arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.19111cs.CRcs.AR

模拟引脚方向性作为混合信号集成电路中的泄露攻击面

Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs

Ramana Ranganatham, Chirag Adiga, Michael Zuzak, Tejasvi Das

首次发表
浏览论文内容

中文总结 AI 辅助

本研究揭示混合信号IC中名义输入模拟引脚可被利用为泄露通道,提出基于方向性的攻击模型,并通过硅片验证,强调需将引脚方向性作为安全属性显式验证。

中文摘要 AI 辅助

混合信号片上系统依赖名义上仅输入的模拟引脚来获取片外信号,但这些接口的方向性通常被视为功能属性,而非作为安全属性进行显式验证。本研究识别并通过实验证明了一类基于方向性的模拟和混合信号(AMS)泄露攻击,其中数据相关的电路偏移调制将名义上仅输入的引脚转变为出站信息通道。我们对攻击机制进行了分析建模,并确定了三个使能的主机条件:闭环放大器、暴露的放大器输入以及该引脚处足够高的阻抗。该攻击类别通过使用商业55纳米CMOS工艺制造的光电容积脉搏波(PPG)模拟前端(AFE)的代表性硅案例研究得到验证。该载荷相对于典型生物传感AFE的面积开销小于0.001%。在评估条件下,载荷激活仅将滤波后的PPG输出信噪比降低0.03分贝,而硬件木马引起的最大扰动为PPG幅度的5.9%,仍处于暴露传感器输入引脚在工艺和温度变化下的34.3%良性变化范围内。原始泄露信干噪比保持在-20分贝以下,而针对性滤波将其提升至14分贝以上并实现信号恢复。硅片测量表明,通过输入引脚以高达10千比特每秒的比特率进行数据泄露,并无误码地恢复PRBS消息。这些结果暴露了常规测试可观测性的差距,并将模拟引脚方向性确立为一项AMS安全属性,需要显式验证、测试覆盖和防御,而非从标称信号流中推断。

英文摘要

Mixed-signal SoCs rely on nominally input-only analog pins to acquire off-chip signals, but the directionality of these interfaces is generally treated as a functional property rather than explicitly verified as a security property. This work identifies and experimentally demonstrates a directionality-based class of analog and mixed-signal (AMS) exfiltration attacks in which data-dependent circuit-offset modulation converts a nominally input-only pin into an outbound information channel. We analytically model the attack mechanism and identify three enabling host conditions: a closed-loop amplifier, an exposed amplifier input, and sufficiently high impedance at that pin. This attack class is validated through a representative silicon case study using a photoplethysmography (PPG) analog front-end (AFE) fabricated in a commercial 55-nm CMOS process. The payload incurs $<$0.001\% area overhead relative to typical biosensing AFEs. Under the evaluated conditions, payload activation reduces the filtered PPG-output SNR by only 0.03~dB, while the maximum HT-induced perturbation of 5.9\% of the PPG amplitude remains within the 34.3\% benign variation at the exposed sensor-input pin across process and temperature. The raw exfiltration SINR remains below -20~dB, while targeted filtering increases it above 14~dB and enables signal recovery. Silicon measurements demonstrate data exfiltration through the input pin at bit rates up to 10~kbps and error-free recovery of a PRBS message. These results expose a conventional test-observability gap and establish analog pin directionality as an AMS security property requiring explicit verification, test coverage, and defense rather than being inferred from nominal signal flow.

发表机构

  • Rochester Institute of Technology(罗切斯特理工学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