X-ray technique can reverse-engineer an entire chip without damaging it(spectrum.ieee.org)
spectrum.ieee.org
X-ray technique can reverse-engineer an entire chip without damaging it
https://spectrum.ieee.org/nanoclast/semiconductors/design/xray-tech-lays-chip-secrets-bare
57 comments
Maybe! I've got some experience with tomographic algorithms, and what they're referring to is correcting for the "missing wedge" in the Radon and/or Fourier transforms - the measurements that tomography produces - of the chip (https://images.app.goo.gl/HWPX2LKBsDd7eeBe6). There has been lots of interest in statistical or data-driven algorithms to reconstruct missing measurement areas from the existing ones. It sounds like a key technology here was better algorithms to accommodate a larger missing wedge, so they didn't have to tilt the chip to extreme angles when getting projections.
It's possible you could fool the algorithm in some way, but you'd have pretty weird and severe constraints on the shapes of your hidden parts to hide their presence from low-angle projections. They're probably not actually hand-crafting geometric assumptions about chip structures or anything like that.
It's possible you could fool the algorithm in some way, but you'd have pretty weird and severe constraints on the shapes of your hidden parts to hide their presence from low-angle projections. They're probably not actually hand-crafting geometric assumptions about chip structures or anything like that.
Yep that's exactly the idea. Basically the silicon version of the underhanded C contest [1]
[1] http://www.underhanded-c.org/
[1] http://www.underhanded-c.org/
Cool! Know of any websites or writeups about the silicon version?
Some anti-reverse-engineering work was put into the Z80 chip 45 years ago.
https://retrocomputing.stackexchange.com/questions/11143/in-...
Before 1984 there was no copyright on the contents of chips, it was completely legal to create masks from a competitor's chips and sell them - people used to create on-chip structures designed to fool the optical processes that were used to do this
Unfortunately no but it would be highly interesting to read!
I would guess that at the lowest level too much is dictated by physics. It may be possible to obfuscate some higher abstraction layers though.
I wouldn't be too sure of that.
> Five individual logic cells were functionally disconnected from the rest— with no pathways that would allow them to influence the output— yet when the researcher disabled any one of them the chip lost its ability to discriminate the tones. Furthermore, the final program did not work reliably when it was loaded onto other FPGAs of the same type.
https://www.damninteresting.com/on-the-origin-of-circuits/
> Five individual logic cells were functionally disconnected from the rest— with no pathways that would allow them to influence the output— yet when the researcher disabled any one of them the chip lost its ability to discriminate the tones. Furthermore, the final program did not work reliably when it was loaded onto other FPGAs of the same type.
https://www.damninteresting.com/on-the-origin-of-circuits/
Note the last sentence of your quote. Device-to-device variability and production yield are opposites. I can't imagine how techniques that exploit variability between devices (with no mention of temperature, lifetime drift, etc) could be reliable.
Maybe not the best example, but this was on FPGA. When making custom chips, you can make all sorts of tuning, including consistent hardly noticeable drifts from spec.
The article says they only image the metal layers, so I guess you can do anything as long as you don't visibly change the metal layers.
The article says they only image the metal layers, so I guess you can do anything as long as you don't visibly change the metal layers.
This has already existed for a while!
That should make it a lot easier to identify hardware back-doors.
Agreed. Also I hope it brings the end of the Apple security-by-obscurity methods that allowed that one iPhone to be cracked by a third party hacker. If you know what's in the hardware a 4-6 digit PIN is fine for deterring casual onlookers but is never enough entropy to secure data.
People should learn to use real passwords if they want their data secure.
People should learn to use real passwords if they want their data secure.
Perhaps... one of the capabilities is to dope gates with different materials so the transistor layout stays the same but the behavior is modified. Unless the system could detect the actual elemental differences you might get a false sense of security just confirming the transistor layout.
I just want this to be cheap enough so that we can archive and re-create no-longer manufactured chips.
+1.
My personal choice: MAX038 (no relation with the 8038), way better than any similar analog wave generators but discontinued long ago and never upgraded.
