Intentar ORO - Gratis
Power Analysis Over JTAG Ports: Hidden Debug Dangers - Block Side-Channel Analysis Attacks
Circuit Cellar
|September 2024
Small changes in the phase of clock signals can encode power leakages. An attacker can use standard interfaces such as the JTAG port to drive clocks across targets, using them as measurement techniques for sidechannel analysis attacks despite limited physical access. This article demonstrates how you can test devices for vulnerability and how to modify devices to prevent attacks.
When I've presented side-channel power analysis attacks, I always use an oscilloscope or ADC that measures analog voltage variations. This is logical because side-channel power analysis attacks exploit the small changes in device power when it executes different instructions or even processes different data. This made it seem like a purely analog attack. Attackers need measurement access, such as a shunt resistor or electromagnetic probe. But what if attackers could use a purely digital interface, one that is already on your board, like the JTAG interface?
Things you always thought were safe might have hidden dangers. In this case, I will show you how a a side-channel power analysis attack occurs through the JTAG interface. But first, the background.
Back in the March 2024 issue of Circuit Cellar (Issue 404, "It's About Time: When Timing Attacks Reveal Power Usage), I recreated the work of a paper presented at CHES 2023 titled "JitSCA: Jitter-based Side-Channel Analysis in Picoscale Resolution", by Kai Schoos, Sergej Meschkov, Mehdi B. Tahoori, and Dennis R. E. Gnad.[1] In this article, I will present an extension of my talk at CHES 2024. If you want to see the full article entitled "Phase Modulation Side Channels: Jittery JTAG for On-Chip Voltage Measurements"[2] use a link to both the original paper and my extension available in article resources.
PHASE MODULATION LEAKAGE In my March 2024 column, I recreated the JitSCA paper to demonstrate how small changes in the phase of a clock directly leak a power trace. In the previous column, I used a basic voltage divider; here, I'm using an RF mixer component. While RF mixers are normally used to create a signal based on frequency differences, they will also give an output related to a phase difference of two signals.
Esta historia es de la edición September 2024 de Circuit Cellar.
Suscríbete a Magzter GOLD para acceder a miles de historias premium seleccionadas y a más de 9000 revistas y periódicos.
¿Ya eres suscriptor? Iniciar sesión
MÁS HISTORIAS DE Circuit Cellar
Circuit Cellar
Combining Nostalgic Design with Embedded Programming
In this article, Maxwell and Noah, two Cornell University undergrads, describe the design and implementation of a retro-inspired, side-scroller game, modeled after Super Mario Bros.
9 mins
May 2026
Circuit Cellar
TI Unveils High-Performance Isolated Power Modules to Advance Power Density in Data Centers and EVs
Texas Instruments (TI) unveiled new isolated power modules, helping enable increased power density, efficiency, and safety in applications ranging from data centers to electric vehicles (EVs).
1 mins
May 2026
Circuit Cellar
Using MapleLink for IoT Device Scanning
A Simple Tool for Probing On-Board Data
10 mins
May 2026
Circuit Cellar
Edge Intelligence
Artificial Intelligence's Next Frontier
11 mins
May 2026
Circuit Cellar
Bringing the World to SBCs
Sensor Shields Bring the Real World to Microcontrollers
7 mins
May 2026
Circuit Cellar
1200V QSiC Dual3 Modules Enable Power Converters with Industry-Leading Conversion Efficiency and Power Density
SemiQ, Inc, a designer, developer, and global supplier of superior silicon carbide (SiC) solutions for ultra-efficient, high-performance, and high-voltage applications, has launched the QSiC Dual3, a family of 1200V half-bridge MOSFET modules for motor drives in data center cooling systems, grid converters in energy storage systems, and industrial drivers.
1 min
May 2026
Circuit Cellar
Marvell Launches Industry's First 260-Lane PCIe 6.0 Switch for AI Data Center Scale-Up Infrastructure
Marvell Technology, Inc., a leader in data infrastructure semiconductor solutions, announced Marvell Structera S 60260, the industry's first 260-lane PCIe 6.0 switch.
1 mins
May 2026
Circuit Cellar
Saelig Introduces Advanced Aim-TTi ADM1055
Saelig Co., Inc., has introduced the Aim-TTi ADM1055 DMM, a next-generation 5½-digit bench digital multimeter engineered to deliver the measurement accuracy, flexible functionality, and seamless integration needed for development labs, production test environments, and educational establishments.
1 mins
May 2026
Circuit Cellar
Granite 4 AI by IBM: Disrupting Traditional Approaches to Embedded Programming
What If Your Edge Device Could Read Its Own Instruction Manual?
9 mins
May 2026
Circuit Cellar
Embedding Ergonomics Into Electronic Design
Tactile Sensing Can Provide Comfort and Fit to Electronics Users
3 mins
May 2026
Listen
Translate
Change font size
