[00:00.000 --> 00:01.180] ...with a little bit later on. [00:01.660 --> 00:06.120] Also, the last announcement I have is we do have what we call the fourth track, the unscheduled track. [00:06.280 --> 00:10.500] We have three scheduled tracks, as you've noticed in your beautiful program this time around. [00:10.820 --> 00:17.160] The fourth track you can sign up for in what we're calling the fourth track room, the Zeus room. [00:17.340 --> 00:18.520] It's just out to the right there. [00:19.040 --> 00:23.220] And feel free to sign up if you want to talk and didn't get yourself on the schedule. [00:24.080 --> 00:27.420] So I think that's all I wanted to mention in terms of announcements up front. [00:27.600 --> 00:29.120] Let's go ahead with our first talk. [00:30.140 --> 00:30.700] Karsten. [00:37.050 --> 00:38.830] Thank you very much for the introduction. [00:39.210 --> 00:39.350] Yeah. [00:40.170 --> 00:42.510] I'm Karsten Nohl from the University of Virginia. [00:43.270 --> 00:53.150] I'd like to illustrate to you today how we reverse engineered a small silicon chip. [00:53.290 --> 00:59.310] And I want to encourage you to do the same with other chips, to add to the knowledge of reverse engineering. [00:59.510 --> 01:10.890] And I want to take mostly away the scare that many people have of hardware, and the belief that by putting something in hardware, it would actually be hard to reverse, and it would be obfuscated. [01:12.310 --> 01:17.050] I'll be mostly talking about algorithms out of cryptography. [01:17.410 --> 01:29.130] But anything that I'll say will equally apply to any other algorithm that you want to reverse engineer from, say, a graphics processor, from a sound card, from a signal encoding, decoding, any of that. [01:29.910 --> 01:37.190] So if you have some piece of hardware that you don't know exactly what it's doing, and you want to find out how, this is where you learn how to do it. [01:38.190 --> 01:54.530] As a motivation for why we have been looking at this intensely from a security perspective, is that there are a lot of algorithms out there that are proprietary, and that are hidden away in hardware, so nobody can find them, so nobody can break our system. [01:55.330 --> 01:57.650] Well, that turns out to not be true. [01:57.770 --> 02:08.890] And in fact, by hiding away this algorithm, they usually turn out to be very weak, since they were developed in the back room by a few people that didn't exactly consider all possible attack factors. [02:08.890 --> 02:15.770] And we'll, towards the end, look at a couple of weaknesses that we have found in a chip that we reversed. [02:16.550 --> 02:22.870] So now, I would optimally want you to, today, walk away with all the pointers needed to start your own reversing effort. [02:23.030 --> 02:27.570] And if you have any questions throughout the talk, please ask them at any point, okay? [02:28.830 --> 02:32.750] Now, as a motivating example, I'll be talking about RFID techs. [02:32.910 --> 02:38.630] These little, tiny chips that have all but one functionality identification. [02:38.630 --> 02:41.690] They send out a static number every time they ask. [02:41.750 --> 02:48.610] And in fact, the technology in the badges, that's some manifestation of RFID tech. [02:48.830 --> 02:50.770] Now, these happen to have a battery. [02:51.430 --> 02:55.790] They come in even smaller form factors where not even a battery would fit. [02:55.790 --> 02:58.930] And so, they're basically the smallest hardware you could possibly find. [02:59.090 --> 03:01.150] Which makes them optimal for reverse engineering. [03:01.370 --> 03:05.410] Since there's only a very small piece of hardware you have to look at. [03:07.090 --> 03:11.370] In our project now, we looked at the MyFair Classic RFID chip. [03:12.270 --> 03:18.010] Very widely deployed card that is used for access control into buildings, for payment. [03:18.390 --> 03:22.150] For example, the Oyster card in London that they used to write the tube. [03:22.150 --> 03:23.890] That's a MyFair Classic chip. [03:24.050 --> 03:27.530] And a number of other smart card applications. [03:28.830 --> 03:35.110] In our project now, we reverse engineered that chip to find out how secure it actually is. [03:35.150 --> 03:39.130] Since it's so widely used for more or less security related applications. [03:39.130 --> 03:49.330] And we did take it one step further and then also exploit a couple of these vulnerabilities that we found using some RFID reader hardware. [03:49.590 --> 03:57.050] That was actually manufactured or designed by the same guy who built these batches or designed the batches. [03:58.950 --> 04:01.470] Now, back to the topic at hand. [04:01.570 --> 04:02.970] How do we reverse engineer hardware? [04:02.970 --> 04:05.790] Well, first we got to get the chips, the silicon chips. [04:06.350 --> 04:08.690] And RFIDs usually come in a plastic card. [04:09.170 --> 04:14.850] Most microcontrollers, microchips would come in a plastic packaging. [04:15.110 --> 04:17.470] So first you want to get rid of that plastic. [04:17.670 --> 04:26.590] And a couple of actions, some solutions, will get rid of the plastic entirely for you while leaving the silicon intact. [04:26.830 --> 04:31.970] Yet a more elegant way of getting those silicon chips is just to buy the blank chips. [04:31.970 --> 04:38.510] Most manufacturers of smart cards, for instance, will not also manufacture the antenna, for instance. [04:38.990 --> 04:46.130] So there is some... you can buy the blank chips if you claim to be in the business of attaching antennas to them. [04:46.270 --> 04:48.150] So we got some blank chips eventually. [04:48.370 --> 04:50.510] We also played around a lot with these actions. [04:50.890 --> 04:53.710] Which can be dangerous at times, but a lot of fun too. [04:54.470 --> 04:57.010] Now, getting the chip out. [04:58.590 --> 05:01.090] The chip will look something like that. [05:01.950 --> 05:03.230] Not all that impressive. [05:03.550 --> 05:04.710] This is the MIFAD chip. [05:04.850 --> 05:07.430] It's about one millimeter by one millimeter. [05:07.430 --> 05:09.710] So it's a tiny, tiny plate of silicon. [05:10.310 --> 05:14.190] And all you see from the outside, really, are a few connectors. [05:14.770 --> 05:18.270] And the RFID tag only has two, actually, to attach an antenna. [05:18.530 --> 05:19.950] So that's not all that impressive. [05:19.950 --> 05:29.730] But if you zoom in a little bit, and we cut out a little corner here, you do see that inside of this chip, there is some structure. [05:30.010 --> 05:37.130] So there's some metal wire running across here, and there's some other wires that come in and go out of this chip. [05:37.130 --> 05:40.430] And that's exactly the type of structure we want to reverse engineer now. [05:40.850 --> 05:52.810] So inside this chip, there's some 3D structure that encodes a circuit, an electronic circuit, consisting just of transistors of different sizes and wires that connect these transistors. [05:53.010 --> 05:55.130] That's all a microchip ever has. [05:55.890 --> 06:03.770] Now, to get to these transistors, or the wires before the transistors, we need to slice the chip. [06:03.950 --> 06:09.450] We need to take away layer by layer by layer and take pictures of those metal wires and transistors. [06:09.910 --> 06:17.150] Now, we were asked a number of times what type of laser we use or how expensive our focused ion beam is and all that. [06:17.310 --> 06:18.470] We don't need any of that. [06:18.750 --> 06:25.030] So these pictures we're taking with an electron microscope, but you clearly don't need an electron microscope to do any reversing. [06:25.030 --> 06:30.550] I mean, these pictures, other than looking cool, have had no effect on our project whatsoever. [06:31.130 --> 06:33.930] This little cutout was done with a focused ion beam. [06:34.250 --> 06:35.690] It took us about three hours. [06:35.870 --> 06:41.010] So you can imagine, like, doing