Practical Full Key Recovery on a Google Titan Security Key

Laurent Imbert, Victor Lomné, Camille MUTCHLER, Thomas Roche · 2025

This chapter presents a practical case study of side-channel analysis. It is based on the work entitled A Side Journey to Titan published at USENIX Security 2021. The original work studies the security of the Google Titan Security Key 1 (a hardware security token for two-factor authentication) and shows that its secure element, the NXPA700x chip, is susceptible to a side-channel attack. The chapter details the process that resulted in the full recovering of the private keys embedded into the NXP's secure components of both Rhea and Titan . Some cryptographic primitive implementations require robustness against strong side-channel attackers (e.g. the so-called secure elements ). Their security is ensured by building up layers of countermeasures such as de-synchronization techniques. Often, one layer of countermeasure is the secrecy of the implementation.

Read the paper · More papers on PaperTik