4 ms·
I found this interesting but not actually very informative and walked away really learning nothing from having read the article submitted itself. It’s all “we u
by ComputerGuru 3y ago
I found this interesting but not actually very informative and walked away really learning nothing from having read the article submitted itself. It’s all “we used this tool” and “we followed this guide” with no explanation of theory or process. (The links provided, I’m sure, are more helpful.)
There wasn’t even a discussion on why the particular AES configuration deployed was used or how it affects the process.
- graphe 3y agoYou really learned nothing? >Therefore, we decided, in similar fashion as Ledger’s scaffold, to make our own custom board where all the relevant signals are routed to dedicated pins. Explaination or theory: someone else did it the same way. >Throughout our research we used two acquisition techniques that are supported by our oscilloscope: normal block mode and rapid block mode. We used Picoscope’s Python bindings to communicate with the oscilloscope. We used their ps3000aRapidBlockExample.py as a reference to integrate rapid block mode into Riscure’s FiPy. Sounds like they used what worked on their hardware.
- jacquesm 3y agoThe chip should not be leaking this much information but the scaffolding around the attack is such that I doubt whether this could be pulled off so easily on a random ESP32 with its flash encryption enabled.
- xw30992 3y agoThat's because this article is more of a part 3 of a series of articles. Part 1: https://eprint.iacr.org/2023/090 https://eprint.iacr.org/2023/090 How to break ESP32 AES with power analysis Part 2: https://courk.cc/breaking-flash-encryption-of-espressif-parts https://courk.cc/breaking-flash-encryption-of-espressif-part... How to do it for no more than $100 Part 3: This article Improving the performance