the whole chip with a focused ion beam takes months or years even, right? [06:41.230 --> 06:45.310] So you want to get somewhat rougher than that and cheaper at that. [06:46.270 --> 06:51.650] And all you need really is some sandpaper or polishing paste to open this chip. [06:54.190 --> 07:10.770] Starbuck, who did all that work in Berlin, he had access to this neat polishing machine, where he put some polishing solution down and then a chip on top of that and will move the chip very slowly over the solution and very controlled take off the layer by layer. [07:11.090 --> 07:12.630] You can use sandpaper, too. [07:12.990 --> 07:13.490] No problem. [07:13.490 --> 07:15.690] Go to Lois, get the finest possible sandpaper. [07:15.850 --> 07:16.690] That will do it. [07:18.350 --> 07:25.030] One thing you got to be cautious with, though, is that you don't want the chip to ever be tilted. [07:25.450 --> 07:26.750] And by tilting, I mean... [07:26.750 --> 07:30.370] So imagine this chip to be some 3D structure, like a building. [07:30.570 --> 07:34.550] And now if it's tilted, you cut through different floors at the same time, diagonally. [07:34.550 --> 07:39.110] So you don't want that, because you want nice pictures of each layer. [07:40.410 --> 07:46.790] And you can imagine how if your chip is only a millimeter square, it's kind of hard to handle. [07:47.490 --> 07:52.590] The way Starbuck got around this was you put the chip in a block of plastic. [07:52.910 --> 08:01.770] So you melded some plastic around it and then had this bigger object that you could then very plainly polish. [08:01.770 --> 08:06.870] So that if your chip is too small to handle, that's probably what you want to do, too. [08:07.270 --> 08:09.350] I think it's an ingenious idea of Starbuck. [08:09.830 --> 08:13.570] So this picture kind of shows the first images we had. [08:13.730 --> 08:15.350] And we did have some tilt. [08:15.510 --> 08:17.650] So you see the blank silicon down here. [08:18.750 --> 08:19.970] Kind of the substrate. [08:20.290 --> 08:21.990] Then a few transistors up here. [08:22.170 --> 08:23.950] It's kind of the first floor of the building. [08:24.150 --> 08:27.010] And then up here, the second floor with some wiring. [08:27.810 --> 08:29.550] And that's clearly too much tilt. [08:30.990 --> 08:38.290] Now, once you do cut layer by layer, you want to take pictures in between to reconstruct this chip later. [08:38.490 --> 08:41.430] And for that, you can use a simple optical microscope. [08:41.570 --> 08:43.390] So no electron microscope needed. [08:43.590 --> 08:49.890] At least not for the size of transistors you'll find in R4D techs, for example. [08:50.390 --> 08:52.330] Pentium chip or something might be different. [08:52.530 --> 08:54.510] There you need some more expensive equipment. [08:55.810 --> 08:57.210] Very cheap, these microphones. [08:57.410 --> 08:58.830] You'll find them in most labs. [08:59.230 --> 09:00.570] Definitely below $1,000. [09:01.010 --> 09:05.110] We just last week bought one for a lab in France for 200 euros off of eBay. [09:05.310 --> 09:07.250] But that's all you need, including the camera. [09:07.470 --> 09:09.170] That and some sandpaper, too. [09:09.530 --> 09:11.110] To kick off your reversing. [09:12.330 --> 09:16.070] So you take these images, and we took them with a one megapixel camera. [09:16.070 --> 09:20.430] And so in one megapixel, you don't get all that much area off the chip. [09:20.550 --> 09:26.250] So you'll have a number of the pictures that together would describe one chip player. [09:26.490 --> 09:29.630] And the next logical step is then to stitch those together. [09:29.850 --> 09:31.910] We used an open source software, Hagen. [09:32.110 --> 09:34.110] It's used for panorama photography. [09:34.490 --> 09:36.110] Did the job really well. [09:36.510 --> 09:41.610] And didn't need much manual interaction from us at all. [09:41.610 --> 09:48.110] And then the last step in this image capturing phase is those different layers have to be aligned. [09:48.310 --> 09:53.310] So that the different stores of the building actually fit on top of each other where they should. [09:54.270 --> 09:58.930] And then, in theory, you have a visual representation of the chip's functionality. [09:59.430 --> 10:03.670] But you don't still know what it's doing since there's huge amounts of images. [10:04.050 --> 10:09.170] And no apparent structure to it from kind of a human standpoint. [10:10.070 --> 10:16.790] And so the chip, those unstructured layers, six of them in total. [10:16.870 --> 10:19.470] And the lowest layer would have the transistors. [10:19.610 --> 10:24.050] Transistors being these switches that every microchip consists of. [10:24.210 --> 10:28.410] And those transistors would be grouped in some logic functions. [10:28.450 --> 10:30.430] We'll talk about those on the next slide. [10:30.690 --> 10:32.130] On the logic layer. [10:32.450 --> 10:35.110] So there you start seeing some structure. [10:35.110 --> 10:39.110] And then the next layers on top of that, three layers total in this case. [10:39.730 --> 10:43.330] All they do is interconnect those different logic functions. [10:43.530 --> 10:45.790] It could be an end function, all function, any of that. [10:46.010 --> 10:50.610] And so they are somehow connected to form a circuit diagram, really. [10:50.830 --> 10:56.370] And then the last layer has no practical functionality other than connecting to antennas. [10:56.370 --> 11:00.090] But it does have some visual protection. [11:00.350 --> 11:03.810] So you couldn't have done what we have done without opening the chip. [11:03.970 --> 11:06.950] Since the last layer prevents you from looking into it. [11:07.150 --> 11:09.050] Where the rest of the chip is really just glass. [11:09.250 --> 11:13.630] So you can maybe see that the lower layer. [11:13.930 --> 11:19.030] For example, the horizontal line here shines through to this layer where it's all vertical. [11:19.030 --> 11:19.650] Right? [11:20.110 --> 11:21.850] Yeah, silicon oxide or glass. [11:25.190 --> 11:29.810] Now, I said these transistors are structured into logic function. [11:29.990 --> 11:33.110] And we call those logic function cells or gates. [11:34.230 --> 11:38.750] And actually, every functionality is only implemented once. [11:38.750 --> 11:42.030] And will look exactly the same wherever it's instantiated. [11:42.070 --> 11:48.290] And there's only a few, well, a couple of logic functions that are implemented to build a microchip. [11:48.290 --> 11:54.370] So each of these would be, in programming terms, a function that takes a small set of boolean values. [11:54.550 --> 11:56.170] And outputs one boolean value. [11:56.570 --> 11:56.870] Okay? [11:57.030 --> 12:02.310] So in this case, it would be a function that takes four inputs at these yellow dots. [12:02.730 --> 12:06.330] And then there's this cyan output pad, what would have an output. [12:06.430 --> 12:12.730] That is computed as, I guess, unless all of these are high, it will be a one. [12:12.930 --> 12:14.530] And if they're all high, it will be zero. [12:14.530 --> 12:18.970] So it's an AND of the four values and then an inversion. [12:19.730 --> 12:20.070] Okay? [12:20.490 --> 12:22.050] And there's only a number of those. [12:22.250 --> 12:25.070] They have at most, I think, six or seven inputs. [12:25.250 --> 12:29.110] And even truth table-wise, there aren't all that many possibilities. [12:29.470 --> 12:33.870] So now, every time this four NAND is instantiated on the tag, it will look exactly the same. [12:34.050 --> 12:35.450] So this is the same as this. [12:35.710 --> 12:37.470] Sometimes it's rotated. [12:37.750 --> 12:38.710] Sometimes it's mirrored. [12:38.850 --> 12:40.170] And all rotated or both. [12:40.770 --> 12:42.490] But they will look the same. [12:42.650 --> 12:47.930] So with that insight, we can use the computer now to do the recognition for us. [12:48.090 --> 12:52.570] And this