4.2 Description of the First Documented Facts …
299
of ProASIC3 series, presents them as the devices that provide “the most impenetrable security for logical program structures” [115, 116]. Second, ProASIC3 is
still (as of the moment of publication of this book) is widely used in military and
industrial spheres, including in so-called critical systems—nuclear industry, spacerocket equipment, etc. Therefore, any results of analysis of this microcircuit are
extremely important for consumers. After all, these consumers are aware of the
fact that ProASIC3 has several different levels of ensuring security. The manufacturers claim that the function of reverse engineering of a FGPA array microcircuit
is virtually impossible to implement from the physical point of view, which makes
these devices absolutely safe in essence: “Low power flash devices do not support
reverse engineering of FGPA programming data; however, FlashROM contents can
be selectively reproduced (or deactivated) through the JTAG port based on the security settings determined by Microsemi Designer software” [111, 117]. High security
level ensures activation of a special user key that prevents rewriting of any security settings: “Designers are capable of using FlashLock Pass Key to prohibit any
recording or verification operations on the device” [118]. We could cite other similar
statements of the chip manufacturer that appeared to be unsubstantiated, to say the
least.
Let us consider the essence of the problem in detail. So, it is known that for
remote update of the contents of the device memory, the bitstream configuration and
the internal flash memory can be encoded with the main key of the AES device.
This function can only be used to decode the data sent to the chip for recording and
verification. According to the security theory, there is no way here to transfer data
back to the outside world even in encrypted form.
The highest level of protection turns the device (our microcircuit) into a nonprogrammable chip; however, it shall be considered with caution by the users, since
in case the above-embedded Trojan is detected, the chip in the device must be physically replaced. Developers of the microcircuit once again claim the following: “The
purpose of the permanent lock feature is to provide the benefits of the highest level
of security to IGLOO and ProASIC3 devices. If selected, the permanent FlashLock
feature will create a constant barrier, preventing any access to the contents of the
device. This is achieved by permanently disabling Write and Verify access to the
array, and Write and Read access to the FlashROM. After permanently locking the
device, it has been effectively rendered one-time-programmable” [111].
However, according to a popular proverb, “better safe than sorry.” The deliberately
embedded defect, which was detected and officially documented by the authors of
[110], can provide the intruder with the possibility to easily recover access to the
configuration data. However, specialists are aware of other hidden JTAG functions,
which provide any intruder with theoretical access to the structure and contents of
the internal memory and theoretically allow modification of any hidden registers at
all. Here, we should take a closer look at the simplified structure of the ProASIC3
security system, which is shown in Fig. 4.16.
The authors of the work [110] confidently state that they have evaluated all protection levels in ProASIC3 microcircuits and managed to bypass security at each of the
examined level.
Précédent

- 318/839

Suivant