Skip to content

Author

Maik Ender

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Jul 2026

Leakback CRC: Optical Plaintext Recovery of Encrypted Bitstreams on AMD 7-Series FPGAs

FPGAs are increasingly deployed in security-critical applications, where both design confidentiality and operational reliability are paramount. To protect IP, safeguard cryptographic secrets, and prevent unauthorized modifications or hardware Trojan insertion, modern hardware platforms employ bitstream encryption. Built-in reliability features, often required by safety regulations, detect and correct singleevent upsets, i.e., bit flips, caused by ionizing radiation. However, these reliability mechanisms can inadvertently compromise bitstream confidentiality.In this work, we present Leakback CRC, the first optical side-channel attack exploiting the Readback CRC functionality in AMD 7-Series FPGAs to recover plaintext configuration data of encrypted bitstreams. Our attack utilizes contactless optical probing to monitor periodic configuration memory accesses by the Readback CRC circuitry. This novel attack results in full netlist reconstruction, even though dynamically changing runtime data cannot be retrieved, as it is not verified by the Readback CRC. After presenting the attack in a case study on an AMD 7-Series FPGA, we discuss its limitations and potential countermeasures, as well as its applicability to other FPGA platforms. Our findings highlight a critical interplay between reliability mechanisms operating on plaintext configuration data and side-channel leakage, underscoring the need to broaden the threat model underlying built-in reliability features in reconfigurable hardware.

Antonio Saavedra, Lars Renkes, F. Hahn et al. · 0 citations