I know there are cheap DDS chips, but they require filters and control logic. This one goes from 100 KHz to 20MHz with just a bunch of parts. Be careful of those sold online however as they're all fakes; this chip was killed well over a decade ago. I'm not aware of any clones yet, though I would welcome them if on par quality wise with the original.
https://datasheets.maximintegrated.com/en/ds/MAX038.pdf
I know there are cheap DDS chips, but they require filters and control logic. This one goes from 100 KHz to 20MHz with just a bunch of parts. Be careful of those sold online however as they're all fakes; this chip was killed well over a decade ago. I'm not aware of any clones yet, though I would welcome them if on par quality wise with the original.
https://datasheets.maximintegrated.com/en/ds/MAX038.pdf
Interesting chip. It's quite literally almost an entire standard function generator on one chip, with a bandwidth far exceeding some similar chips.
Whether it's actually better than those from the 80s, I'm not sure. Both HP and Philips used to use ASICs -- pretty much just matched diode arrays -- for their sine shaping, and that's about the most critical part in this kind of generator.
Whether it's actually better than those from the 80s, I'm not sure. Both HP and Philips used to use ASICs -- pretty much just matched diode arrays -- for their sine shaping, and that's about the most critical part in this kind of generator.
A lot of chips from the 70s and early 80s have already been reverse-engineered publicly: http://www.visual6502.org/
This will make that easier. AND we can do it non-destructively. That means we get more, & rarer chips, instead of only the common stuff.
How do you recreate them? On FPGA? Fabricating a chip is not cheap.
Personally I was thinking of being able to recreate some discrete chips with breadboards.
Then again MOSIS has prices down to a few thousand/square millimeter. Since current gen stuff is so much smaller, that's probably <$100 for the more complex chips from the 70s, & 80s.
The best I think we'll get is some Amiga/Commodore build it yourself kits That weren't possible before because of out-of-production chips.
Then again MOSIS has prices down to a few thousand/square millimeter. Since current gen stuff is so much smaller, that's probably <$100 for the more complex chips from the 70s, & 80s.
The best I think we'll get is some Amiga/Commodore build it yourself kits That weren't possible before because of out-of-production chips.
Even software emulation would be nice.
for completely digital
an fpga would do the job. Analog chips well that's a different.
Previously, in 2017: https://news.ycombinator.com/item?id=13952016
> not just reverse engineering but assurance that chips are manufactured according to design
This, combined with stuff like RISC-V is very good news and big progress towards making a secure (read backdoor-free) hardware platform.
Gotta love the Swiss !
This, combined with stuff like RISC-V is very good news and big progress towards making a secure (read backdoor-free) hardware platform.
Gotta love the Swiss !
I wonder what the implications of this could be for the emulation community...maybe someone more knowledgable about this stuff can enlighten me: would something like this be useful in creating more-accurate emulators?
I wonder if this technique can be used to scan a PCB as they can be in attack vector for supply chain attacks.
My thoughts exactly - I can easily see a business in taking
chips out of a supply chain and performing this analysis against the expected layouts.
Its possible that Intel / other chip manufacturers / board manufacturers would pay for just to improve confidence in their supply chain.
At some point this is a few millions a year, and a nice tick box in the pitch deck.
Its possible that Intel / other chip manufacturers / board manufacturers would pay for just to improve confidence in their supply chain.
At some point this is a few millions a year, and a nice tick box in the pitch deck.
attach photographic plate to lead plate, attach PCB to photographic plate, mail to collaborator across a jurisdiction with X-ray postal inspection, collaborator develops photographic plate, 50% success rate depending on face down or face up, scan image and send result.
Dare I bring up the Bloomberg article without causing a shitstorm? I remember reading around that time a (I think) presentation on how to trick / hide against x-ray tomography etc but I can't find the link to the source if anyone has it?
I recently had an IPMI on on of my Supermicro servers and it was super funny to hear the conspiracy theory from the SuperMicro support that it was not working because maybe the Chinese were worming through a backdoor that was hidden on the machine.
I'm quite sure that the issue was just a faulty IPMI as I've seen it happen before with older units but I had a good laugh.
