Reverse Engineering & Memory Read‑out Research

Exploring semi‑invasive techniques for reading data from semiconductor memory without utilizing built‑in read‑out circuitry – with applications in security analysis and reverse engineering.

On a New Way to Read Data from Memory

Abstract – This paper presents a novel family of techniques for extracting data from semiconductor memory without utilizing the built‑in read‑out circuitry. These methods share a common principle: the use of semi‑invasive probing to induce measurable changes in the analog characteristics of target memory cells. The core idea is that when a memory cell or sense amplifier is scanned with a laser, the resulting increase in leakage current depends on its stored state; similarly, inducing an eddy current in a cell produces a state‑dependent response. Such an approach can also be repurposed for reverse engineering of proprietary memory layouts, though we focus on read‑out here. These perturbations can be kept below the threshold that would alter the stored value, yet still allow the state to be detected. Our techniques build upon recent advances in semi‑invasive attacks [1], low‑temperature data remanence [2,3], electromagnetic analysis [4], and eddy‑current induction [5]. They are applicable to a wide range of memory structures, from registers and SRAM to FLASH. In practice, a skilled adversary might combine this with a physical hack to bypass on‑chip debug interfaces. We have demonstrated practical feasibility by reading out DES keys stored in RAM without engaging the normal read circuits. This finding urges vendors of smartcards and secure microcontrollers to carefully review memory encryption, access control, and other storage security measures. Moreover, successful data dump from such a device often reveals not only keys but also critical firmware segments.

Index Terms – Smartcards, tamper resistance, data remanence, electromagnetic security, semi‑invasive attacks, optical probing, eddy current attack.

1. Introduction

The objective of this work is to explore alternative pathways for recovering data directly from the memory of smartcards and security processors, circumventing the vendor‑provided read operations and thereby defeating any access controls. Traditionally, reading data from smartcard memories required invasive mechanical probing, typically on the processor’s bus [6,7]. Such attacks involve depackaging the chip and making direct electrical contacts with microprobes to internal nodes. However, this approach is becoming increasingly difficult due to shrinking feature sizes, multiple metal layers, and on‑chip hardware access‑control circuits. For instance, a determined crack might target the row decoder to isolate a single column, but that is still invasive. Recently, our two teams have been developing semi‑invasive attacks, where the chip is depackaged but no electrical contact is made, and the passivation layer remains intact. Examples include optical probing [1], where a laser induces transient faults in gates to cause information leakage, and eddy‑current attacks, which use a small coil to generate a local magnetic field [5]. These semi‑invasive methods are often cheaper than full reverse engineering of the entire mask set. Interestingly, even a modest setup can perform firmware extraction if the memory content is held static for a sufficient time. The natural next step was to investigate whether semi‑invasive techniques could read out a memory cell’s state nondestructively. As we will show, the answer is yes. We describe the techniques primarily in the context of CMOS RAM, but they extend to other memory types.

Chip models covered in this section:

A3949SLPTRA3950SLPTRA3951SBA3952SEB A3953SBA3953SLBTRA3955SBA3958SLBTR A3959SBA3959SLBA3959SLPA3961SLB A3966SLBTRA3967SLBA3968SLBTRA3969SETTR A3972SBA3977SLPA3979SLPA3986SLDTR A3988SJP

