Skip to content

Simple Fault Injection

Simple Fault Injection

Fault injection is a technique used to induce errors in a system’s operation by manipulating physical signals or inputs. While complex attacks often require sophisticated equipment, simple fault injection methods—such as reset glitches or input manipulation—can exploit basic vulnerabilities in embedded systems, particularly in authentication mechanisms. These techniques rely on disrupting the normal flow of execution or data processing to bypass security checks.


Reset Glitches

A reset glitch involves briefly interrupting the power supply or clock signal to force a system reset during critical operations. This can disrupt cryptographic computations or authentication processes, potentially leaving the system in an unauthenticated state.

Example:
A reset glitch applied during a cryptographic key derivation process might cause the system to reuse cached intermediate values, bypassing the need for a valid key.

Tools/Commands:
- Use a signal generator or oscilloscope to induce a reset pulse:

# Example: Use a GPIO pin to trigger a reset (hypothetical script)
python reset_glitch.py --duration 1e-6 --pin GPIO12
- Monitor the system’s response with a logic analyzer to identify timing windows for successful injection.


Input Manipulation

By altering input signals (e.g., voltage levels, timing, or data bits), attackers can trick embedded systems into accepting invalid credentials or skipping authentication steps. This is particularly effective against systems that rely on timing-based or protocol-specific validation.

Example:
Modifying the timing of a UART signal to disrupt a challenge-response authentication exchange might cause the system to accept a precomputed response.

Tools/Commands:
- Use a serial interface tool to inject modified data:

# Example: Send a modified payload via UART (hypothetical)
echo -ne "\x01\x02\x03" | screen /dev/ttyUSB0 115200
- Adjust signal timing with a programmable logic device (e.g., FPGA) to synchronize with the target’s clock.


Bypassing Authentication Mechanisms

Simple fault injection can bypass authentication by:
1. Disabling cryptographic checks: Forcing a reset during encryption/decryption may leave the system in a state where it accepts unencrypted data.
2. Tricking protocol validation: Altering input data (e.g., MQTT/CoAP payloads) to bypass message integrity checks.
3. Exploiting timing vulnerabilities: Delaying or accelerating signal transitions to skip authentication steps.


Key takeaways

  • Reset glitches can disrupt cryptographic operations, enabling bypasses of authentication.
  • Input manipulation (e.g., signal timing or data alteration) can trick systems into accepting invalid credentials.
  • Simple fault injection leverages physical signal control to exploit weaknesses in embedded security protocols.