FaultLine: Software-Based Fault Injection on Memory Transfers

Joseph Gravellier, Jean-Max Dutertre, Yannick Teglia, Philippe Loubet Moundi · 2021

Today's integrated memory controllers use complex hardware such as delay-lines to monitor and control signal timings during external memory transfers. Because memory chips with different timing specifications may be used, delay-line tuning registers often remain accessible and programmable from the application processor. In this paper, we introduce FaultLine and the concept of delay-line-based fault injection. First, we demonstrate that by modifying the delay-line calibration value through a simple register access, a malware may induce faults in memory transfers and jeopardize the security of concurrently running assets. Then, we experimentally evaluate the fault injection on an OS-capable system-on-chip by exposing cryptographic applications to corrupted data and retrieving their secret keys. We finally discuss why delay-line-based fault injection should be systematically considered as a potential threat in modern systems where entities with different privileges share external memories.

Read the paper · More papers on PaperTik