Feeds

Silicon backdoor: not an international crisis

Researcher’s second lesson: how to troll the entire Internet

Next gen security for virtualised datacentres

Is it something to do with Slavic names? The Register is quite accustomed to Eugene Kaspersky’s astonishing ability to escalate every threat into a “cybergeddon”; now Cambridge researcher Sergei Skorobogatov seems to have taken his lessons to heart.

Let’s pick up the high points of Skorobogatov’s story again: (1) a ‘military grade’ FPGA that is (2) manufactured in China (3) has a backdoor. With a combination like that, the headlines are guaranteed – even if the threat is nebulous.

First, as Errata Security points out, “military grade” does not have the “wow, spook stuff!” meaning that it’s been given in too many outlets. Here is Actel’s outline of specifications for the ProASIC3 series of chips, including the mil-spec device. The first table shows the difference between different devices in the series; the A3P1000 is the “military” version – which means that it has been tested to military temperature requirements.

“Military” doesn’t mean “this is a chip designed to protect military secrets.” It means “if you put this chip into a product it can stand temperatures from -55°c to 125°C.”

Errata Security also points out that “manufactured in China” does not mean “the Chinese tampered with the design to insert the backdoor”. Following the old rule that a stuff-up is more likely than a conspiracy, Errata suggests that the backdoor was probably an intentional feature that the designers forgot to disable when they committed the FPGA’s design to manufacture.

It’s also important to remember that even if the backdoor exists, and even if it’s malicious, it’s not a very useful backdoor. For example, it’s not likely to enable a remote attack allowing Boeing 787 Dreamliners to drop out of the sky.

FPGAs are attacked not by sending a packet over the Internet with the evil bit set. To interfere with the FPGA, you need physical access to the device, and the appropriate equipment and software to program it.

That puts into context another observation made by Errata Security: the purpose of the encryption that Skorobogatov has cracked. The encryption exists not to protect communication between the device and the Big Bad Internet (more on this in a second) – it exists to protect the design placed on the chip. In other words, the threat is not that “military secrets will be stolen”, it’s that your design (and therefore your intellectual property) will be copied. At worst, if that particular chip was in something like a military drone, and if it were captured by an enemy, and if they were able to reproduce the attack – then the design might yield useful information about the drone’s design.

There is, of course, a scenario in which the FPGA might communicate with the Internet: the design implemented on the chip might be a communications stack. Even in that case, the purely internal encryption, designed to protect the gate designs on the chip, has nothing to do with its relationship to the outside world.

Should sensitive users of the chip be worried? Certainly. They want their designs protected. There’s even a discernable risk to someone like Boeing, since it’s feasible that someone with legitimate access to FPGAs might be persuaded or forced to reprogram them with malicious code, or steal Boeing’s code.

For the rest of us, our time would be better spent defending ourselves against the thousands of threats that affect our security. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.