Skip to content
Open access

Leakback CRC: Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs

Jul 2026 · IACR Transactions on Cryptographic Hardware and Embedded Systems · Vol 2026, pp. 592-615 · 0 citations

TL;DR

This work presents Leakback CRC, the first optical side-channel attack exploiting the Readback CRC functionality in AMD 7-Series FPGAs to recover plaintext configuration data of encrypted bitstreams, highlighting a critical interplay between reliability mechanisms operating on plaintext configuration data and side-channel leakage.

Abstract

FPGAs are increasingly deployed in security-critical applications, where both design confidentiality and operational reliability are paramount. To protect IP, safeguard cryptographic secrets, and prevent unauthorized modifications or hardware Trojan insertion, modern hardware platforms employ bitstream encryption. Built-in reliability features, often required by safety regulations, detect and correct singleevent upsets, i.e., bit flips, caused by ionizing radiation. However, these reliability mechanisms can inadvertently compromise bitstream confidentiality.In this work, we present Leakback CRC, the first optical side-channel attack exploiting the Readback CRC functionality in AMD 7-Series FPGAs to recover plaintext configuration data of encrypted bitstreams. Our attack utilizes contactless optical probing to monitor periodic configuration memory accesses by the Readback CRC circuitry. This novel attack results in full netlist reconstruction, even though dynamically changing runtime data cannot be retrieved, as it is not verified by the Readback CRC. After presenting the attack in a case study on an AMD 7-Series FPGA, we discuss its limitations and potential countermeasures, as well as its applicability to other FPGA platforms. Our findings highlight a critical interplay between reliability mechanisms operating on plaintext configuration data and side-channel leakage, underscoring the need to broaden the threat model underlying built-in reliability features in reconfigurable hardware.

Read PDF

Similar papers

Conference Jul 2026

Lightweight Memory Obfuscation Using PUF-Based XOR Encryption

Securing memory in resource-constrained embedded systems remains a critical challenge due to the susceptibility of statically stored cryptographic keys to physical and sidechannel attacks. This paper presents a lightweight memory obfuscation architecture based on Physical Unclonable Functions (PUFs), utilizing the intr...

Qabas Alkaissi, Selen Qarajeh, Jana Falah et al. · 0 citations
Open access Aug 2026

Design methodology of clock signal manipulation detectors in FPGAs and ASICs to strengthen vulnerable cryptosystems against fault injection

The growth of the secure Internet of Things has led, among other aspects, to the necessity of ensuring the confidentiality of sensitive user data while simultaneously adhering to stringent constraints regarding area and resource consumption. Attacks on physical implementations of cryptographic primitives are numerous a...

F. E. Potestad-Ordóñez, E. Tena-Sánchez, J. M. Mora-Gutiérrez et al. · 0 citations
Conference Aug 2026

CRYPTIC: CRYptographic FPGA Targeting through Intelligent Corruption

Cryptographic accelerators implemented on Field-Programmable Gate Arrays (FPGAs) are highly vulnerable to bitstream-level fault injection attacks. However, executing spatially precise attacks on undocumented, proprietary bitstreams remains a significant reverse-engineering challenge. In this paper, we propose a novel,...

Christopher Josiah Stance, Mani Rupak Gurram, D. Idowu et al. · 0 citations
Preprint Aug 2026

On the Sensitivity to Errors in Homomorphic Computing: Single Transient Bit-flip Client-side Error Characterization

This work identifies homomorphic multiplication as the most error-sensitive operation in practical HE pipelines and characterize how faults propagate and amplify through it, exposing a critical robustness vulnerability and motivating the need for more resilient HE deployments.

Matías Mazzanti, Vattana Chan, Karthik Swaminathan et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.