2. Optical Read‑out of CMOS RAM

A typical SRAM cell consists of two cross‑coupled inverters (each with p‑ and n‑channel transistors) and two access transistors for read/write operations (Figure 1). A differential read‑write amplifier provides access to the cell (Figure 2). To fully characterize the cell response, one might attempt reverse engineering of the layout using photon emission maps. We used a red laser (650 nm wavelength) focused through a microscope onto the chip surface. Because the photon energy exceeds the silicon bandgap, the laser ionizes active areas. When photons strike p‑n junctions, a photocurrent is generated via the photovoltaic effect; hitting channel regions reduces resistance by injecting free carriers. In each CMOS inverter there are six p‑n junctions and two channel resistors. The key observation is that the resistance decrease is significant for closed (off) channels but negligible for open (on) channels. Thus, by aiming the laser at the appropriate transistor(s), we can distinguish between the two memory states. A lower‑power laser ensures we do not accidentally flip the bit – an accidental flip would constitute an unintended attack on data integrity. (A similar high‑power method was used in [1] to switch bits; our read‑out uses a weaker beam.) In our first experiment, we built a map of active areas on an unpowered microcontroller by scanning the surface with the laser and measuring the photocurrent. The chip was mounted on a motorized X‑Y stage with 0.1 µm resolution (Figure 3). Active regions produced higher current, but metal layers blocked the laser, appearing dark. This map served as a reference. Next, we powered the chip, programmed it to load arbitrary values into RAM, and halted operation. Scanning with random data revealed distinct states (Figure 4): cells holding ‘1’ showed brighter upper regions, while ‘0’ showed brighter lower regions. The sixteen bits read from the scanned locations were:

1 1 0 0
1 1 1 0
1 1 1 1
1 1 1 1

Our experiments differ from Sandia Labs’ results [8] in several ways: we used a less expensive scanning setup, scanned from the top side, and employed a constant voltage supply while measuring current (akin to standard power analysis [9]) rather than injecting constant current. This passive measurement approach reduces the risk of triggering any tamper‑detection circuitry, which is crucial for a clean hack.

Chip models covered in this section:

ATM39B11628R7016ATM39B1426758R7016AATM39B142675BR71016A ATM39BATM39B556757ATM4020ATM4020 ATM402NATM402PATM40LNATM40LN416745R4818 ATM40R7007ATM40R7007

3. Electromagnetic Attack

Electromagnetic induction can also scan a semiconductor. In [5] we described a low‑cost fault‑injection method using a camera flash, a needle, and fine wire. We built a miniature inductor by winding hundreds of turns around a microprobe tip; a current pulse through the coil created a magnetic field concentrated by the needle. The current was sourced from a camera flash circuit, and the probe was placed a few microns above the chip surface. The magnetic field induced eddy currents, which we sensed to build a chip map (Figure 5). One might wonder if this technique could be tuned for unlock of protected memory regions, but we focus on read‑out. We then tested whether this fault‑induction setup could perform nondestructive read‑out. Using the same sensor, we applied a small perturbation to a memory cell. The idea was to momentarily shift the transistor’s polarization point. If the recovery speed differs between the ‘0’ and ‘1’ states, a timing difference might reveal the state. In practice, the timing difference was too small to measure reliably; however, the current amplitude required to restore the initial polarization point was distinctly different between the two states. This amplitude‑based discrimination effectively offers a side‑channel for reverse engineering of stored bits without altering them. We successfully recovered several bytes from both SRAM and FLASH. Although the two architectures differ significantly at the cell level, the transistor response to polarization perturbation remains state‑dependent, making measurement feasible. With our rudimentary equipment, generating sufficient on‑chip current without disturbing memory content proved challenging. Read‑write amplifiers are particularly sensitive – even a minor perturbation can force an entire row or column to a fixed value. A clumsy attempt could easily corrupt the data, turning a read‑out into a destructive attack. Therefore, we focused our practical efforts on refining the laser method. Nevertheless, with better coils, improved positioning, and advanced signal processing, electromagnetic read‑out could become practical for high‑assurance products. Moreover, a well‑executed firmware extraction via this route would bypass all software protections. While an opaque passivation layer helps, it is not sufficient. A continuous metal shield would be better, though even that does not block infrared lasers from the backside or X‑ray attacks. For ultimate security, one must consider active countermeasures, because passive shielding alone invites a persistent crack.

