Transactions on Cryptographic Hardware and Embedded Systems 2026
Leakback CRC:
Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs
Antonio Saavedra
Technische Universität Berlin, Berlin, Germany
Lars Renkes
Technische Universität Berlin, Berlin, Germany
Felix Hahn
Max Planck Institute for Security and Privacy (MPI-SP), Bochum, Germany
Maik Ender
Max Planck Institute for Security and Privacy (MPI-SP), Bochum, Germany
Christof Paar
Max Planck Institute for Security and Privacy (MPI-SP), Bochum, Germany
Jean-Pierre Seifert
Technische Universität Berlin, Berlin, Germany
Keywords: Leakback CRC, AMD 7-Series FPGAs, Bitstream Security, Laser Voltage Probing, Photon Emission Microscopy, Optical Side Channel, Readback CRC
Abstract
FPGAs are increasingly deployed in security-critical applications, where both design confidentiality and operational reliability are paramount. To protect IP, safeguard cryptographic secrets, and prevent unauthorized modifications or hardware Trojan insertion, modern hardware platforms employ bitstream encryption. Built-in reliability features, often required by safety regulations, detect and correct singleevent upsets, i.e., bit flips, caused by ionizing radiation. However, these reliability mechanisms can inadvertently compromise bitstream confidentiality.In this work, we present Leakback CRC, the first optical side-channel attack exploiting the Readback CRC functionality in AMD 7-Series FPGAs to recover plaintext configuration data of encrypted bitstreams. Our attack utilizes contactless optical probing to monitor periodic configuration memory accesses by the Readback CRC circuitry. This novel attack results in full netlist reconstruction, even though dynamically changing runtime data cannot be retrieved, as it is not verified by the Readback CRC. After presenting the attack in a case study on an AMD 7-Series FPGA, we discuss its limitations and potential countermeasures, as well as its applicability to other FPGA platforms. Our findings highlight a critical interplay between reliability mechanisms operating on plaintext configuration data and side-channel leakage, underscoring the need to broaden the threat model underlying built-in reliability features in reconfigurable hardware.
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3
PaperArtifact
Artifact number
tches/2026/a35
Artifact published
September 21, 2026
Badge
✅ IACR CHES Artifacts Functional
License
This work is licensed under the MIT License.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Antonio Saavedra, Lars Renkes, Felix Hahn, Maik Ender, Christof Paar, Jean-Pierre Seifert. (2026). Leakback CRC: Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 592–615. https://doi.org/10.46586/tches.v2026.i3.592-615. Artifact at https://artifacts.iacr.org/tches/2026/a35.