Hack Embedded System by Glitching Attacks
No Thumbnail Available
Date
2026
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Saudi Digital Library
Abstract
The proposed project explores Voltage Fault Injection (VFI) as a physical attacker against embedded microcontrollers and specifically aims to show that it is possible to achieve timing determinism at the FPGA level with low-cost and commercially available hardware. The platform of interest was an ATmega328P microcontroller running at 16 MHz and programmed with a deterministic authentication program. The attacker platform was a Raspberry Pi RP2040 because it has dual-core architecture and Programmable I/O (PIO) state machines, giving it hardware-level determinism in execution without interrupt latency. An ad-hoc MOSFET crowbar circuit was developed and constructed to collapse the target supply rail in nanoseconds. The onboard decoupling capacitor of the target was physically removed to shrink the Power Delivery Network time constant of the microsecond range to around 0.47 ns, which put the internal logic gates into submicrosecond power starvation. On the RP2040, a dual-core firmware was used, with Core 1 running the automated Edge-Walker sweep algorithm and Core 0 simply providing deterministic PIO glitch pulses. The three parameters of fault injection: Trigger Delay, Pulse Width and sub-cycle Phase, were systematically swept over the full two-dimensional parameter space to generate high-resolution vulnerability heatmaps of the target processor. Phase 1 determined a sharp induction fault threshold at about 1540 cycles pulse width. Phase 2 traced the nonlinear boundary curve in all delay values measured, and periodic dipssuggested instruction-dependent switching activity in line with the dynamic CMOS power model. In Phase 3, it was shown that the combination of a surgical margin of 160 ns below the sharp corruption threshold, and sub-cycle phase correction at a 62.5 ps resolution, yielded 21 confirmed clean security bypasses (Score 5) without SRAM corruption, and confirmed in three independent trials per coordinate.
Description
Keywords
Voltage Fault Injection (VFI)
Citation
Almutairi,M.(2026).Hack Embedded System by Glitching Attacks(Master’s thesis,University of Portsmouth).
