In this paper, we investigate the impact of permanent
faults on security and show gaping security holes may
exist. We show that an adversary with knowledge of a fault
can launch attacks which can obtain critical secrets like a
private key in less than 2 minutes. The paper’s goal is
to shine light on the problem and we acknowledge
that further work is required to demonstrate practical
value/threat in a real setting.
Our results suggest security and reliability must be
handled in a co-designed fashion and have important
implications. Since the attack time is short, lazy faultdetection
techniques like BIST at boot-time, or coarsegranularity
online-test [10] every day or so, can leave
machines vulnerable. It suggests 100% coverage may
be necessary in fault detection.