Compromising device security via NVM controller vulnerability
Sergei P. Skorobogatov · 2020
This paper introduces a new vulnerability found in a low-cost secure authentication IC that stores its security settings in non-volatile memory (NVM). Such devices are widely used for prevention of counterfeiting in consumable products and accessories (printer cartridges, batteries etc.) and for aftermarket control. The particular device targeted here uses hardwired application logic and lacks a microprocessor, however, more sophisticated security devices used in medical and banking applications could similarly be vulnerable. The newly discovered self-induced fault attacks exploit implications of the use of error-correction codes inside modern embedded NVM blocks and their associated control logic, which can leave the application vulnerable to early termination of NVM write operation. This could potentially be used to change the security settings of a device in a way that bypasses the intended state machine controlling access and allow reverting the stored hardware security level back to the factory test/debug mode. The paper also outlines some measures that could substantially reduce the chances of a successful attack.