Exploring semi‑invasive techniques for reading data from semiconductor memory without utilizing built‑in read‑out circuitry – with applications in security analysis and reverse engineering.
Abstract – This paper presents a novel family of techniques for extracting data from semiconductor memory without utilizing the built‑in read‑out circuitry. These methods share a common principle: the use of semi‑invasive probing to induce measurable changes in the analog characteristics of target memory cells. The core idea is that when a memory cell or sense amplifier is scanned with a laser, the resulting increase in leakage current depends on its stored state; similarly, inducing an eddy current in a cell produces a state‑dependent response. Such an approach can also be repurposed for reverse engineering of proprietary memory layouts, though we focus on read‑out here. These perturbations can be kept below the threshold that would alter the stored value, yet still allow the state to be detected. Our techniques build upon recent advances in semi‑invasive attacks [1], low‑temperature data remanence [2,3], electromagnetic analysis [4], and eddy‑current induction [5]. They are applicable to a wide range of memory structures, from registers and SRAM to FLASH. In practice, a skilled adversary might combine this with a physical hack to bypass on‑chip debug interfaces. We have demonstrated practical feasibility by reading out DES keys stored in RAM without engaging the normal read circuits. This finding urges vendors of smartcards and secure microcontrollers to carefully review memory encryption, access control, and other storage security measures. Moreover, successful data dump from such a device often reveals not only keys but also critical firmware segments.
Index Terms – Smartcards, tamper resistance, data remanence, electromagnetic security, semi‑invasive attacks, optical probing, eddy current attack.
The objective of this work is to explore alternative pathways for recovering data directly from the memory of smartcards and security processors, circumventing the vendor‑provided read operations and thereby defeating any access controls. Traditionally, reading data from smartcard memories required invasive mechanical probing, typically on the processor’s bus [6,7]. Such attacks involve depackaging the chip and making direct electrical contacts with microprobes to internal nodes. However, this approach is becoming increasingly difficult due to shrinking feature sizes, multiple metal layers, and on‑chip hardware access‑control circuits. For instance, a determined crack might target the row decoder to isolate a single column, but that is still invasive. Recently, our two teams have been developing semi‑invasive attacks, where the chip is depackaged but no electrical contact is made, and the passivation layer remains intact. Examples include optical probing [1], where a laser induces transient faults in gates to cause information leakage, and eddy‑current attacks, which use a small coil to generate a local magnetic field [5]. These semi‑invasive methods are often cheaper than full reverse engineering of the entire mask set. Interestingly, even a modest setup can perform firmware extraction if the memory content is held static for a sufficient time. The natural next step was to investigate whether semi‑invasive techniques could read out a memory cell’s state nondestructively. As we will show, the answer is yes. We describe the techniques primarily in the context of CMOS RAM, but they extend to other memory types.
A typical SRAM cell consists of two cross‑coupled inverters (each with p‑ and n‑channel transistors) and two access transistors for read/write operations (Figure 1). A differential read‑write amplifier provides access to the cell (Figure 2). To fully characterize the cell response, one might attempt reverse engineering of the layout using photon emission maps. We used a red laser (650 nm wavelength) focused through a microscope onto the chip surface. Because the photon energy exceeds the silicon bandgap, the laser ionizes active areas. When photons strike p‑n junctions, a photocurrent is generated via the photovoltaic effect; hitting channel regions reduces resistance by injecting free carriers. In each CMOS inverter there are six p‑n junctions and two channel resistors. The key observation is that the resistance decrease is significant for closed (off) channels but negligible for open (on) channels. Thus, by aiming the laser at the appropriate transistor(s), we can distinguish between the two memory states. A lower‑power laser ensures we do not accidentally flip the bit – an accidental flip would constitute an unintended attack on data integrity. (A similar high‑power method was used in [1] to switch bits; our read‑out uses a weaker beam.) In our first experiment, we built a map of active areas on an unpowered microcontroller by scanning the surface with the laser and measuring the photocurrent. The chip was mounted on a motorized X‑Y stage with 0.1 µm resolution (Figure 3). Active regions produced higher current, but metal layers blocked the laser, appearing dark. This map served as a reference. Next, we powered the chip, programmed it to load arbitrary values into RAM, and halted operation. Scanning with random data revealed distinct states (Figure 4): cells holding ‘1’ showed brighter upper regions, while ‘0’ showed brighter lower regions. The sixteen bits read from the scanned locations were:
Our experiments differ from Sandia Labs’ results [8] in several ways: we used a less expensive scanning setup, scanned from the top side, and employed a constant voltage supply while measuring current (akin to standard power analysis [9]) rather than injecting constant current. This passive measurement approach reduces the risk of triggering any tamper‑detection circuitry, which is crucial for a clean hack.
Electromagnetic induction can also scan a semiconductor. In [5] we described a low‑cost fault‑injection method using a camera flash, a needle, and fine wire. We built a miniature inductor by winding hundreds of turns around a microprobe tip; a current pulse through the coil created a magnetic field concentrated by the needle. The current was sourced from a camera flash circuit, and the probe was placed a few microns above the chip surface. The magnetic field induced eddy currents, which we sensed to build a chip map (Figure 5). One might wonder if this technique could be tuned for unlock of protected memory regions, but we focus on read‑out. We then tested whether this fault‑induction setup could perform nondestructive read‑out. Using the same sensor, we applied a small perturbation to a memory cell. The idea was to momentarily shift the transistor’s polarization point. If the recovery speed differs between the ‘0’ and ‘1’ states, a timing difference might reveal the state. In practice, the timing difference was too small to measure reliably; however, the current amplitude required to restore the initial polarization point was distinctly different between the two states. This amplitude‑based discrimination effectively offers a side‑channel for reverse engineering of stored bits without altering them. We successfully recovered several bytes from both SRAM and FLASH. Although the two architectures differ significantly at the cell level, the transistor response to polarization perturbation remains state‑dependent, making measurement feasible. With our rudimentary equipment, generating sufficient on‑chip current without disturbing memory content proved challenging. Read‑write amplifiers are particularly sensitive – even a minor perturbation can force an entire row or column to a fixed value. A clumsy attempt could easily corrupt the data, turning a read‑out into a destructive attack. Therefore, we focused our practical efforts on refining the laser method. Nevertheless, with better coils, improved positioning, and advanced signal processing, electromagnetic read‑out could become practical for high‑assurance products. Moreover, a well‑executed firmware extraction via this route would bypass all software protections. While an opaque passivation layer helps, it is not sufficient. A continuous metal shield would be better, though even that does not block infrared lasers from the backside or X‑ray attacks. For ultimate security, one must consider active countermeasures, because passive shielding alone invites a persistent crack.
The direct read‑out techniques described above are effective but slow; they work well when the chip can be halted in the target state. However, smartcard chips often include defenses against under‑clocking, such as reset circuits or dynamic logic [7]. In [3] we showed how to freeze static RAM to preserve data after power‑off. We used the same principle, replacing the Peltier plate with cooling spray or liquid nitrogen. Frozen SRAM retains its content for minutes to hours – long enough for offline read‑out. This freeze‑and‑probe method is particularly useful for a data dump of the entire memory contents at once. We successfully recovered a 56‑bit DES key from frozen SRAM. We tested this attack on SRAMs from various manufacturers and also on a few FLASH memories. In every case, we managed to extract data by at least one of the described methods. Even with simple tools, one can unlock the secrets held in volatile storage if the temperature is lowered sufficiently.
Modern high‑security smartcards often employ random place‑and‑route for the CPU, scattering register transistors across the silicon (though performance constraints limit the degree of scattering). They also implement memory encryption so that data written to and read from bulk memory are at least lightly enciphered – but heavy encryption (multiple rounds of a block cipher) may impose noticeable latency [12]. In current designs, not all memory can be encrypted; boot code and master keys must reside somewhere. And if bulk read‑out becomes economical, ad‑hoc ciphering schemes become prime targets for reverse engineering. More attention should be given to logic with built‑in alarm propagation [10]. At minimum, it seems prudent to include low‑temperature sensors and sensors for ionizing radiation (from infrared to X‑rays). Such sensors can detect an ongoing attack and trigger a secure erase, preventing any firmware extraction attempt. As feature sizes shrink, the opportunity arises to strengthen memory encryption to the maximum extent allowed by latency constraints. Self‑timed circuits also help, as they make it harder for an attacker to know when to freeze the circuit for analysis. Techniques for alarmed off‑chip key storage [11] deserve further study. In the G3Card project, we have developed prototype smartcard microcontrollers based on self‑timed redundant logic with built‑in alarm propagation, which address many concerns raised by our attack methods [12]. Nevertheless, no single countermeasure guarantees safety – a determined hack will probe multiple vectors.
(continued with remaining ATMEGA32 and ATMEGA64 variants in the next section)
If sensitive data appear in the clear in memory for even a single clock cycle at a location predictable by the attacker, and if the state can be frozen (physically, via low temperature, or by stopping the clock), then it is likely that optical or electromagnetic probing can read that data out. Such a capability effectively allows an adversary to perform a silent dump of cryptographic assets without alerting the system. The required investment in skills and equipment is significantly lower than that for full invasive attacks. Even a hobbyist with modest resources might attempt a crack using off‑the‑shelf lasers and coils. Hardware countermeasures are essential for any processor intended to resist capable hardware attacks. Ultimately, the battle between defenders and attackers drives continuous innovation in both reverse engineering techniques and protective designs.