We use some essential cookies to make our website work.

We use optional cookies, as detailed in our cookie policy, to remember your settings and understand how you use our website.

Everything is better with lasers

Back in August 2024 we launched RP2350, our latest secure microcontroller. At the same time, we kicked off our first of two Hacking Challenges centred around defeating the security measures we’d built into RP2350. The challenge was fun and informative, and multiple winners were awarded, leading us to respin RP2350 to fix most of the breaks that were found in the chip.

A few months ago, the smart folks over at Ledger Donjon got in touch with us to disclose their RP2350 security research findings. They found a security vulnerability that would have won them a prize during that first Hacking Challenge!

Pew pew. Drat!

The Ledger Donjon team have shown that if you have a lab full of smart, motivated people with about $250,000 worth of specialised microscopy and laser equipment, you too can re-enable the debug interface on a secured RP2350-A4 chip (something we were trying to make impossible).

They used some very clever mechanisms to determine the exact parts of the RP2350 chip that could be affected by a highly focused infrared laser beam, which meddled with specific register contents to re-enable debug access and allow OTP readout.

This is fantastic work by the Donjon team, and we’re suitably impressed. We’d like to thank the team for their hard work, professionalism, and responsible disclosure.

Read more about it here.

We’ve taken a look at the research and have determined that these findings don’t warrant a respin of the chip:

  • This is a destructive attack that requires the chip to be removed and de-encapsulated
  • Assuming that per-device keys are used, it should have only a single-device scope
  • It requires a very particular set of skills, together with a lab full of bougie equipment and/or a spare $250K

Honourable (re)mention

If all this sounds a little familiar, it sort of is. Back during the first Hacking Challenge, one of the prizewinners used a homebrew IR laser setup that they developed to glitch the A2 stepping of RP2350 into doing something naughty. Read more about it here. Courk’s break was ultimately fixed by a boot ROM revision that is part of the current A4 die revision of RP2350.

Courk’s I/O board and main carrier board, placed in the laser fault injection platform

What’s next?

Our second Hacking Challenge has been running for some time now. It focuses on side channel analysis (SCA), and after two deadline extensions it remains unbeaten, although there are a few teams seemingly quite close to victory. This second challenge runs until the end of next month, so expect an update soon!

No comments
Jump to the comment form

Leave a Comment