is actually the output of a MATLAB script that I wrote. [12:52.730 --> 13:06.750] So all it does is, once you select one of these cells, it will tell you, including mirroring and rotation and everything, where on the chip this same cell is located, using some template-matching algorithm. [13:07.110 --> 13:08.830] So you do that once. [13:08.830 --> 13:10.030] You get those four. [13:10.270 --> 13:11.990] So next, you will select this one. [13:11.990 --> 13:13.930] So it's here again and there. [13:14.150 --> 13:15.550] You do that a couple of times. [13:15.550 --> 13:21.690] And you fill the chip with instantiations of the same logic gates. [13:21.690 --> 13:23.650] And there's only a total of 70. [13:23.890 --> 13:27.390] And those 70 make up the standard cell library. [13:28.050 --> 13:28.470] Okay? [13:28.610 --> 13:34.490] So every time that the designer of this chip needs a forenand, it will take that same forenand. [13:34.590 --> 13:35.990] Kind of an assembly instruction. [13:36.530 --> 13:38.490] And then instantiate it. [13:38.590 --> 13:45.430] And we can reconstruct the whole assembly language automatically using these tools. [13:45.430 --> 13:53.510] Now, so once we did that, we basically have a map of where, what type of gate is located. [13:53.670 --> 13:56.770] What we don't yet know, though, is what functionality it's computing. [13:57.030 --> 13:58.630] So I told you this was a forenand. [13:58.790 --> 14:00.050] But how do I know that? [14:02.130 --> 14:04.050] Well, I'll go over this briefly. [14:04.130 --> 14:06.850] And if you have more questions, we'll get back to that later. [14:06.850 --> 14:09.750] But I just want to illustrate that this isn't hard. [14:12.610 --> 14:13.710] This is an inverter. [14:13.710 --> 14:19.870] And what I'm showing here is the leftmost picture is the transistor layer. [14:20.090 --> 14:23.130] And the rightmost picture is the layer above it. [14:23.230 --> 14:25.990] Where the input and outputs are connected. [14:26.450 --> 14:28.590] And the picture in the middle blurs those two images. [14:28.870 --> 14:31.430] And orange, the higher level, and the blue, the lower level. [14:31.850 --> 14:34.810] And now, I'm asserting here that this is an inverter. [14:35.750 --> 14:38.810] Anybody, has anybody taken a VLSI class? [14:39.630 --> 14:40.670] Something like that? [14:40.990 --> 14:41.570] Yeah? [14:42.150 --> 14:44.230] I don't have it, but I know what an inverter is about. [14:44.510 --> 14:44.810] Okay. [14:45.510 --> 14:46.310] Well, what... [14:46.310 --> 14:48.350] In a circuit, built from transistors. [14:48.450 --> 14:50.110] What would an inverter be? [14:51.310 --> 14:52.110] Well, basically... [14:53.650 --> 14:55.790] Inverting state basically went to zero, zero to one. [14:55.890 --> 14:56.130] Okay. [14:56.270 --> 14:56.490] So, yeah. [14:56.570 --> 15:00.510] The truth table would be, if you put a zero at the input, a one comes out. [15:00.630 --> 15:02.870] And if you put a one at the input, a zero comes out. [15:03.390 --> 15:03.870] Right? [15:04.110 --> 15:09.650] So, if you had taken a VLSI class, you should be able to find this functionality trivial. [15:09.810 --> 15:14.690] Unfortunately, this type of image isn't really available publicly. [15:15.270 --> 15:20.190] So, when I taught VLSI, we couldn't find any this type of images. [15:20.430 --> 15:22.570] We can only find really old images. [15:23.270 --> 15:24.810] These are usually kept secret. [15:25.050 --> 15:25.630] But, yeah. [15:25.730 --> 15:26.770] So, the inverter is easy. [15:26.850 --> 15:28.530] And I'll give you a couple of clues here. [15:28.530 --> 15:30.750] So, there's two transistors. [15:31.090 --> 15:31.890] One up here. [15:31.990 --> 15:32.630] One down here. [15:32.810 --> 15:34.690] And a transistor is like a button. [15:34.930 --> 15:37.670] If you press the button, current can flow through. [15:37.930 --> 15:40.310] If you don't press, the button is basically blocked. [15:40.730 --> 15:47.250] So, I'm also giving you the hint that there's positive voltage up here and ground voltage down here. [15:47.470 --> 15:53.350] So, now, let's take the annotation from this image and say this was the input. [15:53.550 --> 15:57.950] So, the input, as you can see, this image is kind of in the middle. [15:57.950 --> 16:00.630] So, connect it to the two buttons. [16:00.930 --> 16:01.290] Right? [16:01.470 --> 16:02.610] To where you press. [16:03.270 --> 16:04.270] Which makes sense. [16:04.490 --> 16:05.250] So, this is the input. [16:05.390 --> 16:06.250] This triggers the action. [16:06.490 --> 16:09.570] And the left leg of these transistors is the output. [16:10.050 --> 16:11.630] Or Y, in this case. [16:11.870 --> 16:14.670] So, now, we said Y should be the opposite of A. [16:14.870 --> 16:18.070] You put a zero, one comes out, one zero comes out. [16:18.390 --> 16:21.590] Now, looking just at the bottom transistor for now. [16:21.590 --> 16:23.110] If you press the button. [16:23.730 --> 16:24.170] Right? [16:24.370 --> 16:25.950] If you put a voltage on it. [16:26.070 --> 16:28.610] It will let current through. [16:28.890 --> 16:31.190] Which means it will connect the left leg to the right leg. [16:31.270 --> 16:33.190] And the right leg is connected to ground. [16:33.930 --> 16:37.730] So, if you push the button, the output will become negative. [16:38.630 --> 16:38.990] Right? [16:39.790 --> 16:43.030] Now, the transistor on the other side acts exactly the opposite. [16:43.030 --> 16:49.170] This little circle here says it's kind of a reverse button. [16:49.390 --> 16:51.610] So, if you don't press it, it will let current through. [16:51.690 --> 16:52.990] And if you press it, it will block. [16:53.490 --> 16:54.890] Which, now, again, makes sense. [16:55.010 --> 16:59.210] If you don't press it, it will connect the left leg to the right leg. [16:59.270 --> 17:02.310] Which is connected to the positive voltage. [17:02.630 --> 17:02.750] Right? [17:03.650 --> 17:06.270] So, if you press it, zero will come out. [17:06.370 --> 17:07.810] If you don't press it, one will come out. [17:07.970 --> 17:09.190] That's the inverting function. [17:10.310 --> 17:13.010] And all gates will be similar to this. [17:13.030 --> 17:15.310] This is obviously the smallest possible one. [17:15.690 --> 17:19.970] But, so, more complicated gates would have two transistors on each side. [17:20.110 --> 17:22.510] And this one, for example, has the output in the middle. [17:22.690 --> 17:27.690] So, if either of these buttons is pressed, it will connect to ground. [17:27.870 --> 17:29.090] So, it's a 2-NOR gate. [17:29.270 --> 17:34.970] And so, by following this, you can figure out any gate's functionality. [17:35.350 --> 17:37.250] And, actually, they look very structured. [17:37.250 --> 17:41.170] So, the 3-NOR would just be the same, but a little wider, and so forth. [17:41.670 --> 17:44.410] Now, I won't bore you with any more details here. [17:44.430 --> 17:46.170] But, if you are interested. [17:46.450 --> 17:49.110] I put all that information online, just this morning. [17:49.310 --> 17:50.770] At the Silicon Zoo. [17:51.410 --> 17:54.730] And, I hope you'll use the Silicon Zoo. [17:54.990 --> 17:57.590] Definitely, if you're interested in learning about VLSI. [17:57.790 --> 17:59.570] As I said, it's hard to get these images. [17:59.770 --> 18:02.330] And, we couldn't find any when we were teaching it. [18:02.330 --> 18:05.330] And, so, I want you to study these cells. [18:05.450 --> 18:06.770] To understand how they work. [18:07.050 --> 18:09.550] To maybe compare cells of different manufacturers. [18:10.450 --> 18:12.450] See what different trade-offs they choose. [18:12.690 --> 18:15.570] And then, also use these to reverse engineer your own text. [18:15.770 --> 18:17.550] So, this is the only... [18:17.550 --> 18:20.050] In our reverse engineering system. [18:20.090 --> 18:22.730] This is the only step that really needs manual intervention. [18:23.190 --> 18:25.430] Partly because it's just fun solving these puzzles. [18:25.590 --> 18:26.950] So, we have never automated it. [18:27.350 --> 18:30.230] But, so, partly because it also requires some knowledge. [18:30.230 --> 18:35.050] So, if you do get at your own reverse engineering. [18:35.250 --> 18:36.290] Do use these images. [18:36.510 --> 18:37.470] And, contribute back. [18:38.330 --> 18:40.810] Help populate the Silicon Zoo. [18:42.990 --> 18:45.010] So, back to reverse engineering. [18:45.410 --> 18:49.430] What we have is now a map of all the different logic functions. [18:49.570 --> 18:51.190] On that logic layer. [18:51.570 --> 18:53.490] But, there's still three layers on top of that. [18:53.630 --> 18:56.630] Where these different functions are interconnected. [18:57.470 --> 19:00.810] And, so, those are crucial to the functionality. [19:00.810 --> 19:02.730] As much as the logic cells are. [19:02.970 --> 19:07.730] So, what we want now is to combine information of what gates are where. [19:07.890 --> 19:10.270] With the combination of what is connected to what. [19:10.490 --> 19:12.210] And then reconstruct that circuit diagram. [19:12.470 --> 19:13.670] Something like this disrepresentation. [19:14.630 --> 19:16.750] Now, for this chip that we reversed. [19:16.950 --> 19:17.890] We did that manually. [19:19.110 --> 19:20.270] It's a tiny chip. [19:20.470 --> 19:21.570] So, it was still possible. [19:21.810 --> 19:25.570] But, and it was a good way of building some ground truth. [19:25.570 --> 19:28.750] So, we can now build tools that try to get the same results. [19:29.230 --> 19:30.950] But, it did take a lot of time. [19:32.090 --> 19:33.270] We did do... [19:33.270 --> 19:34.550] We did make a couple of errors. [19:34.730 --> 19:36.190] But, there wasn't so much of a problem. [19:36.210 --> 19:37.610] Since, there's a couple of safety nets. [19:37.790 --> 19:38.390] So, for example. [19:39.910 --> 19:42.370] Two outputs will never be connected to each other. [19:42.810 --> 19:43.910] Or, in cryptography. [19:43.950 --> 19:45.450] Everything will be very structured. [19:45.450 --> 19:47.050] So, if there's some hiccups in the structure. [19:47.310 --> 19:48.570] You know you made an error. [19:48.570 --> 19:52.190] And, well, we did that 1,500 times. [19:52.370 --> 19:54.770] Or rather, Starbucks did that mostly 1,500 times. [19:54.970 --> 19:58.430] To find this chip's functionality. [19:58.850 --> 20:02.590] And, so just to illustrate how much effort that could be. [20:02.770 --> 20:04.630] Now, starting at this little dot here. [20:05.330 --> 20:06.910] As an input to... [20:07.650 --> 20:08.950] To all, I think. [20:10.250 --> 20:12.170] We want to know where it's connected to. [20:12.770 --> 20:14.970] So, we see the little green dot. [20:14.970 --> 20:17.350] Which means it's connected to something above it. [20:17.550 --> 20:19.670] It's a connection between these two floors. [20:20.430 --> 20:21.890] So, we go a layer above it. [20:22.130 --> 20:24.070] And, we see it's going to the left. [20:24.210 --> 20:24.990] And, again, a green dot. [20:24.990 --> 20:26.170] It means it's coming up again. [20:26.730 --> 20:27.630] One more green dot. [20:27.670 --> 20:28.550] It's coming further up. [20:28.830 --> 20:30.010] It's going all the way across here. [20:30.430 --> 20:31.510] And, now it's ending here. [20:31.630 --> 20:32.810] So, chances are... [20:32.810 --> 20:34.050] It goes one layer down. [20:34.210 --> 20:35.350] And, in fact, there's a green dot. [20:35.470 --> 20:37.070] It's going a little further down here. [20:37.710 --> 20:38.530] Next green dot. [20:38.650 --> 20:39.350] It's going up again. [20:39.370 --> 20:40.630] You see it's zig-zagging. [20:40.690 --> 20:41.810] There's no structure to it. [20:41.830 --> 20:44.750] It's all pseudo-random, almost. [20:44.750 --> 20:47.270] And then, it's finally reaching this dot. [20:47.530 --> 20:50.170] So now we know that this dot is connected to this dot. [20:50.330 --> 20:52.270] And now imagine this 1,500 times. [20:52.350 --> 20:54.510] Fortunately, we did automate that. [20:55.790 --> 21:06.730] Given the image on the left, the tool will create the image on the right, where it annotates all the wires in green, and what is a green dot in the left image as a red dot here. [21:07.230 --> 21:11.910] And just given that, you can easily find the circuit diagram. [21:13.190 --> 21:23.090] nitraM from the CCC in Berlin wrote a nice GUI for that, too, which I hope will be released sometime this year, perhaps in Berlin in December. [21:23.310 --> 21:24.690] Good conference to come to, too. [21:26.110 --> 21:35.110] And this GUI will eventually even extract the circuit diagram, so do some checking of what is plausible, how the different layers are connected, and so forth. [21:35.110 --> 21:42.310] So given that tool and the images you can easily get with your 200-year microscope, you should be able to reverse your own chips. [21:43.530 --> 21:47.430] Before we switch gears a little bit here, are there any questions so far? [21:49.150 --> 21:49.630] Yeah? [21:49.630 --> 21:52.910] Who actually are the big manufacturers of the chips? [21:56.110 --> 21:59.210] I'd say... so the question is, who are the big manufacturers? [22:00.670 --> 22:03.490] There aren't all that many manufacturers of microchips. [22:03.870 --> 22:05.250] So Intel, clearly, would be one. [22:05.430 --> 22:06.430] AMD would be one. [22:08.650 --> 22:10.410] IBM manufactures chips, I think. [22:10.570 --> 22:15.510] But if you go a little smaller than that, those would out-contract to the larger ones. [22:15.870 --> 22:24.350] And there's a few dedicated chip manufacturers, like STMicro and so forth, but there are only, I would say, less than 20 in the world. [22:24.350 --> 22:35.510] And, which is interesting now for the Silicon Zoo, since if there's only 20 manufacturers in the world, we should be able to exhaustively collect all the logic cells from all these manufacturers. [22:35.910 --> 22:43.130] They changed with different process technologies, but there's still, I would say, less than 100 libraries that we have to collect. [22:43.310 --> 22:46.070] Is VIA doing their own, or is somebody doing them for them? [22:47.050 --> 22:47.490] VIA? [22:47.750 --> 22:52.310] Yeah, the guys that you started out with motherboard chipsets and now make everything on Earth, including their own processors? [22:52.310 --> 22:55.430] Yeah, I don't know if VIA is manufacturing their own chips. [22:55.570 --> 22:56.890] I imagine, I thought they were. [22:57.230 --> 23:00.710] We probably know if they weren't, you could be seeing their stuff properly. [23:00.990 --> 23:07.810] Yeah, well, those chips we look at are from NXB, which was previously Philips Semiconductors. [23:08.050 --> 23:08.170] Yeah, right. [23:08.810 --> 23:11.690] And they and Infineon are the big European ones. [23:12.070 --> 23:12.370] Yeah. [23:12.570 --> 23:13.250] STMicro, too. [23:13.630 --> 23:14.790] Yeah, first of all, actually. [23:15.830 --> 23:16.270] Yeah. [23:17.670 --> 23:24.130] Have you noticed most of these chips are designed using an autorouting software? [23:24.390 --> 23:24.570] Yeah. [23:24.670 --> 23:34.150] Have you been able to kind of notice similarities between designs that might indicate which autorouting software was used to design a particular chip? [23:34.230 --> 23:35.250] Yeah, that's an excellent question. [23:35.370 --> 23:40.570] So the question is, can we infer the design tool that was used to build these chips? [23:40.570 --> 23:47.110] And since the output is pretty much random, I wouldn't see what cues I could use. [23:47.570 --> 23:53.590] Plus, there really is only one software that everybody is using on this level, Cadence. [23:53.830 --> 23:57.230] There are a couple of smaller ones that universities might use, but yeah. [23:57.850 --> 24:01.110] This is pretty much guaranteed to come out of some version of Cadence. [24:03.150 --> 24:04.050] In the back. [24:04.430 --> 24:07.410] How pissed are the manufacturers at you over this? [24:07.990 --> 24:09.630] How pissed are the manufacturers? [24:09.770 --> 24:10.370] Is that a question? [24:10.530 --> 24:10.630] Yeah. [24:14.490 --> 24:23.230] Well, the manufacturer of this chip, they just today lost a lawsuit trying to prevent the publication of these results. [24:23.390 --> 24:25.070] So they were fairly pissed. [24:32.840 --> 24:33.680] More questions? [24:34.420 --> 24:39.580] Along that line, what are you doing to make sure that Silicon Zoo stays up? [24:40.620 --> 24:44.600] Well, I host it on my university's server. [24:44.780 --> 24:48.800] So, if you want to take it down, sue the university. [24:50.180 --> 24:50.720] Ah, okay. [24:51.820 --> 24:52.860] You have many ideas. [24:55.180 --> 24:55.820] No. [24:56.060 --> 25:03.600] I don't think anybody truly believes that you can prevent reverse engineering results from becoming public. [25:03.920 --> 25:10.300] There are no trade secrets that you could apply since we found the secret ourselves. [25:10.680 --> 25:12.500] The manufacturer didn't tell us the secret. [25:12.720 --> 25:13.800] There's no copyright. [25:14.200 --> 25:17.200] There are no trademarks we infringe. [25:17.360 --> 25:19.180] So there's no legal grounds. [25:19.180 --> 25:24.420] And as I said, the lawsuit was won today in the Netherlands where NXV is due to university. [25:24.860 --> 25:25.040] Rob? [25:25.140 --> 25:26.360] Well, they could use DMCA. [25:27.140 --> 25:28.920] Could they use DMCA? [25:29.180 --> 25:29.580] I think... [25:29.580 --> 25:35.940] If this is ever used to protect copyright information, then your reverse engineering is a breach of DMCA. [25:36.300 --> 25:36.580] Right. [25:36.800 --> 25:43.660] So DMCA could be applied, but from what I understand, universities are exempted from DMCA. [25:45.240 --> 25:45.700] Yeah. [25:45.700 --> 25:46.160] Yeah. [25:46.380 --> 25:46.400] Yeah. [25:46.480 --> 25:48.480] So yeah, we were joking about this. [25:48.580 --> 25:53.460] That somebody should just have put this MyFair tag on a CD as a copyright protection. [25:53.660 --> 25:58.340] And they would have had much more legal grounds to sue anybody who reverses it. [26:01.760 --> 26:02.220] Okay. [26:03.220 --> 26:07.180] So how long do you think you need to reverse engineering a Pentium processor? [26:07.860 --> 26:08.840] It's a great question. [26:08.940 --> 26:10.500] And that kind of leads me to the next slide. [26:10.500 --> 26:21.460] So one possible defense, clearly, against what we are doing is to make the chips huge and to spread out the one algorithm you are after across the entire chip. [26:21.600 --> 26:28.120] So that would clearly defeat the set of tools we have now since we never aimed for scalability. [26:28.340 --> 26:36.400] It would take a lot more time and it would take a lot more automation to reverse something like an Intel microprocessor. [26:36.620 --> 26:38.120] But the stakes are much higher. [26:38.120 --> 26:42.880] So imagine you found a backdoor in an Intel processor, some debug functionality. [26:43.200 --> 26:53.740] You could basically write a virus that works completely independent of operating system, virus scanner, or any of that by just applying a certain sequence of instruction. [26:54.100 --> 26:59.960] So maybe somebody wants to pick up the challenge of making this scalable to much larger chips. [27:00.540 --> 27:02.540] And then we'll find some nice results. [27:02.540 --> 27:09.480] I think Kaspersky is releasing a bug along the same lines at heck in the box. [27:10.700 --> 27:11.260] Yeah. [27:12.100 --> 27:15.460] Well, other defenses that you could use against... [27:15.460 --> 27:27.840] Well, other defenses that are attempted to make what we're doing more difficult is to just generally obfuscate the chip, make things much less structured, do a lot more of the zigzagging. [27:28.860 --> 27:36.180] But since we already automated the detection, our tools don't care whether it makes sense or not from a human perspective. [27:36.540 --> 27:39.000] If two things are connected, it will find a connection. [27:39.240 --> 27:43.780] So this doesn't really prevent what we're doing at all. [27:43.780 --> 27:52.400] Now, another thing a lot of the temper resistant and temper-proof chips do, is they put a lot of dummy functionality on the chip. [27:52.580 --> 27:59.640] So things that might look like that they extend the algorithm in one way or another, but they're never actually used. [27:59.980 --> 28:08.740] Again, our tools, if something doesn't contribute to the output of some block, we will not detect it as needed to describe the algorithm. [28:08.740 --> 28:22.200] So this is mostly used to throughout people that more manually inspect chips, say, more traditionally, just looking at chips and inferring functionality of reverse engineering. [28:22.580 --> 28:30.180] Now, we already said large chips would completely defeat what we are doing at this stage, since we never aim for scalability. [28:30.400 --> 28:37.080] And then one thing that always comes up is, well, just make the chip kill itself once somebody starts opening it. [28:37.080 --> 28:45.980] An idea that does make sense in very high-cost key storage, kind of like TPMs, but a little bit more expensive. [28:46.160 --> 28:51.580] They would have a battery on it and some sensing as to whether they were open or not. [28:51.700 --> 28:54.460] And as soon as they're open, the keys will be deleted. [28:54.680 --> 29:00.920] Well, you can clearly erase memory through that way, but you can't destroy the algorithms, right? [29:01.040 --> 29:02.580] So these are completely different things. [29:02.580 --> 29:12.080] So what you would need to do is kind of like a Da Vinci type approach where you have a vial with some vinegar and then physically break the chip. [29:12.200 --> 29:13.920] But I don't think that has ever been done. [29:16.690 --> 29:28.720] So in conclusion, as far as countermeasures go, we haven't run across ideas that would completely prohibit what we're doing other than just scale. [29:29.000 --> 29:29.520] Rob? [29:30.160 --> 29:36.540] You could make the layers contain traces that are visually there, but not electrically there. [29:36.720 --> 29:40.080] So you could mess with the fact that electrical isn't visual. [29:46.440 --> 29:49.040] That is kind of the idea of dummy cells. [29:49.600 --> 29:52.840] Those are often not even connected to the rest of the chip. [29:53.340 --> 29:55.080] But then... [29:55.860 --> 30:01.020] But you could print traces out of material that looks exactly visually to your picture looks like a trace. [30:01.340 --> 30:01.700] Right. [30:01.780 --> 30:04.280] Or looks like a cell, but just isn't electrically working. [30:04.400 --> 30:12.600] So the idea is to make it so that if you take a picture of the chip, it would look like there is a trace, but really there isn't. [30:12.760 --> 30:14.900] Well, microchips are very simple. [30:15.420 --> 30:18.480] They have either silicon oxide or metal. [30:18.780 --> 30:20.440] There is no third component. [30:20.740 --> 30:29.420] And adding that just to throw out reverse engineering, I don't think anybody would take on that burden and assume that extra cost. [30:29.640 --> 30:35.800] So, so far, microchips are at the edge of what is possible to manufacture. [30:35.800 --> 30:41.000] And any added complexity would make chips either much larger or much more expensive. [30:42.600 --> 30:50.640] What about using blocks that, um, would intend to suck enough power to flip a bit or, say, RF from one side of the chip to another? [30:51.960 --> 30:54.680] Um, so this would be operational measures. [30:54.900 --> 31:01.600] So that, that would throw out somebody who looks at the chip while it's running and tries to, to see some power traces, for example. [31:01.600 --> 31:04.320] But we, we are completely breaking the chip. [31:04.480 --> 31:05.340] We're taking it apart. [31:05.660 --> 31:09.540] There's no current going through the chip while, while we investigate it. [31:10.000 --> 31:17.340] So, any, any of this type of measure would probably prevent side-channel attacks, or might, might aim at preventing side-channel attacks. [31:17.560 --> 31:27.600] But what we are doing is really looking at the, the, the, um, this, the design of the chip, not its functionality while it's operating. [31:27.600 --> 31:30.560] So we never look at input and output data, for example. [31:31.380 --> 31:31.580] Right? [31:31.740 --> 31:32.580] If that makes sense. [31:32.700 --> 31:36.360] If you're going to look at power pluses, you're better at thermal, in thermal imaging anyway. [31:36.680 --> 31:36.960] Right. [31:37.300 --> 31:45.080] So the, the, the comment is that, um, you, if, if you want to look at the running chip, you, you'd probably want to look at thermal imaging or, um, yeah. [31:45.300 --> 31:46.000] That's definitely right. [31:46.620 --> 31:50.000] Um, changing gears again a little bit. [31:50.160 --> 32:00.280] And as, as a, as a last edit motivation, if you're, if you haven't yet started thinking about what chip you'll attack, um, couple of results from, from what we have, uh, reverse. [32:00.480 --> 32:09.900] And, and I already took, took a, um, I already mentioned that there was a lawsuit, so there was a lot of publicity, um, over, over this reversing. [32:10.060 --> 32:16.560] Since this chip is used in thousands of applications, there's about two billion of these chips deployed. [32:16.800 --> 32:18.020] And we don't even know where. [32:18.020 --> 32:23.200] But, uh, a lot of, um, toll collect, what they call it, like, um, fair collect. [32:23.880 --> 32:26.640] Um, paying, paying for buses or metro. [32:26.840 --> 32:31.420] But also higher security, access control to buildings, payment sometimes. [32:32.120 --> 32:32.480] Right. [32:32.760 --> 32:36.040] So, there was a lot of discussion around the security of it. [32:36.180 --> 32:42.500] But before we go into the weaknesses, let me first briefly sketch out what, what this chip is and what it does. [32:42.700 --> 32:47.920] So it's, it's a cryptographic chip and all we really wanted to reverse is the cryptographic cipher. [32:47.920 --> 32:52.440] Which is a proprietary cipher and kind of different from everything we have seen before. [32:53.100 --> 32:58.500] Um, it consists of a 48-bit linear feedback shift register and a filter function. [32:58.680 --> 33:00.360] So that's the linear feedback shift register. [33:00.580 --> 33:06.000] Just a register where everything's shifting over by, by, by one position in each clock. [33:06.240 --> 33:10.560] And then that one empty spot in the beginning is filled by the X of some of these boxes. [33:10.860 --> 33:15.340] It's, it's a pseudo random number generation, or generator, if you so wish. [33:15.340 --> 33:23.240] And then the, the, the binary function on top of that takes 20 of these, these, these bits and generates one bit in each clock. [33:23.460 --> 33:29.200] So it will generate a stream of bits, one in each clock, and that can be used as an XOR pad. [33:29.420 --> 33:32.740] So if you want to send a message, you XOR your message with that pad, send it over. [33:32.960 --> 33:38.200] And if somebody can reconstruct, can, can generate that same XOR pad, the XOR, again, recover the message. [33:38.200 --> 33:40.140] Simple stream cipher, right? [33:40.620 --> 33:45.680] It's not just used for, for data encryption on this take though, but also for authentication. [33:46.480 --> 33:49.880] Authentication meaning you want to prove to somebody that you know something secret. [33:50.520 --> 33:52.740] So that secret would be a 48-bit key. [33:53.360 --> 33:57.360] And to prove to, to that as a party that you know the, the secret key. [33:57.560 --> 34:00.460] You load the secret key in this shift register on both sides. [34:00.460 --> 34:03.340] And now random numbers are supplied from both sides. [34:03.880 --> 34:10.060] Um, those are added into this register in some, some, unfortunately linear fashion, which makes it very vulnerable. [34:10.320 --> 34:13.180] And then also the, the ID number of this chip is added. [34:13.400 --> 34:17.160] And then what comes out is different every time, since the random numbers are different. [34:17.360 --> 34:19.420] It can only be generated knowing the key. [34:19.660 --> 34:21.180] So you can prove that you know the key. [34:21.480 --> 34:21.840] Okay? [34:22.980 --> 34:23.780] Simple enough? [34:24.040 --> 34:25.380] Any questions on this? [34:27.040 --> 34:27.520] Okay. [34:33.010 --> 34:36.390] So the commonest 48-bit key isn't exactly secure. [34:36.770 --> 34:41.890] Well, one, one, one could have, one could have known that years ago. [34:42.090 --> 34:47.830] But often, often times the argument is made that as long as something is a secret, nobody can break it. [34:47.830 --> 34:50.090] Hence, by definition, it must be secure. [34:50.170 --> 34:50.850] It doesn't work that way. [34:50.970 --> 34:51.410] Exactly. [34:51.550 --> 34:52.370] It does not work that way. [34:52.530 --> 34:54.770] It doesn't work that way for any computer data either. [34:54.770 --> 35:01.770] I remember when the public office used to have computers, you'd have a dial-up, it would be undocumented. [35:02.230 --> 35:03.350] There'd be no password on it. [35:03.490 --> 35:06.990] If you found it, if you found the dial-up, you could get in with no password. [35:06.990 --> 35:07.190] Right. [35:07.970 --> 35:08.370] And... [35:08.370 --> 35:11.030] So the, the, the, the point is, the, the, the point... [35:11.030 --> 35:13.290] The security, it didn't work for that either. [35:13.490 --> 35:13.850] That's the point. [35:14.070 --> 35:14.210] Right. [35:14.590 --> 35:14.990] Yeah. [35:15.210 --> 35:17.750] Thanks, thanks for that example of yet another case work. [35:18.270 --> 35:20.110] Security through obscurity does not work. [35:20.470 --> 35:23.410] And now, in this case, everybody knew it was a 48-bit key. [35:23.410 --> 35:30.750] So, everybody knew that on average, in 2 to the 47 cryptographic operation, you should be able to recover that. [35:31.390 --> 35:35.730] Which, um, and that leads me to the next one. [35:54.130 --> 35:58.350] The point that 48-bit security for certain applications is good enough. [35:58.870 --> 36:01.850] Now, this chip does not provide 48-bit security. [36:02.030 --> 36:06.030] You do not have to spend 50 minutes on an expensive computer to break it. [36:07.330 --> 36:07.930] Um... [36:07.930 --> 36:08.790] Where do we start? [36:08.930 --> 36:10.090] There's so many weaknesses. [36:12.350 --> 36:13.910] Let's start with the random numbers. [36:15.350 --> 36:19.950] 32-bit random numbers is what supposedly comes out of the chip. [36:20.130 --> 36:22.430] There are neither 32-bit nor random. [36:24.890 --> 36:30.650] It's a 16-bit number that is determined by the time that you asked for the number. [36:30.650 --> 36:34.970] So, it starts off in the same state, and it's basically a counter. [36:35.270 --> 36:35.690] Right? [36:35.810 --> 36:41.050] It counts secretly, and now you ask it for a random number, and it will tell you the current counter state. [36:41.590 --> 36:42.030] Right? [36:42.050 --> 36:43.030] That's the random number. [36:43.570 --> 36:45.070] Same on the reader side. [36:45.150 --> 36:52.870] There, too, you can, through asking in the right moment, or in the right sequence, rather, get the same random number every time. [36:52.970 --> 36:55.030] So, there's no randomness in this protocol. [36:55.030 --> 37:00.710] And an authentication protocol, without any randomness, is total prey to replay attack. [37:00.970 --> 37:05.550] Once you've overheard one authentication, you can just answer it in the exact same way. [37:05.730 --> 37:09.330] And if the same random numbers were used, the same output is generated. [37:09.830 --> 37:11.990] So, authentication completely breaks apart. [37:12.330 --> 37:22.130] Now, say that we're going to fix that, which they have on the reader side in some newer chips, which they will on the tech side, and what I call the MyFair Plus card. [37:22.130 --> 37:25.110] Now, the MyFair Plus card also has AES encryption. [37:25.150 --> 37:26.290] I'm not going to talk about that. [37:26.430 --> 37:34.810] But, the weak encryption, this crypto-one algorithm, with strong random numbers, is still much more vulnerable than brute force. [37:35.270 --> 37:47.630] One thing that you can do, that you can always do against a 48-bit, poorly seeded cipher, and what the GSM cracking project did, too, is compute rainbow tables, or rather, distinguished point tables. [37:47.630 --> 37:56.510] Now, you still have to spend those 50 minutes on the expensive computer, but you do that only once, to break any number of tags. [37:56.890 --> 38:00.210] And you can break those in about 30 seconds on a computer. [38:00.830 --> 38:03.850] Now, that might be worse for stealing bus tickets. [38:04.090 --> 38:04.670] Nobody knows. [38:04.850 --> 38:07.890] But, it's definitely worse for breaking into building, right? [38:08.250 --> 38:11.450] Maybe the 50 minutes would already have been. [38:11.830 --> 38:13.790] There's a couple of other tags you can do. [38:13.790 --> 38:16.450] The protocol is so simple. [38:16.590 --> 38:17.890] Everything is combined linearly. [38:18.270 --> 38:27.270] So, if you ask the right questions, meaning you send the right random numbers, it will disclose bits of the secret key, one or two at a time. [38:27.490 --> 38:29.630] And you can basically probe for the key. [38:29.730 --> 38:35.930] And just by sending a couple of random numbers and seeing how it's responding, you can figure out large parts of the secret key. [38:35.930 --> 38:38.270] And the group forcing for the rest is just trivial. [38:38.770 --> 38:46.790] A couple of more advanced tags, all what we call the algebraic attacks, exploit the structure of the cipher itself. [38:46.910 --> 39:02.950] So, if you were to fix everything, if you were to increase the secret key size, if you use good random numbers, if you were to fix the protocol, but still use the same basic idea of having a simple function like this, you can do these algebraic attacks. [39:02.950 --> 39:14.790] So, basically build up of the idea of describing the whole cipher as a system of equations, and then using off-the-shelf tools that mathematicians use to solve that system of equations. [39:14.910 --> 39:18.490] Say, MiniSat, for example, is a tool used for that. [39:19.250 --> 39:25.650] And so, the most advanced algebraic attacks on this breaks any 48-bit secret key in 12 seconds. [39:26.450 --> 39:28.230] On a computer, right? [39:28.290 --> 39:30.030] No expensive hardware needed. [39:30.030 --> 39:33.030] And that's basically the bottom of security. [39:34.170 --> 39:37.630] I mean, it takes longer to even type the command than to break the key. [39:38.530 --> 39:39.010] So... [39:41.600 --> 39:42.180] What's that? [39:43.000 --> 39:48.260] I would assume even a high-end home computer would have little trouble doing this in a reasonable frame, but I've never mind anything wrong. [39:48.840 --> 39:49.320] However... [39:49.320 --> 39:49.740] Right. [39:53.160 --> 39:58.400] Well, to conclude, reverse engineering is entirely possible and you should try. [39:58.600 --> 40:00.640] If you do, let me know and I'll help. [40:01.540 --> 40:06.020] I'll help by giving you our tools, which will be released sometime soon anyway. [40:07.440 --> 40:11.380] I'll help by explaining you VLSI if there's something you need. [40:11.380 --> 40:16.360] And I'll help getting around obfuscation where I want to be challenged. [40:16.520 --> 40:21.520] I want to see some obfuscation that actually makes our tools not find anything anymore. [40:21.640 --> 40:24.240] We haven't come across any of that yet. [40:24.240 --> 40:31.260] On the cryptographic side, we haven't necessarily learned but yet again seen that obscured... [40:31.260 --> 40:33.700] security through obscurity doesn't help at all. [40:33.860 --> 40:37.980] And as I said in the beginning, it hurts you. [40:38.440 --> 40:54.080] Beyond not helping, it hurts you very much since designing a crypto algorithm in some company's back room and trying to keep it secret without peer review will produce weak algorithms, almost guaranteed, unless you're the NSA properly. [40:55.120 --> 40:57.640] Well, with that, I want to thank you for your attention. [40:57.920 --> 40:59.520] I'll be happy to answer some more questions. [41:10.580 --> 41:13.500] What if somebody's implemented a design using an FPGA? [41:13.720 --> 41:16.640] I assume that you can recover the design of the FPGA. [41:16.840 --> 41:19.940] Do you have any ability to actually see what's stored in the logic cells? [41:20.320 --> 41:25.260] So the question is, can we reverse something that's stored in an FPGA? [41:25.260 --> 41:40.880] FPGA, which is a chip that... it's a cross between software and hardware, in that it has small hardware cells that are basically programmed through software, but that build a circuit. [41:41.540 --> 41:47.160] And all an FPGA really is, is a memory, from a programming standpoint. [41:47.720 --> 41:51.240] And FPGAs can be written to, but also read from. [41:52.020 --> 41:59.300] Some FPGAs have security features, so you can lock them, but ask Chris from FlyLogic how to get around that. [42:00.100 --> 42:03.460] So it's, it's more a question of software reverse engineering. [42:03.720 --> 42:09.180] And we all know that software is trivial to reverse engineering, using either Pro or any of those tools. [42:10.220 --> 42:10.760] Right? [42:12.980 --> 42:17.580] What applications do you see for reverse engineering hardware besides security risk? [42:17.580 --> 42:22.240] What applications do I see for reverse engineering hardware beyond security? [42:22.460 --> 42:24.640] Well, I think security is the big application. [42:24.820 --> 42:31.540] Since there, it's, it's, or, it's, it's clear that a lot of people haven't yet understood that things should be peer reviewed. [42:31.740 --> 42:42.500] Other applications that I do see though is, um, well, clearly on, on the evil side, stealing somebody's, um, perfect implementations of some, some tricky problem. [42:42.500 --> 42:52.600] So graphics and sound are examples where, where people put a lot of effort into making a known algorithm smaller and smaller and smaller, or more efficient or any of that. [42:52.940 --> 42:57.600] So, uh, we, we, we are definitely not the first to, to do this type of reverse engineering. [42:57.820 --> 43:01.860] We are just the first to, to try to, to get other people to do it. [43:01.960 --> 43:03.600] There's, there's, there's businesses doing that. [43:03.760 --> 43:06.040] And they, um, they do it for a lot of money. [43:06.040 --> 43:08.460] And they, they're usually hired in patent litigations. [43:08.700 --> 43:17.960] So if you suspect some other company to infringe your patent, the, the easiest way to prove that is to reverse engineer their chip, ensuring that they, in fact, use your algorithm. [43:18.660 --> 43:24.320] So this is already being done, um, in, in kind of a different world than academia. [43:24.580 --> 43:28.960] Have you came across any, any person, any, any little hidden IDs of chips? [43:29.040 --> 43:29.760] I know I understand that. [43:29.840 --> 43:37.280] A lot of times designers will put little, uh, little things on chips, like, like initials and other little QC things to sort of mark their work. [43:37.500 --> 43:38.320] Have you seen much of that yet? [43:38.900 --> 43:49.500] Have, have we come across, um, yeah, the question is, have we come across little, little, uh, names or, or markers that, that chip designer left? [43:49.700 --> 43:51.820] And, oh, in this chip, no. [43:52.120 --> 43:56.600] But