Screaming Channels Revisited: Encryption Key Recovery from AES-CCM Accelerator
Yanning Ji, Elena Dubrova, Ruize Wang · 2025
In this paper, we demonstrate the first successful extraction of the encryption key from the hardware AES accelerator in the nRF52832 Bluetooth Low Energy system-on-chip operating in Counter with CBC-MAC (CCM) mode using side-channel information recovered from RF signals. This attack marks a significant milestone, as previous attempts to break this accelerator were unsuccessful. Our results provide a critical insight into the proprietary hardware AES-CCM accelerator in the nRF52832, paving the way for future enhancements to its resistance to side-channel attacks. All the related data are made available to the research community to promote further analysis.