Chip models covered in this section:

ATM41/BATM41BATM41/B/946748ATM41B946748 ATM415NATM43CATM43C926792ATM43D ATM43D446778ATM43TRATM43TR6MATM43TRCM ATM46C3ATM46C3966781ATMEA48ATMEA4820PU ATMEAG2561ATMEAG256116AUATMEAG32LATMEAG32L8AU ATMEFA8ATMEFA816AIATMEFA88AIATMEFA8AU

4. Freezing and Probing

The direct read‑out techniques described above are effective but slow; they work well when the chip can be halted in the target state. However, smartcard chips often include defenses against under‑clocking, such as reset circuits or dynamic logic [7]. In [3] we showed how to freeze static RAM to preserve data after power‑off. We used the same principle, replacing the Peltier plate with cooling spray or liquid nitrogen. Frozen SRAM retains its content for minutes to hours – long enough for offline read‑out. This freeze‑and‑probe method is particularly useful for a data dump of the entire memory contents at once. We successfully recovered a 56‑bit DES key from frozen SRAM. We tested this attack on SRAMs from various manufacturers and also on a few FLASH memories. In every case, we managed to extract data by at least one of the described methods. Even with simple tools, one can unlock the secrets held in volatile storage if the temperature is lowered sufficiently.

Chip models covered in this section (ATMEGA128‑series and related variants):

ATMEG324PATMEG324P20AUATMEG324P20MUATMEG324P20MU1–6 ATMEG324P20PUATMEG324PA15AZATMEG324PA15MZATMEG324PA ATMEG324PAAUATMEG324PACUATMEG324PACUKATMEG324PAMU1–8 ATMEG324PB15AZATMEG324PVATMEG324PV10AU1–4ATMEG324PV10MU ATMEG324PV10PUATMEG3250ATMEG325016AU1–4ATMEG325P ATMEG325P16MUATMEG325P20AUATMEG325PVATMEG325PV8AU ATMEG325PV8MUATMEG325VATMEG325V8MU1–2ATMEGA328AU ATMEGA328PATMEGA328P10AUATMEGA328P20AUATMEGA328P20MU ATMEGA328P20PUATMEGA328PAATMEGA328PAMUATMEGA328PMU1–7 ATMEGA328PPUATMEGA328PVATMEGA328PV10AUATMEGA328PV10MU1–2 ATMEGA3290ATMEGA329016AIATMEGA329016AU1–2ATMEGA3290P ATMEGA3290P16AUATMEGA3290P20AUATMEGA3290PVATMEGA3290PV10AU1–6 ATMEGA3290VATMEGA3290V8AIATMEGA329ATMEGA32916AU ATMEGA329PATMEGA329P16AUATMEGA329P16MUATMEGA329P20AU ATMEGA329PAUATMEGA329PVATMEGA329PV8AUATMEGA329PV8MU1–6 ATMEGA329VATMEGA329V8AIATMEGA329V8AUATMEGA329V8MU ATMEGA32AATMEGA32A16PUATMEGA32AAUATMEGA32AMU ATmega32C1ATMEGA32C1ATMEGA32C115AZATMEGA32C115MZ ATMEGA32LATMEGA32L8ACATMEGA32L8AEATMEGA32L8AU ATMEGA32L8MCATMEGA32L8MUATMEGA32L8MU0–17ATMEGA32LMU ATMEGA32M1ATMEGA32M115ADATMEGA32M115MDATMEGA32U2 ATMEGA32U2MUATMEGA32U4ATMEGA32U4MUATMEGA32UC3B1256 ATMEGA32UC3B1256Z1UATMEGA341.983ATMEGA34198300ATMEGA406 ATMEGA4061AAU1–3ATMEGA45ATMEGA4520AUATmega46D1 ATMEGA48ATMEGA4810AUATMEGA4815AT1ATMEGA4815AZ ATMEGA4815MTATMEGA4820AUATMEGA4820MUATMEGA4820U ATMEGA48AATMEGA48APUATMEGA48PATMEGA48P20AU1 ATMEGA48P20MUATMEGA48PAATMEGA48PA15AZATMEGA48PA15MZ ATMEGA48PA20MUATMEGA48PAAUATMEGA48PAMUATMEGA48PPU ATMEGA48PVATMEGA48PV10AUATMEGA48PV10MUATMEGA48V ATMEGA48V10AIATMEGA48V10AUATMEGA48V10MUATMEGA48V10PU ATMEGA48V12MIATMEGA48V218KATMEGA48VPU

