How to Code Data Integrity Verification Secure Against Single-Spot-Laser-Induced Instruction Manipulation Attacks
Junichi Sakamoto, Shungo Hayashi, Daisuke Fujimoto, Tsutomu Matsumoto · 2020
Fault injection attacks (FIA), which cause information leakage by injecting intentional faults into the data or operations of devices, are one of the most powerful methods compromising the security of confidential data stored on these devices. Previous studies related to FIA on software report that attackers can skip instructions running on many kinds of devices through many means of fault injection. Most existing anti-FIA countermeasures on software are designed to secure against instruction skip (IS). On the other hand, recent studies report that attackers can use laser fault injection to manipulate instructions running on devices as they want. Although the previous studies show that instruction manipulation (IM) can attack the existing countermeasures against IS, no effective countermeasures against IM have been proposed yet to the best of our knowledge. In this paper, we define an attacker's model under the assumption that the attacker injects IM using a single-spot laser, and propose a coding method to verify data integrity secure against the assumed IM model in ARM 16-bit Thumb instruction set.