4 ms·
I simply do not believe one could find a "back door" looking at a chip in a SEM. It sounds to me like you are describing destructive physical analysis whose pur
by aiscott 14y ago
I simply do not believe one could find a "back door" looking at a chip in a SEM. It sounds to me like you are describing destructive physical analysis whose purpose is to make sure requisite manufacturing practices are being followed.
- lukeschlather 14y agoThe way I read that is that they make the designs and look for circuitry that does not match the designs, which is presumed to be backdoors. I would think that defects and intentional backdoors would both be findable on an SEM. Do you think otherwise? I don't have a ton of experience with bare silicon, so I'd be interested to know if that's unreasonable.
- aiscott 14y agoI do think it is unreasonable. With a SEM you only get to look at the surface of things, which is going to be either glass or metal or polysilicon. The only way to see a transistor in a sem is if you chemically remove all the top layers (which are the connections between transistors), or perform a cross section. In the cross section case you are going to see a few dozen transistors out of the millions in a design of any complexity. It would be remotely feasible to discover some sort of shenanigans if you knew the exact layout of the design, which would basically mean you are a foundry yourself. In that case you might get lucky and spot some difference between the mask you made, and the mask that was used to produce the part under inspection. But the scales involved make this not believable to me. It would be roughly like scanning the whole of, say, America, and checking every street and intersection of every town, and comparing it against some known quantity to see if something changed in Springfield Missouri. Maybe somebody could automate this, but the chemical processes for removing layers is less than perfect. Those strands of metal stretching across the ASIC have some built in tension, and if you remove the layer of glass above them, then tend to spring up and jumble. Good luck trying to do something with that.
- knowaveragejoe 14y agoThis. You've articulated the complexity of looking at circuitry schematics for backdoors better than I ever could.
- gouranga 14y agoJust to add... Any "advanced" backdoors take significant silicon and would be visible from the top of the device as a significant design change would be required to accomodate them. Subtle flaws in designs are another thing altogether.
- knowaveragejoe 14y agoEven then - the manufacturer could supply design documents that surreptitiously include backdoors... there's simply so much to look at when it comes to actual circuit schematics, I can't see how anyone would spot "backdoor" circuitry amongst everything else that is presumably legitimate. I don't know much about silicon, so maybe I'm wrong.
- kwantam 14y agoThere are companies that specialize in reverse engineering schematics from silicon. It's entirely possible (albeit relatively expensive and time-consuming compared to good old-fashioned industrial espionage) to recover schematics from silicon. Have a look at this video from ChipWorks http://www.youtube.com/watch?v=Il5sTZKBLO0 http://www.youtube.com/watch?v=Il5sTZKBLO0 See the schematics? They've created those from scratch by deconstructing the chip. (I can say with certainty that this is the case because I'm familiar with the original schematics for this part. The ChipWorks ones are much neater!) Doing this for a larger, all-digital chip is substantially the same. In that case you can probably step up from identifying individual transistors and identify the standard cells directly, since they tend to have distinctive-looking gate structures.