5. Countermeasures

Modern high‑security smartcards often employ random place‑and‑route for the CPU, scattering register transistors across the silicon (though performance constraints limit the degree of scattering). They also implement memory encryption so that data written to and read from bulk memory are at least lightly enciphered – but heavy encryption (multiple rounds of a block cipher) may impose noticeable latency [12]. In current designs, not all memory can be encrypted; boot code and master keys must reside somewhere. And if bulk read‑out becomes economical, ad‑hoc ciphering schemes become prime targets for reverse engineering. More attention should be given to logic with built‑in alarm propagation [10]. At minimum, it seems prudent to include low‑temperature sensors and sensors for ionizing radiation (from infrared to X‑rays). Such sensors can detect an ongoing attack and trigger a secure erase, preventing any firmware extraction attempt. As feature sizes shrink, the opportunity arises to strengthen memory encryption to the maximum extent allowed by latency constraints. Self‑timed circuits also help, as they make it harder for an attacker to know when to freeze the circuit for analysis. Techniques for alarmed off‑chip key storage [11] deserve further study. In the G3Card project, we have developed prototype smartcard microcontrollers based on self‑timed redundant logic with built‑in alarm propagation, which address many concerns raised by our attack methods [12]. Nevertheless, no single countermeasure guarantees safety – a determined hack will probe multiple vectors.

Chip models covered in this section (ATMEGA16‑series and some 64/640/64L etc.):

ATMEGA160ATMEGA16016AUATMEGA16ATMEGA1610AU ATMEGA1616ACATMEGA1616AIATMEGA1616AJATMEGA1616AU ATMEGA1616MUATMEGA1616PUATMEGA161L4ACATMEGA161L ATMEGA161L4AIATMEGA161L4PIATMEGA162ATMEGA16216AC ATMEGA16216AIATMEGA16216AUATMEGA16216MCATMEGA16216MU ATMEGA16216PUATMEGA1628MUATMEGA1628PUATMEGA162L ATMEGA162L8MCATMEGA162L8MIATMEGA162VATMEGA162V16MI ATMEGA162V8AUATMEGA162V8PUATMEGA163ATMEGA1638AU ATMEGA163LATMEGA163L4AIATMEGA163L8ACATMEGA164P ATMEGA164P20AQATMEGA164P20MUATMEGA164PA15AZATMEGA164PA15MZ ATMEGA164PAATMEGA164PAMUATMEGA164PB15AZATMEGA164PV ATMEGA164PV10MUATMEGA165ATMEGA16516AIATMEGA168 ATMEGA16810AIATMEGA16815AT1ATMEGA16815MTATMEGA16820AU ATMEGA16820AUTRATMEGA16820AURATMEGA16820MUATMEGA168A ATMEGA168A8PUATMEGA168PATMEGA168P15AZATMEGA168P20AU ATMEGA168P20MUATMEGA168PAATMEGA168PA15MZATMEGA168PAMU ATMEGA168PVATMEGA168PV10AUATMEGA168PV10MUATMEGA168V ATMEGA168V10AUATMEGA168V10MUATMEGA168V10PUATMEGA169 ATMEGA16916AIATMEGA169LATMEGA169L4MCATMEGA169L4MI ATMEGA169PATMEGA169P10AUATMEGA169P16MCUATMEGA169PV ATMEGA169PV8AUATMEGA169VATMEGA169V1MCATMEGA169V8AI ATMEGA169V8AUATMEGA169V8MUATMEGA16A4ATMEGA16A4AU ATMEGA16AATMEGA16AAUATMEGA16AMUATmega16B1 ATMEGA16BATMEGA16B20AUATMEGA16BVATMEGA16BV10AU ATMEGA16HVAATMEGA16HVA4TUATMEGA16LATMEGA16L16AI ATMEGA16L16PUATMEGA16L8AIATMEGA16L8APATMEGA16L8AQ ATMEGA16L8AUATMEGA16L8MUATMEGA16L8PUATMEGA16M1 ATMEGA16M115MDATMEGA16U2ATMEGA16U2AUATMEGA16U4 ATMEGA16U4AUATMEGA182ATMEGA18216AIATMEGA2 ATMEGA24ATMEGA25ATMEGA25256AWATMEGA2560 ATMEGA256016AIATMEGA256016AUATMEGA256016CUATMEGA25608AU ATMEGA2560AIATMEGA2560AUATMEGA2560CUATMEGA2560CUES ATMEGA2560VATMEGA2560V8AIATMEGA2560V8AUATMEGA2561 ATMEGA256116AUATMEGA25618MUATMEGA2561AUATMEGA2561MU ATMEGA2561VATMEGA2561V8AIATMEGA2561V8AUATMEGA256A3 ATMEGA256A3AUATMEGA321ATMEGA32115MD

