Skip to content
safemode.space
All incidents
2012-05-01 (approximate)
security research
supply chain

Actel/Microsemi ProASIC3 silicon backdoor claim (Skorobogatov and Woods, 2012)

Confidence in this reading:
moderate

What happened

Sergei Skorobogatov of the University of Cambridge and Christopher Woods of Quo Vadis Labs reported that the Actel/Microsemi ProASIC3 field-programmable gate array, a military-grade flash-based device marketed into aerospace and defence, contained an undocumented key-activated access path in the silicon itself, present alongside the documented JTAG functionality and not in any loaded firmware. Using a power-analysis method they called Pipeline Emission Analysis, they recovered the key that activates the path together with the device's AES key and Passkey, and reported that these would permit extraction of the configuration bitstream, reprogramming of crypto and access keys, alteration of low-level silicon features, or permanent damage to the device. The work was presented at CHES 2012 in Leuven on 9-12 September 2012, with a draft circulating from May 2012. Microsemi denied that its devices contain a backdoor and said it could neither confirm nor deny the claim because the researchers had not supplied the technical details of their set-up or access to their custom equipment. Robert Graham of Errata Security argued the mechanism is most likely an overlooked manufacturer debug feature and that no evidence supports the Chinese-insertion framing much of the press coverage carried.

The measurement is peer-reviewed and the dispute is about the label, not the finding. Microsemi's and Graham's answer, that the mechanism is a manufacturer debug or test feature rather than a malicious implant, addresses attribution; it does not remove the technique mapping, because SPARTA's own definition of PER-0002.01 explicitly covers persistent debug interfaces, undocumented device commands and manufacturing modes. What the dispute does remove is the supply-chain mapping: IA-0001.03 requires an adversary to alter programmable logic prior to delivery, and nothing here establishes that, so it is rejected. That rejection is the substantive difference between this record and the 2012 press coverage, which widely reported a Chinese backdoor in a US military chip. On space relevance: the ProASIC3 family is radiation-tolerant logic sold into aerospace, but no source used here names a spacecraft carrying the part and none is asserted. The relevance is to the class of device.

Attack vector

An undocumented, key-activated access path in shipped FPGA silicon adjacent to the JTAG interface, reached after recovering the activation key by power analysis of the device.

Operational impact

None demonstrated. The reported effects, bitstream extraction, key reprogramming and device damage, are capabilities the access path would permit rather than acts performed against a fielded system.

Affected segments

supply_chain, space

Disclosed

2012-09-09

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • EX-0005.01's description names undocumented or weakly specified behaviours, listing scan chains, test modes and debug straps, exploited as inherent properties of the hardware and logic design rather than by injecting new code. That is precisely the object of this research and the way it was exploited. The evidence type is derived rather than direct: the argument runs from the technique's own description to the subject of the research, and no verbatim excerpt of the paper was read against this technique.

    https://www.cl.cam.ac.uk/~sps32/ches2012-backdoor.pdf

  • Pipeline Emission Analysis is a power-analysis method: secrets are inferred by measuring device power consumption and correlating traces against hypothesised internal operations, which is EXF-0002.01's definition. It is the paper's method and it is what recovered the activation key, the AES key and the Passkey.

    https://www.cl.cam.ac.uk/~sps32/ches2012-backdoor.pdf

  • SPARTA's definition names enabled test and scan chains, manufacturing or boot-strap modes invoked by pins or registers, persistent debug interfaces and undocumented device commands as instances of this technique. The reported finding is a key-activated, undocumented access path in shipped silicon sitting alongside the JTAG functionality. Microsemi's and Graham's rebuttals dispute intent and attribution; the technique's definition depends on neither, so the edge survives the dispute intact.

    https://www.cl.cam.ac.uk/~sps32/ches2012-backdoor.pdf

  • The researchers recovered cryptographic material conferring decryption and reconfiguration authority over the device, specifically its AES key and Passkey. RD-0003.02's framing is mission-level material such as uplink authentication keys and link-encryption keys, whereas these are device-level intellectual-property protection keys, so the edge is derived from the acquisition act rather than from a match to the technique's usual objects.

    https://www.cl.cam.ac.uk/~sps32/ches2012-backdoor.pdf

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Also cited in SPARTA's bibliography here. The specific child EX-0005.01 is mapped; mapping the parent as well would double-count one act, and the "corruption" framing fits the glitching case (see the Starlink terminal record) better than it fits an undocumented interface.

  • Also cited in SPARTA's bibliography here. Same reasoning, one level up.

  • Cited in SPARTA's bibliography against this paper, and rejected. The technique requires an adversary to alter boards, modules or programmable logic prior to delivery. The record establishes an undocumented access path present as shipped; it does not establish that anyone inserted it to create latent access. Graham's point that there is no evidence of deliberate malicious insertion is the reason. The technique's description does list "leaving debug interfaces active" among its tactics, which is why this is a considered rejection rather than an obvious one.

  • The paper states that permanent damage to the device is one of the things the access path would permit. It reports a capability, not an act. No device was destroyed.

  • Parent of a mapped child.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

A source marked contradicting disputes the account above rather than supporting it. It is listed because a reader assessing this record should see it.

  • Cryptographic Hardware and Embedded Systems (CHES) 2012, Springer LNCS 7428 · Sergei Skorobogatov, Christopher Woods · 2012-09-09

    Tier 1: Peer-reviewed paper at CHES, the principal academic venue for cryptographic hardware, published in LNCS 7428. Authoritative on the measurement and the method.

  • Errata Security · Robert Graham · 2012-05-28

    Tier 2: Named technical criticism by an established security researcher on his own blog. Authoritative on the argument; not independently verified and not peer-reviewed.

  • EE Times · 2012-05-01

    Tier 3: Electronics trade press carrying the manufacturer's statement. Tier 3: it is a channel for an interested party's position rather than an independent assessment.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.