I'm a believer in Murphy's law where whatever can happen will happen. Supply chain attacks are quite possible, would be very fruitful and therefore must be happening. But will we ever get the truth from the big vendors? I don't think it will happen any time soon but with this x-ray technology, it will be way easier to detect them.
I'm quite sure that the issue was just a faulty IPMI as I've seen it happen before with older units but I had a good laugh.
I'm a believer in Murphy's law where whatever can happen will happen. Supply chain attacks are quite possible, would be very fruitful and therefore must be happening. But will we ever get the truth from the big vendors? I don't think it will happen any time soon but with this x-ray technology, it will be way easier to detect them.
How do you pronounce that word?
I worked at intel in the 90s, and they put malformed cpus in key chains.
But what will be interesting to see will be is when they build a library of Devices where they can quickly ID Trojans
I worked at intel in the 90s, and they put malformed cpus in key chains.
But what will be interesting to see will be is when they build a library of Devices where they can quickly ID Trojans
I still have my 386/486 chip key ring I got from a Journalist friend.
Ty-ko-graphic
Can you also explain the “ty-co” part of it
As a suffix 'tych' (pronounced 'tic') refers to multiple related/connected things ... tables, leaves, panels, works ... (diptych, triptych, polyptych). EG 'triptych' "derives from the Greek adjective τρίπτυχον 'triptukhon' ('three-fold')".
'Ptychography' was coined by crystallographers in 1972. Wikipedia has more on the origin. https://en.wikipedia.org/wiki/Ptychography
'Ptychography' was coined by crystallographers in 1972. Wikipedia has more on the origin. https://en.wikipedia.org/wiki/Ptychography
Thank you
[deleted]
Does this have any implications for Secure Enclave like chips?
I have no expertise on this subject, but here goes. First, I don't think the technique can see electrical charges, which is how any chip stores volatile state. Second, if such chips rely on security by obscurity -- and judging from the NDAs typically required to get any official information about them, I'd say it's part of their defense in depth -- then that security would now be weaker. Finally, this technique would arguably enhance security if independent labs were now able to verify that a chip is devoid of back doors and implementation errors.
I wonder if the 40+ layer NAND chips would give a problem for this technique.
Time for a silicon easter egg hunt!
Can it be used on cryogenically frozen brains? The flick "Sleeper" could become a reality, although you'd probably have an android or R2D2 like body.
Can someone please share the actual paper? Sci-Hub fails to retrieve it either by DOI or by the Nature link.
Next step: chips include critical components that can be damaged by x-rays.
Nice, china is glad to hear that
china has no problem destructively reverse engineering chips. they aren't validating them, they are copying them. and the destructive method may be time consuming, but surely for China it's cheaper?
this technique would be more like CMM validation of a part after manufacturing. very, very useful but with a different goal in mind.
this technique would be more like CMM validation of a part after manufacturing. very, very useful but with a different goal in mind.
Plus aren't many chips made in China? My impression after watching BigClive tear apart stuff was that a lot of Chinese clones use their own chips, and many chips are custom and seem to only exist between Chinese manufacturers (like custom USB charging chips, led chips for flashlights, etc.)
In order to manufacture these chips you need the schematics. It's the same thing as having the source code and the deployment/compilation instructions: You don't need anything else.
Strictly speaking, for manufacturing you need the layout for the chip, but extracting a schematic from a given layout is an automated process and used for verification. You create a layout from a given schematic and later check, whether the layout implements that schematic.
Physical Unclonable Functions were supposed to address this.
I wouldn't expect them to hold a state actor at bay for more than a little while, but at least with a PUF in place overproduction isn't as simple as "just make more."
I wouldn't expect them to hold a state actor at bay for more than a little while, but at least with a PUF in place overproduction isn't as simple as "just make more."
And one should not overlook that a lot of cutting edge chip design is done in China. Just think of all the chips by Huawei. On top of that, the direct layout information is more relevant for reengineering than copying.
This sounds like the beginnings of the silicon obfuscation strategy: hiding things in silicon that lie below these assumptions