Prøve GULL - Gratis

Power Analysis Over JTAG Ports: Hidden Debug Dangers - Block Side-Channel Analysis Attacks

Circuit Cellar

|

September 2024

Small changes in the phase of clock signals can encode power leakages. An attacker can use standard interfaces such as the JTAG port to drive clocks across targets, using them as measurement techniques for sidechannel analysis attacks despite limited physical access. This article demonstrates how you can test devices for vulnerability and how to modify devices to prevent attacks.

- Colin O'Flynn

Power Analysis Over JTAG Ports: Hidden Debug Dangers - Block Side-Channel Analysis Attacks

When I've presented side-channel power analysis attacks, I always use an oscilloscope or ADC that measures analog voltage variations. This is logical because side-channel power analysis attacks exploit the small changes in device power when it executes different instructions or even processes different data. This made it seem like a purely analog attack. Attackers need measurement access, such as a shunt resistor or electromagnetic probe. But what if attackers could use a purely digital interface, one that is already on your board, like the JTAG interface?

Things you always thought were safe might have hidden dangers. In this case, I will show you how a a side-channel power analysis attack occurs through the JTAG interface. But first, the background.

Back in the March 2024 issue of Circuit Cellar (Issue 404, "It's About Time: When Timing Attacks Reveal Power Usage), I recreated the work of a paper presented at CHES 2023 titled "JitSCA: Jitter-based Side-Channel Analysis in Picoscale Resolution", by Kai Schoos, Sergej Meschkov, Mehdi B. Tahoori, and Dennis R. E. Gnad.[1] In this article, I will present an extension of my talk at CHES 2024. If you want to see the full article entitled "Phase Modulation Side Channels: Jittery JTAG for On-Chip Voltage Measurements"[2] use a link to both the original paper and my extension available in article resources.

imagePHASE MODULATION LEAKAGE

In my March 2024 column, I recreated the JitSCA paper to demonstrate how small changes in the phase of a clock directly leak a power trace. In the previous column, I used a basic voltage divider; here, I'm using an RF mixer component. While RF mixers are normally used to create a signal based on frequency differences, they will also give an output related to a phase difference of two signals.

FLERE HISTORIER FRA Circuit Cellar

Circuit Cellar

Circuit Cellar

A GPS-Disciplined Frequency Counter using the PSoC 5LP

In this month's column, Brian tasks one of his mixed-signal favorite MCUs, the Infineon PSoC 5LP, to build a frequency/ period counter using a GPS satellite module to discipline the project's time base.

time to read

16 mins

November 2025

Circuit Cellar

Designing Analog Electronics

Part 1: Error and Uncertainty

time to read

23 mins

November 2025

Circuit Cellar

Samtec Launches 800-Position AcceleRate HP High-Performance Array Connectors

Samtec, Inc., a global leader in high-performance interconnect solutions and a service leader in the industry, announces the expansion of its AcceleRate HP product line with the release of 800-position APM6 and APF6 high-performance array connectors available in a low-profile 5mm stack height.

time to read

1 min

November 2025

Circuit Cellar

Circuit Cellar

CIA for SBCs (and More)

Securing Embedded Systems from Evolving Threats

time to read

14 mins

November 2025

Circuit Cellar

Circuit Cellar

The Future of Embedded Systems and AI: AI in Embedded Systems

Cybersecurity Challenges and Opportunities in a Smarter World

time to read

4 mins

November 2025

Circuit Cellar

Circuit Cellar

An ESP32 Dashboard

Monitoring How a Popular Microcontroller Uses Resources

time to read

11 mins

November 2025

Circuit Cellar

Circuit Cellar

Vishay Intertechnology Power Metal Strip Resistor Delivers Power to 5 W in Compact 1206 Case Size

Vishay Intertechnology, Inc. introduced a new surfacemount Power Metal Strip current sense resistor that combines a high power rating up to 5W, TCR down to ± 75ppm/°C, and extremely low resistance values down to 0.3mΩ in the compact 1206 case size.

time to read

2 mins

November 2025

Circuit Cellar

Circuit Cellar

ROHM Develops New Smart Switches Optimized for Zonal Controllers

ROHM Semiconductor announced the release of six new high-side smart switches (IPDs: Intelligent Power Devices) featuring highly accurate current sensing and low ON resistances ranging from 9mΩ to 180mΩ.

time to read

1 min

November 2025

Circuit Cellar

Circuit Cellar

Bourns Expands Semi-Shielded Power Inductor Portfolio with New Series Featuring Higher Maximum Inductance Values

Bourns, Inc., a leading manufacturer and supplier of electronic components for power, protection, and sensing solutions, announced the expansion of its semi-shielded power inductors.

time to read

1 min

November 2025

Circuit Cellar

Circuit Cellar

STMicroelectronics' New Automotive Linear Voltage Regulator Preserves Battery Energy in Challenging Conditions

The TL99VR03 300mA low-dropout (LDO) regulator provides resilient and efficient power, with a wide input-voltage range and very low quiescent current consumption, only 3.5µA at no load. The IC has an enable pin for turning the regulator off, which reduces the idle current to 800nA, and integrates soft-start circuitry to limit current during power-up and fault recovery.

time to read

1 min

November 2025

Listen

Translate

Share

-
+

Change font size