devices

This whitepaper explores the issues that software developers and medical device ...

Automotive functional safety

Real time control of safety critical applications has been a longtime challenge ...

Adapting to the extremes of rugged design

Ruggedisation and reliability are key requirements for a wide range of embedded ...

40V N channel mosfets

International Rectifier has introduced the COOLiRFET series of automotive ...

SPDT rf switch

Peregrine Semiconductor has introduced of a new SPDT rf switch for harsh ...

Microchip adds to LIN family

Microchip has expanded its LIN portfolio to include a low power transceiver, ...

Wireless Seminars 2013

4-5th June 2013, Manchester and Reading, UK

SCSC DO178C training event

20th June 2013, London Marriott Hotel, Kensington, UK

COG International Conference

25th June - 27th June 2013, Royal York Hotel, York, UK

Automotive instrument cluster

An overview of TI's system solution for instrument cluster.

Automotive radar trends

An overview of the latest trends in automotive radar technology from TI's Niki ...

VGo robot uses Freescale tech

The VGo robotic telepresence machine offers an affordable mobile telepresence ...

Autonomous, not driverless

I don't know about you, but I'm looking forward to the era of self driving ...

Andy Green's Bloodhound diary

Happy New Year – I hope your New Year has started off as well as ours.

Andy Green's December diary

Just back from Los Angeles, where I went to launch a film in Hollywood. OK, so ...

Gregg Lowe, Freescale

Freescale's new ceo tells Graham Pitcher that, while he's not 'dancing' yet, ...

Keith Attwood, ceo, e2v

Many UK based technology companies can trace their origins to the years ...

Ian Menzies, General Dynamics

Graham Pitcher finds out how a new network will give Welsh electronics ...