The NCSC research problem book
Pages
Page 10 of 21
HW1 - How do our devices physically behave?

iStock.com/sarawuth702
How do our devices physically behave, and how do we monitor and secure those behaviours?
The physical behaviour of semiconductors and other materials leads to several classes of vulnerabilities and attacks. This problem focuses thinking on these attacks, and how to mitigate them. Most of these vulnerabilities are only a concern if an attacker is ‘hands on’ in a lab, but as an example, rowhammer demonstrated how the physical behaviour of a device (in this case DRAM) could be exploited remotely.
While these threats are out of scope for many systems, the NCSC is responsible for the security of some of the country’s most sensitive systems, in which an adversary may attempt to exploit these types of vulnerabilities. There is already considerable research underway in the field, but there are some areas where we see value in more focused work.
Strands or sub-problems
-
Practical vulnerabilities and protections
There is a big difference between an attack that is possible, and one that is practical. Research into attacks will be more valuable if it includes an explanation of how practical the attack is. Similarly, understanding the protections that make an attack hard in practice is of more value than designing a perfect mitigation.
-
Resilient hardware security primitives
There is a lot of ongoing research into hardware security primitives such as physically unclonable functions (PUFs) and random number generators (RNGs). But many of these designs are missing evidence of long-term reliability and their resilience to faults and attacks. Practical evidence of this would be of significant value to help decide when it’s appropriate to use them in a system.
-
Anti-tamper
In the face of physical attacks, we want to make it harder for an adversary to gain access to a sensitive device in the first place, and to ensure there is no sensitive data left in the system if they do manage to reach the device. We think of this through three lenses: resistance (making it hard to do), detection (making sure we know it’s happening), and response (taking action to protect the system and/or data, and to recover if possible). A complete approach would therefore encompass both powered and unpowered anti-tamper solutions, so we’re interested in novel approaches to designing and incorporating these solutions.
Why this is important
“Devices used in the most sensitive systems, including communications platforms for defence, intelligence and critical national infrastructure, need to be resistant to attack from our most sophisticated adversaries. A threat scenario might be an adversary getting access to a device and passing it for analysis to a well-equipped lab of highly capable experts. If this enables access to sensitive data held in the device or within the wider system, such as long-term cryptographic keys, a compromise could be highly damaging to national security.“
Jeremy B, Principal Technical Director for Cryptography and High Threat Technologies, NCSC