Laser Injection Attack Bypasses RP2350 Secure Boot and TrustZone
Ledger Donjon's security team performed laser fault injection on the Raspberry Pi Foundation's RP2350 microcontroller. The attack bypassed secure boot and TrustZone, restoring debugger access, after which a 128-bit secret was read from chip memory.
- Attack bypassed RP2350 secure boot, TrustZone and fault protection
- Chip was decapsulated and laser-fired through the silicon substrate
- Laser flipped bits in the register enabling debug mode
- After reset, a 128-bit secret was read from chip memory
Read next
Security