Transactions on Cryptographic Hardware and Embedded Systems 2026
Leakback CRC:
Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs
README
Leakback CRC: Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs
This artifact comprises multiple test designs for the preliminary experiments in Section 4. Additionally, for the case study in Section 5, we provide the target design we attacked, our measurement results, and the final bitstream we reconstructed using the Leakback CRC attack. The preliminary experiment described in Section 4.5 overlaps with our case study in Section 5. Therefore, there is no separate folder for Section 4.5. More detailed descriptions are found in the respective subfolders.
Folder Overview
The list of experiments is the following:
- Section 4.1: "Retrospectively Enabling Readback CRC": 4.1_enabling_rcrc
- Section 4.2: "Determining the Configuration Frames Checked by Readback CRC" 4.2_rcrc_frames
- Section 4.3: "Identifying Readback CRC Bus Locations" 4.3_rcrc_locations
- Section 4.4: "Confirming the Probed Data Matches the Configuration Data" 4.4_rcrc_probing
- Section 4.5: "Aligning the LVP Trigger With the Readback CRC Cycle" 5_case_study
- Section 5: "Leakback CRC Case Study" 5_case_study
Hardware
We conducted our preliminary experiments and case study using a Digilent Nexys Video. The specific part number of the XC7A200T on this board is xc7a200tsbg484-1. The actual measurements were conducted using a HAMAMATSU PHEMOS-1000 emission microscope.
Experiments with Vivado Designs
As our artifact contains multiple Vivado designs, we reused the same folder structure, as described below. Since the projects are rebuilt from scratch, they are independent of a specific Vivado version. In each experiment folder, we specified the Vivado version used for the respective project.
Project Structure
The directory structure is the following:
$(experiment_name)/
constraints/ - Constraint files ip/ - IP cores rtl/ - Verilog source code sim/ - Testbenches rebuild.tcl - TCL script to generate the Vivado project $(experiment_name)_prj/ - Vivado project folder
The $(experiment_name)_prj/ folder will be generated automatically when executing the rebuild.tcl script.
Build Project
To build the projects, run the rebuild.tcl script from the respective experiment folder. The source files are loaded remotely from the respective folders and are not copied to the project folder during build.
cd $(experiment_name)
vivado -source rebuild.tcl
Also, if the project folder exists, it can be deleted and rebuilt.
rm -rf $(experiment_name)_prj
vivado -source rebuild.tcl
Licenses
All our contributions in this artifact are released under the MIT License. If we used external scripts or sources, we specified the respective licenses in the subfolders.