Skip to content

Latest commit

 

History

33 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Hardware security labs

Coursework for Practical Introduction to Hardware Security (Chair of Dependable Nano Computing, Karlsruhe Institute of Technology). Each task is a self-contained FPGA experiment on the same board: a hardware primitive is implemented or attacked in Verilog, driven from a Python host over UART, and evaluated with a short statistical or cryptanalytic write-up.

All tasks target the Lattice iCE40-HX8K breakout board and share one open-source flow. The tasks are otherwise independent; each directory builds, programs, and runs on its own.

Environment

Component Use
Lattice iCE40-HX8K (ct256) target FPGA
Verilog HDL RTL
Yosys synthesis
nextpnr-ice40 place and route
icepack / icetime / iceprog pack, timing, program
Icarus Verilog + cocotb board-free RTL simulation and regression (tasks 2, 5)
Python (pyserial, numpy, matplotlib) host tooling and analysis

The board's USB-UART bridge appears as an FTDI device. On macOS it is /dev/cu.usbserial-*, on Linux /dev/ttyUSB*; the host scripts either auto-detect it or expose the device path as a constant to edit.

Toolchain note. Tasks 4 and 5 require an older oss-cad-suite (2021-11-01). Newer Yosys releases synthesize the ring-oscillator fault primitive differently and the design no longer fits; see task4-dfa/README.md. Tasks 0–3 build with a current oss-cad-suite.

Tasks

Task 0 — FPGA bring-up and UART

Toolchain validation and board bring-up: the Verilog build flow, bitstream programming, a minimal UART path, and LED sanity checks. Establishes the environment every later task depends on.

Directory: task0-lab-setup/

Task 1 — SRAM weak-PUF readout and analysis

A weak physical unclonable function built from the FPGA's SRAM/BRAM power-up state. The controller reads memory before it is overwritten, streams the 16 KiB response over UART, and the response is evaluated across repeated power cycles using uniformity, bit-aliasing, uniqueness, and reliability metrics.

Directory: task1-pufs/ · Notes: SRAM Weak PUF Readout on iCE40

Task 2 — AES-128 hardware implementation

A from-scratch AES-128 datapath (SubBytes, ShiftRows, MixColumns, AddRoundKey, key expansion) following NIST FIPS 197, wrapped in a UART protocol block. Verified against the provided cocotb reference model and characterized for area and timing on the HX8K.

Directory: task2-aes/ · Notes: AES-128 on an iCE40 FPGA

Task 3 — Correlation power analysis on AES

A side-channel attack on the AES core using an on-chip delay-line sensor instead of an external oscilloscope. Sensor traces are captured during the final round, and correlation power analysis over an inverse-S-box leakage model recovers round-10 key bytes. Validated on the supplied example traces, then run on 100k traces collected from the board.

Directory: task3-cpa/ · Notes: Correlation Power Analysis on AES with an FPGA Sensor

Task 4 — Fault injection and DFA on AES

A fault attack using an on-chip ring-oscillator grid as a voltage-drop fault injector — the "FPGAhammer" primitive — against the AES core. The deliverable is a host tool that collects correct/faulty ciphertext pairs in the specific pattern that differential fault analysis (DFA) requires, together with the parameter calibration behind it. Per the course, this is the final task.

Directory: task4-dfa/ · Notes: Fault Injection and DFA on an FPGA AES Core

Task 5 — Voltage-droop characterization and on-chip fault detection

A self-directed extension, not part of the course handouts. It puts Task 3's on-chip TDC sensor and Task 4's ring-oscillator injector on the same die, so the sensor trace and the fault outcome come from the same encryption. This explains Task 4's unexplained result: running fewer than all 4800 oscillators gives exactly 0% faults, while the full grid faults 39% of the time — the threshold is a cliff, not a slope. Droop depth alone doesn't separate faulted encryptions from clean ones, the deciding variable is when the droop lands rather than how deep it goes, so an on-chip threshold detector scores AUC 1.000 at spotting that an attack is running but only 0.500 (chance) at spotting which ciphertexts came out wrong.

Directory: task5-voltage-droop/ · Notes: Measuring the voltage droop that breaks an AES core

Layout

task0-lab-setup/   bring-up, UART path, LED checks
task1-pufs/        SRAM PUF RTL, capture, statistical analysis
task2-aes/         AES-128 RTL, cocotb verification, FPGA reports
task3-cpa/         AES + on-chip sensor, CPA analysis scripts
task4-dfa/         RO fault injector control, DFA collection tooling
task5-voltage-droop/  sensor + injector on one die, droop characterization

Each task directory carries its own README.md with the detailed design, build/run commands, and results.

References

  • NIST FIPS 197 — Advanced Encryption Standard (AES).
  • J. Krautter, D. Gnad, M. Tahoori — FPGAhammer: Remote Voltage Fault Attacks on Shared FPGAs, suitable for DFA on AES (TCHES 2018).
  • G. Piret, J.-J. Quisquater — A Differential Fault Attack Technique against SPN Structures, with Application to the AES and Khazad (CHES 2003).
  • E. Biham, A. Shamir — Differential Fault Analysis of Secret Key Cryptosystems (CRYPTO 1997).

About

FPGA-based hardware security labs and experiments, Lattice iCE40HX8K, UART tooling, Verilog, Yosys, and nextpnr.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages