axlq wrote:> In article <E_adneyngKqVlCLXnZ2dnUVZ_qydnZ2d@web-ster.com>, > Tim Wescott <tim@seemywebsite.com> wrote: >> On Sat, 26 Sep 2009 16:59:44 +0000, axlq wrote: >>> A business partner has an algorithm applicable to schocastic data, for >>> which it isn't possible to reverse engineer by studying the outputs and >>> inputs. Is it possible to fabricate a custom DSP chip in such a way to >>> prevent the underlying algorithm from being extracted, so it can remain >>> a trade secret? > >> Nothing will keep a well-funded potential competitor from grinding the >> top off the chip and reverse-engineering (or just outright copying) the >> code and/or design. >> >> But as others have said, there are chips with security features that'll >> make it harder. >> >> All you can ever do is make it hard enough to be unprofitable; you'll >> never make it impossible. > > That's what I figured. I appreciate all the responses. > > I would have thought these days the chip circuitry might be > sufficiently 3-dimensional to make grinding off the top impractical > for copying purposes.You can probe the various parts. After all, with a lot of probing and analysis, you can work out the circuit defined by a multi-layer circuit board. Some masked ROMs can be read by looking at them under a microscope. Jerry -- Engineering is the art of making what you want from things you can get. �����������������������������������������������������������������������
Snoop-proof DSP: possible?
Started by ●September 26, 2009
Reply by ●September 28, 20092009-09-28
Reply by ●September 28, 20092009-09-28
Jerry Avins wrote:> axlq wrote: > >> In article <E_adneyngKqVlCLXnZ2dnUVZ_qydnZ2d@web-ster.com>, >> Tim Wescott <tim@seemywebsite.com> wrote: >> >>> On Sat, 26 Sep 2009 16:59:44 +0000, axlq wrote: >>> >>>> A business partner has an algorithm applicable to schocastic data, for >>>> which it isn't possible to reverse engineer by studying the outputs and >>>> inputs. Is it possible to fabricate a custom DSP chip in such a way to >>>> prevent the underlying algorithm from being extracted, so it can remain >>>> a trade secret? >> >> >>> Nothing will keep a well-funded potential competitor from grinding >>> the top off the chip and reverse-engineering (or just outright >>> copying) the code and/or design. >>> >>> But as others have said, there are chips with security features >>> that'll make it harder. >>> >>> All you can ever do is make it hard enough to be unprofitable; you'll >>> never make it impossible. >> >> That's what I figured. I appreciate all the responses. >> >> I would have thought these days the chip circuitry might be >> sufficiently 3-dimensional to make grinding off the top impractical >> for copying purposes.In the old times of USSR, they use to analyse the foreigh chips for the purpose of copying. They replicated i386 and analysed i486, however there was no technology avalable to make i486.> You can probe the various parts. After all, with a lot of probing and > analysis, you can work out the circuit defined by a multi-layer circuit > board. Some masked ROMs can be read by looking at them under a microscope.Here are some companies who offer the chip tear down services as well as consultancy about the chip security: www.flylogic.net www.semiresearch.com There is quite some interesting info there. Vladimir Vassilevsky DSP and Mixed Signal Design Consultant http://www.abvolt.com
Reply by ●September 28, 20092009-09-28
On Sep 28, 12:06�pm, Jerry Avins <j...@ieee.org> wrote:> axlq wrote: > > In article <E_adneyngKqVlCLXnZ2dnUVZ_qydn...@web-ster.com>, > > Tim Wescott �<t...@seemywebsite.com> wrote: > >> On Sat, 26 Sep 2009 16:59:44 +0000, axlq wrote: > >>> A business partner has an algorithm applicable to schocastic data, for > >>> which it isn't possible to reverse engineer by studying the outputs and > >>> inputs. �Is it possible to fabricate a custom DSP chip in such a way to > >>> prevent the underlying algorithm from being extracted, so it can remain > >>> a trade secret? > > >> Nothing will keep a well-funded potential competitor from grinding the > >> top off the chip and reverse-engineering (or just outright copying) the > >> code and/or design. > > >> But as others have said, there are chips with security features that'll > >> make it harder. > > >> All you can ever do is make it hard enough to be unprofitable; you'll > >> never make it impossible. > > > That's what I figured. �I appreciate all the responses. > > > I would have thought these days the chip circuitry might be > > sufficiently 3-dimensional to make grinding off the top impractical > > for copying purposes. > > You can probe the various parts. After all, with a lot of probing and > analysis, you can work out the circuit defined by a multi-layer circuit > board. Some masked ROMs can be read by looking at them under a microscope. > > Jerry > -- > Engineering is the art of making what you want from things you can get. > �����������������������������������������������������������������������- Hide quoted text - > > - Show quoted text -I've seen where the circuit is potted in an explosive compound with an internal photo sensor and battery. Try to disolve away the potting compound and the circuit explodes - true you may try this in the dark, but you can put some other gottchas in the circuits that will likely get disturbed by working in the dark. And if the battery goes flat, the circuit forgets important data. True not 100% foolproof, but it does get pretty difficult to beat. Clay
Reply by ●September 28, 20092009-09-28
On Mon, 28 Sep 2009 12:26:40 -0700 (PDT), Clay <clay@claysturner.com> wrote:>And if the battery goes flat, >the circuit forgets important data. True not 100% foolproof, but it >does get pretty difficult to beat.Xilinx has FPGAs which can accept encrypted configuration data where the decryption keys are stored in a battery backed portion of the chip. One stores the encrypted configuration data on a non-volatile memory chip and the fpga decrypts it when it need to reload ie after a power cycle. If anyone has managed to get at the keys of such configuration, they're not telling. One can apply additional intrusion detection and counter-measures on top of that configuration for a significant deterence to IP theft. -- Muzaffer Kal DSPIA INC. ASIC/FPGA Design Services http://www.dspia.com
Reply by ●September 29, 20092009-09-29
On Sep 28, 2:26�pm, Clay <c...@claysturner.com> wrote:> On Sep 28, 12:06�pm, Jerry Avins <j...@ieee.org> wrote: > > > > > > > axlq wrote: > > > In article <E_adneyngKqVlCLXnZ2dnUVZ_qydn...@web-ster.com>, > > > Tim Wescott �<t...@seemywebsite.com> wrote: > > >> On Sat, 26 Sep 2009 16:59:44 +0000, axlq wrote: > > >>> A business partner has an algorithm applicable to schocastic data, for > > >>> which it isn't possible to reverse engineer by studying the outputs and > > >>> inputs. �Is it possible to fabricate a custom DSP chip in such a way to > > >>> prevent the underlying algorithm from being extracted, so it can remain > > >>> a trade secret? > > > >> Nothing will keep a well-funded potential competitor from grinding the > > >> top off the chip and reverse-engineering (or just outright copying) the > > >> code and/or design. > > > >> But as others have said, there are chips with security features that'll > > >> make it harder. > > > >> All you can ever do is make it hard enough to be unprofitable; you'll > > >> never make it impossible. > > > > That's what I figured. �I appreciate all the responses. > > > > I would have thought these days the chip circuitry might be > > > sufficiently 3-dimensional to make grinding off the top impractical > > > for copying purposes. > > > You can probe the various parts. After all, with a lot of probing and > > analysis, you can work out the circuit defined by a multi-layer circuit > > board. Some masked ROMs can be read by looking at them under a microscope. > > > Jerry > > -- > > Engineering is the art of making what you want from things you can get. > > �����������������������������������������������������������������������- Hide quoted text - > > > - Show quoted text - > > I've seen where the circuit is potted in an explosive compound with an > internal photo sensor and battery. Try to disolve away the potting > compound and the circuit explodes - true you may try this in the dark, > but you can put some other gottchas in the circuits that will likely > get disturbed by working in the dark. And if the battery goes flat, > the circuit forgets important data. True not 100% foolproof, but it > does get pretty difficult to beat. > > ClayWhere did you see this!?
