Why analog anti-tamper security IP is crucial in the PQC era

While PQC secures cryptographic algorithms, analog anti-tamper IP protects the physical implementation of those algorithms. The post Why analog anti-tamper security IP is crucial in the PQC era appeared first on EDN.

Why analog anti-tamper security IP is crucial in the PQC era












The global semiconductor industry is transitioning to the post-quantum cryptography (PQC) era. PQC is changing how digital systems defend against potential mathematical attacks. PQC algorithms are designed to protect against hackers who try to recover secret keys by breaking the underlying mathematics. However, physical hardware attacks can bypass mathematically secure algorithms, even if a PQC algorithm is perfectly implemented.

As organizations migrate to PQC, replacing the cryptographic assets being protected—PQC private keys, root keys, firmware signing keys—becomes costly and complex in deployed devices like automotive electronic control units (ECUs) and industrial or defense systems. When a chip processes post-quantum algorithms, it handles significantly larger key sizes and more complex mathematical operations than legacy cryptography.

This extended processing time and high computational intensity widen the vulnerability window, leaving the silicon exposed to physical tampering such as side-channel attacks (SCAs) and fault injection attacks (FIAs).

Mathematically upgrading to PQC only stops a hacker sitting at a quantum computer miles away. It does not stop a hacker from attempting physical attacks. This is where analog anti-tamper security IP comes into play. Analog sensors provide the first layer of defense to secure the silicon itself by detecting tampering techniques used in physical attacks, such as clock, voltage and temperature attacks, as well as electromagnetic and laser fault injection attacks.

Clock, voltage, and temperature attacks

A clock attack occurs when a hacker alters the incoming clock’s frequency or timing on a chip to cause glitches in an effort to interrupt normal operations and extract sensitive information. A clock attack monitor can be implemented to track the frequency and timing of the clock signal. If there is any unusual activity, an alert would be raised and preventive action taken.

A voltage glitch attack takes place when a hacker tries to tamper with the incoming power supply. Generating voltage drops or spikes can cause errors that impact encryption algorithms and bypass security procedures. A voltage glitch detector identifies when there is an unexpected change in voltage and sets off an alarm to reset or shutdown the system to protect against data loss.

A temperature or thermal attack involves a hacker quickly heating or cooling a device to generate timing or supply errors without having access to the clock signal or power supply. A temperature sensor can check for sudden temperature variations and then apply countermeasures if required.

Electromagnetic and laser fault injection attacks

An electromagnetic fault injection (EMFI) attack is when the hacker tampers with a device using an electromagnetic pulse, so no electrical contact or physical connection to the chip’s pins is required. An EMFI sensor can be integrated into the silicon to detect even small changes in the internal magnetic field on the device and respond swiftly to stop an attack from causing damage.

A laser fault injection (LFI) attack occurs when a laser beam is used by a hacker to induce errors to breach security and corrupt data. An LFI sensor is placed on a chip to monitor specific transient characteristics of a malicious laser pulse. If there are any indications of an attack, then the sensor can ensure that secret keys are erased or the device may be forced into lockdown mode.

PQC’s physical side

As PQC becomes more widely adopted, the frequency and complexity of physical hardware attacks are expected to rise. Whilst the latest cryptographic algorithms may resist quantum computers, hackers will continue to exploit physical vulnerabilities because without robust protection these are often easier than breaking the underlying mathematics.

This looks set to drive demand for analog anti-tamper IP that can detect clock, voltage, temperature, EMFI and LFI attacks, trigger responses such as key zeroization or secure reset if required, complement digital root of trust (RoT) solutions, and strengthen compliance with hardware security requirements in sectors such as automotive, industrial, financial and government.

Analog IP solutions offer a continuous line of defense, including clock, voltage, temperature and EMFI sensors, which complement digital RoT systems. As physical attack routes evolve, adding optical and LFI detection to the physical security envelope will become the benchmark for securing next-generation system-on-chips (SoCs).

While PQC addresses the security of cryptographic algorithms, analog anti-tamper IP protects the physical implementation of those algorithms. As organizations invest in PQC, safeguarding the hardware root of trust and stopping physical attacks becomes an even more critical part of a comprehensive security strategy.

Chris Morrison is VP of product marketing at Agile Analog.

Related Content

The post Why analog anti-tamper security IP is crucial in the PQC era appeared first on EDN.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow