International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Leakback CRC:

Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs


Antonio Saavedra
Technische Universität Berlin, Berlin, Germany

Lars Renkes
Technische Universität Berlin, Berlin, Germany

Felix Hahn
Max Planck Institute for Security and Privacy (MPI-SP), Bochum, Germany

Maik Ender
Max Planck Institute for Security and Privacy (MPI-SP), Bochum, Germany

Christof Paar
Max Planck Institute for Security and Privacy (MPI-SP), Bochum, Germany

Jean-Pierre Seifert
Technische Universität Berlin, Berlin, Germany


Keywords: Leakback CRC, AMD 7-Series FPGAs, Bitstream Security, Laser Voltage Probing, Photon Emission Microscopy, Optical Side Channel, Readback CRC


Abstract

FPGAs are increasingly deployed in security-critical applications, where both design confidentiality and operational reliability are paramount. To protect IP, safeguard cryptographic secrets, and prevent unauthorized modifications or hardware Trojan insertion, modern hardware platforms employ bitstream encryption. Built-in reliability features, often required by safety regulations, detect and correct singleevent upsets, i.e., bit flips, caused by ionizing radiation. However, these reliability mechanisms can inadvertently compromise bitstream confidentiality.In this work, we present Leakback CRC, the first optical side-channel attack exploiting the Readback CRC functionality in AMD 7-Series FPGAs to recover plaintext configuration data of encrypted bitstreams. Our attack utilizes contactless optical probing to monitor periodic configuration memory accesses by the Readback CRC circuitry. This novel attack results in full netlist reconstruction, even though dynamically changing runtime data cannot be retrieved, as it is not verified by the Readback CRC. After presenting the attack in a case study on an AMD 7-Series FPGA, we discuss its limitations and potential countermeasures, as well as its applicability to other FPGA platforms. Our findings highlight a critical interplay between reliability mechanisms operating on plaintext configuration data and side-channel leakage, underscoring the need to broaden the threat model underlying built-in reliability features in reconfigurable hardware.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a35

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (71329342 Bytes)  

View repository

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Antonio Saavedra, Lars Renkes, Felix Hahn, Maik Ender, Christof Paar, Jean-Pierre Seifert. (2026). Leakback CRC: Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 592–615. https://doi.org/10.46586/tches.v2026.i3.592-615. Artifact at https://artifacts.iacr.org/tches/2026/a35.