Reply by ●October 2, 20092009-10-02
In article <1sudnZXMXf-60iPXnZ2dnUVZ_sGdnZ2d@giganews.com>, Vladimir Vassilevsky <nospam@nowhere.com> wrote:>axlq wrote: >> A business partner has an algorithm applicable to schocastic data, >> for which it isn't possible to reverse engineer by studying the >> outputs and inputs. Is it possible to fabricate a custom DSP >> chip in such a way to prevent the underlying algorithm from being >> extracted, so it can remain a trade secret? > >It is possible to make a custom or semi-custom chip, however you need to >order large quantities to be commertially viable. You can use DSP with >security features, like ADI BlackFin. That protection is good enough to >stop an individual hacker. Any chip can be reverse engineered, this is a >matter of money and capabilities of the attacker.Sorry to resurrect a few-days-old thread, but I wondered what the experts here think of the security in the Altera MAX-3000 CPLD. http://www.altera.com/literature/ds/m3000a.pdf This chip stores its programming code in its own EEPROM, and provides a mechanism called a "security bit" that disables reading out the programming code. From the data sheet: Design Security All MAX 3000A devices contain a programmable security bit that controls access to the data programmed into the device. When this bit is programmed, a design implemented in the device cannot be copied or retrieved. This feature provides a high level of design security because programmed data within EEPROM cells is invisible. The security bit that controls this function, as well as all other programmed data, is reset only when the device is reprogrammed. That sounds pretty secure to me. If anyone de-caps the chip and examines the circuitry, it wouldn't reveal the programming logic. The big disadvantage I can see (correct me if I'm wrong, I'm not up on the jargon used in that document) is that we can't really program a floating-point algorithm, but rather we must restrict ourselves to programmiing logical operations. We don't need high speed. A floating-point programmable DSP that implements a similar security feature (a "write only" EEPROM) would be nice. -A
Reply by ●October 2, 20092009-10-02
On Sep 29, 1:10=A0pm, "wazerf...@gmail.com" <wazerf...@gmail.com> wrote:> On Sep 28, 2:26=A0pm, Clay <c...@claysturner.com> wrote: > > > > > > > On Sep 28, 12:06=A0pm, Jerry Avins <j...@ieee.org> wrote: > > > > axlq wrote: > > > > In article <E_adneyngKqVlCLXnZ2dnUVZ_qydn...@web-ster.com>, > > > > Tim Wescott =A0<t...@seemywebsite.com> wrote: > > > >> On Sat, 26 Sep 2009 16:59:44 +0000, axlq wrote: > > > >>> A business partner has an algorithm applicable to schocastic data=, for> > > >>> which it isn't possible to reverse engineer by studying the outpu=ts and> > > >>> inputs. =A0Is it possible to fabricate a custom DSP chip in such =a way to> > > >>> prevent the underlying algorithm from being extracted, so it can =remain> > > >>> a trade secret? > > > > >> Nothing will keep a well-funded potential competitor from grinding=the> > > >> top off the chip and reverse-engineering (or just outright copying=) the> > > >> code and/or design. > > > > >> But as others have said, there are chips with security features th=at'll> > > >> make it harder. > > > > >> All you can ever do is make it hard enough to be unprofitable; you='ll> > > >> never make it impossible. > > > > > That's what I figured. =A0I appreciate all the responses. > > > > > I would have thought these days the chip circuitry might be > > > > sufficiently 3-dimensional to make grinding off the top impractical > > > > for copying purposes. > > > > You can probe the various parts. After all, with a lot of probing and > > > analysis, you can work out the circuit defined by a multi-layer circu=it> > > board. Some masked ROMs can be read by looking at them under a micros=cope.> > > > Jerry > > > -- > > > Engineering is the art of making what you want from things you can ge=t.> > > =AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF==AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF= =AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF=AF- Hide= quoted text -> > > > - Show quoted text - > > > I've seen where the circuit is potted in an explosive compound with an > > internal photo sensor and battery. Try to disolve away the potting > > compound and the circuit explodes - true you may try this in the dark, > > but you can put some other gottchas in the circuits that will likely > > get disturbed by working in the dark. And if the battery goes flat, > > the circuit forgets important data. True not 100% foolproof, but it > > does get pretty difficult to beat. > > > Clay > > Where did you see this!?- Hide quoted text - > > - Show quoted text -In one of my past careers!
