Black-Box Firmware Compliance Testing of Programmable IC Chips Using Power Side-Channels
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
University of Waterloo
Abstract
Modern safety-critical embedded systems depend heavily on Commercial Off-The-Shelf
(COTS) programmable Integrated Circuits (ICs) sourced through complex global supply
chains. Sourcing these ICs introduces a major vulnerability, as actors in the supply chain
can maliciously tamper with or inadvertently modify the IC firmware prior to integration.
These unauthorized modifications directly compromise firmware integrity, making it difficult
for system integrators to verify that the IC runs qualified code without access to the
source code or binary images. To address this challenge, we propose a firmware compliance
method based on physical side-channel behavior. This method compares dynamic power
consumption traces from an untrusted IC with a trusted golden reference that executes
identical inputs to detect firmware non-compliance.
Detecting non-compliant ICs requires a comparison method that is invariant to physical
noise and sensitive to genuine firmware differences. Distortions vary across hardware and
are challenging to predict before testing. Relying on a single fixed comparison method risks
overlooking firmware changes, thereby reducing the efficacy of detecting non-compliance
ICs. To address the challenge of selecting an effective comparison method under varying
distortion levels, this thesis presents an evaluation framework that assesses a set of
comparison methods for firmware compliance. Rather than prescribing a single method,
the framework evaluates a suite of methods and produces performance metrics that determine
which methods work well for a given target IC. Applying this framework across three
commercial ICs shows that power-based side-channels can effectively detect non-compliant
firmware and provides metrics to select the appropriate comparison method.