Coursework for Practical Introduction to Hardware Security (Chair of Dependable Nano Computing, Karlsruhe Institute of Technology). Each task is a self-contained FPGA experiment on the same board: a hardware primitive is implemented or attacked in Verilog, driven from a Python host over UART, and evaluated with a short statistical or cryptanalytic write-up.
All tasks target the Lattice iCE40-HX8K breakout board and share one open-source flow. The tasks are otherwise independent; each directory builds, programs, and runs on its own.
| Component | Use |
|---|---|
| Lattice iCE40-HX8K (ct256) | target FPGA |
| Verilog HDL | RTL |
| Yosys | synthesis |
| nextpnr-ice40 | place and route |
| icepack / icetime / iceprog | pack, timing, program |
| Icarus Verilog + cocotb | board-free RTL simulation and regression (tasks 2, 5) |
| Python (pyserial, numpy, matplotlib) | host tooling and analysis |
The board's USB-UART bridge appears as an FTDI device. On macOS it is /dev/cu.usbserial-*, on Linux /dev/ttyUSB*; the host scripts either auto-detect it or expose the device path as a constant to edit.
Toolchain note. Tasks 4 and 5 require an older oss-cad-suite (2021-11-01). Newer Yosys releases synthesize the ring-oscillator fault primitive differently and the design no longer fits; see
task4-dfa/README.md. Tasks 0–3 build with a current oss-cad-suite.
Toolchain validation and board bring-up: the Verilog build flow, bitstream programming, a minimal UART path, and LED sanity checks. Establishes the environment every later task depends on.
Directory: task0-lab-setup/
A weak physical unclonable function built from the FPGA's SRAM/BRAM power-up state. The controller reads memory before it is overwritten, streams the 16 KiB response over UART, and the response is evaluated across repeated power cycles using uniformity, bit-aliasing, uniqueness, and reliability metrics.
Directory: task1-pufs/ · Notes: SRAM Weak PUF Readout on iCE40
A from-scratch AES-128 datapath (SubBytes, ShiftRows, MixColumns, AddRoundKey, key expansion) following NIST FIPS 197, wrapped in a UART protocol block. Verified against the provided cocotb reference model and characterized for area and timing on the HX8K.
Directory: task2-aes/ · Notes: AES-128 on an iCE40 FPGA
A side-channel attack on the AES core using an on-chip delay-line sensor instead of an external oscilloscope. Sensor traces are captured during the final round, and correlation power analysis over an inverse-S-box leakage model recovers round-10 key bytes. Validated on the supplied example traces, then run on 100k traces collected from the board.
Directory: task3-cpa/ · Notes: Correlation Power Analysis on AES with an FPGA Sensor
A fault attack using an on-chip ring-oscillator grid as a voltage-drop fault injector — the "FPGAhammer" primitive — against the AES core. The deliverable is a host tool that collects correct/faulty ciphertext pairs in the specific pattern that differential fault analysis (DFA) requires, together with the parameter calibration behind it. Per the course, this is the final task.
Directory: task4-dfa/ · Notes: Fault Injection and DFA on an FPGA AES Core
A self-directed extension, not part of the course handouts. It puts Task 3's on-chip TDC sensor and Task 4's ring-oscillator injector on the same die, so the sensor trace and the fault outcome come from the same encryption. This explains Task 4's unexplained result: running fewer than all 4800 oscillators gives exactly 0% faults, while the full grid faults 39% of the time — the threshold is a cliff, not a slope. Droop depth alone doesn't separate faulted encryptions from clean ones, the deciding variable is when the droop lands rather than how deep it goes, so an on-chip threshold detector scores AUC 1.000 at spotting that an attack is running but only 0.500 (chance) at spotting which ciphertexts came out wrong.
Directory: task5-voltage-droop/ · Notes: Measuring the voltage droop that breaks an AES core
task0-lab-setup/ bring-up, UART path, LED checks
task1-pufs/ SRAM PUF RTL, capture, statistical analysis
task2-aes/ AES-128 RTL, cocotb verification, FPGA reports
task3-cpa/ AES + on-chip sensor, CPA analysis scripts
task4-dfa/ RO fault injector control, DFA collection tooling
task5-voltage-droop/ sensor + injector on one die, droop characterization
Each task directory carries its own README.md with the detailed design, build/run commands, and results.
- NIST FIPS 197 — Advanced Encryption Standard (AES).
- J. Krautter, D. Gnad, M. Tahoori — FPGAhammer: Remote Voltage Fault Attacks on Shared FPGAs, suitable for DFA on AES (TCHES 2018).
- G. Piret, J.-J. Quisquater — A Differential Fault Attack Technique against SPN Structures, with Application to the AES and Khazad (CHES 2003).
- E. Biham, A. Shamir — Differential Fault Analysis of Secret Key Cryptosystems (CRYPTO 1997).