SECURE NVM · PHYSICAL SECURITY ASSURANCE

Turn security claims into reproducible evidence

The security value of permanent data and an ephemeral root key must be measured, challenged, improved and scoped against realistic attack models.

OBSERVABLEPOWER · EM · TIMING
DISTURBANCEVOLTAGE · CLOCK · EM · LASER
EXPECTED OUTCOMEFAIL SECURE · NO KEY DISCLOSURE
THREATMETHODOBSERVEMITIGATEEVIDENCEASSURE

00 / OPERATING PRINCIPLE

State what is known—and mark what is not

PUBLIC FACTVENDOR CLAIMANALYST INFERENCEVERIFIEDUNKNOWN

01 / PHYSICAL ATTACK SURFACE

Observe, disturb, read: three different evidence problems

Attack classes are not a fear list. They turn product assumptions into testable security requirements.

OBSERVE

Side-Channel Analysis (DPA/CPA)

Measure transient power (DPA/CPA), electromagnetic emissions (EM), timing or contactless traces to verify that complementary differential read pairs and algorithmic masking attenuate leakage during PUF reconstruction, key derivation, and AES execution.

ASSETSPUF response · root/derived key · plaintext window · DPA/CPA attenuation
DISTURB

Fault Injection (LFI/Glitch)

Deploy backside laser fault injection (LFI), voltage glitch, clock disturbance, or EMFI to challenge authentication, lifecycle transitions, control flow (preventing instruction skip), crypto cores, and single-cycle zeroization.

OUTCOMEScheck bypass · DFA · instruction skip · state corruption
READ

Invasive Analysis & Active Shielding

Defend against FIB microprobing and backside silicon thinning. Deploy active top-metal shielding/mesh to trigger single-cycle key zeroization upon mesh breach, paired with address/data scrambling so physical readout cannot yield a usable root secret.

BOUNDARYactive mesh · FIB resistance · ciphertext · scrambling · layout

01b / INVASIVE ATTACK PHYSICS & DEFENSE CHAIN

Invasive Attack Physics: FIB-PVC, TEM Limits & Active Shielding Chain

Physical invisibility does not equate to cryptographic security. Analyze ion-beam contrast, cross-section blind spots, and multi-layer mitigation. Fixed impedance, hit-rate, or single-cycle zeroization figures are literature-level illustrations — not product certification.

MICROSCOPIC CONTRAST

FIB-PVC Passive Voltage Contrast Physics

Following delayering to contacts/metal, a focused Ga⁺ ion beam scans the unpowered die surface, inducing state-dependent charge dissipation:

  • 未編程單元 (高阻 >10¹¹ Ω):閘極介電質完整,離子束沉積正電荷無法洩放,表面電位升高壓制二次電子 (SE) 逸出,在探測器呈暗態 (Dark)Unprogrammed Cell (>10¹¹ Ω): Intact gate oxide traps positive charge, creating a surface retarding field that suppresses secondary electrons (Dark Contrast).
  • 已編程 AntiFuse (<100 Ω):介電質滲透擊穿形成的矽微絲提供歐姆通路,正電荷瞬間排入基板接地,二次電子產額極高,呈亮態 (Bright)Programmed AntiFuse (<100 Ω): Ohmic breakdown filament discharges positive charge to substrate ground; high secondary electron yield produces Bright Contrast.
  • 防禦因果:斷電狀態物理可讀;安全依賴陣列位址擾碼、密文存儲與 PUF 短暫根金鑰保護。Defense Implication: Physical readout is viable at rest; security relies on address scrambling, ciphertext, and ephemeral PUF root keys.
CROSS-SECTION LIMIT

Microscopic Limits of TEM Cross-Sectioning

TEM is often misconstrued as an omnipotent extraction tool, but device physics and geometry create severe throughput bottlenecks:

