Voltage Glitching
Voltage Glitching: Inducing Faults via Power Supply Manipulation¶
Voltage glitching is a fault injection technique that exploits the physical relationship between power supply stability and computational integrity. By introducing transient voltage anomalies (spikes, drops, or oscillations) to a target device’s power supply, an attacker can induce computational errors in cryptographic operations. This method is particularly effective against embedded systems implementing symmetric or asymmetric encryption, where timing and voltage thresholds directly influence algorithmic correctness.
Techniques for Inducing Glitches¶
Voltage glitching relies on precise control over the power supply to disrupt specific stages of cryptographic computations. Common approaches include:
-
Voltage Spike/Step-Down
A sudden drop in voltage (e.g., from 3.3V to 1.8V) during critical operations (e.g., AES key expansion) can cause logic gates to fail, corrupting intermediate values.
Example:
-
Timing Synchronization
Glitches are often synchronized with cryptographic operations using a trigger signal (e.g., via UART or SPI). This ensures the fault occurs during specific algorithmic steps (e.g., during a round of AES).
Example:
Tools and Equipment¶
- Glitch Generator Hardware: Devices like the ChipWhisperer or custom-built circuits with MOSFETs and capacitors to modulate voltage.
- Power Supply: A bench power supply with programmable voltage and current limits (e.g., Keysight 33500 Series).
- Oscilloscope: To monitor voltage waveforms and verify glitch timing (e.g., Siglent SDS1202X-E).
- Trigger Interface: UART, SPI, or GPIO pins to synchronize glitches with target operations.
Impact on Cryptographic Operations¶
Voltage glitches can corrupt critical cryptographic states, leading to:
- Incorrect Key Scheduling: In AES, a glitch during key expansion may produce invalid round keys.
- Faulty State Transitions: In RSA, a voltage drop during modular exponentiation can result in incorrect ciphertext.
- Side-Channel Leakage: Faulty computations may expose partial secrets via timing or power consumption anomalies.
Example: A 100ns voltage drop during AES SubBytes may cause a single byte of the state array to be corrupted, enabling key recovery via differential fault analysis (DFA).
Mitigation Strategies¶
- Robust Power Regulation: Use low-noise voltage regulators (e.g., LDOs) and decoupling capacitors to stabilize supply rails.
- Error Detection: Implement checksums or redundancy in cryptographic algorithms to detect and correct faults.
- Physical Security: Shield power lines and use tamper-evident enclosures to prevent access to the power supply.
- Timing Analysis: Monitor and log power consumption patterns to detect anomalies during cryptographic operations.
Key takeaways¶
- Voltage glitching exploits power supply instability to induce computational faults in cryptographic systems.
- Glitches are typically synchronized with algorithmic steps using hardware triggers or timing signals.
- Mitigation requires robust power regulation, error detection mechanisms, and physical security measures.
- Real-world attacks often combine voltage glitching with side-channel analysis to extract cryptographic secrets.