in, in a couple of other chips, and I think Flylogic's block has a couple examples. [43:56.960 --> 43:57.840] Some definitely have done it. [43:58.000 --> 44:00.040] It's been done, it's, it's been published a few of them, in fact. [44:00.100 --> 44:09.560] Yeah, that does, that, that does, that sometimes designers, even play jokes where then the, the obfuscation layer, um, says something in, in hexa language. [44:10.080 --> 44:10.160] Yeah. [44:10.800 --> 44:10.880] Uh-huh. [44:10.980 --> 44:16.540] It's sort of like you look at the source for a website, and there's some, some strange message there, and you can only see if you're looking at the source. [44:16.780 --> 44:17.320] Things like that. [44:17.420 --> 44:17.860] Same right there. [44:18.840 --> 44:19.540] Exactly, yeah. [44:19.540 --> 44:20.360] It's like, what are you doing here? [44:25.660 --> 44:31.300] Went into the document service, the service level on the menus, which you do to, to change certain options. [44:31.420 --> 44:34.200] It would actually say at the first screen, you should not be here. [44:34.880 --> 44:36.700] It's actually on your screen when you get to this. [44:36.700 --> 44:37.100] Very nice. [44:38.460 --> 44:39.400] Any more questions? [44:39.860 --> 44:46.190] You should open up a market, use a little scalable larger system for reverse engineering. [44:46.970 --> 44:51.390] The question is, wouldn't, wouldn't patent litigation open the market for scalable reverse engineering? [44:51.590 --> 44:52.530] And yes, I hope it will. [44:52.710 --> 45:01.050] If, if somebody wants to take this commercial world, keeping the tools open source, I'll, I'll definitely be, be willing to support that in any way. [45:01.150 --> 45:03.050] But, the automated system wasn't designed to be scalable. [45:03.050 --> 45:06.090] Well, because we, our system wasn't designed to be scalable. [45:06.370 --> 45:13.070] But there's, there, there's no reason why somebody was enough patience couldn't, couldn't make it scalable. [45:13.330 --> 45:14.230] The, the ideas are there. [45:14.930 --> 45:16.190] The idea is scalable. [45:16.650 --> 45:17.110] Yes. [45:17.270 --> 45:17.730] Yeah. [45:17.810 --> 45:19.530] It's just our implementation that isn't. [45:19.710 --> 45:19.910] Yeah. [45:19.970 --> 45:21.730] It's, it's a bunch of MATLAB scripts. [45:31.030 --> 45:33.230] How long did it take for us to reverse this chip? [45:33.230 --> 45:37.370] Well, we, we were trying different things for, over the course of about two years. [45:37.650 --> 45:43.230] Now, if, if we, given all the tools we have now, wanted to do it again, about two weeks. [45:51.860 --> 45:52.280] Yes. [45:52.540 --> 45:56.020] Do you plan to reverse engineer other, any other chips in your future? [45:56.640 --> 45:59.040] Do we, do you plan to reverse engineer other chips? [45:59.340 --> 45:59.860] Clearly, yes. [46:00.140 --> 46:02.880] And our bottleneck at the moment is, is taking the pictures. [46:03.340 --> 46:08.460] Right, and we, we have, we, we have a couple of people starting on that now, get, getting, getting used to the polishing and all that. [46:08.460 --> 46:08.960] So, so yeah. [46:09.200 --> 46:12.320] We, we should have an influx of, of weak algorithms soon. [46:12.540 --> 46:13.860] And hopefully... [46:16.900 --> 46:22.360] Have you noticed that different manufacturers tend to both design the same, but sort of similar ways? [46:22.980 --> 46:25.240] Or are there big differences between the two? [46:25.560 --> 46:29.920] Do, do different, different manufacturers design differently? [46:30.420 --> 46:33.760] Well, they all use the same routing tool, cadence. [46:33.760 --> 46:38.940] So, the way they, they place and route things is, is almost indistinguishable. [46:39.140 --> 46:40.860] But they do use different logic cells. [46:41.020 --> 46:44.740] This, for example, um, does not come from the, from the MyFair. [46:44.980 --> 46:46.940] It's, it's, it's another RFID tech. [46:47.160 --> 46:48.660] Um, this is a flip-flop. [46:49.100 --> 46:51.900] Um, but they are almost the same. [46:52.300 --> 47:00.280] So, the, the, what, what you see in textbooks as good examples of how to build a flip-flop, how to build a multiplier, all these things. [47:00.580 --> 47:02.020] People use that in practice. [47:02.460 --> 47:04.800] They, they, they almost always exactly the same. [47:05.360 --> 47:05.840] Rob? [47:06.420 --> 47:18.480] Um, the selective availability keys for GPS, uh, which is the military GPS which gets you more resolution and better signal, and doesn't get turned off if they ever turn off the civil GPS. [47:19.360 --> 47:21.280] Uh, aren't those on silicon somewhere? [47:21.540 --> 47:22.440] I think they are. [47:22.580 --> 47:29.020] I think there's civil and military versions of the same chip, where the military version doesn't select the availability encryption. [47:29.240 --> 47:29.260] Right. [47:29.260 --> 47:30.220] They don't use that anymore. [47:30.420 --> 47:32.300] It's already been shut off this thing and stuff. [47:32.640 --> 47:33.660] Probably several years ago. [47:33.940 --> 47:35.060] It was, it was, it was probably discussed. [47:35.340 --> 47:36.880] I can tell you get the higher resolution now. [47:36.920 --> 47:45.500] So, the, the question is whether the, the military GPS, the, the, the, the unblurred GPS, um, has an, has a silicon implementation. [47:45.500 --> 47:47.420] And I'm, I'm sure it does. [47:47.560 --> 47:52.520] And if anybody gets me ten copies of that ship, we should know better soon. [47:56.560 --> 47:57.360] More questions? [47:58.740 --> 47:59.100] Yes. [47:59.300 --> 48:07.460] So, it seems like a lot of the effort here was put into developing the tools and, uh, mainly kind of the one time set up the microscope. [48:07.800 --> 48:13.740] So, given that you already have all the tools and the software you wrote, what is the cost now to do your next chip? [48:13.880 --> 48:15.660] Well, what's the cost of doing another chip? [48:15.880 --> 48:27.360] Well, getting the tools from us, getting a microscope, spending probably about a month trying to figure out all the polishing and then spending maybe a week taking the pictures and another week running the tools. [48:28.020 --> 48:30.920] That's the cost, you, you'd have to assume if you wanted to do it. [48:31.120 --> 48:31.140] Yeah? [48:32.100 --> 48:33.500] But it is fun, I promise. [48:38.420 --> 48:38.860] Okay. [48:38.960 --> 48:39.580] No more questions? [48:39.920 --> 48:40.840] Oh, one more? [48:41.040 --> 48:41.120] Yeah? [48:41.440 --> 48:43.500] You said you needed ten copies of the GPS chip. [48:43.740 --> 48:46.000] How many copies do you need typically for something simpler? [48:47.220 --> 48:51.440] So, the question is how many, how many copies of a chip do we need to reverse engineer something? [48:52.080 --> 48:54.560] Um, well, optimally one. [48:56.640 --> 48:57.080] Yeah. [48:57.080 --> 48:59.000] But there's so many things that could go wrong. [48:59.180 --> 49:02.020] So, probably three on average. [49:02.320 --> 49:02.400] Yeah. [49:03.640 --> 49:07.320] There's probably, I, I had reverse engineering project also. [49:07.700 --> 49:10.580] It's usually a trade-off between how careful you have to be. [49:10.860 --> 49:15.120] If you know you're only ever going to have two, you're going to be very, very careful. [49:15.120 --> 49:16.360] And that's going to cost more time. [49:16.440 --> 49:18.980] So, it's a time versus number of parts trade-off. [49:19.240 --> 49:19.400] Yeah. [49:19.620 --> 49:19.760] Definitely. [49:19.980 --> 49:20.040] Yeah. [49:21.880 --> 49:25.440] Especially if you, if you use some of the rougher, faster polishing. [49:25.780 --> 49:25.900] You know? [49:26.120 --> 49:26.860] Just by accident. [49:27.140 --> 49:29.580] You, you, you cut things that you didn't intend to. [49:32.320 --> 49:32.760] Okay. [49:33.420 --> 49:34.040] No more questions? [49:34.220 --> 49:34.860] Thank you very much.