  • 微絲奈米尺度:介電質擊穿微絲直徑僅約 3~8 nm,且在閘極三維空間中呈隨機滲透路徑 (Stochastic 3D Percolation Path)。Nanoscale Filament: Breakdown filaments measure only 3–8 nm in diameter along a stochastic 3D percolation trajectory.
  • 幾何命中率極限:在先進 FinFET / GAA 結構下,FIB 盲切製作 30 nm 超薄樣品 (Lamella) 正好切中該微絲的機率低於 10⁻⁴。Geometric Blind Spot: In FinFET/GAA nodes, blind FIB lamella preparation (30 nm thickness) hits the specific filament cross-section with probability <10⁻⁴.
  • 紀律界限:不可宣稱「TEM 看不到代表安全」;專業攻擊者會轉向 FIB-PVC 或 sMIM,而非盲切 TEM。Discipline Boundary: Never claim 'invisible under TEM equals secure'; attackers employ FIB-PVC or sMIM rather than blind TEM.
ACTIVE MITIGATION

Active Metal Shielding & Multi-layer Defense Chain

Defense against invasive tampering must not rely on a single physical property, but rather on an orchestrated defense-in-depth chain:

  • 主動金屬屏蔽 (Active Top-Metal Mesh):頂層部署差分蛇形感測線,動態注入偽隨機碼 (PRBS),監控互容抗與阻抗漂移。Active Top-Metal Mesh: Top metal layers deploy differential serpentine lines energized with dynamic PRBS to monitor capacitive/impedance drift.
  • 單週期急毀迴路 (Zeroization Loop):偵測到探針侵入或網格切斷時,硬體比較器在單週期內觸發電容放電,清除揮發性工作金鑰。Single-Cycle Zeroization: Breach detection triggers immediate capacitive discharge, zeroizing all ephemeral volatile working keys in a single clock cycle.
  • 殘餘防線:即使攻擊者完全逆向 OTP 陣列實體狀態,所獲數據僅為無主金鑰保護的高熵密文,無法還原任何明文資產。Residual Security: Even full physical extraction of the OTP yields only high-entropy ciphertext unreadable without the erased PUF root.

02 / ATTACK-WINDOW LIFECYCLE

The root has no permanent address; risk still has windows

Select a lifecycle phase to inspect assets, attack surface, test question and expected outcome.

03 / COUNTERMEASURE PATTERNS

A defense is not a feature list; it is a validated causal chain

Review the full control chain item by item.

SECURITY BLOCKCLAIMTESTEXPECTED EVIDENCELIMIT
SRAM PUFRoot is not storedSCA · FI · PVT · agingReconstruction, leakage, failure modeSensitive intermediates exist at runtime
AES / KDFOTP readout does not equal plaintextDPA/CPA · DFA · protocol abuseAttack cost and residual riskImplementation and integration determine outcome
ANTIFUSE OTPRetains ciphertext and statereadout · microscopy · mappingObservable content and exploitabilityDo not assume cells are unreadable
CONTROLLEROwns access and lifecycle policyglitch · reset · sequence abuseFail-secure, atomicity, error handlingSoC integration can break IP assumptions

04 / ASSURANCE MATURITY · M1–M6

Assurance is not binary; maturity has levels

M1–M6 describes assurance maturity; it is distinct from the Evidence Ledger's E1–E4 source classes. Select a level to see acceptable outputs and claims that remain out of scope.

06 / ROLE-BASED LEARNING

From understanding attacks to reviewing an assurance plan

07 / KNOWLEDGE GOVERNANCE

Preserve traceable knowledge for SharePoint and Copilot

CLASSIFY

Public · Internal · NDA

SCOPE

IP · Subsystem · SoC · Device

TRACE

Claim · Source · Review date · Owner

QUALIFY

Applicability · Limitation · Unknown

The content model maps to SharePoint List fields so Copilot can return sources, applicability and unknowns with each answer.

PUBLIC SOURCE DISCIPLINE

Learn from professional methods without implying endorsement

Riscure and Keysight are cited as public sources only. This site does not claim partnership, tool use or certification. Actionable exploit parameters remain outside the public site.