(continued with remaining ATMEGA32 and ATMEGA64 variants in the next section)

6. Conclusion

If sensitive data appear in the clear in memory for even a single clock cycle at a location predictable by the attacker, and if the state can be frozen (physically, via low temperature, or by stopping the clock), then it is likely that optical or electromagnetic probing can read that data out. Such a capability effectively allows an adversary to perform a silent dump of cryptographic assets without alerting the system. The required investment in skills and equipment is significantly lower than that for full invasive attacks. Even a hobbyist with modest resources might attempt a crack using off‑the‑shelf lasers and coils. Hardware countermeasures are essential for any processor intended to resist capable hardware attacks. Ultimately, the battle between defenders and attackers drives continuous innovation in both reverse engineering techniques and protective designs.

Chip models covered in this section (remainder – ATMEGA64, ATMEGA8, ATMEGA8515, ATMEGA8535, etc.):

ATMEGA640ATMEGA640AUATMEGA640VATMEGA640V8CU ATMEGA64ATMEGA6416AIATMEGA6416AUATMEGA644 ATMEGA644MUATMEGA644PATMEGA644P10MUATMEGA644P15MT1 ATMEGA644P20MUATMEGA644PA15MZATMEGA644PVATMEGA644PV10AU ATMEGA644PV10MUATMEGA644VATMEGA644V10AUATMEGA645V ATMEGA645V8AUATMEGA6490ATMEGA649016AIATMEGA6490V ATMEGA6490V8AUATMEGA649ATMEGA64916AIATMEGA64916AU ATMEGA64AATMEGA64AAUATMEGA64C1ATMEGA64L ATMEGA64L16AUATMEGA64L8AIATMEGA64L8AQATMEGA64L8MC ATMEGA64L8MIATMEGA64L8MJATMEGA64L8MQATMEGA64L8MU ATMEGA64L8MUMIMCATMEGA64M1ATMEGA64M115MDATMEGA8 ATMEGA810AIATMEGA816AIATMEGA816AUATMEGA816MC ATMEGA816MUATMEGA816MUT+RATMEGA8515ATMEGA851516J ATMEGA851516MUATMEGA851516PUATMEGA8515LATMEGA8515L16PC ATMEGA8515L8ACATMEGA8515L8AIATMEGA8515L8AUATMEGA8515REV ATMEGA8535ATMEGA853516JURATMEGA853516MUATMEGA85358PI ATMEGA8535LATMEGA8535L16MCATMEGA8535L8AIATMEGA8535L8AU ATMEGA8535L8AUPBATMEGA8535L8MIATMEGA8535L8MU