Reply by ●October 2, 20092009-10-02
axlq@spamcop.net (axlq) wrote in news:ha5b4s$2ap$1@blue.rahul.net:> In article <1sudnZXMXf-60iPXnZ2dnUVZ_sGdnZ2d@giganews.com>, > Vladimir Vassilevsky <nospam@nowhere.com> wrote: >>axlq wrote: >>> A business partner has an algorithm applicable to schocastic data, >>> for which it isn't possible to reverse engineer by studying the >>> outputs and inputs. Is it possible to fabricate a custom DSP >>> chip in such a way to prevent the underlying algorithm from being >>> extracted, so it can remain a trade secret? >> >>It is possible to make a custom or semi-custom chip, however you need to >>order large quantities to be commertially viable. You can use DSP with >>security features, like ADI BlackFin. That protection is good enough to >>stop an individual hacker. Any chip can be reverse engineered, this is a >>matter of money and capabilities of the attacker. > > Sorry to resurrect a few-days-old thread, but I wondered what the > experts here think of the security in the Altera MAX-3000 CPLD. > http://www.altera.com/literature/ds/m3000a.pdf > > This chip stores its programming code in its own EEPROM, and > provides a mechanism called a "security bit" that disables reading > out the programming code. From the data sheet: > > Design Security > > All MAX 3000A devices contain a programmable security bit that > controls access to the data programmed into the device. When > this bit is programmed, a design implemented in the device cannot > be copied or retrieved. This feature provides a high level of > design security because programmed data within EEPROM cells is > invisible. The security bit that controls this function, as well > as all other programmed data, is reset only when the device is > reprogrammed. > > That sounds pretty secure to me. If anyone de-caps the chip > and examines the circuitry, it wouldn't reveal the programming > logic. The big disadvantage I can see (correct me if I'm wrong, I'm > not up on the jargon used in that document) is that we can't really > program a floating-point algorithm, but rather we must restrict > ourselves to programmiing logical operations. > > We don't need high speed. A floating-point programmable DSP that > implements a similar security feature (a "write only" EEPROM) would > be nice. > > -AI assume that you are looking at the 3032 or 3064. These devices have 32 and 64 macrocells, respectively. I am sure that it would be easy to determine the internal logic by simple probing. You would not need to do anything exotic at all. Even a larger PLD would still be easy to reverse engineer. This is very different than the encryption used in many newer processors. The Blackfin BF54x, BF52x and BF51x are examples (lockbox features). As many have already pointed out, nothing is 100% secure. You need to consider the risks. Most I.P. theft is done by just direct copying an external device. It takes almost zero skill. The next level is simple protections like the PLD. This is still easy to duplicate if you have the desire. My guess is that it would stop 90-99% of the casual thieves, mostly because its not worth the trouble. In other words, protection based on laziness of the hacker. Parts with real security features are going to stop most everybody. Dissecting IC's may be possible, but it takes a committed effort. In my experience, most algorithms are not really that special to merit the effort to protect them behind reasonable security measures. I realize that settop box makers, gaming machines, etc might be exceptions. Al Clark Danville Signal
Reply by ●October 2, 20092009-10-02
Al Clark <aclark@danvillesignal.com> wrote:> In my experience, most algorithms are not really that special > to merit the effort to protect them behind reasonable security > measures. I realize that settop box makers, gaming machines, > etc might be exceptions.The big demand right now for reverse-engineering-resistant ASIC's with embedded algorithms comes from the financial engineering sector -- quant trading, high-frequency trading, and so forth. Things like the recent leak of HF software from Goldman is something these guys would like to rule out entirely. I'd bet a nickle the OP is looking at something along these lines. Steve
Reply by ●October 2, 20092009-10-02
In article <ha5o4t$t8m$1@blue.rahul.net>, Steve Pope <spope33@speedymail.org> wrote:>Al Clark <aclark@danvillesignal.com> wrote: >> In my experience, most algorithms are not really that special >> to merit the effort to protect them behind reasonable security >> measures. I realize that settop box makers, gaming machines, >> etc might be exceptions. > >The big demand right now for reverse-engineering-resistant ASIC's >with embedded algorithms comes from the financial engineering >sector -- quant trading, high-frequency trading, and so forth.Well. You guessed it. I wasn't going to mention it, but since you brought it up.... We want to embed an algorithm originally developed for financial trading into a DSP chip, for "stochastic time series" applications such as medical monitoring devices, adaptive optics, weather prediction, and other useful things. Used privately for financial trading, it can be maintained as a trade secret known only to its inventor and a couple trusted people. Once embedded into electronic hardware, however, it becomes a target exactly like you describe, regardless of how far removed the end application appears to be from finance.>I'd bet a nickle the OP is looking at something along these lines.Heh. Where do I send your nickel? And getting back to my original question, is it pointless to search for a secure DSP that fits my needs? -A






