JTAG 신호분석을 이용한 상용 MCU 해킹 취약성 연구

A Study on Hacking Vulnerability for Commercial MCUs using JTAG Signal Analysis
  • 이건하
  • 공원배
  • 정혜민
  • 전지원
  • 김동규

초록

Rapid development of IoT and communication technologies after the 4th industrial revolution, increased demand for smartphones and embedded devices. IoT devices and smartphones often use JTAG for system debugging, but some attacks exploit JTAG vulnerabilities such as forensics to obtain data in the system's internal memory. To prevent JTAG attacks, major vendors who manufacture systems suggested secure JTAG and protection mode as security methods. This paper proposes a method to analyze an authentication protocol using JTAG signal analysis and shows unauthorized users can be authenticated As a result, we could find the authentication protocol and the secret key value used for authentication in STMicro MCUs, one of the major vendors. In addition, we have shown that an unauthorized user can modify the memory protection privileges by revaluing the control register. Through this, we notify the hacking vulnerability of MCUs using a simple authentication protocol that repeatedly uses the same key and JTAG communication that does not consider communication interception.

키워드

JTAGSecure JTAGMCUARMDebugSignal analysis
제목
JTAG 신호분석을 이용한 상용 MCU 해킹 취약성 연구
제목 (타언어)
A Study on Hacking Vulnerability for Commercial MCUs using JTAG Signal Analysis
저자
이건하공원배정혜민전지원김동규
DOI
10.5573/ieie.2021.58.12.19
발행일
2021-12
저널명
전자공학회논문지
58
12
페이지
19 ~ 26

파일 다운로드