Originally published at IOActive Labs, this research explores how physical hardware fault injection (voltage glitching) can be utilized to subvert secure boot and firmware validation mechanisms in commercial unmanned aerial vehicles (drones).
The Attack Surface: Firmware Upgrade Pipelines
Commercial drone platforms enforce digital signature verification using public-key cryptography (such as RSA-2048 or ECDSA) before allowing new firmware binaries to be written to flash memory. However, signature checking algorithms ultimately execute on microcontrollers that are vulnerable to electrical transients.
By injecting a precision negative voltage pulse onto the microcontroller's core power rail ({DD}$) during the exact clock cycle where the return value of verify_signature() is evaluated, an attacker can flip condition branch flags.
"A single nanosecond glitch can convert a failed cryptographic verification from0x00 (DENIED)to0x01 (SUCCESS), causing the device to happily flash unauthorized, modified firmware."
Trigger Synchronization & Oscilloscope Traces
The primary challenge in fault injection is trigger repeatability. By monitoring GPIO activity or power consumption spikes during hash calculations, we generate a deterministic trigger signal using an FPGA or fast microcontroller.
; Cryptographic signature check routine
BL crypto_rsa_verify ; Return 0 if invalid, 1 if valid in R0
CMP R0, #0 ; Check result
BEQ error_invalid_signature ; <-- TARGET GLITCH POINT: Force branch to fall through
BL flash_write_firmware ; Firmware update proceeds!
Mitigations for Hardware Engineers
- Redundant Checks with Randomized Delays: Never rely on a single binary condition check. Implement multi-point integrity checks with randomized software delays.
- Internal Power Supervisory Circuits: Use silicon featuring on-chip brownout detectors and glitch filters directly integrated on the die.
- Dual-Rail Hardware Comparison: Implement fault-tolerant dual-core lockstep architectures.
Get New Research & U-Boot Lab Resources
Subscribe to receive notifications when new embedded security papers, reverse engineering tools, and U-Boot VM updates are released.