Ops! It is JTAG's Fault: Journey to Unlocking Automotive Grade IC

No ratings

Presented at Black Hat USA 2024

JTAG (Joint Test Action Group), a widely used standard interface for IC testing, is extensively applied to debug circuit boards and chips, particularly automotive-grade chips. Automotive-grade ICs have stringent security requirements, and nearly all such ICs are equipped with JTAG protection. This mechanism effectively prevents attackers from illegally connecting to the JTAG interface, such that they cannot read or modify the firmware, thereby ensuring the security of vehicle systems. We conducted analysis on the JTAG protocol of the SPC5 chip, which is widely used in automotive security & safety critical controllers. We reverse-engineered the JTAG password authentication process, and identified the key values indicating whether the authentication passed or not. However, due to a redundant check mechanism in the authentication procedure, it is almost impossible to perform fault injection attacks directly. Therefore, we innovatively designed and made a special hardware gadget to bypass the redundant checks, achieving a single, stable trigger for the chip's JTAG password verification. Ultimately, we passed the JTAG authentication using voltage fault injection. We believe that this vulnerability broadly affects the entire SPC5 series of chips and, very likely, chips from other vendors. We have responsibly reported this vulnerability to STMicroelectronics. This talk will show this "Unlocking Adventure of SPC5 Automotive Chips' JTAG: Protocol Analysis, Redundancy Bypass, and Fault Injection," and remind the users not to have their security critical applications solely rely on the JTAG protection.